Device, method, and program
The virtual model integrates library and equipment information with inspection results to diagnose and simulate security risks in communication systems, addressing the lack of detail in existing models.
Patent Information
- Application Number
- JP2025124928
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-07-25
- Publication Date
- 2025-10-03
AI Technical Summary
Existing virtual models of communication systems do not reveal detailed information about software vulnerabilities, making it difficult to diagnose potential attack scenarios and affected components within these systems.
A data processing device and method that generates a virtual model by associating information on libraries, vulnerabilities, and equipment configurations, allowing for detailed security risk diagnosis by integrating inspection results and hardware/software lists.
Enables detailed diagnosis and simulation of security risks in communication systems, facilitating accurate identification and mitigation of vulnerabilities.
Smart Images

Figure 2025146923000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a data processing device, a data processing method, and a recording medium, and more particularly to a data processing device, a data processing method, and a recording medium for generating a virtual model of a communication system and diagnosing security risks using the virtual model. [Background technology]
[0002] Communications systems can be subject to a variety of cyber attacks, including theft of confidential information, erasure of protected data, website tampering, virus infection, the theft of privileged IDs, or unauthorized access and manipulation of web servers.
[0003] Cyber-attacks against communication systems are carried out by exploiting flaws that arise due to malfunctions or design errors in the software (including software components, firmware, and middleware) of the devices that make up the communication systems. Such flaws are called software vulnerabilities or security holes.
[0004] Related technology uses vulnerability assessment tools, asset management tools, and the like to generate a virtual model of a communications system. Then, attack simulations using the virtual model are performed to analyze potential attack routes against the communications system. Because related technology allows attack simulations to be performed in a virtual environment, it does not affect business activities and eliminates the cost of building a physical replica environment. [Prior art documents] [Patent documents]
[0005] [Patent Document 1] Patent No. 6307453 Summary of the Invention [Problem to be solved by the invention]
[0006] The virtual models generated by the related technologies do not reveal details of software vulnerabilities, making it difficult to diagnose in detail what attack scenarios would result in attacks being successful against a communications system, and which information and communications devices that make up the communications system would be subjected to what type of attacks.
[0007] The present invention has been made in view of the above-mentioned problems, and an object of the present invention is to provide a virtual model of a communication system necessary for diagnosing security risks of the communication system in detail. [Means for solving the problem]
[0008] An apparatus according to one aspect of the present invention generates a model that associates information representing libraries included in the equipment, information representing vulnerabilities related to functions used in the libraries, and information representing the equipment from security inspection information representing the results of an information security inspection on the equipment that constitutes the system and configuration information including a hardware parts list and a software parts list, and then diagnoses security risks related to the system using the created model.
[0009] In a method according to one aspect of the present invention, a computer creates a model that associates information representing libraries included in the equipment, information representing vulnerabilities related to functions used in the libraries, and information representing the equipment from security inspection information representing the results of an information security inspection of equipment that constitutes a system and configuration information including a hardware parts list and a software parts list, and then uses the created model to diagnose security risks related to the system.
[0010] A program according to one aspect of the present invention enables a computer to perform the following functions: create a model that associates information representing libraries included in the equipment, information representing vulnerabilities related to functions used in the libraries, and information representing the equipment, based on security inspection information representing the results of an information security inspection on the equipment that constitutes the system and configuration information including a hardware parts list and a software parts list; and diagnose security risks related to the system using the created model. [Effects of the Invention]
[0011] According to one aspect of the present invention, it is possible to provide a virtual model of a communication system required for a detailed diagnosis of security risks of the communication system. [Brief explanation of the drawings]
[0012] [Figure 1] FIG. 1 is a diagram schematically illustrating an example of a communication system that is the entity of a virtual model generated by a data processing device according to any one of the first to third embodiments. [Figure 2] 1 is a block diagram showing a configuration of a data processing device according to a first embodiment. [Figure 3] 3 is a flowchart showing the operation of the data processing device according to the first embodiment. [Figure 4] 1 is a call graph that schematically shows access to a file from a component device that makes up a communication system via a function in a library. [Figure 5] 10A and 10B are diagrams showing a set of an example of configuration information indicating the components of a component device and an example of an inspection result related to the component device; [Figure 6] FIG. 1 is a diagram illustrating an example of a virtual model of a communication system. [Figure 7] FIG. 10 is a block diagram showing the configuration of a data processing device according to a third embodiment. [Figure 8] 10 is a flowchart showing the operation of the data processing device according to the third embodiment. [Figure 9]FIG. 1 is a diagram illustrating an example of a hardware configuration of a data processing device according to any one of the first to third embodiments. DETAILED DESCRIPTION OF THE INVENTION
[0013] Some embodiments of the present invention are described below with reference to the drawings.
