Information construction device and information construction method using generation model

By ensuring authenticity and evaluating reliability of generative model output, the device constructs accurate product management information, addressing the inaccuracies of generative models in constructing SBOM and other product data.

JP2025125332APending Publication Date: 2025-08-27HITACHI LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024021315
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-02-15
Publication Date
2025-08-27

AI Technical Summary

Technical Problem

Generative models, being probabilistic, often produce incorrect output data, which complicates the construction of product management information such as SBOM, and this issue extends to other product types beyond software.

Method used

An information construction device ensures authenticity of input information, generates prompts for missing configuration information using a generative model, evaluates the reliability of extracted labels, and adds high-reliability labels to a configuration management database.

Benefits of technology

This approach allows for the construction of reliable product management information, including SBOM, by ensuring the accuracy and reliability of the generated data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025125332000001_ABST
    Figure 2025125332000001_ABST
Patent Text Reader

Abstract

To construct at least a portion of product management information having high reliability by using a generation model.SOLUTION: An information construction device generates a prompt for acquiring one or more element levels corresponding to configuration information and inputs the prompt in a generation model in the case that the configuration information extracted from input information that secures authenticity is not included in configuration management information as at least a portion of product management information. The information construction device calculates the reliability of a corresponding element label for each of the one or more element labels extracted from output data of the generation model. The information construction device adds a data set including one or more element labels, each reliability of which satisfies a condition and the extracted configuration information to the configuration management information as an authenticity data set.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention generally relates to information processing using generative models. [Background technology]

[0002] SBOM (Software Bill of Materials) is known. SBOM is used for software vulnerability management. For example, the technology disclosed in Patent Document 1 is known as a vulnerability management technology. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Publication No. 2020-021309 Summary of the Invention [Problem to be solved by the invention]

[0004] By using at least a part of the SBOM as output data of a generative model (typically a text generation model), the burden of constructing the SBOM can be reduced.

[0005] However, since generative models are generally probabilistic models, the output data of the generative models is not always correct.

[0006] This type of issue can also occur when the information constructed using the output data of a generative model is product management information other than SBOM (in other words, when the product is a product other than software). [Means for solving the problem]

[0007] An information construction device acquires information whose authenticity is ensured as input information. When configuration management information, which is at least a part of product management information for one or more products, does not contain configuration information extracted from the input information, the device generates a prompt for obtaining one or more element levels corresponding to the configuration information and inputs the prompt to a generative model. When one or more element labels are extracted from the output data of the generative model, the device calculates the reliability of each of the one or more element labels. When one or more extracted element labels have one or more high-reliability labels, the device adds a dataset including the one or more high-reliability labels and the extracted configuration information to the configuration management information as an authenticity dataset. The configuration information is information representing a product configuration, which is at least one of the product name and model number. A high-reliability label is an element label whose reliability satisfies a condition. Each authenticity dataset in the configuration management information is a dataset including one or more high-reliability labels and configuration information corresponding to the one or more high-reliability labels. [Effects of the Invention]

[0008] According to one aspect of the present invention, it is possible to construct at least a portion of reliable product management information using a generative model. Problems, configurations, and effects other than those described above will become apparent from the following description of the embodiments. [Brief explanation of the drawings]

[0009] [Figure 1] FIG. 1 is a diagram illustrating an example of a configuration of an information construction device according to an embodiment. [Figure 2] FIG. 10 is a diagram showing an example of a flow of processing performed by the information construction device. [Figure 3] FIG. 10 is a diagram showing an example of the flow of a first DB construction process. [Figure 4] FIG. 10 is a diagram showing an example of the flow of a second DB construction process. [Figure 5] FIG. 10 is a diagram illustrating an example of the flow of a DB update process. [Figure 6]FIG. 10 is a diagram illustrating an example of the configuration of a configuration management DB. [Figure 7] FIG. 10 illustrates an example of the configuration of a temporary management DB; [Figure 8] FIG. 10 is a diagram illustrating an example of the configuration of an authenticity evaluation rule DB. [Figure 9] FIG. 10 is a diagram illustrating an example of the configuration of a configuration management DB after updating. DETAILED DESCRIPTION OF THE INVENTION

