Information processing device, information processing program, and information processing method

The information processing device quantitatively evaluates cyberattack difficulty by analyzing objective information about attack reproduction problems, addressing the subjective nature of conventional assessments and enhancing the reliability of security risk evaluations.

JP2026065367APending Publication Date: 2026-04-15MITSUBISHI ELECTRIC CORP +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
MITSUBISHI ELECTRIC CORP
Filing Date
2024-10-03
Publication Date
2026-04-15

AI Technical Summary

Technical Problem

Conventional security risk assessments subjectively evaluate attack difficulty based on personal experience, leading to qualitative assessments rather than quantitative evaluations.

Method used

An information processing device that collects and analyzes objective information about cyberattacks, including attack reproduction problems and their solutions, to quantify the difficulty of cyberattacks using a collection unit, result acquisition unit, attack name acquisition unit, and difficulty evaluation unit.

Benefits of technology

Provides a technology for quantitatively evaluating attack difficulty based on objective information, improving the accuracy and reliability of security risk assessments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026065367000001_ABST
    Figure 2026065367000001_ABST
Patent Text Reader

Abstract

This technology provides a quantitative evaluation of attack difficulty based on objective information. [Solution] The quantification device 100 includes a collection unit 101 that collects a plurality of related information 115 including an attack reproduction problem that can be solved by reproducing a cyberattack, the result of solving the attack reproduction problem, and an attack name corresponding to the attack reproduction problem; a result acquisition unit 103 that acquires a pair of results 116 from the plurality of related information 115, including the result of solving the attack reproduction problem and the attack name corresponding to the attack reproduction problem; an attack name acquisition unit 105 that acquires an attack name for which the difficulty of the cyberattack should be evaluated; and a difficulty evaluation unit 107 that refers to the acquired attack name and the attack name included in the result information 116, extracts a plurality of results corresponding to the acquired attack name from the result information 116, and evaluates the difficulty of the cyberattack for the acquired attack name using the extracted plurality of results.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0004] , , , , , ,

[0003] , , ,

[0001] The present disclosure relates to an information processing apparatus, an information processing program, and an information processing method for quantifying the difficulty level of cyberattacks.

Background Art

[0002] In order to ensure the security of products and services, it is emphasized that security risk assessment should be performed during the design of products and services. Security risk assessment assigns priorities to countermeasures against security threats that a system has, and takes countermeasures against threats with high priorities. This priority is called a risk value. The higher the priority, the larger the risk value. Among the elements for deriving the risk value, the technical ability required by an attacker to carry out a certain attack needs to be evaluated as the attack difficulty level. In Non-Patent Document 1, the risk value is derived from the value of the importance of an asset and the value of "likelihood of occurrence of a threat × likelihood of acceptance of a threat". When determining the likelihood of occurrence of a threat, the attack difficulty level is one of the elements.

Prior Art Documents

Non-Patent Documents

[0003]

Non-Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] In conventional technologies, risk assessors make subjective judgments about the difficulty of each attack based on their own experience. Therefore, a problem exists in that the assessment of attack difficulty is merely qualitative. For example, in the technology described in Non-Patent Document 1, the difficulty of an attack is determined subjectively by the risk assessor using a three-level evaluation based on their own experience.

[0005] This disclosure aims to provide a technology for quantitatively evaluating attack difficulty based on objective information. [Means for solving the problem]

[0006] The information processing device disclosed herein is A collection unit that collects multiple pieces of related information, including an attack reproduction problem which is a problem that can be solved by reproducing a cyberattack, the result of solving the attack reproduction problem, and the name of the attack corresponding to the attack reproduction problem. A result acquisition unit obtains, as result information, a set containing at least the result of solving the attack reproduction problem and the attack name corresponding to the attack reproduction problem, from the aforementioned multiple pieces of related information. An attack name acquisition unit that acquires the attack name for which the difficulty of the aforementioned cyberattack should be evaluated, A difficulty evaluation unit that, by referring to the acquired attack name and the attack name included in the result information, extracts a plurality of results corresponding to the acquired attack name from the result information, and uses the extracted plurality of results to evaluate the difficulty of the cyber attack against the acquired attack name, It is equipped with. [Effects of the Invention]

[0007] This disclosure provides a technology for quantitatively evaluating attack difficulty based on objective information. [Brief explanation of the drawing]