[0014] (Communication System 1) An example of the configuration of a communication system 1 will be described with reference to Fig. 1. Fig. 1 is a diagram schematically illustrating an example of the configuration of the communication system 1. For example, the communication system 1 is any one of an IoT (Internet of Things) system, an ICT (Information and Communication Technology) system, a LAN (Local Area Network), an infrastructure system, and an ICS (Industrial Control Systems).
[0015] The communication system 1 is the entity of a virtual model generated by data processing devices 10, 20, and 30 according to embodiments 1 to 3 described below. That is, the data processing devices 10, 20, and 30 execute data processing for generating a virtual model of the communication system 1.
[0016] As shown in Fig. 1, the communication system 1 includes a control server 100, a client terminal 200 (hereinafter referred to as nodes 100 and 200), a switch 300, and a firewall 400. The communication system 1 establishes a communication network such as a LAN (Local Area Network) or a WAN (Wide Area Network). In Fig. 1, the lines connecting the constituent devices of the communication system 1 (nodes 100 and 200, switch 300, and firewall 400) indicate that the constituent devices can communicate with each other.
[0017] The nodes 100 and 200 are hardware devices or software having communication functions and information processing functions (computing functions). For example, the nodes 100 and 200 are personal computers, HMIs (Human Machine Interfaces), control servers, log servers, PLCs (Programmable Logic Controllers), APIs (Application Programming Interfaces), IoT (Internet of Things) devices, or mobile devices. Here, it is assumed that the node 100 is a client terminal (e.g., a personal computer), and the node 200 is a control server.
[0018] The switch 300 is a network device that realizes a routing function through hardware processing, such as Ethernet. As shown in FIG.
[0019] Firewall 400 is provided between the constituent devices of communication system 1 and between communication system 1 and an external network (the Internet in FIG. 1), and restricts data communication or communication connections for reasons of computer security, etc. Firewall 400 may be implemented in a router, or may be realized as application software (a so-called application firewall).
[0020] 1 is merely an example. For example, the communication system 1 may further include industrial equipment that is controlled by the PLC. Also, the number of nodes 100 and 200 may be one, or two or more.
[0021] In the following description, the term "node 100 (200)" refers to at least one of the node 100 and the node 200.
[0022] [Embodiment 1] The first embodiment will be described with reference to FIGS.
[0023] (Data processing device 10) The configuration of the data processing device 10 according to the first embodiment will be described with reference to Fig. 2. Fig. 2 is a block diagram showing the configuration of the data processing device 10.
[0024] As shown in FIG. 2, the data processing device 10 includes an acquisition unit 11, an extraction unit 12, and a generation unit 13.
[0025] The acquiring unit 11 acquires the inspection results of the information security inspection for the constituent devices (nodes 100, 200, switch 300, and firewall 400 in FIG. 1) that make up the communication system 1 (FIG. 1). The acquiring unit 11 is an example of an acquiring means.
[0026] For example, the acquisition unit 11 acquires software analysis results for the components of the communication system 1 from a first database (not shown) that stores software analysis information. Software analysis includes, for example, source code analysis, binary code analysis, OSS (Open Source Software) analysis, coding check, port scan, and installed software scan.
[0027] For example, the inspection result of the information security inspection for the component device includes information indicating which file was accessed from which function in the library used by the component device.
[0028] Alternatively, the acquiring unit 11 may acquire, from a software analysis device (not shown), the inspection results of the information security inspection of the constituent devices that make up the communication system 1. The acquiring unit 11 may include, as a part thereof, a software analysis unit that executes software analysis of the constituent devices.
[0029] The acquisition unit 11 outputs the inspection result of the information security inspection of the constituent devices that make up the communication system 1 to the extraction unit 12.
[0030] The extraction unit 12 extracts security inspection information from the inspection result, the security inspection information including at least one of first information indicating library functions used by the component devices and second information indicating whether or not a file has been accessed via the library functions. The extraction unit 12 is an example of an extraction means.
