Vulnerability information notification apparatus, vulnerability information notification system, terminal device, vulnerability information notification method, and program

The vulnerability information notification system automates the process of identifying affected systems by processing vulnerability information, reducing the workload on personnel by only notifying relevant systems, thus simplifying the registration and notification process.

JP2025136008APending Publication Date: 2025-09-19NEC CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024034153
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-03-06
Publication Date
2025-09-19

AI Technical Summary

Technical Problem

Existing systems burden personnel with the need to manually register and narrow down vulnerability information, increasing the workload and complexity.

Method used

A vulnerability information notification system that acquires and processes information about products and modules affected by vulnerabilities, determining which systems are not using these modules, and only notifies relevant systems, thereby reducing the need for manual registration and narrowing down.

Benefits of technology

Reduces the burden on personnel by automating the process of identifying and notifying only systems that are affected by vulnerabilities, simplifying the registration process and minimizing unnecessary notifications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025136008000001_ABST
    Figure 2025136008000001_ABST
Patent Text Reader

Abstract

To relatively reduce the burden on information processing system personnel of registering information used to narrow down vulnerability information to be notified.SOLUTION: A vulnerability information notification apparatus is provided with: vulnerability information processing means for acquiring, from vulnerability information, information indicating a product affected by the vulnerability information and information indicating a module affected by the vulnerability information; and vulnerability information notification means for notifying the vulnerability information to an information processing system determined based on information registered for each information processing system indicating a configuration of the information processing system, information indicating the product affected by the vulnerability information, information indicating modules not used by the information processing system, and information indicating the module affected by the vulnerability information.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a vulnerability information notification device, a vulnerability information notification system, a terminal device, a vulnerability information notification method, and a program. [Background technology]

[0002] A technology has been proposed for notifying users of system vulnerability information. For example, in the vulnerability information distribution system described in Patent Document 1, a user selects keywords that indicate the type of vulnerability information the user needs from among the keywords registered in the keyword template database and registers them in the user profile. When new vulnerability information is registered, the vulnerability information notification unit compares one or more keywords that indicate components related to the vulnerability, which are included in the new vulnerability information, with the keywords registered in the user profile. The vulnerability information notification unit obtains the user's destination information included in the user profile with matching keywords, and notifies the user of the new vulnerability information by referring to the destination information. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2009-15570 Summary of the Invention [Problem to be solved by the invention]

[0004] In order to reduce the burden on personnel in charge of the information processing system, it is conceivable that the device that notifies vulnerability information narrows down the vulnerability information to be notified. In this case, it is preferable that the burden on personnel in charge of registering information used to narrow down the vulnerability information to be notified be as small as possible.

[0005] An example of an object of the present disclosure is to provide a vulnerability information notification device, a vulnerability information notification system, a terminal device, a vulnerability information notification method, and a program that can solve the above-mentioned problems. [Means for solving the problem]

[0006] According to a first aspect of the present disclosure, a vulnerability information notification device includes a vulnerability information processing means that acquires, from vulnerability information, information indicating a product that is the subject of the vulnerability information and information indicating a module that is the subject of the vulnerability information, and a vulnerability information notification means that notifies an information processing system that is determined as the notification target based on information that indicates the configuration of the information processing system, which is registered for each information processing system, information that indicates the product that is the subject of the vulnerability information, information that indicates modules that are not used by the information processing system, and information that indicates the module that is the subject of the vulnerability information.

[0007] According to a second aspect of the present disclosure, a vulnerability information notification system includes a vulnerability information notification device and a terminal device, and the vulnerability information notification device includes a vulnerability information processing means for acquiring, from vulnerability information, information indicating a product that is the subject of the vulnerability information and information indicating a module that is the subject of the vulnerability information, and a communication means for transmitting the vulnerability information to a terminal device that is linked to an information processing system that is determined based on information registered for each information processing system that indicates the configuration of the information processing system, information indicating the product that is the subject of the vulnerability information, and information indicating modules that are not used by the information processing system.

[0008] According to a third aspect of the present disclosure, the terminal device includes a display means for displaying an input screen for information indicating modules not used by the information processing system that is the target of the vulnerability information notification.

[0009] According to a fourth aspect of the present disclosure, a vulnerability information notification method includes a computer acquiring, from vulnerability information, information indicating a product that is the subject of the vulnerability information and information indicating a module that is the subject of the vulnerability information, and notifying an information processing system that is determined as the notification target based on information that is registered for each information processing system and indicates the configuration of the information processing system, information that indicates the product that is the subject of the vulnerability information, information that indicates modules that are not used by the information processing system, and information that indicates the module that is the subject of the vulnerability information.

[0010] According to a fifth aspect of the present disclosure, a program causes a computer to obtain, from vulnerability information, information indicating a product that is the subject of the vulnerability information and information indicating a module that is the subject of the vulnerability information, and notify the vulnerability information to an information processing system that is determined as the notification target based on information indicating the configuration of the information processing system, which is registered for each information processing system, information indicating the product that is the subject of the vulnerability information, information indicating modules that are not used by the information processing system, and information indicating the module that is the subject of the vulnerability information. [Effects of the Invention]

[0011] According to one aspect of the present disclosure, the burden on a person in charge of an information processing system to register information used to narrow down vulnerability information to be notified can be relatively reduced. [Brief explanation of the drawings]

[0012] [Figure 1] 1 is a diagram illustrating an example of the configuration of a vulnerability information notification system according to at least one embodiment. [Figure 2] 1 is a diagram illustrating an example of a configuration of a vulnerability information notification device according to at least one embodiment. [Figure 3] FIG. 2 is a diagram illustrating an example of the configuration of a terminal device according to at least one embodiment. [Figure 4]FIG. 2 is a diagram illustrating an example of a data structure of target product information according to at least one embodiment. [Figure 5] FIG. 2 is a diagram illustrating an example of a data structure of target module information according to at least one embodiment. [Figure 6] FIG. 2 is a diagram illustrating an example of a data structure of system configuration information according to at least one embodiment. [Figure 7] FIG. 10 illustrates an example data structure of unused module information according to at least one embodiment. [Figure 8] FIG. 10 is a diagram showing an example of an input screen for vulnerability information displayed by a second display unit according to at least one embodiment. [Figure 9] FIG. 2 is a diagram illustrating an example of system configuration information according to at least one embodiment. [Figure 10] FIG. 10 illustrates an example of unused module information according to at least one embodiment. [Figure 11] FIG. 10 illustrates an example of updated unused module information according to at least one embodiment. [Figure 12] FIG. 2 is a diagram illustrating an example of a procedure of a process performed by a vulnerability information notification device according to at least one embodiment. [Figure 13] FIG. 10 is a diagram illustrating an example of a procedure of a process performed by a terminal device according to at least one embodiment. [Figure 14] 1 is a diagram illustrating an example of a configuration of a vulnerability information notification device according to at least one embodiment. [Figure 15] 1 is a diagram illustrating an example of the configuration of a vulnerability information notification system according to at least one embodiment. [Figure 16] FIG. 2 is a diagram illustrating an example of the configuration of a terminal device according to at least one embodiment. [Figure 17] FIG. 1 is a diagram illustrating an example of a processing procedure in a vulnerability information notification method according to at least one embodiment. [Figure 18] FIG. 1 illustrates a computer configuration according to at least one embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0013] The following describes embodiments of the present invention, but the following embodiments do not limit the scope of the invention as claimed. Furthermore, not all of the combinations of features described in the embodiments are necessarily essential to the solution of the invention.

[0014] First Embodiment 1 is a diagram illustrating an example of the configuration of a vulnerability information notification system according to at least one embodiment. In the configuration illustrated in FIG. 1, the vulnerability information notification system 1 includes a vulnerability information notification device 100 and a terminal device 200. Furthermore, the terminal device 200 is linked to the information processing system 910. The terminal device 200 may be a part of the information processing system 910. Alternatively, the terminal device 200 may be an external component of the information processing system 910.

[0015] The vulnerability information notification system 1 is a system that notifies vulnerability information related to an information processing system 910. When the vulnerability information notifying device 100 acquires newly registered vulnerability information, it determines for each information processing system 910 whether or not to notify the vulnerability information. The vulnerability information notifying device 100 may be configured using a computer such as a personal computer (PC) or a workstation (WS).

[0016] Specifically, the vulnerability information notifying device 100 determines, for each information processing system 910, whether or not the information processing system 910 includes the product indicated in the vulnerability information. The product in this context is the part of an information processing system that is the target of a vulnerability. The product in this context may be hardware or software, or a combination of hardware and software.

[0017] When it is determined that the information processing system 910 is equipped with the product indicated in the vulnerability information, the vulnerability information notification device 100 determines whether or not the module indicated in the vulnerability information corresponds to a module not used by the information processing system 910. The vulnerability information notification device 100 determines whether or not the module indicated in the vulnerability information corresponds to a module not used by the information processing system 910, based on information registered for each information processing system 910 and indicating modules not used by the information processing system 910.

[0018] The module here refers to a part of the configuration or function of an information processing system. Furthermore, a module not used by the information processing system here refers to a module that the information processing system does not have or that is set to be disabled in the information processing system, whereas a module used by the information processing system refers to a module that the information processing system has and that is set to be enabled.

[0019] If it is determined that the module indicated in the vulnerability information is not a module that is not used by the information processing system, the vulnerability information notifying device 100 determines to notify the vulnerability information. When it is determined to notify the vulnerability information, the vulnerability information notifying device 100 notifies the terminal device 200 associated with the information processing system 910 that is the target of the notification of the vulnerability information. Specifically, the vulnerability information notifying device 100 transmits the vulnerability information to the terminal device 200.

