System evaluation device, system evaluation method, and program

The system evaluation apparatus and method address the challenge of detecting and responding to IT system vulnerabilities by evaluating and outputting vulnerability trends, facilitating effective security measures.

JP2026086165APending Publication Date: 2026-05-26NEC CORP

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
NEC CORP
Filing Date
2024-11-14
Publication Date
2026-05-26

AI Technical Summary

Technical Problem

Existing systems fail to provide users with an objective and easy way to grasp the detection of vulnerabilities and the status of countermeasures in IT systems, making it difficult to take effective security measures.

Method used

A system evaluation apparatus and method that evaluates vulnerabilities using multiple methods, generating and outputting vulnerability trend information to facilitate understanding and response, utilizing a generation unit to evaluate vulnerabilities for each type of method and an output unit to present the worst evaluation results.

Benefits of technology

Enables users to easily understand and respond to system security detection and countermeasures, simplifying security measures by providing clear vulnerability trends and evaluation information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026086165000001_ABST
    Figure 2026086165000001_ABST
Patent Text Reader

Abstract

To facilitate the detection and response status of system security issues, thereby simplifying security measures. [Solution] The system evaluation device includes a generation unit that uses detection result information representing the detection results of vulnerabilities possessed by multiple information processing devices included in the system to evaluate the vulnerability status in the system for each different type of evaluation method and generates evaluation result information representing the evaluation results for each evaluation method, and an output unit that causes an output device to output vulnerability trend information representing the vulnerability trend corresponding to the worst evaluation result among the evaluation result information for each evaluation method.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a system evaluation apparatus for security measures, a system evaluation method, and a program.

Background Art

[0002] Currently, users of IT (Information Technology) systems (such as managers and security personnel) cannot objectively and easily grasp the detection of vulnerabilities in IT systems and the status of countermeasures, and it is not easy to take autonomous security measures.

[0003] As a related technology, Patent Document 1 discloses a risk-based authentication system that reduces the processing time of risk evaluation and the resource consumption of the system used for performing risk evaluation. The risk-based authentication system of Patent Document 1 has an information processing apparatus that evaluates the risk of access to resources such as a server by a client terminal and performs processing according to the evaluation result.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] In Patent Document 1, the risk of access by a client terminal to resources such as a server is evaluated using a plurality of risk determination methods. However, in Patent Document 1, it does not easily allow users (such as managers and security personnel) to grasp the detection of system vulnerabilities and the status of countermeasures, and does not facilitate security measures.

[0006] One example of the purpose of this disclosure is to facilitate the detection and response status of system security, thereby simplifying security measures. [Means for solving the problem]

[0007] To achieve the above objective, the system evaluation apparatus in one aspect of this disclosure is A generation unit that uses detection result information representing the detection results of vulnerabilities in multiple information processing devices included in the system to evaluate the vulnerability status in the system for each different type of evaluation method, and generates evaluation result information representing the evaluation results for each evaluation method, An output unit that outputs vulnerability trend information, which represents the vulnerability trend corresponding to the worst evaluation result among the evaluation result information for each of the evaluation methods, to an output device; It is characterized by having the following features.

[0008] Furthermore, in order to achieve the above objectives, the system evaluation method in one aspect of this disclosure is: Computers Using detection result information representing the detection results of vulnerabilities in multiple information processing devices included in the system, the vulnerability status in the system is evaluated for each different type of evaluation method, and evaluation result information representing the evaluation results for each evaluation method is generated. The output device outputs vulnerability trend information, which represents the vulnerability trend corresponding to the worst evaluation result among the evaluation result information for each of the aforementioned evaluation methods. It is characterized by the following:

[0009] Furthermore, in order to achieve the above objectives, the program in one aspect of this disclosure is On the computer, Using detection result information representing the detection results of vulnerabilities in multiple information processing devices included in the system, the vulnerability status in the system is evaluated for each different type of evaluation method, and evaluation result information representing the evaluation results for each evaluation method is generated. The output device outputs vulnerability trend information, which represents the vulnerability trend corresponding to the worst evaluation result among the evaluation result information for each of the aforementioned evaluation methods. It is characterized by the following: [Effects of the Invention]

[0010] As described above, this disclosure makes it easy to understand the detection and response status of system security and facilitates security measures. [Brief explanation of the drawing]

[0011] [Figure 1] Figure 1 is a diagram illustrating an example of a system evaluation device. [Figure 2] Figure 2 shows an example of a system that includes a system evaluation device. [Figure 3] Figure 3 is a diagram illustrating an example of a system vulnerability. [Figure 4] Figure 4 is a diagram illustrating an example of system evaluation information. [Figure 5] Figure 5 is a diagram illustrating the determination of vulnerability trend information. [Figure 6] Figure 6 is a diagram illustrating an example of a system status display. [Figure 7] Figure 7 is a diagram illustrating an example of the operation of the system evaluation device. [Figure 8] Figure 8 is a diagram illustrating an example of a computer that realizes a system evaluation device in an embodiment. [Modes for carrying out the invention]

[0012] Embodiments will be described below with reference to the drawings. In the drawings described below, elements having the same function or corresponding function will be denoted by the same reference numeral, and repeated descriptions of such elements may be omitted.

