Analysis support system and analysis support method

The analysis support system automates the generation of analysis results using stored generation rules, addressing increased man-hours and trial and error in complex system analysis, ensuring efficient and flexible analysis.

JP2026049568APending Publication Date: 2026-03-18HITACHI LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-09-06
Publication Date
2026-03-18

AI Technical Summary

Technical Problem

The analysis of complex systems, such as computer systems, is hindered by increased man-hours and periods due to changes in configuration or requirements, necessitating repeated analyses and impacting subsequent steps in a waterfall model, leading to trial and error.

Method used

An analysis support system that stores generation rules for each process in a waterfall model, allowing automatic generation of results using previous process data, facilitating sequential and robust analysis.

Benefits of technology

Facilitates trial and error in analysis, automating processes to handle changes flexibly and efficiently, reducing man-hours and enhancing customer satisfaction.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026049568000001_ABST
    Figure 2026049568000001_ABST
Patent Text Reader

Abstract

It facilitates trial and error in analysis. [Solution] For each of the waterfall-type processes that constitute the analysis process, generation rule data representing the generation rule for generating process result data representing the result of that process is stored. For each of the multiple processes, the generation rule corresponding to that process specifies how to process the data included in the process result data of the preceding process. The analysis support system executes the processes in order, and in the execution of each process, it acquires the generation rule data corresponding to that process and the process result data of the preceding process, and generates process result data as the process result for that process using the process result data acquired for the preceding process according to the generation rule represented by the acquired generation rule data, and stores the generated process result data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention generally relates to data processing technology for analysis support.

Background Art

[0002] As a technology related to analysis support, for example, the technology disclosed in Patent Document 1 is known. Patent Document 1 discloses a threat analysis support system that can support the analysis of threats in information security.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] With the complication of a system to be analyzed (for example, a computer system implemented for a customer) as an analysis target, the analysis man-hours and period tend to increase. Particularly in cases corresponding to at least one of the following, the man-hours for countermeasures may soar, squeezing the process and potentially lowering customer satisfaction. · During the analysis, there is a change in the configuration or analysis requirements due to a request from the customer. · It is necessary to re-analyze at the timing of changes during operation after system release (for example, specification changes or function updates). · The project has continuity, and it is necessary to utilize past analysis results. · Since the analysis target is continuously updated in DevOps, it is necessary to perform repeated analysis.

[0005] The security analysis process follows a waterfall model, where the output of the previous step is the input for the next step. Therefore, even minor changes in the initial steps can significantly impact the results of later steps. This makes trial and error in analysis difficult.

[0006] Such problems can occur not only in security analysis, but also in other types of analysis where the results of the previous step are used as input for the next step, such as vulnerability analysis. [Means for solving the problem]

[0007] For each of the multiple waterfall-type processes that make up the analysis process, generation rule data representing the generation rules for generating process result data that represents the results of that process is stored. For each of the multiple processes, the generation rule corresponding to that process specifies how to process the data contained in the process result data of the preceding process. The analysis support system executes the processes in order, and in the execution of each process, it acquires the generation rule data corresponding to that process and the process result data of the preceding process, and according to the generation rule represented by the acquired generation rule data, it uses the process result data acquired for the preceding process to generate process result data as the process result for that process, and stores the generated process result data. [Effects of the Invention]

[0008] According to the present invention, trial and error in analysis can be facilitated. [Brief explanation of the drawing]

