Support systems, support methods, and support programs

The support system addresses the challenge of creating security requirements from vague requests by using a reception, extraction, questioning, and generation framework, enabling users to generate detailed requirements with minimal effort through general guidelines and authoritative combinations.

JP2026055121AActive Publication Date: 2026-03-31ATTC CO LTD
View PDF 9 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-09-18
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

Existing technologies struggle to create security requirements based on vague user requests without burdening the user, as they require specialized knowledge and effort.

Method used

A support system comprising a reception unit, extraction unit, questioning unit, and generation unit that assists users in generating security requirements by receiving requests, extracting necessary information, asking questions, and generating requirements based on user inputs and answers, using large language models to minimize user burden.

Benefits of technology

Enables users to create detailed security requirements that meet their needs with minimal effort by utilizing general security guidelines and combining authoritative guidelines, allowing even non-specialists to generate appropriate security requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026055121000001_ABST
    Figure 2026055121000001_ABST
Patent Text Reader

Abstract

To provide a new technology that allows users to create security requirements without burdening them. [Solution] A support system for creating security requirements, The support system comprises a reception unit, an extraction unit, a questioning unit, and a generation unit. The aforementioned reception department receives requests from users regarding security requirements. The extraction unit extracts the necessary information required to generate the security requirements based on the request, The questioning unit will ask questions regarding the necessary information, The generation unit generates security requirements based on the requests and the answers to the questions.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a support system, a support method, and a support program.

Background Art

[0002] Conventionally, there is a technology for supporting the creation of security requirements.

[0003] For example, Patent Document 1 discloses a technology for inputting security standards and security levels and displaying security requirements and countermeasures.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] By the way, recently, there has been an increasing demand to create unique security requirements without burdening the user based on vague requests and the like. However, with the technology of Patent Document 1, while security requirements and the like can be displayed by inputting security standards and the like, it is not possible to create security requirements based on vague requests.

[0006] The present invention has been made in view of the above circumstances, and an object thereof is to provide a new technology for creating security requirements without burdening the user.

Means for Solving the Problems

[0007] [1] A support system for supporting the creation of security requirements, The support system includes a reception unit, an extraction unit, a question unit, and a generation unit. The aforementioned reception department receives requests from users regarding security requirements. The extraction unit extracts the necessary information required to generate the security requirements based on the request, The questioning unit will ask questions regarding the necessary information, The generation unit generates security requirements based on the requests and the answers to the questions. Support system.

[0008] [8] A support method performed by a support system that assists in creating security requirements, The support system comprises a reception unit, an extraction unit, a questioning unit, and a generation unit. The aforementioned reception department receives requests from users regarding security requirements, The extraction unit performs the step of extracting the necessary information required to generate the security requirements based on the request, The questioning unit performs the step of asking questions regarding the necessary information, The generation unit includes the step of generating security requirements based on the requests and the answers to the questions, How to help.

[0009] [9] A support program that assists in creating security requirements, The computer will function as a reception unit, an extraction unit, a questioning unit, and a generation unit. The aforementioned reception department receives requests from users regarding security requirements. The extraction unit extracts the necessary information required to generate the security requirements based on the request, The questioning unit will ask questions regarding the necessary information, The generation unit generates security requirements based on the requests and the answers to the questions. Support program.

[0010] This configuration makes it possible to generate security requirements even from vague requests, allowing users to create security requirements without incurring any burden (time, effort, stress, etc.).

[0011] [2] The support system includes a memory unit, The aforementioned storage unit stores security guidelines, The extraction unit extracts the security guidelines based on the request, The questioning section will ask questions regarding the security guidelines. [1] The support system described above.

[0012] This configuration allows even users without specialized knowledge to generate their own security requirements using general security guidelines, or to generate appropriate security requirements by combining existing authoritative security guidelines.

[0013] [3] The generation unit generates a custom list containing items in a hierarchical structure based on the requests and the answers to the questions, and further generates security requirements based on the custom list and the answers to the questions regarding the items. The support system described in [1] or [2].

[0014] This configuration minimizes the burden on users while generating security requirements that meet their needs.

[0015] [4] The generation unit generates mixed structure information, which has a structure in which items of different granularities are mixed, based on the request and the answers to the questions, and further generates security requirements based on the mixed structure information and the answers to the questions regarding the items. The support system described in [1] or [2].

[0016] By adopting such a configuration, it is possible to generate security requirements that meet the user's needs while minimizing the burden on the user.

[0017] [5] The hierarchical structure includes a plurality of items, The question section asks questions about the items for generating a custom list, When the generation section receives an answer to the question about the item, it generates a custom list including sub-items indicating more detailed requirement information than the item in the hierarchical structure. [3] or the support system according to [4].

[0018] By adopting such a configuration, it is possible to generate detailed security requirements that meet the user's needs while minimizing the burden on the user.

[0019] [6] The support system includes a determination section, The determination section determines that answers regarding all items included in the custom list have been received, [[ID=2I]] The question section generates security requirements based on the determination result. [5] The support system according to [5].

[0020] By adopting such a configuration, it is possible to switch from the mode for receiving the user's needs to the mode for generating security requirements.

[0021] [7] The extraction section, the question section, and the generation section are large language models. [1] to [6] The support system according to any one of [1] to [6].

[0022] By adopting such a configuration, it is possible to accurately extract necessary information, ask questions to the user, and generate security requirements.

