Information processing system, information processing method, and program

The information processing system addresses the challenge of obtaining vulnerability information by employing multiple detection processes, ensuring efficient and accurate detection through snapshots, agent-based configuration scanning, and reconstructed scanning systems.

JP2026014753AActive Publication Date: 2026-01-29BIZREACH INC
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2024116178
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-07-19
Publication Date
2026-01-29
Estimated Expiration
2044-07-19

AI Technical Summary

Technical Problem

Existing technologies face challenges in easily obtaining vulnerability information from detection target systems.

Method used

An information processing system that executes multiple detection processes, including a first detection process using a snapshot, a second detection process with an agent for system configuration information, and a third detection process with a reconstructed scanning system, to detect vulnerability information.

Benefits of technology

Enables easy and comprehensive detection of vulnerability information by selecting the appropriate process based on the detection target system's configuration and environment, enhancing detection accuracy and efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026014753000001_ABST
    Figure 2026014753000001_ABST
Patent Text Reader

Abstract

To provide an information processing system, method and program for facilitating acquisition of vulnerability information in a system.SOLUTION: In an information processing system, a processor of an information processing device executes, in a vulnerability detection step, at least two processes of a first detection process, a second detection process, and a third detection process on a detection target system that detects vulnerability information, executes, in the first detection process, scanning of vulnerability information on a first snapshot in which a state of the detection target system is saved, and causes an agent to acquire configuration information of the detection target system in the second detection process. Scanning of vulnerability information is executed on the configuration information, and in the third detection processing, a second snapshot storing a state of at least a part of the detection target system is acquired, at least a part of the detection target system is reconstructed as a scanning system on the basis of the second snapshot, and scanning of vulnerability information is executed on the scanning system.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an information processing system, an information processing method, and a program. [Background technology]

[0002] Patent Document 1 describes a method for detecting vulnerability information contained in software. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2008-165794 Summary of the Invention [Problem to be solved by the invention]

[0004] Therefore, there is a need for technology that makes it easier to obtain vulnerability information.

[0005] In view of the above circumstances, the present invention provides an information processing system and the like that can easily acquire vulnerability information in a system. [Means for solving the problem]

[0006] According to one aspect of the present invention, there is provided an information processing system comprising at least one processor, the processor being configured to execute the following steps by reading a program: in the vulnerability detection step, at least two of a first detection process, a second detection process, and a third detection process are executed on a detection target system for detecting vulnerability information; in the first detection process, a scan for vulnerability information is executed within the detection target system using a first snapshot created within the detection target system and saving the state of at least a portion of the detection target system; in the second detection process, an agent installed in the detection target system for collecting system configuration information is caused to obtain the configuration information of at least a portion of the detection target system, and the configuration information is received, and a scan for vulnerability information is executed on the configuration information; and in the third detection process, a second snapshot is obtained within the detection target system saving the state of at least a portion of the detection target system, and at least a portion of the detection target system is reconstructed as a scanning system based on the second snapshot, and a scan for vulnerability information is executed on the scanning system.

[0007] According to this aspect, vulnerability information can be detected from a detection target system by any combination of the first detection process, the second detection process, and the third detection process. Therefore, vulnerability information can be easily obtained by selecting a detection process according to the configuration and usage environment of the detection target system. [Brief explanation of the drawings]

[0008] [Figure 1] 1 is a configuration diagram illustrating an information processing system 1. FIG. [Figure 2] 1 is a block diagram showing a hardware configuration of an information processing device 10. FIG. [Figure 3] FIG. 2 is a block diagram showing the hardware configuration of the user terminal 20. [Figure 4] 1 is a block diagram showing functions realized by an information processing device 10 (controller 11) and a user terminal 20 (controller 21). [Figure 5] 10 is a flowchart showing an example of the flow of a first detection process executed by a vulnerability detection unit 113. FIG. [Figure 6] 10 is a flowchart showing an example of the flow of a second detection process executed by a vulnerability detection unit 113. FIG. [Figure 7] 10 is a flowchart showing an example of the flow of a third detection process executed by a vulnerability detection unit 113. FIG. [Figure 8] 1 is an activity diagram showing an example of the flow of information processing (processing for detecting vulnerability information) executed by the information processing system 1. FIG. DETAILED DESCRIPTION OF THE INVENTION

[0009] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS The present invention will be described below with reference to the accompanying drawings. Various features shown in the following embodiments can be combined with each other.

[0010] Incidentally, the program for realizing the software appearing in one embodiment may be provided as a non-transitory computer-readable medium, or may be provided so that it can be downloaded from an external server, or may be provided so that the program is started on an external computer and its functions are realized on a client terminal (so-called cloud computing).

[0011] Furthermore, various information processing according to an embodiment may realize input and output corresponding to the input. Here, the form of information referenced in such information processing (hereinafter referred to as reference information) is not limited as long as an output is obtained as a result of the input. The reference information may be, for example, rule-based information such as a database, a lookup table, or a predetermined function (including a decision formula such as a regression formula constructed using a statistical method), a trained model that has previously trained the correlation between input and output, or a large-scale language model that can output a desired result by inputting a prompt.

[0012] In one embodiment, a "unit" may include, for example, a combination of hardware resources implemented by a circuit in the broad sense and software information processing that can be specifically realized by these hardware resources. In one embodiment, various information is handled, and this information is represented, for example, by physical values ​​of signal values ​​representing voltage and current, high and low signal values ​​as a binary bit set consisting of 0 or 1, or quantum superposition (so-called quantum bits), and communication and calculations can be performed on a circuit in the broad sense.

[0013] Furthermore, a circuit in the broad sense is a circuit realized by at least an appropriate combination of a circuit, circuitry, processor, memory, etc. The processor may be a general-purpose processor or a dedicated circuit. That is, it includes an application specific integrated circuit (ASIC), a programmable logic device (e.g., a simple programmable logic device (SPLD), a complex programmable logic device (CPLD), and a field programmable gate array (FPGA)), etc.

[0014] 1. Hardware Configuration This section explains the hardware configuration.

[0015] <Information Processing System 1> 1 is a configuration diagram showing an information processing system 1. The information processing system 1 includes a communication line 2, an information processing device 10, a plurality of user terminals 20, a plurality of managed servers 30, and a vulnerability information server 40. The information processing device 10, the user terminals 20, the managed servers 30, and the vulnerability information server 40 are configured to be able to communicate with each other via the communication line 2. The information processing device 10, the user terminals 20, the managed servers 30, and the vulnerability information server 40 may be connected by wire or wirelessly.

[0016] The information processing system 1 constitutes, for example, at least a part of a vulnerability management system that manages vulnerabilities of the managed server 30. The information processing system 1 mainly detects vulnerabilities of the managed server 30 used or managed by a user U. In one embodiment, the information processing system 1 is made up of one or more devices or components. These components will be described below.

