Information processing system and information processing method

The information processing system enhances vulnerability risk assessment by integrating trend and damage information to provide precise risk identification and management strategies for organizations.

JP2025175771AActive Publication Date: 2025-12-03SECOM TRUST SYST
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
JP2024082023
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-05-20
Publication Date
2025-12-03
Estimated Expiration
2044-05-20

AI Technical Summary

Technical Problem

Existing systems lack the accuracy in identifying vulnerability risks faced by organizations managing devices, necessitating a more precise method to assess and respond to potential threats.

Method used

An information processing system that includes a memory unit to store device information, a standard score acquisition unit, an attack information acquisition unit, a corrected score calculation unit, and an output control unit to accurately determine and output vulnerability risks by incorporating trend and damage information related to each vulnerability.

Benefits of technology

The system enables more accurate identification of vulnerability risks, allowing for targeted risk management and improved security measures by considering direct and indirect attack scenarios on organizations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025175771000001_ABST
    Figure 2025175771000001_ABST
Patent Text Reader

Abstract

To provide an information processing system and an information processing method for more accurately identifying a risk of vulnerability of an organization that manages a device.SOLUTION: In an information processing system, an information processing device includes: a storage section that stores device information indicating a device managed by an organization; a reference score acquisition section that acquires, for each device managed by the organization, a reference score related to a risk of vulnerability of each device; an attack information acquisition section that acquires, for each vulnerability, attack information related to an attack based on each vulnerability; a corrected score calculation section that acquires, for each vulnerability, a corrected score obtained by correcting the reference score of the device having each vulnerability, on the basis of the attack information; and an output control section that outputs information indicating the risk of vulnerability of the organization on the basis of the corrected score.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an information processing system and an information processing method. [Background technology]

[0002] In recent years, security threats in cyberspace have increased due to the increasing sophistication and ingenuity of attack methods, creating a need for early detection of threats, response to them, and rapid recovery from damage.To this end, systems have been developed to identify the risk of vulnerabilities that an organization has based on publicly disclosed vulnerability information about vulnerabilities in the devices that the organization manages.For example, the Security Center of the Information-technology Promotion Agency, Japan (IPA) has published the Common Vulnerability Scoring System (CVSS) as an index for assessing the severity of vulnerabilities.

[0003] Patent Document 1 discloses a threat information sharing system between multiple organizations that evaluates the usefulness of reported security threat information and provides the evaluated security threat information to information purchasers. This threat information sharing system automatically generates and outputs a configuration file for a security appliance using the evaluated security threat information. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] Japanese Patent Application Publication No. 2019-191657 Summary of the Invention [Problem to be solved by the invention]

[0005] In a system for identifying vulnerability risks posed by organizations that manage devices, there is a demand for more accurate identification of vulnerability risks posed by organizations.

[0006] An object of the present invention is to provide an information processing system and an information processing method that can more accurately identify vulnerability risks present in organizations that manage devices. [Means for solving the problem]

[0007] In order to solve this problem, the present invention provides an information processing system having a memory unit that stores device information indicating devices managed by an organization, a standard score acquisition unit that acquires, for each device managed by the organization, a standard score related to the risk of vulnerabilities held by each device, an attack information acquisition unit that acquires, for each vulnerability, attack information related to attacks based on each vulnerability, a corrected score calculation unit that calculates, for each vulnerability, a corrected score obtained by correcting the standard score of each device having a vulnerability based on the attack information, and an output control unit that outputs information indicating the risk of vulnerabilities held by the organization based on the corrected score.

[0008] In this information processing system, it is preferable that the attack information acquisition unit acquires, as the attack information, trend information that indicates the trends of attacking organizations that carry out attacks based on each vulnerability.

[0009] In this information processing system, the attack information acquisition unit preferably acquires, as attack information, trend information of attacking organizations that launch attacks based on each vulnerability against the organization or related organizations associated with the organization.

[0010] In this information processing system, it is preferable that the corrected score calculation unit uses different corrected scores when an organization is attacked based on each vulnerability and when a related organization is attacked based on each vulnerability.

[0011] In this information processing system, it is preferable that the attack information acquisition unit acquires, as the attack information, damage information indicating victim organizations that have been attacked based on each vulnerability.

[0012] In this information processing system, it is preferable that the corrected score calculation unit calculates the corrected score when the organization or an associated organization related to the organization is attacked based on each vulnerability.

[0013] In this information processing system, it is preferable that the corrected score calculation unit uses different corrected scores when an organization is attacked based on each vulnerability and when a related organization is attacked based on each vulnerability.

[0014] In order to solve this problem, the present invention provides an information processing method that stores device information indicating devices managed by an organization, obtains, for each device managed by the organization, a standard score related to the risk of vulnerabilities held by each device, obtains, for each vulnerability, attack information related to attacks based on each vulnerability, calculates, for each vulnerability, a corrected score by correcting the standard score of each device having a vulnerability based on the attack information, and outputs information indicating the risk of vulnerabilities held by the organization based on the corrected score. [Effects of the Invention]

[0015] The information processing system and information processing method according to the present invention make it possible to more accurately identify the risk of vulnerabilities present in an organization that manages devices. [Brief explanation of the drawings]

[0016] [Figure 1] 1 is a diagram showing the overall system configuration of an information processing system 1. FIG. [Figure 2] FIG. 6 is a diagram showing an example of the data structure of an organization table 641. [Figure 3] (A) is a diagram showing an example of the data structure of the vulnerability table 642, (B) is a diagram showing an example of the data structure of the trend information table 643, and (C) is a diagram showing an example of the data structure of the damage information table 644. [Figure 4] FIG. 10 is a diagram illustrating an example of the data structure of a device table 645. [Figure 5] 10 is a flowchart illustrating an example of the operation of a notification process. [Figure 6] 10A and 10B are schematic diagrams showing an example of a display screen. DETAILED DESCRIPTION OF THE INVENTION

[0017] A monitoring system according to an embodiment will be described below with reference to the drawings.