[0010] In the following description, an "interface apparatus" may refer to one or more interface devices, which may be at least one of the following: One or more I / O (Input / Output) interface devices. The I / O (Input / Output) interface devices are interface devices for at least one of an I / O device and a remote display computer. The I / O interface device for the display computer may be a communications interface device. The at least one I / O device may be a user interface device, for example, either an input device such as a keyboard and a pointing device, or an output device such as a display device. One or more communication interface devices. The one or more communication interface devices may be one or more homogeneous communication interface devices (e.g., one or more NICs (Network Interface Cards)) or two or more heterogeneous communication interface devices (e.g., a NIC and an HBA (Host Bus Adapter)).

[0011] In the following description, "memory" refers to one or more memory devices, which are an example of one or more storage devices, and may typically be a primary storage device. At least one memory device in the memory may be a volatile memory device or a non-volatile memory device.

[0012] In the following description, a "persistent storage device" may refer to one or more persistent storage devices, which are an example of one or more storage devices. A persistent storage device may typically be a non-volatile storage device (e.g., an auxiliary storage device), and specifically may be, for example, a hard disk drive (HDD), a solid state drive (SSD), a non-volatile memory express (NVME) drive, or a storage class memory (SCM).

[0013] In the following description, the term "storage device" may refer to at least one of memory and persistent storage device.

[0014] Furthermore, in the following description, a "processor" may refer to one or more processor devices. The at least one processor device may typically be a microprocessor device such as a CPU (Central Processing Unit), but may also be another type of processor device such as a GPU (Graphics Processing Unit). The at least one processor device may be a single-core or multi-core. The at least one processor device may also be a processor core. The at least one processor device may also be a processor device in a broader sense, such as a circuit that is a collection of gate arrays written in a hardware description language that performs some or all of the processing (for example, an FPGA (Field-Programmable Gate Array), a CPLD (Complex Programmable Logic Device), or an ASIC (Application Specific Integrated Circuit)).

[0015] In the following description, functions are sometimes described using the expression "yyy unit." However, the functions may be realized by one or more computer programs executed by a processor, by one or more hardware circuits (e.g., FPGAs or ASICs), or by a combination thereof. When a function is realized by a program executed by a processor, the specified processing is performed using a storage device and / or an interface device, etc., as appropriate, and therefore the function may be considered to be at least a part of the processor. Processing described using a function as the subject may be processing performed by a processor or a device having the processor. A program may be installed from a program source. The program source may be, for example, a program distribution computer or a computer-readable storage medium (e.g., a non-transitory storage medium). The description of each function is merely an example; multiple functions may be combined into one function, or one function may be divided into multiple functions.

[0016] In the following description, data that produces an output in response to an input may be described using the expression "xxxDB" ("DB" is an abbreviation for database), but the data may be data of any structure (for example, structured data or unstructured data), or may be a neural network that generates an output in response to an input, or a learning model such as a genetic algorithm or random forest. Therefore, "xxxDB" can be referred to as "xxx information." In the following description, the configuration of each DB is an example, and one DB may be divided into two or more DBs, or all or part of two or more DBs may be one DB.

[0017] In the following explanation, a "dataset" refers to a logical block of electronic data as seen from a program such as an application program, and may be, for example, a record, a file, a key-value pair, a tuple, etc. Below, a record will be taken as an example of a dataset.

[0018] Hereinafter, embodiments will be described with reference to the drawings. In the following embodiments, the generative model may be a trained generative model, for example, a generative model trained using one or more datasets as training data, each of which includes configuration information and one or more element labels. Software is used as an example of a product, and SBOM is used as an example of product management information related to one or more products. Furthermore, configuration information labels and vendor names are used as the multiple element labels. As an example of a generative model, a text generation model, for example, an LLM (Large Language Model), is used.

