Evaluation support system, evaluation support method, and program

The evaluation support system addresses the issue of incomplete device evaluations by linking threat and vulnerability analysis with evaluation specifications, ensuring comprehensive and accurate assessments through coordinated analysis and redefined specifications.

JP2025141764AActive Publication Date: 2025-09-29PANASONIC AUTOMOTIVE SYST CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2024157078
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-03-13
Filing Date
2024-09-11
Publication Date
2025-09-29
Estimated Expiration
2044-09-11

AI Technical Summary

Technical Problem

Existing risk assessment and countermeasure planning systems fail to effectively support the evaluation of devices by not coordinating threat analysis, vulnerability analysis, and security testing, leading to the possibility of incomplete evaluations.

Method used

An evaluation support system that includes a threat linking unit to link threat analysis information with evaluation specifications, a vulnerability linking unit to link vulnerability analysis information with evaluation specifications, and a redefinition unit to generate updated evaluation specifications based on these linkages, ensuring comprehensive evaluation.

Benefits of technology

The system enhances the completeness and accuracy of device evaluations by linking threat and vulnerability analysis results with evaluation specifications, reducing the likelihood of incomplete assessments and enabling effective risk management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025141764000001_ABST
    Figure 2025141764000001_ABST
Patent Text Reader

Abstract

To provide an evaluation support system that can effectively support the evaluation of an evaluation target device.SOLUTION: An evaluation support system 10 includes: a threat linking section 11 that performs first cooperative processing for linking at least part of threat analysis information d21 indicating an analysis result of a threat to information security of an evaluation target device 40 with first evaluation specification information d31 indicating one or more evaluation specifications of the evaluation target device 40; a vulnerability linking section 12 that performs second cooperative processing for linking at least part of vulnerability analysis information d22 indicating an analysis result of vulnerability to information security of the evaluation target device 40 with the first evaluation specification information d31; and a re-defining section 13 that generates and outputs second evaluation specification information d13 by re-defining, on the basis of the first cooperative processing and the second cooperative processing, the one or more evaluation specifications indicated by the first evaluation specification information d31.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to an evaluation support system that supports the evaluation of a device to be evaluated. [Background technology]

[0002] For example, Patent Document 1 discloses a risk assessment countermeasure planning system as an evaluation support system. This risk assessment countermeasure planning system plans countermeasures against attacks on the system to be evaluated and plans security tests. Note that planning security tests can also be considered as defining evaluation specifications. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] International Publication No. 2020 / 202934 Summary of the Invention [Problem to be solved by the invention]

[0004] However, the risk assessment and countermeasure planning system of Patent Document 1 has a problem in that it cannot effectively support the assessment of the equipment to be assessed.

[0005] Therefore, the present disclosure provides an evaluation support system that can effectively support the evaluation of a device to be evaluated. [Means for solving the problem]

[0006] An evaluation support system according to one embodiment of the present disclosure is an evaluation support system that supports the evaluation of a device to be evaluated, and includes: a threat linking unit that performs a first linking process to link at least a portion of threat analysis information indicating analysis results of information security threats in the device to be evaluated to first evaluation specification information indicating one or more evaluation specifications for the device to be evaluated; a vulnerability linking unit that performs a second linking process to link at least a portion of vulnerability analysis information indicating analysis results of information security vulnerabilities in the device to be evaluated to the first evaluation specification information; and a redefinition unit that generates and outputs second evaluation specification information by redefining one or more evaluation specifications indicated in the first evaluation specification information based on the first linking process and the second linking process.

[0007] The comprehensive or specific aspects may be realized as an apparatus, a method, an integrated circuit, a computer program, or a computer-readable recording medium such as a CD-ROM, or may be realized as any combination of the apparatus, the method, the integrated circuit, the computer program, and the recording medium. The recording medium may also be a non-transitory recording medium. [Effects of the Invention]

[0008] The evaluation support system of the present disclosure can effectively support the evaluation of a device to be evaluated.

[0009] Further advantages and effects of one aspect of the present disclosure will become apparent from the specification and drawings. Such advantages and / or effects are provided by the configurations described in the embodiments and the specification and drawings, but not all of the configurations are necessarily required. [Brief explanation of the drawings]

[0010] [Figure 1] FIG. 1 is a diagram showing an example of the configuration of a development system according to the first embodiment. [Figure 2] FIG. 2 is a diagram for exemplifying a part of the threat analysis performed by the threat analysis unit in the first embodiment. [Figure 3]FIG. 3 is a diagram showing a schematic example of threat analysis information generated and output by the threat analysis unit according to the first embodiment. [Figure 4] FIG. 4 is a diagram showing a schematic example of vulnerability analysis information generated and output by the vulnerability analysis unit according to the first embodiment. [Figure 5] FIG. 5 is a diagram showing a schematic example of first evaluation specification information generated and output by the evaluation specification definition unit according to the first embodiment. [Figure 6] FIG. 6 is a diagram for explaining the processing operation of the evaluation support system according to the first embodiment. [Figure 7] FIG. 7 is a diagram showing an example of evaluated specification information according to the first embodiment. [Figure 8] FIG. 8 is a diagram showing a specific example of threat analysis information according to the first embodiment. [Figure 9] FIG. 9 is a diagram showing a specific example of vulnerability analysis information according to the first embodiment. [Figure 10] FIG. 10 is a diagram showing a specific example of the second evaluation specification information according to the first embodiment. [Figure 11] FIG. 11 is a diagram showing a specific example of a part of the evaluated specification information according to the first embodiment. [Figure 12] FIG. 12 is a sequence diagram showing an example of the processing operation of the development system according to the first embodiment. [Figure 13] FIG. 13 is a flowchart showing an example of the processing operation of the evaluation support system according to the first embodiment. [Figure 14] FIG. 14 is a diagram illustrating an example of the configuration of a development system according to the second embodiment. [Figure 15] FIG. 15 is a diagram illustrating an example of the configuration of a development system according to the third embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0011] (Findings that formed the basis of this disclosure) The present inventors have found that the risk assessment and countermeasure planning system of Patent Document 1 described in the "Background Art" section has the following problems.

[0012] The risk assessment and countermeasure planning system in Patent Document 1 does not coordinate threat analysis, vulnerability analysis, and security testing, which are performed as security measures in product development. Therefore, there is a problem that the evaluation of the evaluation target device that will become a product may not be performed appropriately. For example, there is a possibility that necessary evaluation may not be performed.

[0013] Therefore, an evaluation support system according to a first aspect of the present disclosure is an evaluation support system that supports the evaluation of a device to be evaluated, and includes: a threat linking unit that performs a first linking process to link at least a portion of threat analysis information indicating analysis results of information security threats in the device to be evaluated to first evaluation specification information indicating one or more evaluation specifications for the device to be evaluated; a vulnerability linking unit that performs a second linking process to link at least a portion of vulnerability analysis information indicating analysis results of information security vulnerabilities in the device to be evaluated to the first evaluation specification information; and a redefinition unit that generates and outputs second evaluation specification information by redefining one or more evaluation specifications indicated in the first evaluation specification information based on the first linking process and the second linking process.

[0014] As a result, through the first linkage process, the second linkage process, and the redefinition, one or more evaluation specifications included in the second evaluation specification information are linked to the threat analysis information and the vulnerability analysis information. In other words, while conventionally, the security evaluation of the evaluation target device, the threat analysis, and the vulnerability analysis are not linked, in the first aspect, they are linked. As a result, it is possible to increase the possibility that necessary evaluations will be suppressed and that the evaluation of the evaluation target device can be performed comprehensively. In other words, it is possible to reduce the possibility that the security evaluation of the evaluation target device will be incomplete. Therefore, it is possible to effectively support the evaluation of the evaluation target device.

[0015] In the evaluation support system according to the second aspect, the first evaluation specification information may indicate, for each evaluation item, an evaluation specification corresponding to the evaluation item, and the threat linking unit may perform the first linking process by linking the information to the first evaluation specification information so that, for each evaluation item in the first evaluation specification information, information indicating countermeasures against the threats as analysis results corresponding to the evaluation item, which is included in the threat analysis information, is associated with the evaluation specification for the evaluation item. Note that the second aspect may be subordinate to the first aspect.

[0016] As a result, the countermeasures against the threats are associated with the evaluation specifications through the first cooperation process, and therefore, in evaluations based on the first evaluation specification information that has undergone the first cooperation process, the countermeasures can be used as a reference, thereby more effectively supporting the evaluation of the device to be evaluated.

[0017] In the evaluation support system according to a third aspect, the first evaluation specification information may indicate, for each evaluation item, an evaluation specification corresponding to the evaluation item, and the vulnerability linking unit may perform the second linking process by linking, for each evaluation item in the first evaluation specification information, the vulnerability identification information, which is an analysis result corresponding to the evaluation item and is included in the vulnerability analysis information, to the first evaluation specification information so that the identification information is associated with the evaluation specification for the evaluation item. Note that the third aspect may be subordinate to the first or second aspect.

[0018] As a result, the vulnerability identification information is associated with the evaluation specification by the second linkage process, and therefore, in an evaluation according to the second evaluation specification information that has undergone the second linkage process, the vulnerability can be used as a reference, thereby more effectively supporting the evaluation of the device to be evaluated.

