Information processing system, information processing method and program
The information processing system addresses the challenge of creating applicable security policies by analyzing and identifying logics that link attribute information with actions, ensuring accurate and cost-effective policy implementation in real environments.
Patent Information
- Application Number
- JP2024043912
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-19
- Publication Date
- 2025-10-02
AI Technical Summary
Existing management systems face challenges in creating policies that accurately determine actions for security events due to the inability to obtain necessary attribute information, leading to potential misapplication or impracticality of the created policies in real environments.
An information processing system and method that analyze first logic linking attribute information with actions, identify a second logic based on differences and additional costs, and generate decision logic applicable to real environments by using an analysis unit and identification unit to link second attribute information with corresponding actions.
Enables the creation of decision logic that can be effectively applied in real environments, ensuring accurate and practical policy implementation by minimizing differences and additional costs.
Smart Images

Figure 2025144234000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to an information processing system, an information processing method, and a program. [Background technology]
[0002] With security in mind, technology is evolving to determine actions to be taken in response to security events by using policies and the like.
[0003] For example, Patent Document 1 discloses a system that analyzes security events using dynamic policies and displays a unified view including active threats, user activities, and dynamic policies triggered by the active threats and user activities, where the system can use historical data to create additional rules and policies that can be applied in real time. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Application Publication No. 2023-175878 Summary of the Invention [Problem to be solved by the invention]
[0005] When a management system creates a policy and uses that policy to determine an action for a security event, it is possible that the management system may not be able to obtain the attribute information necessary for making a decision using the policy, in which case the management system will not be able to determine an action using the created policy.
[0006] In this case, as described in Patent Document 1, it is conceivable that the management system determines the action by creating an additional policy. However, it is conceivable that the additional policy created by the management system may not be applicable to the actual environment. For example, the action determined by the created policy may be significantly different from the action that should have been determined. Alternatively, it is conceivable that the created policy may be practically unusable because the management system cannot or has difficulty in acquiring attribute information required for the created policy.
[0007] One of the objectives that the embodiments of the present disclosure aim to achieve is to provide an information processing system, an information processing method, and a program that are capable of creating decision logic for actions that can be applied to real environments. Note that this objective is only one of multiple objectives that the embodiments disclosed herein aim to achieve. Other objectives or problems and novel features will become apparent from the description of this specification or the accompanying drawings. [Means for solving the problem]
[0008] An information processing system according to one aspect includes: an analysis unit that analyzes a first logic that links first attribute information with a first action corresponding to the first attribute information and candidates for the attribute information; an identification unit that identifies a second logic that links second attribute information and a second action corresponding to the second attribute information based on an analysis result of the analysis unit; The identification unit identifies the second logic based on at least one of the difference between the judgment result based on the first logic and the judgment result based on the second logic and the additional cost incurred by using the second attribute information instead of the first attribute information.
[0009] An information processing method according to one aspect includes: Analyzing first logic that links first attribute information with a first action corresponding to the first attribute information and candidates for the attribute information; identifying a second logic that links second attribute information with a second action corresponding to the second attribute information based on the analysis result, wherein the second logic is identified in accordance with at least one of a difference between a determination result based on the first logic and a determination result based on the second logic and an additional cost incurred by using the second attribute information instead of the first attribute information; It is a computer-implemented method.
[0010] In one aspect, the program Analyzing first logic that links first attribute information with a first action corresponding to the first attribute information and candidates for the attribute information; identifying a second logic that links second attribute information with a second action corresponding to the second attribute information based on the analysis result, wherein the second logic is identified in accordance with at least one of a difference between a determination result based on the first logic and a determination result based on the second logic and an additional cost incurred by using the second attribute information instead of the first attribute information; This is what causes a computer to execute the above. [Effects of the Invention]
[0011] The present disclosure makes it possible to provide an information processing system, an information processing method, and a program that are capable of creating decision logic for actions that can be applied to real environments. [Brief explanation of the drawings]
[0012] [Figure 1] FIG. 1 is a block diagram illustrating an example of an information processing system according to the present disclosure. [Figure 2] 1 is a flowchart illustrating an example of a typical process of the information processing system. [Figure 3] FIG. 1 is a block diagram illustrating an example of an access management system according to the present disclosure. [Figure 4]10 shows an example of a data flow when a policy engine determines an action based on attribute information of a real environment. [Figure 5] 10 is a flowchart illustrating an example of a typical process of the access management system. [Figure 6] FIG. 1 is a block diagram illustrating an example of an access management system according to the present disclosure. [Figure 7] 10 shows an example of a data flow when a policy engine determines an action based on attribute information of a real environment. [Figure 8A] 10 is a flowchart illustrating an example of a typical process of the access management system. [Figure 8B] 10 is a flowchart illustrating an example of a typical process of the access management system. [Figure 9] FIG. 1 is a block diagram illustrating an example of a hardware configuration of an information processing device in which processing of a system or device according to the present disclosure is executed. DETAILED DESCRIPTION OF THE INVENTION
[0013] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings. Note that the following descriptions and drawings in the embodiments have been omitted or simplified as appropriate for clarity of explanation. Furthermore, in this disclosure, unless otherwise specified, when multiple items are defined as "at least one of multiple items," the definition may mean any one item, or any multiple items including all items.
[0014] Each drawing referenced in the embodiments is merely an example for describing one or more embodiments. Each drawing may not relate to only one particular embodiment, but may also relate to one or more other embodiments. As will be understood by those skilled in the art, various features or steps described with reference to any one drawing can be combined with features or steps shown in one or more other drawings to create, for example, an embodiment not explicitly shown or described. Not all features or steps shown in any one drawing are necessarily required to describe an exemplary embodiment, and some features or steps may be omitted. The order of steps described in any drawing may be changed as appropriate.
[0015] Additionally, common definitions used in this disclosure are explained below.
[0016] [Definition explanation] In this disclosure, the term "user" refers to any person who may be involved in the handling of a resource. For example, a user may be a person involved in access management. Persons involved in access management include, for example, end users who issue access requests to resources to be accessed (hereinafter also referred to as access resources), as well as administrators who manage access control. Here, the access resource refers to any access target, such as an information asset, an application, a computer file, or a device to be accessed. However, as another example, a user may also be a person who handles resources, such as encrypting the resources they handle or storing the resources in a secure area.
[0017] In this disclosure, "attribute information" refers to information required to determine the action to be taken for the target resource being handled. "Attribute information" refers to, for example, access attributes related to access control. The access attribute indicates any element that identifies the nature of the access when a certain access destination is accessed. Specific examples of elements may include one or more specific pieces of information (values) related to the nature of the access, such as (1) various data of the access source, (2) various data of the access destination, and (3) other data indicating the nature of the access.
[0018] (1) Specific examples of various data (Subject Attributes) of the access source include any one or more of information on the access source's ID (IDentification), the physical location of the access source, information on the end user, information on at least one of the access source's device or subsystem, information on the access source's IP (Internet Protocol) address, information on port numbers, software names (e.g., application names), and access authentication methods. Here, information on the access source's ID includes any one or more of the access source's ID (e.g., end user ID), end user name, device ID, subsystem ID, application ID, and end user authentication results (authentication history) for the access source ID. Information on the end user includes any one or more of the end user's affiliation (organization), job title, job type, end user location (or location of the access source device), affiliation of the access source device, and behavioral anomaly level of the end user or the access source device. Information on the access source device includes any one or more of the OS (Operating System) and its version used by the access source device, the manufacturer name, and the like. The information about the IP address of the access source includes, for example, one or more of the IP address of the access source, the risk level of the IP address of the access source, etc. In the above, the OS version indicates the vulnerability of the access, and the behavioral anomaly level indicates the possibility of an attack.