[0017] <Information processing device 10> 2 is a block diagram showing the hardware configuration of the information processing device 10. The information processing device 10 is a vulnerability diagnosis device that scans, identifies, manages, etc. asset information and vulnerability information of a system (e.g., software). The information processing device 10 may be provided by a provider of a vulnerability diagnosis service that scans, identifies, manages, etc. vulnerability information, and may be used by a user (user U) of the vulnerability diagnosis service. As shown in FIG. 2, the information processing device 10 includes a control unit 11, a storage unit 12, a communication unit 13, and a communication bus 14. The control unit 11, the storage unit 12, and the communication unit 13 are electrically connected within the information processing device 10 via the communication bus 14.

[0018] <Control unit 11> The control unit 11 processes and controls the overall operations related to the information processing device 10. The control unit 11 is, for example, a central processing unit (CPU). The control unit 11 realizes various functions related to the information processing device 10 by reading out predetermined programs stored in the storage unit 12. In other words, information processing by software stored in the storage unit 12 is specifically realized by the control unit 11, which is an example of hardware, and can be executed as each functional unit included in the control unit 11. These will be described in more detail in the next section. Note that the control unit 11 is not limited to being single, and there may be multiple control units 11 for each function. Furthermore, the control unit 11 may be a combination of these.

[0019] <Storage section 12> The memory unit 12 stores various pieces of information defined above. This can be implemented, for example, as a storage device such as a solid state drive (SSD) that stores various programs and the like related to the information processing device 10 executed by the control unit 11, or as a memory such as a random access memory (RAM) that stores temporarily required information (arguments, arrays, etc.) related to the program operations. The memory unit 12 stores various programs, variables, etc. related to the information processing device 10 executed by the control unit 11.

[0020] <Communications Department 13> The communication unit 13 is preferably a wired communication means such as USB, IEEE1394, Thunderbolt (registered trademark), wired LAN network communication, etc., but may also include wireless LAN network communication, mobile communication such as 3G / LTE / 5G, BLUETOOTH (registered trademark) communication, etc. as needed. In other words, it is more preferable to implement it as a collection of multiple communication means. In other words, the information processing device 10 may communicate various information from the outside via the communication unit 13 and the network.

[0021] The information processing device 10 may be an on-premise type or a cloud type. The cloud type information processing device 10 may provide the above-described functions and processes in the form of, for example, SaaS (Software as a Service) or cloud computing.

[0022] <User terminal 20> Fig. 3 is a block diagram showing the hardware configuration of the user terminal 20. As shown in Fig. 3, the user terminal 20 includes a control unit 21, a storage unit 22, a communication unit 23, an input unit 24, an output unit 25, and a communication bus 26. The control unit 21, the storage unit 22, the communication unit 23, the input unit 24, and the output unit 25 are electrically connected via the communication bus 26 inside the user terminal 20. The user terminal 20 is an information processing terminal used by a user U (administrator) who manages the managed server 30. The explanation of the control unit 21, the storage unit 22, and the communication unit 23 is omitted because they are the same as the explanation of each unit in the information processing device 10.

[0023] <Input section 24> The input unit 24 accepts operation inputs made by the user. The operation inputs are transferred as command signals to the control unit 21 via the communication bus 26. The control unit 21 can execute predetermined control or calculations based on the transferred command signals as necessary. The input unit 24 may be included in the housing of the user terminal 20 or may be attached externally. For example, the input unit 24 may be implemented as a touch panel integrated with the output unit 25. When the input unit 24 is implemented as a touch panel, the user can input tap operations, swipe operations, etc. to the input unit 24. Instead of a touch panel, a switch button, a mouse, a trackpad, a QWERTY keyboard, etc. can be used as the input unit 24.

[0024] <Output section 25> The output unit 25 displays a screen of a graphical user interface (GUI) that can be operated by the user. The output unit 25 may be included in the housing of the user terminal 20 or may be attached externally. Specifically, the output unit 25 may be implemented as a display device such as a CRT display, a liquid crystal display, an organic EL display, or a plasma display. It is preferable that these display devices are used appropriately depending on the type of user terminal 20.

[0025] <Managed Server 30> The managed server 30 is a server including a detection target system for which the information processing device 10 detects vulnerability information, or a server whose entirety is the detection target system. The managed server 30 may be a physical server, or a virtual server built on a cloud provided by a cloud service provider. In other words, the detection target system may be a virtual server. This makes it possible to detect vulnerability information according to a cloud environment, such as a cloud platform. The cloud platform may be, for example, a platform that allows access to services such as databases, storage, and applications via the Internet.

[0026] <Vulnerability Information Server 40> The vulnerability information server 40 is a server that manages software vulnerability information. The vulnerability information server 40 may be configured with multiple servers. Examples of the vulnerability information server 40 include management servers for vulnerability information websites (vulnerability information databases) such as CVE (Common Vulnerabilities and Exposures), NVD (National Vulnerability Database), ICAT (IPA Cybersecurity Alert Service) Metabase, JVN (Japan Vulnerability Notes), JVN iPedia, and OSVDB (Open Source Vulnerability Database). The vulnerability information server 40 may also include a server that stores vulnerability information (e.g., security advisories) provided independently by software suppliers. The software for which vulnerability information is managed may include OSS (Open Source Software).

[0027] 2. Functional configuration This section describes the functional configuration of this embodiment. Information processing by software stored in the storage unit 12 is specifically realized by the control unit 11, which is an example of hardware, and can be executed as each functional unit included in the control unit 11 (at least one processor included in the information processing system 1).

[0028] FIG. 4 is a block diagram showing functions realized by the information processing device 10 (controller 11) and the user terminal 20 (controller 21).

[0029] 4A, the information processing device 10 (control unit 11) includes a basic display control unit 111, a system registration unit 112, and a vulnerability detection unit 113. As shown in FIG. 4B, the user terminal 20 (control unit 21) includes a display unit 211 and an operation acquisition unit 212.

[0030] <Basic display control unit 111> The basic display control unit 111 is configured to display various information on the user terminal 20. For example, the basic display control unit 111 displays vulnerability information detected by the vulnerability detection unit 113 on the display unit 211 of the user terminal 20.

[0031] <System Registration Unit 112> The system registration unit 112 is configured to register a detection target system for detecting vulnerability information. Specifically, the system registration unit 112 receives input of information for identifying the detection target system (for example, an address (URL, etc.) of the detection target system on the network, information such as an identifier indicating a resource to be scanned, etc.) from the user terminal 20, and registers the registration information of the detection target system in a detection target system database of the storage unit 12, for example.

[0032] <Vulnerability detection unit 113> The vulnerability detection unit 113 is configured to detect vulnerability information by cooperating with the detection target system registered by the system registration unit 112. Specifically, the vulnerability detection unit 113 executes at least two of a first detection process, a second detection process, and a third detection process on the detection target system (managed server 30). The vulnerability information includes information on vulnerabilities such as usage defects and bugs in software, programs, applications, components, etc. The vulnerability information may also include security information such as misconfigurations and omissions in cloud services.