[0019] FIG. 1 is a diagram illustrating an example of a configuration of an information construction device according to an embodiment.

[0020] In this embodiment, the information construction device 110 is a physical computer system (one or more computers), but it may alternatively be a logical computer system based on a physical computer system (for example, a system as a cloud computer service based on a cloud infrastructure).

[0021] The information construction device 110 includes an interface device 120, a storage device 140, and a processor 130 connected thereto.

[0022] The interface device 120 communicates with external devices such as an information source 100, a generation server 101, and a UI (User Interface) device 102 via, for example, a communication network (e.g., the Internet or a Wide Area Network (WAN)). The information source 100 may be a server (site) on the Internet and stores information about software. The generation server 101 may be a physical or logical computer system, has a generative model, and executes processing using the generative model. Specifically, the generation server 101 receives a prompt from a sender, inputs the received prompt into the generative model, and returns data output from the generative model to the sender of the prompt. The generative model may be located on an external server as illustrated in FIG. 1, or may be stored in the storage device 140 of the information construction device 110 and used within the information construction device 110. The UI device 102 may be an input / output device such as a keyboard, a pointing device, and a display device, or may be a remote information processing terminal (e.g., a personal computer or a smartphone) serving as a client when the information construction device 110 is a server. The user can use the UI device 102 to send desired instructions to the information construction device 110 and view information sent from and displayed by the information construction device 110.

[0023] The storage device 140 stores information and programs. For example, the storage device 140 stores a configuration management DB 141, a temporary management DB 142, and an evaluation rule DB 143 (these DBs 141 to 143 will be described later). The storage device 140 also stores programs executed by the processor 130.

[0024] When the processor 130 executes the program, functions such as an information acquisition unit 131, a prompt generation unit 132, an authenticity evaluation unit 133, and an information update unit 134 are realized (these functions 131 to 134 will be described later).

[0025] FIG. 2 is a diagram showing an example of the flow of processing performed by the information construction device 110.

[0026] The information acquisition unit 131 acquires, as input information, information whose authenticity has been ensured from the information source 100 (S201). "Information whose authenticity has been ensured" may mean information from the information source 100 operated by an institution that is deemed to be trustworthy (for example, a security vendor's website, a website of a company that provides product information, a National Vulnerability Database (NVD), or a news website). In other words, whether or not the authenticity of information is ensured may depend on the reliability of the information provided by the information source 100. The definition of "information whose authenticity has been ensured" may additionally include information that has been encrypted or information in which no tampering has been detected in a tampering detection process.

[0027] The information acquisition unit 131 extracts configuration information from the input information acquired in S201 (S202) and determines whether the configuration information is included in the configuration management DB 141 (S203). For example, in S202, the information acquisition unit 131 may extract the configuration information by inputting the input information to a trained machine learning model (e.g., a generative model) implemented in the information construction device 110. Also, for example, in S202, the information acquisition unit 131 may acquire the configuration information from an external information processing device by inputting the input information to a trained machine learning model (e.g., a generative model) implemented in an information processing device external to the information construction device 110. These machine learning models may be models that input authentic information and output configuration information. "Configuration information" is information that represents a product configuration, which is at least one of the product name and model number. For example, as shown in FIG. 6, the configuration management DB 141 is one or more records, and each record has information such as a configuration information label 601, configuration information 602, and a vendor name 603. The configuration information label 601 represents the label of the category to which the product configuration belongs, and the vendor name represents the name of the product vendor. Each record in the configuration management DB 141 includes configuration information 602, and a configuration information label 601 and a vendor name 603 whose reliability is equal to or greater than a threshold. If the reliability of only one of the configuration information label and the vendor name is equal to or greater than a threshold, only that one will be registered in the configuration management DB 141 (see the record for configuration information 602 "Bluetooth Stack C" in FIG. 6). Such a configuration management DB 141 can be said to be a DB whose authenticity is guaranteed.

