Threat analysis system, threat analysis method, and program

The threat analysis system addresses the lack of specific countermeasures in existing systems by generating functional layer-specific security measures, enhancing security implementation efficiency and quality.

JP2026017900APending Publication Date: 2026-02-05PANASONIC AUTOMOTIVE SYST CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024118957
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-07-24
Publication Date
2026-02-05

AI Technical Summary

Technical Problem

Existing threat analysis systems fail to provide specific and actionable countermeasures against security threats, making it difficult for developers to implement effective security measures in complex systems.

Method used

A threat analysis system that includes an input unit, analysis unit, countermeasure processing unit, and output unit to analyze security threats and generate detailed, functional layer-specific countermeasures, using design information to identify assets and threats, and combine these with specific measures for each functional layer.

Benefits of technology

Enables developers to easily identify and implement specific security measures tailored to their functional layers, improving security efficiency and quality by providing clear, actionable countermeasures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026017900000001_ABST
    Figure 2026017900000001_ABST
Patent Text Reader

Abstract

To provide a threat analysis system capable of presenting an appropriate countermeasure against a threat.SOLUTION: A threat analyzing system 10 is a system that analyzes a threat to an analyzed system 50, and includes an inputter 11 that acquires designing information d10, an analyzer 12 that analyzes the threat to the analyzed system 50 based on the designing information d10 to output first analyzed result information d1 indicating an asset handled by the analyzed system 50, the threat to the asset, and a management measure as a measure against the threat, a measure processor 13 that combines a specific measure obtained by embodying the management measure indicated in the first analyzed result information d1 and corresponding to each of one or more functional layers included in the analyzed system 50 with the first analyzed result information d1 to generate second analyzed result information d1 including the first analyzed result information d2 and the specific measure, and an outputter 14 that outputs the second analyzed result information d2.SELECTED DRAWING: Figure 3
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to a threat analysis system that analyzes security threats to a system to be analyzed. [Background technology]

[0002] For example, Patent Document 1 discloses a threat analysis system. This threat analysis system acquires design information of a system to be analyzed, and based on the design information, analyzes the possibility of an attack on an asset and the impact of an attack on the asset for each component and function included in the system to be analyzed. Note that an asset is, for example, data handled by the system to be analyzed. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Publication No. 2023-47569 Summary of the Invention [Problem to be solved by the invention]

[0004] However, the threat analysis system of Patent Document 1 has a problem in that it does not propose appropriate countermeasures against threats.

[0005] Therefore, the present disclosure provides a threat analysis system and the like that can suggest appropriate countermeasures against threats. [Means for solving the problem]

[0006] A threat analysis system according to one embodiment of the present disclosure is a threat analysis system that analyzes security threats to a system under analysis, and includes: an input unit that acquires design information related to the design of the system under analysis; an analysis unit that analyzes threats to the system under analysis based on the design information, and outputs first analysis result information that indicates assets handled by the system under analysis, threats to the assets, and control measures that are countermeasures against the threats; a countermeasure processing unit that combines specific measures that embody the control measures indicated in the first analysis result information, the specific measures corresponding to each of one or more functional layers included in the system under analysis, with the first analysis result information, to generate second analysis result information that includes the first analysis result information and the specific measures; and an output unit that outputs the second analysis result information.

[0007] The comprehensive or specific aspects may be realized as an apparatus, a method, an integrated circuit, a computer program, or a computer-readable recording medium such as a CD-ROM, or may be realized as any combination of the apparatus, the method, the integrated circuit, the computer program, and the recording medium. The recording medium may also be a non-transitory recording medium. [Effects of the Invention]

[0008] The threat analysis system of the present disclosure can suggest appropriate countermeasures against threats.

[0009] Further advantages and effects of one aspect of the present disclosure will become apparent from the specification and drawings. Such advantages and / or effects are provided by the configurations described in the embodiments and the specification and drawings, but not all of the configurations are necessarily required. [Brief explanation of the drawings]

[0010] [Figure 1] FIG. 1 is a block diagram showing the configuration of a possible conventional threat analysis system. [Figure 2]FIG. 2 is a diagram showing an example of analysis result information output from a supposed conventional threat analysis system. [Figure 3] FIG. 3 is a diagram illustrating an example of the configuration of a threat analysis system according to an embodiment. [Figure 4] FIG. 4 is a diagram illustrating the function layer information according to the embodiment. [Figure 5] FIG. 5 is a diagram illustrating an example of a specific measure database according to the embodiment. [Figure 6] FIG. 6 is a diagram illustrating an example of part of the second analysis result information according to the embodiment. [Figure 7] FIG. 7 is a diagram illustrating another part of the second analysis result information according to the embodiment. [Figure 8] FIG. 8 is a flowchart showing an example of the processing operation of the threat analysis system according to the embodiment. [Figure 9] FIG. 9 is a flowchart showing an example of a specific processing operation of the countermeasure processing by the threat analysis system according to the embodiment. [Figure 10] FIG. 10 is a diagram showing an example of first analysis result information including a plurality of pieces of row information according to the embodiment. [Figure 11] FIG. 11 is a diagram illustrating an example of asset input / output information according to the embodiment. [Figure 12] FIG. 12 is a diagram showing an example of a portion related to row information in the second analysis result information according to the embodiment. [Figure 13] FIG. 13 is a diagram showing an example of a portion related to other row information in the second analysis result information according to the embodiment. [Figure 14] FIG. 14 is a diagram showing an example of a portion related to still other row information in the second analysis result information according to the embodiment. [Figure 15] FIG. 15 is a diagram showing an example of the second analysis result information after editing according to the embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0011] (Findings that formed the basis of this disclosure) The present inventors have found that the threat analysis system of Patent Document 1 described in the "Background Art" section has the following problems.

[0012] In recent years, many devices mounted on vehicles have been connected to each other so that they can communicate with each other via CAN (Controller Area Network), Ethernet (registered trademark), and the like. Furthermore, with the spread of connected cars and the like, the above-mentioned devices may communicate with devices outside the vehicle. Furthermore, the types of communication are becoming more diverse. With the advancement of CASE (Connected, Autonomous, Smart / Shared & Services, Electric) in vehicles, it has become essential to analyze threats and security risks to systems that include the above-mentioned devices at the early stages of their development lifecycle.

[0013] The threat analysis system of Patent Document 1 analyzes the possibility of attacks on assets handled by the system being analyzed and the impact of attacks on those assets. However, in the threat analysis system of Patent Document 1, as in the conventional threat analysis systems envisioned below, the countermeasures against threats presented or pointed out by the analysis are too abstract.

[0014] FIG. 1 is a block diagram showing the configuration of a possible conventional threat analysis system.

[0015] The assumed conventional threat analysis system 90 is a system that analyzes cybersecurity threats to a target system, such as a system installed in a vehicle, and includes an input unit 91, an analysis unit 92, and an output unit 94.

[0016] The input unit 91 acquires design information d71 of the system under analysis based on, for example, an input operation by a user. The analysis unit 92 acquires the design information d71 from the input unit 91 and analyzes the above-mentioned threats to the system under analysis based on the design information d71. At this time, the analysis unit 92 refers to a threat database stored in the threat memory unit 80. The analysis unit 92 generates analysis result information d72 through the analysis. The output unit 94 outputs the analysis result information d72 generated by the analysis unit 92 to, for example, a display.

[0017] FIG. 2 is a diagram showing an example of the analysis result information d72 output from the threat analysis system 90. As shown in FIG.

[0018] The analysis result information d72 shows functions, assets, threat scenarios, security requirements, assignees, and control measures in association with each other. The assets are, for example, data handled by the threat analysis system 90. The functions are functions that use the assets. The threat scenarios are scenarios of threats to the assets. The security requirements are requirements for preventing the threat scenarios. The assignees are components that have the above-mentioned functions among the multiple components that the system under analysis has. The control measures are measures against the above-mentioned threats and are measures for satisfying the security requirements.