[0033] The vulnerability detection unit 113 preferably executes the first detection process and at least one of the second detection process and the third detection process. This allows the first detection process, which is the easiest of the three detection processes to detect vulnerability information, to be executed, and then the second detection process or the third detection process to be selectively executed to supplement the detection result of the first detection process. This allows a balance between the load of the detection process and the detection accuracy.

[0034] <First detection process> In the first detection process, the vulnerability detection unit 113 performs a scan of vulnerability information within the detection target system (managed server 30) using a first snapshot created within the detection target system (managed server 30) that saves the state of at least a part of the detection target system (resources to be detected).

[0035] A snapshot is, for example, information that records the state of assets included in a discovery target system (discovery target resource). Typically, a snapshot contains information that allows the discovery target system (discovery target resource) at the time the snapshot was created to be restored by mounting it on a virtual server or operating system (OS).

[0036] The assets of a system to be discovered include all system environments, entities, and services that can be managed by the user (in the case of a virtual server, can be managed on a cloud platform). The assets may include, for example, virtual machines, virtual disks, virtual networks, storage accounts, software such as web applications, databases, policies, roles, etc. included in the system to be discovered. Here, roles and policies are information that define who has what authority to resources.

[0037] The policies and roles are created and managed by, for example, IAM (Identity and Access Management). IAM is a function that grants resource operation authority (roles) to cloud services, applications, etc., and is a function that can grant authority to scan a system environment associated with a resource. IAM grants a role to a resource that allows the information processing device 10 to perform processing required to scan vulnerability information by the information processing device 10. For example, the role and policy define that a scan account is assigned authority to scan asset information associated with a resource. This enables the information processing device 10 to cooperate with a detection target system and perform processing required to scan vulnerability information of the detection target system. In other words, when the information processing device 10 sends a scan request, the scan request is permitted based on the role assigned to the resource, and the information processing device 10 can acquire asset information of the system environment associated with the resource.

[0038] In the first detection process, the vulnerability detection unit 113 obtains authority to scan the detection target system (managed server 30), creates a first snapshot for the detection target system within the detection target system based on the authority, and may delete the first snapshot after scanning the first snapshot for vulnerability information. This allows for easy scanning of vulnerability information without installing a program such as an agent in the detection target system (managed server 30). It also reduces the load associated with directly scanning the detection target system. It is also possible to detect vulnerability information in the detection target system even when a scan for vulnerability information cannot be performed directly on the detection target system, for example, because the detection target system does not have an API (Application Programming Interface) for accessing the detection target system.

[0039] "Authorization to scan the target system" (hereinafter referred to as "scanning authority") is authorization that allows the target system to obtain asset information (property information) for creating a snapshot from the target system's storage (volume). "Asset information" is information that indicates the status of an asset. Asset information includes, for example, application libraries, hosts, container images, and SBOMs (Software Bill of Materials).

[0040] An application library is, for example, a collection of applications included in a system environment. The application library may include the name, version, EOL (End Of Life), etc. of the application. Note that the "application" in the application library may be interpreted as software or program.

[0041] The host includes, for example, the name and configuration of the device (terminal, router, server, etc.) that configures the system environment. The host may also include the name of the account associated with the system environment.

[0042] A container image is, for example, an image that is generated by building a container file and then running it to generate a container. A container is, for example, a package of applications used in an environment where a container engine is installed on an OS installed on a physical server. The content includes, for example, middleware (MW) and an application installed on the middleware. The container image may also include the name and version of the application. Note that the "application" included in the container may be interpreted as software or a program.

[0043] The SBOM includes, for example, software components included in the system to be detected, dependencies between components, license data, and the like.

[0044] The scanning authority for the detection target system is assigned to the scanning account used by the vulnerability detection unit 113, for example, by the role (or policy) assigned to the resource to be scanned. The role allows copying and scanning of the detection target system (for example, a virtual disk in the detection target system). The creation of the role and the assignment of the scanning authority are performed, for example, by a user who accesses the managed server 30 from the user terminal 20. The vulnerability detection unit 113 acquires the agent authority assigned by the user.

[0045] If a user manages multiple systems to be discovered (for example, if the user owns or manages accounts for multiple virtual servers), the user creates a role and assigns scanning privileges for each system to be discovered (for example, one management server account). Note that roles may be managed by IAM. In other words, roles may be assigned to resources to be scanned by IAM. Note that roles assigned by IAM do not necessarily have to include privileges such as creating resources, deleting resources, checking billing information for systems to be discovered, and obtaining resource structures.

[0046] The scan account is an account used by the vulnerability detection unit 113 to scan the detection target system. The vulnerability detection unit 113 accesses the detection target system (the managed server 30) using the scan account and executes various processes in the detection target system. The vulnerability detection unit 113 associates the scan account with a user account on the managed server 30 by registering a role identifier (e.g., a resource name or a resource ID) created in the detection target system in the scan account. The role identifier may be a name or symbol that can uniquely identify the role. In addition to the role identifier, the vulnerability detection unit 113 may also register scan credentials issued by the detection target system. As a result, the vulnerability detection unit 113 obtains authority to scan a system environment associated with a resource to which a role has been assigned, by coordinating with the detection target system. In other words, when the vulnerability detection unit 113 sends a scan request to the detection target system, the scan request is permitted based on the role assigned to the resource. Note that the scan request sent by the vulnerability detection unit 113 may include a role identifier.

[0047] The vulnerability detection unit 113 accesses the detection target system using the scan account, and then creates a first snapshot within the detection target system by scanning the resources to be scanned (resources to which roles have been assigned) of the detection target system using the scan account.

[0048] For example, the vulnerability detection unit 113 acquires scan information including asset information and the like from the resource to be scanned, and creates a first snapshot including the asset information and the like. Specifically, the system to be scanned transmits a scan response capable of identifying the asset information to the scan account (vulnerability detection unit 113). If the system to be scanned is a virtual server, the vulnerability detection unit 113 creates a first snapshot of a virtual disk (e.g., storage volume, data volume, block storage, and the like) attached to the virtual server within the virtual server based on the scan information (asset information, and the like). The first snapshot is stored, for example, in storage within the virtual server.

[0049] After creating the first snapshot, the vulnerability detection unit 113 detects (scans) vulnerability information from the first snapshot. For example, the vulnerability detection unit 113 extracts asset information from the first snapshot and determines whether the asset information contains vulnerability information based on master information of the vulnerability information (reference information for vulnerability information scanning). The vulnerability detection unit 113 may indirectly access and scan the first snapshot in the detection target system by sending a request to an API provided by the provider of the detection target system or the cloud platform.

[0050] The master information is, for example, information acquired by the information processing device 10 from the vulnerability information server 40, and is stored, for example, in a vulnerability information database in the storage unit 12. The master information includes, for example, security vulnerabilities (defects) contained in hardware or software, the types of defects, countermeasures for the defects, severity (level of vulnerability), etc. Examples of the severity include a score value (e.g., base score) defined by the Common Vulnerability Scoring System (CVSS). The master information may also include the version of the CVSS.