[0028] If the determination result in S203 is true (S203: YES), the information acquisition unit 131 determines whether or not the configuration information label and vendor name associated with the configuration information are registered in the configuration management DB 141 (S204). If both the configuration information label and the vendor name are registered in the configuration management DB 141, the determination result in S204 is true. If either or both of the configuration information label and the vendor name are not registered in the configuration management DB 141, the determination result in S204 is false.

[0029] If the determination result in S204 is true (S204: YES), both the configuration information label and the vendor name for the configuration information extracted in S202 are registered in the configuration management DB 141, and therefore the process ends.

[0030] If the determination result in S203 is false (S203: NO), or if the determination result in S204 is false (S204: NO), the prompt generation unit 132 generates a prompt as an inquiry or request for the configuration information label and / or vendor name that is missing from the configuration information extracted in S202, and inputs the prompt into the generation model; specifically, in this embodiment, it sends the prompt to the generation server 101 (S205). The information construction device 110 receives the output data of the generation model that was generated in S205 and into which the prompt was input from the generation server 101.

[0031] The authenticity evaluation unit 133 extracts registration candidates from the output data (S206). The "registration candidates" here are words that are presumed to be configuration information labels and / or words that are presumed to be vendor names. The presumption of a configuration information label and / or vendor name may be made based on the context of the text contained in the output data, or may be made by other methods. It is possible that no registration candidates exist in the output data. If a registration candidate cannot be presumed in S206 (S207: NO), the processing ends.

[0032] If a registration candidate can be estimated in S206 (S207: YES), the authenticity evaluation unit 133 evaluates the registration candidate, specifically, calculates the reliability of the registration candidate (S208). In S208, the authenticity evaluation unit 133 calculates the reliability of the registration candidate (words estimated to be configuration information labels and / or words estimated to be vendor names) based on the authenticity evaluation rule DB 143. As shown in FIG. 8, for example, the authenticity evaluation rule DB 143 has a record for each evaluation rule, and each record has information such as type 801, evaluation rule 802, and points 803. The type 801 indicates the type of the registration candidate (in this embodiment, whether it is a configuration information label or a vendor name). The rule 802 indicates the evaluation rule. The points 803 indicate points added when the evaluation rule is satisfied. The authenticity evaluation unit 133 calculates the total value of points 803 corresponding to one or more rules 802 that the registration candidate matches, and calculates the total value or a value based on the total value as the reliability. Regarding rule 802 that "the vendor name is the name of an existing company," one possible way to check whether the vendor name is the name of an existing company is to use information that organizes existing company names to a certain extent, such as a CPE (Common Platform Enumeration) dictionary.

[0033] The information update unit 134 determines whether the temporary management DB 142 contains a record that matches or is similar to the extracted dataset, which is a dataset including the configuration information extracted in S202 and the registration candidates extracted in S206 (words presumed to be configuration information labels and / or words presumed to be vendor names) (S209). The temporary management DB 142 has one or more records, as shown in FIG. 7, for example, and each record is an example of a temporary dataset. Each record has information such as a configuration information label 701, configuration information 702, configuration information label reliability 703, vendor name 704, and vendor name reliability 705. The configuration information label reliability 703 indicates the reliability of the configuration information 702, and the vendor name reliability 705 indicates the reliability of the vendor name 704.

[0034] If the determination result of S209 is false (S209: NO), the first DB construction process is performed (S210). If the determination result of S209 is true (S209: YES), the second DB construction process is performed (S211).

[0035] FIG. 3 is a diagram illustrating an example of the flow of the first DB construction process.

[0036] The information update unit 134 determines whether the calculated reliability of each of the configuration information labels and / or vendor names in the extracted data set is equal to or greater than the reliability threshold of the label of the element (S301). The reliability thresholds of the configuration information labels and vendor names may be the same or different.

[0037] If the determination result of S301 is true for an element label (S301: YES), DB update processing is performed on the element label in the configuration management DB 141 (S302). That is, a pair including an element label and configuration information whose reliability is equal to or greater than a threshold is registered in the configuration management DB 141.