[0020] In this way, the vulnerability information notifying device 100 narrows down the vulnerability information to be notified to the terminal device 200 linked to the information processing system 910 based on information indicating modules not used by the information processing system 910. By having the vulnerability information notification device 100 narrow down the vulnerability information to be notified to the terminal device 200, the frequency with which the person in charge of the information processing system 910 needs to obtain vulnerability information can be reduced, and in this respect, the burden on the person in charge of the information processing system 910 can be reduced. The person in charge of the information processing system 910 here is the person in charge of dealing with vulnerabilities in the information processing system 910. The person in charge of the information processing system 910 is also simply referred to as the person in charge.

[0021] Furthermore, by having the vulnerability information notification device 100 narrow down the vulnerability information to be notified to the terminal device 200 based on information indicating modules not used by the information processing system 910, the burden on the person in charge of registering information used to narrow down the vulnerability information to be notified can be relatively reduced.

[0022] Specifically, if the information processing system 910 is not using the module that is the subject of the vulnerability information received, the person in charge can register information to be used to narrow down the vulnerability information through a relatively simple process of feeding this information back to the vulnerability information notification device 100. Furthermore, the person in charge can receive vulnerability information without having to pre-register information used to narrow down vulnerability information.

[0023] The vulnerability information acquired by the vulnerability information notifying device 100, i.e., the vulnerability information notified by the vulnerability information notifying device 100, is not limited to a specific one. For example, the vulnerability information notifying device 100 may acquire vulnerability information provided by CVE (Common Vulnerabilities and Exposures) or JVN (Japan Vulnerability Notes), but is not limited to these.

[0024] The terminal device 200 is a terminal device in the vulnerability information notification system 1 that is used by a person in charge of the information processing system 910. The terminal device 200 notifies the person in charge of the vulnerability information notified from the vulnerability information notifying device 100. For example, the terminal device 200 may display the vulnerability information transmitted from the vulnerability information notifying device 100.

[0025] The terminal device 200 may be configured using a computer such as a personal computer or a workstation. Furthermore, the terminal device 200 may be configured as a terminal device dedicated to the vulnerability information notification system 1. Alternatively, the terminal device 200 may be configured as a general-purpose device, such as by installing the functions of the terminal device 200 in a general-purpose personal computer used by a person in charge.

[0026] Fig. 2 is a diagram illustrating an example of the configuration of the vulnerability information notification device 100. In the configuration shown in Fig. 2, the vulnerability information notification device 100 includes a first communication unit 110, a first display unit 120, a first operation input unit 130, a first storage unit 180, and a first processing unit 190. The first storage unit 180 includes a target product information storage unit 181, a target module information storage unit 182, a system configuration information storage unit 183, and an unused module information storage unit 184. The first processing unit 190 includes a vulnerability information processing unit 191, a target system identification unit 192, a determination unit 193, a vulnerability information notification processing unit 194, and a vulnerability handling information processing unit 195.

[0027] The first communication unit 110 communicates with other devices. For example, the first communication unit 110 receives new vulnerability information from a device that transmits vulnerability information. The vulnerability information notification device 100 may periodically receive vulnerability information from a server device that provides vulnerability information using the first communication unit 110, and detect new vulnerability information.

[0028] Furthermore, the first communication unit 110 transmits the vulnerability information to the terminal device 200. Furthermore, the first communication unit 110 receives vulnerability handling information from the terminal device 200. The vulnerability handling information is information indicating the handling that has been performed in response to the vulnerability information or information indicating that it has been determined that no handling is necessary. The first communication unit 110 corresponds to an example of a communication means.

[0029] The first display unit 120 has a display screen such as a liquid crystal panel or an LED (Light Emitting Diode) panel, and acquires various images. For example, the first display unit 120 may display various information related to the notification of vulnerability information by the vulnerability information notifying device 100, such as vulnerability information and information indicating the information processing system 910 determined to be the target of the vulnerability information.

[0030] The first operation input unit 130 is configured to include input devices such as a keyboard and a mouse, and accepts user operations. For example, the first operation input unit 130 may accept user operations for making various settings related to the notification of vulnerability information by the vulnerability information notifying device 100, such as a user operation for inputting address information of a destination from which vulnerability information is obtained.

[0031] The first storage unit 180 stores various types of information. The first storage unit 180 may be configured using a storage device included in the vulnerability information notification device 100. The target product information storage unit 181 stores target product information. The target product information is information that indicates the product that is the target of the vulnerability information. The target product information includes identification information that identifies the vulnerability information, the product name of the product that is the target of the vulnerability information, and version information that indicates the version of the product that is the target of the vulnerability information.

[0032] 4 is a diagram showing an example of the data structure of the target product information. In the example of Fig. 4, the target product information has the following columns: "Vulnerability Information ID," "Product Name," "Version," and "Summary." The "vulnerability information ID" column stores identification information for identifying vulnerability information. The "product name" column stores the name of the product that is the subject of the vulnerability information. The "version" column stores version information indicating the version of the product indicated by the product name that is the subject of vulnerability information. The "Summary" column stores a summary of the vulnerability information.

[0033] For example, for vulnerability information identified by vulnerability information ID: CVE-2023-28625, the vulnerability information ID "CVE-2023-28625" is stored in the "Vulnerability Information ID" column. The "Product Name" column and "Version" column store the product name "Apache 2.x HTTP server" and version "2.0.0" to "2.4.13.1" listed in the vulnerability information description. The "Summary" column stores the description of the vulnerability information. Vulnerability information identified by a vulnerability information ID is also referred to as vulnerability information of that vulnerability information ID.

[0034] The target module information storage unit 182 stores target module information. The target module information is information indicating the module that is the target of the vulnerability information. The target module information includes identification information that identifies the vulnerability information and the module name of the module that is the target of the vulnerability information. The target module information can be used as information indicating the correspondence between the product and version and the module.

[0035] Fig. 5 is a diagram showing an example of the data structure of target module information. In the example of Fig. 5, the target module information has the following columns: "Vulnerability Information ID," "Product Name," "Version," and "Module." The "Vulnerability Information ID" field stores identification information that identifies the vulnerability information that is the subject of the target module information. The vulnerability information ID of the target module information can be used as a key to search for the module that is the subject of the vulnerability information, for example, when narrowing down the subjects of vulnerability information notifications.

[0036] The "product name" column stores the name of the product that is the subject of the vulnerability information. The "version" column stores version information indicating the version of the product indicated by the product name that is the subject of vulnerability information. The "Module" column stores the name of the module that is the subject of the vulnerability information.

[0037] For example, in the case of vulnerability information for CVE-2023-28625, the "Product Name" and "Version" columns of the target module information will contain the product name "Apache 2.x HTTP server" and version "2.0.0" to "2.4.13.1" listed in the vulnerability information's description. The "Module" column will contain the module name "mod_auth_openidc" listed in the vulnerability information's description.

[0038] The system configuration information storage unit 183 stores system configuration information. The system configuration information is information that indicates the configuration of the information processing system 910. The system configuration information includes identification information that identifies the information processing system 910, and the product name and version information of the product included in the information processing system 910.

[0039] Fig. 6 is a diagram showing an example of the data structure of system configuration information. In the example of Fig. 6, the system configuration information has the following columns: "System ID," "Server Name," "Product Name," and "Version." The "system ID" column stores identification information (for example, system name) that identifies the information processing system 910. The "server name" field stores the server names given to the servers included in the information processing system 910 by the information processing system 910. The vulnerability information notifying device 100 can uniquely identify the servers included in the information processing system 910 by using a combination of the system ID and the server name. Each server is subject to a determination as to whether it is vulnerable. The "product name" column stores the product name of the server identified by the combination of the system ID and the server name. The "Version" column stores version information indicating the product version of the server identified by the combination of the system ID and server name.

[0040] For example, a person in charge of each information processing system 910 may notify in advance the person in charge of the vulnerability information notifying device 100 of the configuration information of the information processing system 910. Then, the person in charge of the vulnerability information notifying device 100 may register the configuration information of each information processing system 910 in the vulnerability information notifying device 100 as system configuration information.

[0041] The vulnerability information notification device 100 compares the product name and version indicated in the target product information with the product name and version indicated in the system configuration information to determine whether the server identified by the combination of the system ID and server name is the target of the vulnerability information.

[0042] The unused module information storage unit 184 stores unused module information. The unused module information is information indicating modules that are not used by the information processing system 910. The unused module information includes identification information that identifies the information processing system 910 and the module names of modules that are not used by the information processing system 910.

[0043] The unused module information is generated based on vulnerability countermeasure information that is fed back in response to vulnerability information by a person in charge of the information processing system 910. The vulnerability countermeasure information is information indicating the countermeasure taken in response to the vulnerability information or information indicating that no countermeasure is necessary. If the information processing system 910 does not use the module that is the subject of the vulnerability information, no action is required for the vulnerability information. In this case, the person in charge of the information processing system 910 feeds back vulnerability action information indicating the module name indicated in the vulnerability information to the vulnerability information notification device 100 as a reason why no action is required for the vulnerability information. In this case, the module name indicated in the vulnerability information corresponds to the module name of a module that is not used by the information processing system 910.

[0044] The vulnerability information notification device 100, which has acquired the vulnerability handling information, generates unused module information that includes identification information that identifies the information processing system 910 that is the subject of the vulnerability handling information and the name of a module that is indicated as a reason why handling of the vulnerability information is not necessary. The vulnerability information notifying device 100 may use the vulnerability countermeasure information for each information processing system 910 as unused module information for that information processing system 910.