[0051] Furthermore, the master information may include information indicating the vulnerability level set by a third-party organization, information indicating whether the vulnerability is accessible from the outside, information indicating whether an attack against the vulnerability will have a significant impact on business operations, information indicating whether attack code against the vulnerability is in circulation, information indicating whether exploitation of the vulnerability has been confirmed, etc. If attack code against the vulnerability is in circulation, the master information may include the attack code.

[0052] The master information may be information obtained by processing the information acquired from the vulnerability information server 40. Examples of processing the information acquired from the vulnerability information server 40 include extracting parts of the information, correcting the information, and adding new information. These processes may be performed by the user, or may be performed mechanically by text analysis by the control unit 11, processing using a learning model, or the like. The master information may be information acquired from a website such as a security-related news site or blog, or may be information entered by the user from the user terminal 20 and registered in the vulnerability information database.

[0053] The vulnerability detection unit 113 may determine the priority of vulnerability information detected in the first detection process (perform vulnerability triage) based on at least one of the following information included in the master information: information indicating the vulnerability level set by a third-party organization; information indicating whether the vulnerability is accessible from the outside; information indicating whether an attack against the vulnerability will have a significant impact on business operations; information indicating whether attack code against the vulnerability is in circulation; and information indicating whether exploitation of the vulnerability has been confirmed. This allows the user to determine the order in which to respond to detected vulnerabilities based on the results of the first detection process.

[0054] For example, a score value defined by CVSS is used as information indicating the vulnerability level. The vulnerability detection unit 113 determines vulnerability information whose score value is less than a predetermined threshold as level 0, which is the lowest priority. Level 0 vulnerability information is defined as information about a vulnerability for which no particular countermeasures need be taken, for example. Vulnerability information whose score value is equal to or greater than the threshold is determined to be level 1 or higher.

[0055] For example, the vulnerability detection unit 113 determines that vulnerability information with a score value equal to or greater than a threshold value, which is inaccessible from outside the system targeted for attack code detection (i.e., accessible only from inside the system targeted for detection) and which has little impact on business operations when attacked, is level 1. Level 1 vulnerability information is defined as information on vulnerabilities for which countermeasures should be implemented during regular maintenance of the system targeted for detection (e.g., once a month). The priority of responding to level 1 vulnerability information is higher than the priority of responding to level 0 vulnerability information.

[0056] For example, the vulnerability detection unit 113 determines that vulnerability information with a score value equal to or greater than a threshold, which relates to a vulnerability that is accessible from the outside or a vulnerability that will have a significant impact on business operations if attacked, is level 2 (excluding vulnerability information that corresponds to levels 3 or 4, which will be described later). Level 2 vulnerability information is defined as information on a vulnerability for which countermeasures should be implemented within a first deadline (for example, within two weeks). The priority of responding to level 2 vulnerability information is higher than the priority of responding to level 1 vulnerability information.

[0057] For example, the vulnerability detection unit 113 determines that vulnerability information that satisfies the determination conditions for level 2 and that relates to vulnerabilities for which attack code is circulating is level 3 (excluding vulnerability information that corresponds to level 4, which will be described later). Level 3 vulnerability information is defined as information about vulnerabilities for which countermeasures should be implemented within a second deadline (for example, within one day) that is shorter than the first deadline. The priority of responding to level 3 vulnerability information is higher than the priority of responding to level 2 vulnerability information.

[0058] For example, the vulnerability detection unit 113 determines that, among vulnerability information that satisfies the determination conditions for level 3, vulnerability information related to vulnerabilities for which attacks have been observed and exploitation of the vulnerability has been confirmed is the highest level, level 4. Level 4 vulnerability information is defined as information related to vulnerabilities for which countermeasures should be implemented within a third deadline (for example, immediately) that is shorter than the second deadline. The priority of responding to level 4 vulnerability information is higher than the priority of responding to level 3 vulnerability information.

[0059] Apart from the above level determination, the vulnerability detection unit 113 may set the highest priority to vulnerability information for which exploitation of the vulnerability has been confirmed and for which the vulnerability is accessible from the outside.

[0060] In addition, the vulnerability detection unit 113 may, for example, set a first rank as a priority for vulnerability information for which attack code against the vulnerability is circulating, and may set a second rank, which is higher than the first rank, as a priority for vulnerability information for which exploitation of the vulnerability has been confirmed and the vulnerability is accessible from outside.

[0061] Furthermore, the vulnerability detection unit 113 may set a third rank as a priority for vulnerability information for which attack code for the vulnerability is in circulation and the vulnerability is accessible from outside, and may set a fourth rank, which is lower than the third rank, as a priority for vulnerability information for which exploitation of the vulnerability has been confirmed and the vulnerability is not accessible from outside.

[0062] After scanning the first snapshot (after detecting vulnerability information), the vulnerability detection unit 113 deletes the first snapshot from the detection target system (for example, storage in a virtual server).

[0063] The timing at which the vulnerability detection unit 113 executes the first detection process (the timing at which the first snapshot is created and scanned) may be at a timing determined by the user (for example, when an instruction to execute the first detection process is input into the user terminal 20), or may be periodically performed at a predetermined period.

[0064] 5 is a flow diagram showing an example of the flow of the first detection process executed by the vulnerability detection unit 113. In the first detection process, first, the vulnerability detection unit 113 acquires scan authority for scanning the resource to be scanned based on the role assigned to the resource (step S110). Here, if the vulnerability detection unit 113 has already acquired scan authority (for example, in the case of the second or subsequent first detection process for the same detection target system), step S110 is omitted. Next, the vulnerability detection unit 113 accesses the detection target system using a scan account that has scan authority by linking with an API or the like (step S120). Note that the vulnerability detection unit 113 may acquire scan authority after accessing the detection target system.

[0065] After the scan account with scan authority accesses the detection target system, the vulnerability detection unit 113 creates a first snapshot of the resources to be scanned in the detection target system (step S130). After creating the first snapshot, the vulnerability detection unit 113 scans the first snapshot for vulnerability information (step S140). After detecting vulnerability information, the vulnerability detection unit 113 deletes the first snapshot in the detection target system (step S150).

[0066] The vulnerability detection unit 113 may scan a first snapshot (for example, a first snapshot created by a user) created in advance in the detection target system for vulnerability information in the detection target system. In this case, the vulnerability detection unit 113 does not need to delete the first snapshot after the scan.

[0067] <Second detection process> In the second detection process, the vulnerability detection unit 113 causes an agent installed in the system to be detected (managed server 30) that collects system configuration information to obtain configuration information of at least a portion of the system to be detected (resources to be detected), receives the configuration information, and further scans the configuration information for vulnerability information.

[0068] The agent is a resident program installed in a detection target system (e.g., a virtual server) for monitoring the detection target system. The configuration information collected by the agent includes, for example, the configuration of the hardware included in the detection target system (e.g., the CPU model, etc.), the name and version of the OS installed in the detection target system, the name, version, and settings of software installed in the detection target system, the user account and account privileges of the detection target system, the network to which the detection target system is connected, the IP (Internet Protocol) address of the detection target system, devices connected to the detection target system, devices communicating with the detection target system, the content of communication and communication protocols, and information indicating the status of ports (open ports) of the detection target system. The configuration information collected by the agent may also include asset information acquired by the vulnerability detection unit 113 in the first detection process.