Advantages of the Invention

[0023] According to the present invention, it is possible to provide a new technology for creating security requirements without burdening the user. [Brief explanation of the drawing]

[0024] [Figure 1] A block diagram showing the configuration of the support system in this embodiment. [Figure 2] Hardware configuration diagram in this embodiment. [Figure 3] A block diagram showing the functional components in this embodiment. [Figure 4] An example of the data structure stored in the memory unit in this embodiment. [Figure 5] An example of the data structure stored in the memory unit in this embodiment. [Figure 6] An example of the data structure stored in the memory unit in this embodiment. [Figure 7] A schematic diagram of the support system in this embodiment. [Figure 8] A flowchart illustrating the process for creating security requirements in this embodiment. [Figure 9] A diagram illustrating the details of the text recognition process in this embodiment. [Figure 10] A diagram illustrating the details of the text classification process in this embodiment. [Figure 11] A conceptual diagram of the structure in this embodiment where items of different granularities are mixed together. [Figure 12] An example of interaction between a user and a support device via a user terminal in this embodiment. [Figure 13] A diagram illustrating an example of security level calculation in this embodiment. [Modes for carrying out the invention]

[0025] The support system of the present invention will be described below with reference to the drawings. Preferred embodiments are shown in the drawings. However, the present invention can be carried out in many different forms and is not limited to the embodiments described herein.

[0026] For example, in this embodiment, the configuration and operation of the support system will be described, but similar effects can be achieved by the method (steps) of execution, the apparatus, the computer program, etc. The program in this embodiment may be provided as a non-transient recording medium that can be read by a computer, or it may be provided so that it can be downloaded from an external server, or the program may be launched on an external computer in order for the client terminal to perform its functions (so-called cloud computing).

[0027] Furthermore, in this embodiment, "part" may include, for example, hardware resources implemented by a circuit in a broad sense, and information processing of software that can be specifically realized by these hardware resources. In this embodiment, "information" can be represented, for example, by the physical value of a signal value representing voltage or current, the high or low value of a signal value as a set of binary bits composed of 0s or 1s, or by a quantum superposition (so-called qubit), and communication and calculations can be performed on a circuit in a broad sense.

[0028] In a broad sense, a circuit is a circuit realized by appropriately combining circuits, circuits (including processors and memory). Specifically, it includes CPUs (Central Processing Units), GPUs (Graphics Processing Units), LSIs (Large Scale Integration), ASICs (Application Specific Integrated Circuits), FPGAs (Field-Programmable Gate Arrays), SoCs (System on a Chip), and so on.

[0029] <System Overview> Figure 1 is a block diagram showing the configuration of the support system in this embodiment. As shown in Figure 1, the support system 0 comprises a support device 1 and a user terminal 2. The support device 1 is configured to communicate with the user terminal 2 via a network NW. The support device 1 operates as a server, and the user terminal 2 operates as a client terminal.

[0030] Support device 1 receives questions, requests, and answers to questions asked of the user via user terminal 2. Based on the information received via user terminal 2, support device 1 generates security requirements.

[0031] Support device 1 can utilize general-purpose server computers or personal computers. It is also possible to configure support device 1 using multiple computers.

[0032] User Terminal 2 is a terminal used by users who wish to create security requirements to input questions, requests, answers to questions from Support Device 1, etc. User Terminal 2 can be a smartphone, tablet, personal computer, or other terminal device. There may be multiple User Terminals 2.

[0033] In this embodiment, the network NW is an IP (Internet Protocol) network, but there are no restrictions on the type of communication protocol, nor on the type or size of the network.

[0034] <Hardware Configuration> Figure 2 is a hardware configuration diagram. As shown in Figure 2(a), the information processing device 10 (support device 1) has a control unit 101, a storage unit 102, and a communication unit 103, which are used to enable the operation of each unit and each process.

[0035] The control unit 101 includes one or more processors such as a CPU (Central Processing Unit), and controls the entire operation of the information processing device 10 by executing support programs, operating systems, browser software, middleware, and other applications according to the present invention.

[0036] The storage unit 102 is an HDD (Hard Disk Drive), SSD (Solid State Drive), ROM (Read Only Memory), RAM (Random Access Memory), etc., and stores the support program according to the present invention and data used by the control unit 101 when executing processing based on the program. The control unit 101 executes processing based on the support program stored in the storage unit 102, thereby realizing the functional configuration described later.

[0037] The communication unit 103 performs communication control with the network NW and provides inputs necessary for operating the information processing device 10, as well as outputs related to the operation results.

[0038] As shown in Figure 2(b), the terminal device 9 (user terminal 2) has a control unit 91, a storage unit 92, a communication unit 93, an input unit 94, and an output unit 95, which are used to perform the functions of each unit and each process.

[0039] The control unit 91 of the terminal device 9 includes one or more processors such as a CPU and controls the entire operation process of the terminal device 9. The storage unit 92 of the terminal device 9 is an HDD, SSD, ROM, RAM, etc., and stores the above-mentioned application and data used by the control unit 91 when it executes processing based on the program.

[0040] The communication unit 93 of the terminal device 9 controls communication with the network NW. The input unit 94 of the terminal device 9 is a mouse, keyboard, etc., which inputs operation requests from the user / provider to the control unit 91. The output unit 95 of the terminal device 9 is a display, etc., which displays the results of processing by the control unit 91.

[0041] <Functional Components> As shown in Figure 3, the support device 1 comprises a reception unit 11, an extraction unit 12, a question unit 13, a generation unit 14, a determination unit 15, and an update unit 16.

[0042] The arrangement of these functional components is just one example; it is also possible to implement these functional components on multiple computers to constitute the support system 0. For example, some of the functional components of the support device 1 may be arranged on the user terminal 2 and one or more devices configured to communicate with the support device 1.

[0043] Furthermore, some or all of the functional configuration of the support device 1 may be a natural language processing model (NLP). For example, the extraction unit 12, the questioning unit 13, and the generation unit 14 are natural language processing models, preferably large language models (LLM). A natural language processing model enables the processing of data input as natural language by a computer.

[0044] <Data Structure> Figures 4-6 show an example of the data configuration stored in the storage unit in this embodiment. The storage unit of the support device 1 stores security guideline information, item information, requirement information, custom list information, and the like.

[0045] The arrangement of each data is merely an example, and some or all of the data stored in the memory unit of the support device 1 may also be stored in the user terminal 2 and one or more devices configured to communicate with the support device 1.