[0018] FIG. 1 is a diagram showing the overall system configuration of an information processing system 1. As shown in FIG. As shown in FIG. 1, the information processing system 1 includes a device information management device 10, a vulnerability information management device 20, a trend information management device 30, an organization information management device 40, a notification device 50, and an information processing device 60. The number of each of the device information management device 10, vulnerability information management device 20, trend information management device 30, organization information management device 40, notification device 50, and information processing device 60 is not limited to one and may be multiple. The information processing system 1 identifies vulnerability risks of one or more organizations that each own and manage one or more devices. The devices include any device connected to a communication network, such as terminal devices such as personal computers or servers, and network devices such as routers or switches. The organizations are any groups such as companies and schools. The multiple organizations include related organizations that are mutually related. The related organizations include organizations whose managed devices are connected to each other via a communication network. The type of related organizations is not limited to one and may be multiple, such as organizations belonging to the same corporate group, organizations belonging to the same supply chain, organizations in the same industry, etc.

[0019] The device information management device 10, the vulnerability information management device 20, the trend information management device 30, the organization information management device 40, the notification device 50, and the information processing device 60 are connected to a communication network N such as an intranet or the Internet. The information processing device 60 is communicatively connected to the device information management device 10, the vulnerability information management device 20, the trend information management device 30, the organization information management device 40, and the notification device 50 via the communication network N. The networks connecting the information processing device 60 to each device may be provided separately.

[0020] The device information management device 10 is located in each organization managed by the information processing system 1 and manages device information indicating each device managed by each organization. The device information may be, for example, a device ID for identifying each device. The device information management device 10 also manages configuration information indicating the configuration of each device, organization information indicating the organization managing each device, and group information indicating one or more groups managing each device. The configuration of each device is the hardware and / or software that each device possesses. A group is any group included in an organization, and includes groups related to multiple hierarchies such as business divisions, departments, and sections (groups that overlap partially or completely), as well as independent groups (groups that do not overlap with each other). That is, each device may be simultaneously managed (owned) by groups related to multiple hierarchies (such as a first business division group, a first department group, and a first section group). Each group and a group related to a higher hierarchy of each group are examples of a first group and a second group that encompasses the first group, respectively. For example, the device information management device 10 transmits a signal requesting inventory information to each device managed by each organization, and receives the inventory information from each device. The inventory information indicates the configuration of each device and the group that manages (owns) each device. The device information management device 10 assigns a device ID as device information to each device that has transmitted inventory information. The device information management device 10 stores organizational information indicating the corresponding organization, configuration information indicating the configuration included in the inventory information, and group information indicating the group included in the inventory information, in association with the device information. The device information management device 10 may acquire the configuration of each device and / or the group that manages each device by receiving it from an administrator using an input device (not shown).

[0021] The vulnerability information management device 20 is installed in a management company that monitors vulnerability risks held by each organization, and manages vulnerability information indicating vulnerabilities occurring worldwide. The vulnerability information includes a vulnerability ID for identifying each vulnerability (type), the date and time when each vulnerability occurred (discovered), the date and time when a countermeasure was completed, a standard score related to the risk of each vulnerability, and configuration information indicating the configuration containing each vulnerability. The vulnerability ID is uniquely determined by a management organization that manages and discloses vulnerabilities occurring worldwide. The standard score is a point indicating the severity (significance) of each vulnerability, and the greater the severity of each vulnerability, the higher the standard score for each vulnerability. The standard score is determined commonly worldwide by the management organization. The vulnerability information management device 20 transmits a signal requesting vulnerability information to the management organization, and receives vulnerability information from the management organization. The vulnerability information management device 20 stores each piece of vulnerability information that it receives.

[0022] The trend information management device 30 is located at a management company that monitors the vulnerability risks of each organization and manages trend information that shows the trends of attacking organizations that conduct attacks based on each vulnerability. The trend information is external information obtained from organizations external to the information processing system 1 and is an example of attack information related to attacks based on each vulnerability. The trend information includes information about each attacking organization, the attack method used by each attacking organization, the intrusion route, the details of the damage, the attack status (attack occurrence, possibility of attack, end of attack, etc.), the risk level, the vulnerability IDs (related vulnerability IDs) of vulnerabilities that may be used in the attack, whether each attacking organization has made a claim or announced a crime, the organizations that are the targets of the attack, whether or not individuals (key individuals) belonging to each attacking organization have been arrested, and the date and time when such information was generated (confirmed). The trend information management device 30 acquires and stores trend information by receiving it from an administrator using an input device (not shown). The trend information management device 30 may also acquire trend information by receiving it from a social networking site or the like that provides high confidentiality regarding cyber attacks.