[0069] The agent may be one that is attached to the detection target system (for example, an agent that is provided as standard for a virtual server by a cloud platform provider), or may be one that is provided by the information processing device 10. If an agent is not installed in the detection target system, the user installs the agent in the detection target system before the second detection process is executed.

[0070] In the second detection process, the vulnerability detection unit 113 may obtain authority to have the agent acquire configuration information and transmit it outside the detection target system, and may cause the agent to input a command to output the configuration information to the detection target system. This makes it possible to detect the latest vulnerability information of the detection target system over a wider range (breadth and depth) than in the first detection process. In addition, it becomes possible to detect vulnerability information that cannot be detected by snapshots, such as vulnerability information of software and packages managed by the virtual server OS.

[0071] The "authority to have the agent acquire configuration information and transmit it outside the system to be detected" (hereinafter referred to as "agent authority") is the authority to allow the system to be detected to output and transmit the configuration information of the system to be detected to an external location. The external location of the system to be detected is typically the information processing device 10.

[0072] Agent authority for the detection target system is assigned to the agent, for example, by a role assigned to the resource from which configuration information is to be acquired. The role allows the agent to scan the detection target system (e.g., a virtual server) and retrieve the scan results. Role creation and agent authority assignment are performed, for example, by a user who accesses the managed server 30 from the user terminal 20.

[0073] Furthermore, if the agent is an external agent installed from outside the detection target system (for example, an agent provided by the information processing device 10), the user grants the agent authority to the external agent. The vulnerability detection unit 113 acquires the agent authority assigned or granted by the user. Note that the assignment or granting of the agent authority to the agent may be performed before or after the installation of the agent.

[0074] The vulnerability detection unit 113 transmits a configuration information acquisition instruction to an agent that is installed in the detection target system and has agent authority. Upon receiving the acquisition instruction, the agent inputs a configuration information output command to a management function of the detection target system (for example, a management function of a cloud platform of a management server), thereby causing the detection target system to output the configuration information. In other words, the agent acquires the configuration information within the detection target system. The agent also transmits the configuration information that the detection target system has output to the vulnerability detection unit 113. Note that the agent may acquire and transmit the configuration information in response to a scan instruction from a user or at a predetermined timing, without receiving an acquisition instruction from the vulnerability detection unit 113.

[0075] The vulnerability detection unit 113 stores the configuration information of the detection target system received from the agent in the memory unit 12 or in a storage external to the information processing device 10. Furthermore, the vulnerability detection unit 113 detects (scans) vulnerability information from the stored configuration information. For example, the vulnerability detection unit 113 determines whether the configuration information includes vulnerability information based on master information common to the first detection process.

[0076] The vulnerability detection unit 113 may determine the priority of vulnerability information detected in the second detection process (perform vulnerability triage) based on at least one of the following information included in the master information: information indicating the vulnerability level set by a third-party organization; information indicating whether the vulnerability is accessible from outside; information indicating whether an attack against the vulnerability will have a significant impact on business operations; information indicating whether attack code against the vulnerability is in circulation; and information indicating whether exploitation of the vulnerability has been confirmed. This allows the user to determine the order in which to respond to detected vulnerabilities based on the results of the second detection process. The procedure for determining the priority of vulnerability information in the second detection process is the same as that in the first detection process.

[0077] 6 is a flow diagram showing an example of the flow of the second detection process executed by the vulnerability detection unit 113. In the second detection process, first, the vulnerability detection unit 113 acquires agent authority for acquiring configuration information by an agent installed in the detection target system (step S210). Here, if the vulnerability detection unit 113 has already acquired agent authority (for example, in the case of the second or subsequent second detection process for the same detection target system), step S210 is omitted. Next, the vulnerability detection unit 113 causes the agent to acquire configuration information of the detection target system (step S220).

[0078] After acquiring the configuration information, the vulnerability detection unit 113 receives the configuration information from the agent (step S230). After receiving the configuration information, the vulnerability detection unit 113 scans the configuration information for vulnerability information (step S240).

[0079] <Third detection process> In the third detection process, the vulnerability detection unit 113 acquires a second snapshot that saves the state of at least a part of the detection target system (resources to be detected) within the detection target system (managed server 30), and reconstructs at least a part of the detection target system as a scanning system based on the second snapshot, and performs a scan of the scanning system for vulnerability information.

[0080] When the vulnerability detection unit 113 executes the first detection process and the third detection process, the second snapshot may be a snapshot different from the first snapshot used in the first detection process (created separately from the first snapshot), or may be the same as the first snapshot used in the first detection process. In other words, the first snapshot may be used as the second snapshot in the third detection process.

[0081] The vulnerability detection unit 113 constructs a scanning system (a system obtained by restoring the detection target system) in a restoration server external to the detection target system. Examples of the restoration server include a virtual server provided in the storage unit 12 of the information processing device 10, a physical server or a virtual server other than the information processing device 10, etc.

[0082] If the detection target system is a virtual server, in the third detection process, the vulnerability detection unit 113 may build a scanning system in the virtual server on the same cloud platform as the detection target system. This increases the accuracy of reproducing the detection target system, thereby improving the accuracy of detecting vulnerability information.

[0083] If the cloud platform used by the target system provides multiple types of management services (services with different methods for constructing virtual servers), the vulnerability detection unit 113 may construct a scanning system on a virtual server provided by the same management service as the target system.

[0084] In the third detection process, the vulnerability detection unit 113 obtains authority to scan the detection target system, creates a second snapshot for the detection target system within the detection target system based on the authority, receives a copy of the second snapshot, and may delete the second snapshot from the detection target system after constructing a scanning system. This allows for a detailed scan to be performed, targeting software not managed by the OS of the detection target system (e.g., software that cannot be scanned on a certain OS), without placing a load on the detection target system. Furthermore, a scan can be performed without installing an agent on the detection target system, without causing any effort to the user.

[0085] The "authority to scan the detection target system" is the same as the scan authority in the first detection process. As in the first detection process, the scan authority for the detection target system is assigned to the scan account used by the vulnerability detection unit 113, for example, by the role assigned to the resource to be scanned. In addition, the procedure for creating the second snapshot in the detection target system is the same as the procedure for creating the first snapshot in the first detection process.

[0086] After creating the second snapshot, the vulnerability detection unit 113 downloads the second snapshot to storage external to the detection target system using the scan account. The storage to which the second snapshot is downloaded may be a storage that restores the scan system (i.e., storage of the restoration server), or may be a storage separate from the restoration server.

[0087] After downloading the second snapshot, the vulnerability detection unit 113 mounts the downloaded second snapshot on a restoration server that builds a scanning system, and restores the detection target system (scan target resource) on the restoration server based on the second snapshot. As a result, a scanning system having a data volume (virtual disk) of the detection target system is built in the restoration server. For example, if the restoration server is a virtual server on a cloud platform, the scanning system is built on the virtual server.