[0046] Security guideline information refers to information about security guidelines that are already widely distributed and known both domestically and internationally. As shown in Figure 4(a), security guideline information includes the name of the guideline, the year of publication of the guideline, and the data of the guideline, and is managed by a guideline ID for each security guideline.

[0047] By including the publication year of the security guideline information, users can specify the publication year to generate security requirements for their desired combination of guidelines.

[0048] The data for the guidelines may include document files, image files, etc., and there are no restrictions on their format. Furthermore, security guideline information may include the location where the guideline data is stored.

[0049] Furthermore, security guideline information may also include information about the content of the security guidelines. For example, information about the content of the security guidelines may include information about the information assets described in the guidelines, information about the site's purpose, and information about the number of users.

[0050] Item information refers to information about the requirements items described in the security guidelines. As shown in Figure 5(a), item information includes major items, medium items, minor items, etc., and is managed by the guideline ID. Item information is structured with a mix of items of different levels of granularity based on the content of each guideline. Specifically, item information is structured in a hierarchical manner based on the content of each guideline.

[0051] In this embodiment, the structure is represented in three stages (major items, medium items, minor items), but the number of stages is not limited. For example, in Figure 5(a), the major items consist of requirements information such as system architecture and information management, the medium items consist of requirements information such as the formulation of information security policies and access control, and the minor items consist of requirements information such as the setting of access rights and user management.

[0052] A sub-item is a lower-level item in a hierarchical structure that provides more detailed requirements information than a major item, and is a finer-grained item than a major item. For example, as shown in Figure 5(a), the requirements information of a major item (information management) may include multiple requirements information of a sub-item (formulation of information security policy, implementation of risk assessment, access control), and the requirements information of a sub-item (access control) may include multiple requirements information of a minor item (setting of access rights, periodic review of access rights, physical access management). The requirements information belonging to a sub-item is finer-grained requirements information included in the requirements information belonging to a certain major item.

[0053] User information refers to information about users who wish to create security requirements. As shown in Figure 5(b), user information includes the user's name, the name of the company they belong to, the address of the user or their company, contact information, etc., and is managed by a user ID. User information may also include information about the user's job title or the industry of the company they belong to, and this user information may be used to create security requirements.

[0054] Requirement information is a compilation of relevant requirement information for items described in the stored security guidelines. As shown in Figure 5(c), requirement information includes sub-items, minor items, etc., and is managed by requirement information IDs.

[0055] For example, in Figure 5(a), guideline IDs "GL00001" and "GL00003" both include the sub-item requirement information "access control." However, the sub-item requirement information included in the access control of guideline ID "GL00001" and guideline ID "GL00003" is different.

[0056] For example, if different security guidelines stored in the memory unit contain the same sub-item, the sub-items can be grouped together by that sub-item, as shown in Figure 5(c). In this way, if a user requests enhanced access control, security requirements can be created that include items at a lower level than the item contained in the different security guidelines.

[0057] In other words, it is possible to create comprehensive security requirements using multiple related security guidelines. Furthermore, if there is overlap in content between different security guidelines, the same content can be grouped together.

[0058] In addition, the memory unit may also store cloud-type-specific information, which is organized by cloud type. Security requirements differ depending on the cloud type. For example, security guidelines differ for e-commerce (EC), remote access, and internal portals, and furthermore, multiple security guidelines exist for each of these. By organizing these security guidelines by cloud type, when a user requests a specific cloud type, it becomes possible to create comprehensive security requirements using multiple relevant security guidelines.

[0059] Custom list information refers to information about custom lists used to create security requirements, based on user questions, requests, and responses. As shown in Figure 6(a), custom list information includes custom lists of major, medium, and minor categories of security requirements desired by the user, and is managed by a custom list ID. Furthermore, by including a user ID in the custom list information, it is possible to manage which user desires which security requirement.

[0060] <Overview image> Figure 7 is a schematic diagram of the support system in this embodiment. The schematic diagram will be used to explain the process of assisting in the creation of security requirements.

[0061] The user inputs and transmits requests regarding security requirements, questions regarding security requirements, and answers to questions from support device 1 via user terminal 2 (see (A)). Support device 1 stores the information received via user terminal 2 in its storage unit.

[0062] Support device 1 extracts the necessary information to generate security requirements based on the information received via user terminal 2 and generates questions related to that information (see (B)). For example, support device 1 receives a request via user terminal 2 stating, "We want to install a secure cloud for the newly established hospital," extracts medical standard security guidelines, and generates questions such as, "Is it sufficient to comply with the medical standard security guidelines?"

[0063] Support device 1 sends a question to user terminal 2 in order to ask the user a question (see (C)). Support device 1 and the user repeatedly perform the exchanges (processes) (A), (B), and (C) in order to create security requirements.

[0064] Support device 1 repeatedly performs the exchanges (processes) of (A), (B), and (C), and when it determines that it has received all the information necessary to generate security requirements that meet the user's requirements, it generates the security requirements and sends them to the user.

[0065] <Processing flowchart> Figure 8 is a flowchart of the process that supports the generation of security requirements in this embodiment.

[0066] <Request acceptance> In step S801, the reception unit 11 receives requests from the user regarding security requirements. Specifically, the reception unit 11 receives requests from the user via the user terminal 2 for generating security requirements. The requests received from the user may include questions.

[0067] For example, the reception desk 11 receives requests from users that include information about the implementation location, such as "We want to install a secure cloud for our newly built hospital" or "We want to introduce a secure cloud to our factory." In addition, the reception desk 11 receives requests that include information about the system's purpose, usage, and scale. Furthermore, the reception desk 11 receives questions from users such as "Please tell me your recommended security requirements."

[0068] The reception unit 11 accepts both requests that are purely requests for generating security requirements, and questions regarding security requirements, etc. The reception unit 11 may accept each type of request alternately, or it may accept both types of requests intermittently.