[0019] (2) Specific examples of various data (Object Attributes) of the access destination include any one or more of the following: information on the ID of the access destination, information on the access resource, the address of the access destination (e.g., IP address or web address port number), information on the OS used by the access destination device, operation type, etc. Information on the ID of the access destination includes any one or more of the following: the subsystem ID of the access destination, resource ID, owner name of the access resource ID, etc. Information on the access resource includes any one or more of the following: the organization of the access destination (organization that owns the access resource), the type of access resource requested, creator, creation date and time, confidentiality, etc. The confidentiality of the access resource indicates the expected damage in the event of an attack.
[0020] (3) Specific examples of data indicating the nature of other accesses include any one or more of the following: access history, frequency of requests from the access source ID to the access resource ID, time of day (or time) of access, session key method, importance of the access resource to the requesting subject, traffic level such as bandwidth usage, degree of network abnormality during access, traffic encryption strength, and various data related to authentication. Various data related to authentication include any one or more of the following: various authentication methods (including, for example, information on authentication strength), device authentication results, application authentication results, various authentication times, and the number of various authentication failures. The importance of the access resource to the requesting subject indicates the usability of access, and bandwidth usage indicates the possibility of performance degradation when controlling multiple accesses. However, the elements listed above are merely examples, and elements indicating attributes are not limited to these.
[0021] The "attribute information" may also include information necessary to determine an action to be taken on a target resource when the target resource is not being accessed. In this case, the "attribute information" may include, for example, elements of the information about the accessed resource shown in (2).
[0022] In this disclosure, a "combination of multiple attributes" means that there are multiple elements listed above. For example, assume that X, Y, and Z are attributes, and assume that X1 and X2 are elements with different values of the same attribute X, Y1 and Y2 are elements with different values of the same attribute Y, and Z1 and Z2 are elements with different values of the same attribute Z. In this case, the "combination of multiple attributes" corresponds to any set from among "X1, Y1," "X1, Z1," "Y1, Z1," "X1, Y2," ... "X1, Y1, Z1," ... "X2, Y2, Z2." The attribute information indicates any of these sets (i.e., a combination of multiple specific elements).
[0023] In this disclosure, "logic" refers to any entity that can be operated on a computer. Logic links attribute information with an action corresponding to the attribute information. Logic includes, for example, policies, algorithms, and models learned by machine learning techniques. Logic may also be referred to as, for example, a decision device.
[0024] When the logic is a policy, the policy associates attribute information with actions corresponding to the attribute information (for example, as a table). A computer can identify an action corresponding to certain attribute information by referring to the policy. When the logic is an algorithm or a trained model, a computer can obtain an action output from the logic by inputting attribute information into the logic.
[0025] The trained model may include, for example, a neural network. Furthermore, such a model may be generated using a deep learning technique and include layers such as a feature extraction layer and a fully connected layer.
[0026] In this disclosure, an "action" refers to any automatic or manual process performed on a target resource. Examples of actions include encrypting the target resource, moving the target resource to a secure area or a non-secure area, deleting the target resource, etc. When access is attempted to the target resource, the action may be defined as granting, denying, or conditionally granting (requiring additional authentication) access to the target resource.
[0027] In the present disclosure, "accessibility" is information indicating at least whether an action for access corresponds to authorization or denial, or the degree to which it corresponds to authorization or denial (e.g., a score). For example, accessibility may be information indicating whether it corresponds to authorization or denial, or may be information indicating whether it corresponds to authorization, denial, or conditional authorization (additional authentication request). Accessibility may also be indicated as a numerical value within a predetermined range. In this case, a numerical value at one end of the predetermined range corresponds to authorization, a numerical value at the other end of the predetermined range corresponds to denial, and other numerical values indicate the degree of authorization or denial. However, the information indicated by "accessibility" is not limited to that shown above.
[0028] In this disclosure, "cost" refers to any constraint that arises in the use of information, such as time, capacity, or money. Examples of costs include the time required to obtain or reference information, the capacity required to store information, or pay-per-use charges.
[0029] Embodiment 1 [Configuration Description] 1 is a block diagram showing an example of an information processing system according to the present disclosure. The information processing system 10 includes an analysis unit 12 and an identification unit 14. Each unit of the information processing system 10 will be described below.
[0030] The analysis unit 12 performs an analysis on a first logic that links the first attribute information with a first action corresponding to the first attribute information and candidate attribute information. The first attribute information includes one attribute or a combination of multiple attributes. The candidate attribute information includes, for example, one or multiple sets of attribute information that can be used in place of the first attribute information.
[0031] For example, the analysis unit 12 may perform analysis by applying, to the first logic, attribute information that can be applied directly to the first logic instead of the first attribute information, among the candidate attribute information. For example, if the first logic is a policy, the analysis unit 12 identifies an action corresponding to the attribute information by referring to the policy. If the first logic is an algorithm or a trained model, the analysis unit 12 inputs attribute information into the logic, thereby acquiring an action output from the logic.
[0032] The analysis unit 12 may change the format of attribute information candidates that cannot be directly applied to the first logic instead of the first attribute information so that the attribute information becomes applicable to the first logic. Then, the analysis unit 12 performs analysis by applying the changed attribute information to the first logic. The application of attribute information to the first logic is as described above. In this way, the analysis unit 12 obtains, as the analysis result, information on the action to be determined or output by the first logic.
[0033] The identification unit 14 identifies a second logic that links the second attribute information with a second action corresponding to the second attribute information, based on the analysis result of the analysis unit 12. Here, the identification unit 14 may select one or more sets of attribute information from candidate attribute information and set the selected attribute information as the second attribute information. Alternatively, the identification unit 14 may change the format of one or more sets of attribute information selected from the candidate attribute information and set the changed attribute information as the second attribute information. Note that the identification unit 14 may generate the second attribute information by combining any attributes across multiple sets from multiple sets of attribute information selected from the candidate attribute information.
[0034] Furthermore, the identification unit 14 determines a second action using information about the action, which is the analysis result acquired by the analysis unit 12. The identification unit 14 determines the second action using part or all of the information about the analysis result. The identification unit 14 can determine whether or not to weight some of the actions in the analysis result, or the degree of weighting. Details of this will be described later in the second embodiment. The second action may be the same as or different from the first action.
[0035] The identification unit 14 identifies a second logic that associates the second attribute information with the second action. Here, the second logic may be in the same format as the first logic. For example, the first logic and the second logic may both be a policy, an algorithm, or a learned model. However, the second logic may be in a format different from the first logic. For example, if the first logic is a policy, an algorithm, or a learned model, the second logic may be in a format that does not correspond to the first logic, among the policy, algorithm, and learned model.
[0036] The identification unit 14 identifies the second logic based on at least one of the difference between the determination result based on the first logic and the determination result based on the second logic and the additional cost incurred by using the second attribute information instead of the first attribute information. The additional cost is the cost incurred when the cost for acquiring the first attribute information is subtracted from the cost for acquiring the second attribute information. The definition of "cost" is as described above. For example, the additional cost is the additional time, capacity, or pay-per-use charge required to acquire the second attribute information compared to acquiring the first attribute information. If the acquisition cost of the second attribute information is lower than the acquisition cost of the first attribute information, the additional cost may be expressed as a negative value.