[0023] The organizational information management device 40 is located at a management company that monitors the vulnerability risks of each organization, and manages damage information and organizational information. The damage information is external information obtained from organizations external to the information processing system 1, and is an example of attack information related to attacks based on each vulnerability. The damage information includes the damage status caused by attacks based on each vulnerability (damage occurred, possibility of damage, end of damage, etc.), the vulnerability ID (related vulnerability ID) of the vulnerability used in the attack, the victim organizations attacked, the severity of the damage suffered by each victim organization, and the date and time of occurrence (confirmation) of this information. The organizational information indicates the related organizations related to each organization managed by the information processing system 1, and the groups included in each organization. The organizational information management device 40 acquires and stores damage information for each vulnerability and organizational information for each organization by receiving the information from an administrator using an input device (not shown). The trend information management device 30 may acquire the damage information and organizational information by receiving the information from a management device or the like that manages sales information for each organization.

[0024] The notification device 50 is installed in a management company that monitors the vulnerability risks of each organization. The notification device 50 receives risk information indicating the vulnerability risks of each organization from the information processing device 60, and notifies the administrator of the information processing system 1 or the person in charge of each organization by displaying the vulnerability risks of each organization on a display unit (not shown).

[0025] The information processing device 60 is installed in a management company that monitors vulnerability risks held by each organization, monitors the vulnerability risks held by each organization, and transmits risk information to the notification device 50. The information processing device 60 includes an operation unit 61, a display unit 62, a communication unit 63, a storage unit 64, a control unit 65, and the like.

[0026] The operation unit 61 has input devices such as a keyboard, a mouse, and a touch panel, and an interface circuit that acquires signals from the input devices, accepts operations by a user, and outputs a signal according to the accepted operation to the control unit 65. The display unit 62 has a liquid crystal display or an organic EL display and an interface circuit that outputs signals to the display, and displays various information such as images and text according to instructions from the control unit 65.

[0027] The communication unit 63 has a communication interface circuit that complies with, for example, TCP / IP, and is connected to the communication network N. Alternatively, the communication unit 63 has, for example, an antenna for transmitting and receiving wireless signals and a wireless communication interface circuit for transmitting and receiving signals through a wireless communication line in accordance with a wireless communication protocol such as a wireless LAN, and is connected to the communication network N via an access point. The communication unit 63 outputs data received from each device via the communication network N to the control unit 65, and transmits data input from the control unit 65 to the communication network N.

[0028] The storage unit 64 has semiconductor memory such as ROM and RAM, a magnetic disk or an optical disk drive such as a CD-ROM or DVD-ROM, and a recording medium thereof. The storage unit 64 stores computer programs and various data for controlling the information processing device 60, and inputs and outputs this information to and from the control unit 65. The computer programs may be installed into the storage unit 64 from a computer-readable portable recording medium such as a CD-ROM or DVD-ROM using a known setup program or the like. The computer programs may also be stored in a recording medium owned by a predetermined server and installed via a network. The storage unit 64 also stores data such as an organization table 641, a vulnerability table 642, a trend information table 643, a damage information table 644, and a device table 645. Details of each table will be described later.

[0029] The control unit 65 has a processor such as a CPU or MPU, memories such as a ROM or RAM, and peripheral circuits thereof, and executes various signal processing for the information processing device 60. The control unit 65 has a standard score acquisition unit 651, an attack information acquisition unit 652, a corrected score calculation unit 653, a risk information determination unit 654, an output control unit 655, and the like, which are implemented as functional modules of a program running on the processor. Note that the control unit 65 may be a DSP, an LSI, an ASIC, an FPGA, or the like.

[0030] 2 is a diagram showing an example of the data structure of organization table 641. As shown in Fig. 2, organization table 641 stores, for each of one or more organizations, related organizations associated with each organization and groups included in each organization, in mutual association with each other. Control unit 65 periodically transmits an organization information request signal requesting organization information for each organization to organization information management device 40 via communication unit 63, and receives organization information from organization information management device 40 via communication unit 63. Control unit 65 stores the related organizations and groups included in each received organization information in organization table 641, and updates organization table 641.

[0031] FIG. 3A is a diagram showing an example of the data structure of the vulnerability table 642. As shown in FIG. 3A, the vulnerability table 642 stores, for each of one or more (types of) vulnerabilities, the vulnerability ID, the occurrence date and time, the countermeasure completion date and time, the reference score, the configuration having each vulnerability, and the like, in association with each other. The vulnerability table 642 may store information only about vulnerabilities possessed by devices managed by an organization managed by the information processing system 1. The control unit 65 periodically transmits a vulnerability information request signal requesting vulnerability information for each vulnerability to the vulnerability information management device 20 via the communication unit 63, and receives vulnerability information from the vulnerability information management device 20 via the communication unit 63. The control unit 65 stores the vulnerability ID, the occurrence date and time, the countermeasure completion date and time, the reference score, and the configuration included in each piece of vulnerability information received in the vulnerability table 642, and updates the vulnerability table 642.