[0069] <Extracting necessary information> In step S802, the extraction unit 12 extracts the necessary information required to generate security requirements based on the request. The extraction unit 12 determines whether the content received from the user is a question or a request (not a question).

[0070] The extraction unit 12 extracts keywords from information such as text received from the user, compares the extracted keywords with information pre-stored in the memory unit, and determines whether the content received from the user is a question or a request. Furthermore, the extraction unit 12 may also generate synonymous words derived from the extracted keywords and determine whether the content received from the user is a question or a request. Alternatively, the extraction unit 12 may be a pre-trained machine learning model that takes the information received from the user as input and determines whether the content received from the user is a question or a request.

[0071] If the content received from the user is a question, the extraction unit 12 generates an answer to that question. If the content received from the user is a request, the extraction unit 12 extracts the necessary information required to generate security requirements.

[0072] For example, if the reception unit 11 receives a request from a user stating, "We want to install a secure cloud for a newly established hospital," the extraction unit 12 will extract medical-related security guidelines as security guidelines necessary to generate security requirements.

[0073] Figure 9(a) is a diagram illustrating the details of the text recognition process in this embodiment. The user inputs a request, including a question, via the user terminal 2. The memory unit stores keywords such as "I want to know" as a keyword to determine if it is a question, and keywords such as "I want this included" or "This is a request" as keywords to determine if it is a request.

[0074] In step S901, the extraction unit 12 determines whether the user input is a question or a request based on the keywords stored in the memory unit. In step S902, if the extraction unit 12 determines that the user input is a question, it processes to understand the content of the question and generate an answer. In step S903, if the extraction unit 12 determines that the user input is a request, it processes to extract security guidelines for converting it into security requirements (such as asking the user a question).

[0075] Figure 10(a) is a diagram illustrating the details of the text classification process in this embodiment (step S901 in Figure 9(a)). In step S1011, the extraction unit 12 performs morphological analysis on the received content (text, etc.).

[0076] In step S1012, the extraction unit 12 determines whether the judgment in step S1013 has been made for all of the analyzed morphemes. If the judgment has been made for all of the morphemes, it determines that the received content is a (normal) request and not a question, outputs "This is a request" as the judgment result 2, and analyzes the content of the request.

[0077] In step S1013, in order to determine whether the received content is a question, the extraction unit 12 determines whether the analyzed morpheme corresponds to the base form of a question-related verb such as "teach". If the extraction unit 12 determines that it corresponds to the verb, it proceeds to processing S1014.

[0078] In step S1014, the extraction unit 12 determines whether the morpheme following the base form of the verb related to the question it has determined corresponds to the "volitional / conjectural form (form expressing volition or conjecture)". If the received content is a question, the morpheme following the verb is the "volitional / conjectural form", so the extraction unit 12 makes this determination. If the extraction unit 12 determines that the morpheme following the verb corresponds to the "volitional / conjectural form", it may output "This (received content) is a question" as determination result 1.

[0079] Multiple verbs are possible in relation to a question, and furthermore, the appropriate "volitional / conjectural form" for a question consisting of that verb differs depending on the verb. The memory unit stores a certain number of question sentences (for example, 10 different sentences) for each verb, consisting of multiple verbs for asking questions (for example, to teach, to instruct, to ask, etc.), with the sentence ending in the "volitional / conjectural form" (the appropriate particle according to the verb). The extraction unit 12 determines whether the received content is a question based on the sentences stored in the memory unit.

[0080] Furthermore, the memory unit may store a certain number of request sentences (for example, 10 different sentences) for each verb, each consisting of multiple verbs for making (ordinary) requests (for example, to request, to consider, etc.) and ending with an appropriate particle, and the extraction unit 12 may determine whether the received content is a request based on the sentences stored in the memory unit.

[0081] As the memory unit stores the text, the extraction unit 12 determines whether it is a request or not in a two-step process, based on the presence or absence of the basic form of the verb contained in the text stored by the memory unit and the suffixes following that verb (appropriate particles, etc., for determining whether it is a request or a question). This configuration makes it possible to determine whether the content received from the user regarding security requirements is a question or a request.

[0082] As shown in Figures 4(a) and 5(a), by storing multiple security guidelines and their items in the storage unit, the extraction unit 12 can extract security guidelines that meet the user's requirements. The extraction unit 12 extracts security guidelines using information such as the names, items, and content of the security guidelines stored in the storage unit.

[0083] If the reception unit 11 is unable to extract any security guidelines based on user requests or other information, the extraction unit 12 extracts the necessary information required to extract the security guidelines. For example, the extraction unit 12 extracts information such as the purpose of the site or system, who will use it, information assets, the number of users, and operating hours as necessary information.

[0084] The extraction unit 12 extracts security guidelines that will serve as the basis for generating a custom list, based on user requests regarding security requirements, questions regarding security requirements, and answers to questions from the questioning unit 13.

[0085] <Conducting questions> In step S803, the questioning unit 13 asks questions regarding the necessary information. Specifically, the questioning unit 13 generates questions regarding the necessary information extracted by the extraction unit 12. For example, the questioning unit 13 sends the generated questions to the user terminal 2 to ask the user questions.

[0086] Question Unit 13 asks questions regarding security guidelines. Specifically, based on the security guidelines extracted by Extraction Unit 12, Question Unit 13 generates questions to determine the base security guidelines for creating security requirements, such as "Is it sufficient to comply with the medical standard security guidelines?"

[0087] In addition, if the extraction unit 12 is unable to extract any security guidelines, the questioning unit 13 generates questions to identify candidate base security guidelines, such as questions about the purpose of the site or system, who will use the site or system, questions about the information assets that the site or system should protect, the scale of the number of people using the site or system, and the operating hours of the site or system.

[0088] Furthermore, the questioning unit 13 asks questions to generate a custom list. The custom list includes the security guideline items extracted by the extraction unit 12, and is a list in which the items have been modified to suit the user's requests, based on user requests and other factors.