[0045] Fig. 7 is a diagram showing an example of the data structure of unused module information. In the example of Fig. 7, the unused module information has the following columns: "System ID," "Vulnerability Information ID," "Product Name," "Version," and "Reason for Exclusion." The "System ID" column stores identification information (e.g., system name) that identifies the information processing system 910 that is determined not to require action against the vulnerability information (the information processing system 910 used by the sender of the vulnerability action information). The "vulnerability information ID" column stores identification information for identifying vulnerability information that has been determined not to require action. The "Product Name" column stores the product names of servers that are determined not to require action against vulnerability information. The "Version" column stores version information indicating the version of the server for which it has been determined that no action is required to address the vulnerability information. The "Reasons for non-application" column stores the names of modules that are subject to vulnerability information and that are determined not to require action. These modules correspond to the reasons why the person in charge of the information processing system 910 determined that the information processing system 910 is not subject to vulnerability information. In other words, if the person in charge of the information processing system 910 determines that the information processing system 910 that the person in charge is not using the module that is subject to vulnerability information, the person in charge determines that no action is required for the vulnerability information.

[0046] The first processing unit 190 executes various functions by controlling each unit of the vulnerability information notification device 100. The functions of the first processing unit 190 are executed, for example, by a CPU (Central Processing Unit) included in the vulnerability information notification device 100 reading and executing a program from the first storage unit 180.

[0047] The vulnerability information processing unit 191 acquires, from the vulnerability information, information indicating the product that is the target of the vulnerability information and information indicating the module that is the target of the vulnerability information. The vulnerability information processing unit 191 is an example of a vulnerability information processing means. For example, the vulnerability information notifying device 100 may acquire new vulnerability information in the form of text data. Then, the vulnerability information processing unit 191 may analyze the text data to extract the product name and version information of the product that is the subject of the vulnerability information, and the module name of the module that is the subject of the vulnerability information. In this case, the product name and version information are examples of information that indicates the product. The module name is an example of information that indicates the module.

[0048] The vulnerability information processing unit 191 may extract the product name, version information, and module name based on the appearance pattern of these in the vulnerability information. For example, the description of the vulnerability information for CVE-2008-0455 states, "Cross-site scripting (XSS) vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows..."

[0049] In this way, vulnerability information provided by CVE often includes the module name between the string "vulnerability in" and the string "module" (or the string "Module"). Also, the information is often presented in the order of module name, server name, and server version.

[0050] The vulnerability information processing unit 191 may attempt to extract the product name, version information, and module name from the vulnerability information based on the above-described patterns. The vulnerability information processing unit 191 may also attempt to extract the product name, version information, and module name from the vulnerability information using a learning model that has been trained on the appearance patterns of the product name, version information, and module name.

[0051] Alternatively, the vulnerability information processing unit 191 may perform natural language analysis on the vulnerability information to estimate and extract character strings corresponding to the server name, version information, and module name.

[0052] When the reliability of the extracted information is equal to or lower than a predetermined standard, such as when the vulnerability information processing unit 191 extracts multiple server name candidates from one piece of vulnerability information, the vulnerability information processing unit 191 may display the extracted information on the first display unit 120. Then, the person in charge of the vulnerability information notification device 100 may edit the information displayed on the first display unit 120.

[0053] Furthermore, if the vulnerability information processing unit 191 fails to extract the product name, version information, and module name, the vulnerability information may be displayed on the first display unit 120. Then, a person in charge of the vulnerability information notifying device 100 may extract the product name, version information, and module name from the vulnerability information displayed by the first display unit 120.

[0054] The vulnerability information processing unit 191 generates target product information including information indicating the product that is the target of the vulnerability information, which is acquired from the vulnerability information. Then, the vulnerability information processing unit 191 stores the generated target product information in the target product information storage unit 181. Furthermore, the vulnerability information processing unit 191 generates target module information including information indicating the module that is the target of the vulnerability information, which is acquired from the vulnerability information. Then, the vulnerability information processing unit 191 stores the generated target module information in the target module information storage unit 182.

[0055] The target system identifying unit 192 identifies the information processing system 910 that is the target of the vulnerability information. The target system identifying unit 192 corresponds to an example of a target system identifying means. Specifically, the target system identification unit 192 determines whether or not a product included in the information processing system 910, which is indicated in the system configuration information for each information processing system 910, corresponds to a product that is the target of vulnerability information indicated by the target product information. In particular, the target system identification unit 192 determines whether or not the product names are the same, and also based on whether or not the version of the product indicated by the target product information is within the range of versions indicated by the vulnerability information.

[0056] The target system specifying unit 192 may make the determination by directly using the product name and version information extracted from the vulnerability information, instead of the product name and version information indicated in the target product information. If it is determined that the product included in the information processing system 910 corresponds to the product targeted by the vulnerability information, the target system identifying unit 192 identifies the information processing system 910 as the target of the vulnerability information.

[0057] The determining unit 193 narrows down the information processing systems 910 that are the targets of the vulnerability information. The determining unit 193 is an example of a determining means. Specifically, the determination unit 193 determines whether the module that is the subject of the vulnerability information, which is indicated by the target module information, is included in the modules that are not used by the information processing system 910 and which are indicated for each information processing system 910 by the unused module information storage unit 184. The determination unit 193 determines whether the modules are the same based on whether the module names are the same. The determining unit 193 may make a determination by directly using the module name extracted from the vulnerability information instead of the module name indicated by the target module information.

[0058] If it is determined that the module that is the subject of the vulnerability information is not included in the modules that are not used by the information processing system 910, the determination unit 193 sets the information processing system 910 as a target for notification of the vulnerability information. On the other hand, if it is determined that the module that is the subject of the vulnerability information is included in the modules that are not used by the information processing system 910, the determination unit 193 excludes the information processing system 910 from the targets for notification of the vulnerability information. The narrowing down of the information processing systems 910 that are the targets of vulnerability information, performed by the determining unit 193, can also be considered as narrowing down of the vulnerability information that is the target of notification regarding the information processing systems 910.

[0059] The vulnerability information notification processing unit 194 notifies the information processing system 910 of the vulnerability information that has been determined to be a notification target of the vulnerability information by the determination unit 193. The vulnerability information notification processing unit 194 is an example of a vulnerability information notification means. Specifically, the vulnerability information notification processing unit 194 controls the first communication unit 110 to send the vulnerability information to the terminal device 200 linked to the information processing system 910 that the determination unit 193 has determined to be the target of the vulnerability information.

[0060] The vulnerability information notifying device 100 may integrally determine the target of vulnerability information based on the product name and version information, and the target of vulnerability based on the module name. For example, the function of the target system identification unit 192 may be configured as part of the function of the determination unit 193. Then, the determination unit 193 may determine, for each information processing system 910, that the information processing system 910 to be notified of vulnerability information is one in which the product name and version of the server correspond to the product name and version that are the target of the vulnerability information and in which the module names indicated in the unused module information do not include the module name that is the target of the vulnerability information.

[0061] The vulnerability countermeasure information processing unit 195 generates unused module information based on the vulnerability countermeasure information from the terminal device 200. Specifically, the terminal device 200 generates vulnerability handling information indicating the module name indicated in the vulnerability information as a factor for why handling of the vulnerability information is unnecessary, in accordance with a user operation by a person in charge of the information processing system 910. At this time, the terminal device 200 generates vulnerability handling information including identification information for identifying the information processing system 910 linked to the terminal device 200. In this case, the information processing system 910 linked to the terminal device 200 corresponds to the information processing system 910 that is the target of the vulnerability information. The terminal device 200 transmits the generated vulnerability handling information to the vulnerability information notification device 100.

[0062] The vulnerability countermeasure information processing unit 195 reads out identification information for identifying the information processing system 910 and the module name indicated in the cause of no action being required from the vulnerability countermeasure information transmitted from the terminal device 200. Then, the vulnerability countermeasure information processing unit 195 generates unused module information that includes the read identification information and module name. The vulnerability handling information processing unit 195 stores the generated unused module information in the unused module information storage unit 184.

[0063] Fig. 3 is a diagram showing an example of the configuration of the terminal device 200. In the configuration shown in Fig. 3, the terminal device 200 includes a second communication unit 210, a second display unit 220, a second operation input unit 230, a second storage unit 280, and a second processing unit 290. The second processing unit 290 includes a vulnerability information display control unit 291, a vulnerability address information generation unit 292, and a vulnerability address information transmission processing unit 293.

[0064] The second communication unit 210 communicates with other devices. For example, the second communication unit 210 receives vulnerability information transmitted by the vulnerability information notification device 100. The second communication unit 210 also transmits the vulnerability address information generated by the vulnerability address information generation unit 292 to the vulnerability information notification device 100 under the control of the vulnerability address information transmission processing unit.

[0065] The second display unit 220 has a display screen such as a liquid crystal panel or an LED panel, and acquires various images. For example, the second display unit 220 displays vulnerability information transmitted from the vulnerability information notifying device 100. The second display unit 220 also displays an input screen for vulnerability handling information. The second display unit 220 corresponds to an example of a display means.

[0066] The second operation input unit 230 is configured to include input devices such as a keyboard and a mouse, and accepts user operations. For example, the second operation input unit 230 accepts a user operation to input vulnerability handling information while the second display unit 220 is displaying an input screen for vulnerability handling information.

[0067] The second storage unit 280 stores various types of information. The second storage unit 280 may be configured using a storage device included in the terminal device 200. The second processing unit 290 executes various functions by controlling each unit of the terminal device 200. The functions of the second processing unit 290 are executed, for example, by the CPU included in the terminal device 200 reading and executing a program from the second storage unit 280.

