Countermeasure proposal device, countermeasure proposal method, and countermeasure proposal program
The countermeasure proposal device uses a learning model to estimate security behavior probabilities and threat impacts, enabling targeted countermeasure prioritization and implementation guidance for enhanced security.
Patent Information
- Application Number
- JP2024110017
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-07-09
- Publication Date
- 2026-01-22
AI Technical Summary
Existing methods fail to provide users and organizations with clear guidance on prioritizing and implementing necessary security measures based on their current implementation status and the potential impacts of not performing these measures, limiting the effectiveness of security improvements.
A countermeasure proposal device and method that generates a feature vector from user responses to a security behavior questionnaire, uses a learning model to estimate the probability of non-performance of security behaviors, sets impacts based on relevant threats, and calculates priorities for proposed countermeasures, providing targeted recommendations.
Enables users and organizations to understand their security implementation status and prioritize effective countermeasures, improving overall security levels by addressing specific vulnerabilities.
Smart Images

Figure 2026010280000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a countermeasure proposal device, a countermeasure proposal method, and a countermeasure proposal program that propose countermeasures to be implemented for various security actions. [Background technology]
[0002] In recent years, cyber attacks using malware have become more sophisticated, causing numerous incidents of spam emails and unauthorized access, necessitating the implementation of more stringent security measures by users and organizations such as companies.
[0003] For example, in Non-Patent Document 1, a psychological scale (Security behavior intention scale: SeBIS) is proposed to measure behavioral intentions for four security behaviors (ensuring device security, password generation, active attention, and updates) based on self-reporting.
[0004] Furthermore, Non-Patent Document 2 shows that the behavioral intentions regarding the four security behaviors that can be estimated by SeBIS are highly related to the implementation status of those four security behaviors. In other words, it suggests that it is possible to estimate actual behavior from behavioral intentions (SeBIS scores).
[0005] Non-Patent Document 3 similarly proposes estimating various other behaviors in addition to these five behaviors based on a questionnaire about five security behaviors (ensuring data safety, active attention, antivirus, updates, and password generation).
[0006] On the other hand, Non-Patent Document 4 proposes that when trying to predict whether a user will be directed to a dangerous site (i.e., low active attention), machine learning is performed using a feature vector generated from session information regarding the most recent website access, as well as questions measuring active attention from the Japanese version of SeBIS (RSeBIS).
[0007] Non-Patent Document 5 proposes a method for assessing knowledge about information security by answering test-style questions and improving skills corresponding to each test item.
[0008] Non-Patent Document 6 provides a checklist that asks about the implementation status of measures within an organization and information on items where measures have not been implemented. It also presents a tool that enables users (or managers) within an organization to check the measures that have low scores on the checklist and check the measures that should be implemented. [Prior art documents] [Non-patent literature]
[0009] [Non-Patent Document 1] Serge Egelman and Eyal Peer. 2015. Scaling the Security Wall: Developing a Security Behavior Intentions Scale (SeBIS). In Proceedings of the 33rd Annual ACM Conference on Human Factors in Computing Systems (CHI '15). Association for Computing Machinery, New York, NY, USA, 2873-2882. [Non-patent document 2] Serge Egelman, Marian Harbach, and Eyal Peer. 2016. Behavior Ever Follows Intention? A Validation of the Security Behavior Intentions Scale (SeBIS). In Proceedings of the 2016 CHI Conference on Human Factors in Computing Systems (CHI '16). Association for Computing Machinery, New York, NY, USA, 5257-5261. [Non-Patent Document 3] Yukiko Sawaya, Sarah Lu, Takamasa Isohara, Mahmood Sharif, A High Coverage Cybersecurity Scale Predictive of User Behavior, The 33rd USENIX Security Symposium, 2024.(https: / / www.usenix.org / conference / usenixsecurity24 / presentation / sawaya) [Non-Patent Document 4] Mahmood Sharif, Jumpei Urakawa, Nicolas Christin, Ayumu Kubota, and Akira Yamada. 2018. Predicting Impending Exposure to Malicious Content from User Behavior. In Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security (CCS '18). Association for Computing Machinery, New York, NY, USA, 1487-1501. [Non-Patent Document 5] Self-check site for information security knowledge, JNSA Information Security Understanding Self-Check (http: / / slb.jnsa.org / slbm / ) [Non-patent document 6] IPA In-house diagnosis in 5 minutes! (https: / / security-shien.ipa.go.jp / diagnosis / ) Summary of the Invention [Problem to be solved by the invention]
[0010] In Non-Patent Documents 1-4, behavior can be predicted, and if risky behavior or non-implementation of security measures is predicted, the user only understands it and is unable to know how to improve it. Furthermore, in Non-Patent Document 5, the proposed method is limited to the skills corresponding to each test item, and priorities and the like are not taken into consideration, so the user cannot determine which measures to implement first. Furthermore, Non-Patent Document 6 also does not consider the priorities of the measures that should be taken by the company, so managers or users within the organization cannot determine which measures should be implemented first.