[0089] Specifically, question unit 13 asks questions about the items used to generate the custom list. For example, question unit 13 might ask, "Are there any items you would like to strengthen?" or, based on the items included in the security guidelines extracted by extraction unit 12, "Is access control an item that needs strengthening?"

[0090] Enhancement items are the security requirements that the user wants to strengthen, specifically the items for which the user wants to generate fine-grained security requirements. For example, if a user specifies a medium-level requirement as an enhancement item, security requirements will be generated that include the requirement information of sub-items related to that requirement information.

[0091] Furthermore, the questioning unit 13 asks questions to determine the items to be included in the security guidelines extracted by the extraction unit 12. For example, if the extraction unit 12 extracts the guideline ID "GL00001" as the base for generating a custom list, it will ask questions about the size of the medical institution where the system will be implemented in order to determine the sub-items (more detailed) below the major item "System Implementation Type by Scale".

[0092] Questioning unit 13 asks questions about the items included in the custom list. Specifically, questioning unit 13 asks questions about all items included in the custom list generated by generation unit 14. For example, questioning unit 13 asks questions about the requirement information of all items included in the custom list to confirm whether or not they can be adopted into security requirements.

[0093] <Reception of responses> In step S804, the reception unit 11 receives the user's response to the question asked by the questioning unit 13.

[0094] <Generating a custom list> In step S805, the generation unit 14 generates a custom list containing hierarchical items based on the requests received by the reception unit 11 and the answers to the questions. As shown in Figure 5(a), by storing the contents described in the guidelines in the storage unit in advance as a hierarchical structure, the generation unit 14 can generate a custom list like the one shown in Figure 6(a) which contains hierarchical items.

[0095] The generation unit 14 generates a custom list based on the security guidelines extracted by the extraction unit 12 based on the requests received by the reception unit 11. Furthermore, the generation unit 14 generates a custom list based on the answers to the questions asked by the questioning unit 13.

[0096] For example, if the reception unit 11 receives "access control" as an enhancement item, the generation unit 14 generates a custom list that makes the granularity of the received item finer. Specifically, the generation unit 14 generates a custom list by obtaining sub-items that are lower (more detailed) than access control from security guidelines other than the security guidelines extracted by the extraction unit 12.

[0097] The generation unit 14 may also generate a custom list using security guidelines other than the one used as the base. For example, if the generation unit 14 generates a custom list on "access control" based on the guidelines of an international organization, the extraction unit 12 will also extract guidelines from other organizations that contain information on "access control".

[0098] Because the content described in each guideline may differ, the generation unit 14 can generate a more detailed custom list by using multiple guidelines extracted by the extraction unit 12. Specifically, the generation unit 14 generates a guideline using all the descriptions of the received item "access control" described in multiple guidelines.

[0099] On the other hand, if all entries are used, there is a possibility of duplication of content. Therefore, the generation unit 14 checks the keywords contained in each entry and deletes one if there is duplication. In addition, the generation unit 14 may also determine whether the content does not overlap with the base security guideline and generate a custom list by adding non-duplicate content from other guidelines.

[0100] As shown in Figure 5(a), by storing items from different security guidelines in a hierarchical structure in the storage unit beforehand, the generation unit 14 can generate a custom list with fine granularity for specific items.

[0101] When the generation unit 14 receives a response to a question about an item, it generates a custom list that includes sub-items in a hierarchical structure that are more detailed (finer in granularity) than the item in question. When the generation unit 14 receives requirement information as a response to a question about an item, it generates a custom list that includes sub-items in a hierarchical structure that show requirement information more detailed than the item in question. When the generation unit 14 receives a response about requirement information, it generates a custom list that includes requirement information of a finer granularity (lower level) that is related to (linked to) that requirement information.

[0102] In addition, when the generation unit 14 receives a response regarding the nth item (requirements information), it generates a custom list that includes the n+1th item (requirements information), which is a more detailed item of the nth item (n=1, 2, ...). In this embodiment, n is 3, with the first item being a major item, the second item a medium item, and the third item a minor item. When the reception unit 11 receives a medium item as an enhancement item, the generation unit 14 generates a custom list that includes the minor items, which are more detailed items of the medium item.

[0103] Furthermore, if the base security guideline extracted by the extraction unit 12 does not contain the content received as an enhancement item, the generation unit 14 will extract the relevant item from another security guideline, add that item, and generate a custom list. In this case, the generation unit 14 may also extract from security guidelines related to the base security guideline extracted by the extraction unit 12.

[0104] Figure 11 is an illustrative diagram of the structure in this embodiment in which items of different granularities are mixed. Based on the requests and the answers to the questions, the generation unit 14 may generate mixed structure information in which items of different granularities are mixed, as shown in Figure 11, which is not a hierarchical structure.

[0105] Mixed structure information is information in which items of different granularities are mixed together, but it lacks information about higher-level items to which certain items are linked (information about which sub-items a small item is linked to, information about which major items a sub-item is linked to, etc.), as shown in Figure 11.

[0106] In Figure 11, W111 represents a minor item, W112 a medium item, and W113 a major item. The granularity of each item can be determined by the size of the circle, but the information of the medium item W112 to which minor item W111 is linked is not included. Mixed structure information only needs to include information about the item and information to determine what level of granularity that item is (e.g., major item, medium item, minor item).

[0107] Figure 12 shows an example of interaction between the user and the support device via a user terminal in this embodiment. In step S1201, the user inputs a request via the user terminal 2. In step S1202, the reception unit 11 receives input from the user, the extraction unit 12 extracts security guidelines, and the questioning unit 13 generates a question.

[0108] In step S1203, the user inputs their answer to the question via the user terminal 2. In step S1204, the reception unit 11 receives the input from the user, and the generation unit 14 generates a custom list based on the received answer.

[0109] In step S1205, the question unit 13 generates questions based on the generated custom list. In step S1206, the user inputs answers to the questions via the user terminal 2. In step S1207, the reception unit 11 receives input from the user, and the generation unit 14 generates a custom list based on the received answers. In step S1208, the user inputs questions via the user terminal 2.