[0008] [Figure 1] Figure 1 of Embodiment 1 shows a block diagram of the quantification device 100. [Figure 2]The diagram of Embodiment 1 shows a flowchart of the operation of the quantification device 100. [Figure 3] This figure shows an image of how related information 115 is stored in related information DB 102 in Embodiment 1. [Figure 4] A diagram of Embodiment 1 showing an example of related information 115. [Figure 5] The diagram of Embodiment 1 shows an image of how result information 116 is stored in the result DB 104. [Figure 6] This figure shows the result information 116 stored in the result DB 104, according to Embodiment 1. [Figure 7] The diagram in Embodiment 1 shows an image of how the attack name INi is stored in the attack name DB106. [Figure 8] The diagram of Embodiment 1 shows an image of how the result information 116 and the attack name INi are input to the difficulty evaluation unit 107. [Figure 9] Figure 2 shows a block diagram of the quantification device 100. [Figure 10] Figure 2 of Embodiment shows a flowchart of the operation of the quantification device 100. [Figure 11] This figure shows the operation of the quality evaluation unit 109 in Embodiment 2. [Figure 12] The figure for Embodiment 2 shows an example of the result DB104, which reflects the quality evaluation results. [Figure 13] Figure 3 of Embodiment 3 shows a block diagram of the quantification device 100. [Figure 14] Figure 3 of the third embodiment shows a flowchart of the operation of the quantification device 100. [Figure 15] The diagram in Embodiment 3 shows the generation of the mapping DB112. [Figure 16] Figure 4 of the embodiment shows a block diagram of the quantification device 100. [Figure 17] Figure 4 of the embodiment shows a flowchart of the quantification device 100. [Figure 18] Figure 5 of the embodiment shows the hardware configuration diagram of the quantification device 100. [Figure 19]Another hardware configuration diagram of the quantification device 100 in the figure of Embodiment 5.

Embodiments for Carrying Out the Invention

[0009] Hereinafter, embodiments will be described with reference to the drawings. The following embodiments are merely examples, and various modifications are possible within the scope of the present invention. In the description of the embodiments and the drawings, the same elements and corresponding elements are denoted by the same reference numerals. The description of the elements denoted by the same reference numerals will be omitted or simplified as appropriate. In the following embodiments, "part" may be appropriately read as "circuit", "circuitry", "step", "procedure", or "process".

[0010] In the following description, DB indicates a database. In the following description, an attack refers to a cyber attack. The quantification device 100 described in the following embodiments is an information processing device. The information processing device is a computer.

[0011] Embodiment 1. ***Description of Configuration*** The quantification device 100 of Embodiment 1 will be described with reference to FIGS. 1 to 8. FIG. 1 is a block diagram of an attack difficulty quantification device 100 (hereinafter, quantification device) that quantifies the difficulty of an attack. The quantification device 100 includes a collection unit 101, a related information DB 102, a result acquisition unit 103, a result DB 104, an attack name acquisition unit 105, an attack name DB 106, a difficulty evaluation unit 107, and an output unit 108.

[0012] (1) The collection unit 101 collects related information 115 related to the attack reproduction problem. (2) The related information DB 102 stores the related information 115 collected by the collection unit 101. (3) The result acquisition unit 103 acquires the result of solving the attack reproduction problem. (4) The result DB 104 stores the "result of solving the attack reproduction problem" acquired by the result acquisition unit 103. (5) The attack name acquisition unit 105 acquires the attack name for which the attack difficulty is to be determined. (6) The attack name DB 106 stores the attack names obtained by the attack name acquisition unit 105. (7) The difficulty level evaluation unit 107 evaluates the difficulty level of the attack based on the attack name and the results of solving the "attack reproduction problem corresponding to the attack name". (8) The output unit 108 outputs the attack difficulty level evaluated by the difficulty evaluation unit 107.

[0013] ***Explanation of operation*** Figure 2 is a flowchart showing the operation of the quantification device 100. The operation of the quantification device 100 will be explained below.

[0014] The operation of the quantification device 100 corresponds to the quantification method. Furthermore, the operation of the quantification device 100 corresponds to the processing of the quantification program 100P. These are the same in Embodiments 1 to 4. Note that the quantification method is an information processing method, and the quantification program is an information processing program.

[0015] <Step S201> In step S201, the collection unit 101 collects information 115 related to the attack reproduction problem. The collection unit 101 collects related information 115. The related information 115 includes multiple pieces of information, including an attack reproduction problem Qi, which is a problem that can be solved by reproducing a cyberattack; the result Ri of solving the attack reproduction problem; and the attack name Ni, which corresponds to the attack reproduction problem Qi. In the related information 115 described below, the result Ri of multiple related information 115 is the result of multiple people solving the attack reproduction problem. I will explain in detail below.

[0016] An attack reproduction problem is "a problem that can be solved by reproducing a certain attack." Related information 115 includes both "attack reproduction problems" and "information related to attack reproduction problems," such as "the results of solving the attack reproduction problem."

[0017] The information related to the attack reproduction problem collected by the collection unit 101, 115, is stored in the related information DB 102. Figure 3 shows an image of how multiple pieces of related information 115 are stored in the related information DB 102 via the collection unit 101. For example, to obtain related information 115 for an attack reproduction problem, the risk assessment implementer 200 prepares the attack reproduction problem and related information. The risk assessment implementer 200 inputs this information into the information collection unit 101 as related information 115. The collection unit 101 stores the related information 115 in the related information DB 102. Alternatively, as shown in Figure 1, the collection unit 101 may acquire CTF (Capture The Flag) data publicly available on Web 302 via the Internet 301 as attack reproduction problems and related information 115. Alternatively, the risk assessment implementer 200 may acquire the CTF data and input it into the collection unit 101.