[0031] For example, the extraction unit 12 receives from the acquisition unit 11 the inspection results of the information security inspection of the constituent devices that make up the communication system 1.
[0032] The extraction unit 12 acquires a software parts list for the component device from a second database (not shown) that stores configuration information indicating the components of the component device. Then, the extraction unit 12 identifies the library functions used by the component device from the software parts list. A "library function" is a group of functions compiled into a so-called function library.
[0033] Next, the extraction unit 12 extracts security inspection information including at least one of first information indicating library functions used by the component devices and second information indicating whether or not a file has been accessed via the library functions from the inspection results received from the acquisition unit 11. The access to a file includes opening the file and reading / writing the file.
[0034] The extraction unit 12 outputs security inspection information relating to the component devices to the generation unit 13.
[0035] The generating unit 13 uses configuration information that identifies the components of the component devices and security inspection information to generate a virtual model of the communication system 1. The generating unit 13 is an example of a generating means.
[0036] For example, the generation unit 13 receives security inspection information related to the component devices from the extraction unit 12. The generation unit 13 also acquires configuration information that identifies the component parts of the component devices from a second database (not shown).
[0037] The generation unit 13 then generates a virtual model of the communication system 1 using the configuration information that identifies the components of the component devices and the security inspection information. The virtual model is a copy of the communication system 1 in digital space, in other words, a representation of the communication system 1 on a computer. One example of the use of the virtual model is to diagnose the security risks of the communication system 1 in detail and with high accuracy using a computer.
[0038] The generator 13 may store the generated virtual model of the communication system 1 in a third database (not shown).
[0039] (Operation of data processing device 10) The operation of the data processing device 10 according to the first embodiment will be described with reference to Fig. 3. Fig. 3 is a flowchart showing the flow of processing executed by each unit of the data processing device 10.
[0040] 3, first, the acquisition unit 11 acquires the inspection result of the information security inspection for the constituent devices that make up the communication system 1 (S101). The acquisition unit 11 outputs the inspection result of the information security inspection to the extraction unit 12.
[0041] The extraction unit 12 receives the inspection results of the information security inspection from the acquisition unit 11.
[0042] Next, the extraction unit 12 extracts security inspection information including at least one of first information indicating library functions used by the component devices and second information indicating whether or not a file has been accessed via the library functions from the received inspection result (S102). The extraction unit 12 outputs the security inspection information regarding the component devices to the generation unit 13.
[0043] The generation unit 13 receives security inspection information related to the constituent devices from the extraction unit 12. The generation unit 13 also acquires configuration information that identifies the constituent parts of the constituent devices from a second database (not shown) that stores configuration information.
[0044] Next, the generation unit 13 generates a virtual model of the communication system 1 using the configuration information that identifies the components of the component devices and the security inspection information (S103). Thereafter, the generation unit 13 may store the generated virtual model of the communication system 1 in a third database (not shown).
[0045] This completes the operation of the data processing device 10 according to the first embodiment.
[0046] (Effects of this embodiment) According to the configuration of this embodiment, the acquisition unit 11 acquires the inspection results of an information security inspection of the constituent devices that make up the communication system 1. The extraction unit 12 extracts security inspection information from the inspection results, including at least one of first information indicating library functions used by the constituent devices and second information indicating whether or not a file has been accessed via the library function. The generation unit 13 generates a virtual model of the communication system 1 using the configuration information that identifies the components of the constituent devices and the security inspection information.
[0047] The virtual model of the communication system 1 is generated using not only the configuration information of the constituent devices but also security inspection information including at least one of first information indicating library functions used by the constituent devices and second information indicating whether or not a file has been accessed via the library functions. This makes it possible to provide a virtual model of the communication system 1 necessary for diagnosing security risks of the communication system 1 in detail.
[0048] [Embodiment 2] A second embodiment will be described with reference to Figs. 4 to 6. In the second embodiment, an example of a method for generating a virtual model of the communication system 1 constituting the above-described communication system 1 (Fig. 1) will be described. The configuration and operation of a data processing device 20 according to the second embodiment are the same as the configuration and operation of the data processing device 10 (Fig. 2) according to the first embodiment. In the second embodiment, the description of the first embodiment will be cited and a description of the configuration and operation of the data processing device 20 will be omitted.