[0019] Because these control measures are too abstract, even if the control measures are presented, each developer of the system under analysis cannot easily understand which functional layer the control measures apply to. Furthermore, it is difficult for each developer to immediately implement the measures against the threats.

[0020] Therefore, a threat analysis system according to a first aspect of the present disclosure is a threat analysis system for analyzing security threats to a target system, the threat analysis system including: an input unit that acquires design information about the target system; an analysis unit that analyzes threats to the target system based on the design information and outputs first analysis result information indicating assets handled by the target system, threats to the assets, and control measures as countermeasures against the threats; a countermeasure processing unit that combines the first analysis result information with specific measures that embody the control measures indicated in the first analysis result information and that correspond to one or more functional layers included in the target system, to generate second analysis result information including the first analysis result information and the specific measures; and an output unit that outputs the second analysis result information. For example, the assets may be data, and the functional layers may be a hardware layer, an OS (Operating System) layer, a middleware layer, an application layer (i.e., an application program layer), etc.

[0021] As a result, second analysis result information including the first analysis result information and specific measures is output. In other words, not only the control measures but also specific measures that embody the control measures and correspond to one or more functional layers are output and displayed, for example, on a display. Therefore, for example, developers of each functional layer can easily identify specific measures corresponding to the functional layer they are responsible for among measures against threats to the system under analysis. In this way, the first aspect of the present disclosure can present appropriate measures against threats. As a result, developers of each functional layer can appropriately apply the specific measures, which are specific countermeasures, to components belonging to that functional layer in the system under analysis. In other words, even if developers are not security personnel, they can easily identify the specific measures and immediately implement them. As a result, the efficiency of security activities and the quality of security can be improved.

[0022] In the threat analysis system according to the second aspect, the countermeasure processing unit may, in combining the specific measures, refer to a specific measures database that indicates specific measures for each functional layer for each of a plurality of management measures, identify from the specific measures database the specific measures that correspond to the management measures indicated in the first analysis result information and each of the one or more functional layers, and combine the identified specific measures with the first analysis result information. Note that the second aspect may be subordinate to the first aspect.

[0023] As a result, the specific measures database pre-determines specific measures for each functional layer for each of the multiple management measures, so by referring to the specific measures database, appropriate specific measures can be identified and combined with the first analysis result information.

[0024] In a threat analysis system according to a third aspect, the design information may indicate functional layers to which each of a plurality of components included in the system to be analyzed belongs, and the countermeasure processing unit may, in combining the specific measures, identify one or more functional layers to which one or more components related to the asset belong, among the plurality of functional layers indicated in the design information, by referring to the design information. For example, the design information may include functional layer information indicating the functional layer to which each of the plurality of components belongs. Note that the third aspect may be subordinate to the first or second aspect.

[0025] As a result, since the design information indicates in advance the functional layer to which each of the multiple components belongs, it is possible to identify the appropriate functional layer by referencing the design information (specifically, the functional layer information).In addition, it is possible to prevent the identification of functional layers to which components that are not related to the assets handled in the system to be analyzed belong, and it is possible to present only specific measures corresponding to the required functional layers.

[0026] In a threat analysis system according to a fourth aspect, the design information may further indicate the flow of input and output of the asset in the plurality of components as a data flow, and the countermeasure processing unit may, in combining the specific measures, identify one or more components among the plurality of components on the data flow as one or more components related to the asset by referring to the data flow in the design information. For example, the design information may include asset input / output information indicating the flow of input and output of the asset in the plurality of components as a data flow. Note that the fourth aspect may be dependent on the third aspect.

[0027] This allows one or more components associated with an asset to be properly identified.

[0028] In addition, in the threat analysis system according to a fifth aspect, in combining the specific measures, the countermeasure processing unit may select one component as a processing target component from one or more components on the data flow in reverse order of the data flow, and each time a processing target component is selected, identify a specific measure corresponding to the management measure indicated in the first analysis result information and a functional layer of the processing target component by referring to the specific measure database. Note that the fifth aspect may be dependent on the fourth aspect.

[0029] This makes it possible to select one or more components related to the asset in an appropriate order, and to identify specific measures for the components on the data flow in accordance with the order.

[0030] In a threat analysis system according to a sixth aspect, when outputting the second analysis result information, the output unit outputs, for each component included in the analysis target system, one or more specific measures corresponding to the functional layer of the component indicated in the second analysis result information. If there are multiple specific measures corresponding to the functional layer of the component indicated in the second analysis result information and the multiple specific measures include the same multiple specific measures, the output unit may output only one of the multiple identical specific measures as an aggregated specific measure. Note that the sixth aspect may be subordinate to any one of the first to fifth aspects. For example, the output unit displays the specific measures, the aggregated specific measures, etc. by outputting them to a display.

[0031] As a result, for each component, one or more specific measures corresponding to the functional layer of that component are output (e.g., displayed), allowing the developer of each functional layer to easily grasp the one or more specific measures required for the component to which that functional layer belongs. Furthermore, for multiple identical specific measures, only one of them is output (e.g., displayed) as an aggregated specific measure. In other words, multiple identical specific measures are aggregated into one specific measure. This reduces the number of specific measures presented. As a result, the developer can reduce the burden of checking the specific measures that he or she needs to implement and can easily grasp those specific measures. Note that the output destination of the specific measures, aggregated specific measures, etc. by the output unit is not limited to a display, and may be other devices such as a recording medium.

[0032] In addition, in the threat analysis system according to a seventh aspect, when the same plurality of specific measures correspond to a plurality of different assets, the output unit may output information indicating the plurality of different assets in association with the aggregated specific measures. Note that the seventh aspect may be subordinate to the sixth aspect.

[0033] As a result, even if multiple identical specific measures are aggregated into one specific measure, information indicating multiple different assets is associated with that single specific measure, the aggregated specific measure, and output (for example, displayed), so that the developer can easily understand which asset the aggregated specific measure corresponds to.

[0034] Furthermore, a threat analysis method according to a first aspect of the present disclosure is a threat analysis method in which a computer analyzes security threats to a system under analysis, the method acquiring design information related to the design of the system under analysis, and analyzing threats to the system under analysis based on the design information, thereby outputting first analysis result information indicating assets handled by the system under analysis, threats to the assets, and control measures that are countermeasures against the threats, and combining specific measures that embody the control measures indicated in the first analysis result information and that correspond to each of one or more functional layers included in the system under analysis with the first analysis result information to generate second analysis result information that includes the first analysis result information and the specific measures, and outputs the second analysis result information.

[0035] This makes it possible to achieve the same effects as those of the threat analysis system according to the first aspect.

[0036] Hereinafter, the embodiments will be specifically described with reference to the drawings.

[0037] The embodiments described below are all comprehensive or specific examples. The numerical values, shapes, materials, components, component placement and connection configurations, steps, and step order shown in the following embodiments are merely examples and are not intended to limit the present disclosure. Furthermore, among the components in the following embodiments, components that are not described in the independent claims that represent the highest concepts are described as optional components.

[0038] In addition, each drawing is a schematic diagram and is not necessarily an exact illustration. In addition, the same components are denoted by the same reference numerals in each drawing.

[0039] (Embodiment) FIG. 3 is a diagram showing an example of the configuration of a threat analysis system according to this embodiment.

[0040] The threat analysis system 10 in this embodiment is a system that analyzes security threats to a system under analysis, and includes an input unit 11, an analysis unit 12, a countermeasure processing unit 13, and an output unit 14. The security is, for example, cybersecurity.

[0041] The input unit 11 acquires design information d10 of the system to be analyzed based on, for example, an input operation by a user. Here, the design information d10 is information related to the design of the system to be analyzed, and includes system configuration information d11, function allocation configuration information d12, function layer information d13, asset information d14, and asset input / output information d15.