[0110] In this way, by interacting with the support device 1 via the user terminal 2 (inputting requests, answering questions, etc.), users can generate their own security requirements using general security guidelines or generate appropriate security requirements by combining existing authoritative security guidelines.

[0111] <Quantifying Security Levels> The generation unit 14 may also calculate the security level of the generated custom list as a numerical value based on the generated custom list. Specifically, the storage unit stores numerical values ​​associated with keywords, the generation unit 14 identifies the keyword from the generated custom list, and calculates the security level of the custom list as a numerical value using the numerical value associated with the identified keyword. For example, the generation unit 14 calculates the security level of the custom list by adding the numerical values ​​associated with the keyword.

[0112] Furthermore, the generation unit 14 may calculate the relative security level of the generated custom list based on the average security level of the custom list. By calculating the relative security level, the user can confirm that the generated custom list has a security level higher than the average, and can then determine when to stop adding items.

[0113] In addition, the generation unit 14 may also calculate and present a numerical value indicating how much the security level will improve if a certain item is added. By showing how much the security level will improve, the user can decide whether or not to add that item.

[0114] Figure 13 is a diagram illustrating an example of security level calculation in this embodiment. Figure 13(a) is an example of calculating security levels for security requirements in the same field (e.g., multi-factor authentication). In step S1301, the generation unit 14 performs morphological analysis on the wording (or sentences) of the security requirements.

[0115] In step S1302, the generation unit 14 determines whether the determination in step S1304 has been made for all of the analyzed morphemes. If the determination has been made for all morphemes, it determines that the subsequent "multi-factor authentication" is not "mandatory" and outputs "security level 4".

[0116] In step S1303, the generation unit 14 determines whether the analyzed morpheme corresponds to "multi-factor authentication". If the generation unit 14 determines that it corresponds to "multi-factor authentication", it proceeds to the process in S1304. In step S1304, the generation unit 14 determines whether the word following "multi-factor authentication" is "required". If the generation unit 14 determines that it is "required", it outputs "security level 5".

[0117] The memory unit stores a security level associated with a keyword in a certain field (e.g., multi-factor authentication) and the word that follows that keyword (e.g., required, desirable). The generation unit 14 determines the security level by performing a two-stage determination of the keyword and the word that follows it.

[0118] For example, in the calculation shown in Figure 13(a), the memory unit may associate and store security level 4 if the subsequent word is "desirable," and the generation unit 14 may output "security level 3" if the subsequent word is anything other than "mandatory" or "desirable." If the subsequent word is one that would encourage the inclusion of that keyword in security requirements, it is conceivable to set the security level to be higher.

[0119] Figure 13(b) shows an example of calculating the security level in security requirements according to the set keywords. In step S1311, the generation unit 14 performs morphological analysis on the wording of the security requirements.

[0120] In step S1312, the generation unit 14 determines whether the determination in step S1313 has been made for all of the analyzed morphemes. If the determination has been made for all morphemes, it determines that none of the morphemes are any of the keywords set for the determination in step S1313 and outputs "Security Level 1 or 2".

[0121] The memory unit stores a security level associated with each keyword (e.g., multi-factor authentication, one-time password, password, etc.), and the generation unit 14 determines whether a security requirement includes that keyword and calculates the corresponding security level. It is conceivable to set a higher security level for keywords that provide stronger security. Alternatively, security levels may be set to conform to the security level standards of domestic and international companies and organizations.

[0122] <Calculation of security risk value> The generation unit 14 may calculate a security risk value instead of a security level. For example, if the security risk value is set to 100 in advance, the generation unit 14 may calculate (reduce) the security risk value based on the keyword and the words that follow it if the security requirement contains a specific keyword.

[0123] The memory unit stores multiple keywords and a subtraction value for each keyword, and further stores the words following the keywords and a weight for each word. The generation unit 14 determines whether the security requirement includes the keywords and the following words, and calculates a security risk value based on the determination result, the subtraction value, and the weight.

[0124] Specifically, the security risk value for a smartphone without anti-spoofing measures is set to 100. The keyword for security requirements is "implementing multi-factor authentication," and its reduction value is set to 80%. Furthermore, the keyword is "implementing fingerprint authentication," and its reduction value is set to 90%. Then, the following word is "required," and its weight is set to 1.0, and the following word is "desirable," and its weight is set to 0.5.

[0125] For example, if a smartphone requires multi-factor authentication, the generation unit 14 calculates a security risk value of 100 - 80 × 1.0 = 20. If a smartphone requires multi-factor authentication, the generation unit 14 calculates a security risk value of 100 - 80 × 0.5 = 60. Additionally, if a smartphone requires fingerprint authentication, the generation unit 14 calculates a security risk value of 100 - 90 × 1.0 = 10.

[0126] One approach is to assign higher deduction values ​​to keywords that enhance security. Furthermore, it's possible to assign greater weight to subsequent words that encourage the inclusion of those keywords in security requirements. In this way, it becomes possible to calculate the security risk value when a specific phrase is missing from the security requirements.

[0127] In addition, the generation unit 14 may calculate the magnitude of the security risk (security risk value) for each of the three elements before the generation of security requirements (countermeasures) based on the importance (degree of security risk) of the security risks stored in the memory unit and coefficients linked to the three elements of security (confidentiality, availability, and integrity), and may further calculate how much the security risk value for each of the three elements will decrease as a result of the generated security requirements (countermeasures).

[0128] In this way, it becomes possible to appropriately define the magnitude of security risks related to the three elements of security before countermeasures are implemented, using appropriately configurable importance levels or coefficients.