[0037] For example, the identification unit 14 may identify the second logic so that the difference is minimized, or may identify the second logic so that the difference is equal to or less than a predetermined standard. Here, the difference refers to the difference between the corresponding action in the first logic and the corresponding action in the second logic, for each piece of attribute information that is commonly applicable to the first logic and the second logic, taking into consideration all of the attribute information. The identification unit 14 may calculate the difference by simply adding up the differences related to each piece of attribute information. Alternatively, the identification unit 14 may calculate the difference by arbitrarily weighting one or more specific differences among the differences related to each piece of attribute information.
[0038] As another example, the specifying unit 14 may specify the second logic so that the additional cost is minimized, or may specify the second logic so that the additional cost is equal to or less than a predetermined standard.
[0039] Furthermore, the identification unit 14 may identify the second logic using both the difference and the additional cost. For example, the identification unit 14 may identify the second logic such that the difference is equal to or smaller than a predetermined standard and the additional cost is equal to or smaller than a predetermined standard.
[0040] [Flow description] 2 is a flowchart showing an example of a representative process of the information processing system 10. This flowchart explains the process of the information processing system 10. Note that the details of each process are as described above, and therefore will not be explained as appropriate.
[0041] First, the analysis unit 12 executes an analysis of the first logic and the candidate attribute information (step S12). Then, the identification unit 14 identifies the second logic that links the second attribute information and the second action corresponding to the second attribute information based on the analysis result of step S12 (step S14).
[0042] [Effect description] As described above, the identification unit 14 identifies the second logic by using at least one of the difference between the determination results obtained by different logics and the additional cost associated with a change in attribute information. Therefore, the identification unit 14 can eliminate second logics that result in a large difference between the determination results or a large additional cost, thereby creating a decision logic for an action that can be applied to a real environment.
[0043] Furthermore, the specification unit 14 specifies the second logic according to both the difference and the additional cost, so that the action decision logic can be made more easily applicable to the real environment.
[0044] The information processing system 10 may be configured as a single computer device, or may be configured as a distributed system having multiple computer devices. In a distributed system, the processing executed by the information processing system 10 can be shared and executed by multiple computer devices. In other words, the analysis unit 12 and the identification unit 14 may be distributed and installed on two or more computer devices.
[0045] In each of the following embodiments, a specific example of the information processing system 10 described in the first embodiment will be disclosed. However, the specific example of the information processing system 10 described in the first embodiment is not limited to the one shown below. Furthermore, the configurations and processes described below are merely examples, and are not limited to these.
[0046] Embodiment 2 [Configuration Description] 3 is a block diagram showing an example of an access management system according to the present disclosure. The access management system 20 includes a policy engine 22, an output unit 24, and a reception unit 26. The access management system 20 is, for example, a PDP (Policy Decision Point) in a zero trust network. Each unit of the access management system 20 is controlled by a hardware controller (not shown).
[0047] The policy engine 22 is an engine that generates an alternative access control policy when the original access control policy P1 cannot be used in the actual environment. Specifically, it is assumed that attribute information of the access attributes that are originally applicable to the access control policy P1 cannot be obtained in the actual environment. Hereinafter, the "access control policy" will also be simply referred to as a "policy." Furthermore, the attribute information that is originally applicable to the policy P1 will also be referred to as "attribute information P1."
[0048] The policy engine 22 includes an inference unit 222, a method selection unit 224, and an evaluation unit 226. Each unit of the policy engine 22 will be described below.
[0049] The inference unit 222 acquires attribute information AT, which is attribute information that can be acquired in the real environment, and relationship information RE. The relationship information RE is information that indicates the relationship between the attribute information AT and the attribute information P1. Note that the attribute information AT may be a part of the attribute information that can be acquired in the real environment.
[0050] For example, let us assume that the access resources subject to policy P1 are stored on a server within the premises of a company. Within this premises, there are workplaces for various departments of the company. In this example, the departments are the production department, the accounting department, and the development department.
[0051] In this example, attribute information P1 indicates an element that identifies a company department (access source department) and an element that identifies the possibility of communication tampering. On the other hand, attribute information AT indicates an element that identifies the location (physical location) of the access source. The location of the access source may, for example, identify the floor of the building in which the department is located or an individual business location. Note that attribute information AT may also be another element that uniquely identifies the location of the access source, such as an IP address. Even in such a case, the inference unit 222 can identify the location of the access source using attribute information AT based on information indicating the correspondence between the IP address and the location of the access source.
[0052] In this case, the relationship information RE may be information that associates the department-specific information and information indicating the possibility of communication tampering with the location of the access source. For example, the relationship information RE defines {"Business Site A": 0.9, "Business Site B": 0.1, "Floor C": 0,...} corresponding to ("Production Department", "No Possibility of Tampering"). Also, the relationship information RE defines {"Business Site A": 0.1, "Business Site B": 0.1, "Floor C": 0.1,...} corresponding to ("Development Department", "Possibility of Tampering"). Here, Business Site A, Business Site B, Floor C... indicate locations within the premises, and the numbers associated with each location are the probability (or weight in weighting) that each location applies. In addition, when business establishment A is associated as a specific location with department-specific information and information indicating the possibility of communication tampering, a probability of "1" is associated only with business establishment A, as in {"Business establishment A": 1, "Business establishment B": 0, "Floor C": 0,...}, and a probability of "0" is associated with other locations.
[0053] The relationship information RE may define information indicating the possibility of tampering with department-specific information and communications, corresponding to the location of a specific access source. For example, the relationship information RE may define {"Development department, tampering possibility": 0.3, "Production department, tampering possibility": 0.1, ...} corresponding to (Business site A). Here, the numbers associated with each set of information indicating the possibility of tampering with department-specific information and communications are the probability (or weight in weighting) that each set of information applies.
[0054] The access management system 20 may generate the attribute information AT by verifying in advance what kind of attribute data will be collected in the real environment for access control decisions before acquiring actual data in the real environment. The relationship information RE may be input in advance by a user via the reception unit 26, or may be automatically generated by the access management system 20. The relationship information RE is stored in a memory unit (not shown) of the access management system 20, and the inference unit 222 refers to it as needed to execute the above-mentioned inference process.
[0055] The inference unit 222 determines whether or not the attribute information P1 is included in the attribute information AT by referring to the policy P1. If the attribute information P1 is included in the attribute information AT, the inference unit 222 determines to apply the attribute information P1 included in the attribute information AT to the policy P1.
[0056] However, in this example, the attribute information P1 and the attribute information AT are different information, so the inference unit 222 determines that the attribute information P1 is not included in the attribute information AT. In other words, it is determined that the attribute information P1 cannot be directly acquired in the real environment. In response to this determination result, the inference unit 222 applies the relationship information RE to the attribute information AT to perform inference, thereby deriving data for all attribute information P1 that is expected in the real environment. Here, the inference unit 222 assigns a weight in the weighting as an inference result to each piece of expected attribute information P1 (hereinafter also referred to as expected attribute). This weight is calculated by the inference unit 222 based on the probability defined in the relationship information RE, and is a value that is proportional to or corresponds to the probability that each expected attribute can take.