[0042] The system configuration information d11 indicates, for example, a plurality of components (also called constituent elements) included in the system to be analyzed, the connection relationships between the plurality of components, and the connection relationships between the system to be analyzed and external devices. Each of the plurality of components may be a CPU (Central Processing Unit), memory, a network IF (Interface), an OS (Operating System), an application, etc. An application refers to an application program. A component may also be an ECU (Electronic Control Unit).

[0043] The function allocation configuration information d12 indicates a plurality of functions of the system to be analyzed and the components in which each of the plurality of functions is implemented.

[0044] The function layer information d13 indicates the function layer to which each of the components included in the system to be analyzed belongs, such as a hardware layer, an OS layer, a middleware layer, an application layer, and the like.

[0045] The asset information d14 indicates assets used by each function of the system to be analyzed. The assets are, for example, data. The asset information d14 may also indicate CIA (Confidentiality, Integrity, Availability) characteristics, an impact assessment in the event of an intrusion, etc.

[0046] The asset input / output information d15 indicates, for each asset, the flow of inputs and outputs of the asset in a plurality of components included in the system to be analyzed as a data flow.

[0047] The analysis unit 12 acquires the design information d10 from the input unit 11 and analyzes the above-mentioned threats to the system under analysis based on the design information d10. At this time, the analysis unit 12 refers to the threat database stored in the threat memory unit 20. Note that the threat database stored in the threat memory unit 20 may be the same as the threat database stored in the threat memory unit 80 shown in FIG. 1. The threat memory unit 20 is a recording medium for storing the threat database. For example, the threat memory unit 20 is a hard disk drive, a RAM (Random Access Memory), a ROM (Read Only Memory), or a semiconductor memory. Furthermore, such a threat memory unit 20 may be volatile or non-volatile.

[0048] The analysis unit 12 generates and outputs first analysis result information d1 through the above-mentioned analysis. The first analysis result information d1 indicates the assets handled by the system under analysis, the threats to the assets, and the management measures that are countermeasures against the threats. This first analysis result information d1 may indicate the same content as the analysis result information d72 shown in FIGS. 1 and 2. Note that the first analysis result information d1 indicates the above-mentioned threats as threat scenarios.

[0049] In this way, the analysis unit 12 in this embodiment analyzes threats to the analysis target system based on the design information d10, and outputs the first analysis result information d1.

[0050] The countermeasure processing unit 13 acquires first analysis result information d1 from the analysis unit 12. Then, the countermeasure processing unit 13 generates second analysis result information d2 by combining specific measures shown in the specific measure database stored in the specific measure storage unit 30 with the first analysis result information d1. The specific measure storage unit 30 is a recording medium for storing the specific measure database. For example, the specific measure storage unit 30 is a hard disk drive, RAM, ROM, or semiconductor memory, similar to the threat storage unit 20. The specific measure storage unit 30 may be volatile or non-volatile.

[0051] In other words, the countermeasure processing unit 13 in this embodiment generates second analysis result information d2 that includes the first analysis result information d1 and the specific measures, by combining the specific measures that are concrete implementations of the management measures shown in the first analysis result information d1 and that correspond to each of one or more functional layers included in the system to be analyzed with the first analysis result information d1.

[0052] The output unit 14 outputs the second analysis result information d2 generated by the countermeasure processing unit 13 to, for example, a display.

[0053] FIG. 4 is a diagram for explaining the function layer information d13 in this embodiment.

[0054] The function layer information d13 indicates the function layer of each component included in the analysis target system 50, as shown in FIG. 4, for example. Specifically, the analysis target system 50 includes a first device 51, a second device 52, and a third device 53. When the analysis target system 50 is an in-vehicle system, the first device 51, the second device 52, and the third device 53 may be ECUs. Furthermore, each of the first device 51, the second device 52, and the third device 53 may be a server device or a terminal device. The terminal device may be a personal computer, a tablet terminal, a smartphone, or the like.

[0055] The first device 51 includes, for example, a first CPU, a first memory, a first recording medium, a first network IF, a first OS, a first middleware, a second middleware, a first application, and a second application as components.

[0056] The second device 52 includes, for example, a second CPU, a second memory, a second recording medium, a second network IF, a second OS, a third middleware, a third application, and a fourth application as components.

[0057] The third device 53 includes, for example, a third CPU, a third memory, a third OS, a fourth middleware, and a fifth application as components.

[0058] The function layer information d13 indicates a function layer to which each component of each of the above-mentioned devices belongs. For example, the function layer information d13 indicates a hardware layer as the function layer of each of the first CPU, second CPU, third CPU, first memory, second memory, third memory, first recording medium, second recording medium, first network IF, and second network IF. The function layer information d13 also indicates an OS layer as the function layer of each of the first OS, second OS, and third OS. The function layer information d13 also indicates a middleware layer as the function layer of each of the first middleware, second middleware, third middleware, and fourth middleware. The function layer information d13 also indicates an application layer as the function layer of each of the first application, second application, third application, fourth application, and fifth application.

[0059] The system configuration information d11 may indicate the type, manufacturer, model number, etc. of these components. The system configuration information d11 may also indicate the connection relationship between the components. For example, the system configuration information d11 may indicate the connection relationship between a first network IF and a second network IF. This connection relationship may include the network type, standard version, protocol, encryption method, encryption key length, etc.

[0060] FIG. 5 is a diagram showing an example of the concrete measures database in this embodiment.

[0061] The concrete measure storage unit 30 stores, for example, a concrete measure database 31 shown in FIG. 5. As shown in FIG. 5, the concrete measure database 31 indicates concrete measures for each functional layer for each of a plurality of control measures. That is, for each of a plurality of control measures, the concrete measure database 31 indicates concrete measures for the application layer, middleware, OS, and hardware layers. For example, for the control measure "Verify that the public key is signed by a certificate authority," the concrete measure database 31 indicates an application layer concrete measure "The 'public key certificate' for ensuring the authenticity of the communication destination must be issued by a certificate authority (CA)...." Furthermore, for the above control measure, the concrete measure database 31 indicates "No action is required for this requirement" as a concrete measure for each of the middleware layer, OS layer, and hardware layer. This concrete measure "No action is required for this requirement" indicates that there is no concrete measure or that no concrete measure is required. The control measures shown in Figure 5 correspond to, for example, Mitigations in CAPEC (Common Attack Pattern Enumeration and Classification)-94.

[0062] FIG. 6 is a diagram illustrating an example of a portion of the second analysis result information d2 in this embodiment.

[0063] 6, the second analysis result information d2 includes the first analysis result information d1 and a specific measure linked to the first analysis result information d1. For example, the countermeasure processing unit 13 acquires the first analysis result information d1 from the analysis unit 12, and further acquires the function layer information d13 included in the design information d10 from the input unit 11 via the analysis unit 12. Next, the countermeasure processing unit 13 identifies the function layer of the component indicated as the allocation destination in the first analysis result information d1 by referring to the function layer information d13. Furthermore, the countermeasure processing unit 13 identifies, from the specific measure database 31, a specific measure associated with the function layer and the management measure indicated in the first analysis result information d1. Then, the countermeasure processing unit 13 links the identified specific measure to the first analysis result information d1 so that the specific measure is associated with the management measure.

[0064] Specifically, the first analysis result information d1 indicates the component "first application" as the allocation destination. Therefore, the countermeasure processing unit 13 identifies "application layer" as the functional layer of the component "first application" by referring to the function layer information d13. Next, the countermeasure processing unit 13 identifies, from the concrete measure database 31, a concrete measure associated with the functional layer "application layer" and the control measure "Verify that the public key is signed by a certificate authority" indicated in the first analysis result information d1. That is, the countermeasure processing unit 13 identifies the concrete measure "The 'public key certificate' for ensuring the authenticity of the communication destination is issued by a certificate authority (CA)...". Then, the countermeasure processing unit 13 combines the identified concrete measure "The 'public key certificate' for ensuring the authenticity of the communication destination is issued by a certificate authority (CA)..." with the first analysis result information d1 so that the concrete measure is associated with the control measure "Verify that the public key is signed by a certificate authority (CA)." Such combination of specific measures is performed so that a specific measure is associated with each management measure indicated in the first analysis result information d1.