[0049] (Example of test results) The inspection results of the information security inspection for the constituent devices that make up the communication system 1 will be described with reference to Fig. 4. Fig. 4 is an example of software analysis information related to the constituent devices that make up the communication system 1, and is a diagram showing an example of a call graph that visualizes functions that are called during the execution of a certain process or the calling relationships between functions.
[0050] As shown in FIG. 4, software analysis information relating to the components of the communication system 1 reveals the relationship between a file being read / written by a certain process and the function in the library being used.
[0051] As described in the first embodiment, the acquisition unit 11 acquires the inspection results of the information security inspection of the constituent devices that make up the communication system 1. The inspection results include, in the above-mentioned software analysis information, information that indicates the relationship between the libraries used by the constituent devices that make up the communication system 1 and the files accessed through specific functions in the libraries.
[0052] (Configuration information and inspection results) 5, the correspondence between the configuration information indicating the components of the component devices that make up the communication system 1 and the inspection results of the information security inspection of the component devices (FIG. 4) will be described. FIG. 5 shows an example of the configuration information and inspection results regarding the component devices that make up the communication system 1.
[0053] 5, the configuration information includes a software parts list, package information, and file information. The configuration information may further include a hardware parts list that indicates the hardware configuration. However, the concept of software described here also includes firmware.
[0054] In one example, the software bill of materials of the configuration information includes information on the software name, metadata, device IDs that identify the component devices, versions, and packages (1 to M). A package here refers to a program part, and includes the concepts of component, library, and module.
[0055] The package information includes the package name for each package (1 to M) and information about the files (1 to N) that make up the package. The file information includes information about the file name given to each file (1 to N) and a hash value for determining the identity of the file.
[0056] In one example, the inspection result includes a result of file tampering detection, which includes information on a device ID for identifying a component device, the inspection date and time, a function in a library used by the component device, the name of an accessed file, a hash value for determining the identity of the file, and whether an abnormality was detected.
[0057] 5, the device IDs included in the configuration information correspond to the device IDs included in the inspection results. The constituent devices that make up the communication system 1 are identified by these device IDs. Furthermore, the file names and their hash values included in the configuration information correspond to the accessed file names and their hash values included in the inspection results.
[0058] As described in the first embodiment, the extraction unit 12 extracts security inspection information from the inspection results of the information security inspection of the constituent devices that make up the communication system 1. The security inspection information includes information indicating functions in the library used by the node 100 (200) and information indicating files accessed for reading and writing.
[0059] At this time, the extraction unit 12 extracts the inspection results of the information security inspection for the constituent devices that make up the communication system 1 from a second database (not shown) based on the correspondence between the device ID included in the configuration information and the device ID included in the inspection results.
[0060] (Example of virtual model configuration; configuration information and security inspection information) Fig. 6 is a diagram showing an example of the configuration of a virtual model of the communication system 1. As shown in Fig. 6, the virtual model includes configuration information indicating the components of the node 100 (200) and security inspection information extracted from the inspection results (Fig. 4) of the information security inspection of the component devices that make up the communication system 1.
[0061] In the virtual model shown in FIG. 6, information indicating libraries X and Y used by a certain piece of software is linked to information indicating files a and b accessed through functions A and B in libraries X and Y.
[0062] As described in the first embodiment, the generation unit 13 generates a virtual model of the communication system 1 using configuration information indicating the components of the node 100 (200) and security inspection information. At this time, the generation unit 13 identifies which file was accessed from which function in a library used by the component device, based on the security inspection information. Then, the generation unit 13 associates information indicating libraries X and Y used by a certain piece of software with information indicating files a and b accessed through functions A and B in libraries X and Y (FIG. 6).
[0063] (Effects of this embodiment) According to the configuration of this embodiment, the acquisition unit 11 acquires the inspection results of an information security inspection of the constituent devices that make up the communication system 1. The extraction unit 12 extracts security inspection information from the inspection results, including at least one of first information indicating library functions used by the constituent devices and second information indicating whether or not a file has been accessed via the library function. The generation unit 13 generates a virtual model of the communication system 1 using the configuration information that identifies the components of the constituent devices and the security inspection information.
[0064] The virtual model of the communication system 1 is generated using not only configuration information indicating the components of the component devices, but also security inspection information including at least one of first information indicating library functions used by the component devices and second information indicating whether or not a file is accessed through the library functions. This makes it possible to provide a virtual model of the communication system 1 necessary for diagnosing security risks of the communication system 1 in detail.