[0068] The vulnerability information display control unit 291 notifies the user of the information processing system 910 of the vulnerability information transmitted from the vulnerability information notifying device 100. Specifically, the vulnerability information display control unit 291 controls the second display unit 220 to display the vulnerability information.

[0069] The vulnerability address information generation unit 292 generates vulnerability address information. Specifically, the vulnerability address information generation unit 292 controls the second display unit 220 to display an input screen for vulnerability address information. Then, while the second display unit 220 is displaying the input screen for vulnerability address information, the vulnerability address information generation unit 292 generates vulnerability address information in accordance with user operations received by the second operation input unit 230.

[0070] Fig. 8 is a diagram showing an example of an input screen for vulnerability information displayed by the second display unit 220. Fig. 8 shows an example of a screen displayed when a person in charge of the information processing system 910 determines that no action is required for the vulnerability information. For example, when the person in charge of the information processing system 910 determines that no action is required for the vulnerability information, the person in charge performs a user operation to display the input screen shown in Fig. 8 on the second display unit 220 in order to generate vulnerability target information.

[0071] 8, the vulnerability information input screen has display fields for "System Name," "Vulnerability Information ID," "Product Name," and "Version," as well as an input field for "Excluded Configuration or Function." The vulnerability information input screen also displays a Send button and a Cancel button.

[0072] The "Vulnerability Information ID" column displays the identification information of the vulnerability information being addressed. The "System Name," "Product Name," and "Version" display columns display the system name of the information processing system 910 that is the target of the vulnerability information being addressed, and the product names and versions of the servers that the system is equipped with. If the information processing system 910 that is the target of the vulnerability information being addressed has multiple servers, the product name and version of the server that is the target of the vulnerability information among those multiple servers are displayed in the "Product Name" column and the "Version" column.

[0073] For example, the vulnerability information notifying device 100 may include this information in the vulnerability information and transmit it. Then, the vulnerability handling information generating unit 292 may extract information to be displayed in the "System Name," "Vulnerability Information ID," "Product Name," and "Version" columns from the vulnerability information notifying device 100.

[0074] The name of the configuration or function that is the reason why it was determined that no action is required in response to the vulnerability information is entered in the input field for "Configuration or function not targeted." Specifically, if the information processing system 910 does not use a module that is targeted in the vulnerability information, the person in charge of the information processing system 910 enters the name of that module in the input field for "Configuration or function not targeted."

[0075] The vulnerability information notification device 100 may also include information about the module names of modules targeted by the vulnerability information in the vulnerability information and transmit the information. The vulnerability handling information generation unit 292 may then extract the module names from the vulnerability information of the vulnerability information notification device 100 and control the second display unit 220 to display the module names in the "Configuration or function as not targeted" column.

[0076] Alternatively, if the person in charge of the information processing system 910 is unsure of the module name that should be entered in the "Configuration or function to be excluded from the target" field, the person in charge may enter the reason for determining that the vulnerability information is excluded in natural language. In this case, the person in charge of the vulnerability information notifying device 100 may refer to the vulnerability countermeasure information, determine the corresponding module name, and update the vulnerability countermeasure information.

[0077] The send button is a button used by the person in charge of the information processing system 910 to instruct the transmission of vulnerability handling information. When the person in charge of the information processing system 910 has completed inputting information into the "Configuration or function to be excluded" field, or when the person in charge of the information processing system 910 has determined that there is no problem with the module name displayed in the "Configuration or function to be excluded" field, the person in charge presses the send button, for example, by clicking the mouse.

[0078] The cancel button is pressed by the person in charge of the information processing system 910 when he or she wishes to cancel the transmission of vulnerability response information. When the cancel button is pressed, the second display unit 220 terminates the display of the vulnerability response information input screen exemplified in Fig. 8 and displays the original screen (the screen that was displayed before the vulnerability response information input screen was displayed).

[0079] The vulnerability handling information transmission processor 293 controls the second communication unit 210 to transmit the vulnerability handling information to the vulnerability information notification device 100 . For example, when the send button is pressed on the vulnerability handling information input screen illustrated in FIG. 8, the vulnerability handling information transmission processing unit 293 controls the second communication unit 210 to transmit vulnerability handling information indicating the information displayed on the screen to the vulnerability information notification device 100.

[0080] The processing performed by the vulnerability information notification system 1 will be further explained using an example. Fig. 9 is a diagram showing an example of system configuration information. In the example of Fig. 9, the system configuration information indicates that System A has one server named Server A, and that the product name and version of that server is Apache HTTP Server version 2.4.0.

[0081] Fig. 10 is a diagram showing an example of unused module information. In the example of Fig. 10, the unused module information indicates that for the server of System A, the module names of the modules for which no action is required in response to vulnerability information are mod_negotiation and mod_auth_openidc.

[0082] Now, consider a case where the vulnerability information notification device 100 acquires new vulnerability information when the system configuration information is as shown in Fig. 9 and the unused module information is as shown in Fig. 10. Assume that the product name of the server targeted by the new vulnerability information acquired by the vulnerability information notification device 100 is Apache HTTP Server, and the version is between 2.4.0 and 2.4.55. Also assume that the module targeted by the new vulnerability information has the name of mod_proxy.

[0083] In this case, for system A, the product name of server A shown in the system configuration information is the same as the product name that is the target of the vulnerability information, and the version is within the range of versions that are the target of the vulnerability information. Therefore, target system identification unit 192 determines that system A is the target of the newly obtained vulnerability information.

[0084] Next, the determination unit 193 narrows down the information processing systems 910 that are targets of the vulnerability information. For system A, the module name indicated in the new vulnerability information is not included in the module names indicated in the unused module information. Therefore, the determination unit 193 sets system A as a target for notification of the new vulnerability information. The vulnerability information notification processing unit 194 controls the first communication unit 110 in accordance with the determination of the determination unit 193 to transmit new vulnerability information to the terminal device 200 used by the person in charge of system A.

[0085] Here, it is assumed that the module mod_proxy is set to be unused in system A. In this case, the terminal device 200, in accordance with the operation of the person in charge of system A, transmits vulnerability handling information indicating the module name mod_proxy as an "excluded configuration or function" to the vulnerability information notifying device 100.

[0086] In the vulnerability information notification device 100 that receives the vulnerability handling information, the vulnerability handling information processing unit 195 registers (adds) the module name mod_proxy indicated in the vulnerability handling information to the unused module information as the module name of a module not used by system A. As a result, the unused module information will look like that shown in FIG.

[0087] Fig. 11 is a diagram showing an example of unused module information after updating. In the example of Fig. 11, the unused module information indicates that for the server of System A, the names of the modules for which no action is required in response to vulnerability information are mod_negotiation, mod_auth_openidc, and mod_proxy.

[0088] Let us consider a case where the vulnerability information notifying device 100 subsequently acquires new vulnerability information that has the same target product name, version, and module name as the previously acquired vulnerability information. That is, the product name of the server targeted by the new vulnerability information is Apache HTTP Server, and the version is 2.4.0 to 2.4.55. Furthermore, the module name of the module targeted by the new vulnerability information is mod_proxy.

[0089] In this case, the target system identifying unit 192 determines that the system A is subject to the newly obtained vulnerability information. On the other hand, for System A, the module name indicated in the new vulnerability information is included in the module names indicated in the unused module information. Therefore, the determination unit 193 excludes System A from the targets for notification of new vulnerability information. The vulnerability handling information processing unit 195 does not transmit the vulnerability information acquired this time to the terminal device 200 used by the person in charge of system A.

[0090] Fig. 12 is a diagram showing an example of a procedure of processing performed by the vulnerability information notifying device 100. The vulnerability information notifying device 100 performs the processing of Fig. 12, for example, every time new vulnerability information is acquired.

[0091] (Step S101) The vulnerability information processing unit 191 acquires information indicating the product name and version of the vulnerability information from the vulnerability information. The information indicating the product name and version of the vulnerability information is also referred to as product identification information. After step S101, the process proceeds to step S102.

[0092] (Step S102) The vulnerability information processing unit 191 acquires information indicating the name of the module that is the target of the vulnerability information from the vulnerability information. The information indicating the name of the module that is the target of the vulnerability information is also referred to as module identification information. After step S102, the process proceeds to step S103.

[0093] (Step S111) The first processing unit 190 starts a loop L11 in which it performs processing for each information processing system 910 whose system configuration information is registered. The information processing system 910 that is the processing target in the loop L11 is also referred to as the processing target system. After step S111, the process proceeds to step S112.

[0094] (Step S112) The target system identifying unit 192 acquires system configuration information of the processing target system. In particular, the target system identifying unit 192 reads the product name and version information of the server included in the processing target system from the system configuration information stored in the system configuration information storage unit 183. After step S112, the process proceeds to step S113.

[0095] (Step S113) The target system identification unit 192 determines whether or not a server included in the processing target system corresponds to a target of vulnerability information. Specifically, the target system identification unit 192 determines whether or not the product name and version read from the system configuration information for the server included in the processing target system correspond to a target of vulnerability information.

[0096] If the target system identifying unit 192 determines that the server included in the processing target system corresponds to the target of the vulnerability information (step S113: YES), the process proceeds to step S121. On the other hand, if the target system identifying unit 192 determines that the server included in the processing target system is not subject to the vulnerability information (step S113: NO), the process proceeds to step S134.

[0097] (Step S121) The determination unit 193 acquires unused module information of the processing target system. In particular, the determination unit 193 reads out the module names of modules that are unused in the processing target system from the unused module information stored in the unused module information storage unit 184. After step S121, the process proceeds to step S122.