[0088] After the scan system is constructed, the vulnerability detection unit 113 detects (scans) vulnerability information in the scan system (scan virtual server). For example, the vulnerability detection unit 113 extracts configuration information, asset information, etc. from the scan system, and determines whether vulnerability information is included in the configuration information, asset information, etc. of the scan system based on master information common to the first detection process and the second detection process. Note that in the third detection process, the vulnerability detection unit 113 does not scan the second snapshot.

[0089] The vulnerability detection unit 113 may determine the priority of vulnerability information detected in the third detection process (perform vulnerability triage) based on at least one of the following information included in the master information: information indicating the vulnerability level set by a third-party organization; information indicating whether the vulnerability is accessible from outside; information indicating whether an attack against the vulnerability will have a significant impact on business operations; information indicating whether attack code against the vulnerability is in circulation; and information indicating whether exploitation of the vulnerability has been confirmed. This allows the user to determine the order in which to respond to detected vulnerabilities based on the results of the third detection process. The procedure for determining the priority of vulnerability information in the third detection process is the same as that in the first detection process and the second detection process.

[0090] After scanning the second snapshot (after detecting vulnerability information), the vulnerability detection unit 113 deletes the second snapshot from the detection target system (for example, storage in a virtual server).

[0091] The timing at which the vulnerability detection unit 113 executes the third detection process (the timing at which the second snapshot is created, a scanning system is constructed, and a scanning is performed) may be at a timing determined by the user (for example, the timing at which an instruction to execute the third detection process is input on the user terminal 20), or may be periodically performed at a predetermined period.

[0092] The third detection process may be performed in parallel with the first detection process. In this case, the first snapshot and the second snapshot may be the same. Furthermore, the third detection process may be performed in parallel with the second detection process.

[0093] 7 is a flow diagram showing an example of the flow of the third detection process executed by the vulnerability detection unit 113. In the third detection process, first, the vulnerability detection unit 113 acquires scan authority for scanning the resource to be scanned based on the role assigned to the resource (step S310). Here, if the vulnerability detection unit 113 has already acquired scan authority (for example, if the first detection process has already been executed), step S310 is omitted. Next, the vulnerability detection unit 113 accesses the detection target system using a scan account that has scan authority (step S320). Note that the vulnerability detection unit 113 may acquire scan authority after accessing the detection target system.

[0094] After the scan account with scan authority accesses the detection target system, the vulnerability detection unit 113 creates a second snapshot of the resources to be scanned in the detection target system (step S330). After creating the second snapshot, the vulnerability detection unit 113 receives the second snapshot from the detection target system (step S340). Next, the vulnerability detection unit 113 constructs a scan system based on the received second snapshot (step S350).

[0095] After the scan system is constructed, the vulnerability detection unit 113 scans the scan system for vulnerability information (step S360). After detecting vulnerability information, the vulnerability detection unit 113 deletes the second snapshot in the detection target system (step S370).

[0096] When the third detection process is performed in parallel with the first detection process, steps S310 and S320 are replaced with steps S110 and S120 of the first detection process. That is, steps S310 and S320 are omitted in the third detection process. Furthermore, when the first snapshot of the first detection process is used as the second snapshot, steps S330 and S370 are omitted in the third detection process.

[0097] Furthermore, the vulnerability detection unit 113 may construct a scanning system using a second snapshot created in advance in the detection target system (for example, a second snapshot created by the user himself / herself). In this case, the vulnerability detection unit 113 does not need to delete the second snapshot after the scan.

[0098] <Detection results> The vulnerability detection unit 113 may first execute a first detection process for one detection target system (detection target resource), and then execute at least one of a second detection process and a third detection process according to the detection result of the first detection process. As a result, one of the second detection process and the third detection process that is suitable for supplementing the detection result obtained by the first detection process is executed, thereby reducing the load of the detection process on the detection target system and improving the detection accuracy of vulnerability information.

[0099] The detection results in the first detection process include, for example, the detection items, the detection results of the detection items (information extracted from asset information, configuration information, etc.), vulnerability information for the detection items, the type and priority (level) of the vulnerability information (for example, whether or not attack code is in circulation), and whether or not countermeasures are required (alert).

[0100] For example, the vulnerability detection unit 113 determines to execute one of the second detection process, the third detection process, or a combination of the second detection process and the third detection process, depending on the detection item (hereinafter referred to as the "specific item") that could not be scanned (information acquisition) or was insufficiently scanned in the first detection process. For example, if the specific item is a detection item that can be scanned by an agent (for example, an item included in configuration information collected by an agent), the vulnerability detection unit 113 determines to execute the second detection process. Also, for example, if the specific item is a detection item that cannot be scanned within the detection target system (for example, an item related to software not managed by the OS of the detection target system), the vulnerability detection unit 113 determines to execute the third detection process.

[0101] Furthermore, the vulnerability detection unit 113 may further execute a third detection process depending on the detection result of the second detection process performed after the first detection process. Also, the vulnerability detection unit 113 may further execute a second detection process depending on the detection result of the third detection process performed after the first detection process. In particular, in the third detection process, if the second snapshot cannot be mounted or if scanning of the restored scanning system cannot be performed, the vulnerability detection unit 113 may execute the second detection process.

[0102] In addition, after the first detection process, the vulnerability detection unit 113 may display the detection results of the first detection process on the user terminal 20 and then execute the second detection process and / or the third detection process, or may execute the second detection process and / or the third detection process without displaying the detection results of the first detection process on the user terminal 20.

[0103] Depending on the detection result of the first detection process, the vulnerability detection unit 113 may display the detection result, and may also present the execution of the second detection process and / or the third detection process to the user, and may receive an instruction to execute the second detection process and / or the third detection process from the user. This allows the user to confirm the detection result of the first detection process and then additionally execute the second detection process and / or the third detection process as necessary.

[0104] For example, the vulnerability detection unit 113 displays the detection results of the first detection process on the user terminal 20, and also displays an object on the user terminal 20 that accepts execution of the second detection process or the third detection process depending on the content of the specific item. For example, if the specific item is a detection item that can be scanned by an agent, the vulnerability detection unit 113 suggests execution of the second detection process (displays an object such as a button that accepts execution of the second detection process on the user terminal 20). Also, for example, if the specific item is a detection item that cannot be scanned in the detection target system, the vulnerability detection unit 113 suggests execution of the third detection process (displays an object such as a button that accepts execution of the third detection process on the user terminal 20). The vulnerability detection unit 113 executes the detection process (the second detection process or the third detection process) selected (the execution instruction of which has been input) on the user terminal 20.

[0105] The vulnerability detection unit 113 may change the display mode of the results for each detection item in the detection results of the first detection process displayed on the user terminal 20 depending on the amount of information detected from the first snapshot. This allows the user to confirm the reliability of the detection results of the first detection process. Therefore, the user can select to execute the second detection process and / or the third detection process based on the reliability of the detection results.