[0129] Specifically, the memory unit stores one or more pieces of information associated with each of the three elements (for example, important information that would be problematic if leaked) with a pre-assigned importance level. The generation unit 14 then calculates the security risk value before countermeasures (security requirement generation) based on that importance level and the coefficient associated with each piece of information. Furthermore, the generation unit 14 calculates the security risk value after countermeasures (security requirement generation) based on one or more aspects of the threat side (for example, an attacker targeting important information) (for example, an attack method).

[0130] For example, consider calculating the security risk values ​​for confidentiality, availability, and integrity of information assets within a smartphone. If the memory unit stores bank account information, personal information of business partners, and contact email addresses as information assets with confidentiality risks within a smartphone, and further stores importance levels of 3, 3, and 2 for each, the generation unit 14 multiplies the sum of importance levels (3 + 3 + 2 = 8) by a predetermined coefficient (for example, 10) to calculate a security risk value of 80 before countermeasures are implemented.

[0131] From the perspective of confidentiality on the threat side, impersonation and eavesdropping are possible, and the generation unit 14 calculates the importance of each after countermeasures based on the generated security requirements, and further calculates the security risk value of confidentiality after countermeasures for each perspective based on the calculated importance.

[0132] The memory unit stores keywords and importance levels of security requirements related to the three elements, allowing the generation unit 14 to calculate the importance level of each element after the countermeasures are implemented. The memory unit stores the importance level associated with a given keyword when it is included in the security requirements. The generation unit 14 may also calculate a reduced security risk value based on the calculated security risk values ​​before and after the countermeasures.

[0133] If, due to certain anti-spoofing measures (security requirements), the importance level of bank account information, business partner personal information, and contact email addresses is reduced to 1, the generation unit 14 calculates a security risk value of 1 (importance) × 3 (quantity) × 10 (coefficient) = 30. Also, if, due to certain anti-eavesdropping measures (security requirements), the importance level of bank account information, business partner personal information, and contact email addresses is reduced to 2, the generation unit 14 calculates a security risk value of 2 (importance) × 3 (quantity) × 10 (coefficient) = 60.

[0134] Furthermore, the generation unit 14 may display messages regarding suggestions or evaluations of the generated security requirements based on the calculated security risk values ​​for each perspective (for example, "further consideration is needed regarding theft prevention," "equivalent measures have been taken," etc.).

[0135] In addition, the generation unit 14 may calculate a security risk value for confidentiality based on the numerical value of importance that decreases due to the security requirements for each perspective. If the security requirements decrease the security risk value for impersonation by 50, and the security risk value for eavesdropping by 30, the generation unit 14 may calculate 80 (security risk value for confidentiality before countermeasures) - 50 - 30 = 0 as the security risk value for confidentiality after countermeasures.

[0136] The memory unit may store information assets related to the availability risk within a smartphone, such as business applications (priority level 3), calendar information (priority level 2), and network connection information (priority level 1). Furthermore, it may also store information assets related to the integrity risk within a smartphone, such as company-specific data within business applications (priority level 3), company-specific schedule information (priority level 3), and contact information for company executives (priority level 3). In this way, even on the same smartphone, the memory unit may associate different information with each of the three elements, and further associate different levels of importance with each of those pieces of information.

[0137] From the perspective of the threat's view of availability, this could include system destruction and ransomware, while from the perspective of the threat's view of integrity, this could include data tampering and unauthorized access. Thus, the perspectives on each of the three elements from the threat's viewpoint can differ.

[0138] The generation unit 14 calculates security risk values ​​for availability and integrity, similar to confidentiality. Furthermore, the coefficients associated with each of the three elements may be different. For example, when prioritizing confidentiality in the evaluation, the confidentiality coefficient is set higher than the availability and integrity coefficients.

[0139] <Determination of whether the response has been received> In step S806, the determination unit 15 determines that it has received responses for all items included in the custom list. For example, if information indicating that a response has been received from the user is linked to the custom list information in Figure 6(a), the determination unit 15 makes a determination based on whether or not that information is linked.

[0140] If the determination unit 15 determines that it has not received answers for any of the items, it proceeds to step S803 to ask questions about the items for which it has not received answers.

[0141] If the determination unit 15 determines that it has received answers for all items, it will ask the user if it is okay to end the request acceptance process. For example, the determination unit 15 will send a message to the user terminal 2 to confirm that it is okay to end the request acceptance process. If the determination unit 15 receives a signal from the user indicating that it is okay to end the request acceptance process, it will end the request acceptance mode and proceed to step S807 (security requirement generation mode) for generating security requirements.

[0142] Figure 9(b) is a diagram illustrating the details of the text recognition process in this embodiment. The determination unit 15 confirms with the user whether it is OK to end the request acceptance process, and the user inputs a response to this confirmation via the user terminal. The storage unit stores, for example, "end" as a keyword for determining the end of the request acceptance mode, and "no" or "continue" as keywords for determining the continuation of the request acceptance mode.

[0143] In step S904, the determination unit 15 determines, based on the keyword stored in the memory unit, whether the user's input indicates the end of the request acceptance mode or the continuation of the request acceptance mode. For example, if the user's input includes the keyword "end" immediately after a message is sent to the user to confirm the end of request acceptance, the determination unit 15 determines that the request acceptance mode has ended.

[0144] Figure 10(b) is a diagram illustrating the details of the text classification process in this embodiment (step S904 in Figure 9(b)). In step S1041, the determination unit 15 performs morphological analysis on the received content (text, etc.).

[0145] In step S1042, the determination unit 15 determines whether the determination in step S1043 has been made for all of the analyzed morphemes. If the determination has been made for all morphemes, it determines that the received content is to continue the request acceptance mode and outputs "Request acceptance mode to continue" as determination result 4, and continues the request acceptance mode.

[0146] In step S1043, in order to determine whether the received content relates to the termination of the request reception mode, the determination unit 15 determines whether the analyzed morpheme corresponds to the base form of a verb related to the termination of a request (termination of the request reception mode), such as "to convey" (for example, "I conveyed everything," "I conveyed what I wanted to convey," etc.). If the determination unit 15 determines that it corresponds to such a verb, it proceeds to the process in S1044.