[0098] (Step S122) The determination unit 193 determines whether the module that is the subject of the vulnerability information corresponds to a module that is unused in the processing target system. Specifically, the determination unit 193 determines whether the module name indicated in the vulnerability information is included in the modules read from the unused module information.

[0099] If the determining unit 193 determines that the module targeted by the vulnerability information is a module that is not in use in the processing target system (step S122: YES), the process proceeds to step S134. On the other hand, if the determining unit 193 determines that the module targeted by the vulnerability information does not correspond to a module unused in the processing target system (step S122: NO), the process proceeds to step S131.

[0100] (Step S131) The vulnerability information notification processing unit 194 notifies the processing target system of vulnerability information. Specifically, the vulnerability information notification processing unit 194 controls the first communication unit 110 to transmit the vulnerability information to the terminal device 200 linked to the processing target system. After step S131, the process proceeds to step S132.

[0101] (Step S132) The vulnerability handling information processing unit 195 waits for vulnerability handling information from the terminal device 200 linked to the processing target system. When the first communication unit 11 receives vulnerability handling information from the terminal device 200 linked to the processing target system, the vulnerability handling information processing unit 195 acquires the vulnerability handling information. After step S132, the process proceeds to step S133.

[0102] (Step S133) The vulnerability countermeasure information processing unit 195 updates the unused module information. Specifically, the vulnerability countermeasure information processing unit 195 registers (adds) to the unused module information the module name indicated as the "excluded configuration or function" in the vulnerability countermeasure information as the module name of the module unused in the processing target system. After step S133, the process proceeds to step S134.

[0103] (Step S134) The first processing unit 190 performs a termination process of the loop L11. Specifically, the first processing unit 190 determines whether or not the process of the loop L11 has been performed for all the information processing systems 910 whose system configuration information is registered. When it is determined that there is an information processing system 910 that has not yet performed the processing of the loop L11, the first processing unit 190 continues to perform the processing of the loop L11 for the unprocessed information processing system 910. On the other hand, if it is determined that the processing of loop L11 has been performed for all information processing systems 910 whose system configuration information is registered, the first processing unit 190 ends loop L11. In this case, the vulnerability information notifying device 100 ends the processing of FIG.

[0104] The vulnerability information processing unit 191 may integrally perform the process of step S101 and the process of step S102. For example, when the vulnerability information processing unit 191 performs a syntax analysis of the vulnerability information, the vulnerability information processing unit 191 may identify the server name, version information, and module name included in the vulnerability information in one syntax analysis and extract this information.

[0105] The first processing unit 190 may execute the processing of the loop L11 in parallel. In addition, after the first processing unit 190 makes the judgment in step S113 for all information processing systems 910 for which system configuration information is registered, it may perform the processing in step S121 and subsequent steps for the information processing systems 910 for which the judgment in step S113 is YES.

[0106] 13 is a diagram showing an example of a procedure of processing performed by the terminal device 200. The terminal device 200 performs the processing of FIG. (Step S201) The second display unit 220 displays the vulnerability information. Specifically, the vulnerability information display control unit 291 controls the second display unit 220 to display the vulnerability information from the vulnerability information notifying device 100. After step S201, the process proceeds to step S202.

[0107] (Step S202) The second display unit 220 displays an input screen for vulnerability handling information. Specifically, the vulnerability information display control unit 291 controls the second display unit 220 to display the input screen for vulnerability handling information in accordance with a user operation that instructs the display of the input screen for vulnerability handling information. After step S202, the process proceeds to step S203.

[0108] (Step S203) The vulnerability countermeasure information generation unit 292 generates vulnerability countermeasure information in accordance with user operations on the vulnerability countermeasure information input screen. After step S203, the process proceeds to step S204.

[0109] (Step S204) The second communication unit 210 transmits the vulnerability address information. Specifically, the vulnerability address information transmission processing unit 293 controls the second communication unit 210 to transmit the vulnerability address information generated by the vulnerability address information generation unit 292 to the vulnerability information notification device 100. After step S204, the terminal device 200 ends the processing of FIG.

[0110] As described above, the vulnerability information processing unit 191 obtains, from the vulnerability information, information indicating the product that is the target of the vulnerability information and information indicating the module that is the target of the vulnerability information. The vulnerability information notification processing unit 194 notifies vulnerability information to an information processing system 910 determined as the notification target based on information registered for each information processing system 910 indicating the configuration of the information processing system 910, information indicating the product that is the subject of the vulnerability information, information indicating modules that are not used by the information processing system 910, and information indicating the modules that are the subject of the vulnerability information.

[0111] In this way, the vulnerability information notifying device 100 narrows down the vulnerability information to be notified based on information indicating modules that are not used by the information processing system 910. In this respect, the vulnerability information notifying device 100 can relatively reduce the burden on the person in charge of the information processing system 910 of registering information used to narrow down the vulnerability information to be notified.

[0112] For example, if the information processing system 910 is not using the module that is the subject of the vulnerability information received, the person in charge can register information to be used to narrow down the vulnerability information through the relatively simple process of registering that fact. Furthermore, the person in charge of the information processing system 910 can receive vulnerability information without having to pre-register information used to narrow down vulnerability information.

[0113] In addition, the target system identification unit 192 identifies the information processing system 910 that is the target of the vulnerability information based on information indicating the configuration of the information processing system 910, which is registered for each information processing system 910, and information indicating the product that is the target of the vulnerability information. The determination unit 193 determines whether the module that is the subject of the vulnerability information corresponds to a module that is not used by the identified information processing system 910, based on information registered for each information processing system 910 indicating the module that is not used by that information processing system 910 and information indicating the module that is the subject of the vulnerability information. If the vulnerability information notification processing unit 194 determines that the module that is the subject of the vulnerability information is not a module that is not used by the identified information processing system 910, it notifies the information processing system 910 of the vulnerability information.

[0114] In the vulnerability information notification device 100, the determination unit 193 only acquires information indicating modules not used by the information processing system 910 that the target system identification unit 192 has identified as the target of the vulnerability information, and determines whether the module that is the target of the vulnerability information is a module not used by the identified information processing system 910.

[0115] In this regard, the vulnerability information notifying device 100 can reduce the number of times information indicating modules not used by the information processing system 910 is acquired and the number of times it is determined whether a module that is the subject of vulnerability information is a module not used by the identified information processing system 910. For example, when it takes time to acquire information indicating modules not used by the information processing system 910, the vulnerability information notifying device 100 can make the processing time relatively short.

[0116] In addition, the information registered for each information processing system 910 indicating modules not used by that information processing system is generated based on information indicating that the information processing system 910 that was the subject of the vulnerability information notification is not using the module that was the subject of the vulnerability information.

[0117] According to the vulnerability information notifying device 100, if the information processing system 910 does not use a module that is the subject of received vulnerability information, the person in charge of the information processing system 910 can register information to be used for narrowing down vulnerability information by a relatively simple process of registering that fact. In this respect, the vulnerability information notifying device 100 can relatively reduce the burden on the person in charge of the information processing system 910 of registering information to be used for narrowing down vulnerability information to be notified.

[0118] Furthermore, information indicating that the information processing system 910 that is the target of the vulnerability information notification is not using the module that is the target of the vulnerability information is indicated in the feedback information in response to the vulnerability information notification. According to the vulnerability information notifying device 100, when a person in charge of the information processing system 910 receives vulnerability information, if the module that is the subject of the vulnerability information is not being used by the information processing system 910, the person in charge can register information to be used to narrow down the vulnerability information through a relatively simple process of providing feedback to that effect. In this respect, the vulnerability information notifying device 100 can relatively reduce the burden on the person in charge of the information processing system 910 of registering information to be used to narrow down the vulnerability information to be notified.

[0119] In addition, the information indicating that the information processing system 910 that was the subject of the vulnerability information notification is not using the module that was the subject of the vulnerability information is information indicating the name of the module that is not used by the information processing system. The vulnerability information processing unit 191 obtains the name of the module that is the target of the vulnerability information from the vulnerability information. The determination unit 193 determines whether the information processing system is the target of the vulnerability information based on whether the name of the module that is the target of the vulnerability information corresponds to the name of a module that is not used by the information processing system.

[0120] According to the vulnerability information notifying device 100, the determining unit 193 can determine whether the information processing system 910 is a target of the vulnerability information by a relatively simple process of determining whether the name of the module that is the target of the vulnerability information is the same as the name of a module that is not used by the information processing system 910. In this respect, according to the vulnerability information notifying device 100, the load on the determining unit 193 can be relatively lightened.

[0121] Furthermore, according to the vulnerability information notification device 100, the person in charge of the vulnerability information notification device 100 can register information to be used to narrow down the vulnerability information through a relatively simple process in which the information processing system 910 feeds back the module names indicated in the vulnerability information as the module names of modules that are not used by the information processing system 910. In this respect, the vulnerability information notification device 100 can relatively reduce the burden on the person in charge of the information processing system 910 of registering information to be used to narrow down the vulnerability information to be notified.

[0122] The information indicating the product that is the subject of the vulnerability information is information indicating the name of the product and the version of the product that is the subject of the vulnerability information. The target system identification unit 192 identifies the information processing system 910 that is the target of the vulnerability information based on information registered for each information processing system 910 indicating the name and version of the product that the information processing system 910 is equipped with.

[0123] According to the vulnerability information notification device 100, the target system identification unit 192 can identify the information processing system 910 that is the target of the vulnerability information by a relatively simple process of determining whether the name and version of a product included in the information processing system 910 correspond to the name and version of the product that is the target of the vulnerability information. In this respect, according to the vulnerability information notification device 100, the load on the target system identification unit 192 can be relatively lightened.