[0018] Figure 4 shows a specific example of related information 115 stored in related information DB 102. Each row in Figure 4 represents related information 115. As shown in Figure 4, related information 115 includes, for example, the attack reproduction problem Qi, the result of solving the attack reproduction problem Ri (for example, the accuracy rate of solving the attack reproduction problem), the name of the attack corresponding to the attack reproduction problem Ni, and the number of people who solved the attack reproduction problem Pi. In the attack reproduction problem Q1, the solution yielded R1 (ans_1 to ans_k), the corresponding attack name N1 was SQL injection, and the number of people who solved it was P1=k. In the attack reproduction problem Q2, the solution yielded R2 (ans_k+1 to ans_n), the corresponding attack name N2 was SQL injection, and the number of people who solved it was P2=(nk). In the attack reproduction problem Q3, the result of solving it is R3, the corresponding attack name N3 is N3=XSS ((Cross-site scripting)), and the number of people who solved it is P3. Furthermore, at least "Ri, the result of solving the attack reproduction problem" and "Ni, the attack name" are obtained as result information 116 in step S202 described below.

[0019] <Step S202> In step S202, the result acquisition unit 103 takes the related information DB 102 as input. The result acquisition unit 103 acquires, as result information 116, a set from multiple related information 115 that includes at least the result Ri of solving the attack reproduction problem Qi and the attack name Ni corresponding to the attack reproduction problem Qi. I will explain in detail below.

[0020] The result acquisition unit 103 acquires a pair containing the result Ri of solving the attack reproduction problem and the corresponding attack name Ni from the related information DB 102 which stores multiple related information 115, as result information 116. The result acquisition unit 103 stores the acquired result information 116 in the result DB 104. Figure 5 shows an image of how result information 116 is stored in result DB 104. Figure 6 shows a specific example of result information 116 stored in the result DB 104. Each row is result information 116. The result Ri in result information 116, which is the success rate of solving the attack reproduction problem, is, for example, the success rate of multiple people solving the attack reproduction problem. For example, if the attack reproduction problems Q1 and Q2 are shown in Figure 4, R1 = ans_1 to ans_k, R2 = ans_k + 1 to ans_n, That is the case.

[0021] <Step S203> In step S203, the attack name acquisition unit 105 acquires the attack name INi, which is the attack name for which the difficulty level D of the cyberattack should be evaluated. Figure 7 shows an image of how attack names INi are stored in attack name DB106. Examples of attack names INI include IN1 for SQL injection and IN2 for XSS (cross-site scripting). Regarding the attack name INi, the risk assessment implementer 200 pre-defines the attack name INi for which the attack difficulty D should be evaluated. The risk assessment implementer 200 inputs the attack name INi into the attack name acquisition unit 105. The attack name acquisition unit 105 saves the input attack name INi into the attack name DB 106.

[0022] <Step S204> In step S204, the difficulty evaluation unit 107 receives the result information 116 from the result DB 104 and the attack name INi from the attack name DB 106 as input. The difficulty evaluation unit 107 refers to the acquired attack name INi and the attack name Ni included in the result information 116. By referring, the difficulty evaluation unit 107 extracts multiple result Ri corresponding to the acquired attack name INi from the result information 116. The difficulty evaluation unit 107 uses the extracted multiple result Ri to evaluate the difficulty of a cyberattack against the acquired attack name INi. I will explain in detail below.

[0023] Figure 8 shows an image of how the difficulty evaluation unit 107 receives the result information 116 from the result DB 104 and the attack name INi from the attack name DB 106. The difficulty evaluation unit 107 evaluates the attack difficulty based on the calculation formula. That is, the difficulty evaluation unit 107 calculates the attack difficulty using the calculation formula. Here, the name of the attack to be evaluated for difficulty is IN1 = "SQL Injection". The difficulty evaluation unit 107 evaluates the attack difficulty D, which indicates how difficult the attack being evaluated is. The method for evaluating the attack difficulty D is shown below.

[0024] The difficulty evaluation unit 107 extracts result information 116 of the attack reproduction problem to be evaluated from the result DB 104, using the attack name IN1 as the key. The difficulty evaluation unit 107 combines the extracted result information 116 of the attack reproduction problem to construct a formula for calculating the attack difficulty D. In the case of attack name IN1 = "SQL injection", the specifics are as follows: In Figure 8, the difficulty evaluation unit 107 extracts results R1 and R2 from result information 116 where "corresponding attack name" = "SQL injection". R1 = (ans_1, ..., ans_k). R2 = (ans_k+1, ..., ans_n).