[0147] In step S1044, the determination unit 15 determines whether the morpheme following the base form of the verb related to the termination of the determined request acceptance mode is in the "terminal form (the form that normally ends a sentence) or general form". If the received content is related to the termination of the request acceptance mode, the morpheme following the verb is in the "terminal form or general form", so the determination unit 15 makes this determination. If the determination unit 15 determines that the morpheme following the verb is in the "terminal form or general form", it may output "Request acceptance mode has ended" as determination result 1.

[0148] Multiple verbs are possible that relate to the termination of the request reception mode, and furthermore, the appropriate "terminal form / general form" for terminating the request reception mode using these verbs differs depending on the verb. The memory unit stores a certain number of sentences (for example, 10 types of sentences) for terminating the request reception mode, each consisting of multiple verbs for terminating the request reception mode (for example, to convey, to complete, to terminate, etc.), with the sentence ending in the "terminal form / general form" (the appropriate particle depending on the verb). The determination unit 15 determines, based on the sentences stored in the memory unit, whether the received content relates to the termination of the request reception mode.

[0149] As the memory unit stores the text, the determination unit 15 determines whether the content is related to the termination of the request acceptance mode by performing a two-stage determination based on the presence or absence of the basic form of the verb contained in the text stored by the memory unit and the suffix following that verb (appropriate particles, etc., for determining the content related to the termination of the request acceptance mode). This configuration makes it possible to determine whether the content received from the user regarding security requirements is related to the termination of the request acceptance mode.

[0150] <Security Requirements Generation> In step S807, the generation unit 14 generates security requirements based on the request received by the reception unit 11 and the answers to the questions asked by the questioning unit 13. Specifically, the generation unit 14 generates security requirements based on the items included in the security guidelines extracted by the extraction unit 12 and the answers to the questions related to those items.

[0151] The generation unit 14 generates security requirements based on the determination result of the determination unit 15. Specifically, the generation unit 14 generates a list of security requirements on the user terminal 2 based on the generated custom list. The generation unit 14 displays the list of security requirements on the user terminal 2 based on the custom list. In addition, the generation unit 14 may also generate a list of security requirements based on the generated mixed structure information.

[0152] Furthermore, the generation unit 14 may also display the publication year of the security guideline used. By doing so, users can identify the security guideline described in each security requirement and gain a clearer understanding of the content of the security requirements.

[0153] <Security Guidelines Update> The update unit 16 automatically updates the security guidelines as needed. Since the security guidelines are updated periodically, the update unit 16 regularly checks for updates to the guidelines.

[0154] Furthermore, the update unit 16 may update the information stored in the memory unit using the updated security guidelines. For example, the update unit 16 may extract items from the content of the security guidelines. Furthermore, the update unit 16 may generate information categorized by requirements information, etc., based on the extracted information.

[0155] As described above, the configuration of the present invention provides a new technology for creating security requirements without burdening the user. [Explanation of Symbols]

[0156] 0 Support System 1 Support equipment 11 Reception Department 12 Extraction part 13 Question Section 14 Generation part 15 Judgment section 16 Update section 2 User terminals NW Network

Claims

1. A support system for creating security requirements, The support system comprises a reception unit, an extraction unit, a questioning unit, and a generation unit. The aforementioned reception department receives requests from users regarding security requirements. The extraction unit extracts the necessary information required to generate the security requirements based on the request, The questioning unit will ask questions regarding the necessary information, The generation unit generates security requirements based on the requests and the answers to the questions. Support system.

2. The aforementioned support system includes a memory unit, The aforementioned storage unit stores security guidelines, The extraction unit extracts the security guidelines based on the request, The questioning section will ask questions regarding the security guidelines. The support system according to claim 1.

3. The generation unit generates a custom list containing items in a hierarchical structure based on the request and the answers to the questions, and further generates security requirements based on the custom list and the answers to the questions regarding those items. The support system according to claim 1 or 2.

4. The generation unit generates mixed structure information, which has a structure in which items of different granularities are mixed, based on the request and the answers to the questions, and further generates security requirements based on the mixed structure information and the answers to the questions regarding the items. The support system according to claim 1 or 2.

5. The aforementioned hierarchical structure includes multiple items, The aforementioned question section asks questions regarding the items for generating a custom list. When the generation unit receives an answer to a question regarding the item, it generates a custom list that includes sub-items in the hierarchical structure that show more detailed requirement information than the item in question. The support system according to claim 3.

6. The support system includes a determination unit, The determination unit determines that it has received responses for all items included in the custom list, The generation unit generates security requirements based on the determination result. The support system according to claim 5.

7. The extraction unit, the questioning unit, and the generation unit are a large-scale language model. The support system according to claim 6.

8. A support method performed by a support system that assists in creating security requirements, The support system comprises a reception unit, an extraction unit, a questioning unit, and a generation unit. The aforementioned reception department receives requests from users regarding security requirements, The extraction unit performs the step of extracting the necessary information required to generate the security requirements based on the request, The questioning unit performs the step of asking questions regarding the necessary information, The generation unit includes the step of generating security requirements based on the requests and the answers to the questions, How to help.

9. A support program that assists in creating security requirements, The computer will function as a reception unit, an extraction unit, a questioning unit, and a generation unit. The aforementioned reception department receives requests from users regarding security requirements. The extraction unit extracts the necessary information required to generate the security requirements based on the request, The questioning unit will ask questions regarding the necessary information, The generation unit generates security requirements based on the requests and the answers to the questions. Support program.

Citation Information

Patent Citations

  • Security policy structuring device, question maintenance device, policy maintenance device and document maintenance device

    JP2005004679A

  • Information security management program, device and method

    JP2005135239A

  • Information protection method, information security management device, information security management system and information security management program

    JP2006023916A

  • Electronic unit

    JP2006135239A

  • Text generation device and text generation method

    JP7325152B1