[0124] Furthermore, the vulnerability information processing unit 191 reads out the name and version of the product described in the vulnerability information as the name and version of the product that is the subject of the vulnerability information. According to the vulnerability information notifying device 100, the vulnerability information processing unit 191 directly reads the name of the product that is the subject of the vulnerability information and the version of that product from the vulnerability information, so there is no need to prepare other information.

[0125] The second display unit 220 also displays an input screen for information indicating modules that are not used by the information processing system that is the target of the vulnerability information notification. According to the terminal device 200, the person in charge of the information processing system 910 can input information indicating modules that are not being used by the information processing system 910 by operating the input screen. In this respect, according to the terminal device 200, the burden on the person in charge of the information processing system 910 to input information indicating modules that are not being used by the information processing system 910 is relatively small.

[0126] Second Embodiment 14 is a diagram illustrating an example of the configuration of a vulnerability information notification device according to at least one embodiment. A vulnerability information notification device 610 in the configuration illustrated in FIG. 14 includes a vulnerability information processing unit 611 and a vulnerability information notification unit 612.

[0127] With this configuration, the vulnerability information processing unit 611 obtains, from the vulnerability information, information indicating the product that is the target of the vulnerability information and information indicating the module that is the target of the vulnerability information. The vulnerability information notification unit 612 notifies the vulnerability information to an information processing system that is determined based on information registered for each information processing system, indicating the configuration of the information processing system, information indicating the product that is the target of the vulnerability information, information indicating modules not used by the information processing system, and information indicating the module that is the target of the vulnerability information. The vulnerability information processing unit 611 is an example of a vulnerability information processing means, and the vulnerability information notification unit 612 is an example of a vulnerability information notification means.

[0128] In this way, the vulnerability information notifying device 610 narrows down the vulnerability information to be notified based on information indicating modules that are not used by the information processing system. In this respect, the vulnerability information notifying device 610 can relatively reduce the burden on the person in charge of the information processing system of registering information used to narrow down the vulnerability information to be notified.

[0129] For example, if an information processing system staff member does not use a module that is the subject of vulnerability information received, the person in charge can register information that will be used to narrow down vulnerability information by the relatively simple process of registering that fact. Furthermore, the person in charge of the information processing system can receive vulnerability information without having to pre-register information used to narrow down vulnerability information.

[0130] Third Embodiment Fig. 15 is a diagram illustrating an example of the configuration of a vulnerability information notification system according to at least one embodiment. In the configuration illustrated in Fig. 15, a vulnerability information notification system 620 includes a vulnerability information notification device 621 and a terminal device 624. The vulnerability information notification device 621 includes a vulnerability information processing unit 622 and a communication unit 623.

[0131] With this configuration, the vulnerability information processing unit 622 acquires, from the vulnerability information, information indicating the product that is the target of the vulnerability information and information indicating the module that is the target of the vulnerability information. The communication unit 623 transmits the vulnerability information to a terminal device 624 that is linked to an information processing system that is determined based on information registered for each information processing system that indicates the configuration of the information processing system, information indicating the product that is the target of the vulnerability information, and information indicating modules that are not used by the information processing system.

[0132] In this way, the vulnerability information notifying device 621 narrows down the vulnerability information to be notified based on information indicating modules that are not used by the information processing system. In this respect, the vulnerability information notifying system 620 can relatively reduce the burden on the person in charge of the information processing system of registering information used to narrow down the vulnerability information to be notified.

[0133] For example, if an information processing system staff member does not use a module that is the subject of vulnerability information received, the person in charge can register information that will be used to narrow down vulnerability information by the relatively simple process of registering that fact. Furthermore, the person in charge of the information processing system can receive vulnerability information without having to pre-register information used to narrow down vulnerability information.

[0134] <Fourth embodiment> 16 is a diagram illustrating an example of the configuration of a terminal device according to at least one embodiment. In the configuration illustrated in FIG. With this configuration, the display unit 631 displays an input screen for information indicating modules not in use by the information processing system that is the target of the vulnerability information notification. The display unit 631 is an example of a display means.

[0135] With the terminal device 630, the person in charge of the information processing system can input information indicating modules not used by the information processing system by operating the input screen. In this respect, with the terminal device 630, the burden on the person in charge of the information processing system to input information indicating modules not used by the information processing system is relatively small.

[0136] Fifth Embodiment 17 is a diagram showing an example of a processing procedure in a vulnerability information notification method according to at least one embodiment. The vulnerability information notification method shown in FIG. 17 includes acquiring information (step S611) and notifying vulnerability information (step S612).

[0137] In acquiring information (step S611), the computer acquires, from the vulnerability information, information indicating the product that is the target of the vulnerability information and information indicating the module that is the target of the vulnerability information. In notifying vulnerability information (step S612), the computer notifies vulnerability information to an information processing system determined based on information registered for each information processing system indicating the configuration of the information processing system, information indicating the product that is the subject of the vulnerability information, information indicating modules not used by the information processing system, and information indicating the module that is the subject of the vulnerability information.

[0138] In this way, the vulnerability information notification method shown in Fig. 17 narrows down the vulnerability information to be notified based on information indicating modules that are not used by the information processing system. In this respect, the vulnerability information notification method shown in Fig. 17 can relatively reduce the burden on the person in charge of the information processing system of registering information used to narrow down the vulnerability information to be notified.

[0139] For example, if an information processing system staff member does not use a module that is the subject of vulnerability information received, the person in charge can register information that will be used to narrow down vulnerability information by the relatively simple process of registering that fact. Furthermore, the person in charge of the information processing system can receive vulnerability information without having to pre-register information used to narrow down vulnerability information.

[0140] FIG. 18 is a diagram illustrating a computer configuration according to at least one embodiment. In the configuration shown in FIG. 18, a computer 700 includes a CPU 710, a main memory device 720, an auxiliary memory device 730, an interface 740, and a non-volatile recording medium 750.

[0141] One or more of the vulnerability information notification device 100, the terminal device 200, the vulnerability information notification device 610, the vulnerability information notification device 621, the terminal device 624, and the terminal device 630, or a part thereof, may be implemented in the computer 700. In this case, the operation of each of the above-described processing units is stored in the auxiliary storage device 730 in the form of a program. The CPU 710 reads the program from the auxiliary storage device 730, loads it into the main storage device 720, and executes the above-described processing in accordance with the program. The CPU 710 also allocates storage areas in the main storage device 720 corresponding to each of the above-described storage units in accordance with the program. Communication between each device and other devices is performed by an interface 740 having a communication function and performing communication under the control of the CPU 710. The interface 740 also has a port for a nonvolatile recording medium 750, and reads information from the nonvolatile recording medium 750 and writes information to the nonvolatile recording medium 750.

[0142] When the vulnerability information notifying device 100 is implemented in a computer 700, the operations of the first processing unit 190 and each of its units are stored in the form of a program in an auxiliary storage device 730. The CPU 710 reads the program from the auxiliary storage device 730, loads it into the main storage device 720, and executes the above-described processing in accordance with the program.

[0143] Furthermore, the CPU 710 allocates a storage area for the first storage unit 180 in the main storage device 720 in accordance with the program. Communication with other devices by the first communication unit 110 is performed by the interface 740 having a communication function and operating under the control of the CPU 710. Display of images by the first display unit 120 is performed by the interface 740 having a display device and displaying various images under the control of the CPU 710. Reception of a user operation by the first operation input unit 130 is performed by the interface 740 having an input device and receiving the user operation under the control of the CPU 710.

[0144] When the terminal device 200 is implemented in the computer 700, the operations of the second processing unit 290 and each of its units are stored in the form of a program in the auxiliary storage device 730. The CPU 710 reads the program from the auxiliary storage device 730, loads it into the main storage device 720, and executes the above-described processing in accordance with the program.

[0145] Furthermore, the CPU 710 allocates a storage area for the second storage unit 280 in the main storage device 720 in accordance with the program. Communication with other devices by the second communication unit 210 is performed by the interface 740 having a communication function and operating under the control of the CPU 710. Display of images by the second display unit 220 is performed by the interface 740 having a display device and displaying various images under the control of the CPU 710. Reception of a user operation by the second operation input unit 230 is performed by the interface 740 having an input device and receiving the user operation under the control of the CPU 710.

[0146] When the vulnerability information notification device 610 is implemented in the computer 700, the operations of the vulnerability information processing unit 611 and the vulnerability information notification unit 612 are stored in the form of a program in the auxiliary storage device 730. The CPU 710 reads the program from the auxiliary storage device 730, loads it into the main storage device 720, and executes the above-mentioned processing in accordance with the program.

[0147] Furthermore, the CPU 710, in accordance with the program, allocates a storage area in the main storage device 720 for the vulnerability information notification device 610 to perform processing. Communication between the vulnerability information notification device 610 and other devices is performed by an interface 740 having a communication function and operating under the control of the CPU 710. Interaction between the vulnerability information notification device 610 and a user is performed by the interface 740 having an input device and an output device, presenting information to the user via the output device under the control of the CPU 710, and accepting user operations via the input device.

[0148] When the vulnerability information notification device 621 is implemented in the computer 700, the operation of the vulnerability information processing unit 622 is stored in the form of a program in the auxiliary storage device 730. The CPU 710 reads the program from the auxiliary storage device 730, loads it into the main storage device 720, and executes the above-mentioned processing in accordance with the program.