[0025] The following formula (1) shows an example of a formula for calculating the attack difficulty D1 for an attack named IN1 = "SQL injection". Attack difficulty D1 = 1 - max(ans_1, ..., ans_n) (1) The difficulty evaluation unit 107 calculates the attack difficulty D1 based on multiple results of solving an attack reproduction problem related to the attack name IN1 = "SQL injection". Here, the multiple results of solving the attack reproduction problem are the sum of R1 = (ans_1, ..., ans_k) and R2 = (ans_k + 1, ..., ans_n). Therefore, the multiple results of solving the attack reproduction problem are constructed as ans_1 to ans_n. Each of ans_1 to ans_n takes a value between 0 and 1, depending on the accuracy rate of solving the attack reproduction problem.

[0026] In equation (1), the attack difficulty D1 is evaluated using the value obtained by subtracting the maximum value of "ans_1 to ans_n" from 1. This evaluation is just one example, and the evaluation of attack difficulty D1 is not limited to using the maximum value. For example, the evaluation of attack difficulty D1 could also be done using the value obtained by subtracting the average value of "ans_1 to ans_n" from 1. That is, attack difficulty D1 = 1 - average value, The mean can also be expressed as (ans_1 + ans_2 + ... + ans_n) ÷ n.

[0027] Alternatively, the formula for calculating the attack difficulty D may be based on the correlation between the attack name INi to be evaluated and the attack name Ni of each attack reproduction problem. Alternatively, the formula for calculating the attack difficulty D may be based on the correlation between the attack name INi to be evaluated and each of the attack reproduction problems Qi.

[0028] <Step S205> In step S205, the output unit 108 notifies the user of the attack difficulty D1 evaluated by the difficulty evaluation unit 107 using a display device. The display device is, for example, the display device 10e shown in Figure 18, which will be described later. The output unit 108 outputs the attack difficulty D1 as a score value. The score value is the result of the calculation of formula (1).

[0029] ***Explanation of the effects of Embodiment 1*** The quantification device 100 of Embodiment 1 comprises a data collection unit 101, a result acquisition unit 103, an attack name acquisition unit 105, and a difficulty evaluation unit 107. Therefore, the quantification device 100 has the effect of quantifying the difficulty of an attack based on objective information.

[0030] Embodiment 2. The quantification apparatus 100 of Embodiment 2 will be described with reference to Figures 9 to 12. The quantification apparatus 100 of Embodiment 2 is characterized by having a quality evaluation unit 109. The quality evaluation unit 109 evaluates whether the attack reproduction problem Qi in the related information 115 has a quality equal to or greater than the standard value. The result acquisition unit 103 acquires only the sets corresponding to attack reproduction problems that are evaluated as having a quality equal to or higher than the standard value, as result information 116. I will explain in detail below.

[0031] Figure 9 is a block diagram of the quantification device 100 according to Embodiment 2. Figure 10 is a flowchart showing the operation of the quantification device 100. Figure 11 shows the operation of the quality evaluation unit 109 in the second embodiment.

[0032] The quantification device 100 of Embodiment 2 further includes a quality evaluation unit 109 and a quality DB 110 compared to the quantification device 100 of Embodiment 1. The quality evaluation unit 109 evaluates the quality of the attack reproduction problem Qi. The quality DB 110 stores the evaluation results from the quality evaluation unit 109.

[0033] Referring to Figure 10, the operation of the quantification device 100 in Embodiment 2 will be described. In Embodiment 2, the related information 115 in Figure 11 has, in addition to the related information 115 in Embodiment 1 (Figure 4), a skill equivalent value Si of the person who created the attack reproduction problem. The operation of steps S201, S203, and S205 is the same as in Embodiment 1, so the explanation will be omitted.

[0034] <Step S201-1> In step S201-1, the quality evaluation unit 109 evaluates the quality evaluation value E based on a calculation formula set in advance by the risk assessment implementer 200. The quality evaluation unit 109 takes as input multiple related information 115 from the related information DB 102 shown in Figure 11.

[0035] When evaluating quality, the quality evaluation unit 109 uses at least one of the following: the skill level of the person who created the attack reproduction problem Qi, or the number of people who solved the attack reproduction problem Qi. I will explain in detail below.

[0036] The quality evaluation unit 109 evaluates the quality of the attack reproduction problem Qi in the related information 115. As an example of attack reproduction problem Qi, we take attack reproduction problem Q1 in Figure 11. The corresponding attack name N1 for attack reproduction problem Q1 is "SQL injection". The quality evaluation unit 109 calculates the quality evaluation value E1 for attack reproduction problem Q1 using a calculation formula, based on the number of people P1 who solved the attack reproduction problem and the skill equivalent value Si of the person who created the attack reproduction problem. An example of the calculation formula for the quality evaluation value E1 is shown in equation (2) below. Using the number of people P1 who solved it and the skill equivalent value S1, the quality evaluation unit 109 evaluates the quality of attack reproduction problem Q1 from equation (2).