[0065] [Embodiment 3] A third embodiment will be described with reference to Figures 7 and 8. In the third embodiment, as an example of using the virtual model of the communication system 1 described in the first and second embodiments, a configuration will be described in which a virtual model is used in an attack simulation against the communication system 1.
[0066] (Data processing device 30) The configuration of a data processing device 30 according to the third embodiment will be described with reference to Fig. 7. Fig. 7 is a block diagram showing the configuration of the data processing device 30.
[0067] 7, the data processing device 30 includes an acquisition unit 11, an extraction unit 12, and a generation unit 13. In addition, the data processing device 30 further includes an execution unit 34 and an evaluation unit 35. With regard to the components of the data processing device 30 that are common to the data processing devices 10 and 20 according to the first and second embodiments, in the third embodiment, the explanations in the first and second embodiments will be cited and repeated explanations will be omitted.
[0068] The execution unit 34 uses the virtual model to execute an attack simulation against the communication system 1. The execution unit 34 is an example of an execution means.
[0069] In one example, the execution unit 34 receives data of a virtual model of the communication system 1 from the generation unit 13. As described in the first embodiment, the virtual model is a digital replica of the communication system 1. The execution unit 34 executes an attack simulation against the communication system 1 using the received virtual model.
[0070] For example, the execution unit 34 performs an attack simulation based on an attack scenario using various cyber-attack methods in a virtual environment. For example, the cyber-attack methods include attacks using email or the web, data tampering, spoofing, and attacks on isolated networks using devices connected to a USB (Universal Serial Bus) (e.g., memory, smartphone, digital camera, etc.).
[0071] In one example, first, preconditions such as the starting point and end point of an attack on the communication system 1, the means of the attack, and the cause of the attack (such as a defect or mistake) are input to the data processing device 30. Then, the execution unit 34 executes an attack simulation on the communication system 1 in accordance with the preconditions using an attack graph generation technique, an existing penetration test tool, or an analysis tool with equivalent functionality.
[0072] The execution unit 34 outputs the results of the attack simulation against the communication system 1 to the evaluation unit 35. For example, the results of the attack simulation include information on the number of alternative attack routes, the number of attack steps, whether or not an Exploit Code was used, whether or not a user was involved, and whether or not the attack was successful.
[0073] Based on the results of the attack simulation, the evaluation unit 35 evaluates the security risk of the communication system 1. The evaluation unit 35 is an example of evaluation means.
[0074] In one example, the evaluation unit 35 receives the results of an attack simulation against the communication system 1 from the execution unit 34. The evaluation unit 35 calculates an index representing the security risk of the communication system 1 based on the received results of the attack simulation. For example, the evaluation unit 35 calculates a threat level, a vulnerability level, and a business damage level based on the results of the attack simulation. For example, the evaluation unit 35 converts information included in the results of the attack simulation into several parameters and substitutes the parameters into a predetermined evaluation formula to calculate the indexes exemplified above.
[0075] The evaluation unit 35 then calculates a security risk value (hereinafter abbreviated as risk value) based on at least one of the calculation results of the threat level, vulnerability level, and business damage level. The risk value represents the magnitude or urgency of the security risk.
[0076] The evaluation unit 35 may output the calculated risk value data or alert information based on the risk value to an external device. Alternatively, the evaluation unit 35 may store the risk value data in a storage device (not shown).
[0077] This allows the system administrator or user to accurately recognize the security risk of the communication system 1 by referring to the risk value calculated by the evaluation unit 35, and also to consider and implement appropriate measures based on the security risk evaluation results.
[0078] (Operation of data processing device 30) The operation of the data processing device 30 according to the third embodiment will be described with reference to Fig. 8. Fig. 8 is a flowchart showing the flow of processing executed by each unit of the data processing device 30.
[0079] 8, first, the acquisition unit 11 acquires the inspection result of the information security inspection for the constituent devices that make up the communication system 1 (S301). The acquisition unit 11 outputs the inspection result of the information security inspection to the extraction unit 12.
[0080] The extraction unit 12 receives the inspection results of the information security inspection of the constituent devices that make up the communication system 1 from the acquisition unit 11.
[0081] Next, the extraction unit 12 extracts security inspection information including at least one of first information indicating library functions used by the component devices and second information indicating whether or not a file has been accessed via the library functions from the received inspection result (S302). The extraction unit 12 outputs the security inspection information regarding the component devices to the generation unit 13.