[0011] The present invention aims to provide a countermeasure proposal device, a countermeasure proposal method, and a countermeasure proposal program that, when each user or organization has grasped the status of their own countermeasure implementation, proposes what countermeasures to prioritize and what method to use to implement them. [Means for solving the problem]
[0012] The countermeasure proposal device of the present invention comprises: a feature vector generation unit that generates a feature vector including at least a quantified security behavior status from the subject's answers to a questionnaire regarding security behavior; an estimation unit that inputs the feature vector of the subject generated by the feature vector generation unit into a learning model that has been generated in advance using teacher data of the feature vector of an arbitrary user and the arbitrary user's actual behavioral results for each of a plurality of information security behaviors, and estimates the probability that the subject has not performed each of the plurality of behaviors; and a feedback unit, wherein the feedback unit comprises: an impact setting unit that sets an impact for each of the plurality of behaviors based on the most relevant threat among a plurality of threats in the information security for each of the plurality of behaviors; a countermeasure / action setting unit that sets proposed countermeasures / actions against threats related to each of the plurality of behaviors; and a countermeasure / action proposal unit that calculates the priority of the countermeasures / actions based on the probability that the subject has not performed each of the plurality of behaviors estimated by the estimation unit and the impact for each of the plurality of behaviors set by the impact setting unit, and outputs the proposed countermeasures / actions in order of the calculated priority.
[0013] The influence setting unit may set the influence of each of the plurality of behaviors for each of the target persons.
[0014] The measure / action suggestion unit may calculate the probability of not performing each of the plurality of behaviors in the organization based on the probability of not performing each of the plurality of behaviors of individual subjects belonging to the organization estimated by the estimation unit.
[0015] The impact setting unit may inquire of an external AI device about the most relevant threat among the plurality of threats for each of the plurality of actions, and set the impact for each of the plurality of actions based on a response from the AI device.
[0016] When the subject is an individual, the impact setting unit may set the impact of each of the plurality of actions for each subject based on the subject's frequency of use of each service provided via a network.
[0017] The system may also include an action quantification unit that quantifies the actual action results of whether or not the subject actually performed each of the plurality of actions, and a learning model generation unit that performs machine learning using the feature vector and the quantified actual action results for each of the plurality of actions, and generates the learning model.
[0018] The feature vector generation unit may calculate a degree of deviation between the answers to the security behavior questionnaire and the actual behavior, and include the calculated degree of deviation as a vector element of the feature vector.
[0019] The countermeasure proposal method of the present invention comprises: a feature vector generation step of generating a feature vector including at least a quantified security behavior status from the subject's answers to a questionnaire regarding security behavior; an estimation step of inputting the feature vector of the subject generated by the feature vector generation step into a learning model that has been generated in advance using teacher data of the feature vector of an arbitrary user and the arbitrary user's actual behavioral results for each of a plurality of information security behaviors, and estimating the probability that the subject has not performed each of the plurality of behaviors; and a feedback step, wherein the feedback step comprises an impact setting step of setting an impact for each of the plurality of behaviors based on the most relevant threat among a plurality of threats in the information security for each of the plurality of behaviors; a countermeasure / action setting step of setting proposed countermeasures / actions for each of the plurality of behaviors; and a countermeasure / action proposal step of calculating priorities of the countermeasures / actions based on the probability that the subject has not performed each of the plurality of behaviors estimated by the estimation step and the impact for each of the plurality of behaviors set by the impact setting step, and outputting the proposed countermeasures / actions in order of the calculated priorities.