[0032] Fig. 3(B) is a diagram showing an example of the data structure of the trend information table 643. As shown in Fig. 3(B), the trend information table 643 stores trend information, first points, second points, etc., in mutual association for each trend of an attacking organization. The first point is a point used to correct the standard score of a device managed by a target organization that is the target of an attack, and the second point is a point used to correct the standard score of a device managed by an organization related to the target organization. The first and second points are set to higher values ​​as the possibility of an attack increases, and lower values ​​as the possibility of an attack decreases. If the possibility of an attack increases, the first and second points are set to positive values, and if the possibility of an attack decreases, the first and second points are set to negative values. As a result, the standard score is corrected to be higher as the possibility of an attack increases, and lower as the possibility of an attack decreases. Furthermore, the first and second points are set so that the absolute value of the first point is greater than the absolute value of the second point. As a result, the standard score of a target organization that is the direct target of an attack is corrected to be greater than the standard scores of related organizations that may be attacked. The control unit 65 periodically transmits a trend information request signal to the trend information management device 30 via the communication unit 63, requesting trend information on each attacking organization, and receives the trend information from the trend information management device 30 via the communication unit 63. The control unit 65 displays the received trend information on the display unit 62 and notifies the administrator. The control unit 65 acquires the first points and the second points by receiving them from the administrator of the information processing system 1 who has confirmed the trend information using the operation unit 61. Note that the information processing device 60 may previously store a table or formula indicating the relationship between the trend information and each point in the storage unit 64, and the control unit 65 may automatically calculate the first points and the second points by referring to the table or formula stored in the storage unit 64. The control unit 65 stores the received trend information and the first points and the second points in the trend information table 643 and updates the trend information table 643.

[0033] Fig. 3(C) is a diagram showing an example of the data structure of the damage information table 644. As shown in Fig. 3(C), the damage information table 644 stores, for each damage event, damage information, third points, fourth points, etc., in mutually associated relation with each other. The third point is used to adjust the standard score for devices managed by the victim organization, and the fourth point is used to adjust the standard score for devices managed by the victim organization's affiliates. The third and fourth points are set to higher values ​​as the severity of the damage suffered by the victim organization or its affiliates increases, and lower values ​​as the severity of the damage suffered by the victim organization or its affiliates decreases. If the damage is ongoing, the third and fourth points are set to positive values, and if the damage is ending, the third and fourth points are set to negative values. As a result, the standard score is adjusted higher as the severity of the damage or the likelihood of damage increases, and lower as the severity of the damage or the likelihood of damage decreases. In addition, the third and fourth points are set so that the absolute value of the third point is greater than the absolute value of the fourth point. As a result, the standard score of a victim organization that has already suffered damage is adjusted higher than the standard score of affiliates that may suffer damage. The control unit 65 periodically transmits a damage information request signal requesting damage information to the organization information management device 40 via the communication unit 63, and receives the damage information from the organization information management device 40 via the communication unit 63. The control unit 65 displays the received damage information on the display unit 62 and notifies the administrator. The control unit 65 acquires the third point and the fourth point by receiving the third point and the fourth point from the administrator of the information processing device 60 using the operation unit 61. Note that the information processing device 60 may store in advance in the memory unit 64 a table or formula indicating the relationship between the damage information and each point, and the control unit 65 may automatically calculate the third point and the fourth point by referring to the table or formula stored in the memory unit 64. The control unit 65 stores the received damage information and the third point and the fourth point in the damage information table 644 and updates the damage information table 644.

[0034] FIG. 4 is a diagram showing an example of the data structure of the device table 645. As shown in FIG. 4, the device table 645 stores, for each device managed by the information processing system 1, the device ID, management organization, management group, configuration information, supported vulnerability ID, standard score, and corrected score of each device, in mutual association. The management organization is the organization that manages each device. The management group is the group that manages each device. The configuration information is configuration information of each device, indicating the hardware, software, etc. that each device has. The supported vulnerability ID is the vulnerability ID of the vulnerability that the hardware and software of each device has. The standard score is the standard score of the vulnerability corresponding to each supported vulnerability ID. The corrected score is a corrected score corrected from each standard score. The device table 645 is set or updated in the notification process described below.

[0035] Fig. 5 is a flowchart showing an example of the operation of notification processing by the information processing device 60. This flowchart is executed mainly by the control unit 65 in cooperation with each element of the information processing device 60, based on a program stored in advance in the storage unit 64. The notification processing shown in Fig. 5 is executed periodically for each organization managed by the information processing system 1.

[0036] First, the standard score acquisition unit 651 acquires device information indicating devices managed by the target organization and stores it in the device table 645 (step S101). The standard score acquisition unit 651 transmits an information request signal, via the communication unit 63, to the device information management device 10 that manages the target organization, requesting device information, configuration information, and group information of the target organization. The information request signal includes organizational information of the target organization. Upon receiving the information request signal, the device information management device 10 identifies the device information, configuration information, and group information stored in association with the organizational information included in the received information request signal, and transmits them to the information processing device 60. The standard score acquisition unit 651 receives the device information, configuration information, and group information from the organizational information management device 40 via the communication unit 63. The standard score acquisition unit 651 associates the received device information, configuration information, and group information and the transmitted organizational information in the device table 645 as device IDs, configuration information, managed groups, and managed organizations, respectively.

[0037] The processing of steps S102 to S112 is executed for each device indicated in the device information acquired by standard score acquisition unit 651, that is, for each device managed by each organization.

[0038] First, the standard score acquisition unit 651 acquires standard scores related to vulnerabilities possessed by each configuration of each device (step S102). The standard score acquisition unit 651 acquires vulnerability IDs and standard scores related to vulnerabilities possessed by each configuration of each device by reading out vulnerability IDs and standard scores stored in association with configuration information indicating each configuration of each device in the vulnerability table 642. The standard score acquisition unit 651 associates the acquired vulnerability IDs and standard scores with the configuration information of each device as corresponding vulnerability IDs and standard scores and stores (sets or updates) them in the device table 645. Note that the standard score acquisition unit 651 may consider vulnerabilities for which a countermeasure completion date and time is set in the vulnerability table 642 to be no risk, and may not set the vulnerability IDs and standard scores in the device table 645. Furthermore, the standard score acquisition unit 651 may acquire vulnerability IDs and standard scores related to vulnerabilities possessed by each configuration by transmitting a vulnerability information request signal requesting vulnerability information corresponding to each piece of configuration information to the vulnerability information management device 20 via the communication unit 63 and receiving vulnerability information from the vulnerability information management device 20 via the communication unit 63. This allows the standard score acquisition unit 651 to acquire the latest standard scores managed by the vulnerability information management device 20.