[0019] In addition, in the evaluation support system according to a fourth aspect, when the vulnerability analysis information contains identification information of a vulnerability corresponding to a missing evaluation specification, which is an evaluation specification not indicated in the first evaluation specification information, the redefinition unit may redefine one or more evaluation specifications indicated in the first evaluation specification information by adding the missing evaluation specification and the identification information of the vulnerability corresponding to the missing evaluation specification to the first evaluation specification information after the first cooperation process and the second cooperation process. Note that the fourth aspect may be subordinate to the third aspect.

[0020] As a result, the first evaluation specification information is updated to the second evaluation specification information including the missing evaluation specification and the vulnerability identification information by the redefinition, thereby preventing the omission of necessary evaluations and enabling comprehensive evaluation of the evaluation target device.

[0021] In addition, the evaluation support system according to a fifth aspect may further include a feedback unit that feeds back the second evaluation specification information, which indicates an evaluation result of the evaluation target device obtained by evaluation in accordance with the second evaluation specification information, to a threat analysis unit and a vulnerability analysis unit as evaluated specification information, wherein the threat analysis unit generates the threat analysis information by performing a threat analysis on the evaluation target device, and the vulnerability analysis unit generates the vulnerability analysis information by performing a vulnerability analysis on the evaluation target device. Note that the fifth aspect may be subordinate to any one of the first to fourth aspects.

[0022] As a result, the evaluated specification information is fed back to the threat analysis unit and the vulnerability analysis unit. Therefore, if the evaluated specification information indicates a good evaluation result for the evaluated specification, the threat analysis unit can guarantee the analysis result for the threat. For example, if the analysis result is a countermeasure against the threat, the effectiveness of the countermeasure can be guaranteed. On the other hand, if the evaluated specification information indicates a bad evaluation result for the evaluated specification, the threat analysis unit can improve the threat analysis. For example, if the analysis result is a countermeasure against the threat, the countermeasure can be improved. As a result, the accuracy of countermeasure planning can be improved. Furthermore, the vulnerability analysis unit can improve the accuracy of vulnerability analysis based on the evaluation result indicated in the evaluated specification information. In other words, in the fifth aspect, the process is not only one-way from threat analysis and vulnerability analysis to evaluation, but also feedback of the evaluation result to threat analysis and vulnerability analysis, thereby enabling effective risk management of the device to be evaluated.

[0023] An evaluation support system according to a sixth aspect of the present disclosure is an evaluation support system that supports the evaluation of a device to be evaluated, and includes: a threat linking unit that performs a first linking process to link at least a portion of threat analysis information that indicates an analysis result of information security threats in the device to be evaluated to first evaluation specification information that indicates one or more evaluation specifications for the device to be evaluated; and a redefinition unit that generates and outputs second evaluation specification information by redefining one or more evaluation specifications indicated in the first evaluation specification information based on the first linking process.

[0024] This makes it possible to achieve the same effects as the evaluation support system according to the first aspect with respect to threats to the device to be evaluated.

[0025] In addition, in the evaluation support system according to a seventh aspect, the first evaluation specification information may indicate, for each evaluation item, an evaluation specification corresponding to the evaluation item, and the threat linking unit may perform the first linking process by linking the information to the first evaluation specification information so that, for each evaluation item in the first evaluation specification information, information indicating countermeasures against the threats as analysis results corresponding to the evaluation item is associated with the evaluation specification for the evaluation item. Note that the seventh aspect may be dependent on the sixth aspect.

[0026] This makes it possible to achieve the same effects as those of the evaluation support system according to the second aspect.

[0027] In addition, in the evaluation support system according to an eighth aspect, if the threat analysis information contains information indicating measures against the threat corresponding to a missing evaluation specification, which is an evaluation specification not included in the first evaluation specification information, the redefinition unit may redefine one or more evaluation specifications indicated in the first evaluation specification information by adding the missing evaluation specification and the information indicating the measures against the threat corresponding to the missing evaluation specification to the first evaluation specification information after the first collaboration process. Note that the eighth aspect may be dependent on the sixth or seventh aspect.

[0028] As a result, the first evaluation specification information is updated to the second evaluation specification information including the missing evaluation specification and the information indicating the countermeasures against the threats through the redefinition, thereby preventing the omission of necessary evaluations and enabling the evaluation of the evaluation target device to be performed comprehensively.

[0029] In addition, the evaluation support system according to a ninth aspect may further include a feedback unit that feeds back the second evaluation specification information, which indicates an evaluation result of the evaluation target device obtained by evaluation in accordance with the second evaluation specification information, to a threat analysis unit as evaluated specification information, and the threat analysis unit may generate the threat analysis information by performing a threat analysis on the evaluation target device. Note that the ninth aspect may be subordinate to any one of the sixth to eighth aspects.

[0030] This makes it possible to achieve the same effects as the evaluation support system according to the fifth aspect with respect to threats to the device to be evaluated.

[0031] An evaluation support system according to a tenth aspect of the present disclosure is an evaluation support system that supports the evaluation of a device to be evaluated, and includes: a vulnerability linking unit that performs a second linking process to link at least a portion of vulnerability analysis information that indicates an analysis result of information security vulnerabilities in the device to be evaluated to first evaluation specification information that indicates one or more evaluation specifications for the device to be evaluated; and a redefinition unit that generates and outputs second evaluation specification information by redefining one or more evaluation specifications indicated in the first evaluation specification information based on the second linking process.

[0032] This makes it possible to achieve the same effects as the evaluation support system according to the first aspect with respect to vulnerabilities of the device to be evaluated.

[0033] In an eleventh aspect of the evaluation support system, the first evaluation specification information may indicate, for each evaluation item, an evaluation specification corresponding to the evaluation item, and the vulnerability linking unit may perform the second linking process by linking, for each evaluation item in the first evaluation specification information, the vulnerability identification information, which is an analysis result corresponding to the evaluation item and is included in the vulnerability analysis information, to the first evaluation specification information so that the identification information is associated with the evaluation specification for the evaluation item. Note that the eleventh aspect may be dependent on the tenth aspect.

[0034] This makes it possible to achieve the same effects as those of the evaluation support system according to the third aspect.

[0035] In addition, in the evaluation support system according to a twelfth aspect, when the vulnerability analysis information contains identification information of a vulnerability corresponding to a missing evaluation specification, which is an evaluation specification not indicated in the first evaluation specification information, the redefinition unit may redefine one or more evaluation specifications indicated in the first evaluation specification information by adding the missing evaluation specification and the identification information of the vulnerability corresponding to the missing evaluation specification to the first evaluation specification information after the second linkage process. Note that the twelfth aspect may be subordinate to the tenth or eleventh aspect.

[0036] This makes it possible to achieve the same effects as those of the evaluation support system according to the fourth aspect.

[0037] In addition, the evaluation support system according to a thirteenth aspect may further include a feedback unit that feeds back, to a vulnerability analysis unit, the second evaluation specification information indicating an evaluation result of the evaluation target device obtained by evaluation in accordance with the second evaluation specification information, as evaluated specification information, and the vulnerability analysis unit may generate the vulnerability analysis information by performing a vulnerability analysis on the evaluation target device. Note that the thirteenth aspect may be subordinate to any one of the tenth to twelfth aspects.

[0038] This makes it possible to achieve the same effects as the evaluation support system according to the fifth aspect with respect to vulnerabilities of the device to be evaluated.

[0039] Hereinafter, the embodiments will be specifically described with reference to the drawings.

[0040] The embodiments described below are all comprehensive or specific examples. The numerical values, shapes, materials, components, component placement and connection configurations, steps, and step order shown in the following embodiments are merely examples and are not intended to limit the present disclosure. Furthermore, among the components in the following embodiments, components that are not described in the independent claims that represent the highest concepts are described as optional components.

[0041] In addition, each drawing is a schematic diagram and is not necessarily an exact illustration. In addition, the same components are denoted by the same reference numerals in each drawing.

[0042] (Embodiment 1) FIG. 1 is a diagram showing an example of the configuration of a development system according to this embodiment.

[0043] Development system 100 in this embodiment is a system that supports the development of evaluation target devices (e.g., products), such as ECUs (Electronic Control Units) to be installed in vehicles. Development system 100 may also be a system that complies with the regulations of ISO (International Organization for Standardization) / SAE (Society of Automotive Engineers) 21434. This development system 100 includes a threat analysis unit 21, a vulnerability analysis unit 22, an evaluation specification definition unit 31, an evaluation unit 32, a result determination unit 33, a determination processing unit 34, and an evaluation support system 10.

[0044] The threat analysis unit 21 generates threat analysis information d21 by performing a threat analysis on the device to be evaluated. The threat analysis information d21 indicates the analysis results of information security threats in the device to be evaluated. For example, the threat analysis unit 21 uses the threat analysis to formulate countermeasures against the threats and generates threat analysis information d21 indicating the countermeasures. The threat analysis unit 21 may identify and evaluate threats that the device to be evaluated may face. The threats include malicious attackers, natural disasters, and any other factors that may impede the security of the device to be evaluated.

[0045] The vulnerability analysis unit 22 generates and outputs vulnerability analysis information d22 by performing vulnerability analysis on the evaluation target device. The vulnerability analysis information d22 indicates the analysis result of information security vulnerabilities in the evaluation target device. For example, the vulnerability analysis unit 22 determines whether the evaluation target device has each vulnerability, and generates vulnerability analysis information d22 indicating the determination result. The vulnerability analysis unit 22 may also identify and evaluate vulnerabilities present in the evaluation target device. Note that a vulnerability can also be considered as a weak point that the evaluation target device cannot defend against an attack. The vulnerability analysis unit 22 may also identify the severity of a vulnerability. The severity is, for example, a CVSS (Common Vulnerability Scoring System) value.