[0013] (Embodiment) The configuration of the system evaluation device in the embodiment will be explained using Figure 1. Figure 1 is a diagram illustrating an example of a system evaluation device. [Device configuration] The system evaluation device shown in FIG. 1 is a device that facilitates understanding of the security detection and countermeasure status of a system and facilitates security measures. As shown in FIG. 1, the system evaluation device 10 includes a generation unit 11 and an output unit 12.

[0014] The generation unit 11 uses detection result information representing the detection results of vulnerabilities possessed by a plurality of information processing devices (terminal devices) included in the system, and evaluates the vulnerability status in the system for each different type of evaluation method, and generates evaluation result information representing the evaluation results for each evaluation method.

[0015] The output unit 12 causes the output device to output vulnerability trend information representing the trend of vulnerabilities corresponding to, for example, the worst evaluation result among the evaluation result information for each evaluation method. Further, the output unit 12 may output vulnerability trend information representing the trend of the most notable vulnerabilities among the evaluation result information for each evaluation method to the output device. Furthermore, the output unit 12 may select evaluation result information that satisfies the attention criteria from the evaluation result information for each evaluation method and output the selected evaluation result information to the output device. When the evaluation result is represented by a numerical value indicating the urgency level, the attention criteria is, for example, a value for determining that the urgency level is high. When the evaluation result is represented by a character string indicating the degree of attention, the attention criteria may be, for example, matching the character string representing the class to be noted in the evaluation result.

[0016] As described above, in the embodiment, by presenting the vulnerability trend information representing the trend of vulnerabilities corresponding to the worst evaluation result among the evaluation result information for each evaluation method, the user of the system (for example, the manager, the security person, etc.) can easily understand the security detection and countermeasure status of the system and can easily take security measures.

[0017] [System Configuration] Subsequently, the configuration of the system evaluation device 10 in the embodiment will be described more specifically with reference to FIG. 2. FIG. 2 is a diagram showing an example of a system having a system evaluation device.

[0018] As shown in Figure 2, the system 100 in the embodiment includes at least a system evaluation device 10, a plurality of information processing devices 20 (20a, 20b, 20c...), a storage device 30, an output device 40, and a network 50.

[0019] The system evaluation device 10 is, for example, an information processing device such as a CPU (Central Processing Unit), a programmable device such as an FPGA (Field-Programmable Gate Array), a GPU (Graphics Processing Unit), or a circuit equipped with one or more of these, a server computer, a personal computer, or a mobile terminal.

[0020] The information processing device 20 (20a, 20b, 20c...) is, for example, a server computer, personal computer, mobile terminal, or other terminal device equipped with a CPU, FPGA, or both.

[0021] The storage device 30 includes a database, a server computer, and a circuit with memory. The storage device 30 stores information such as detection result information, evaluation result information, vulnerability risk level, standard evaluation information, and system evaluation information, which will be described later. In the example in Figure 2, the storage device 30 is located outside the system evaluation device 10, but it may also be located inside the system evaluation device 10.

[0022] The output device 40 acquires output information, which has been converted into an outputtable format, and outputs generated images and sounds based on that output information. The output device 40 is, for example, an image display device using liquid crystal, organic EL (Electro Luminescence), or CRT (Cathode Ray Tube). Furthermore, the image display device may also be equipped with sound output devices such as speakers. The output device 40 may also be a printing device such as a printer.

[0023] Network 50 is a general network constructed using communication lines such as the Internet, LAN (Local Area Network), dedicated lines, telephone lines, corporate networks, mobile communication networks, Bluetooth®, and Wi-Fi (Wireless Fidelity)®.

[0024] ●The system evaluation equipment will be explained in detail. The system evaluation device 10 includes a generation unit 11, an output unit 12, and a calculation unit 13.

[0025] The generation unit 11 first obtains detection result information, which represents the detection results of vulnerabilities present in multiple information processing devices 20 included in the system 100, and which is stored in the storage device 30.