[0020] A countermeasure proposal program according to the present invention is for causing a computer to function as the countermeasure proposal device. [Effects of the Invention]
[0021] According to the present invention, when each user or organization is able to grasp the status of their own countermeasure implementation, it is possible to propose what to prioritize and what method to use to implement the countermeasures. [Brief explanation of the drawings]
[0022] [Figure 1] FIG. 2 is a diagram illustrating a functional configuration of a countermeasure proposal device according to the present embodiment. [Figure 2] FIG. 2 is a diagram showing an example of a questionnaire in the present embodiment. [Figure 3] FIG. 1 is a diagram showing an example of the top 10 information security threats for an individual in this embodiment. [Figure 4] FIG. 10 is a diagram illustrating an example of an individual influence table according to the present embodiment. [Figure 5] FIG. 10 is a diagram illustrating an example of a prompt according to the present embodiment. [Figure 6] FIG. 6 is a diagram showing an example of a response from an AI device to the prompt in FIG. 5. [Figure 7] FIG. 1 is a diagram showing an example of the top 10 information security threats in the case of an organization in this embodiment. [Figure 8] 10 is a flowchart showing a countermeasure proposal process of the countermeasure proposal device in the present embodiment. [Figure 9] FIG. 10 is a diagram illustrating an example of a correspondence table. [Figure 10] FIG. 10 is a diagram illustrating an example of a usage frequency table. [Figure 11] FIG. 10 is a diagram illustrating an example of an individual influence table. DETAILED DESCRIPTION OF THE INVENTION
[0023] An example of one embodiment of the present invention will be described below. First, an outline of this embodiment will be described. In this embodiment, the countermeasure proposal device uses a psychological scale capable of measuring four security behaviors (ensuring device security, password generation, active attention, and updates) or a psychological scale capable of measuring five security behaviors (ensuring data security, active attention, antivirus, updates, and password generation) to estimate the implementation status of various behaviors as a probability of not performing the behavior. The countermeasure proposal device stores in advance the impact of not performing each security behavior, prioritizes the countermeasures to be implemented based on the probability of not performing the behavior and the impact, and provides information on how to implement each countermeasure, thereby realizing a system that enables each user or organization to prioritize the implementation of necessary countermeasures. The above is an outline of this embodiment.
[0024] 1 is a diagram showing the functional configuration of a countermeasure proposal device 1 in this embodiment. Here, a case where a psychological scale capable of measuring four security behaviors (ensuring device security, password generation, active attention, and updates) is used is illustrated. Note that the present invention is also applicable to a case where a psychological scale capable of measuring five security behaviors (ensuring data security, active attention, antivirus, updates, and password generation) is used. The countermeasure proposal device 1 is an information processing device (computer) equipped with a control unit 10, a storage unit 20, various data input / output devices, communication devices, etc. The countermeasure proposal device 1 is a terminal on which software for realizing each function of this embodiment is installed, which generates a feature vector including at least a quantified security behavior status from responses to a questionnaire about security behavior by users within an organization or general users, estimates the probability that each of a plurality of information security behaviors has not been performed by inputting the generated feature vector into a learning model, calculates the priority of countermeasures / actions to be implemented based on the estimation result, and proposes countermeasures / actions in the calculated order of priority.
[0025] The control unit 10 is a part that controls the entire countermeasure proposal device 1, and operates as each functional unit described below by appropriately reading and executing various programs stored in the storage unit 20, thereby realizing each function in this embodiment. The control unit 10 may be a CPU.
[0026] The storage unit 20 is a storage area for various programs for causing the hardware group to function as the countermeasure proposal device 1, various data, etc., and may be a ROM, RAM, flash memory, hard disk drive (HDD), or the like. Specifically, the memory unit 20 may store software (countermeasure proposal program) for causing the control unit 10 to execute each function of this embodiment, as well as various databases such as responses to questionnaires by each subject linked to the identifiers of users within an organization or general users, quantified actions indicating whether or not the security behavior was actually performed, and operation logs related to security behavior from each subject's user terminal (e.g., PC, smartphone, tablet terminal, etc.).
[0027] The control unit 10 includes a feature vector generation unit 110, an execution behavior digitization unit 111, a matching unit 112, a learning model generation unit 113, an estimation unit 114, an individual feedback unit 115, and an organization feedback unit 116. The individual feedback unit 115 includes an influence setting unit 1151, a measure / action setting unit 1152, and a measure / action suggestion unit 1153. The organization feedback unit 116 includes an influence setting unit 1161, a measure / action setting unit 1162, and a measure / action suggestion unit 1163.