[0039] Next, the attack information acquisition unit 652 acquires trend information indicating the trends of attacking organizations that launch attacks based on each vulnerability for each vulnerability in each configuration of each device (step S103). The attack information acquisition unit 652 acquires trend information of each attacking organization by reading trend information including a vulnerability ID (related vulnerability ID) corresponding to each vulnerability from the trend information table 643. The attack information acquisition unit 652 may acquire trend information corresponding to vulnerabilities possessed by each component by transmitting a trend information request signal requesting trend information corresponding to vulnerabilities possessed by each component to the trend information management device 30 via the communication unit 63, and receiving the trend information from the vulnerability information management device 20 via the communication unit 63. This allows the attack information acquisition unit 652 to acquire the latest trend information managed by the trend information management device 30. In this case, the attack information acquisition unit 652 acquires the first point and the second point at the timing of receiving the trend information. The attack information acquisition unit 652 can identify the vulnerability risks that each organization has with high accuracy by using trend information related to each vulnerability.

[0040] The attack information acquisition unit 652 may also acquire trend information indicating the trends of attacking organizations that launch attacks based on each vulnerability against each organization or related organizations associated with each organization. In this case, the attack information acquisition unit 652 refers to the organization table 641 to identify related organizations associated with each organization. The attack information acquisition unit 652 reads only trend information in the trend information table 643 that includes each vulnerability ID (related vulnerability ID) and in which the target organization is each organization or a related organization of each organization. The attack information acquisition unit 652 can identify the vulnerability risks of each organization with less load and higher accuracy by using only trend information related to each organization, without using trend information unrelated to each organization.

[0041] Next, the corrected score calculation unit 653 determines whether or not trend information related to vulnerabilities in each configuration of each device exists (step S104). For each vulnerability in each configuration of each device, the corrected score calculation unit 653 determines whether or not trend information related to vulnerabilities in each configuration of each device exists, depending on whether or not the attack information acquisition unit 652 has acquired trend information indicating the trends of attacking organizations that carry out attacks based on each vulnerability in step S103. If trend information related to vulnerabilities in each configuration of each device does not exist, the corrected score calculation unit 653 proceeds to step S108.

[0042] On the other hand, if there is trend information related to vulnerabilities in each configuration of each device, the corrected score calculation unit 653 determines whether or not attacks based on each vulnerability are directly related to each organization (step S105). For example, if the target organizations included in the trend information are the organizations themselves, the corrected score calculation unit 653 determines that attacks based on each vulnerability are directly related to each organization, and if the target organizations included in the trend information are not the organizations themselves, the corrected score calculation unit 653 determines that attacks based on each vulnerability are not directly related to each organization.

[0043] When an attack based on each vulnerability is directly related to each organization, the corrected score calculation unit 653 calculates a corrected score by correcting the standard score for each vulnerability using the first point corresponding to each vulnerability (stored in the trend information table 643 in association with the related vulnerability ID) (step S106). On the other hand, when an attack based on each vulnerability is not directly related to each organization, the corrected score calculation unit 653 calculates a corrected score by correcting the standard score for each vulnerability using the second point corresponding to each vulnerability (stored in the trend information table 643 in association with the related vulnerability ID) (step S107). The corrected score calculation unit 653 stores each calculated corrected score in the device table 645 in association with the target organization and the corresponding vulnerability ID corresponding to each vulnerability. In this way, the corrected score calculation unit 653 calculates, for each vulnerability, a corrected score by correcting the standard score of a device having each vulnerability based on the trend information. In particular, the corrected score calculation unit 653 sets different corrected scores for when each organization is attacked based on each vulnerability and when an organization related to each organization is attacked based on each vulnerability. This allows the information processing system 1 to set different corrected scores depending on the likelihood that each organization will be attacked based on each vulnerability, and to more accurately identify the risk of vulnerabilities that each organization has.

[0044] In step S105, the corrected score calculation unit 653 may determine that the attack based on each vulnerability is directly related to the target organization if the target organization is the target organization itself or a related organization, and may determine that the attack based on each vulnerability is not directly related to the target organization if the target organization is neither the target organization itself nor a related organization. Alternatively, the corrected score calculation unit 653 may determine that the attack based on each vulnerability is directly related to the target organization if the target organization is the target organization itself or a directly related organization, and may determine that the attack based on each vulnerability is not directly related to the target organization if the target organization is neither the target organization itself nor a directly related organization. The administrator predetermines, among the related organizations of each organization, related organizations that are likely to be attacked (e.g., related organizations with a large amount of communication with each organization, organizations with close relationships with each organization, etc.). In this case, the information processing system 1 can also vary the corrected score depending on the likelihood that each organization will be attacked based on each vulnerability, thereby more accurately identifying the vulnerability risk of each organization. Furthermore, the corrected score calculation unit 653 may calculate the corrected score in three or more stages depending on the degree to which an attack based on each vulnerability is related to each organization. In this case, the corrected score calculation unit 653 calculates the corrected score so that the higher the degree to which an attack based on each vulnerability is related to each organization, the higher the corrected score. This allows the information processing system 1 to identify the vulnerability risk of each organization with even higher accuracy.