[0009] [Figure 1] This is a schematic diagram of the security analysis flow according to the embodiment. [Figure 2] This is a diagram showing the overall system configuration, including the analysis support system according to the embodiment. [Figure 3] This is a flowchart of the security analysis process. [Figure 4] This figure shows an example of a definition of the object of analysis. [Figure 5] It is a diagram showing an example of the first generation rule. [Figure 6] It is a configuration diagram of a list of module functions. [Figure 7] It is a diagram showing an example of the second generation rule. [Figure 8] It is a configuration diagram of a list of threat scenarios. [Figure 9] It is a diagram showing an example of the third generation rule. [Figure 10] It is a configuration diagram of a list of damage scenarios. [Figure 11] It is a diagram showing an example of the fourth generation rule. [Figure 12] It is a configuration diagram of a list of threat-risks. [Figure 13] It is a diagram showing an example of the fifth generation rule. [Figure 14] It is a configuration diagram of a list of grouped threats. [Figure 15] It is a diagram showing an example of the sixth generation rule. [Figure 16] It is a configuration diagram of a list of threat-FTs. [Figure 17] It is a diagram showing an example of the seventh generation rule. [Figure 18] It is a configuration diagram of a list of countermeasure policies. [Figure 19] It is a diagram showing an example of the eighth generation rule. [Figure 20] It is a configuration diagram of a list of security function requirements. [Figure 21] It is a schematic diagram of visualization and update. [Figure 22] It is a flowchart of the process flow of the analysis process after update.

Modes for Carrying Out the Invention

[0010] In the following description, the "interface device" may be one or more interface devices. The one or more interface devices may be at least one of the following. An I / O interface device is one or more I / O (Input / Output) interface devices. An I / O (Input / Output) interface device is an interface device to at least one of the following: an I / O device and a remote display computer. The I / O interface device to the display computer may be a communication interface device. The at least one I / O device may be either a user interface device, such as an input device like a keyboard and a pointing device, or an output device like a display device. A communication interface device which is one or more communication interface devices. One or more communication interface devices may be one or more identical communication interface devices (for example, one or more NICs (Network Interface Cards)) or two or more different communication interface devices (for example, a NIC and an HBA (Host Bus Adapter)).

[0011] Furthermore, in the following explanation, "memory" refers to one or more memory devices, which are examples of one or more storage devices, and may typically be main memory devices. At least one memory device in memory may be a volatile memory device or a non-volatile memory device.

[0012] Furthermore, in the following explanation, "persistent storage device" may refer to one or more persistent storage devices, which are examples of one or more storage devices. Persistent storage devices are typically non-volatile storage devices (e.g., auxiliary storage devices), and specifically may be, for example, HDDs (Hard Disk Drives), SSDs (Solid State Drives), NVME (Non-Volatile Memory Express) drives, or SCMs (Storage Class Memory).

[0013] Furthermore, in the following explanation, "storage device" may refer to at least memory, including both memory and persistent storage.

[0014] Furthermore, in the following explanation, "processor" may refer to one or more processor devices. At least one processor device may typically be a microprocessor device such as a CPU (Central Processing Unit), but may also be other types of processor devices such as a GPU (Graphics Processing Unit). At least one processor device may be single-core or multi-core. At least one processor device may be a processor core. At least one processor device may be a broad-sense processor device such as a circuit that is a collection of gate arrays according to a hardware description language that performs some or all of the processing (e.g., FPGA (Field-Programmable Gate Array), CPLD (Complex Programmable Logic Device), or ASIC (Application Specific Integrated Circuit)).

[0015] Furthermore, in the following explanation, functions may be described using the expression "yyy section," but a function may be realized by the execution of one or more computer programs by a processor, by one or more hardware circuits (e.g., FPGA or ASIC), or by a combination thereof. When a function is realized by the execution of a program by a processor, the defined processing is carried out using memory and / or interface devices as appropriate, so the function may be at least a part of the processor. Processing described with a function as the subject may be processing performed by the processor or a device having that processor. Programs may be installed from program source. Program source may be, for example, a program distribution computer or a storage medium that the computer can read (e.g., a non-temporary storage medium). The description of each function is an example, and multiple functions may be combined into one function, or one function may be divided into multiple functions.

[0016] Furthermore, in the following explanation, when describing similar elements without distinction, a common reference code will be used, and when describing similar elements with distinction, a reference code will be used.

[0017] The following describes one embodiment of the present invention.

[0018] Figure 1 is a schematic diagram of the security analysis flow according to the embodiment.

[0019] Regarding security analysis, the process, consisting of multiple steps S1 to S8, follows a waterfall model. In other words, the result (output) of the previous step becomes the input for the next step.