[0057] For example, as in the above example, attribute information P1 is information indicating elements that identify the department from which the access originates and elements that identify the possibility of communication tampering, and attribute information AT is information that indicates elements that identify the location of the access origin. Relationship information RE is information that associates attribute information P1 with attribute information AT. In this case, the inference unit 222 acquires information indicating the assumed attributes and their weights, such as ("production department", "no possibility of tampering"): 0.9, ("accounting department", "no possibility of tampering"): 0.01, and ("production department", "possibility of tampering"): 0.2.
[0058] In this way, even if the attribute information P1 cannot be acquired, the inference unit 222 can obtain the assumed attribute and weight corresponding to the attribute information P1 by using the attribute information AT that can be acquired. Therefore, as will be described later, the evaluation unit 226 can use this inference result to derive information on an action that is considered appropriate for the assumed attribute.
[0059] The relationship information RE may be information that completely indicates the correspondence between the department-specific information and the information indicating the possibility of communication tampering, and the location of the access source, or information that does not partially indicate the correspondence (incomplete information). Even when using such relationship information RE, the inference unit 222 can perform inference to obtain the assumed attribute and weight corresponding to the attribute information P1.
[0060] The inference unit 222 can execute the above-described inference process by using, for example, the following software techniques. For example, as is widely known, the inference unit 222 may execute the inference process by applying classical logic as rules to the configuration information and executing deterministic transformation. Other examples of the inference process performed by the inference unit 222 include concept transformation using fuzzy logic, concept transformation between attributes using Word2vec, concept transformation using LLMs (Large Language Models), language inference using the configuration information and LLMs, and building an inference model using machine learning. Techniques such as decision trees, rule extraction, linear regression, multilayer perceptrons, and SVMs (Support-Vector Machines) may be used to build the inference model.
[0061] After the evaluation unit 226 evaluates each assumed attribute, the method selection unit 224 adjusts the evaluation method to be executed for all evaluated assumed attributes in accordance with a user instruction via the reception unit 26. For example, the method selection unit 224 may be configured to be able to select from a plurality of preset evaluation methods. In accordance with a user instruction, the method selection unit 224 changes the evaluation method executed by the evaluation unit 226 from a first evaluation method to a second evaluation method. As another example, the method selection unit 224 may be configured to be able to change parameters of the evaluation method. In accordance with a user instruction, the method selection unit 224 changes the parameters of the evaluation method executed by the evaluation unit 226.
[0062] For example, the user may set the method selection unit 224 via the reception unit 26 so that, for each action indicated by all evaluated assumed attributes, an action that is to be denied is weighted more heavily than the other actions. The evaluation unit 226 tallies (e.g., adds up) the scores indicating whether or not each action is accessible, with the weight set by the method selection unit 224 being assigned to the action of each assumed attribute, and calculates the average of the scores. As a result, the score that is the evaluation result of the evaluation unit 226 approaches the score for "deny," and therefore the action that is the evaluation result is more likely to be "deny."
[0063] Furthermore, when the evaluation unit 226 determines an action based on the score of the evaluation result, the method selection unit 224 may change the score threshold for determining whether to approve or deny, in response to a user instruction via the reception unit 26. For example, assume that the score takes a value between 0 and 1, with "1" meaning approve and "0" meaning deny. Assume that the determination threshold is 0.8. In this case, the evaluation unit 226 evaluates the action as "approved" if the score is 0.8 or higher, and evaluates the action as "denied" if the score is less than 0.8. In this case, the method selection unit 224 may change the determination threshold from 0.8 to 0.9 in response to a user instruction. This makes it easier for the evaluation unit 226 to evaluate the action as "denied," resulting in access control that places even more emphasis on security than on convenience.
[0064] The determination threshold may be the same regardless of the type of attribute information, or may be different depending on the type. For example, different determination thresholds may be set depending on information such as the department or location of the access source. The method selection unit 224 may then change the determination threshold for a specific type of attribute information in response to a user instruction via the reception unit 26.
[0065] As described above, the evaluation unit 226 determines an action such as "approval" or "denial" by comparing the score of the evaluation result with the judgment threshold. However, the method selection unit 224 may set an exception condition so that the evaluation unit 226 determines a specific action such as "approval" or "denial" regardless of the score of the evaluation result. For example, if the department from which the access originates is a specific business establishment, "approval" may be set as the action regardless of the score. The method selection unit 224 may set or change such an exception condition in the evaluation by the evaluation unit 226 in response to an instruction from the user via the reception unit 26.
[0066] The evaluation unit 226 applies each expected attribute to the policy P1 individually (or in parallel) to obtain information on the score of the action corresponding to each expected attribute. Here, the evaluation unit 226 may obtain information such as "approval" or "denial" as the action corresponding to each expected attribute. In this way, the evaluation unit 226 evaluates each expected attribute.
[0067] Thereafter, the evaluation unit 226 calculates a score for the action corresponding to the attribute information AT of the real environment, taking into consideration the weighting for each assumed attribute set by the inference unit 222. For example, the evaluation unit 226 may calculate an arithmetic mean of the scores corresponding to each assumed attribute with the weighting applied. Alternatively, the evaluation unit 226 may calculate a score by further reflecting the weighting set by the method selection unit 224 as described above. In this way, the evaluation unit 226 comprehensively evaluates all assumed attributes.
[0068] Thereafter, the evaluation unit 226 evaluates the action corresponding to the attribute information AT using the calculated score of the action and at least one of the judgment threshold or the exception condition derived from the evaluation method selected by the method selection unit 224. For example, if a score of "1" means approval and "0" means rejection, and the calculated score of the action is 0.8 and the judgment threshold is 0.9, the evaluation unit 226 will "reject" the action corresponding to the attribute information AT.
[0069] However, the evaluation unit 226 may evaluate actions by extracting some of the scores of actions corresponding to each expected attribute and performing the above calculations on the extracted scores. The some scores may fall within a predetermined range defined using at least one of an arbitrary minimum value and a maximum value. Alternatively, the some scores may fall within a range that is above or below a predetermined quantile of statistics.
[0070] As another example, the evaluation unit 226 may use a machine learning model to evaluate actions. This model is trained by inputting, for example, training data including multiple sets of distributions of scores of sample actions and information indicating scores to be extracted as correct labels. After this training, information on the scores of actions corresponding to each expected attribute is input to the model. The model outputs information on scores to be extracted corresponding to this input information. In this way, the evaluation unit 226 can use a classification model to classify scores to be extracted.
[0071] Furthermore, the evaluation unit 226 generates a new policy that defines the relationship between the attribute information AT and the action evaluated as the action corresponding to the attribute information AT. This new policy replaces policy P1 and is applicable to the real environment. The evaluation unit 226 may generate the new policy using any algorithmic method. Alternatively, the evaluation unit 226 may generate the new policy by building a model using machine learning using any method.
[0072] The inference unit 222 to the evaluation unit 226 perform the above process not only for the attribute information AT but also for all combinations of attributes that can be acquired in the real environment (i.e., attribute information other than the attribute information AT). For example, if the attribute information AT indicates an element that identifies the location of the access source, the inference unit 222 to the evaluation unit 226 can perform the above process for information that indicates an element that identifies the location of the access source other than the attribute information AT. All combinations of attributes that can be acquired in the real environment are candidate attribute information that can be selected by the evaluation unit 226. Then, the evaluation unit 226 calculates the difference between the judgment result of each policy generated for all the attribute information processed and the judgment result of policy P1. The judgment result is information consisting of a bundle of at least one of policy-based actions or scores aggregated for each attribute information. Furthermore, the evaluation unit 226 calculates the additional cost incurred by using attribute information required for each generated policy (attribute information AT in the above example) instead of the attribute information used in policy P1.