[0046] The evaluation specification definition unit 31 generates and outputs first evaluation specification information d31 indicating one or more evaluation specifications for the evaluation target device. For example, the evaluation specification definition unit 31 acquires security requirements 1, test guidelines 2, and architecture specifications 3 for the evaluation target device, and generates the first evaluation specification information d31 based on these. The first evaluation specification information d31 indicates, for each evaluation item, the evaluation specification corresponding to that evaluation item.

[0047] The evaluation unit 32 acquires second evaluation specification information d13 generated by the evaluation support system 10 based on the first evaluation specification information d31, and performs an evaluation (i.e., a test) on the evaluation target device in accordance with the second evaluation specification information d13. The evaluation unit 32 then outputs information indicating the evaluation results as result information d32. The result information d32 indicates, for example, the evaluation results for each evaluation item. The evaluation of the evaluation target device is an evaluation of the security state, such as a fuzzing test, a vulnerability test, a function test, or a penetration test. The evaluation specifications are specifications for performing these evaluations.

[0048] The result determination unit 33 acquires the result information d32 output from the evaluation unit 32 and generates determination information d33 by making a determination on the evaluation result for each evaluation item indicated in the result information d32. The determination information d33 indicates, for example, whether the evaluation result for the evaluation item is OK or NG. Note that NG indicates that the evaluation result is not OK, i.e., is unacceptable. The result determination unit 33 then outputs the determination information d33 to the evaluation support system 10 and the determination processing unit 34.

[0049] The judgment processing unit 34 acquires the judgment information d33 output from the result judgment unit 33, and outputs an NG report regarding the NG evaluation items and evaluation results indicated in the judgment information d33. The judgment processing unit 34 may also propose improvement plans for measures to address the NG evaluation items.

[0050] The evaluation support system 10 in this embodiment is an evaluation support system that supports the evaluation of a device to be evaluated, and generates second evaluation specification information d13 by performing processing such as redefinition on the first evaluation specification information d31. Then, the evaluation support system 10 feeds back evaluated specification information d14, which is configured by adding the above-mentioned determination information d33 to the second evaluation specification information d13, to the threat analysis unit 21 and the vulnerability analysis unit 22.

[0051] Such an evaluation support system 10 includes a threat linking unit 11, a vulnerability linking unit 12, a redefinition unit 13, and an evaluation database (also referred to as evaluation DB) 14.

[0052] The threat linking unit 11 acquires threat analysis information d21 from the threat analysis unit 21, and acquires first evaluation specification information d31 from the evaluation specification definition unit 31. The threat linking unit 11 then links the threat analysis information d21 to the first evaluation specification information d31. That is, the threat linking unit 11 performs a first linking process to link at least a portion of the threat analysis information d21 to the first evaluation specification information d31, which indicates one or more evaluation specifications for the device to be evaluated. The threat linking unit 11 outputs threat linking information d11, which indicates the result of the first linking process, to the redefinition unit 13.

[0053] The vulnerability linking unit 12 acquires vulnerability analysis information d22 from the vulnerability analysis unit 22, and acquires first evaluation specification information d31 from the evaluation specification definition unit 31. Then, the vulnerability linking unit 12 links the vulnerability analysis information d22 to the first evaluation specification information d31. That is, the vulnerability linking unit 12 performs a second linking process to link at least a part of the vulnerability analysis information d22 to the first evaluation specification information d31. The vulnerability linking unit 12 outputs vulnerability linking information d12 indicating the result of the second linking process to the redefinition unit 13.

[0054] The redefinition unit 13 redefines one or more evaluation specifications indicated in the first evaluation specification information d31 based on the first linking process and the second linking process, thereby generating and outputting second evaluation specification information d13. That is, the redefinition unit 13 acquires threat linking information d11 from the threat linking unit 11 and vulnerability linking information d12 from the vulnerability linking unit 12, and generates second evaluation specification information d13 based on the threat linking information d11 and the vulnerability linking information d12. Then, the redefinition unit 13 outputs the second evaluation specification information d13 to the evaluation unit 32 and stores it in the evaluation database 14.

[0055] The evaluation database 14 is a recording medium for storing the second evaluation specification information d13, etc. For example, the evaluation database 14 is a hard disk drive, a RAM (Random Access Memory), a ROM (Read Only Memory), or a semiconductor memory, etc. Note that such an evaluation database 14 may be volatile or non-volatile.

[0056] Furthermore, the evaluation database 14 stores evaluated specification information d14. That is, the result determination unit 33 stores the determination information d33 in the evaluation database 14. At this time, the result determination unit 33 generates the evaluated specification information d14 by adding the determination information d33 to the second evaluated specification information d13 already stored in the evaluation database 14. As a result, the evaluated specification information d14 is stored in the evaluation database 14. Then, the evaluated specification information d14 stored in the evaluation database 14 is fed back to the threat analysis unit 21 and the vulnerability analysis unit 22. That is, the evaluation database 14 in this embodiment is configured as a feedback unit that feeds back the second evaluated specification information d13, which indicates the evaluation result of the evaluation target device obtained by evaluation in accordance with the second evaluated specification information d13, to the threat analysis unit 21 and the vulnerability analysis unit 22 as the evaluated specification information d14.

[0057] FIG. 2 is a diagram for explaining an example of part of the threat analysis performed by the threat analysis unit 21. In FIG.

[0058] As shown in FIG. 2A, the threat analysis unit 21 may evaluate the risk values ​​of assets A, B, and C of the device under evaluation 40. Assets A, B, and C are data or functions to be protected in the device under evaluation 40. These functions are implemented, for example, by programs. The device under evaluation 40 may be configured as an ECU mounted on a vehicle and communicate with external devices such as a smartphone 91 and a diagnostic device 92 via wired or wireless connections. The smartphone 91 is a smartphone, and the diagnostic device 92 is a diagnostic device that diagnoses vehicle defects and malfunctions. The device under evaluation 40 includes physical components: a Bluetooth interface 41, a USB interface 42, a CAN interface 43, a main microcomputer 44, and a CAN microcomputer 45. The Bluetooth interface 41, also referred to as a Bluetooth I / F, is an interface for Bluetooth (registered trademark). The USB interface 42, also referred to as a USB I / F, is an interface for USB (Universal Serial Bus). The CAN interface 43 is also written as CAN I / F and is an interface for a CAN (Controller Area Network). The main microcomputer 44 is a microcomputer that controls the evaluation target device 40. The main microcomputer 44 has the above-mentioned assets A, B, and C. The CAN microcomputer 45 is a microcomputer that controls the CAN of the evaluation target device 40. Note that physical components are hardware components.

[0059] Here, there are physical paths between the Main microcomputer 44 and each of the BT interface 41, the USB interface 42, and the CAN microcomputer 45. There is also a physical path between the BT interface 41 and the smartphone 91. There is also a physical path between the CAN microcomputer 45 and the CAN interface 43, and there is also a physical path between the CAN interface 43 and the Diag 92. Note that the physical paths are physical connection paths.

[0060] Additionally, physical components may be assigned a level of attackability. For example, the BT interface 41 is assigned a Medium level of attackability, and the USB interface 42 is assigned a Very Low level of attackability.

[0061] Furthermore, for each asset, a level of impact that an attack on the asset will have on the evaluation target device 40 is set. For example, Moderate is set as the impact level for asset A, Severe is set as the impact level for asset B, and Major is set as the impact level for asset C. The impact level is also called the impact degree.

[0062] The threat analysis unit 21 determines an attack path to each of assets A, B, and C. That is, for each of assets A, B, and C, the threat analysis unit 21 determines a physical path consisting of an arrangement of one or more physical components from an external device to the asset. When there are multiple attack paths to an asset, the threat analysis unit 21 determines one attack path from the multiple attack paths. An attack path is also called an attack path.

[0063] For example, if the smartphone 91 attacks assets A, B, and C, the smartphone 91 may access the main microcomputer 44 via the BT interface 41, which is assigned an attack probability level of "Medium." Alternatively, the smartphone 91 may access the main microcomputer 44 via the USB interface 42, which is assigned an attack probability level of "Very Low." In other words, the attack paths to assets A, B, and C include an attack path via the BT interface 41 and an attack path via the USB interface 42. In this case, the threat analysis unit 21 determines an attack path via a physical component assigned the highest attack probability level. In the above example, the highest attack probability level is Medium. Therefore, the attack path determined by the threat analysis unit 21 indicates a physical path from the smartphone 91 to the main microcomputer 44 via the BT interface 41.

[0064] The threat analysis unit 21 evaluates the risk value of the asset by referring to the risk matrix table shown in Figure 2(b) and using the level of attack probability "Medium" and the level of impact on the asset to derive the risk value of the asset.

[0065] As shown in Figure 2(b), the risk matrix table shows the risk value corresponding to each combination of the attack probability level and the impact level. The attack probability levels are classified as Very Low, Low, Medium, and High. These levels are arranged in ascending order. The impact levels are classified as Severe, Major, Moderate, and Negligible. These levels are arranged in ascending order.