[0020] Each process is associated with a generation rule 101 that enables the automatic generation of results in the current process (the next process for the previous process) using the results of the previous process as input. The generation rule 101 is data that represents the generation rule for the automatic generation of results. In each process, according to the generation rule 101 associated with that process, the process result 102 of the previous process is used as input data to generate the process result 102 of that process. For each process, the process result 102 is data that represents the result of that process.

[0021] As shown in Figure 1, there are eight processes S1 to S8, and therefore there are first to eighth generation rules 101A to 101H, and process results 102A to 102H for the first to eighth processes. In the first process S1, the data to be analyzed 100 is the input data. The data to be analyzed 100 represents the data to be analyzed. The data to be analyzed 100, processes S1 to S8, the first to eighth generation rules 101A to 101H, and the process results 102A to 102H for the first to eighth processes will be described in detail later.

[0022] Note that the generation rules 101A to 101H may be physically distinct data or logically distinct data (for example, eight generation rules may be described in one file). Similarly, the process results 102A to 102H may be physically distinct data or logically distinct data (for example, eight process results may be described in one file).

[0023] Furthermore, at least a portion of generation rules 101A to 101H may be logic data generated by the generation AI.

[0024] Figure 2 is a diagram showing the overall system configuration, including the analysis support system according to the embodiment.

[0025] A user terminal 240 is connected to the analysis support system 200 via, for example, a communication network 270. For example, the user terminal 240 may be an input / output console (e.g., a client device) of the analysis support system 200.

[0026] External systems 250 other than the user terminal 240 may be connected to the analysis support system 200 via, for example, a communication network 270. The external system 250 may be a system that serves as a source of some input data for at least one of the multiple processes S1 to S8 performed by the analysis support system 200, or it may be a system that uses at least some of the process results 102 of at least one of the multiple processes S1 to S8 as input data and processes them.

[0027] In this embodiment, the analysis support system 200 is a physical computer system (one or more physical computers) and includes an interface device 201, a storage device 202, and a processor 203 connected thereto. The analysis support system 200 may also be a logical computer system based on a physical computer system (for example, a virtual machine or a cloud computing system).

[0028] Communication with the user terminal 240 is performed through the interface device 201.

[0029] The storage device 202 stores data and programs. The data stored includes the generation rule DB221 and the process result DB222. The generation rule DB221 is a database where generation rules 101A to 101H are stored. The process result DB222 is a database where process results 102A to 102H are stored.

[0030] The processor 203 executes a program stored in the memory device 202, thereby realizing functions such as the input unit 231, the calculation unit 232, and the output unit 233. For each of the processes S1 to S8, each function performs the following processing: The input unit 231 obtains the process result 102 of the previous process from the process result DB 222 and obtains the generation rule 101 associated with the process from the generation rule DB 221. The calculation unit 232 performs calculations in the process using the obtained generation rule 101 and the process result 102 of the previous process. The output unit 233 stores the process result 102 as a result of the calculation in the process result DB 222.

[0031] Figure 3 is a flowchart of the security analysis process.

[0032] First, an initial input S0 is performed. In the initial input S0, the input unit 231 receives the input of the analysis target 100 from the user terminal 240 (or other data source), and the output unit 233 stores the analysis target 100 in the process result DB 222. In the analysis target 100, the analysis target is represented according to predetermined rules. For example, as shown in Figure 4, in the analysis target 100, the protection range is defined by a rectangle, modules (ECU1 to ECU4) are defined by double circles, communication connections are defined by lines between modules and lines from outside the protection range to modules, and entry points (interfaces to ECU1 and ECU2) are defined by circles. In addition, the analysis target 100 includes data representing one or more protected assets for each module (for example, data representing the asset name or type of the protected asset). Types of protected assets include "data" and "function". With such definitions, the protection range, entry points, modules, and protected assets can be identified from the analysis target 100.

[0033] Next, the first process S1 is performed. In the first process S1, the input unit 231 obtains the first generation rule 101A associated with the first process S1 from the generation rule DB 221 and obtains the analysis target 100 (the process result of the previous process for the first process S1) in the initial input S0 from the process result DB 222. The calculation unit 232 generates the module function list 102A, which is the first process result 102A, using the analysis target 100 according to the first generation rule 101A. The output unit 233 stores the module function list 102A in the process result DB 222.