[0073] For example, the evaluation unit 226 may identify a pair of newly generated policies and attribute information required for the policies that fall within a predetermined ranking when the calculated difference and additional cost are sorted in ascending order. Furthermore, the evaluation unit 226 may further satisfy a condition that the calculated difference is equal to or less than a predetermined threshold Th1 and the additional cost is equal to or less than a predetermined threshold Th2. In this example, the evaluation unit 226 selects policy P2 and attribute information AT as satisfying the condition.
[0074] Detailed examples of additional costs are explained below, showing (i) to (iii). (i) Assume that attribute information P1 includes an element for identifying the access source department, an element for identifying the possibility of communication tampering, and an element for an access resource ID, and attribute information AT includes an element for identifying the location of the access source and an element for an access resource ID. In this case, the access management system 20 needs to acquire attribute information P1, i.e., to identify the access source department and the possibility of communication tampering, an authentication process for the access source is required. Therefore, the acquisition cost for acquiring attribute information P1 is V1, which is a high positive value. On the other hand, the acquisition cost for the access management system 20 to acquire attribute information AT (i.e., to identify the location of the access source) is 0 or a very low positive value V2. This is because the access management system 20 (or a device managed by the access management system 20) is an access control device, and information about the location of the access source is considered to be known information for the access control device. Therefore, in this case, the additional cost incurred by using attribute information AT instead of attribute information P1 is V2-V1, which is a negative value with a large absolute value.
[0075] In the case of (i), the evaluation unit 226 determines that the calculated additional cost is equal to or less than a predetermined threshold Th2 (for example, 0). Therefore, if the difference between the policy P2 created using the attribute information AT and the policy P1 is within an allowable range (for example, equal to or less than a predetermined threshold Th1), the evaluation unit 226 selects the policy P2 and attribute information AT corresponding to (i).
[0076] (ii) Assume that attribute information P1 includes an element identifying the access source department, an element identifying the possibility of communication tampering, and an element of an access resource ID, and attribute information AT includes an element indicating the location of the access source, an element indicating the behavioral abnormality level, and an element of an access resource ID. In this case, the access management system 20 needs to acquire additional attribute information, "behavioral abnormality level," which was not previously implemented. Therefore, the acquisition cost for the access management system 20 to acquire the attribute information AT is a positive value V3. However, the "behavioral abnormality level" can be derived by calculation within the access management system 20 and is relatively easy to acquire compared to information based on the authentication process. Therefore, the acquisition cost V3 is a low value. In contrast, as shown in (i), the acquisition cost V1 of attribute information P1 is a high positive value. Therefore, in this case, the additional cost incurred by using attribute information AT instead of attribute information P1 is V3-V1, which is a negative value.
[0077] In the case of (ii), compared to the case of (i), the attribute information AT includes a "degree of behavioral abnormality." Therefore, the difference between policy P2 created using the attribute information AT and policy P1 may be smaller in (ii) than in (i). Therefore, while the policy difference in (i) is not equal to or less than the predetermined threshold Th1, it is possible that the policy difference in (ii) is equal to or less than the predetermined threshold Th1. In this case, if the calculated additional cost in (ii) is equal to or less than the predetermined threshold Th2, the evaluation unit 226 can select policy P2 and attribute information AT corresponding to (ii) rather than (i).
[0078] (iii) Depending on the situation, the additional cost incurred by using attribute information AT instead of attribute information P1 may be a positive value. Here, if the additional cost is greater than a predetermined threshold Th2 (e.g., 0), the evaluation unit 226 does not select policy P2 and attribute information AT. However, if the additional cost is equal to or less than the predetermined threshold Th2 (>0) and the difference between the policies is equal to or less than a predetermined threshold Th1, the evaluation unit 226 may select policy P2 and attribute information AT.
[0079] The output unit 24 is an interface and outputs at least one of the calculated action score or action information corresponding to the attribute information AT. The output unit 24 may also output the newly generated policy. The output unit 24 may output the above information to, for example, a PEP (Policy Enforcement Point), which is an entity that executes zero-trust access control. This enables the PEP to perform access control in the real environment based on the determined action or the newly generated policy. Alternatively, the output unit 24 may notify the user of the information by outputting the above information to a notification unit connected to the access management system 20. The notification may be realized, for example, by displaying the information on a display unit such as a display, or by audio notification using a speaker or the like.
[0080] The reception unit 26 is an interface for input such as a touch panel, a keyboard, etc. The user can input the related information RE and set the method selection unit 224 via the reception unit 26.
[0081] FIG. 4 shows an example of a data flow when the policy engine 22 determines an action based on attribute information of the real environment. First, when attribute information AT is given, the inference unit 222 determines that attribute information P1 is not included in the attribute information AT. Based on this determination result, the inference unit 222 derives data for all assumed attributes. The inference unit 222 also assigns weights to each assumed attribute. In FIG. 4, the derived assumed attributes are represented as assumed attributes 1, 2, 3, etc., and the weights assigned to each assumed attribute are represented as μ1, μ2, μ3.
[0082] The evaluation unit 226 applies each assumed attribute to the policy P1, thereby executing judgments 1, 2, 3, etc. for each assumed attribute. The evaluation unit 226 then obtains scores 1, 2, 3, etc., which are scores for each assumed attribute. The evaluation unit 226 determines an action corresponding to the attribute information AT using each obtained score and information such as the evaluation method and exception conditions determined by the method selection unit 224. The evaluation unit 226 then generates a new policy P2 using the attribute information AT and the determination action. The generated policy P2 is output by the output unit 24.
[0083] [Flow description] 5 is a flowchart showing an example of a typical process of the access management system 20. This flowchart explains the process of the access management system 20. Note that the details of each process are as described above, and therefore will not be explained further.
[0084] First, in response to a user instruction, the method selection unit 224 adjusts the evaluation method and exception conditions for policy P1 to be executed by the evaluation unit 226 (step S22). The inference unit 222 acquires attribute information that can be acquired in the real environment (step S24). The inference unit 222 derives all expected attributes that can be applied to policy P1 by inference based on the attribute information acquired in step S24 (step S26). Note that the process of step S22 and the process of step S24 or S26 may be executed first, or both processes may be executed in parallel.
[0085] The evaluation unit 226 individually evaluates each assumed attribute derived in step S26 by applying each assumed attribute to the policy P1 (step S28). Then, the evaluation unit 226 comprehensively evaluates all assumed attributes by calculating a score using the evaluation of each assumed attribute derived in step S28 (step S30). The evaluation unit 226 evaluates the action using the information set in step S22, and also generates a new policy. The output unit 24 outputs the generated action and new policy (step S32).
[0086] [Effect description] In the zero trust access control that has been developed in recent years, a management system determines whether to allow access to an access resource by comprehensively considering various attribute information related to the access. The management system determines whether to allow access regardless of whether the access is made from inside or outside the network, allowing trusted access and denying untrusted access. Therefore, it is possible to achieve both secure and available communications even when using a network that includes untrusted nodes.