[0037] Quality evaluation value Ei = Peo_i * Skl_i (2) In the attack reproduction problem Q1, i=1, Quality evaluation value E1 = Peo_1 * Skl_1 * indicates multiplication. Peo_1 is a value determined by the number of people P1=k who solved the attack reproduction problem Q1. The value of Peo_1 can take a value between 0 and 1, depending on the number of people P1 who solved the problem. For example, if the number of people P1 who solved the attack reproduction problem Q1 is 1000 or less, then Peo_1 = 0.1. If the number of people P1 who solved it is 100,000 or more, then Peo_1 = 1. The quality evaluation unit 109 converts P1 to Peo_1.

[0038] Skill level Skl_1, like the skill equivalent value S1, indicates the skill level of the person who created the attack reproduction problem Q1. Skill level Skl_1 takes a value between 0 and 1, depending on the skill equivalent value S1 of the person who created the attack reproduction problem Q1. For example, skill level Skl_1 has three levels: high, medium, and low. If the skill equivalent value S1 is low, skill level Skl_1 takes the value 0.1. If the skill equivalent value S1 is high, skill level Skl_1 takes the value 1. The quality evaluation unit 109 converts the skill equivalent value Si to Skl_i. The quality evaluation unit 109 stores the calculated quality evaluation value E1 in the quality DB 110. The same applies to other attack reproduction problems Qi (i>2).

[0039] Furthermore, the quality evaluation value Ei may be calculated from other factors related to the quality of the attack reproduction problem Qi, distinct from the number of solvers Pi and the skill equivalent value Si.

[0040] <Step S201-2> In step S201-2, the quality evaluation unit 109 determines whether the quality evaluation value Ei of the attack reproduction problem Qi is equal to or greater than the standard value. If the quality evaluation value Ei is equal to or greater than the standard value (step S201-2, YES), the result Ri obtained by solving the attack reproduction problem Qi is used in the evaluation of the attack difficulty D. If the quality evaluation value Ei is less than the standard value (step S201-2, NO), the quality evaluation unit 109 does not include the result Ri obtained by solving the attack reproduction problem Qi in the evaluation of the attack difficulty. The process then proceeds to step S201, and the quality evaluation unit 109 moves on to evaluating the quality of the next attack reproduction problem.

[0041] Figure 11 shows quality information 118, in which the quality evaluation result Ei of the attack reproduction problem Qi is registered. Quality information 118 is stored in the quality DB 110 by the quality evaluation unit 109. In the right column of quality information 118, YES indicates that the quality evaluation value Ei is above the standard value, and NO indicates that it is below the standard value.

[0042] <Step S202> In step S202, as shown in Figure 11, the result acquisition unit 103 takes the quality DB 110 and the related information DB 102 as input. The result acquisition unit 103 refers to the attack name Ni of the attack reproduction problem Qi whose quality evaluation value Ei is equal to or greater than the standard value. The result acquisition unit 103 acquires the attack name Ni that is equal to or greater than the standard value, and the result Ri corresponding to the attack name Ni that is equal to or greater than the standard value, from the related information 115. In this way, the result Ri of solving the attack reproduction problem is collected for attack reproduction problem Qi whose quality is equal to or greater than the standard value.

[0043] <Step S204-1> In step S204-1, the difficulty evaluation unit 107 receives the result DB 104 and the attack name DB 106 as input. The difficulty evaluation unit 107 evaluates the attack difficulty D2 based on a pre-set calculation formula. In this case, the result DB 104 stores the result Ri of the attack reproduction problem Qi that has a quality evaluation value Ei equal to or greater than the standard value. Therefore, the difficulty evaluation unit 107 evaluates the attack difficulty D2 using the result Ri of the attack reproduction problem Qi that has a quality evaluation value Ei equal to or greater than the standard value.

[0044] The evaluation method for attack difficulty D2 is as follows. Figure 12 shows an example of the result DB 104 reflecting the quality evaluation results. The result DB 104 in Figure 12 is the result obtained by the result acquisition unit 103 in Figure 11. The result DB 104 stores the result Ri of the attack reproduction problem Qi that has a quality evaluation value Ei of or greater than the standard value. The difficulty evaluation unit 107 evaluates the attack difficulty in the same manner as in step S204 in Figure 2. If the acquired attack name is "SQL injection", the difficulty evaluation unit 107 calculates the attack difficulty D2 using the following formula (3), similar to step S204 in Figure 2.

[0045] Attack difficulty D2 = 1 - max(ans_1, ..., ans_n) (3) In equation (3), "ans_1 to ans_n" are the results of solving the "attack reproduction problem with a quality evaluation value E above the standard value". Each value of "ans_1 to ans_n" is between 0 and 1, depending on the accuracy rate.