[0028] The feature vector generation unit 110 generates a feature vector including at least a numerical value of security behavior status from the subject's answers to a questionnaire about security behavior. Note that the subject may be an individual within an organization, a general user, or an organization (e.g., a company). Specifically, the feature vector generation unit 110 uses, for example, a questionnaire shown in FIG. 2 to measure four security behaviors (subscales). Each subject answers 16 self-reported questions with one of the following responses: "never," "rarely," "occasionally," "often," or "always" to the questionnaire. The questionnaire may include questions about other attribute information (e.g., gender, age, frequency of use of various services, etc.) in addition to the 16 questions measuring the four security behaviors (subscales "device safety," "password generation," "active attention," and "updates"). The feature vector generation unit 110 associates each subject's responses with their identifiers and stores them in the storage unit 20.
[0029] The feature vector generation unit 110 may numerically represent the answers to the questionnaire in FIG. 2 as, for example, "1" for "never," "2" for "rarely," "3" for "occasionally," "4" for "often," and "5" for "always." The feature vector generation unit 110 may sum up the numerical values of the answers for each of the security behaviors, "device security," "password generation," "active attention," and "update." That is, the sum of the values for "device security" is between 4 and 20. The sum of the values for "password generation" is between 4 and 20. The sum of the values for "active attention" is between 5 and 25. The sum of the values for "update" is between 3 and 15. The feature vector generation unit 110 generates a feature vector consisting of the total value for each of the items "Device Security," "Password Generation," "Active Attention," and "Updates," a numerical value indicating the gender of the subject, with "1" representing "Male" or "0" representing "Female," and a numerical value indicating the age of the subject.
[0030] The action digitizing unit 111 digitizes the actual action result of whether or not the subject actually performs each of a plurality of actions related to information security (hereinafter also referred to as "actions B1 to Bn") (n is an integer of 2 or more). Specifically, the behavior quantifying unit 111 tracks the OS update status, etc., of n behaviors B1 to Bn (e.g., OS updates) to be estimated for each subject by using logs or the like of an IT asset management system. Alternatively, the behavior quantifying unit 111 may request each subject to check the status of their OS and accept a self-report of whether or not the OS has been updated. Based on the tracking results and the self-reported results, the behavior quantifying unit 111 quantifies behavior Bi as "1" if the OS is up to date, and "0" if not (i is an integer from 1 to n). Note that System Support best1 (registered trademark) (https: / / www.dos-osaka.co.jp / ss1 / point / ) or the like may be used as the IT asset management system. The actual behavior quantifying unit 111 stores the actual behavior results for each of the quantified behaviors B1 to Bn in the storage unit 20 in association with the identifier of the subject.
[0031] The matching unit 112 uses the subject's identifier as a key to associate the feature vector of any user generated by the feature vector generation unit 110 with the actual behavioral results for each of the user's actions B1 to Bn quantified by the action quantification unit 111, thereby creating training data.
[0032] The learning model generation unit 113 performs machine learning using training data of the feature vector of an arbitrary user and the actual behavioral results for each of the quantified actions B1 to Bn, and generates a learning model that estimates the probability that the subject has not performed each of the actions B1 to Bn by inputting the feature vector of the subject generated by the feature vector generation unit 110. Specifically, the learning model uses a general learning algorithm, for example. That is, the learning model generation unit 113 selects a combination of feature vectors and parameters by grid search, and generates a learning model that outputs the probability that behavior Bi has not been performed by using random forest. The learning model generation unit 113 stores the generated learning model in the storage unit 20.
[0033] When the learning model generation unit 113 generates a learning model using the feature vector, the feature vector generation unit 110 may generate a feature vector including additional vector elements. That is, the feature vector generation unit 110 vectorized the feature vector based on the self-reported results, which are the answers to the questionnaire in FIG. 2 . However, the authenticity of the self-reported results may not be certain based on the self-report alone. Therefore, the feature vector generation unit 110 may, for example, collect log data related to at least one behavior Bi among the self-reported behaviors via an IT asset management system, compare the self-reported results with the log data, and generate a feature vector including the degree of discrepancy as one vector element. That is, the feature vector generation unit 110 may, for example, compare a question about the OS update status (update behavior) with the collected log data on the actual update status, and generate a feature vector including a vector element with a value of "0" if there is consistency and a value of "1" if there is no consistency. The learning model generation unit 113 can improve estimation accuracy by learning using the feature vector including this vector element.