[0038] If the determination result of S301 is false for any element label (S301: NO), DB update processing is performed for the element label in the temporary management DB 142 (S302). That is, a set including an element label whose reliability is less than the threshold, its reliability, and configuration information is registered in the temporary management DB 142.

[0039] FIG. 4 is a diagram showing an example of the flow of the second DB construction process. In the following description, for convenience, a record in the temporary management DB 142 that matches or is similar to the extracted dataset will be referred to as a "target temporary record." The components of the extracted dataset and the target temporary record are the same. For example, if the extracted dataset includes configuration information, a configuration information label, and a vendor name, the target temporary record also includes configuration information, a configuration information label, and a vendor name. If the extracted dataset includes configuration information and a configuration information label but not a vendor name, the target temporary record also includes configuration information and a configuration information label but not a vendor name. If the extracted dataset includes configuration information and a vendor name but not a configuration information label, the target temporary record also includes configuration information and a vendor name but not a configuration information label.

[0040] The information update unit 134 determines whether the calculated reliability of each element label of the configuration information label and the vendor name is higher than the reliability in the target temporary record (S401).

[0041] If the determination result of S401 is that there is a true element label (S401: YES), the information update unit 134 determines whether the calculated reliability of the element label is equal to or greater than the threshold reliability of the label of the element (S402).

[0042] If the determination result of S402 is true for an element label (S402: YES), DB update processing of the configuration management DB 141 is performed for the element label (S403). That is, a pair including an element label and configuration information whose reliability is equal to or greater than the threshold is registered in the configuration management DB 141. The information update unit 134 deletes the pair including the element label and configuration information from the temporary management DB 142 (S404). Specifically, for example, if a certain record in the temporary management DB 142 has both a configuration information label 701 and a vendor name 704, but the only element label whose reliability is equal to or greater than the threshold is the configuration information label 701, the pair including the configuration information 702 and the configuration information label 701 (and the configuration information label reliability 703) is deleted from the temporary management DB 142, but the pair including the configuration information 702 and the vendor name 704 (and the vendor name reliability 705) remains in the temporary management DB 142. More specifically, for example, in the temporary management DB 142, the element labels registered in the configuration management DB 141, among the configuration information label 701 and the vendor name 704, may be associated with information (e.g., a flag) indicating that registration in the configuration management DB 141 has been completed, and the association of this information may indicate deletion from the temporary management DB 142.

[0043] If the determination result of S402 is false for any element label (S402: NO), DB update processing is performed for the element label in the temporary management DB 142 (S405). That is, the element label whose reliability is less than the threshold and its new reliability are registered in the target temporary record in the temporary management DB 142.

[0044] 5 is a diagram showing an example of the flow of DB update processing for each of the configuration management DB 141 and the temporary management DB 142. In the explanation of FIG.

[0045] If the target DB contains a record having the same configuration information as the extracted configuration information (S501: YES), the information update unit 134 integrates the record containing the extracted element label (the word presumed to be the configuration information label and / or the word presumed to be the vendor name) with the record (S502). For example, S502 is performed in S403 of FIG. 4.

[0046] On the other hand, if the target DB does not contain a record having the same configuration information as the extracted configuration information (S501: NO), the information update unit 134 adds a record including the extracted configuration information and the extracted element label to the target DB (S503). For example, S503 is performed in S302 and S303 of FIG.

[0047] Although one embodiment of the present invention has been described, this embodiment is presented as an example and is not intended to limit the scope of the invention. The present invention can be embodied in various other forms, and various omissions, substitutions, and modifications can be made without departing from the spirit of the invention. This embodiment is included within the scope and spirit of the invention, and is also included in the invention described in the claims and their equivalents.

[0048] For example, the above description can be summarized as follows: Note that the following summary may include supplementary explanations and explanations of modifications of the above description.