[0082] The generation unit 13 receives security inspection information related to the constituent devices from the extraction unit 12. The generation unit 13 also acquires configuration information that identifies the constituent parts of the constituent devices from a second database (not shown) that stores configuration information.
[0083] Next, the generation unit 13 generates a virtual model of the communication system 1 using the configuration information that identifies the components of the component devices and the security inspection information (S303). Thereafter, the generation unit 13 may store the generated virtual model of the communication system 1 in a third database (not shown).
[0084] The generator 13 outputs the virtual model of the communication system 1 to the executor 34 .
[0085] The execution unit 34 receives the virtual model of the communication system 1 from the generation unit 13. The execution unit 34 uses the virtual model to execute an attack simulation against the communication system 1 (S304).
[0086] The execution unit 34 outputs the results of the attack simulation against the communication system 1 to the evaluation unit 35.
[0087] The evaluation unit 35 receives the results of the attack simulation against the communication system 1 from the execution unit 34. The evaluation unit 35 evaluates the security risk of the communication system 1 based on the results of the attack simulation (S305). For example, the evaluation unit 35 calculates a risk value that indicates the magnitude or urgency of the security risk.
[0088] Thereafter, the evaluation unit 35 may output the calculated risk value data or alert information based on the risk value to an external device, or may store the risk value data in a storage device (not shown).
[0089] This completes the operation of the data processing device 30 according to the third embodiment.
[0090] (Effects of this embodiment) According to the configuration of this embodiment, the acquisition unit 11 acquires the inspection results of an information security inspection of the constituent devices that make up the communication system 1. The extraction unit 12 extracts security inspection information from the inspection results, including at least one of first information indicating library functions used by the constituent devices and second information indicating whether or not a file has been accessed via the library function. The generation unit 13 generates a virtual model of the communication system 1 using the configuration information that identifies the components of the constituent devices and the security inspection information.
[0091] The virtual model of the communication system 1 is generated using not only the configuration information of the constituent devices but also security inspection information including at least one of first information indicating library functions used by the constituent devices and second information indicating whether or not a file has been accessed via the library functions. This makes it possible to provide a virtual model of the communication system 1 necessary for diagnosing security risks of the communication system 1 in detail.
[0092] Furthermore, according to the configuration of this embodiment, the execution unit 34 uses the virtual model to execute an attack simulation against the communication system 1. The evaluation unit 35 evaluates the security risk of the communication system 1 based on the results of the attack simulation.
[0093] This allows the system administrator or user to accurately recognize the security risks of the communication system 1, and also allows them to consider and implement appropriate measures in accordance with the results of the security risk assessment.
[0094] (About hardware configuration) Each of the components of the data processing devices 10, 20, and 30 described in the first to third embodiments represents a functional block. Some or all of these components are realized by an information processing device 900 as shown in Fig. 9. Fig. 9 is a block diagram showing an example of the hardware configuration of the information processing device 900.
[0095] As shown in FIG. 9, an information processing device 900 includes, for example, the following configuration.
[0096] ·CPU(Central Processing Unit)901 ROM (Read Only Memory) 902 ·RAM(Random Access Memory)903 Program 904 loaded into RAM 903 A storage device 905 for storing a program 904 A drive device 907 for reading and writing data from and to the recording medium 906 A communication interface 908 for connecting to a communication network 909 Input / output interface 910 for inputting and outputting data Bus 911 connecting each component Each of the components of the data processing devices 10, 20, and 30 described in the first to third embodiments is realized by the CPU 901 reading and executing a program 904 that realizes the functions of the components. The program 904 that realizes the functions of the components is stored in advance in the storage device 905 or the ROM 902, for example, and is loaded into the RAM 903 and executed by the CPU 901 as needed. The program 904 may be supplied to the CPU 901 via the communication network 909, or may be stored in advance in the recording medium 906, and the drive device 907 may read out the program and supply it to the CPU 901.
[0097] According to the above configuration, the data processing devices 10, 20, and 30 described in the first to third embodiments are realized as hardware, and therefore the same effects as those described in any of the first to third embodiments can be achieved.
[0098] [Note] One aspect of the present invention can be described as, but is not limited to, the following supplementary notes.