[0065] FIG. 7 is a diagram illustrating another example of the second analysis result information d2 in this embodiment.

[0066] The countermeasure processing unit 13 in this embodiment also includes, in the second analysis result information d2, specific measures corresponding to functional layers of allocation destinations different from those indicated in the first analysis result information d1. For example, in the data flow of the first data, which is an asset indicated in the first analysis result information d1, not only the first application but also a system on a chip (SoC) exists as a component. The data flow of the first data is indicated in the asset input / output information d15. In such a case, the countermeasure processing unit 13 creates a copy of the first analysis result information d1 and changes the allocation destination from "first application" to "SoC." Furthermore, the countermeasure processing unit 13 identifies "hardware layer" as the functional layer of the component "SoC" by referring to the functional layer information d13. Next, the countermeasure processing unit 13 identifies, from the concrete measure database 31, a concrete measure associated with the functional layer "hardware layer" and the control measure "verify that the public key is signed by a certificate authority" indicated in the first analysis result information d1. That is, the countermeasure processing unit 13 identifies the concrete measure "No action is required for this requirement." Then, the countermeasure processing unit 13 combines the identified specific measure "There is no action to be taken for this requirement" with the control measure "Verify that the public key is signed by a certificate authority" into the first analysis result information d1 whose assignment destination has been changed. This combination of specific measures is performed so that, for each control measure indicated in the first analysis result information d1 whose assignment destination has been changed, the specific measure is associated with that control measure.

[0067] Note that the specific measure "There is no work to be done for this requirement." means that there is no specific measure, so the specific measure may be skipped without being combined.

[0068] The second analysis result information d2 in this embodiment includes a part of the second analysis result information d2 shown in FIG. 6 and another part of the second analysis result information d2 shown in FIG.

[0069] As described above, in this embodiment, the countermeasure processing unit 13 refers to the data flow of the asset input / output information d15 included in the design information d10, and identifies, among multiple components, one or more components on the data flow as one or more components related to the asset. This makes it possible to appropriately identify one or more components related to the asset. Note that in the example of FIG. 6, the first application is also identified as a component from the data flow. Therefore, in the examples of FIGS. 6 and 7, the one or more components are the first application and the SoC.

[0070] Next, the countermeasure processing unit 13 identifies one or more functional layers to which one or more components related to the first data, which is an asset, belong, from among the multiple functional layers indicated in the functional layer information d13 of the design information d10, by referring to the functional layer information d13. In the examples of FIGS. 6 and 7, the one or more functional layers are an application layer and a hardware layer.

[0071] Then, the countermeasure processing unit 13 refers to the specific measures database 31, identifies from the specific measures database 31 specific measures corresponding to the management measures indicated in the first analysis result information d1 and each of its one or more functional layers, and combines the identified specific measures with the first analysis result information d1.

[0072] FIG. 8 is a flowchart showing an example of the processing operation of the threat analysis system 10 in this embodiment.

[0073] The input unit 11 of the threat analysis system 10 acquires design information d10 (step S1). Next, the analysis unit 12 generates first analysis result information d1 by performing threat analysis based on the design information d10 and the threat database stored in the threat storage unit 20 (step S2). Next, the countermeasure processing unit 13 generates second analysis result information d2 by performing countermeasure processing based on the first analysis result information d1 generated in step S2 and the specific measure database 31 stored in the specific measure storage unit 30 (step S3). Then, the output unit 14 outputs the second analysis result information d2 generated in step S3 to, for example, a display (step S4).

[0074] Fig. 9 is a flowchart showing an example of a specific processing operation of the countermeasure processing by the threat analysis system 10 in this embodiment. That is, the flowchart in Fig. 9 shows in detail the countermeasure processing of step S3 shown in Fig. 8. Hereinafter, the countermeasure processing will be described in detail using not only Fig. 9 but also Figs. 10 to 15.

[0075] First, in the countermeasure processing, when the countermeasure processing unit 13 acquires the first analysis result information d1 from the analysis unit 12, the countermeasure processing unit 13 extracts one line of information (that is, line information described below) from the first analysis result information d1 (step S301).

[0076] FIG. 10 is a diagram showing an example of first analysis result information d1 including a plurality of pieces of row information.

[0077] As shown in FIG. 10 , the first analysis result information d1 includes one row of information (row information d1n) for each combination of an asset and a threat scenario. That is, row information d1n indicates the combination of an asset and a threat scenario, the function that uses the asset, the security requirements corresponding to the threat scenario, the assignment destination (i.e., the component to which the function is assigned), and one or more management measures for satisfying the security requirements. In the example of FIG. 10 , the first analysis result information d1 includes three pieces of row information d1n, each consisting of row information d1a, row information d1b, and row information d1c. Row information d1a is row information d1n that includes the combination of an asset "First Data" and a threat scenario "A001." Row information d1b is row information d1n that includes the combination of an asset "Second Data" and a threat scenario "A002." Row information d1c is row information d1n that includes the combination of an asset "Third Data" and a threat scenario "A003."

[0078] Note that "A001," "A002," "A003," "B001," "X011," "X012," "X212," and "X312" in Fig. 10 each simply represent a sentence. Also, in Figs. 11 to 15, as in Fig. 10, a character string consisting of an alphabet at the beginning followed by a three-digit number simply represents a document. Also, although the example in Fig. 10 shows three pieces of line information d1n, it is sufficient that the first analysis result information d1 includes at least one piece of line information d1n, and it may also include four or more pieces of line information d1n.

[0079] For example, in step S301 of FIG. 9, the countermeasure processing unit 13 extracts row information d1a, which is information for one row having a combination of the asset "first data" and the threat scenario "A001."

[0080] Next, for each of the one or more control measures included in the row information d1a, the countermeasure processing unit 13 obtains specific measures for each functional layer corresponding to the control measure from the specific measure database 31 (step S302). For example, row information d1a is extracted in step S301. In this case, the countermeasure processing unit 13 obtains specific measures associated with the control measure "X011" shown in the row information d1a and each of the application layer, middleware layer, OS layer, and hardware layer from the specific measure database 31. As a result, specific measures for each of the four functional layers are obtained for the control measure "X011," i.e., four specific measures. Furthermore, the countermeasure processing unit 13 obtains specific measures associated with the control measure "X012" shown in the row information d1a and each of the application layer, middleware layer, OS layer, and hardware layer from the specific measure database 31. As a result, specific measures for each of the four functional layers are obtained for control measure "X012," that is, four specific measures.

[0081] Note that the concrete measure "There is no work to be done for this requirement" shown in the concrete measure database 31 means that there is no concrete measure. Therefore, if the concrete measure "There is no work to be done for this requirement" is associated with the management measure shown in the row information d1a and any of the functional layers in the concrete measure database 31, the countermeasure processing unit 13 does not need to acquire that concrete measure.

[0082] Then, the countermeasure processing unit 13 temporarily stores the specific countermeasures for each function layer acquired in step S302 (step S303).

[0083] Next, the countermeasure processing unit 13 identifies one or more components present in the data flow of the target asset, which is the asset indicated in the row information d1n (for example, row information d1a) extracted in step S301 (step S304). Such a data flow is indicated in the asset input / output information d15.

[0084] FIG. 11 is a diagram showing an example of the asset input / output information d15.

[0085] For example, as shown in FIG. 11 , the analysis target system 50 includes an SoC, an OS, a service, a gateway, a wireless communication unit, and a first application as components. The wireless communication unit is a component that performs wireless communication, for example, according to Wi-Fi (registered trademark). The asset input / output information d15 indicates the data flow of each asset in the analysis target system 50 configured in this manner. For example, if the row information d1n extracted in step S301 is row information d1a, the target asset is first data. In the data flow of the first data, for example, as shown by the solid arrows in FIG. 11 , the first data is input from the SoC to the first application via the OS, the service, and the gateway, and is further output from the first application to the outside of the analysis target system 50 via the wireless communication unit, the service, the OS, and the SoC. In other words, the SoC, the OS, the service, the gateway, the first application, and the wireless communication unit each exist as components in the data flow of the first data.