[0034] Specifically, for example, the first generation rule 101A is as shown in Figure 5. The first generation rule 101A may be a rule relating to the definition of CIA, namely, a rule relating to the definitions of Confidentiality, Integrity, and Availability, and may include, for example, a rule for estimating the protection perspective for each type of protected asset and a rule for estimating the type of protected asset from the asset name of the protected asset. According to the first generation rule 101A, when the type of protected asset of a module is identified from the analysis target 100, the calculation unit 232 estimates the protection perspective corresponding to that type from the estimation rule for the protection perspective corresponding to that type, and determines the estimated protection perspective as the protection perspective of that protected asset. Furthermore, according to the first generation rule 101A, if the asset name of a module's protected asset is identified from the analysis target 100, the calculation unit 232 estimates the type of protected asset from that asset name (for example, if the asset name ends with "data", it estimates the type to be "data"), estimates the protection perspective corresponding to the estimated type from the estimation rule for the protection perspective corresponding to that type, and determines the estimated protection perspective as the protection perspective for that protected asset. As a result of such calculations, a module function list 102A illustrated in Figure 6 is generated, that is, for each module, data representing the module name 601, the protected asset name 602, and the protection perspective 603 is generated.

[0035] Following the first process S1, the second process S2 is performed. In the second process S2, the input unit 231 obtains the second generation rule 101B associated with the second process S2 from the generation rule DB 221, and obtains the module function list 102A (the process result 102A of the process preceding the second process S2) and the analysis target 100 from the process result DB 222. The calculation unit 232 generates the threat scenario list 102B, which is the second process result 102B, using the module function list 102A and the analysis target 100 according to the second generation rule 101B. The output unit 233 stores the threat scenario list 102B in the process result DB 222.

[0036] Specifically, for example, the second generation rule 101B is as shown in Figure 7. According to the second generation rule 101B, a threat scenario is generated for each protected asset according to the 5Ws (Who, Where, When, Why, and What). The second generation rule 101B also specifies one or more possible scenario components (scenario components as constituent elements of a threat scenario) for each of the 5Ws. The calculation unit 232 generates multiple threat scenarios for each protected asset identified from the module function list 102A according to the second generation rule 101B, using all possible combinations of the 5W scenario components. As a result of such calculations, the threat scenario list 102B exemplified in Figure 8 is generated, that is, for each protected asset, data representing the protected asset 801, the 5Ws 802-806, and the generated threat scenario 807 is generated. The second generation rule 101B specifies, for each protected asset, scenario components that may or may not be possible for each protection perspective when that protection perspective is associated with that protected asset, and the generation of threat scenarios for that protected asset may be performed based on the protection perspective associated with that protected asset and the second generation rule 101B.

[0037] Following the first process S1, the third process S3 is performed. The third process S3 may be performed before or after the second process S2, or it may be performed in parallel with the second process S2. In the third process S3, the input unit 231 obtains the third generation rule 101C associated with the third process S3 from the generation rule DB 221, and obtains the module function list 102A (the process result 102A of the process preceding the third process S3) from the process result DB 222. The calculation unit 232 generates the damage scenario list 102C, which is the third process result 102C, using the module function list 102A according to the third generation rule 101C. The output unit 233 stores the damage scenario list 102C in the process result DB 222.

[0038] Specifically, for example, the third generation rule 101C is as shown in Figure 9. The third generation rule 101C may be a rule relating to the automatic generation of damage scenario templates and candidates. According to the third generation rule 101C, for each protected asset, a damage scenario generation perspective and a damage scenario template for each generation perspective are defined. The calculation unit 232 generates damage scenarios for each damage scenario generation perspective for each protected asset identified from the module function list 102A, in accordance with the third generation rule 101C. As a result of such calculations, data is generated representing the damage scenario list 102C exemplified in Figure 10, that is, for each protected asset, protected asset 1001 (damage incurred on the protected asset) and generation perspectives 1002 to 1005 for that damage (i.e., the impact of the damage for each generation perspective). Furthermore, the third generation rule 101C specifies, for each protected asset, damage scenarios that may or may not occur when that protection perspective is associated with that protected asset, and the generation of damage scenarios for each generation perspective of that protected asset may be performed based on the protection perspective corresponding to that protected asset and the third generation rule 101C.