[0066] In the above example, the impact level of asset A is Moderate, the impact level of asset B is Severe, and the impact level of asset C is Major. The attack probability level for the attack paths to these assets is Medium. In other words, the highest attack probability level on the attack path, i.e., the physical path leading to the assets, is Medium. Therefore, by referring to the risk matrix table, the threat analysis unit 21 derives a risk value of "2" for asset A, a risk value of "4" for asset B, and a risk value of "3" for asset C. This evaluates the risk values ​​of each of asset A, asset B, and asset C. The impact levels, attack probability levels, and risk matrix table are defined, for example, by ISO 21434.

[0067] FIG. 3 is a diagram showing a schematic example of threat analysis information d21 generated and output by the threat analysis unit 21. As shown in FIG.

[0068] As shown in FIG. 3, the threat analysis information d21 generated by the threat analysis unit 21 indicates, for each threat scenario ID, a threat scenario ID associated with a countermeasure against the threat identified by the threat scenario ID. The threat scenario ID is information for identifying a threat. The threat is, for example, a threat against an asset such as the above-mentioned asset A. In a specific example, the threat analysis information d21 indicates a threat scenario ID "ID-a1" associated with a countermeasure "A1" against the threat identified by the threat scenario ID "ID-a1." The threat analysis information d21 may also indicate the details of the threat. The details of the threat may include the above-mentioned attack path, impact level, risk value, etc.

[0069] FIG. 4 is a diagram showing a schematic example of vulnerability analysis information d22 generated and output by the vulnerability analysis unit 22. As shown in FIG.

[0070] As shown in FIG. 4, the vulnerability analysis information d22 generated by the vulnerability analysis unit 22 indicates, for each vulnerability ID, the vulnerability ID in association with a pertinence determination result indicating whether or not the vulnerability identified by the vulnerability ID applies to the evaluation target device 40. The vulnerability ID is information (i.e., identification information) for identifying a vulnerability. The pertinence determination result indicates "pertinent" if the vulnerability exists in the evaluation target device 40, and indicates "not pertinent" if the vulnerability does not exist in the evaluation target device 40. In other words, the vulnerability determination result indicates whether or not the vulnerability exists in the evaluation target device 40. In a specific example, the vulnerability analysis information d22 indicates a vulnerability ID "ID-b1" in association with the pertinence determination result "pertinent" for the vulnerability identified by the vulnerability ID "ID-b1". Note that the vulnerability analysis information d22 may also indicate the content of the vulnerability.

[0071] FIG. 5 is a diagram showing a schematic example of first evaluation specification information d31 generated and output by the evaluation specification definition unit 31. As shown in FIG.

[0072] As shown in Fig. 5, the first evaluation specification information d31 generated by the evaluation specification definition unit 31 indicates, for each evaluation ID, the evaluation ID and the evaluation specification corresponding to the evaluation item identified by the evaluation ID. The evaluation ID is information for identifying the evaluation item. In a specific example, the first evaluation specification information d31 indicates the evaluation ID "1" in association with the evaluation specification "C4" corresponding to the evaluation item identified by the evaluation ID "1."

[0073] FIG. 6 is a diagram for explaining the processing operation of the evaluation support system 10. As shown in FIG.

[0074] First, the threat linking unit 11 of the evaluation support system 10 performs a first linking process. Specifically, in the first linking process, the threat linking unit 11 links, for each evaluation item in the first evaluation specification information d31, information that indicates countermeasures against threats as analysis results corresponding to the evaluation item, included in the threat analysis information d21, to the first evaluation specification information d31 so that the information is associated with the evaluation specification of the evaluation item.

[0075] By this first linkage process, the first evaluation specification information d31 after the first linkage process, i.e., the second evaluation specification information d13, shows measures associated with each evaluation specification. In a specific example, measure "A1" is associated with evaluation specification "C4," and measure "A6" is associated with evaluation specification "C6." Such association of measures with evaluation specifications may be performed by referring to a table that shows a correspondence between each evaluation specification and each measure in advance, or may be performed in response to a human input operation.

[0076] Next, the vulnerability linking unit 12 of the evaluation support system 10 performs a second linking process. Specifically, in the second linking process, for each evaluation item in the first evaluation specification information d31, the vulnerability linking unit 12 links identification information of a vulnerability corresponding to that evaluation item, which is included in the vulnerability analysis information d22, to the first evaluation specification information d31 so that the identification information is associated with the evaluation specification of that evaluation item. The identification information of the vulnerability is a vulnerability ID.

[0077] Specifically, the vulnerability linking unit 12 links only the vulnerability ID associated with the judgment result "Correct" in the vulnerability analysis information d22 to the first evaluation specification information d31. At this time, the vulnerability linking unit 12 refers to a vulnerability specification table. The vulnerability specification table indicates, for each vulnerability ID, an evaluation specification for evaluating the vulnerability identified by the vulnerability ID. That is, the vulnerability linking unit 12 searches the vulnerability specification table for the vulnerability ID associated with the judgment result "Correct" in the vulnerability analysis information d22, and identifies the evaluation specification associated with the vulnerability ID in the vulnerability specification table. Then, the vulnerability linking unit 12 searches the identified evaluation specification from the first evaluation specification information d31, and associates the above-mentioned vulnerability ID with the searched evaluation specification. For example, the vulnerability linking unit 12 links the vulnerability ID "ID-b1" associated with the judgment result "Correct" in the vulnerability analysis information d22 to the first evaluation specification information d31. At this time, the vulnerability linking unit 12 searches the vulnerability specification table for the vulnerability ID "ID-b1" and identifies an evaluation specification "C1" for evaluating the vulnerability identified by the vulnerability ID "ID-b1". Then, the vulnerability linking unit 12 searches the first evaluation specification information d31 for the identified evaluation specification "C1" and associates the vulnerability ID "ID-b1" with the searched evaluation specification "C1".

[0078] Next, the redefinition unit 13 of the evaluation support system 10 redefines one or more evaluation specifications indicated in the first evaluation specification information d31. For example, there may be cases where vulnerability identification information (i.e., vulnerability ID) corresponding to a missing evaluation specification, which is an evaluation specification not indicated in the first evaluation specification information d31, exists in the vulnerability analysis information d22. In such a case, the redefinition unit 13 redefines one or more evaluation specifications indicated in the first evaluation specification information d31 by adding the missing evaluation specification and the vulnerability ID corresponding to the missing evaluation specification to the first evaluation specification information d31 after the first and second cooperation processes have been performed.

[0079] In a specific example, the vulnerability analysis information d22 indicates that a vulnerability ID "ID-b2" is associated with the judgment result "matched." Furthermore, in the vulnerability specification table, an evaluation specification "C2" is associated with the vulnerability ID "ID-b2." However, the evaluation specification "C2" is not included in the first evaluation specification information d31 shown in FIG. 5 . Therefore, the evaluation specification "C2" is the aforementioned insufficient evaluation specification. Therefore, the redefinition unit 13 adds the insufficient evaluation specification "C2" and the vulnerability ID "ID-b2" corresponding to the evaluation specification "C2" to the first evaluation specification information d31. At this time, the redefinition unit 13 associates a new evaluation ID "n+1" with the vulnerability ID "ID-b2" and the evaluation specification "C2," and further associates the countermeasure "A2" included in the threat analysis information d21 with the evaluation specification "C2."

[0080] The redefinition unit 13 may perform the above-described redefinition by changing the evaluation specifications indicated in the first evaluation specification information d31 after the first and second cooperative processes have been performed, based on the countermeasures against threats and vulnerability IDs associated with the evaluation specifications. Such a change in the evaluation specifications may be performed by referring to a table that associates the evaluation specifications with the countermeasures against threats and vulnerability IDs. For example, in changing the evaluation specifications, the evaluation specifications associated with the countermeasures against threats and vulnerability IDs in the first evaluation specification information d31 may be replaced with evaluation specifications associated with the countermeasures against threats and vulnerability IDs in the table.

[0081] Through the first and second cooperative processes and redefinition, the first evaluation specification information d31 is updated to second evaluation specification information d13. The redefinition unit 13 then stores the second evaluation specification information d13 in the evaluation database 14 and outputs it to the evaluation unit 32. The evaluation unit 32 evaluates the evaluation target device 40 according to the second evaluation specification information d13, generates result information d32 indicating the evaluation results, and outputs the result information d32 to the result determination unit 33. The result determination unit 33 acquires the result information d32 and performs a determination on the evaluation results indicated in the result information d32, thereby generating determination information d33 indicating the determination results. The result determination unit 33 then combines the determination information d33 with the second evaluation specification information d13 stored in the evaluation database 14 to generate evaluated specification information d14.

[0082] FIG. 7 is a diagram showing an example of the evaluated specification information d14.

[0083] The evaluated specification information d14 includes second evaluation specification information d13 and judgment information d33. Specifically, the evaluated specification information d14 indicates, for each evaluation ID indicated in the second evaluation specification information d13, a judgment result for the evaluation item identified by the evaluation ID. The judgment result is indicated as OK, NG, NT, conditional OK, or the like. When the evaluation result is expressed as a numerical value, for example, if the numerical value is equal to or greater than a threshold, the result judgment unit 33 writes OK as the judgment result for the evaluation result in the judgment information d33 of the evaluated specification information d14. Alternatively, if the evaluation result is as expected, the result judgment unit 33 writes OK in the judgment information d33. On the other hand, for example, if the numerical value is less than the threshold, the result judgment unit 33 writes NG as the judgment result for the evaluation result in the judgment information d33 of the evaluated specification information d14. Alternatively, if the evaluation result is not as expected, the result judgment unit 33 writes NG in the judgment information d33. Note that NT indicates that the evaluation is not applicable. Conditional OK indicates that the evaluation result is OK if certain conditions are met. Alternatively, conditional OK indicates that the evaluation result has security issues but is correct as a result of the specification.