[0149] Furthermore, the CPU 710, in accordance with the program, allocates a storage area in the main storage device 720 for the vulnerability information notification device 621 to perform processing. Communication between the communication unit 623 and other devices is performed by an interface 740 having a communication function and operating under the control of the CPU 710. Interaction between the vulnerability information notification device 621 and a user is performed by the interface 740 having an input device and an output device, presenting information to the user via the output device under the control of the CPU 710, and accepting user operations via the input device.

[0150] When the terminal device 624 is implemented in the computer 700, its operation is stored in the form of a program in the auxiliary storage device 730. The CPU 710 reads the program from the auxiliary storage device 730, loads it into the main storage device 720, and executes the above-described processing in accordance with the program.

[0151] Furthermore, the CPU 710 allocates a storage area in the main memory device 720 for the terminal device 624 to perform processing in accordance with the program. Communication between the terminal device 624 and other devices is performed by the interface 740, which has a communication function and operates under the control of the CPU 710. Interaction between the terminal device 624 and a user is performed by the interface 740, which has an input device and an output device, presenting information to the user via the output device under the control of the CPU 710 and accepting user operations via the input device.

[0152] When the terminal device 630 is implemented in the computer 700, its operation is stored in the form of a program in the auxiliary storage device 730. The CPU 710 reads the program from the auxiliary storage device 730, loads it into the main storage device 720, and executes the above-described processing in accordance with the program.

[0153] Furthermore, the CPU 710 allocates a storage area in the main memory device 720 for the terminal device 630 to perform processing in accordance with the program. Communication between the terminal device 630 and other devices is performed by the interface 740, which has a communication function and operates under the control of the CPU 710. Interaction between the terminal device 630 and a user, such as displaying an image on the display unit 631, is performed by the interface 740, which has an input device and an output device, presenting information to the user via the output device under the control of the CPU 710 and accepting user operations via the input device.

[0154] One or more of the above-described programs may be recorded on nonvolatile recording medium 750. In this case, interface 740 may read the programs from nonvolatile recording medium 750. CPU 710 may then directly execute the programs read by interface 740, or may temporarily store the programs in main storage device 720 or auxiliary storage device 730 and then execute them.

[0155] Note that a program for executing all or part of the processing performed by the vulnerability information notification device 100, the terminal device 200, the vulnerability information notification device 610, the vulnerability information notification device 621, the terminal device 624, and the terminal device 630 may be recorded on a computer-readable recording medium, and the program recorded on this recording medium may be read into a computer system and executed to perform the processing of each part. Note that the term "computer system" here includes an OS (Operating System) and hardware such as peripheral devices. Furthermore, "computer-readable recording media" refers to portable media such as flexible disks, optical magnetic disks, ROMs (Read Only Memory), and CD-ROMs (Compact Disc Read Only Memory), as well as storage devices such as hard disks built into computer systems. The program may be one that realizes part of the aforementioned functions, or may be one that can realize the aforementioned functions in combination with a program already stored in the computer system.

[0156] Although the embodiments of the present invention have been described in detail above with reference to the drawings, the specific configuration is not limited to these embodiments and includes designs that do not deviate from the gist of the present invention. Furthermore, the above-described embodiments can be combined with other embodiments as appropriate.

[0157] Some or all of the above embodiments can be described as, but are not limited to, the following supplementary notes.

[0158] (Appendix 1) a vulnerability information processing means for acquiring, from the vulnerability information, information indicating a product that is the target of the vulnerability information and information indicating a module that is the target of the vulnerability information; a vulnerability information notifying means for notifying the vulnerability information to an information processing system determined as a notification target based on information registered for each information processing system indicating the configuration of the information processing system, information indicating the product that is the target of the vulnerability information, information indicating modules not used by the information processing system, and information indicating the module that is the target of the vulnerability information; A vulnerability information notification device comprising:

[0159] (Appendix 2) a target system identification means for identifying an information processing system that is the target of the vulnerability information based on information indicating the configuration of the information processing system and information indicating the product that is the target of the vulnerability information, which are registered for each of the information processing systems; a determining means for determining whether or not a module that is the subject of the vulnerability information corresponds to a module that is not used by a specified information processing system, based on information that is registered for each information processing system and indicates a module that is not used by the information processing system and information that indicates a module that is the subject of the vulnerability information; Equipped with When it is determined that the module that is the subject of the vulnerability information is not a module that is not used by the identified information processing system, the vulnerability information notifying means notifies the identified information processing system of the vulnerability information. 2. A vulnerability information notification device according to claim 1.

[0160] (Appendix 3) The information registered for each information processing system and indicating modules not used by that information processing system is generated based on information indicating that the information processing system that is the target of the vulnerability information notification does not use the module that is the target of the vulnerability information. 3. A vulnerability information notification device according to claim 2.

[0161] (Appendix 4) The information indicating that the information processing system that is the target of the vulnerability information notification does not use the module that is the target of the vulnerability information is indicated in feedback information in response to the vulnerability information notification. 4. A vulnerability information notification device according to claim 3.

[0162] (Appendix 5) the information indicating that the information processing system that has been notified of the vulnerability information does not use the module that is the subject of the vulnerability information is information indicating the name of the module that is not used by the information processing system; The vulnerability information processing means acquires, from the vulnerability information, the name of a module that is the target of the vulnerability information; the determining means determines whether the information processing system is a target of the vulnerability information based on whether the name of the module that is the target of the vulnerability information corresponds to the name of a module that is not used by the information processing system; 5. A vulnerability information notification device according to claim 4.

[0163] (Appendix 6) The information indicating the product that is the subject of the vulnerability information is information indicating the name of the product and the version of the product that is the subject of the vulnerability information, the target system identification means identifies the information processing system that is the target of the vulnerability information based on information registered for each information processing system and indicating the name and version of a product that the information processing system is equipped with; 6. A vulnerability information notification device according to any one of appendices 2 to 5.

[0164] (Appendix 7) the vulnerability information processing means reads out the name and version of the product described in the vulnerability information as the name and version of the product that is the subject of the vulnerability information; 7. A vulnerability information notification device according to claim 6.

[0165] (Appendix 8) A vulnerability information notification device and a terminal device are provided, the vulnerability information notification device, a vulnerability information processing means for acquiring, from the vulnerability information, information indicating a product that is the target of the vulnerability information and information indicating a module that is the target of the vulnerability information; a communication means for transmitting the vulnerability information to a terminal device linked to an information processing system determined based on information registered for each information processing system indicating the configuration of the information processing system, information indicating a product that is the target of the vulnerability information, and information indicating a module that is not used by the information processing system; A vulnerability information notification system.

[0166] (Appendix 9) a target system identification means for identifying an information processing system that is the target of the vulnerability information based on information indicating the configuration of the information processing system and information indicating the product that is the target of the vulnerability information, which are registered for each of the information processing systems; a determining means for determining whether or not a module that is the subject of the vulnerability information corresponds to a module that is not used by a specified information processing system, based on information that is registered for each information processing system and indicates a module that is not used by the information processing system and information that indicates a module that is the subject of the vulnerability information; Equipped with When it is determined that the module that is the subject of the vulnerability information is not a module that is not used by the identified information processing system, the communication means notifies the identified information processing system of the vulnerability information. The vulnerability information notification system described in Appendix 8.

[0167] (Appendix 10) The information registered for each information processing system and indicating modules not used by that information processing system is generated based on information indicating that the information processing system that is the target of the vulnerability information notification does not use the module that is the target of the vulnerability information. The vulnerability information notification system described in Appendix 9.

[0168] (Appendix 11) The information indicating that the information processing system that is the target of the vulnerability information notification does not use the module that is the target of the vulnerability information is indicated in feedback information in response to the vulnerability information notification. The vulnerability information notification system described in Appendix 10.

[0169] (Appendix 12) the information indicating that the information processing system that has been notified of the vulnerability information does not use the module that is the subject of the vulnerability information is information indicating the name of the module that is not used by the information processing system; The vulnerability information processing means acquires, from the vulnerability information, the name of a module that is the target of the vulnerability information; the determining means determines whether the information processing system is a target of the vulnerability information based on whether the name of the module that is the target of the vulnerability information corresponds to the name of a module that is not used by the information processing system; The vulnerability information notification system described in Appendix 11.

[0170] (Appendix 13) The information indicating the product that is the subject of the vulnerability information is information indicating the name of the product and the version of the product that is the subject of the vulnerability information, the target system identification means identifies the information processing system that is the target of the vulnerability information based on information registered for each information processing system and indicating the name and version of a product that the information processing system is equipped with; 13. A vulnerability information notification system according to any one of appendices 9 to 12.

[0171] (Appendix 14) the vulnerability information processing means reads out the name and version of the product described in the vulnerability information as the name and version of the product that is the subject of the vulnerability information; The vulnerability information notification system described in Appendix 13.

[0172] (Appendix 15) A display means for displaying an input screen for information indicating modules not in use by the information processing system that is the target of the vulnerability information notification. A terminal device comprising:

[0173] (Appendix 16) The computer From the vulnerability information, information indicating the product that is the target of the vulnerability information and information indicating the module that is the target of the vulnerability information are obtained; notifying the vulnerability information to an information processing system determined as a notification target based on information registered for each information processing system indicating the configuration of the information processing system, information indicating the product that is the target of the vulnerability information, information indicating modules not used by the information processing system, and information indicating the module that is the target of the vulnerability information; A vulnerability information notification method including:

[0174] (Appendix 17) Identifying the information processing system that is the target of the vulnerability information based on information indicating the configuration of the information processing system and information indicating the product that is the target of the vulnerability information, which are registered for each of the information processing systems; determining whether or not the module that is the subject of the vulnerability information corresponds to a module that is not used by the identified information processing system, based on information that is registered for each information processing system and that indicates a module that is not used by the information processing system and information that indicates a module that is the subject of the vulnerability information; This includes: notifying the vulnerability information includes, when the computer determines that the module that is the subject of the vulnerability information is not a module that is not used by the identified information processing system, notifying the identified information processing system of the vulnerability information, The vulnerability information notification method described in Appendix 16.