[0086] In step S304 of FIG. 9, if the target asset is the first data, the countermeasure processing unit 13 identifies the SoC, OS, service, gateway, first application, and wireless communication unit that exist in the data flow of the first data as components.

[0087] Then, the countermeasure processing unit 13 selects one component from the one or more components identified in step S304, and identifies the functional layer of the component by referring to the functional layer information d13 (step S305). Here, when the processing of step S305 is repeatedly executed, the countermeasure processing unit 13 selects components present on the data flow of the target asset in reverse order of the data flow of the target asset. Note that the reverse order of the data flow is the order from the downstream side to the upstream side of the data flow, which is the order indicated by the dashed arrows in FIG. 11. Furthermore, in the first processing of step S305, the component at the most downstream of the data flow is selected. For example, if the target asset is first data and the data flow of the first data is indicated by the solid arrows in FIG. 11, the countermeasure processing unit 13 selects the component "SoC" at the most downstream of the data flow. Then, the countermeasure processing unit 13 identifies the "hardware component" as the functional layer of the component "SoC" by referring to the functional layer information d13.

[0088] Next, the countermeasure processing unit 13 determines whether specific measures corresponding to the functional layer identified in step S305 are held in step S303 (step S306). Here, for example, in step S303, specific measures corresponding to the control measure "X011" and the application layer, specific measures corresponding to the control measure "X011" and the middleware layer, specific measures corresponding to the control measure "X011" and the OS layer, and specific measures corresponding to the control measure "X011" and the hardware layer are held. Furthermore, in step S303, specific measures corresponding to the control measure "X012" and the application layer, specific measures corresponding to the control measure "X012" and the middleware layer, specific measures corresponding to the control measure "X012" and the OS layer, and specific measures corresponding to the control measure "X012" and the hardware layer are held. Also, for example, in step S305, the functional layer "hardware component" is identified.

[0089] In this case, among the multiple controls held in step S303, the specific measures corresponding to the control measure "X011" and the hardware layer, and the specific measures corresponding to the control measure "X012" and the hardware layer are respectively specific measures corresponding to the functional layer "hardware layer" identified in step S305. Therefore, in step S306, the countermeasure processing unit 13 determines that the specific measures corresponding to the functional layer identified in step S305 are held in step S303 (Yes in step S306).

[0090] Next, when the countermeasure processing unit 13 determines that the above-mentioned specific measures are held (Yes in step S306), it adds analysis result information indicating the component selected in step S305 as the allocation destination to the row information d1n extracted in step S301 (step S307). The analysis result information is information that differs from the row information d1n only in the allocation destination. Furthermore, the countermeasure processing unit 13 combines a specific measure group consisting of one or more specific measures corresponding to the functional layer identified in step S305, among the multiple specific measures held in step S303, with the added analysis result information (step S308). For example, if the row information d1a shown in FIG. 10 is extracted in step S301, the portion of the second analysis result information d2 related to the row information d1a includes the row information d1a, the analysis result information added to the row information d1a, and the specific measure group combined with the analysis result information.

[0091] FIG. 12 is a diagram showing an example of a portion of the second analysis result information d2 relating to the row information d1a.

[0092] In step S307, the countermeasure processing unit 13 adds analysis result information d1aa to the row information d1a, for example, as shown in Fig. 12. The analysis result information d1aa is information that differs from the row information d1a only in the allocation destination. The analysis result information d1aa indicates, as the allocation destination, for example, the component "SoC" selected in step S305.

[0093] In step S308, the countermeasure processing unit 13 adds a specific measure group f21 to the added analysis result information d1aa, as shown in FIG. 12, for example. The specific measure group f21 includes one or more specific measures, among the multiple specific measures held in step S303, that correspond to the functional layer "hardware layer" identified for the component "SoC" in step S305. The one or more specific measures are, for example, "Y111" and "Y112." Note that the specific measure "Y111" is a specific measure that corresponds to the functional layer "hardware layer" of the component "SoC" to which the component is assigned and the control measure "X011." The specific measure "Y112" is a specific measure that corresponds to the functional layer "hardware layer" of the component "SoC" to which the component is assigned and the control measure "X012."

[0094] Next, the countermeasure processing unit 13 determines whether or not any component not selected in step S305 exists as another component among the one or more components identified in step S304 (step S309). If the countermeasure processing unit 13 determines that another component exists (Yes in step S309), the countermeasure processing unit 13 repeatedly executes the processing from step S305. For example, in the data flow of the first data shown in FIG. 11, the component "OS" follows the component "SoC" in the reverse order of the data flow. Therefore, if the countermeasure processing unit 13 selected the component "SoC" in the immediately preceding step S305, the countermeasure processing unit 13 determines that the component "OS" exists as another component (Yes in step S309). As a result, in the next step S305, the countermeasure processing unit 13 selects the component "OS" and identifies the OS layer as the functional layer of the component "OS." Then, the countermeasure processing unit 13 executes the processing of steps S306 to S308 again. As a result, as shown in FIG. 12, the countermeasure processing unit 13 adds the analysis result information d1ab to the row information d1a of the first analysis result information d1, and combines the specific countermeasure group f22 with the added analysis result information d1ab.

[0095] The analysis result information d1ab is information that differs from the row information d1a only in the allocation destination. The analysis result information d1ab indicates the component "OS" selected in step S305 as the allocation destination.

[0096] The group of specific measures f22 is made up of one or more specific measures, among the multiple specific measures held in step S303, that correspond to the functional layer "OS Layer" identified for the component "OS" in step S305. The one or more specific measures are, for example, "Y211" and "Y212." Specific measure "Y211" is a specific measure that corresponds to the functional layer "OS Layer" of the component "OS" to which it is assigned, and the control measure "X011." Specific measure "Y212" is a specific measure that corresponds to the functional layer "OS Layer" of the component "OS" to which it is assigned, and the control measure "X012."

[0097] Furthermore, by repeatedly executing the processes of steps S305 to S309, the component "first application" indicated in the row information d1a as the allocation destination may be selected in step S305. In this case, the process of step S307 is skipped, and the countermeasure processing unit 13 combines the specific countermeasure group f23 with the row information d1a (step S308).

[0098] The specific measure group f23 includes one or more specific measures corresponding to the functional layer "Application Layer" of the component "First Application" among the multiple specific measures held in step S303. The one or more specific measures are, for example, "Y011" and "Y012." Note that the specific measure "Y011" is a specific measure corresponding to the functional layer "Application Layer" of the component "First Application" to which it is assigned, and the control measure "X011." The specific measure "Y012" is a specific measure corresponding to the functional layer "Application Layer" of the component "First Application" to which it is assigned, and the control measure "X012."

[0099] In this way, by repeating the processes of steps S305 to S309, a portion of the second analysis result information d2 relating to row information d1a is generated, as shown in FIG. 12, for example.

[0100] In this embodiment, the countermeasure processing unit 13 selects one component as a processing target component from one or more components in the data flow of the target asset (in the above example, the first data) in the reverse order of the data flow. In the above example, in step S305, the SoC, OS, . . . , and first application are selected as processing target components in this order. Then, each time the countermeasure processing unit 13 selects a processing target component, it identifies specific measures corresponding to the management measures indicated in the first analysis result information d1 and the functional layer of the processing target component by referring to the specific measures database 31. In the above example, the identified specific measures are "Y111," "Y112," "Y211," "Y212," "Y011," "Y012," and so on. This makes it possible to identify one or more components related to the asset in an appropriate order and identify specific measures according to that order.

[0101] In step S306, if the countermeasure processing unit 13 determines that a specific measure corresponding to the functional layer identified in step S305 is not held in step S303 (No in step S306), it skips the processing of steps S307 and S308.