[0049] The information construction device (e.g., 110) includes an information acquisition unit (e.g., 131), a prompt generation unit (e.g., 132), an authenticity evaluation unit (e.g., 133), and an information update unit (e.g., 134). The information acquisition unit acquires information whose authenticity is ensured as input information. When configuration management information, which is at least a part of product management information related to one or more products, does not contain configuration information extracted from the input information, the prompt generation unit generates a prompt for obtaining one or more element levels corresponding to the configuration information and inputs the prompt to the generative model. When one or more element labels are extracted from the output data of the generative model, the authenticity evaluation unit calculates the reliability of each of the one or more element labels. When one or more extracted element labels have one or more high-reliability labels, the information update unit adds a dataset including the one or more high-reliability labels and the extracted configuration information to the configuration management information (e.g., the configuration management DB 141) as an authenticity dataset. Configuration information is information that represents a product configuration, which is at least one of the product name and model number. A high-confidence label is an element label whose reliability satisfies a condition (e.g., an element label whose reliability is equal to or greater than a threshold). The reliability condition may differ depending on the type of element label, or may be common regardless of the type of element label. Each authenticity dataset (e.g., each record) contained in the configuration management information is a dataset containing one or more high-confidence labels and configuration information corresponding to the one or more high-confidence labels. This makes it possible to construct at least a portion of highly reliable product management information using a generative model. Each element label may be a configuration information label, which is a label for the category to which the product configuration belongs, or the vendor name, which is the vendor of the product. Furthermore, the product management information may be a software bill of materials (SBOM). This makes it possible to construct configuration management information as part of the SBOM.

[0050] If one or more extracted element labels have one or more low-reliability labels, the information update unit may add a data set including the one or more low-reliability labels and the extracted configuration information as a temporary data set to the temporary management information (e.g., temporary management DB 142). A low-reliability label may be an element label whose reliability does not satisfy a condition (e.g., an element label whose reliability is less than a threshold). Each temporary data set included in the temporary management information may be a data set including one or more low-reliability labels and configuration information corresponding to the one or more low-reliability labels. Improvements to information construction (e.g., at least one of improved prompts and improved reliability calculation methods) are expected based on the temporary management information in which low-reliability labels are registered.

[0051] The information update unit may perform a similarity determination to determine whether a target temporary dataset, which is a temporary dataset that matches or is similar to an extracted dataset including the extracted one or more element labels and the extracted configuration information, is temporary management information. If the result of the similarity determination is true, the information update unit may delete from the target temporary dataset any low-confidence labels that match or are similar to any of the one or more high-confidence labels added to the configuration management information among the extracted one or more element labels. This is expected to allow the datasets registered in the temporary management information to be appropriately reflected in the configuration management information, and to prevent the temporary management information from becoming bloated.

[0052] The configuration information in the target temporary dataset may match the configuration information in the extracted dataset, allowing configuration management information to be built using the configuration information as a primary key.

[0053] Each temporary data set included in the temporary management information may include a calculated reliability for each element label included in the temporary data set. For example, if the calculated reliability of each element label in the extracted data set is higher than the reliability of an element label in the target temporary data set that matches or is similar to the element label, the information update unit may update the reliability in the target temporary data set to the calculated reliability. This is expected to improve information construction (e.g., at least one of improved prompts and improved reliability calculation methods) based on the latest reliability or a history of calculated reliability.

[0054] If the result of the similarity determination is false and the extracted multiple element labels include one or more low-confidence labels, the information update unit may add a dataset including the extracted multiple element labels and the extracted configuration information as a temporary dataset to the temporary management information, regardless of whether the extracted multiple element labels include one or more high-confidence labels. If the result of the similarity determination is true and the target temporary dataset contains one or more element labels whose confidence levels do not satisfy a condition, and for each of the one or more element labels, the confidence levels calculated for element labels in the extracted dataset that match or are similar to the element labels satisfy the condition, the information update unit may add the extracted dataset and / or the target temporary dataset to the configuration management information. That is, after the extracted dataset is added to the temporary management information as a temporary dataset, the temporary dataset may be identified as the target temporary dataset, and the calculated confidence levels for element labels that match or are similar to the low-confidence labels for each of all low-confidence labels in the temporary dataset may be added to the configuration management information. In this way, the extracted multiple element labels are added to the configuration management information as one combination, and it is expected that the relationship between the configuration information and the element labels will be more detailed to create configuration management information.