[0039] Following the second process S2 and the third process S3, the fourth process S4 is performed. In the fourth process S4, the input unit 231 obtains the fourth generation rule 101D associated with the fourth process S4 from the generation rule DB 221, and obtains the threat scenario list 102B (process result 102B of the process preceding the fourth process S4) and the damage scenario list 102C (process result 102C of the process preceding the fourth process S4) from the process result DB 222. The calculation unit 232 generates the threat-risk list 102D, which is the fourth process result 102D, using the threat scenario list 102B and the damage scenario list 102C according to the fourth generation rule 101D. The output unit 233 stores the threat-risk list 102D in the process result DB 222.

[0040] Specifically, for example, the fourth generation rule 101D is as shown in Figure 11. According to the fourth generation rule 101D, a method for calculating scores using damage scenarios and threat scenarios is defined. For example, a method for calculating the score for impact on assets may be defined using one or more scenario components (e.g., words) in a damage scenario as variables. Also, a method for calculating the score for ease of attack may be defined using one or more scenario components (e.g., words) in a threat scenario as variables. Furthermore, a method for calculating the score for risk may be defined using the score for impact on assets and the score for ease of attack as variables. The calculation unit 232 calculates the score for impact on assets, the score for ease of attack, and the score for risk for each protected asset, according to the fourth generation rule 101D, using the threat scenario identified from the threat scenario list 102B and the damage scenario identified from the damage scenario list 102C. As a result of these calculations, data is generated, as illustrated in Figure 12, in the Threat-Risk List 102D, which represents, for each protected asset, a Threat Scenario 1201 (identified threat scenario), an Impact on Assets 1202 (a score calculated for the impact on assets), an Ease of Attack 1203 (a score calculated for the ease of attack), and a Risk 1204 (a score calculated for the risk). For each of the pieces of information 1201 to 1204, the score can be on a 5-point scale (maximum value "5", minimum value "1"), where a higher value indicates a more negative situation, and a lower value indicates a more positive situation.

[0041] Following the fourth process S4, the fifth process S5 is performed. In the fifth process S5, the input unit 231 obtains the fifth generation rule 101E associated with the fifth process S5 from the generation rule DB 221 and obtains the threat-risk list 102D (the process result 102D of the process preceding the fifth process S5) from the process result DB 222. The calculation unit 232 generates the grouped threat list 102E, which is the fifth process result 102E, using the threat-risk list 102D according to the fifth generation rule 101E. The output unit 233 stores the grouped threat list 102E in the process result DB 222.

[0042] Specifically, for example, the fifth generation rule 101E is as shown in Figure 13. According to the fifth generation rule 101E, rules are defined for classifying threat scenarios into groups. For example, each group may be associated with conditions related to aspects such as the 5Ws, protection aspects, asset impact score, attack ease score, and risk score. The calculation unit 232 classifies the threat scenarios identified from the threat-risk list 102D according to the fifth generation rule 101E into one of several groups (for example, the group to which the threat scenario meets the most conditions). As a result of such calculations, data representing threat scenario 1401 and group 1402 is generated for each threat scenario, as illustrated in Figure 14. In addition, depending on the conditions associated with a group in the fifth generation rule 101E, there may be conditions that cannot be identified from the explicit statements in the threat-risk list 102D. Such conditions may be identified by estimation from the threat-risk list 102D or by referring to the process result 102 generated in a process prior to the fourth process S4. Furthermore, the fifth generation rule 101E may include a rule for merging multiple threat scenarios classified in the same group into a single threat scenario. According to this rule, multiple threat scenarios classified in the same group may be treated as a single threat scenario, and in subsequent processes, this single threat scenario may be used for each group.