[0084] Such evaluated specification information d14 is stored in the evaluation database 14 and is fed back to the threat analysis unit 21 and the vulnerability analysis unit 22. The feedback of the evaluated specification information d14 may be realized by the threat analysis unit 21 and the vulnerability analysis unit 22 accessing the evaluation database 14 to acquire the evaluated specification information d14. Alternatively, the feedback of the evaluated specification information d14 may be realized by a processing circuit provided in the evaluation database 14 actively transmitting the evaluated specification information d14 to the threat analysis unit 21 and the vulnerability analysis unit 22.

[0085] FIG. 8 is a diagram showing a specific example of the threat analysis information d21.

[0086] The threat analysis information d21 indicates a threat scenario ID, a threat scenario, an attack path ID, an attack path, and example design measures. In the example of FIG. 8, the threat analysis information d21 indicates that tampering with the program data of the first unit will have a major impact on safety, as an example of a threat scenario. The program data may be an example of an asset. The attack path may be the attack route described above. The example design measures are countermeasures against threats, and include TCR, which is a technically required measure, HCR, which is a hardware-required measure, and SCR, which is a software-required measure.

[0087] FIG. 9 is a diagram showing a specific example of the vulnerability analysis information d22.

[0088] Vulnerability analysis information d22 indicates the CWE (Common Weakness Enumeration)-ID, category, CVE (Common Vulnerabilities and Exposures)-ID, title, description, and the applicability determination result. The CWE-ID is the identification information of the vulnerability category. The CVE-ID is the identification information of the vulnerability and corresponds to the vulnerability ID. The title is the subject of the vulnerability, and the description is a description of the vulnerability.

[0089] FIG. 10 is a diagram showing a specific example of the second evaluation specification information d13.

[0090] The second evaluation specification information d13 indicates an evaluation ID, a CVE-ID, a requirement name, a test case purpose, prerequisites, confirmation items, a TCR, an SCR, an HCR, and an operation procedure. For example, the requirement name, the test case purpose, the prerequisites, and the confirmation items constitute an evaluation specification, and the TCR, the SCR, and the HCR constitute a countermeasure. The requirement name is the name of the evaluation item, and the test case purpose is the purpose of the evaluation. The prerequisites are conditions that are assumed for the evaluation, and the confirmation items are items that should be confirmed in the evaluation. The operation procedure is the procedure for performing the evaluation.

[0091] FIG. 11 is a diagram showing a specific example of part of the evaluated specification information d14.

[0092] The evaluated specification information d14 indicates the evaluation specification, the judgment result, and remarks. Note that in the example of Fig. 11, the evaluation ID, vulnerability ID, and countermeasures are omitted in order to specifically indicate the evaluation specification.

[0093] The evaluation specification includes a test type, a requirement name, prerequisites, confirmation items, operation procedures, and criteria. The evaluation specification may also include the purpose of the evaluation. The test type is the type of evaluation. For example, test types include a fuzzing test and a vulnerability test. A fuzzing test is a test that finds unknown vulnerabilities due to the input of unauthorized data. The number of evaluation items included in this fuzzing test is, for example, approximately 100. These evaluation items may be categorized into Bluetooth, Bluetooth Low Energy (BLE), CAN, Transmission Control Protocol / Internet Protocol (TCP / IP), and Denial of Service (DoS) attacks. A vulnerability test is a test that finds known vulnerabilities in a network or platform. The number of evaluation items included in this vulnerability test is, for example, approximately 120. These evaluation items may be categorized into network communication analysis, in-vehicle network (e.g., CAN) analysis, binary analysis, application analysis, platform analysis, etc. The criteria correspond to, for example, the confirmation items described above and indicate conditions, standards, thresholds, etc. for the determination by the determination processing unit 34. If the evaluation result satisfies the conditions, etc., a judgment result of OK is indicated in the evaluated specification information d14.

[0094] This evaluated specification information d14 is fed back to the threat analysis unit 21 and the vulnerability analysis unit 22. When the threat analysis unit 21 receives the evaluated specification information d14 as feedback, it reviews the countermeasures based on the judgment results indicated in the evaluated specification information d14. For example, the threat analysis unit 21 reviews the countermeasures corresponding to the judgment result "NG." Furthermore, if the threat analysis unit 21 derives risk values ​​for each of multiple threats corresponding to the judgment result "NG," the threat analysis unit 21 may prioritize the review of the countermeasures for each of the multiple threats using the risk values. In other words, the threat analysis unit 21 can prioritize the review of multiple countermeasures, that is, weight the review of multiple countermeasures, by using the risk values. For example, when an incident occurs, an analysis can be performed according to the priority. On the other hand, the threat analysis unit 21 can guarantee the effectiveness of the countermeasures corresponding to the judgment result "OK." Similarly to the threat analysis unit 21, when the vulnerability analysis unit 22 acquires the evaluated specification information d14 through feedback, it reviews the vulnerability analysis based on the determination result indicated in the evaluated specification information d14. For example, the vulnerability analysis unit 22 may review the pertinence determination result as to whether or not a vulnerability applies to the evaluation target device 40. Alternatively, the vulnerability analysis unit 22 may guarantee the validity of the pertinence determination result. In this way, the efficiency of the analysis can be improved based on the evaluated specification information d14.

[0095] FIG. 12 is a sequence diagram showing an example of the processing operation of the development system 100.

[0096] The evaluation specification definition unit 31 generates first evaluation specification information d31 and outputs it to the threat linking unit 11 and the vulnerability linking unit 12 (step S1). The threat analysis unit 21 generates threat analysis information d21 and outputs it to the threat linking unit 11 (step S2). The vulnerability analysis unit 22 generates vulnerability analysis information d22 and outputs it to the vulnerability linking unit 12 (step S3). The threat linking unit 11 generates threat linking information d11 based on the first evaluation specification information d31 and the threat analysis information d21 and outputs it to the redefinition unit 13. Furthermore, the vulnerability linking unit 12 generates vulnerability linking information d12 based on the first evaluation specification information d31 and the vulnerability analysis information d22 and outputs it to the redefinition unit 13 (step S4).

[0097] The redefinition unit 13 generates second evaluation specification information d13 based on the threat linking information d11 and the vulnerability linking information d12 and outputs it to the evaluation database 14 (step S5), and further outputs the second evaluation specification information d13 to the evaluation unit 32 (step S6).

[0098] The evaluation unit 32 evaluates the evaluation target device 40 in accordance with the second evaluation specification information d13, generates result information d32 indicating the evaluation result, and outputs it to the result determination unit 33 (step S7). The result determination unit 33 determines whether the evaluation result indicated in the result information d32 is OK or NG based on the above-mentioned criteria, and stores determination information d33 indicating the determination result in the evaluation database 14 (step S8). As a result, evaluated specification information d14 including the second evaluation specification information d13 and the determination information d33 is generated and stored in the evaluation database 14.

[0099] Such evaluated specification information d14 is fed back from the evaluation database 14 to the threat analysis unit 21 and vulnerability analysis unit 22 (steps S9 and S10).

[0100] FIG. 13 is a flowchart showing an example of the processing operation of the evaluation support system 10.

[0101] First, each of the threat linking unit 11 and the vulnerability linking unit 12 acquires first evaluation specification information d31 from the evaluation specification definition unit 31 (step S21). Then, the threat linking unit 11 acquires threat analysis information d21 from the threat analysis unit 21 (step S22), and the vulnerability linking unit 12 acquires vulnerability analysis information d22 from the vulnerability analysis unit 22 (step S23).

[0102] Next, the threat linking unit 11 and the vulnerability linking unit 12 execute a loop process (step S24). In this loop process, the threat linking unit 11 finds a countermeasure corresponding to the threat number from the threat analysis information d21 and links the countermeasure to the evaluation specification corresponding to the countermeasure in the first evaluation specification information d31, i.e., performs countermeasure mapping (step S24a). The threat number is a number assigned to each threat ID included in the threat analysis information d21. For example, each threat ID included in the threat analysis information d21 is assigned a different integer in the range of 0 to h (h is an integer equal to or greater than 1) as the threat number. Then, in step S24, the threat linking unit 11 repeatedly executes mapping for the threat number (step S24a) while incrementing the threat number within the range of 0 to h.

[0103] Similarly, in the loop processing, the vulnerability linking unit 12 finds a vulnerability ID corresponding to the vulnerability number from the vulnerability analysis information d22 and links the vulnerability ID to the evaluation specification corresponding to the vulnerability ID in the first evaluation specification information d31, i.e., performs vulnerability ID mapping (step S24a). Note that if there is no evaluation specification corresponding to the vulnerability ID in the first evaluation specification information d31, the mapping is skipped. The vulnerability number is a number assigned to each vulnerability ID associated with the pertinence determination result "pertinent" among all vulnerability IDs included in the vulnerability analysis information d22. For example, each vulnerability ID included in the vulnerability analysis information d22 is assigned a different integer in the range of 0 to k (k is an integer equal to or greater than 1) as the vulnerability number. Then, in step S24, the vulnerability linking unit 12 repeatedly performs mapping for the vulnerability number (step S24a) while incrementing the vulnerability number within the vulnerability number range from 0 to k.