[0046] The attack difficulty is evaluated by subtracting the maximum value of "ans_1 to ans_n" from 1. However, it is not limited to using the maximum value. For example, the attack difficulty could also be evaluated by subtracting the average value of "ans_1 to ans_n" from 1. Alternatively, a formula for calculating the attack difficulty D2 could be constructed using the correlation between the attack name INi to be evaluated and each attack reproduction problem Qi, or the correlation between each attack reproduction problem Qi. Furthermore, only the result Ri obtained by solving attack reproduction problems Qi where the quality evaluation value Ei is equal to or greater than the threshold value is extracted. However, a formula that uses the quality evaluation value Ei as an element of the calculation formula for the attack difficulty D2 could also be used.

[0047] ***Effects of Embodiment 2*** In the quantification device 100 of Embodiment 2, the quality evaluation unit 109 evaluates the quality of the attack reproduction problem. The difficulty evaluation unit 107 then evaluates the attack difficulty using the results of solving "attack reproduction problems with a quality equal to or greater than the standard value". Therefore, in addition to the effects described in Embodiment 1, the quantification device 100 of Embodiment 2 has the effect of improving the quality of the attack difficulty D2 being evaluated.

[0048] Embodiment 3. The quantification device 100 of Embodiment 3 will be described with reference to Figures 13 to 15. The quantification device 100 of Embodiment 3 is characterized by the inclusion of a mapping unit 111. The mapping unit 111 generates a mapping that associates the acquired attack name INi with the attack reproduction problem Qi corresponding to the acquired attack name INi. The difficulty evaluation unit 107 extracts multiple results corresponding to the acquired attack name INi from the result information 116 by referring to the mapping. This will be explained in detail below.

[0049] Figure 13 is a block diagram of the quantification device 100 according to Embodiment 3. Figure 14 is a flowchart showing the operation of the quantification device 100 according to Embodiment 3. Figure 15 shows the generation of the mapping DB112.

[0050] In Figure 13, the quantification device 100 is equipped with a mapping unit 111 and a mapping DB 112 compared to the quantification device 100 of Embodiment 1. The mapping unit 111 searches the related information DB 102 for an attack reproduction problem Qi corresponding to the attack name INi obtained by the attack name acquisition unit 105. The attack reproduction problem Qi corresponding to the attack name INi will be referred to as the optimal problem Qi below.

[0051] Referring to Figure 14, the operation of the quantification device 100 of Embodiment 3 will be described. The operation from step S201 to step S203 is the same as in Embodiment 1, so the description will be omitted.

[0052] <Step S203-1> In step S203-1, the mapping unit 111 maps the optimal problem Qi to the attack name INi obtained by the attack name acquisition unit 105. As shown in Figure 15, the mapping unit 111 takes the related information DB 102 and the attack name DB 106 as input. The mapping unit 111 maps the optimal problem Qi that was hit in the search using the attack name INi as the key to the attack name INi.

[0053] For example, let's assume the attack name INi is IN1 = "SQL Injection". The mapping unit 111 searches the related information DB 102 for the optimal problem Qi for IN1 = "SQL Injection". If the mapping unit 111 finds the optimal problem Qi corresponding to IN1 = "SQL Injection", it maps the attack name IN1 = "SQL Injection" to "Optimal problem Qi for SQL Injection". In Figure 15, optimal problems Q1 and Q2 exist in the related information DB 102. Therefore, the mapping unit 111 maps IN1 = "SQL Injection" to optimal problems Q1 and Q2. If no optimal problem Qi for IN1 = "SQL Injection" is found, the mapping unit 111 maps IN1 = "SQL Injection" to "No optimal problem". This result is shown in the third row of Figure 15. The mapping unit 111 stores the mapping result between the attack name INi and the optimal problem Qi in the mapping DB 112.

[0054] <Step S204> In step S204, the difficulty evaluation unit 114 receives the result DB 104, the attack name DB 106, and the mapping DB 112 as input. By referring to the mapping DB 112, the difficulty evaluation unit 107 can immediately determine the optimal problems Q1 and Q2 corresponding to IN1 = "SQL injection". Therefore, the difficulty evaluation unit 107 can immediately obtain the results R1 and R2 shown in Figure 6 from the result DB 104 and evaluate the attack difficulty D3 shown below.

[0055] The method used by the difficulty evaluation unit 107 to evaluate the difficulty of an attack is as follows. The difficulty evaluation unit 107 extracts the results of attack reproduction problems that are subject to evaluation for attack difficulty D from the mapping results between attack names and optimal problems stored in the mapping DB 112, and places them in the results DB 104. The difficulty evaluation unit 107 combines the extracted results of attack reproduction problems to construct an attack difficulty calculation formula. In this example, the difficulty evaluation unit 107 obtains the results R1 and R2 shown in Figure 6. R1 = ans_1, ..., ans_k R2 = ans_k+1, ..., ans_n, The difficulty evaluation unit 107 combines the extracted results R1 and R2 to construct the following equation (4).

[0056] Attack difficulty D3 = 1 - max(ans_1, ..., ans_n) (4)

[0057] The attack name 117 being evaluated this time is "SQL injection". Therefore, the difficulty evaluation unit 107 evaluates the attack difficulty D3 based on the results of solving the attack reproduction problem related to "SQL injection".