[0087] A management system can determine whether or not to allow access by using a policy, for example. However, depending on the actual environment, it is possible that the management system may not be able to obtain the attribute information necessary to make a decision using the policy. Furthermore, even if a new policy is created, it may be difficult to actually apply the policy.
[0088] The access management system 20 can solve the above-mentioned problems. Specifically, instead of using the initially set policy as is, the access management system 20 creates a new policy by using currently obtainable attribute information of the real environment and relationship information indicating correspondences. From a best-effort perspective, the new policy is considered to be a policy that is similar to the initially set policy. In other words, it is expected that the actions presented when the new policy is used will be the same as or similar to the actions presented when the initially set policy is used.
[0089] For example, assume that user authentication information is used as attribute information in policy P1, which is a preset policy. If the authentication system that provides the authentication information fails, it is considered inappropriate from the standpoint of availability for the access management system 20 to uniformly restrict access while taking communication security into consideration. Therefore, the access management system 20 creates a new policy P2 in place of policy P1 and configures it to use the new attribute information instead of the authentication information. As described above, policy P2 has behavior similar to that of the preset policy P1. Furthermore, because policy P2 is created to be as similar as possible to the behavior of policy P1, the attribute information used in policy P2 is also expected to have properties similar to those of the authentication information. Therefore, the access management system 20 can ensure communication security and availability as much as possible when using a preset policy.
[0090] Furthermore, the evaluation unit 226 evaluates actions associated with each expected attribute using the expected attribute inferred by the inference unit 222 and the policy P1, and identifies actions for generating the policy P2 using all the evaluated actions. In this way, the evaluation unit 226 can make the policy P2 more similar to the policy P1 by evaluating all the actions.
[0091] Furthermore, since the user can set the method selection unit 224 via the reception unit 26, the newly generated policy can be made closer to the desired one.
[0092] Furthermore, the access management system 20 executes the above process when attribute information used in a preset policy cannot be acquired in the real environment. Therefore, if processing is not required so that attribute information used in the policy can be acquired in the real environment, the access management system 20 does not need to execute the processing. This reduces the amount of calculations performed by the access management system 20.
[0093] Embodiment 3 In the following third embodiment, a variation of the access management system 20 described in the second embodiment will be disclosed. However, the variations of the access management system 20 are not limited to those described below.
[0094] [Configuration Description] Fig. 6 is a block diagram showing an example of an access management system according to the present disclosure. Compared to the access management system 20 shown in Fig. 3, the access management system 30 is newly provided with an inference compression unit 228 and an explanation unit 28. Each unit of the access management system 30 is controlled by a hardware controller (not shown). Below, explanations of points already explained in the actual embodiment 2 will be omitted as appropriate, and components and processes unique to the embodiment 3 will be particularly explained.
[0095] The inference compression unit 228 can execute at least one of the following processes. By using the relationship information RE, the inference compression unit 228 sets the attribute information inferred by the inference unit 222 to be a portion of all the expected attribute information, rather than all the expected attribute information. For example, when the inference compression unit 228 analyzes a plurality of pieces of attribute information and determines that they can be compressed into one piece of attribute information, it may execute a process of compressing the plurality of pieces of attribute information into one piece of attribute information. In this way, by limiting the range of elements of the attribute information inferred by the inference unit 222, it is possible to reduce the amount of calculation by the evaluation unit 226.
[0096] For example, assume that the attribute information includes an element that identifies the access source department and an element that indicates whether or not the communication may have been tampered with. The access source departments include the production department, the accounting department, and the development department. In this case, there would originally be six patterns of attribute information, but the inference compression unit 228 may reduce the number of patterns of attribute information by integrating multiple similar patterns into one representative pattern. For example, the inference compression unit 228 may aggregate the six patterns into three patterns: ("production department", "no possibility of tampering"), ("accounting department", "no possibility of tampering"), and ("production department", "possibility of tampering").
[0097] Note that, for example, when there are multiple production departments but they can be combined into one production department, the inference compression unit 228 may combine the production departments in the attribute information into one. This makes it possible to reduce the amount of calculation by the evaluation unit 226. Furthermore, when there are common or similar characteristics between multiple different departments (for example, when multiple departments are departments related to a common client), the inference compression unit 228 may combine the multiple departments into one.
[0098] As another example, the inference compression unit 228 may adjust the weight assigned by the inference unit 222 to each assumed attribute. For example, the inference compression unit 228 may set the weight assigned to one or more specific assumed attributes to 0. In particular, if the weight (μ in FIG. 4) assigned by the inference unit 222 is equal to or less than a predetermined threshold, the inference compression unit 228 may set the weight to 0. Alternatively, the inference compression unit 228 may delete assumed attributes other than those to be calculated by the evaluation unit 226. In this way, the inference compression unit 228 can reduce the amount of calculation by the evaluation unit 226 by also limiting the range of actions to be evaluated by the evaluation unit 226.
[0099] The user may input information for adjusting the above-described processing content executed by the inference compression unit 228 via the reception unit 26. In this way, the user can arbitrarily adjust the degree of inference compression (reduction of the amount of calculation).
[0100] The inference compression unit 228 can execute the above-described process by using, for example, the following software techniques. For example, the inference unit 222 can execute any fitting process (e.g., learning of transformation examples) using a machine-learned regression model, selection of weighted representative points, analysis using a sparse graph representation, inference processing using a model learned by reinforcement learning, and the like. For example, the inference compression unit 228 can exclude expected attributes other than those with weights equal to or less than a predetermined threshold from the evaluation target of the evaluation unit 226 by selecting weighted representative points or performing analysis using a sparse graph representation. The inference compression unit 228 can compress and improve the efficiency of calculations by narrowing down the calculation targets to important elements using such heuristic techniques.
[0101] The explanation unit 28 can notify the user of at least one of the following items, for example. The explanation unit 28 can explain to the user the difference between the judgment result of policy P2 identified by the evaluation unit 226 and the judgment result of the original policy P1 by displaying it on a display unit or the like connected to the access management system 20 or by outputting it as audio from a speaker or the like. The explanation unit 28 may display the difference in the judgment results in its original format, or may display the difference in the judgment results in a categorized manner according to the type of attribute information or the like. Therefore, the user can clearly understand how similar (or different) policy P2 is to policy P1.
[0102] The explanation unit 28 may also explain the disadvantages that will occur in each of the cases of approval and denial in the determination result of policy P2. For example, the explanation unit 28 may explain the risks (e.g., a specific location of damage, an explanation of the access resources affected by the damage, and an estimated amount of damage) when the determination result is "approval." For example, the explanation unit 28 may explain information such as the specific location of damage: the storage area of the server in the production department, the access resources affected by the damage: the blueprints of a new product, and the estimated amount of damage: 100 million yen. The explanation unit 28 may also explain the risks (e.g., a specific work delay, an explanation of the inaccessible access resources, and an estimated amount of damage caused by the delay) when the determination result is "denial." Information regarding such risks may be generated, for example, by the explanation unit 28 referring to information indicating the risk corresponding to the difference based on the difference between the determination result of policy P2 and the determination result of policy P1. The information indicating the risk corresponding to the difference may be stored in a storage unit (not shown) of the explanation unit 28 or may be information input by the user via the reception unit 26.