[0043] Following the fifth process S5, the sixth process S6 is performed. In the sixth process S6, the input unit 231 obtains the sixth generation rule 101F associated with the sixth process S6 from the generation rule DB 221 and obtains the grouping threat list 102E (the process result 102E of the process preceding the sixth process S6) from the process result DB 222. The calculation unit 232 generates the threat-FT list 102F, which is the sixth process result 102F, using the grouping threat list 102E according to the sixth generation rule 101F. The output unit 233 stores the threat-FT list 102F in the process result DB 222.

[0044] Specifically, for example, the sixth generation rule 101F is as shown in Figure 15. The sixth generation rule 101F defines rules (e.g., FT templates) for expanding threat scenarios (groups) into a Fault Tree (FT), such as the relationship between scenario components in a threat scenario and nodes in the FT. Nodes that become elements of the FT may represent some kind of threat, such as an attack or failure. The sixth generation rule 101F may define rules regarding the feasibility of an attack (e.g., the relationship with scenario components in a threat scenario) for each node that can become an element of the FT. The calculation unit 232 expands the FT from the threat scenarios (groups) identified from the grouped threat list 102E according to the sixth generation rule 101F and determines the feasibility of an attack for each node in the FT. As a result of such calculations, data is generated representing the threat-FT list 102F exemplified in Figure 16, that is, for each threat scenario (group), the threat scenario 1601, the FT 1602, and the feasibility of an attack for each node in the FT 1603.

[0045] Following the sixth process S6, the seventh process S7 is performed. In the seventh process S7, the input unit 231 obtains the seventh generation rule 101G associated with the seventh process S7 from the generation rule DB 221 and obtains the threat-FT list 102F (the process result 102F of the process preceding the seventh process S7) from the process result DB 222. The calculation unit 232 generates the countermeasure policy list 102G, which is the seventh process result 102G, using the threat-FT list 102F according to the seventh generation rule 101G. The output unit 233 stores the countermeasure policy list 102G in the process result DB 222.

[0046] Specifically, for example, the seventh generation rule 101G is as shown in Figure 17. The seventh generation rule 101G specifies rules (e.g., countermeasures template) for determining possible countermeasures against each threat (attack, etc.) that can be a component of the FT of a threat scenario (group). Countermeasures may be specified for both attack feasibility and attack feasibility. The calculation unit 232 determines a countermeasure for each node in the FT of the threat scenario (group) identified from the threat-FT list 102F, according to the seventh generation rule 101G, based, for example, on whether the attack corresponding to that node is feasible or not. As a result of such calculations, data is generated representing the countermeasures list 102G exemplified in Figure 18, that is, for each threat scenario (group), the threat scenario 1801, FT 1802, and the countermeasures 1803 for each node in the FT.

[0047] Finally, the eighth step S8 is performed. In the eighth step S8, the input unit 231 obtains the eighth generation rule 101H associated with the eighth step S8 from the generation rule DB 221 and obtains the countermeasure policy list 102G (the process result 102G of the step preceding the eighth step S8) from the process result DB 222. The calculation unit 232 generates the security function requirements list 102H, which is the eighth process result 102H, using the countermeasure policy list 102G according to the eighth generation rule 101H. The output unit 233 stores the security function requirements list 102H in the process result DB 222.

[0048] Specifically, for example, the eighth generation rule 101H is as shown in Figure 19. The eighth generation rule 101H specifies rules for determining security function requirements corresponding to the countermeasures for each threat (attack, etc.) that can be a component of the FT of a threat scenario (group). The calculation unit 232 determines the security function requirements (for example, the security functions necessary to realize the countermeasures) for each node in the FT of the threat scenario (group) identified from the countermeasures list 102G, based on the countermeasures corresponding to that node, in accordance with the eighth generation rule 101H. As a result of such calculations, data is generated representing the security function requirements list 102H exemplified in Figure 20, that is, for each threat scenario (group), the threat scenario 2001, the FT 2002, the countermeasures 2003 for each node in the FT, and the security function requirements 2004.

[0049] The above describes the security analysis process. In this process, for at least one generation rule 101, at least a portion of the process result 102 generated according to that generation rule 101 may be generated using a generation AI (for example, a text generation AI that uses a language model such as Large Language Models).