[0058] The results of solving the SQL injection attack reproduction problem are represented by ans_1 to ans_n. ans_1 to ans_n take values ​​from 0 to 1 depending on the accuracy of the solution. The attack difficulty D3 is evaluated by subtracting the maximum value of ans_1 to ans_n from 1. However, it is not limited to the maximum value. For example, the attack difficulty could also be evaluated using the value obtained by subtracting the average value of ans_1 to ans_n from 1. Alternatively, a formula for calculating the attack difficulty could be constructed using the relevance of the 117 attack names to be evaluated to each attack reproduction problem, or the relevance of each attack reproduction problem to each other.

[0059] ***Effects of Embodiment 3*** The quantification device 100 of Embodiment 3 includes a mapping unit. Therefore, in addition to the effects of Embodiment 1, the difficulty evaluation unit 107 has the effect of being able to immediately extract the result of the optimal problem by using the mapping result.

[0060] Embodiment 4. The quantification device 100 of Embodiment 4 will be explained with reference to Figures 16 and 17. The quantification device 100 of Embodiment 4 is characterized by a configuration that combines the quantification devices 100 of Embodiment 2 and Embodiment 3. That is, the quantification device 100 of Embodiment 4 includes a quality evaluation unit 109 and a mapping unit 111. Figure 16 is a block diagram of the quantification device 100. Figure 17 is a flowchart of the quantification device 100. Figure 16 shows the configuration combined from Figures 9 and 13. Figure 17 shows the process combined from Figures 10 and 14. Since Figures 9, 13, 10, and 14 have already been explained, the explanations for Figures 16 and 17 will be omitted.

[0061] In addition, the result acquisition unit 103, difficulty evaluation unit 107, quality evaluation unit 109, and mapping unit 111 described in Embodiments 1 to 4 may acquire information directly from each DB, or they may acquire information via the upstream functional unit. Furthermore, the mapping unit 111 can also acquire and utilize information such as MITRE ATT&CK (registered trademark, Adversarial Tactics, Techniques, and Common Knowledge) and CWE (Common Weakness Enumeration).

[0062] Embodiment 5. Figure 18 shows the hardware configuration of the quantification device 100. The hardware configuration of the quantification device 100 described in Embodiments 1 to 4 will be explained with reference to Figure 18.

[0063] In Figure 18, the computer 10 comprises a processor 10a, main memory 10b, keyboard 10c, mouse 10d, display device 10e, auxiliary storage device 10f, and network interface 10g. The processor 10a is the arithmetic unit. The keyboard 10c uses, for example, a USB (Universal Serial Bus) connection. The display device 10e provides display output to the user. The network interface 10g is used for communication with the outside world.

[0064] The processor 10a is, for example, a CPU (Central Processing Unit). The processor 10a may also be a logic circuit such as an FPGA (Field Programmable Gate Array). The main memory 10b is volatile memory. The main memory 10b is, for example, RAM (Read Only Memory). The auxiliary memory 10f is non-volatile memory. The auxiliary memory 10f is, for example, an HDD (Hard Disk Drive) or an SSD (Solid State Drive). The auxiliary memory 10f stores the quantification program 100P that implements the attack difficulty quantification method of Embodiment 1. The auxiliary memory 10f also stores control parameters, etc. The display device 10e is, for example, a display.

[0065] The quantification program 100P may be provided stored on a computer-readable recording medium, or it may be provided as a program product.

[0066] When the quantification device 100 shown in Figure 1 is implemented with the hardware configuration shown in Figure 15, the following operations are performed. The processor 10a reads the quantification program 100P from the auxiliary storage device 10f and uses the main storage device 10b as work memory to execute each process of the quantification program 100P. In other words, by the processor 10a executing the quantification program, the functions of the quantification device 100, name acquisition device 101, result acquisition device 103, attack name acquisition device 105, difficulty evaluation device 107, output device 108, quality evaluation device 109, and mapping device 111 are realized. In addition, the related information DB 102, result DB 104, attack name DB 106, quality DB 110, and mapping device 111 are realized by the main storage device 10b or auxiliary storage device 10f. Furthermore, the related information DB102, result DB104, attack name DB106, quality DB110, and mapping unit 111 databases may reside inside the quantification device 100, or they may reside on other devices such as a cloud server.

[0067] <Supplementary information on hardware configuration> Figure 19 shows a configuration in which the functions of the quantification device 100 are implemented in hardware. In the computer 10 shown in Figure 18, the functions of the quantification device 100 are implemented in software called the quantification program 100P. However, the functions of the quantification device 100 may also be implemented in hardware. In the electronic circuit 90 shown in Figure 19, the functions of the constituent elements of the quantification device 100, name acquisition unit 101, result acquisition unit 103, attack name acquisition unit 105, difficulty evaluation unit 107, output unit 108, quality evaluation unit 109, and mapping unit 111, as well as the database functions of related information DB 102, result DB 104, attack name DB 106, quality DB 110, and mapping DB 112, are realized. The electronic circuit 90 is a dedicated electronic circuit that realizes the functions of each component and each DB function. The electronic circuit 90 is connected to the signal line 91.