[0102] Next, if the countermeasure processing unit 13 determines that no other components exist (No in step S309), it determines whether all lines included in the first analysis result information d1, i.e., all line information d1n, have been extracted (step S310). For example, if only line information d1a has been extracted from the three line information d1n and line information d1b and d1c have not been extracted, the countermeasure processing unit 13 determines that all line information d1n has not been extracted (No in step S310). In this case, the countermeasure processing unit 13 repeatedly executes the process from step S301. For example, in step S301, the countermeasure processing unit 13 extracts line information d1b from the first analysis result information d1. Then, the countermeasure processing unit 13 uses the line information d1b to generate a portion of the second analysis result information d2 related to the line information d1b.

[0103] FIG. 13 is a diagram showing an example of a portion of second analysis result information d2 relating to row information d1b.

[0104] In step S301, when row information d1b is extracted from the first analysis result information d1, the countermeasure processing unit 13 executes the processes of steps S302 to S309 in the same manner as described above. As a result, in the first process of steps S305 to S309, the countermeasure processing unit 13 adds analysis result information d1ba to row information d1b and combines a specific measure group f31 with the added analysis result information d1ba, as shown in FIG.

[0105] The analysis result information d1ba is information that differs from the row information d1b only in the allocation destination. The analysis result information d1ba indicates the component "SoC" selected in step S305 as the allocation destination.

[0106] The group of specific measures f31 consists of one or more specific measures corresponding to the "hardware layer" functional layer identified for the component "SoC." The one or more specific measures are, for example, "Y111" and "Y312." Note that the specific measure "Y111" is a specific measure corresponding to the "hardware layer" functional layer of the component "SoC" to which it is assigned and the control measure "X011." The specific measure "Y312" is a specific measure corresponding to the "hardware layer" functional layer of the component "SoC" to which it is assigned and the control measure "X212."

[0107] Next, in the second processing of steps S305 to S309, the countermeasure processing unit 13 adds analysis result information d1bb to row information d1b, and combines a specific countermeasure group f32 with the added analysis result information d1bb, as shown in FIG.

[0108] The analysis result information d1bb is information that differs from the row information d1b only in the allocation destination. The analysis result information d1bb indicates the component "OS" selected in step S305 as the allocation destination.

[0109] The group of specific measures f32 consists of one or more specific measures corresponding to the functional layer "OS Layer" identified for the component "OS." The one or more specific measures are, for example, "Y211" and "Y312." Note that the specific measure "Y211" is a specific measure corresponding to the functional layer "OS Layer" of the component "OS" to which it is assigned and the control measure "X011." The specific measure "Y312" is a specific measure corresponding to the functional layer "OS Layer" of the component "OS" to which it is assigned and the control measure "X212."

[0110] Furthermore, in the n-th (n is an integer equal to or greater than 3) processing of steps S305 to S309, the component "first application" indicated in the row information d1b as the allocation destination is selected in step S305. In this case, the processing of step S307 is skipped, and the countermeasure processing unit 13 combines the specific countermeasure group f33 with the row information d1b, as shown in FIG.

[0111] The specific measure group f33 consists of one or more specific measures corresponding to the functional layer "Application Layer" identified for the component "First Application." The one or more specific measures are, for example, "Y011" and "Y412." Note that the specific measure "Y011" is a specific measure corresponding to the functional layer "Application Layer" of the component "First Application" to which it is assigned, and the control measure "X011." The specific measure "Y412" is a specific measure corresponding to the functional layer "Application Layer" of the component "First Application" to which it is assigned, and the control measure "X212."

[0112] Next, if the countermeasure processing unit 13 determines that no other components exist (No in step S309), it determines whether all lines included in the first analysis result information d1, i.e., all line information d1n, have been extracted (step S310). For example, if, of the three pieces of line information d1n, line information d1a and line information d1b have been extracted but line information d1c has not been extracted, the countermeasure processing unit 13 determines that all line information d1n has not been extracted (No in step S310). In this case, the countermeasure processing unit 13 repeatedly executes the process from step S301. For example, in step S301, the countermeasure processing unit 13 extracts line information d1c from the first analysis result information d1. Then, the countermeasure processing unit 13 uses the line information d1c to generate a portion of the second analysis result information d2 related to the line information d1c.

[0113] FIG. 14 is a diagram showing an example of a portion of second analysis result information d2 relating to row information d1c.

[0114] As in the example shown in Fig. 13, the countermeasure processing unit 13 executes the processes of steps S302 to S309 to add analysis result information d1ca and analysis result information d1cb to row information d1c, as shown in Fig. 14. Furthermore, the countermeasure processing unit 13 adds a specific measure group f41 to analysis result information d1ca, adds a specific measure group f42 to analysis result information d1cb, and adds a specific measure group f43 to row information d1c. As a result, the part of the second analysis result information d2 related to row information d1c is generated.

[0115] Next, if the countermeasure processing unit 13 determines that no other components exist (No in step S309), it determines whether all rows included in the first analysis result information d1, i.e., all row information d1n, have been extracted (step S310). For example, if line information d1a, line information d1b, and line information d1c have been extracted from the three row information d1n, the countermeasure processing unit 13 determines that all row information d1n has been extracted (Yes in step S310). In this case, the countermeasure processing unit 13 arranges one or more specific measures corresponding to each component indicated as an allocation destination in the second analysis result information d2, and aggregates the one or more specific measures if there are multiple identical specific measures among the one or more specific measures (step S311). In other words, the countermeasure processing unit 13 edits the second analysis result information d2 so that the same multiple specific measures corresponding to each component are aggregated and displayed as a single specific measure. At this time, the countermeasure processing unit 13 may also edit the second analysis result information d2 so that, for each security requirement of each of the multiple components, one or more specific measures corresponding to that component and its security requirement are indicated.

[0116] FIG. 15 is a diagram showing an example of the second analysis result information d2 after editing.

[0117] The edited second analysis result information d2 indicates one or more security requirements for the component "first application" that is the allocation destination, as shown in Fig. 15, for example. Each of the one or more security requirements is a security requirement that was associated with the component "first application" that is indicated as the allocation destination in the second analysis result information d2 before editing. In the example of Fig. 15, a security requirement "B001" is indicated for the component "first application."

[0118] Furthermore, the edited second analysis result information d2 indicates one or more sets of measures, each consisting of a control measure and a specific measure, for the security requirement "B001." Each of these one or more sets of measures is a set of measures that was associated with the component "first application" and the security requirement "B001" in the second analysis result information d2 before editing. In the example of FIG. 15, the first set of measures included in the one or more sets of measures is a control measure "X011" and a specific measure "Y011," and the second set of measures is a control measure "X012" and a specific measure "Y012."

[0119] Furthermore, the edited second analysis result information d2 indicates an asset group consisting of one or more assets for each of the one or more sets of measures. The asset group corresponding to the set of measures is made up of the component "Application 1," security requirement "B001," and one or more assets that were associated with the set of measures in the pre-edited second analysis result information d2. In the example of Fig. 15, the asset group corresponding to the first set of measures, i.e., control measure "X011" and specific measure "Y011," is made up of first data, second data, and third data, which are assets, respectively.

[0120] That is, in the second analysis result information d2 before editing, as shown in Figures 12 to 14, the control measure "X011" and the specific measure "Y011" are shown as a set of measures for the component "Application 1" for each of the assets of the first data, second data, and third data. However, in the second analysis result information d2 after editing, only one set of measures, i.e., one control measure "X011" and one specific measure "Y011," is shown for the component "Application 1." In other words, multiple sets of measures have been aggregated into a single set of measures.

[0121] In this way, the countermeasure processing unit 13 edits the second analysis result information d2 so that, for each security requirement of each of the multiple components, one or more sets of measures corresponding to that component and that security requirement are indicated. Furthermore, if there are multiple sets of the same measures corresponding to the component and security requirement, the countermeasure processing unit 13 edits the second analysis result information d2 so that those sets of measures are collectively indicated as a single set of measures.