[0175] (Appendix 18) The information registered for each information processing system and indicating modules not used by that information processing system is generated based on information indicating that the information processing system that is the target of the vulnerability information notification does not use the module that is the target of the vulnerability information. The vulnerability information notification method described in Appendix 17.

[0176] (Appendix 19) The information indicating that the information processing system that is the target of the vulnerability information notification does not use the module that is the target of the vulnerability information is indicated in feedback information in response to the vulnerability information notification. The vulnerability information notification method described in Appendix 18.

[0177] (Appendix 20) the information indicating that the information processing system that has been notified of the vulnerability information does not use the module that is the subject of the vulnerability information is information indicating the name of the module that is not used by the information processing system; obtaining the information includes obtaining, by the computer, from the vulnerability information, a name of a module that is the target of the vulnerability information; The determining step includes determining, by the computer, whether or not the information processing system is subject to the vulnerability information based on whether or not a name of a module that is the subject of the vulnerability information corresponds to a name of a module that is not used by the information processing system. The vulnerability information notification method described in Appendix 19.

[0178] (Appendix 21) The information indicating the product that is the subject of the vulnerability information is information indicating the name of the product and the version of the product that is the subject of the vulnerability information, Identifying the information processing system includes the computer identifying the information processing system that is the target of the vulnerability information based on information registered for each information processing system and indicating the name and version of a product that the information processing system is equipped with. 21. A vulnerability information notification method according to any one of appendices 17 to 20.

[0179] (Appendix 22) Obtaining the information includes reading, by the computer, the name and version of the product described in the vulnerability information as the name and version of the product that is the subject of the vulnerability information; The vulnerability information notification method described in Appendix 21.

[0180] (Appendix 23) On the computer, acquiring, from the vulnerability information, information indicating a product that is the target of the vulnerability information and information indicating a module that is the target of the vulnerability information; notifying the vulnerability information to an information processing system determined as a notification target based on information registered for each information processing system indicating the configuration of the information processing system, information indicating the product that is the target of the vulnerability information, information indicating a module not used by the information processing system, and information indicating the module that is the target of the vulnerability information; A program that executes the following.

[0181] (Appendix 24) The computer, Identifying the information processing system that is the target of the vulnerability information based on information indicating the configuration of the information processing system and information indicating the product that is the target of the vulnerability information, which are registered for each of the information processing systems; determining whether or not the module that is the target of the vulnerability information corresponds to a module that is not used by the identified information processing system, based on information that is registered for each information processing system and that indicates a module that is not used by the information processing system and information that indicates a module that is the target of the vulnerability information; Execute In notifying the vulnerability information, when it is determined that the module that is the subject of the vulnerability information is not a module that is not used by the identified information processing system, the computer is caused to notify the identified information processing system of the vulnerability information. 23. The program described in Appendix 23.

[0182] (Appendix 25) The information registered for each information processing system and indicating modules not used by that information processing system is generated based on information indicating that the information processing system that is the target of the vulnerability information notification does not use the module that is the target of the vulnerability information. 2. The program described in Appendix 24.

[0183] (Appendix 26) The information indicating that the information processing system that is the target of the vulnerability information notification does not use the module that is the target of the vulnerability information is indicated in feedback information in response to the vulnerability information notification. 2. The program described in Appendix 25.

[0184] (Appendix 27) the information indicating that the information processing system that has been notified of the vulnerability information does not use the module that is the subject of the vulnerability information is information indicating the name of the module that is not used by the information processing system; The acquiring of the information includes causing the computer to acquire, from the vulnerability information, a name of a module that is the target of the vulnerability information; In the determining, the computer is caused to determine whether the information processing system is a target of the vulnerability information based on whether the name of the module that is a target of the vulnerability information corresponds to the name of a module that is not used by the information processing system. 26. The program described in Appendix 26.

[0185] (Appendix 28) The information indicating the product that is the subject of the vulnerability information is information indicating the name of the product and the version of the product that is the subject of the vulnerability information, In identifying the information processing system, the computer is caused to execute a process of identifying the information processing system that is the target of the vulnerability information, based on information registered for each information processing system and indicating the name and version of a product that the information processing system is equipped with. 28. The program of any one of appendices 24 to 27.

[0186] (Appendix 29) By acquiring the information, the computer is caused to read out the name and version of the product described in the vulnerability information as the name and version of the product that is the subject of the vulnerability information; 28. The program described in Appendix 28. [Explanation of symbols]

[0187] 1. Vulnerability Information Notification System 100 Vulnerability information notification device 110 First Communications Department 120 First display section 130 First operation input unit 180 First memory section 181 Target product information storage unit 182 Target module information storage unit 183 System configuration information storage unit 184 Unused module information storage unit 190 First Processing Section 191 Vulnerability Information Processing Unit 192 Target System Identification Department 193 Judgment Department 194 Vulnerability Information Notification Processing Unit 195 Vulnerability Handling Information Processing Unit 200 Terminal Device 210 Second Communications Department 220 Second display section 230 Second operation input unit 280 Second memory section 290 Second Processing Section 291 Vulnerability information display control section 292 Vulnerability handling information generation unit 293 Vulnerability handling information transmission processing unit 910 Information Processing Systems

Claims

1. a vulnerability information processing means for acquiring, from the vulnerability information, information indicating a product that is the target of the vulnerability information and information indicating a module that is the target of the vulnerability information; a vulnerability information notifying means for notifying the vulnerability information to an information processing system determined as a notification target based on information registered for each information processing system indicating the configuration of the information processing system, information indicating the product that is the target of the vulnerability information, information indicating modules not used by the information processing system, and information indicating the module that is the target of the vulnerability information; A vulnerability information notification device comprising:

2. a target system identification means for identifying an information processing system that is the target of the vulnerability information based on information indicating the configuration of the information processing system and information indicating the product that is the target of the vulnerability information, which are registered for each of the information processing systems; a determining means for determining whether or not a module that is the subject of the vulnerability information corresponds to a module that is not used by a specified information processing system, based on information that is registered for each information processing system and indicates a module that is not used by the information processing system and information that indicates a module that is the subject of the vulnerability information; Equipped with When it is determined that the module that is the subject of the vulnerability information is not a module that is not used by the identified information processing system, the vulnerability information notifying means notifies the identified information processing system of the vulnerability information. The vulnerability information notification device according to claim 1 .

3. The information registered for each information processing system and indicating modules not used by that information processing system is generated based on information indicating that the information processing system that is the target of the vulnerability information notification does not use the module that is the target of the vulnerability information. The vulnerability information notification device according to claim 2 .

4. The information indicating that the information processing system that is the target of the vulnerability information notification does not use the module that is the target of the vulnerability information is indicated in feedback information in response to the vulnerability information notification. The vulnerability information notification device according to claim 3 .

5. the information indicating that the information processing system that has been notified of the vulnerability information does not use the module that is the subject of the vulnerability information is information indicating the name of the module that is not used by the information processing system; The vulnerability information processing means acquires, from the vulnerability information, the name of a module that is the target of the vulnerability information; the determining means determines whether the information processing system is a target of the vulnerability information based on whether the name of the module that is the target of the vulnerability information corresponds to the name of a module that is not used by the information processing system; The vulnerability information notification device according to claim 4.

6. The information indicating the product that is the subject of the vulnerability information is information indicating the name of the product and the version of the product that is the subject of the vulnerability information, the target system identification means identifies the information processing system that is the target of the vulnerability information based on information registered for each information processing system and indicating the name and version of a product that the information processing system is equipped with; The vulnerability information notifying device according to claim 2 .

7. the vulnerability information processing means reads out the name and version of the product described in the vulnerability information as the name and version of the product that is the subject of the vulnerability information; The vulnerability information notification device according to claim 6.

8. A vulnerability information notification device and a terminal device are provided, the vulnerability information notification device, a vulnerability information processing means for acquiring, from the vulnerability information, information indicating a product that is the target of the vulnerability information and information indicating a module that is the target of the vulnerability information; a communication means for transmitting the vulnerability information to a terminal device linked to an information processing system determined based on information registered for each information processing system indicating the configuration of the information processing system, information indicating a product that is the target of the vulnerability information, and information indicating a module that is not used by the information processing system; A vulnerability information notification system.

9. A display means for displaying an input screen for information indicating modules not in use by the information processing system that is the target of the vulnerability information notification. A terminal device comprising:

10. The computer From the vulnerability information, information indicating the product that is the target of the vulnerability information and information indicating the module that is the target of the vulnerability information are obtained; notifying the vulnerability information to an information processing system determined as a notification target based on information registered for each information processing system indicating the configuration of the information processing system, information indicating the product that is the target of the vulnerability information, information indicating modules not used by the information processing system, and information indicating the module that is the target of the vulnerability information; A vulnerability information notification method including:

11. On the computer, acquiring, from the vulnerability information, information indicating a product that is the target of the vulnerability information and information indicating a module that is the target of the vulnerability information; notifying the vulnerability information to an information processing system determined as a notification target based on information registered for each information processing system indicating the configuration of the information processing system, information indicating the product that is the target of the vulnerability information, information indicating a module not used by the information processing system, and information indicating the module that is the target of the vulnerability information; A program that executes the following.

Citation Information

Patent Citations

  • System and method for distributing vulnerability information

    JP2009015570A