[0104] Next, the redefinition unit 13 generates and outputs second evaluation specification information d13 by redefining one or more evaluation specifications included in the first evaluation specification information d31 after the loop processing of step S24 (step S25). That is, the redefinition unit 13 generates the second evaluation specification information d13 by adding the vulnerability IDs whose mapping has been skipped and the evaluation specifications corresponding to those vulnerability IDs (i.e., the missing evaluation specifications) to the first evaluation specification information d31 after the loop processing. This second evaluation specification information d13 is output to the evaluation unit 32, used for evaluating the evaluation target device 40, and further stored in the evaluation database 14. Then, the result determination unit 33 determines the evaluation result of the evaluation target device 40. As a result, determination information d33 indicating the determination result is stored in the evaluation database 14 by the result determination unit 33.

[0105] As a result of the result determination unit 33 storing the determination information d33, the second evaluated specification information d13 reflecting the determination information d33 is stored as evaluated specification information d14 in the evaluation database 14 (step S26). Then, the evaluation database 14 (i.e., the feedback unit) feeds back the evaluated specification information d14 to the threat analysis unit 21 (step S27), and further feeds back the evaluated specification information d14 to the vulnerability analysis unit 22 (step S28).

[0106] As described above, in the evaluation support system 10 according to the present embodiment, one or more evaluation specifications included in the second evaluation specification information d13 are linked to the threat analysis information d21 and the vulnerability analysis information d22 through the first linkage process, the second linkage process, and the redefinition. In other words, while conventionally, the security evaluation of the evaluation target device 40, the threat analysis, and the vulnerability analysis are not linked, in the present embodiment, they are linked. As a result, it is possible to increase the possibility that necessary evaluations will be suppressed and that the evaluation of the evaluation target device 40 can be performed comprehensively. In other words, it is possible to reduce the possibility that the security evaluation of the evaluation target device 40 will be incomplete. Therefore, it is possible to effectively support the evaluation of the evaluation target device 40.

[0107] Furthermore, in this embodiment, the first cooperation process associates the countermeasures against the threat with the evaluation specifications. Therefore, in the evaluation according to the first evaluation specification information d31 that has undergone the first cooperation process, the countermeasures can be used as a reference, and the evaluation of the evaluation target device 40 can be more effectively supported.

[0108] Furthermore, in this embodiment, the vulnerability identification information is associated with the evaluation specification by the second linkage process. Therefore, in the evaluation according to the second evaluation specification information d13 that has been subjected to the second linkage process, the vulnerability can be referred to, and the evaluation of the evaluation target device 40 can be more effectively supported.

[0109] Furthermore, in this embodiment, the first evaluation specification information d31 is updated to the second evaluation specification information d13 including the missing evaluation specification and the vulnerability identification information by the redefinition, thereby preventing the omission of necessary evaluations and enabling the evaluation of the evaluation target device 40 to be performed comprehensively.

[0110] Furthermore, in this embodiment, the evaluated specification information d14 is fed back to the threat analysis unit 21 and the vulnerability analysis unit 22. Therefore, if the evaluated specification information d14 indicates a good evaluation result (e.g., OK) for the evaluated specification, the threat analysis unit 21 can guarantee the analysis result for the threat. For example, if the analysis result is a countermeasure against the threat, the effectiveness of the countermeasure can be guaranteed. On the other hand, if the evaluated specification information d14 indicates a bad evaluation result (e.g., NG) for the evaluated specification, the threat analysis unit 21 can improve the threat analysis. For example, if the analysis result is a countermeasure against the threat, the countermeasure can be improved. As a result, the accuracy of countermeasure planning can be improved. Furthermore, the vulnerability analysis unit 22 can improve the accuracy of vulnerability analysis based on the evaluation result indicated in the evaluated specification information d14. In other words, in this embodiment, not only is there a one-way flow from threat analysis and vulnerability analysis to evaluation, but the evaluation result is also fed back to threat analysis and vulnerability analysis, thereby enabling effective risk management of the evaluation target device 40.

[0111] (Embodiment 2) The difference between the first and second embodiments is that the second embodiment deals with only the threat analysis information d21 out of the threat analysis information d21 and the vulnerability analysis information d22. Only the differences between the first and second embodiments will be described below.

[0112] FIG. 14 is a diagram showing an example of the configuration of a development system 100 according to the second embodiment.

[0113] The development system 100 of the second embodiment comprises a threat analysis unit 21, an evaluation specification definition unit 31, an evaluation unit 32, a result determination unit 33, a determination processing unit , and an evaluation support system .

[0114] The threat analysis unit 21, evaluation specification definition unit 31, evaluation unit 32, result determination unit 33, and determination processing unit 34 are the same as those in the first embodiment.

[0115] The evaluation support system 10 includes a threat linking unit 11, a redefinition unit 13, and an evaluation database (also referred to as evaluation DB) 14. The threat linking unit 11 is the same as that in the first embodiment.

[0116] The redefinition unit 13 redefines one or more evaluation specifications indicated in the first evaluation specification information d31 based on the first linkage process, thereby generating and outputting second evaluation specification information d13. That is, the redefinition unit 13 obtains the threat linkage information d11 from the threat linkage unit 11 and generates the second evaluation specification information d13 based on the threat linkage information d11. The redefinition unit 13 then outputs the second evaluation specification information d13 to the evaluation unit 32 and stores it in the evaluation database 14. Note that the redefinition unit 13 may perform the above-described redefinition by changing the evaluation specifications indicated in the first evaluation specification information d31 after the first linkage process based on measures against threats associated with the evaluation specifications. Such a change in evaluation specifications may be performed by referencing a table that associates evaluation specifications with measures against threats. For example, in changing the evaluation specifications, the evaluation specifications associated with measures against threats in the first evaluation specification information d31 may be replaced with evaluation specifications associated with the measures against the threats in the table.

[0117] Furthermore, the redefinition unit 13 of the evaluation support system 10 redefines one or more evaluation specifications indicated in the first evaluation specification information d31. For example, there may be cases where information indicating a countermeasure against a threat corresponding to a missing evaluation specification, which is an evaluation specification not indicated in the first evaluation specification information d31 (i.e., a threat ID), exists in the threat analysis information d21. In such a case, the redefinition unit 13 redefines one or more evaluation specifications indicated in the first evaluation specification information d31 by adding the missing evaluation specification and the threat ID corresponding to the missing evaluation specification to the first evaluation specification information d31 after the first linkage process.

[0118] The evaluation database 14 stores evaluated specification information d14. The evaluated specification information d14 stored in the evaluation database 14 is fed back to the threat analysis unit 21. That is, the evaluation database 14 in this embodiment is configured as a feedback unit that feeds back the second evaluated specification information d13, which indicates the evaluation result of the evaluation target device obtained by evaluation in accordance with the second evaluated specification information d13, to the threat analysis unit 21 as evaluated specification information d14.

[0119] FIG. 12 is a sequence diagram showing an example of the processing operation of the development system 100.

[0120] The evaluation specification definition unit 31 generates first evaluation specification information d31 and outputs it to the threat linking unit 11 (step S1). The threat analysis unit 21 generates threat analysis information d21 and outputs it to the threat linking unit 11 (step S2). The threat linking unit 11 generates threat linking information d11 based on the first evaluation specification information d31 and the threat analysis information d21 and outputs it to the redefinition unit 13 (step S4).

[0121] The redefinition unit 13 generates second evaluation specification information d13 based on the threat linkage information d11, outputs it to the evaluation database 14 (step S5), and further outputs the second evaluation specification information d13 to the evaluation unit 32 (step S6).

[0122] The redefinition unit 13 and the result determination unit 33 are the same as those in the first embodiment.

[0123] The evaluated specification information d14 generated in the evaluation database 14 is fed back from the evaluation database 14 to the threat analysis unit 21 (step S10).

[0124] FIG. 13 is a flowchart showing an example of the processing operation of the evaluation support system 10.

[0125] First, the threat linking unit 11 acquires the first evaluation specification information d31 from the evaluation specification definition unit 31 (step S21). Then, the threat linking unit 11 acquires the threat analysis information d21 from the threat analysis unit 21 (step S22).

[0126] The threat linking unit 11, the redefinition unit 13 and the result determination unit 33 are the same as those in the first embodiment.

[0127] As a result of the result determination unit 33 storing the determination information d33, the second evaluated specification information d13 reflecting the determination information d33 is stored as evaluated specification information d14 in the evaluation database 14 (step S26). Then, the evaluation database 14 (i.e., the feedback unit) feeds back the evaluated specification information d14 to the threat analysis unit 21 (step S27).

[0128] In the evaluation support system 10 according to the second embodiment, one or more evaluation specifications included in the second evaluation specification information d13 are linked to the threat analysis information d21 through the first linking process and redefinition. That is, conventionally, the security evaluation of the evaluation target device 40 and the threat analysis are not linked, but in the present embodiment, they are linked. As a result, it is possible to increase the possibility that necessary evaluations will be suppressed and that the evaluation of the evaluation target device 40 can be performed comprehensively. That is, it is possible to reduce the possibility that the security evaluation of the evaluation target device 40 will be incomplete. Therefore, it is possible to effectively support the evaluation of the evaluation target device 40.

[0129] (Embodiment 3) The difference between the embodiment 3 and the embodiment 1 is that, of the threat analysis information d21 and the vulnerability analysis information d22, only the vulnerability analysis information d22 is handled. Only the differences between the embodiment 3 and the embodiment 1 will be described below.

[0130] FIG. 15 is a diagram showing an example of the configuration of a development system 100 according to the third embodiment.