[0106] For example, the vulnerability detection unit 113 may highlight the results (vulnerability information, priority of vulnerability information, etc.) related to a detection item with a small amount of information (insufficient amount of information) by adjusting the size, color, font, etc. of characters. Furthermore, the vulnerability detection unit 113 may attach a mark, label, etc. indicating that the amount of information is small to a detection item with a small amount of information. Note that a "detection item with a small amount of information" is, for example, a detection item for which not enough information was detected to detect vulnerability information (for comparison with master information). Furthermore, a "detection item with a small amount of information" may be, for example, a detection item for which not all of the information necessary for detecting vulnerability information was obtained from the information on the asset (e.g., software) targeted by the detection item.

[0107] For a detection item for which information could not be detected, the vulnerability detection unit 113 may display a message indicating that the detection item could not be detected, along with the name of the detection item, on the user terminal 20. At this time, the message may suggest execution of a second detection process or a third detection process to complement the detection item that could not be detected.

[0108] After executing the second detection process and / or the third detection process, the vulnerability detection unit 113 may display a final detection result, which is the detection result of the first detection process updated by the detection result of the second detection process and / or the third detection process, on the user terminal 20. This allows the user to be presented with a final detection result that integrates the results of multiple detection processes, making it easier for the user to check vulnerability information of the detection target system even when multiple detection processes are performed.

[0109] For example, if an alert was issued for a detection item in the detection results of the first detection process due to an attempted detection of information, but the information is detected by the second or third detection process, the alert for that detection item will be deleted in the final detection results (however, if vulnerability information is detected, a separate alert will be issued). Also, if vulnerability information that was not detected in the detection results of the first detection information is detected by the second or third detection process, that vulnerability information will be added to the final detection results.

[0110] The vulnerability detection unit 113 may display on the user terminal 20 the initial detection result of the first detection process, and then display on the user terminal 20 an intermediate detection result obtained by updating the initial detection result with the detection result of one of the second detection process and the third detection process, and then further display on the user terminal 20 a final detection result obtained by updating the intermediate detection result with the remaining detection result of the second detection process and the third detection process.

[0111] <Display section> The display unit 211 of the user terminal 20 displays a screen indicated by the screen data transmitted from the information processing device 10.

[0112] <Operation acquisition part> The operation acquisition unit 212 of the user terminal 20 accepts operations by the user who uses the user terminal 20 .

[0113] 3. Information Processing Method This section describes an information processing method of the information processing device 10. This information processing method is executed by a computer, with each unit of the information processing device 10 acting as each step.

[0114] This information processing includes a vulnerability detection step. In the vulnerability detection step, at least two of a first detection process, a second detection process, and a third detection process are executed on a detection target system for detecting vulnerability information. In the first detection process, a first snapshot created in the detection target system and saving the state of at least a portion of the detection target system is scanned for vulnerability information within the detection target system. In the second detection process, an agent installed in the detection target system for collecting system configuration information is caused to acquire the configuration information of at least a portion of the detection target system, the configuration information is received, and a vulnerability information scan is executed on the configuration information. In the third detection process, a second snapshot is acquired in the detection target system, saving the state of at least a portion of the detection target system, and at least a portion of the detection target system is reconstructed as a scan target system based on the second snapshot, and a vulnerability information scan is executed on the scan target system.

[0115] 8 is an activity diagram showing an example of the flow of information processing (processing for detecting vulnerability information) executed by the information processing system 1. Below, the information processing will be described along with each activity in this activity diagram.

[0116] The vulnerability information detection process begins with the registration of a search target system. The user inputs settings required for scanning the search target system by the information processing device 10, such as specifying the search target system and creating and assigning roles, into the user terminal 20 (activity A101). The information processing device 10 registers the search target system input into the user terminal 20 as a scan target (activity A102).

[0117] After the search target system is registered, the user inputs a scan instruction to the information processing device 10 on the user terminal 20 (activity A103). The scan instruction on the user terminal 20 may be an instruction to set the timing of the scan. Upon receiving the scan instruction from the user terminal 20, the information processing device 10 executes a first detection process on the search target system (activity A104). After executing the first detection process, the information processing device 10 outputs the detection result of the first detection process (initial detection result) and a proposal to additionally execute a second detection process and / or a third detection process to the user terminal 20 (activity A105). As a result, the initial detection result and the proposal for additional detection process are displayed on the user terminal 20 (activity A106).

[0118] After checking the initial detection result, the user inputs an instruction to execute the second detection process and / or the third detection process (additional detection process) in the user terminal 20 (activity A107). Upon receiving the instruction to execute the additional detection process from the user terminal 20, the information processing device 10 executes the additional detection process for the search target system (activity A108). After executing the additional detection process, the information processing device 10 outputs the detection result in the additional detection process (final detection result) to the user terminal 20 (activity A109). As a result, the final detection result is displayed on the user terminal 20 (activity A110).

[0119] 4. Effect The operation of this embodiment can be summarized as follows: That is, vulnerability information can be detected from a detection target system by any combination of the first detection process, the second detection process, and the third detection process. Therefore, vulnerability information can be easily obtained by selecting a detection process according to the configuration and usage environment of the detection target system.

[0120] Although the embodiment of the present invention has been described above, the present invention is not limited to this and can be modified as appropriate within the scope of the technical idea of ​​the invention.

[0121] 5.Other In the above embodiment, the information processing device 10 performs various storage and control operations, but multiple external devices may be used instead of the information processing device 10. That is, various information and programs may be distributed and stored in multiple external devices using blockchain technology or the like.

[0122] The aspect of this embodiment is not limited to the information processing system 1, and may be an information processing method or a program. The information processing method includes steps executed by the information processing system 1. The program causes a computer to execute the steps of the information processing system 1.

[0123] It may be provided in the following manner.

[0124] (1) An information processing system including at least one processor, the processor being configured to execute each of the following steps by reading a program: in the vulnerability detection step, at least two of a first detection process, a second detection process, and a third detection process are executed on a detection target system for detecting vulnerability information; in the first detection process, a first snapshot created in the detection target system, which saves the state of at least a part of the detection target system, is scanned for vulnerability information within the detection target system; in the second detection process, an agent installed in the detection target system for collecting system configuration information is caused to acquire the configuration information of at least a part of the detection target system, the agent receives the configuration information, and the agent scans the configuration information for vulnerability information; and in the third detection process, a second snapshot is acquired in the detection target system, which saves the state of at least a part of the detection target system, and at least a part of the detection target system is reconstructed as a scanning system based on the second snapshot, and the agent scans the scanning system for vulnerability information.

[0125] (2) In the information processing system described in (1) above, the vulnerability detection step executes the first detection process and at least one of the second detection process and the third detection process.

[0126] (3) In the information processing system described in (2) above, in the vulnerability detection step, the first detection process is executed, and at least one of the second detection process and the third detection process is executed depending on the detection result of the first detection process.

[0127] (4) In the information processing system described in (3) above, in the vulnerability detection step, depending on the detection result of the first detection process, the detection result is displayed and the user is prompted to execute the second detection process and / or the third detection process, and an instruction to execute the second detection process and / or the third detection process is received from the user.