[0045] Next, the attack information acquisition unit 652 acquires damage information indicating victim organizations that have been attacked based on each vulnerability for each vulnerability in each configuration of each device (step S108). The attack information acquisition unit 652 acquires damage information related to each vulnerability by reading damage information including each vulnerability ID (related vulnerability ID) from the damage information table 644. The attack information acquisition unit 652 may acquire trend information corresponding to each vulnerability by transmitting a damage information request signal requesting damage information indicating victim organizations that have been attacked based on each vulnerability to the organizational information management device 40 via the communication unit 63, and receiving the damage information from the vulnerability information management device 20 via the communication unit 63. This allows the attack information acquisition unit 652 to acquire the latest trend information managed by the organizational information management device 40. In this case, the attack information acquisition unit 652 acquires the third point and the fourth point at the time of receiving the damage information. The attack information acquisition unit 652 can identify the vulnerability risks that each organization has with high accuracy by using the damage information related to each vulnerability.

[0046] Next, the corrected score calculation unit 653 determines whether or not damage information related to each organization exists for each vulnerability in each configuration of each device (step S109). The corrected score calculation unit 653 determines whether or not damage information related to each organization exists by determining whether or not the victim organization included in the damage information corresponding to each vulnerability is either the organization itself or a related organization for each vulnerability in each configuration of each device. Note that the corrected score calculation unit 653 may determine that damage information related to each organization exists if the industry of the victim organization included in the damage information corresponding to each vulnerability is the same as the industry of the organization itself. If damage information related to each organization does not exist, the corrected score calculation unit 653 determines whether or not there is any device that has not yet been processed. If there is any device that has not yet been processed, the corrected score calculation unit 653 repeats the processes of steps S102 to S112. If all devices have been processed, the corrected score calculation unit 653 proceeds to step S113.

[0047] On the other hand, if there is damage information that includes damage information related to each organization, the corrected score calculation unit 653 determines whether the victim organization that was attacked based on each vulnerability is directly related to each organization (step S110). If the victim organization included in the damage information is each organization itself, the corrected score calculation unit 653 determines that the victim organization that was attacked based on each vulnerability is directly related to each organization, and if the victim organization included in the damage information is not each organization itself, the corrected score calculation unit 653 determines that the victim organization that was attacked based on each vulnerability is not directly related to each organization.

[0048] If the victim organization attacked based on each vulnerability is directly related to each organization, the corrected score calculation unit 653 calculates a corrected score by correcting the standard score for each vulnerability using the third point corresponding to each vulnerability (stored in the damage information table 644 in association with the related vulnerability ID) (step S111). On the other hand, if the victim organization attacked based on each vulnerability is not directly related to each organization, the corrected score calculation unit 653 calculates a corrected score by correcting the standard score for each vulnerability using the fourth point corresponding to each vulnerability (stored in the damage information table 644 in association with the related vulnerability ID) (step S112). Note that in step S111 or S112, if the corrected score has already been calculated in step S106 or S107, the corrected score calculation unit 653 further corrects the calculated corrected score. The corrected score calculation unit 653 stores (or updates) each calculated corrected score in the device table 645 in association with the target organization and the corresponding vulnerability ID corresponding to each vulnerability. If the corrected score has not been calculated in any of steps S106, S107, S111, and S112, the corrected score calculation unit 653 stores the standard score as the corrected score as is. In this way, the corrected score calculation unit 653 calculates, for each vulnerability, a corrected score obtained by correcting the standard score of the device having each vulnerability based on the damage information. In particular, the corrected score calculation unit 653 calculates a corrected score when each organization or an associated organization related to each organization is attacked based on each vulnerability. This allows the information processing system 1 to correct the standard score when each organization is likely to be attacked based on each vulnerability, and to more accurately identify the risk of vulnerabilities that each organization has. Furthermore, the corrected score calculation unit 653 sets different corrected scores for when each organization is attacked based on each vulnerability and when an organization related to each organization is attacked based on each vulnerability. This allows the information processing system 1 to set different corrected scores depending on the possibility that each organization will be attacked based on each vulnerability, and to more accurately identify the vulnerability risks that each organization has.

[0049] In step S110, the corrected score calculation unit 653 may determine that the victim organization attacked based on each vulnerability is directly related to each organization if the victim organization is the organization itself or a related organization, and may determine that the victim organization attacked based on each vulnerability is not directly related to each organization if the victim organization is neither the organization itself nor a related organization. Alternatively, the corrected score calculation unit 653 may determine that the victim organization attacked based on each vulnerability is directly related to each organization if the victim organization is the organization itself or a directly related organization, and may determine that the victim organization attacked based on each vulnerability is not directly related to each organization if the victim organization is neither the organization itself nor a directly related organization. In this case, the information processing system 1 can also vary the corrected score depending on the likelihood that each organization will be attacked based on each vulnerability, thereby more accurately identifying the vulnerability risk of each organization. Furthermore, the corrected score calculation unit 653 may calculate the corrected score in three or more stages depending on the degree to which the victim organization attacked based on each vulnerability is related to each organization. In this case, the corrected score calculation unit 653 calculates the corrected score so that the higher the relationship between the victim organization attacked based on each vulnerability and each organization, the higher the corrected score. This allows the information processing system 1 to identify the vulnerability risk of each organization with even higher accuracy.