[0103] The storage unit of the explanation unit 28 may store a first list in which attribute information and an action that should originally be set corresponding to the attribute information are associated with each piece of attribute information. The explanation unit 28 analyzes information on the difference in the determination results, and for a portion where the determination result of policy P1 is "deny" but the determination result of policy P2 is "approval," references the first list to identify one or more additional attribute information necessary to determine "deny." The explanation unit 28 then explains the identified attribute information to the user. Note that, when the explanation unit 28 determines that it is sufficient to select some attribute information from multiple candidate attribute information as the additional attribute information necessary to determine "deny," the explanation unit 28 explains this.
[0104] Furthermore, a second list in which attribute information and a user action required to acquire each piece of attribute information are associated with each piece of attribute information may be stored in the storage unit of the explanation unit 28. The explanation unit 28 may explain to the user the action to acquire the attribute information by referring to the second list for the identified attribute information.
[0105] Furthermore, a third list in which the cost of acquiring each piece of attribute information is defined may be stored in the storage unit of the explanation unit 28. Assume that the explanation unit 28 determines that selecting some attribute information from a plurality of candidate attribute information will change the action from "approval" to "denial." In this case, the explanation unit 28 may refer to the third list for the plurality of candidate attribute information, and give explanations in order of priority to attribute information with a lower cost.
[0106] In the example shown above, an example of correcting an action from "Approve" to "Deny" is described, but the same processing as above is also performed in an example of correcting an action from "Deny" to "Approve."
[0107] The explanation unit 28 may perform the explanation process by using, for example, LLMs (Large Language Models).
[0108] By referring to the information explained by the explanation unit 28, the user can input the relationship information RE, information related to the settings of the method selection unit 224, and additional attribute information to be acquired via the reception unit 26. This allows the user to adjust the newly generated policy P2.
[0109] 7 shows an example of a data flow when the policy engine 22 determines an action based on attribute information of the real environment. The difference between FIG. 7 and FIG. 4 is that the above-described processing of the inference compression unit 228 controls the evaluation unit 226 not to calculate the assumed attribute 2. For example, the inference compression unit 228 can omit the calculation of the assumed attribute 2 by setting the weight μ2 shown in FIG. 4 to 0.
[0110] [Flow description] 8A and 8B are flowcharts showing an example of a typical process of the access management system 30. This flowchart explains the process of the access management system 30. Note that a description of the same processes as those in the access management system 20 will be omitted.
[0111] The processes of steps S22 to S24 in Fig. 8A are the same as the processes of steps S22 to S24 in Fig. 5, respectively, and therefore will not be described again. The inference compression unit 228 performs settings so that at least one of the processes of the inference unit 222 or the evaluation unit 226 is reduced, for example, based on information input by the user via the reception unit 26 (step S42). Thereafter, the processes of steps S26 to S32 are executed based on the settings made in step S42. These processes are also the same as those shown in Fig. 5, and therefore will not be described again. Note that the process of step S42 and the process of step S22 or S24 may be executed first, or both processes may be executed in parallel.
[0112] The explanation unit 28 explains the difference in the judgment result due to the policy change, information on the risk arising from the policy judgment result, etc. (step S44). In response to the explanation, the access management system 30 determines whether the user has input information for the policy change via the reception unit 26 (step S46). As described above, the information for the policy change includes new relationship information RE, information related to the settings of the method selection unit 224, and additional attribute information to be acquired. If information has been input (Yes in step S46), the access management system 30 returns to step S22 and executes the process. On the other hand, if information has not been input (No in step S46), the access management system 30 ends the process. Note that the process of step S44 and the process of step S32 may be executed first, or both processes may be executed in parallel.
[0113] [Effect description] As described above, the access management system 30 can reduce the amount of calculation required to create an alternative policy by including the inference compression unit 228. Furthermore, by allowing the user to adjust the level of inference via the reception unit 26, the user can achieve a trade-off between ensuring the accuracy of the alternative policy and reducing the amount of calculation.
[0114] Furthermore, the explanation unit 28 explains to the user the difference in the judgment result or the disadvantages that arise from the policy change, so that the user can determine whether or not to adjust the newly generated policy. Then, the user inputs information for policy adjustment via the reception unit 26, so that the user can obtain a policy that is more suitable for the actual environment.
[0115] Furthermore, the explanation unit 28 may generate risk-related information based on a difference in the judgment result that occurs as a result of a policy change. This allows the explanation unit 28 to use a smaller amount of information than when generating risk-related information by analyzing a new policy, thereby reducing the amount of calculation required for information generation.
[0116] Like the information processing system 10, the access control systems 20 and 30 may be configured as a single computer device, or may be configured as a distributed system having multiple computer devices.
[0117] In the above-described embodiments, the present disclosure has been described as a hardware configuration, but the present disclosure is not limited to this. The present disclosure can also be realized by causing a processor in a computer to execute a computer program to perform the processing of each device constituting the information processing system 10 or the access control systems 20 and 30 described in the above-described embodiments.
[0118] 9 is a block diagram showing an example of the hardware configuration of an information processing device in which processing of the system or device according to the present disclosure is executed. Referring to FIG. 9, the information processing device 90 includes a signal processing circuit 91, a processor 92, and a memory 93.
[0119] The signal processing circuit 91 is a circuit for processing signals in accordance with the control of the processor 92. The signal processing circuit 91 may include a communication circuit for receiving signals from a transmitting device.
[0120] The processor 92 is connected to the memory 93, and performs the processing of the device described in the above embodiment by reading and executing a computer program from the memory 93. As an example of the processor 92, one of a CPU (Central Processing Unit), an MPU (Micro Processing Unit), an FPGA (Field-Programmable Gate Array), a DSP (Demand-Side Platform), and an ASIC (Application Specific Integrated Circuit) may be used, or a plurality of these may be used in parallel.
[0121] The memory 93 is configured with a volatile memory, a nonvolatile memory, or a combination thereof. The memory 93 is not limited to one, and multiple memories may be provided. The volatile memory may be, for example, a RAM (Random Access Memory) such as a DRAM (Dynamic Random Access Memory) or an SRAM (Static Random Access Memory). The nonvolatile memory may be, for example, a ROM (Read Only Memory) such as a PROM (Programmable Random Only Memory) or an EPROM (Erasable Programmable Read Only Memory), a flash memory, or an SSD (Solid State Drive).
[0122] The memory 93 is used to store one or more instructions. Here, the one or more instructions are stored as programs in the memory 93. The processor 92 can perform the processes described in the above embodiments by reading and executing these programs from the memory 93.
[0123] The memory 93 may include memory built into the processor 92 in addition to memory provided outside the processor 92. The memory 93 may also include storage located away from the processors constituting the processor 92. In this case, the processor 92 can access the memory 93 via an I / O (Input / Output) interface.
[0124] As described above, one or more processors included in each system or device in the above-described embodiments execute one or more programs including instructions for causing a computer to execute the algorithms described using the drawings. Execution of the programs enables the information processing described in each embodiment to be realized.