[0034] The estimation unit 114 inputs the feature vector generated by the feature vector generation unit 110 from the responses to the questionnaire of the subject to be estimated into a learning model, and estimates the probabilities P1 to Pn that the subject has not performed each of the behaviors B1 to Bn. Here, n is assumed to be around 20 to 30.
[0035] When the subject is an individual, the individual feedback unit 115 uses the probabilities P1 to Pn of not performing the behavior estimated by the estimation unit 114 to present the subject with the necessary measures / actions.
[0036] The impact setting unit 1151 sets an impact level for each of the actions B1 to Bn based on the most relevant threat among a plurality of threats in information security for each of the actions B1 to Bn. Specifically, the impact setting unit 1151 determines and sets the impact I1 to In of each behavior B1 to Bn on an individual using, for example, the top 10 information security threats provided by the Information-technology Promotion Agency, Japan (IPA) shown in Fig. 3. That is, the impact setting unit 1151 assigns "10" to the highest-ranked threat among the top 10 information security threats shown in Fig. 3 and "1" to the lowest-ranked threat, determines which threat each behavior B1 to Bn is related to, and manually or automatically sets the numerical value corresponding to the highest rank among the related threats as the impact Ii of the behavior Bi. FIG. 4 is a diagram showing an example of an individual influence table in this embodiment. As shown in Figure 4, behavior B1 is most closely related to "theft of personal information through phishing," which is ranked first among the top 10 information security threats, and therefore is assigned an impact I1 of "10." Additionally, behavior B2 is most closely related to "theft of personal information from online services," which is ranked eighth among the top 10 information security threats, and therefore is assigned an impact I2 of "3." Additionally, behavior Bn is most closely related to "harm to smartphone users caused by malicious apps," which is ranked sixth among the top 10 information security threats, and therefore is assigned an impact In of "5."
[0037] The impact setting unit 1151 sets the impacts I1 to In of the actions B1 to Bn manually or automatically, but is not limited to this. For example, the impact setting unit 1151 may generate a prompt inquiring about the threat of "using a VPN when using public Wi-Fi (registered trademark)" as an action Bi in addition to the top 10 information security threats in Figure 3, and transmit the generated prompt to an external AI device (not shown). Fig. 5 is a diagram showing an example of a prompt in this embodiment, and Fig. 6 is a diagram showing an example of a response from an AI device (not shown) to the prompt in Fig. 5. As shown in FIG. 6, the impact setting unit 1151 may receive a response from the AI device as to which threat an action Bi is associated with, and automatically set the impact Ii of the action Bi.
[0038] Furthermore, for example, if it is stated that "theft of personal information from online services" is ranked eight times in five consecutive years among the top ten threats to information security, the impact setting unit 1151 may set the impact Ii of the action Bi after normalizing the "5" for "five consecutive years" and the "8" for "ranked eight times" to a value between 1 and 10.
[0039] The impact setting unit 1151 may also set the number of threats related to the behavior Bi among the top 10 information security threats in FIG. 3 as the impact Ii.
[0040] The countermeasure / action setting unit 1152 sets proposed countermeasures / actions for threats associated with each of the actions B1 to Bn. Specifically, for example, when the behavior Bi is "(not) reusing passwords," the measure / action setting unit 1152 sets suggested content for measures / actions to be proposed to the target person to prevent the reusing of passwords (for example, information about available password managers, or a method for setting an easy-to-remember password for each service). Here, the suggested content for measures / actions to be set may be text only, or may use images or videos. Furthermore, the measure / action setting unit 1152 may create a library of suggested content and store it in the storage unit 20. In this case, the measure / action suggesting unit 1153, which will be described later, calls up necessary suggested content from the storage unit 20. Furthermore, if the gender, age, literacy, etc. of the subject can be ascertained from the questionnaire, the measure / action setting unit 1152 may change the display of suggested content for each highly effective measure / action according to the attributes of the subject. In this case, the measure / action setting unit 1152 assigns meta information such as the subject's attributes to each suggested content, so that the measure / action suggesting unit 1153, which will be described later, can output suitable, highly effective suggested content to the subject's terminal.