[0050] When the processes of steps S102 to S112 have been executed for all devices managed by each organization, the risk information determination unit 654 extracts all groups included in the target organization (step S113). The risk information determination unit 654 extracts each group included in the target organization by reading each group stored in association with the target organization in the organization table 641.

[0051] The processing of steps S114 to S115 is executed for each group extracted by the risk information determining unit 654, that is, for each group included in each organization.

[0052] First, the risk information determination unit 654 determines risk information indicating the vulnerability risk of each group (step S114). The risk information determination unit 654 extracts all devices stored in association with each group (management group) in the device table 645. The risk information determination unit 654 calculates the statistical value of the corrected score of each corresponding vulnerability ID associated with the extracted device as the risk of each device. The statistical value may be an average value, median value, maximum value, minimum value, total value, or the like. The risk information determination unit 654 determines that the state of an appliance whose calculated risk is equal to or greater than a first threshold is an emergency. The first threshold is preset to the minimum value of risk that requires urgent action. The risk information determination unit 654 determines that the state of an appliance whose calculated risk is less than the first threshold and equal to or greater than a second threshold is a caution state. The second threshold is preset to a value smaller than the first threshold. The risk information determination unit 654 determines that the state of an appliance whose calculated risk is less than the second threshold and equal to or greater than a third threshold is a warning state. The third threshold is preset to a value smaller than the second threshold. The risk information determination unit 654 determines that the state of an appliance whose calculated risk is less than the third threshold and equal to or greater than a fourth threshold is a caution state. The fourth threshold is preset to a value smaller than the third threshold. The risk information determination unit 654 determines that the state of an appliance whose calculated risk is less than the fourth threshold is safe. The fifth threshold is preset to a value smaller than the fourth threshold, particularly the maximum value of risk for an appliance that can be considered sufficiently safe. The risk information determination unit 654 may classify the state of the device into any number of stages, not limited to five stages.

[0053] The risk information determination unit 654 determines the vulnerability risk of each group to be an emergency if a first ratio, which is the ratio of the number of devices in an emergency state to the total number of extracted devices, i.e., the total number of devices managed by each group, is greater than a first ratio threshold. An emergency indicates a state of being directly attacked, a state of being indirectly attacked, or a state of increased threat. The first ratio threshold is preset to the minimum value of the first ratio at which an emergency response is deemed necessary. The risk information determination unit 654 determines the vulnerability risk of each group to be an emergency if a second ratio, which is the ratio of the number of devices in an important state to the total number of devices managed by each group, is greater than a second ratio threshold. The second ratio threshold is preset to the minimum value of the second ratio at which an emergency response is deemed necessary. The risk information determination unit 654 determines the vulnerability risk of each group to be an emergency if a third ratio, which is the ratio of the number of devices in a warning state to the total number of devices managed by each group, is greater than a third ratio threshold. The third ratio threshold is preset to the minimum value of the third ratio at which an emergency response is deemed necessary. If a fourth ratio, which is the ratio of the number of devices in a warning state to the total number of devices managed by each group, is greater than the fourth ratio threshold, the risk information determination unit 654 determines the vulnerability risk of each group to be emergency. The fourth ratio threshold is preset to the minimum value of the fourth ratio at which an emergency response is deemed necessary. If the first to fourth ratios are equal to or less than the first to fourth ratio thresholds, respectively, the risk information determination unit 654 determines the vulnerability risk of each group to be normal. Normal indicates a state where no attack is being performed or where countermeasures have been taken against vulnerabilities. The risk information determination unit 654 may classify the vulnerability risk of each group into any number of stages, not limited to two stages.

[0054] In this way, the risk information determination unit 654 calculates a corrected score for each device managed by each group, and determines risk information for vulnerabilities owned by each group based on the total number of devices managed by each group and the corrected score for each device. This allows the information processing system 1 to easily determine (calculate) risks for each group into which an organization is subdivided, thereby reducing the processing load in notification processing. Furthermore, the information processing system 1 can identify high-risk groups for each group into which an organization is subdivided and take focused measures, thereby improving the safety of each organization.

[0055] In particular, the risk information determination unit 654 determines risk information about vulnerabilities of each group based on the ratio of the number of devices with corrected scores greater than the threshold to the total number of devices managed by each group. This allows the information processing system 1 to accurately determine the risk of vulnerabilities of each group, thereby improving the safety of each organization.

[0056] Furthermore, the risk information determination unit 654 determines risk information for each of groups related to multiple hierarchical levels, i.e., for a specific group and each of the groups that include that specific group. This allows the information processing system 1 to accurately determine which hierarchical level group should be addressed for groups that have an inclusion relationship, such as a business division, department, or section, and efficiently improve the safety of each organization.

[0057] The group may include a group that includes the entire organization. That is, the risk information determination unit 654 may calculate risk information indicating the vulnerability risk of each organization based on the corrected scores of all devices managed by each organization.

[0058] Next, the output control unit 655 outputs the risk information for each group determined by the risk information determination unit 654 by transmitting it to the notification device 50 (step S115). In this way, the output control unit 655 outputs risk information for each of the multiple groups included in each organization. The notification device 50 receives the risk information from the information processing device 60 and displays the received risk information on a display unit (not shown), thereby notifying the administrator of the information processing system 1 of the risk for each group. The output control unit 655 may transmit the risk information for each group to a terminal device owned by a predetermined administrator or person in charge of each group. When the processing of steps S114 to S115 has been executed for all groups included in each organization, the output control unit 655 ends the notification processing.