[0125] The program includes instructions or software code that, when loaded into a computer, causes the computer to perform one or more functions described in the embodiments. The program may be stored in a non-transitory computer-readable medium or a tangible storage medium. By way of example and not limitation, computer-readable media or tangible storage media include random-access memory (RAM), read-only memory (ROM), flash memory, solid-state drive (SSD) or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disk (DVD), Blu-ray disc or other optical disk storage, magnetic cassette, magnetic tape, magnetic disk storage or other magnetic storage devices. The program may also be transmitted on a transitory computer-readable medium or communication medium. By way of example and not limitation, transitory computer-readable media or communication media include electrical, optical, acoustic, or other forms of propagated signals. The transitory computer-readable medium or communication medium may provide the program to the computer via a wired communication path, such as electrical wires and optical fibers, or via a wireless communication path.
[0126] Some or all of the above embodiments may also be described as, but are not limited to, the following supplementary notes. Also, some or all of the elements (e.g., configurations and functions) described in supplementary notes 2 to 10 that are dependent on supplementary note 1 may also be dependent on supplementary notes 11 and 12 in the same dependent relationship as supplementary notes 2 to 10. In this way, some or all of the elements described in any supplementary note may be applied to various hardware, software, recording means for recording software, systems, and methods. (Appendix 1) an analysis unit that analyzes a first logic that links first attribute information with a first action corresponding to the first attribute information and candidates for the attribute information; an identification unit that identifies a second logic that links second attribute information and a second action corresponding to the second attribute information based on an analysis result of the analysis unit; the identification unit identifies the second logic according to at least one of a difference between a determination result based on the first logic and a determination result based on the second logic and an additional cost incurred by using the second attribute information instead of the first attribute information. Information processing system. (Appendix 2) the specifying unit specifies the second logic according to both the difference and the additional cost. 10. The information processing system of claim 1. (Appendix 3) The information processing system includes: a notification unit that notifies at least one of the difference or a disadvantage that occurs when the second logic is used instead of the first logic; and a receiving unit that receives adjustment information for adjusting the second logic from a user. 3. The information processing system according to claim 1 or 2. (Appendix 4) the identifying unit evaluates, based on the difference, a disadvantage caused by using the second logic instead of the first logic. An information processing system according to any one of appendices 1 to 3. (Appendix 5) the analysis unit infers an element of the first attribute information using the candidate attribute information; the identification unit evaluates the first actions associated with the element using the inferred element and the first logic, and identifies the second action using all the evaluated first actions, thereby identifying the second logic. An information processing system according to any one of appendices 1 to 4. (Appendix 6) The information processing system includes: a receiving unit that receives, from a user, adjustment information for adjusting a method for identifying the second action using all of the evaluated first actions, 6. The information processing system according to claim 5. (Appendix 7) The information processing system includes: a limiting unit that limits at least one of a range of elements of the first attribute information to be inferred using the candidate attribute information or a range of the first action to be evaluated, 7. An information processing system according to claim 5 or 6. (Appendix 8) The information processing system includes: a reception unit that receives, from a user, adjustment information for adjusting the restriction method of the restriction unit, 8. The information processing system of claim 7. (Appendix 9) when determining that the first attribute information cannot be acquired, the analysis unit performs the analysis using acquireable candidates of the attribute information. An information processing system according to any one of appendices 1 to 8. (Appendix 10) the first logic and the second logic are access control policies; An information processing system according to any one of appendices 1 to 9. (Appendix 11) Analyzing first logic that links first attribute information with a first action corresponding to the first attribute information and candidates for the attribute information; identifying a second logic that links second attribute information with a second action corresponding to the second attribute information based on the analysis result, wherein the second logic is identified in accordance with at least one of a difference between a determination result based on the first logic and a determination result based on the second logic and an additional cost incurred by using the second attribute information instead of the first attribute information; A computer-implemented information processing method. (Appendix 12) Analyzing first logic that links first attribute information with a first action corresponding to the first attribute information and candidates for the attribute information; identifying a second logic that links second attribute information with a second action corresponding to the second attribute information based on the analysis result, wherein the second logic is identified in accordance with at least one of a difference between a determination result based on the first logic and a determination result based on the second logic and an additional cost incurred by using the second attribute information instead of the first attribute information; A program that makes a computer do something.
[0127] Although the present disclosure has been described above with reference to the embodiments, the present disclosure is not limited to the above-described embodiments. Various modifications that can be understood by those skilled in the art can be made to the configuration and details of the present disclosure within the scope of the present disclosure. Furthermore, each embodiment can be combined with other embodiments as appropriate. [Explanation of symbols]
[0128] 10 Information Processing Systems 12 Analysis section 14 Specification section 20, 30 Access control system 22 Policy Engine 24 Output Unit 26 Reception 28 Explanation 222 Inference section 224 Method selection section 226 Evaluation unit 228 Inference compression unit
Claims
1. an analysis unit that analyzes first logic that links first attribute information with a first action corresponding to the first attribute information and candidates for the attribute information; an identification unit that identifies a second logic that links second attribute information with a second action corresponding to the second attribute information based on an analysis result of the analysis unit; the identification unit identifies the second logic based on at least one of a difference between a determination result based on the first logic and a determination result based on the second logic and an additional cost incurred by using the second attribute information instead of the first attribute information. Information processing system.
2. the specifying unit specifies the second logic according to both the difference and the additional cost. The information processing system according to claim 1 .
3. The information processing system includes: a notification unit that notifies at least one of the difference or a disadvantage that occurs when the second logic is used instead of the first logic; a receiving unit that receives adjustment information for adjusting the second logic from a user, 3. The information processing system according to claim 1 or 2.
4. the identifying unit evaluates, based on the difference, a disadvantage caused by using the second logic instead of the first logic.
3. The information processing system according to claim 1 or 2.
5. the analysis unit infers an element of the first attribute information using the candidate attribute information; the identification unit evaluates the first actions associated with the element using the inferred element and the first logic, and identifies the second action using all the evaluated first actions, thereby identifying the second logic.
3. The information processing system according to claim 1 or 2.
6. The information processing system includes: a receiving unit that receives, from a user, adjustment information for adjusting a method for identifying the second action using all of the evaluated first actions. The information processing system according to claim 5 .
7. The information processing system includes: a limiting unit that limits at least one of a range of elements of the first attribute information to be inferred using the candidate attribute information or a range of the first action to be evaluated, The information processing system according to claim 5 .
8. The information processing system includes: a reception unit that receives, from a user, adjustment information for adjusting the restriction method of the restriction unit, The information processing system according to claim 7 .
9. when determining that the first attribute information cannot be acquired, the analysis unit performs the analysis using acquireable candidates of the attribute information.
3. The information processing system according to claim 1 or 2.
10. the first logic and the second logic are access control policies; 3. The information processing system according to claim 1 or 2.
11. Analyzing candidates for a first logic and attribute information that connects first attribute information with a first action corresponding to the first attribute information; identifying a second logic that links second attribute information with a second action corresponding to the second attribute information based on the analysis result, and identifying the second logic based on at least one of a difference between a determination result based on the first logic and a determination result based on the second logic and an additional cost that occurs due to using the second attribute information instead of the first attribute information; A computer-implemented information processing method.
12. Analyzing candidates for a first logic and attribute information that connects first attribute information with a first action corresponding to the first attribute information; identifying a second logic that links second attribute information with a second action corresponding to the second attribute information based on the analysis result, and identifying the second logic based on at least one of a difference between a determination result based on the first logic and a determination result based on the second logic and an additional cost that occurs due to using the second attribute information instead of the first attribute information; A program that makes a computer do something.
Citation Information
Patent Citations
Dynamic policy injection and access visualization for threat detection
JP2023175878A