[0068] The processor 10a and the electronic circuit 90 are also called processing circuits or circuits. In the quantification device 100, each component function and each DB function may be realized by circuits.

[0069] The quantification device 100 has been described in four embodiments, from Embodiment 1 to Embodiment 4. These four embodiments may be implemented in combination. Alternatively, one of these four embodiments may be implemented in part. Alternatively, these four embodiments may be implemented in part in combination. Furthermore, the configurations and procedures described in these four embodiments may be modified as necessary. [Explanation of Symbols]

[0070] 10 Computer, 10a Processor, 10b Main memory, 10c Keyboard, 10d Mouse, 10e Display device, 10f Auxiliary memory, 10g Network interface, 90 Electronic circuit, 91 Signal line, 100 Quantification device, 100P Quantification program, 101 Collection unit, 102 Related information DB, 103 Result acquisition unit, 104 Result DB, 105 Attack name acquisition unit, 106 Attack name DB, 107 Difficulty evaluation unit, 108 Output unit, 109 Quality evaluation unit, 110 Quality DB, 111 Mapping unit, 112 Mapping DB, 115 Related information, 116 Result information, 118 Quality information, 200 Risk assessment implementer, 301 Internet, 302 Web.

Claims

1. A collection unit that collects multiple pieces of related information, including an attack reproduction problem which is a problem that can be solved by reproducing a cyberattack, the result of solving the attack reproduction problem, and the name of the attack corresponding to the attack reproduction problem. A result acquisition unit obtains, as result information, a set containing at least the result of solving the attack reproduction problem and the attack name corresponding to the attack reproduction problem, from the aforementioned multiple pieces of related information. An attack name acquisition unit that acquires the attack name for which the difficulty of the aforementioned cyberattack should be evaluated, A difficulty evaluation unit that, by referring to the acquired attack name and the attack name included in the result information, extracts a plurality of results corresponding to the acquired attack name from the result information, and uses the extracted plurality of results to evaluate the difficulty of the cyber attack against the acquired attack name, An information processing device equipped with the following features.

2. The aforementioned information processing device further, The system includes a quality evaluation unit that evaluates whether the attack reproduction problem in the related information has a quality equal to or greater than a certain standard value. The result acquisition unit, The information processing apparatus according to claim 1, which acquires only the sets corresponding to the attack reproduction problem that are evaluated to have a quality equal to or greater than the aforementioned standard value as the result information.

3. The aforementioned quality evaluation unit, The information processing apparatus according to claim 2, which, when evaluating the aforementioned quality, uses at least one of the skills of the person who created the attack reproduction problem and the number of people who solved the attack reproduction problem.

4. The aforementioned information processing device is The system includes a mapping unit that generates a mapping that associates the acquired attack name with the attack reproduction problem corresponding to the acquired attack name. The aforementioned difficulty level evaluation unit, An information processing device according to any one of claims 1 to 3, which extracts the plurality of results corresponding to the acquired attack name from the result information by referring to the mapping.

5. The multiple results included in the aforementioned multiple pieces of related information are, An information processing device according to any one of claims 1 to 4, which is the result of multiple people solving the attack reproduction problem.

6. On the computer, An attack reproduction problem, which is a problem that can be solved by reproducing a cyberattack; an information collection process that collects multiple pieces of related information, including the result of solving the attack reproduction problem and the name of the attack corresponding to the attack reproduction problem; A result acquisition process that obtains, as result information, a pair containing at least the result of solving the attack reproduction problem and the attack name corresponding to the attack reproduction problem, from the aforementioned multiple pieces of related information. An attack name acquisition process to obtain the attack name for which the difficulty of the aforementioned cyberattack should be evaluated, A difficulty evaluation process is performed to evaluate the difficulty of the cyberattack against the acquired attack name by referring to the acquired attack name and the attack name included in the result information, extracting multiple results corresponding to the acquired attack name from the result information, and using the extracted multiple results, the difficulty of the cyberattack against the acquired attack name. An information processing program that executes [something].

7. Computers Collect multiple pieces of related information, including an attack reproduction problem which can be solved by reproducing a cyberattack, the result of solving the said attack reproduction problem, and the name of the attack corresponding to the said attack reproduction problem. From the aforementioned multiple pieces of related information, a set containing at least the result of solving the attack reproduction problem and the attack name corresponding to the attack reproduction problem is obtained as result information. The attack name should be obtained to evaluate the difficulty of the aforementioned cyberattack. An information processing method that, by referring to the acquired attack name and the attack name included in the result information, extracts a plurality of results corresponding to the acquired attack name from the result information, and uses the extracted plurality of results to evaluate the difficulty level of the cyber attack against the acquired attack name.