[0128] (5) In the information processing system described in (3) or (4) above, in the vulnerability detection step, the display mode of the results for each detection item in the detection results of the first detection process is changed depending on the amount of information that can be detected from the first snapshot.

[0129] (6) In the information processing system described in any one of (3) to (5) above, in the vulnerability detection step, after executing the second detection process and / or the third detection process, the detection result of the first detection process is updated by the detection result of the second detection process and / or the third detection process, and the updated detection result is displayed.

[0130] (7) In the information processing system according to any one of (1) to (6) above, the detection target system is a virtual server.

[0131] (8) In the information processing system described in (7) above, in the third detection process, the scanning system is constructed on a virtual server on the same cloud platform as the detection target system.

[0132] (9) In the information processing system described in any one of (1) to (8) above, in the first detection process, authority to scan the detection target system is obtained, the first snapshot for the detection target system is created within the detection target system based on the authority, and the first snapshot is deleted after scanning the first snapshot for vulnerability information.

[0133] (10) In the information processing system described in any one of (1) to (9) above, in the second detection process, the agent acquires authority to acquire the configuration information and transmit it outside the detection target system, and the agent inputs a command to the detection target system to output the configuration information.

[0134] (11) In the information processing system described in any one of (1) to (10) above, in the third detection process, the authority to scan the detection target system is obtained, the second snapshot for the detection target system is created within the detection target system based on the authority, a copy of the second snapshot is received, and further, after the scanning system is constructed, the second snapshot within the detection target system is deleted.

[0135] (12) In the information processing system described in any one of (1) to (11) above, in the vulnerability detection step, the information processing system determines the priority of vulnerability information detected in any one of the first detection process, the second detection process, and the third detection process based on at least one of information indicating the vulnerability level set by a third-party organization, information indicating whether the vulnerability is accessible from outside, information indicating whether an attack against the vulnerability will have a significant impact on business operations, information indicating whether attack code against the vulnerability is in circulation, and information indicating whether exploitation of the vulnerability has been confirmed.

[0136] (13) An information processing method, comprising steps executed by the information processing system according to any one of (1) to (12) above.

[0137] (14) A program for causing a computer to execute each step of the information processing system described in any one of (1) to (12) above. Of course, this is not the case.

[0138] Finally, while various embodiments of the present disclosure have been described, they are presented as examples and are not intended to limit the scope of the invention. The novel embodiments may be embodied in various other forms, and various omissions, substitutions, and modifications may be made without departing from the spirit of the invention. Such embodiments and modifications are intended to be included within the scope and spirit of the invention, as well as within the scope of the inventions and their equivalents as defined in the claims. [Explanation of symbols]

[0139] 1: Information processing system 2: Communication line 10: Information processing device 11: Control section 12: Storage section 13: Communications Department 14: Communication bus 20: User terminal 21: Control unit 22: Storage section 23: Communications Department 24: Input section 25: Output section 26: Communication bus 30: Managed server 40: Vulnerability Information Server 111: Basic display control section 112: System Registration Department 113: Vulnerability detection unit 211: Display section 212: Operation acquisition section U: User

Claims

1. An information processing system, at least one processor; The processor is configured to execute the following steps by reading the program: In the vulnerability detection step, at least two processes among a first detection process, a second detection process, and a third detection process are executed on a detection target system for detecting vulnerability information; In the first detection process, a first snapshot, which is created in the detection target system and saves a state of at least a part of the detection target system, is scanned for vulnerability information in the detection target system; In the second detection process, an agent installed in the detection target system for collecting system configuration information is caused to acquire at least a part of the configuration information of the detection target system, the configuration information is received, and a vulnerability information scan is performed on the configuration information; In the third detection process, an information processing system obtains a second snapshot within the detection target system that saves the state of at least a portion of the detection target system, reconstructs at least a portion of the detection target system as a scanning system based on the second snapshot, and performs a scan of vulnerability information on the scanning system.

2. 2. The information processing system according to claim 1, In the vulnerability detection step, the information processing system executes the first detection process and at least one of the second detection process and the third detection process.

3. 3. The information processing system according to claim 2, In the vulnerability detection step, the information processing system executes the first detection process, and executes at least one of the second detection process and the third detection process depending on the detection result of the first detection process.

4. 4. The information processing system according to claim 3, In the vulnerability detection step, the information processing system displays the detection result in the first detection process depending on the detection result, and presents the execution of the second detection process and / or the third detection process to the user, and accepts an instruction from the user to execute the second detection process and / or the third detection process.

5. 4. The information processing system according to claim 3, In the vulnerability detection step, the information processing system changes a display mode of the detection results for each detection item in the first detection process depending on the amount of information that can be detected from the first snapshot.

6. 4. The information processing system according to claim 3, In the vulnerability detection step, after executing the second detection process and / or the third detection process, the information processing system displays the detection results updated from the detection results of the first detection process by the detection results of the second detection process and / or the third detection process.

7. 2. The information processing system according to claim 1, An information processing system, wherein the detection target system is a virtual server.

8. 8. The information processing system according to claim 7, In the third detection process, the scanning system is constructed on a virtual server on the same cloud platform as the detection target system.

9. 2. The information processing system according to claim 1, In the first detection process, an information processing system obtains authority to scan the detection target system, creates the first snapshot for the detection target system within the detection target system based on the authority, and further deletes the first snapshot after performing a scan of vulnerability information for the first snapshot.

10. 2. The information processing system according to claim 1, In the second detection process, an information processing system obtains authority to have the agent acquire the configuration information and transmit it outside the detection target system, and has the agent input a command to output the configuration information to the detection target system.

11. 2. The information processing system according to claim 1, In the third detection process, an information processing system obtains authority to scan the system to be detected, creates a second snapshot for the system to be detected within the system to be detected based on the authority, receives a copy of the second snapshot, and further deletes the second snapshot within the system to be detected after the scanning system is constructed.

12. 2. The information processing system according to claim 1, In the vulnerability detection step, the information processing system determines the priority of vulnerability information detected in any of the first detection process, the second detection process, and the third detection process based on at least one of information indicating the vulnerability level set by a third-party organization, information indicating whether the vulnerability is accessible from outside, information indicating whether an attack against the vulnerability will have a significant impact on business operations, information indicating whether attack code against the vulnerability is in circulation, and information indicating whether exploitation of the vulnerability has been confirmed.

13. An information processing method, comprising: An information processing method comprising the steps executed by the information processing system according to any one of claims 1 to 12.

14. A program, A program for causing a computer to execute each step of the information processing system according to any one of claims 1 to 12.

Citation Information

Patent Citations

  • Checking backups for vulnerabilities

    JP2022552891A

  • Security assessment of virtual computing environment using logical volume image

    US11216563B1

  • Facilitating analysis of software vulnerabilities

    US20230169183A1

  • State reproduction system, state reproduction program, security inspection system, and security inspection program

    WO2019069462A1

  • Embedded mechanism for platform vulnerability assessment

    JP2008165794A