[0050] This embodiment facilitates trial and error in analysis. Specifically, security analysis can be performed automatically in a sequential manner according to pre-set rules, thereby realizing robust analysis support that is resistant to changes in conditions, etc. Furthermore, for at least one process (for example, each process), process result data may be output to the user terminal 240 by the output unit 233, that is, the process results may be visualized. In addition, the generation rules may be updated as appropriate. This enables trial and error and flexible application.

[0051] Although one embodiment has been described above, this is merely an example for the purpose of explaining the present invention, and is not intended to limit the scope of the present invention to this embodiment alone. The present invention can be carried out in various other forms.

[0052] The embodiments described above can be summarized as follows. The summary below may include supplementary explanations and descriptions of variations to the above description.

[0053] The analysis support system (e.g., analysis support system 200) comprises a storage device (e.g., storage device 202) and a processor (e.g., processor 203) connected to the storage device. The storage device stores generation rule data representing generation rules for generating process result data that represents the results of each of the waterfall-type processes that constitute the analysis process.

[0054] For each of the multiple processes, the generation rule corresponding to that process specifies how to process the data included in the process result data of the preceding process. For example, for each process, a processing method (e.g., regression equation) is specified where the data instance (e.g., value) of a data item (e.g., column) included in the process result data of the preceding process is used as a variable (e.g., explanatory variable), and by performing calculations according to that processing method, data instances (e.g., dependent variable) for the data items required in the process result data of that process are obtained.

[0055] The processor executes each process according to the sequence of multiple processes (i.e., the sequence of processes in a waterfall model), and in the execution of each process, it performs the following (x). (x) The system retrieves the generation rule data corresponding to the process and the process result data of the preceding process from the storage device, generates process result data as the process result for the process in question using the process result data obtained for the preceding process according to the generation rule represented by the retrieved generation rule data, and stores the generated process result data in the storage device.

[0056] In this way, the analysis process is automated, making it easier to experiment with different approaches to analysis.

[0057] The analysis support system may further include an interface device (e.g., interface device 201) connected to an information processing device (e.g., user terminal 240). The processor may output process result data for at least one of the multiple processes to the information processing device through the interface device. For example, as illustrated in Figure 21, the process results may be visualized by the analysis support system through the information processing device. Visualization of process results can contribute to appropriate updates of generation rules by the user. For example, the process result 102 of at least one of the first to eighth processes (S1 to S8) in the above embodiment may be output to the user terminal 240 by the output unit 233, and the process result represented by the process result 102 may be displayed on the display of the user terminal 240.

[0058] The processor may receive data representing the object to be analyzed (e.g., object 100) from the information processing device via an interface device and store the data in a storage device. In the execution of the first step, the processor identifies elements (e.g., modules) from the data to be analyzed that meet the conditions specified in the generation rule data corresponding to the first step (e.g., conditions representing modules), processes the data identified from the data to be analyzed for the identified elements (e.g., protected assets) according to the generation rule (e.g., determining the protection perspective for the protected assets), generates process result data for the first step, and stores the process result data in a storage device. In this way, the first step can generate process result data for the object to be analyzed for the next step.

[0059] As illustrated in Figure 21, the processor may receive updates from the information processing device via an interface device for one or more processes, including updates to the process itself, the process result data for that process, or the generation rule data corresponding to the process. A process in which the process itself, the process result data, or the generation rule data has been updated can be called an "updated process." If there is one or more updated processes, the processor may identify the earliest updated process among the one or more updated processes (S2201), as illustrated in Figure 22, and perform (x) above for the identified earliest updated process and each subsequent process (S2202). As a result, even if one or more updated processes, including processes that have already been performed, occur during or after the analysis process, the earliest updated process among those one or more updated processes and the subsequent processes will be performed in the order of the processes, making trial and error in the analysis easier.