[0122] The edited second analysis result information d2 may differ from the unedited second analysis result information d2 only in structure, and may have substantially the same content.

[0123] The output unit 14 outputs this edited second analysis result information d2 to the display. That is, the output unit 14 displays the edited second analysis result information d2 on the display. At this time, the output unit 14 may display the content indicated by the edited second analysis result information d2 on the display in stages in response to an input operation by the user.

[0124] For example, the output unit 14 displays on the display the names of multiple components indicated as allocation destinations in the edited second analysis result information d2. Then, when the name of one component is selected in response to a user's input operation, the output unit 14 displays on the display one or more security requirements associated with the component in the edited second analysis result information d2. Furthermore, when one security requirement is selected in response to a user's input operation, the output unit 14 displays on the display one or more sets of measures associated with the security requirement in the edited second analysis result information d2. The output unit 14 may display the one or more sets of measures one by one on the display. Here, when displaying the sets of measures on the display, the output unit 14 may also display on the display the names of each asset included in the asset group associated with the set of measures in the edited second analysis result information d2.

[0125] For example, when the output unit 14 displays a set of measures consisting of the management measure "X011" and the specific measure "Y011" on the display, it also displays the names of the first data, second data, and third data included in the asset group corresponding to that set of measures on the display.

[0126] In this way, when outputting the second analysis result information d2, the output unit 14 in this embodiment outputs, for each component included in the analysis target system 50, one or more specific measures indicated in the second analysis result information d2 and corresponding to the functional layer of the component. If there are multiple specific measures indicated in the second analysis result information d2 and the multiple specific measures include the same multiple specific measures, the output unit 14 outputs only one of the multiple identical specific measures as an aggregated specific measure. Note that the same multiple specific measures are specific measures included in each of the same multiple sets of measures described above.

[0127] As a result, for each component, one or more specific measures corresponding to the functional layer of that component are output (e.g., displayed), allowing developers of each functional layer to easily grasp the one or more specific measures required for the component to which that functional layer belongs. Furthermore, for multiple identical specific measures, only one of them is output (e.g., displayed) as an aggregated specific measure. In other words, multiple identical specific measures are aggregated into one specific measure. This reduces the number of specific measures presented. As a result, developers can reduce the burden of checking the specific measures they need to implement and easily grasp those specific measures.

[0128] Furthermore, in the case where the same multiple specific measures correspond to multiple different assets, the output unit 14 in this embodiment outputs information indicating the multiple different assets in association with the aggregated specific measures. In the above example, the names of the first data, second data, and third data are output as information indicating the multiple different assets and displayed on the display.

[0129] As a result, even if multiple identical specific measures are aggregated into one specific measure, information indicating multiple different assets is associated with that single specific measure, the aggregated specific measure, and output (for example, displayed), so that the developer can easily understand which asset the aggregated specific measure corresponds to.

[0130] As described above, in this embodiment, second analysis result information d2 including first analysis result information d1 and specific measures is output. That is, not only the control measures but also specific measures that embody the control measures, corresponding to one or more functional layers, are output and displayed, for example, on a display. Therefore, for example, developers of each functional layer can easily identify specific measures corresponding to the functional layer they are responsible for among measures against threats to the analysis target system 50. In this way, this embodiment can present appropriate measures against threats. As a result, developers of each functional layer can appropriately apply the specific measures to the components belonging to that functional layer in the analysis target system 50. That is, even if developers are not security personnel, they can easily identify the specific measures and immediately implement them. As a result, the efficiency of security activities and the quality of security can be improved.

[0131] Furthermore, in this embodiment, the specific measures database 31 indicates in advance specific measures for each functional layer for each of the multiple management measures, so that by referring to the specific measures database 31, appropriate specific measures can be identified and combined with the first analysis result information d1.

[0132] In this embodiment, the functional layer information d13 of the design information d10 indicates in advance the functional layer to which each of the multiple components belongs, so that an appropriate functional layer can be identified by referring to the functional layer information d13. Furthermore, it is possible to prevent the identification of functional layers to which components unrelated to the assets handled by the analysis target system 50 belong, and it is possible to present only specific measures corresponding to the required functional layers.

[0133] (Variation) The threat analysis system 10 and the threat analysis method according to one or more aspects of the present disclosure have been described above based on the embodiments, but the present disclosure is not limited to these embodiments. As long as the modifications do not deviate from the spirit of the present disclosure, various modifications that would occur to those skilled in the art may also be included in the present disclosure.

[0134] For example, in response to a user's operation of the zoom button, the output unit 14 may display on the display only one or more specific measures corresponding to the function layer corresponding to the operation, from among the second analysis result information d2.

[0135] Furthermore, when the output unit 14 displays, for each component, one or more specific measures corresponding to the functional layer of that component on the display as described above, the output unit 14 may also display on the display whether there are specific measures corresponding to the functional layers of other components other than the component. The output unit 14 may also display on the display specific measures corresponding to the functional layers of the other components described above. The output unit 14 may also determine, based on information indicating the functional layers for which a developer is responsible, whether the functional layer corresponding to the specific measure displayed on the display corresponds to the functional layer for which the developer is responsible. The output unit 14 may then display the result of the determination on the display.

[0136] Although the number of functional layers is four in the above embodiment, the number of functional layers may be any number as long as each functional layer is defined as one or more. The one or more defined functional layers may be multiple layers arbitrarily set by the user, or multiple layers based on the OSI (Open Systems Interconnection) reference model.

[0137] In the above embodiment, the four function layers indicated by the function layer information d13 correspond one-to-one to the four function layers indicated by the concrete measure database 31. However, the multiple function layers indicated by the function layer information d13 and the multiple function layers indicated by the concrete measure database 31 do not have to correspond one-to-one to each other as long as they are associated according to a predetermined rule. In other words, the resolution of the function layers indicated by the function layer information d13 and the resolution of the function layers indicated by the concrete measure database 31 may be different.

[0138] For example, the number of function layers indicated by the function layer information d13 may be three, and the number of function layers indicated by the specific measure database 31 may be four. In a specific example, the three function layers indicated by the function layer information d13 are A, B, and C. On the other hand, the four function layers indicated by the specific measure database 31 are a, b, c, and d. In this case, the function layer "A" may correspond to the function layer "a" and be treated as the function layer "a." Furthermore, the function layer "B" may correspond to the function layers "b" and "c" and be treated as the function layers "b" and "c." The function layer "C" may correspond to the function layer "d" and be treated as the function layer "d." In this way, the multiple function layers indicated by the function layer information d13 and the multiple function layers indicated by the specific measure database 31 do not need to be in one-to-one correspondence as long as they are previously associated with each other.

[0139] The association between the plurality of function layers indicated by the function layer information d13 and the plurality of function layers indicated by the specific measure database 31 may be performed by AI (Artificial Intelligence).

[0140] Furthermore, if the system under analysis 50 is composed of multiple devices, as shown in Figure 4, for example, the output unit 14 may select one device from the multiple devices in response to a user operation, and display only the specific measures corresponding to that device among the multiple specific measures on the display.

[0141] Furthermore, in the above embodiment, the concrete measure storage unit 30 stores one concrete measure database 31, but it may store multiple concrete measure databases 31. In this case, the countermeasure processing unit 13 may select one concrete measure database 31 from the multiple concrete measure databases 31 according to the threat scenario, etc. For example, the countermeasure processing unit 13 selects a concrete measure database 31 according to the communication system, memory system, architecture system, etc., and generates the second analysis result information d2 using the selected concrete measure database 31. Note that two or more concrete measure databases 31 may be selected.

[0142] Furthermore, the specific measure storage unit 30 may be connected to the threat analysis system 10 via a communication line such as the Internet, or may be provided in a cloud server or the like.

[0143] In the above embodiment, the countermeasure processing unit 13 determines whether or not a specific measure corresponding to the functional layer of the selected component is held in step S306 of Fig. 9. At this time, the countermeasure processing unit 13 may use AI to determine whether or not each held specific measure corresponds to the functional layer of the component.