[0055] The authenticity evaluation unit may calculate the reliability of at least one of the extracted one or more element labels based on rules. For example, the authenticity evaluation unit may identify which one or more evaluation rules, each of which has a point associated therewith, are satisfied for at least one of the extracted one or more element labels, and calculate the reliability based on the points corresponding to each of the satisfied one or more evaluation rules. This is expected to allow for the calculation of an appropriate reliability depending on the type of element label, input information including the element label, etc. When the information update unit determines from the temporary management information that a low reliability of a certain element label is maintained, it may update the evaluation rule for the certain element label. This is expected to allow for the calculation of a more appropriate reliability.

[0056] When a temporary data set having the extracted configuration information is included in the temporary management information, the prompt generation unit may generate a prompt for obtaining a low-confidence label in the temporary data set for the configuration information. This increases the likelihood that an element label that matches or is similar to the low-confidence label will be extracted from the input information and a confidence level that satisfies a condition will be calculated for the element label, thereby increasing the likelihood that an element label that matches or is similar to the low-confidence label in the temporary data set will be reflected in the configuration management information. [Explanation of symbols]

[0057] 110: Information construction device

Claims

1. an information acquisition unit that acquires information whose authenticity is assured as input information; a prompt generation unit that, when the configuration information extracted from the input information is not included in configuration management information as at least a part of product management information related to one or more products, generates a prompt for obtaining one or more element levels corresponding to the configuration information and inputs the prompt into a generation model; an authenticity evaluation unit that, when one or more element labels are extracted from the output data of the generative model, calculates the reliability of each of the one or more element labels; an information updating unit that, when the extracted one or more element labels include one or more highly reliable labels, adds a dataset including the one or more highly reliable labels and the extracted configuration information as an authentic dataset to the configuration management information; Equipped with The configuration information is information representing a product configuration, which is at least one of a product name and a model number, The high-reliability label is an element label whose reliability satisfies a condition, Each authenticity data set included in the configuration management information is a data set including one or more high-reliability labels and configuration information corresponding to the one or more high-reliability labels. Information construction device.

2. when the extracted one or more element labels have one or more low-reliability labels, the information updating unit adds a data set including the one or more low-reliability labels and the extracted configuration information to temporary management information as a temporary data set; The low-reliability label is an element label whose reliability does not satisfy a condition, Each temporary data set included in the temporary management information is a data set including one or more low-reliability labels and configuration information corresponding to the one or more low-reliability labels. The information construction device according to claim 1 .

3. the information update unit performs a similarity determination as to whether a target temporary dataset, which is a temporary dataset that matches or is similar to an extracted dataset including the extracted one or more element labels and the extracted configuration information, is the temporary management information; If the result of the similarity determination is true, the information update unit deletes, from the target temporary dataset, low-reliability labels that match or are similar to any of the one or more high-reliability labels to be added to the configuration management information among the one or more extracted element labels.

3. The information construction device according to claim 2.

4. the configuration information in the target temporary dataset matches the configuration information in the extracted dataset; 4. The information construction device according to claim 3.

5. Each temporary data set included in the temporary management information includes a calculated reliability for each element label included in the temporary data set.

4. The information construction device according to claim 3.

6. the information updating unit, for each element label in the extracted dataset, updates the reliability in the target temporary dataset to the calculated reliability when the calculated reliability of the element label is higher than the reliability of an element label in the target temporary dataset that matches or is similar to the element label; 6. The information construction device according to claim 5.