[0041] The countermeasure / action suggestion unit 1153 calculates the priority of countermeasures / actions based on the probability P1 to Pn of the subject not performing each of the actions B1 to Bn estimated by the estimation unit 114 and the impact I1 to In for each of the actions B1 to Bn set by the impact setting unit 1151, and outputs proposals for countermeasures / actions in the calculated order of priority. Specifically, the measure / action suggestion unit 1153 calculates the value of influence Ii x probability Pi for each behavior Bi as a priority using, for example, the individual influence table of Fig. 4, and arranges the calculated priorities in descending order. The measure / action suggestion unit 1153 reads proposed content for measures / actions from the storage unit 20 in order of priority, and outputs the proposed content to the target person's terminal, such as a PC, smartphone, or tablet terminal. In addition, the measure / action suggestion unit 1153 may arrange, based on a preset threshold T, the actions Bi for which the probability Pi of not performing the action is higher than the threshold T, in descending order of impact Ii as a priority.
[0042] Furthermore, as will be described later, when the influence setting unit 1161 of the organizational feedback unit 116 sets the influence O1 to On of each of the actions B1 to Bn on the organization, the countermeasure / action proposing unit 1153 may use the influence I and influence O of both the individual and the organization. In this case, for example, based on the number E of employees in the organization, the weight on the organization is 1-1 / logE and the weight on the influence I on the individual is logE (log base is 10), so the countermeasure / action proposing unit 1153 may calculate the total influence of each action Bi using formula (1). Total impact = Ii × logE + Oi × (1-1 / logE) (1) The measure / action proposing unit 1153 may calculate the value of the total influence degree x probability Pi as the priority.
[0043] When the target person is an organization (e.g., a company, etc.), the organizational feedback unit 116 uses the probabilities P1 to Pn of individual users belonging to the organization not performing the behavior estimated by the estimation unit 114 to present the target person (e.g., a manager, etc.) with the necessary measures / actions.
[0044] As in the case of the impact setting unit 1151, the impact setting unit 1161 sets an impact for each of the actions B1 to Bn based on the most relevant threat among a plurality of information security threats for each of the actions B1 to Bn. Specifically, the impact setting unit 1161 determines the impact O1 to On of each action B1 to Bn on the organization using, for example, the Top 10 Information Security Threats (Top 10 Information Security Threats 2023, Information Security, IPA, Information-technology Promotion Agency, Japan (https: / / www.ipa.go.jp / security / 10threats / 10threats2023.html)) provided by the Information-technology Promotion Agency, Japan (IPA) shown in FIG. 7, and manually or automatically sets the organizational impact table. The impact setting unit 1161 may also set the number of threats related to the behavior Bi among the top 10 information security threats in FIG. 7 as the impact Oi.
[0045] The countermeasure / action setting unit 1162, like the countermeasure / action setting unit 1152, sets, for each of the actions B1 to Bn, a countermeasure / action proposal for a related threat.
[0046] The countermeasure / action suggestion unit 1163 calculates the priority of countermeasures / actions based on the probability P1 to Pn of not performing each of the actions B1 to Bn of individual users belonging to the organization estimated by the estimation unit 114 and the impact O1 to On for each of the actions B1 to Bn set by the impact setting unit 1161, and outputs proposals for countermeasures / actions in the calculated order of priority. Specifically, the measure / action suggestion unit 1163 calculates the probability that an action Bi in the organization has not been performed, based on the probability Pi of each individual user belonging to the organization not performing the action Bi estimated by the estimation unit 114. For example, the measure / action suggestion unit 1163 may calculate a statistical value such as the average or median of the estimated probabilities Pi of each individual user belonging to the organization not performing the action Bi as the probability Qi of each individual user not performing the action Bi in the organization. The measure / action suggestion unit 1163 uses an organizational influence table to calculate the value of influence Oi x probability Qi for each action Bi as a priority, and sorts the calculated priorities in descending order. The measure / action suggestion unit 1163 reads proposed content for measures / actions from the storage unit 20 in order of priority, and outputs the proposed content to a terminal of a target person (e.g., a manager of an information system in the organization). In addition, the measure / action suggestion unit 1163 may arrange, based on a preset threshold T, the actions Bi for which the probability Pi of not performing the action is higher than the threshold T, in descending order of impact Oi as a priority.
[0047] Furthermore, the measure / action proposing unit 1163 may calculate the total impact of each behavior Bi using the impact I and impact O of both the individual and the organization and equation (1). The measure / action proposing unit 1163 may calculate the value of total impact x probability Qi as the priority.
[0048] FIG. 8 is a flowchart showing the countermeasure proposal process of the countermeasure proposal device 1 in this embodiment. Here, an example will be given in which the subject is an individual, but the same applies to the case of an organization, and a description thereof will be omitted.