[0131] The development system 100 of the third embodiment comprises a vulnerability analysis unit 22, an evaluation specification definition unit 31, an evaluation unit 32, a result determination unit 33, a determination processing unit , and an evaluation support system .

[0132] The vulnerability analysis unit 22, the evaluation specification definition unit 31, the evaluation unit 32, the result determination unit 33, and the determination processing unit 34 are the same as those in the first embodiment.

[0133] The evaluation support system 10 includes a vulnerability linking unit 12, a redefinition unit 13, and an evaluation database (also referred to as an evaluation DB) 14.

[0134] The vulnerability linking unit 12 is the same as that in the first embodiment.

[0135] The redefinition unit 13 redefines one or more evaluation specifications indicated in the first evaluation specification information d31 based on the second linking process, thereby generating and outputting the second evaluation specification information d13. That is, the redefinition unit 13 obtains the vulnerability linking information d12 from the vulnerability linking unit 12 and generates the second evaluation specification information d13 based on the vulnerability linking information d12. The redefinition unit 13 then outputs the second evaluation specification information d13 to the evaluation unit 32 and stores it in the evaluation database 14. Note that the redefinition unit 13 may perform the above-described redefinition by changing the evaluation specifications indicated in the first evaluation specification information d31 after the second linking process based on a vulnerability ID associated with the evaluation specifications. Such a change in the evaluation specifications may be performed by referring to a table that associates evaluation specifications with vulnerability IDs. For example, in the change of the evaluation specifications, the evaluation specifications associated with the vulnerability IDs in the first evaluation specification information d31 may be replaced with the evaluation specifications associated with the vulnerability IDs in the table.

[0136] The evaluation database 14 stores evaluated specification information d14. The evaluated specification information d14 stored in the evaluation database 14 is fed back to the vulnerability analysis unit 22. That is, the evaluation database 14 in this embodiment is configured as a feedback unit that feeds back the second evaluation specification information d13, which indicates the evaluation result of the evaluation target device obtained by evaluation in accordance with the second evaluation specification information d13, to the vulnerability analysis unit 22 as evaluated specification information d14.

[0137] FIG. 12 is a sequence diagram showing an example of the processing operation of the development system 100.

[0138] The evaluation specification definition unit 31 generates first evaluation specification information d31 and outputs it to the vulnerability linking unit 12 (Step S1). The vulnerability analysis unit 22 generates vulnerability analysis information d22 and outputs it to the vulnerability linking unit 12 (Step S3). The vulnerability linking unit 12 generates vulnerability linking information d12 based on the first evaluation specification information d31 and the vulnerability analysis information d22 and outputs it to the redefinition unit 13 (Step S4).

[0139] The redefinition unit 13 generates second evaluation specification information d13 based on the vulnerability linking information d12 and outputs it to the evaluation database 14 (step S5), and further outputs the second evaluation specification information d13 to the evaluation unit 32 (step S6).

[0140] The redefinition unit 13 and the result determination unit 33 are the same as those in the first embodiment.

[0141] The evaluated specification information d14 generated in the evaluation database 14 is fed back from the evaluation database 14 to the vulnerability analysis unit 22 (step S9).

[0142] FIG. 13 is a flowchart showing an example of the processing operation of the evaluation support system 10.

[0143] First, the vulnerability linking unit 12 acquires the first evaluation specification information d31 from the evaluation specification definition unit 31 (step S21). Then, the vulnerability linking unit 12 acquires the vulnerability analysis information d22 from the vulnerability analysis unit 22 (step S23).

[0144] The vulnerability linking unit 12, the redefinition unit 13 and the result determination unit 33 are the same as those in the first embodiment.

[0145] As a result of the result determination unit 33 storing the determination information d33, the second evaluated specification information d13 reflecting the determination information d33 is stored as evaluated specification information d14 in the evaluation database 14 (step S26). Then, the evaluation database 14 (i.e., the feedback unit) feeds back the evaluated specification information d14 to the vulnerability analysis unit 22 (step S28).

[0146] In the evaluation support system 10 according to the third embodiment, one or more evaluation specifications included in the second evaluation specification information d13 are linked to the vulnerability analysis information d22 through the second linking process and redefinition. That is, conventionally, the security evaluation of the evaluation target device 40 and the vulnerability analysis are not linked, but in the present embodiment, they are linked. As a result, it is possible to increase the possibility that necessary evaluations will be suppressed and that the evaluation of the evaluation target device 40 can be performed comprehensively. That is, it is possible to reduce the possibility that the security evaluation of the evaluation target device 40 will be incomplete. Therefore, it is possible to effectively support the evaluation of the evaluation target device 40.

[0147] The evaluation support system 10 and the evaluation support method according to one or more aspects of the present disclosure have been described above based on the respective embodiments, but the present disclosure is not limited to those embodiments. As long as the modifications do not deviate from the spirit of the present disclosure, various modifications conceivable by those skilled in the art to the above-described embodiments may also be included in the present disclosure.

[0148] For example, in each of the above embodiments, the device 40 to be evaluated is an ECU, but it may be any other device that processes information.

[0149] In each of the above embodiments, evaluated specification information d14 is stored in the evaluation database 14, and the evaluated specification information d14 is fed back. Here, new countermeasures for evaluation items for which the judgment result (specifically, NG) included in the evaluated specification information d14 is obtained may be stored in the evaluation database 14 and fed back. The new countermeasures may be stored by a human input operation.

[0150] Furthermore, the evaluated specification information d14 and the like may be fed back to other components in addition to the threat analysis unit 21 and the vulnerability analysis unit 22. The other components may be a security execution unit, a CS (Cyber ​​Security) regulatory compliance unit, etc. The security execution unit is a process performed at the bottom of the V-process for automobile development, and performs coding of the software program of the device 40 to be evaluated, etc.

[0151] Furthermore, in each of the above embodiments, the evaluation support system 10 does not include the evaluation unit 32 and the result determination unit 33, but may include these components.

[0152] Furthermore, in each of the above embodiments, each component included in evaluation support system 10 may perform the processing corresponding to that component in response to a human input operation, or may perform the processing automatically without receiving the input operation. Similarly, each component included in development system 100 may perform the processing corresponding to that component in response to a human input operation, or may perform the processing automatically without receiving the input operation. Furthermore, a machine learning model that shows the correlation between input and output may be used for the automatic processing.

[0153] In each of the above embodiments, each component may be configured with dedicated hardware or may be realized by executing a software program suitable for each component. Each component may be realized by a program execution unit such as a CPU (Central Processing Unit) or processor reading and executing a software program recorded on a recording medium such as a hard disk or semiconductor memory. Here, the software that realizes the evaluation support system of each of the above embodiments is a computer program that causes a computer to execute each step of the flowchart shown in Figure 13.

[0154] The following cases are also included in this disclosure:

[0155] (1) The at least one system or device is specifically a computer system comprising a microprocessor, ROM, RAM, hard disk unit, display unit, keyboard, mouse, etc. A computer program is stored in the RAM or hard disk unit. The at least one device achieves its function when the microprocessor operates in accordance with the computer program. Here, the computer program is composed of a combination of multiple instruction codes that indicate instructions to the computer to achieve a predetermined function.

[0156] (2) Some or all of the components constituting at least one of the above systems or devices may be configured as a single system LSI (Large Scale Integration). A system LSI is an ultra-multifunctional LSI manufactured by integrating multiple components on a single chip, and specifically, is a computer system configured including a microprocessor, ROM, RAM, etc. A computer program is stored in the RAM. The system LSI achieves its functions when the microprocessor operates in accordance with the computer program.

[0157] (3) Some or all of the components constituting at least one of the above systems or devices may be configured as an IC card or a standalone module that can be attached to or detached from the device. The IC card or module is a computer system composed of a microprocessor, ROM, RAM, etc. The IC card or module may include the above-mentioned ultra-multifunctional LSI. The IC card or module achieves its functions when the microprocessor operates in accordance with a computer program. This IC card or module may be tamper-resistant.

[0158] (4) The present disclosure may be embodied as the methods described above, a computer program for implementing these methods on a computer, or a digital signal comprising the computer program.

[0159] The present disclosure may also be a computer program or a digital signal recorded on a computer-readable recording medium, such as a flexible disk, a hard disk, a CD (Compact Disc)-ROM, a DVD, a DVD-ROM, a DVD-RAM, a BD (Blu-ray (registered trademark) Disc), a semiconductor memory, etc. Alternatively, the present disclosure may be a digital signal recorded on such a recording medium.

[0160] The present disclosure may also be applied to transmitting a computer program or digital signal via a telecommunications line, a wireless or wired communication line, a network such as the Internet, data broadcasting, or the like.