[0059] Note that either one of the processes of steps S103 to S107 or the processes of steps S108 to S112 may be omitted. Also, the process of step S104 may be omitted. Also, the process of step S105 may be omitted, and either the process of step S106 or the process of step S107 may be executed in a fixed manner. Also, the process of step S109 may be omitted. Also, the process of step S110 may be omitted, and either the process of step S111 or the process of step S112 may be executed in a fixed manner. Also, the processes of steps S114 to S115 may not be executed for each group, but may be executed only once for one organization.

[0060] 6(A) and 6(B) are schematic diagrams showing examples of display screens displayed on the notification device 50 or the terminal device. Fig. 6(A) shows a display screen 600 when the vulnerability risk of a group is in normal times, and Fig. 6(B) shows a display screen 600 when the vulnerability risk of a group is in an emergency. As shown in Figs. 6(A) and 6(B), each display screen displays the total number of devices managed by each group, the number and percentage of devices whose status is emergency, important, warning, caution, or safe, etc. By referring to each display screen, the administrator can visually and accurately grasp the vulnerability risk of each group.

[0061] As described above, the information processing system 1 acquires attack information related to attacks based on vulnerabilities, and identifies vulnerability risks posed to organizations that manage devices based on the acquired attack information. Therefore, the information processing system 1 can more accurately identify vulnerability risks posed to organizations that manage devices. Furthermore, the information processing system 1 identifies the vulnerability risk of each group based on the total number of devices managed by each group included in the organization and the score related to the vulnerability risk of each device. Therefore, the information processing system 1 can more appropriately identify the vulnerability risk of each group in an organization that includes multiple groups.

[0062] This allows the administrator of the information processing system 1 to more easily and accurately determine the importance of risks in information security and the priority of measures to be taken against the risks before they occur. In recent years, there has been an increase in cyber attacks that do not target individual organizations, but target multiple organizations that are linked together in business or on a network, such as in a supply chain. The information processing system 1 can improve the security of each organization that is linked together in business or on a network by taking into consideration the relationships between multiple organizations and the damage status of related organizations. Furthermore, the information processing system 1 can more accurately identify the risk of vulnerability that an organization has by taking into consideration the trends of the attacker and the relevance to the organization that is the target of the attack. The administrator of the information processing system 1 can easily and accurately determine the risk of threats occurring or likely to occur in devices used by each organization and the need for a response, thereby preventing damage from occurring or minimizing the extent of the damage. Therefore, the information processing system 1 can improve the security of each organization. [Explanation of symbols]

[0063] 1 Information processing system, 60 Information processing device, 64 Memory unit, 651 Standard score acquisition unit, 652 Attack information acquisition unit, 653 Corrected score calculation unit, 654 Risk information determination unit, 655 Output control unit

Claims

1. a storage unit that stores device information indicating devices managed by the organization; a standard score acquisition unit that acquires a standard score related to a vulnerability risk of each device managed by the organization; an attack information acquisition unit that acquires, for each vulnerability, attack information regarding attacks based on each vulnerability; a corrected score calculation unit that calculates a corrected score for each of the vulnerabilities by correcting the reference score of the device having each vulnerability based on the attack information; an output control unit that outputs information indicating a vulnerability risk of the organization based on the corrected score; An information processing system comprising:

2. The information processing system according to claim 1 , wherein the attack information acquisition unit acquires, as the attack information, trend information indicating trends of attacking organizations that carry out attacks based on each vulnerability.

3. The information processing system according to claim 1 , wherein the attack information acquisition unit acquires, as the attack information, trend information of an attacking organization that launches attacks based on each vulnerability against the organization or an associated organization related to the organization.

4. The information processing system according to claim 3 , wherein the corrected score calculation unit calculates different corrected scores for a case where the organization is attacked based on each vulnerability and a case where the related organization is attacked based on each vulnerability.

5. The information processing system according to claim 1 , wherein the attack information acquisition unit acquires, as the attack information, damage information indicating victim organizations that have been attacked based on each vulnerability.

6. The information processing system according to claim 5 , wherein the corrected score calculation unit calculates the corrected score when the organization or an associated organization related to the organization is attacked based on each vulnerability.

7. 7. The information processing system according to claim 6, wherein the corrected score calculation unit calculates different corrected scores for a case where the organization is attacked based on each vulnerability and a case where the related organization is attacked based on each vulnerability.

8. storing device information indicating devices managed by the organization; obtaining a baseline score for each device managed by the organization regarding the risk of vulnerabilities that each device has; For each vulnerability, obtain attack information regarding attacks based on each vulnerability; calculating a corrected score for each of the vulnerabilities by correcting the reference score for each of the devices having the vulnerabilities based on the attack information; outputting information indicating the vulnerability risk of the organization based on the corrected score; 1. An information processing method comprising:

Citation Information

Patent Citations

  • Security rule evaluation device and security rule evaluation system

    JP2018077607A

  • Threat information sharing system between a plurality of organizations and method

    JP2019191657A

  • Electronic apparatus, image forming apparatus, and security level management program

    JP2020067983A

  • Information processing device, information processing method, data structure, and program

    JP2021060665A

  • Cyber attack scenario generation method, and device

    JP2022076159A