[0060] The analysis process may be either a security analysis or a vulnerability analysis. For security analysis, multiple steps may be included, but at least one of the steps 1 through 8 below may be included. For example, step 3, which concerns damage scenarios, and step 5, which concerns threat scenario grouping, may be omitted. For vulnerability analysis, by replacing "threat" in security analysis with "vulnerability" and adapting at least one of the steps 1 through 8 below to suit vulnerability analysis, it is possible to automate vulnerability analysis in addition to security analysis. The first step is to generate first step result data for one or more protected assets for each module of the analysis target represented by the analysis target data, in accordance with the first generation rule data corresponding to the first step. The second step is to generate second step result data representing threat scenarios related to threats to protected assets, using the first step result data and following second generation rule data corresponding to the second step. The third step is to generate third step result data representing damage scenarios related to damage to protected assets, using the first step result data and following the third generation rule data corresponding to the third step. The fourth step is to generate fourth step result data representing a score for each of one or more perspectives, using at least the second step result data of the second and third step result data, in accordance with the fourth generation rule data corresponding to the fourth step. The fifth step is to generate fifth step result data representing a group of threat scenarios, using the fourth step result data, in accordance with the fifth step generation rule data corresponding to the fifth step. The sixth step is to generate sixth step result data regarding the Fault Tree (FT) of a threat scenario, using the fifth step result data, in accordance with the sixth step generation rule data corresponding to the sixth step. The seventh step is to generate the seventh step result data regarding countermeasures for each element of the FT of the threat scenario, using the sixth step result data and according to the seventh step generation rule data corresponding to the seventh step. The eighth step is to generate the eighth step result data for each element of the FT of the threat scenario, using the seventh step result data, in accordance with the eighth step generation rule data corresponding to the eighth step. [Explanation of Symbols]

[0061] 101: Generation rules, 102: Process results, 200: Analysis support system

Claims

1. Memory device and A processor connected to the aforementioned storage device and Equipped with, The storage device stores generation rule data representing generation rules for generating process result data representing the results of each of the waterfall-type processes that constitute the analysis process. For each of the aforementioned steps, the generation rule corresponding to that step specifies how to process the data included in the process result data of the step preceding that step. The processor performs each step in the order of the plurality of steps, and in the performance of each step, it performs (x) below: (x) Obtain generation rule data corresponding to the process and process result data of the preceding process from the storage device, generate process result data as the process result for the process using the process result data obtained for the preceding process according to the generation rule represented by the obtained generation rule data, and store the generated process result data in the storage device. Analysis support system.

2. Interface device connected to information processing device, Furthermore, The processor outputs process result data for at least one of the plurality of processes to the information processing device through the interface device. The analysis support system according to claim 1.

3. Interface device connected to information processing device, Furthermore, The processor receives data representing the object to be analyzed from the information processing device through the interface device, and stores the data to be analyzed in the storage device. In the execution of the first step, the processor identifies elements from the data to be analyzed that meet the conditions specified in the generation rule data corresponding to the first step, processes the data identified from the data to be analyzed for the identified elements according to the generation rule, generates process result data for the first step, and stores the process result data in the storage device. The analysis support system according to claim 1.

4. Interface device connected to information processing device, Furthermore, The processor receives updates from the information processing device, through the interface device, for one or more processes, including the process itself, the process result data for that process, or the generation rule data corresponding to the process. If there is one or more update processes, each of which is a process in which process result data or generation rule data has been updated, the processor identifies the earliest update process among the one or more update processes, and performs (x) for the identified earliest update process and each subsequent process. The analysis support system according to claim 1.

5. The aforementioned analysis process is a security analysis or vulnerability analysis process. The analysis support system according to claim 1.

6. For each of the multiple waterfall-type processes that constitute the analysis process, generation rule data representing the generation rules for generating process result data that represents the results of that process is stored in a storage device. For each of the aforementioned steps, the generation rule corresponding to that step specifies how to process the data included in the process result data of the step preceding that step. Perform the following (x) for each step in the order of the process: (x) Obtain generation rule data corresponding to the process and process result data of the preceding process from the storage device, generate process result data as the process result for the process using the process result data obtained for the preceding process according to the generation rule represented by the obtained generation rule data, and store the generated process result data in the storage device. A computer-assisted analysis method for performing this task.

Citation Information

Patent Citations

  • Threat analysis support device, and threat analysis support program

    JP2022101716A