[0099] (Appendix 1) an acquisition means for acquiring an inspection result of an information security inspection of a component device that constitutes a communication system; an extraction means for extracting security inspection information from the inspection result, the security inspection information including at least one of first information indicating a library function used by the component device and second information indicating whether a file has been accessed through the library function; a generating means for generating a virtual model of the communication system using configuration information that identifies components of the component devices and the security inspection information; A data processing device comprising:
[0100] (Appendix 2) an execution means for executing an attack simulation against the communication system using the virtual model; evaluation means for evaluating a security risk of the communication system based on the results of the attack simulation; Further equipped 2. A data processing device according to claim 1.
[0101] (Appendix 3) The inspection results include the results of file tampering detection. 3. The data processing device according to claim 1 or 2.
[0102] (Appendix 4) The communication system is any one of an IoT (Internet of Things) system, an ICT (Information and Communication Technology) system, an OT (Operational Technology) system, an infrastructure system, and a control system. 4. The data processing device according to any one of claims 1 to 3.
[0103] (Appendix 5) Obtain the results of information security inspections of the components of the communications system, extracting security inspection information from the inspection result, the security inspection information including at least one of first information indicating a library function used by the component device and second information indicating whether a file has been accessed through the library function; generating a virtual model of the communication system using configuration information identifying components of the component equipment and the security inspection information; Data processing methods.
[0104] (Appendix 6) Using the virtual model, a simulation of an attack on the communication system is performed; Evaluating the security risk of the communication system based on the results of the attack simulation. 6. The data processing method of claim 5, further comprising:
[0105] (Appendix 7) Obtaining inspection results of information security inspections of component devices that make up the communication system; extracting security inspection information from the inspection result, the security inspection information including at least one of first information indicating a library function used by the component device and second information indicating whether a file has been accessed through the library function; generating a virtual model of the communication system using configuration information identifying components of the component equipment and the security inspection information; A temporary recording medium that stores a program for causing a computer to execute the above.
[0106] (Appendix 8) using the virtual model to perform an attack simulation against the communication system; assessing a security risk of the communication system based on a result of the attack simulation; and 8. The recording medium according to claim 7, further storing a program for causing a computer to execute the above. [Industrial Applicability]
[0107] The present invention can be used for diagnosing a communication system, for example, analyzing the vulnerability of components that make up the communication system, or evaluating the security risk of the communication system. [Explanation of symbols]
[0108] 1. Communication Systems 10 Data processing device 11 Acquisition Department 12 Extraction part 13 Generation part 20 Data processing device 30 Data processing device 34 Executive Department 35 Evaluation Department 100 nodes (control server) 200 nodes (client terminals) 300 Switch 400 Firewall
Claims
1. generating a model in which information representing libraries included in the devices, information representing vulnerabilities related to functions used in the libraries, and information representing the devices are associated with each other, from security inspection information representing the results of an information security inspection on the devices that make up the system and configuration information including a hardware parts list and a software parts list; Diagnosing security risks related to the system using the created model; Device.
2. the configuration information and the security inspection information each include a device ID that identifies the device; The model is generated based on a correspondence relationship between the device ID included in the configuration information and the device ID included in the security inspection information.
10. The apparatus of claim 1.
3. Using the model, which is a digital replica of the system, to conduct an attack simulation against the system based on an attack scenario using a predetermined cyber-attack method; Diagnosing security risks related to the system based on the results of the attack simulation 10. The apparatus of claim 1.
4. The predetermined cyber attack method includes an attack on an isolated network using a device connected to a USB.
4. The apparatus of claim 3.
5. The predetermined cyber attack method includes spoofing.
4. The apparatus of claim 3.
6. Calculating a threat level, a vulnerability level, and a business damage level based on the results of the attack simulation, and calculating the security risk value based on the calculated threat level, vulnerability level, and business damage level.
4. The apparatus of claim 3.
7. The computer A model is created in which information representing libraries included in the devices, information representing vulnerabilities related to functions used in the libraries, and information representing the devices are associated with security inspection information representing the results of an information security inspection on the devices that make up the system, and configuration information including a hardware parts list and a software parts list; The created model is used to diagnose security risks related to the system. method.
8. a function for creating a model in which information representing libraries included in the devices, information representing vulnerabilities related to functions used in the libraries, and information representing the devices are associated with security inspection information representing the results of security inspections of devices that constitute the system, and configuration information including a hardware parts list and a software parts list; a function of diagnosing security risks related to the system using the created model; A program that makes the computer realize the above.
Citation Information
Patent Citations
Mortar filling type reinforcing bar joint sleeve
JP1988007453A