7. the information update unit performs a similarity determination as to whether a target temporary dataset, which is a temporary dataset that matches or is similar to an extracted dataset including the extracted plurality of element labels and the extracted configuration information, is the temporary management information; when the result of the similarity determination is false and the extracted plurality of element labels have one or more low-reliability labels, regardless of whether the extracted element labels have one or more high-reliability labels, the information update unit adds a data set including the extracted plurality of element labels and the extracted configuration information to the temporary management information as the temporary data set; When the result of the similarity determination is true, the target temporary dataset contains one or more element labels whose reliability levels contained in the target temporary dataset do not satisfy a condition, and for each of the one or more element labels, the reliability levels calculated for element labels in the extracted dataset that match or are similar to the element labels satisfy the condition, the information update unit adds the extracted dataset and / or the target temporary dataset to the configuration management information.

7. The information construction device according to claim 6.

8. Each element label is a configuration information label, which is a label of a category to which the product configuration belongs, or a vendor name, which is a vendor of the product. The information construction device according to claim 1 .

9. The product management information is a Software Bill of Materials (SBOM).

9. The information construction device according to claim 8.

10. the authenticity evaluation unit calculates a reliability of at least one of the extracted one or more element labels on a rule basis; The information construction device according to claim 1 .

11. the authenticity evaluation unit identifies, for at least one of the extracted one or more element labels, which one or more evaluation rules among a plurality of evaluation rules each associated with a point have been satisfied, and calculates a reliability based on the points corresponding to each of the one or more evaluation rules that have been satisfied; The information construction device according to claim 1 .

12. the information updating unit, when the extracted one or more element labels include one or more low-reliability labels, adds a data set including the one or more low-reliability labels and the extracted configuration information to temporary management information as a temporary data set; The low-reliability label is an element label whose reliability does not satisfy a condition, each temporary data set included in the temporary management information is a data set including one or more low-reliability labels and configuration information corresponding to the one or more low-reliability labels; when it is determined from the temporary management information that a low reliability of a certain element label is maintained, the information update unit updates an evaluation rule related to the certain element label. The information construction device according to claim 1 .

13. the prompt generation unit generates a prompt for obtaining a low-confidence label for the configuration information in a temporary data set when the temporary data set includes the extracted configuration information and the temporary data set is included in the temporary management information.

4. The information construction device according to claim 3.

14. Acquire information whose authenticity is guaranteed as input information, If the configuration information extracted from the input information is not included in configuration management information as at least a part of product management information related to one or more products, generating a prompt for obtaining one or more element levels corresponding to the configuration information and inputting the prompt into a generative model; When one or more element labels are extracted from the output data of the generative model, a reliability of each of the one or more element labels is calculated; If the extracted one or more element labels have one or more high-reliability labels, add a dataset including the one or more high-reliability labels and the extracted configuration information as an authentic dataset to the configuration management information. This is done by computer, The configuration information is information representing a product configuration, which is at least one of a product name and a model number, The high-reliability label is an element label whose reliability satisfies a condition, Each authenticity data set included in the configuration management information is a data set including one or more high-reliability labels and configuration information corresponding to the one or more high-reliability labels. How to build information.

15. Acquire information whose authenticity is guaranteed as input information, If the configuration information extracted from the input information is not included in configuration management information as at least a part of product management information related to one or more products, generating a prompt for obtaining one or more element levels corresponding to the configuration information and inputting the prompt into a generative model; When one or more element labels are extracted from the output data of the generative model, a reliability of each of the one or more element labels is calculated; If the extracted one or more element labels have one or more high-reliability labels, add a dataset including the one or more high-reliability labels and the extracted configuration information as an authentic dataset to the configuration management information. Let the computer do that, The configuration information is information representing a product configuration, which is at least one of a product name and a model number, The high-reliability label is an element label whose reliability satisfies a condition, Each authenticity data set included in the configuration management information is a data set including one or more high-reliability labels and configuration information corresponding to the one or more high-reliability labels. Computer program.

Citation Information

Patent Citations

  • Vulnerability management system and program

    JP2020021309A