[0161] Furthermore, the program or digital signal may be recorded on a recording medium and transferred, or the program or digital signal may be transferred via a network or the like, so that the program or digital signal may be implemented by another independent computer system. [Industrial Applicability]

[0162] The evaluation support system of the present disclosure can be applied to a device or system that supports the evaluation of an ECU or the like that is incorporated in a vehicle, for example. [Explanation of symbols]

[0163] 1. Security Requirements 2 Testing Guidelines 3 Architecture Specifications 10 Evaluation Support System 11 Threat Link 12 Vulnerable connections 13 Redefinition part 14 Evaluation database (feedback section) 21 Threat Analysis Department 22 Vulnerability Analysis Department 31 Evaluation specification definition section 32 Evaluation Section 33 Result judgment section 34 Judgment processing unit 40 Equipment to be evaluated 41 BT interface 42 USB interface 43 CAN interface 44 Main microcomputer 45 CAN microcontroller 91 Smartphone 92 Diag 100 Development System d11 Threat Collaboration Information d12 Vulnerability Linkage Information d13 Second evaluation specification information d14 Evaluated specification information d21 Threat Analysis Information d22 vulnerability analysis information d31 First evaluation specification information d32 result information d33 Judgment information

Claims

1. An evaluation support system for supporting evaluation of an evaluation target device, a threat linking unit that performs a first linking process of linking at least a portion of threat analysis information indicating an analysis result of an information security threat in the evaluation target device to first evaluation specification information indicating one or more evaluation specifications for the evaluation target device; a vulnerability linking unit that performs a second linking process of linking at least a part of vulnerability analysis information indicating an analysis result of information security vulnerabilities in the evaluation target device to the first evaluation specification information; a redefinition unit that redefines one or more evaluation specifications indicated in the first evaluation specification information based on the first cooperative processing and the second cooperative processing, thereby generating and outputting second evaluation specification information. Evaluation support system.

2. the first evaluation specification information indicates, for each evaluation item, an evaluation specification corresponding to the evaluation item; The threat linking unit performing the first linking process by linking the information to the first evaluation specification information so that, for each evaluation item of the first evaluation specification information, information indicating measures against the threats, which is included in the threat analysis information and corresponds to the evaluation item as an analysis result, is associated with the evaluation specification of the evaluation item; The evaluation support system according to claim 1 .

3. the first evaluation specification information indicates, for each evaluation item, an evaluation specification corresponding to the evaluation item; The fragile link is performing the second linking process by linking the vulnerability identification information, which is an analysis result corresponding to each evaluation item included in the vulnerability analysis information, to the first evaluation specification information so that the identification information is associated with the evaluation specification for the evaluation item, for each evaluation item of the first evaluation specification information; The evaluation support system according to claim 1 .

4. The redefinition unit If the vulnerability analysis information contains the vulnerability identification information corresponding to the missing evaluation specification, which is an evaluation specification not shown in the first evaluation specification information, redefining one or more evaluation specifications indicated in the first evaluation specification information by adding the missing evaluation specifications and the vulnerability identification information corresponding to the missing evaluation specifications to the first evaluation specification information after the first cooperation process and the second cooperation process have been performed; The evaluation support system according to claim 3 .

5. The evaluation support system further includes: a feedback unit that feeds back the second evaluation specification information, which indicates an evaluation result of the evaluation target device obtained by evaluation in accordance with the second evaluation specification information, to a threat analysis unit and a vulnerability analysis unit as evaluated specification information; the threat analysis unit generates the threat analysis information by performing a threat analysis on the evaluation target device; the vulnerability analysis unit generates the vulnerability analysis information by performing a vulnerability analysis on the evaluation target device. The evaluation support system according to claim 1 .

6. An evaluation support system for supporting evaluation of an evaluation target device, a threat linking unit that performs a first linking process of linking at least a portion of threat analysis information indicating an analysis result of an information security threat in the evaluation target device to first evaluation specification information indicating one or more evaluation specifications for the evaluation target device; a redefinition unit that redefines one or more evaluation specifications indicated in the first evaluation specification information based on the first collaboration process, thereby generating and outputting second evaluation specification information. Evaluation support system.

7. the first evaluation specification information indicates, for each evaluation item, an evaluation specification corresponding to the evaluation item; The threat linking unit performing the first linking process by linking the information to the first evaluation specification information so that, for each evaluation item of the first evaluation specification information, information indicating measures against the threats, which is included in the threat analysis information and corresponds to the evaluation item as an analysis result, is associated with the evaluation specification of the evaluation item; The evaluation support system according to claim 6.

8. The redefinition unit If the threat analysis information includes information indicating a measure against the threat corresponding to a missing evaluation specification that is an evaluation specification not included in the first evaluation specification information, redefining one or more evaluation specifications indicated in the first evaluation specification information by adding the deficient evaluation specifications and information indicating measures against the threats corresponding to the deficient evaluation specifications to the first evaluation specification information after the first collaboration process has been performed; The evaluation support system according to claim 6.

9. The evaluation support system further includes: a feedback unit that feeds back the second evaluation specification information, which indicates an evaluation result of the evaluation target device obtained by evaluation in accordance with the second evaluation specification information, to a threat analysis unit as evaluated specification information; the threat analysis unit generates the threat analysis information by performing a threat analysis on the evaluation target device. The evaluation support system according to claim 6.

10. An evaluation support system for supporting evaluation of an evaluation target device, a vulnerability linking unit that performs a second linking process of linking at least a part of vulnerability analysis information indicating an analysis result of information security vulnerabilities in the evaluation target device to first evaluation specification information indicating one or more evaluation specifications for the evaluation target device; a redefinition unit that redefines one or more evaluation specifications indicated in the first evaluation specification information based on the second collaboration process, thereby generating and outputting second evaluation specification information. Evaluation support system.

11. the first evaluation specification information indicates, for each evaluation item, an evaluation specification corresponding to the evaluation item; The fragile link is performing the second linking process by linking the vulnerability identification information, which is an analysis result corresponding to each evaluation item included in the vulnerability analysis information, to the first evaluation specification information so that the identification information is associated with the evaluation specification for the evaluation item, for each evaluation item of the first evaluation specification information; The evaluation support system according to claim 10.

12. The redefinition unit If the vulnerability analysis information contains the vulnerability identification information corresponding to the missing evaluation specification, which is an evaluation specification not shown in the first evaluation specification information, redefining one or more evaluation specifications indicated in the first evaluation specification information by adding the missing evaluation specification and the vulnerability identification information corresponding to the missing evaluation specification to the first evaluation specification information after the second collaboration process has been performed; The evaluation support system according to claim 10.

13. The evaluation support system further includes: a feedback unit that feeds back the second evaluation specification information, which indicates an evaluation result of the evaluation target device obtained by evaluation in accordance with the second evaluation specification information, to a vulnerability analysis unit as evaluated specification information; the vulnerability analysis unit generates the vulnerability analysis information by performing a vulnerability analysis on the evaluation target device. The evaluation support system according to claim 10.

14. An evaluation support method in which a computer supports evaluation of an evaluation target device, comprising: performing a first linking process of linking at least a portion of threat analysis information indicating an analysis result of an information security threat in the evaluation target device to first evaluation specification information indicating one or more evaluation specifications for the evaluation target device; performing a second linking process of linking at least a part of vulnerability analysis information indicating an analysis result of information security vulnerabilities in the evaluation target device to the first evaluation specification information; generating and outputting second evaluation specification information by redefining one or more evaluation specifications indicated in the first evaluation specification information based on the first cooperative processing and the second cooperative processing; Evaluation support methods.

15. An evaluation support method in which a computer supports evaluation of an evaluation target device, comprising: performing a first linking process of linking at least a portion of threat analysis information indicating an analysis result of an information security threat in the evaluation target device to first evaluation specification information indicating one or more evaluation specifications for the evaluation target device; generating and outputting second evaluation specification information by redefining one or more evaluation specifications indicated in the first evaluation specification information based on the first cooperative processing; Evaluation support methods.

16. An evaluation support method in which a computer supports evaluation of an evaluation target device, comprising: performing a second linking process of linking at least a portion of vulnerability analysis information indicating an analysis result of information security vulnerabilities in the evaluation target device to first evaluation specification information indicating one or more evaluation specifications for the evaluation target device; generating and outputting second evaluation specification information by redefining one or more evaluation specifications indicated in the first evaluation specification information based on the second collaboration process; Evaluation support methods.

17. A program for supporting evaluation of an evaluation target device, performing a first linking process of linking at least a portion of threat analysis information indicating an analysis result of an information security threat in the evaluation target device to first evaluation specification information indicating one or more evaluation specifications for the evaluation target device; performing a second linking process of linking at least a part of vulnerability analysis information indicating an analysis result of information security vulnerabilities in the evaluation target device to the first evaluation specification information; generating and outputting second evaluation specification information by redefining one or more evaluation specifications indicated in the first evaluation specification information based on the first cooperative processing and the second cooperative processing; A program that makes a computer do something.

18. A program for supporting evaluation of an evaluation target device, performing a first linking process of linking at least a portion of threat analysis information indicating an analysis result of an information security threat in the evaluation target device to first evaluation specification information indicating one or more evaluation specifications for the evaluation target device; generating and outputting second evaluation specification information by redefining one or more evaluation specifications indicated in the first evaluation specification information based on the first cooperative processing; A program that makes a computer do something.

19. A program for supporting evaluation of an evaluation target device, performing a second linking process of linking at least a portion of vulnerability analysis information indicating an analysis result of information security vulnerabilities in the evaluation target device to first evaluation specification information indicating one or more evaluation specifications for the evaluation target device; generating and outputting second evaluation specification information by redefining one or more evaluation specifications indicated in the first evaluation specification information based on the second collaboration process; A program that makes a computer do something.

Citation Information

Patent Citations

  • Brittleness information generator and brittleness evaluation device

    JP2019192101A

  • Security design support system and security design support method

    JP2024058377A

  • Development-side security analysis support device and security analysis support system

    JP7403686B2

  • Information processing device, information processing method, and information processing program

    WO2020115782A1

  • Risk evaluation / countermeasure planning system and risk evaluation / countermeasure planning method

    WO2020202934A1