[0049] In step S11, the feature vector generating unit 110 generates a feature vector including a security behavior situation quantified based on the subject's answers to a questionnaire regarding security behavior.
[0050] In step S12, the estimation unit 114 inputs the feature vector generated in step S11 into the learning model, and estimates the probability P1 to Pn of not performing each of the actions B1 to Bn.
[0051] In step S13, the countermeasure / action suggestion unit 1153 calculates the priority of the countermeasure / action based on the probability Pi that the subject is not performing the action for each action Bi estimated in step S12 and the impact Ii for each action Bi that has been set.
[0052] In step S14, the measure / action suggestion unit 1153 outputs the measure / action suggestion contents to the target user's terminal in the calculated order of priority.
[0053] According to this embodiment, the countermeasure proposal device 1 generates a feature vector including a quantified security behavior status from the subject's answers to a questionnaire regarding security behavior, and inputs the generated feature vector into a learning model to estimate the probability P1 to Pn of not performing each of the actions B1 to Bn. The countermeasure proposal device 1 calculates the priority of countermeasures / actions based on the estimated probability Pi of not performing each of the subject's actions Bi and the set impact Ii (or Oi) for each action Bi, and outputs countermeasure / action proposal content to the subject's terminal in the calculated order of priority. In other words, when each user or organization understands the status of their own countermeasure implementation, the countermeasure proposal device 1 can propose what countermeasures should be prioritized and by what method, thereby improving the security countermeasure level of each user / organization.
[0054] <Variation 1> In this embodiment, when the target is an individual, the countermeasure proposal device 1 sets the impact I1 to In of each of the actions B1 to Bn on the target based on the top 10 information security threats provided by the IPA in Fig. 3, but is not limited to this. For example, when the target is an individual, the countermeasure proposal device 1 may set the impact I1 to In of each of the actions B1 to Bn based on the frequency of use of each service provided via the network for each target. Specifically, the influence setting unit 1151 may hold, for example, a correspondence table in which each of the actions B1 to Bn is previously associated with each of the services S1 to Sm provided via the network (m is an integer of 2 or more). 9 is a diagram showing an example of the association table. Note that the services S1 to Sm are, for example, services provided by financial applications, services provided by shopping sites, and the like. In addition, the influence setting unit 1151 accepts responses to a questionnaire regarding the frequency of use of services S1 to Sm for each individual subject (for example, a five-point scale rating of 1 to 5 for frequency of use per week), and stores a usage frequency table for each subject. FIG. 10 is a diagram illustrating an example of a usage frequency table. The influence setting unit 1151 sets, for each subject, the value of the five-level evaluation of the service with the highest usage frequency among the services associated with each behavior Bi, as the influence Ii, based on the association table in Fig. 9 and the usage frequency table in Fig. 10. The influence setting unit 1151 may be configured to hold an individual influence table shown in Fig. 11.
[0055] <Variation 2> In this embodiment, the countermeasure proposal device 1 calculates the probability of not performing the behavior Bi in the organization based on the probability Pi of not performing the behavior Bi of each estimated individual subject belonging to the organization, but is not limited to this. For example, the countermeasure proposal device 1 may generate a feature vector including a quantified security behavior situation from responses to a questionnaire about security behavior by an administrator of the organization's system, etc., and input the generated feature vector into a learning model to estimate the probability of not performing each of the behaviors B1 to Bn when the subject is an organization.
[0056] <Variation 3> In this embodiment, the countermeasure proposal device 1 has the execution behavior quantification unit 111, the matching unit 112, and the learning model generation unit 113, but is not limited to this. For example, the countermeasure proposal device 1 does not need to have the execution behavior quantification unit 111, the matching unit 112, and the learning model generation unit 113, and may acquire a learning model generated by an external machine learning device.
[0057] Furthermore, this embodiment can improve the level of security measures of each user / organization, thereby contributing to Goal 9 of the United Nations-led Sustainable Development Goals (SDGs), which is to "Develop resilient infrastructure, promote sustainable industrialization and foster innovation."
[0058] Although the embodiments of the present invention have been described above, the present invention is not limited to the above-described embodiments. Furthermore, the effects described in the above-described embodiments are merely a list of the most preferable effects resulting from the present invention, and the effects of the present invention are not limited to those described in the embodiments.