[0144] Furthermore, for example, specific measures for the operational environment may be registered in the specific measures database 31. The operational environment here refers to vehicle functions, production facilities, services, repairs, and the like that are required for operating the components. More specifically, the specific measures database 31 registers management measures for the operational environment that are linked to the "operational environment layer" of the function layer. The countermeasure processing unit 13 adds components of the operational environment that are defined as the operational environment layer in the function layer information d13 to one or more components identified in step S304 of FIG. 9. Thereafter, steps S305 to S309 are executed, thereby linking the specific measures for the operational environment to the first analysis result d1.

[0145] In the above embodiments, each component may be configured with dedicated hardware or may be realized by executing a software program appropriate for that component. Each component may be realized by a program execution unit such as a CPU or processor reading and executing a software program recorded on a recording medium such as a hard disk or semiconductor memory. Here, the software that realizes the threat analysis system of the above embodiments and modifications is a computer program that causes a computer to execute each step of the flowcharts shown in Figures 8 and 9.

[0146] The following cases are also included in this disclosure:

[0147] (1) The at least one system or device is specifically a computer system comprising a microprocessor, ROM, RAM, hard disk unit, display unit, keyboard, mouse, etc. A computer program is stored in the RAM or hard disk unit. The at least one device achieves its function when the microprocessor operates in accordance with the computer program. Here, the computer program is composed of a combination of multiple instruction codes that indicate instructions to the computer to achieve a predetermined function.

[0148] (2) Some or all of the components constituting at least one of the above systems or devices may be configured as a single system LSI (Large Scale Integration). A system LSI is an ultra-multifunctional LSI manufactured by integrating multiple components on a single chip, and specifically, is a computer system configured including a microprocessor, ROM, RAM, etc. A computer program is stored in the RAM. The system LSI achieves its functions when the microprocessor operates in accordance with the computer program.

[0149] (3) Some or all of the components constituting at least one of the above systems or devices may be configured as an IC card or a standalone module that can be attached to or detached from the device. The IC card or module is a computer system composed of a microprocessor, ROM, RAM, etc. The IC card or module may include the above-mentioned ultra-multifunctional LSI. The IC card or module achieves its functions when the microprocessor operates in accordance with a computer program. This IC card or module may be tamper-resistant.

[0150] (4) The present disclosure may be embodied as the methods described above, a computer program for implementing these methods on a computer, or a digital signal comprising the computer program.

[0151] The present disclosure may also be a computer program or a digital signal recorded on a computer-readable recording medium, such as a flexible disk, a hard disk, a CD (Compact Disc)-ROM, a DVD, a DVD-ROM, a DVD-RAM, a BD (Blu-ray (registered trademark) Disc), a semiconductor memory, etc. Alternatively, the present disclosure may be a digital signal recorded on such a recording medium.

[0152] The present disclosure may also be applied to transmitting a computer program or digital signal via a telecommunications line, a wireless or wired communication line, a network such as the Internet, data broadcasting, or the like.

[0153] Furthermore, the program or digital signal may be recorded on a recording medium and transferred, or the program or digital signal may be transferred via a network or the like, so that the program or digital signal may be implemented by another independent computer system. [Industrial Applicability]

[0154] The threat analysis system of the present disclosure can be applied to a device or system that analyzes threats to a system installed in a vehicle, for example. [Explanation of symbols]

[0155] 10, 90 Threat Analysis System 11, 91 Input section 12, 92 Analysis Department 13 Countermeasures Department 14, 94 Output section 20, 80 Threat Memory Department 30 Specific Measures Memory Section 31 Specific Measures Database 50 Analyzed Systems 51 1st device 52 Second device 53 Third device d1 First analysis result information d1a, d1b, d1c, d1n row information d1aa, d1ab, d1ba, d1bb, d1ca, d1cb Analysis result information d2 Second analysis result information d11 System configuration information d12 Functional allocation configuration information d13 Functional layer information d14 Asset information d15 Asset input / output information D10, D71 Design Information d72 Analysis Results Intelligence specific strategy groups f21, f22, f23, f31, f32, f33, f41, f42, f43

Claims

1. A threat analysis system that analyzes security threats to an analysis target system, an input unit for acquiring design information relating to the design of the system to be analyzed; an analysis unit that analyzes threats to the analysis target system based on the design information, and outputs first analysis result information that indicates assets handled by the analysis target system, threats to the assets, and management measures that are countermeasures against the threats; a countermeasure processing unit that generates second analysis result information including the first analysis result information and the specific measures, the specific measures being specific implementations of the management measures indicated in the first analysis result information and corresponding to one or more functional layers included in the system to be analyzed, by combining the first analysis result information with the specific measures; an output unit that outputs the second analysis result information; A threat analysis system comprising:

2. The countermeasure processing unit In combining the above specific measures, referencing a specific measures database that indicates specific measures for each functional layer for each of a plurality of management measures, and identifying from the specific measures database the management measures indicated in the first analysis result information and the specific measures that correspond to each of the one or more functional layers; combining the identified specific measures with the first analysis result information; The threat analysis system according to claim 1 .

3. the design information indicates a functional layer to which each of a plurality of components included in the system to be analyzed belongs; The countermeasure processing unit In combining the above specific measures, Identifying, by referring to the design information, one or more functional layers to which one or more components related to the asset belong, from among the plurality of functional layers indicated in the design information; The threat analysis system according to claim 2 .

4. the design information further indicates input / output flows of the assets in the plurality of components as data flows; The countermeasure processing unit In combining the above specific measures, by referring to the data flow of the design information, identifying one or more components on the data flow among the plurality of components as one or more components related to the asset; The threat analysis system according to claim 3 .

5. The countermeasure processing unit In combining the above specific measures, selecting one component as a processing target component from one or more components on the data flow in reverse order of the data flow; each time the processing target component is selected, a specific measure corresponding to the management measure indicated in the first analysis result information and the functional layer of the processing target component is identified by referring to the specific measure database. The threat analysis system according to claim 4 .

6. The output unit When the second analysis result information is output, outputting, for each component included in the system to be analyzed, one or more specific measures corresponding to a functional layer of the component indicated in the second analysis result information; When there are a plurality of specific measures corresponding to the functional layer of the component indicated in the second analysis result information, and the plurality of specific measures include the same plurality of specific measures, outputting only one specific measure from the same plurality of specific measures as an aggregated specific measure; The threat analysis system according to claim 1 .

7. The output unit When the same plurality of specific measures correspond to a plurality of mutually different assets, outputting information indicating the plurality of mutually different assets in association with the aggregated specific measure; The threat analysis system according to claim 6 .

8. A threat analysis method in which a computer analyzes security threats to an analysis target system, comprising: acquiring design information relating to the design of the system to be analyzed; analyzing threats to the analysis target system based on the design information, and outputting first analysis result information indicating assets handled by the analysis target system, threats to the assets, and management measures that are countermeasures against the threats; generating second analysis result information including the first analysis result information and the specific measures, the specific measures being obtained by concretizing the management measures indicated in the first analysis result information and corresponding to one or more functional layers included in the system to be analyzed, by combining the specific measures with the first analysis result information; outputting the second analysis result information; Threat analysis methods.

9. A program for analyzing security threats to a target system, acquiring design information relating to the design of the system to be analyzed; analyzing threats to the analysis target system based on the design information, and outputting first analysis result information indicating assets handled by the analysis target system, threats to the assets, and management measures that are countermeasures against the threats; generating second analysis result information including the first analysis result information and the specific measures, the specific measures being obtained by concretizing the management measures indicated in the first analysis result information and corresponding to one or more functional layers included in the system to be analyzed, by combining the specific measures with the first analysis result information; outputting the second analysis result information; A program that makes a computer do something.

Citation Information

Patent Citations

  • Threat analysis method, and threat analysis system

    JP2023047569A