[0059] The countermeasure proposal method by the countermeasure proposal device 1 is realized by software. When realized by software, the programs constituting this software are installed in an information processing device (computer). These programs may be recorded on removable media such as CD-ROMs and distributed to users, or may be distributed by being downloaded to the user's computer via a network. Furthermore, these programs may be provided to the user's computer as a web service via a network without being downloaded. [Explanation of symbols]
[0060] 1. Countermeasure proposal device 10 Control Unit 110 Feature vector generation unit 111 Execution Motion Quantification Department 112 Butt joint 113 Learning model generation unit 114 Estimation Department 115 Personal Feedback Section 1151 Impact Setting Section 1152 Countermeasures / Action Setting Division 1153 Countermeasures / Action Proposal Department 116 Organizational Feedback Department 1161 Impact Setting Section 1162 Countermeasures / Action Setting Division 1163 Countermeasures / Action Proposal Department
Claims
1. a feature vector generation unit that generates a feature vector including at least a numerically quantified security behavior status from the subject's answers to a questionnaire regarding security behavior; an estimation unit that inputs the feature vector of the subject generated by the feature vector generation unit into a learning model that is generated in advance using teacher data of the feature vector of an arbitrary user and actual behavioral results of the arbitrary user for each of a plurality of behaviors related to information security, and estimates the probability that the subject has not performed each of the plurality of behaviors; a feedback unit, The feedback unit an impact setting unit that sets an impact level for each of the plurality of actions based on the most relevant threat among the plurality of threats in information security for each of the plurality of actions; a countermeasure / action setting unit that sets a countermeasure / action proposal for a threat associated with each of the plurality of actions; a measure / action suggestion unit that calculates priorities of the measures / actions based on the probability that the subject has not performed each of the plurality of actions estimated by the estimation unit and the impact of each of the plurality of actions set by the impact setting unit, and outputs proposals for the measures / actions in the calculated order of priority. Countermeasure suggestion device.
2. The countermeasure proposal device according to claim 1 , wherein the influence setting unit sets the influence of each of the plurality of actions for each of the target persons.
3. 3. The countermeasure proposal device according to claim 1, wherein the countermeasure / action proposal unit calculates a probability of not performing each of the plurality of behaviors in the organization based on a probability of not performing each of the plurality of behaviors of individual subjects belonging to the organization estimated by the estimation unit.
4. 3. The countermeasure proposal device according to claim 1, wherein the impact setting unit queries an external AI device for each of the plurality of actions regarding the most relevant threat among the plurality of threats, and sets the impact for each of the plurality of actions based on a response from the AI device.
5. 3. The countermeasure proposal device according to claim 1, wherein the impact setting unit sets the impact of each of the plurality of actions for each of the target persons based on the target person's frequency of use of each of services provided via a network.
6. an action quantification unit that quantifies the actual action results, indicating whether or not the subject actually performed each of the plurality of actions; 3. The countermeasure proposal device according to claim 1, further comprising: a learning model generation unit that performs machine learning using the feature vector and actual behavioral results for each of the plurality of quantified behaviors, and generates the learning model.
7. 3. The countermeasure proposal device according to claim 1, wherein the feature vector generation unit calculates a degree of deviation between the answers to the security behavior questionnaire and actual behavior, and includes the calculated degree of deviation as a vector element of the feature vector.
8. a feature vector generation step of generating a feature vector including at least a numerically quantified security behavior status from the subject's answers to a questionnaire regarding security behavior; an estimation step of inputting the feature vector of the subject generated by the feature vector generation step into a learning model that has been generated in advance using training data of the feature vector of an arbitrary user and actual behavioral results of the arbitrary user for each of a plurality of behaviors related to information security, and estimating the probability that the subject has not performed each of the plurality of behaviors; a feedback step, The feedback step comprises: an impact setting step of setting an impact level for each of the plurality of actions based on the most relevant threat among the plurality of threats in information security for each of the plurality of actions; a measure / action setting step of setting a measure / action proposal for each of the plurality of actions; a measure / action proposing step of calculating priorities of the measures / actions based on the probability that the subject has not performed each of the plurality of actions estimated in the estimation step and the impact of each of the plurality of actions set in the impact setting step, and outputting proposals of the measures / actions in the order of the calculated priorities. How to propose measures.
9. A countermeasure proposal program for causing a computer to function as the countermeasure proposal device according to claim 1 or 2.