[0026] The detection results information is log information that includes at least information about the detected vulnerabilities and the actions taken to address them. For example, the detection results information includes the vulnerability status of the OS (Operating System: server OS and client OS) of the information processing device 20, the detection and remediation status for each system, the detection and remediation status of vulnerabilities of interest, the monthly vulnerability detection and remediation status, the average number of days to remediate, middleware modernization, and the client OS vulnerability status.

[0027] Next, the generation unit 11 uses the acquired detection result information to evaluate the vulnerability status in the system 100 for each different type of evaluation method, and generates evaluation result information that represents the evaluation result for each evaluation method.

[0028] The evaluation result information for each evaluation method is generated using, for example, the evaluation methods (1), (2), and (3) shown below.

[0029] (1) In the first evaluation method, a score S1 (first evaluation result information) representing the status of the system is generated using the total number of information processing devices (terminal devices) 20 managed by the system 100, Im, and the total number of vulnerabilities Sm of the information processing devices 20 managed by the system 100. The score S1 can be expressed as shown in equation 1.

[0030] (Math 1) S1 = ((Sm-1) / Im) × α S1: Score (First evaluation result information) Sm: Total number of vulnerabilities in terminal devices Im: Number of terminal devices α: weight

[0031] Figure 3 is a diagram illustrating an example of a system vulnerability. In the example in Figure 3, there are six information processing devices 20 (terminal devices) managed by system 100, represented as terminals A through F. Therefore, if the weight α is set to 10, the score S1 will be 125 (= ((4+5+12+16+32+7-1) / 6)×10) = ((76-1) / 6)×10).

[0032] However, while score S1 is good when the number of vulnerabilities in each terminal from A to F is roughly equal (similar), score S1 cannot accurately represent the overall system situation when there is one terminal device with a large number of vulnerabilities and several terminal devices with a small number of vulnerabilities. For example, if one terminal device has 25 vulnerabilities and several other terminal devices each have 1 vulnerability, score S1 cannot accurately represent the system situation. In such cases, the second evaluation method is effective.

[0033] (2) In the second evaluation method, the number of vulnerabilities Smm in the most vulnerable information processing device 20 in system 100 is defined as the score S2 (second evaluation result information). The score S2 can be expressed as shown in equation 2.

[0034] (Math 2) S2 = (Smm-1) × β S2: Score (Second evaluation result information) Smm: Number of vulnerabilities in the most vulnerable terminal device β: weight

[0035] In the example shown in Figure 3, among the multiple information processing devices (terminal devices) 20 managed by system 100, terminal E with 32 vulnerabilities Smm is detected as the most dangerous terminal within system 100. Therefore, if the weight β is set to 10, the score S2 will be 310 (= (32-1) × 10).

[0036] However, score S2 can accurately represent the most dangerous terminal in the system if there is one terminal with a high number of vulnerabilities and several terminals with a low number of vulnerabilities. However, score S2 cannot represent the most dangerous terminal if there are several terminals with a high number of vulnerabilities and several terminals with a low number of vulnerabilities. In other words, it cannot indicate that there are several other terminals with a high number of vulnerabilities. For example, if several terminals each have 24 or more vulnerabilities and several terminals each have 5 or fewer vulnerabilities, score S2 cannot indicate that there are several dangerous terminals. In such cases, the third evaluation method is effective.

[0037] (3) In the third evaluation method, a score S3 (third evaluation result information) is generated in the system 100 that represents the total number Imm of information processing devices 20 in which the number of vulnerabilities is equal to or greater than a pre-set threshold Th. The score S3 can be expressed as shown in equation 3.

[0038] The threshold Th can be determined, for example, by defining a dangerous terminal device, and is determined and modified based on the vulnerability status of the target information processing device 20 (the organization's vulnerability response maturity). For example, "A terminal device that has not addressed a vulnerability with a risk score of 80 for more than two months is defined as a dangerous terminal device, and if an average of two vulnerabilities with a risk score of 80 are detected per month for a terminal device, then a terminal device with four or more vulnerabilities with a risk score of 80 is defined as a dangerous terminal device, which is a worse condition than that."

[0039] (Math 3) S3 = Imm × γ S3: Score (Third evaluation result information) Imm: Number of terminal devices with a number of vulnerabilities equal to or greater than the threshold Th. γ: weight

[0040] In the example in Figure 3, since the threshold Th is set to 5, terminal F is detected as a dangerous terminal among the multiple information processing devices (terminal devices) 20 managed by system 100, specifically terminal C which has 5 or more vulnerabilities Smm. Therefore, if the weight γ is set to 40, the score S3 will be 160 (= 4 × 40).

[0041] Score S3 accurately represents the number of dangerous terminal devices in system 100 if there are many terminal devices that are above the threshold Th and have a number of vulnerabilities close to the threshold Th (for example, if there are 5 terminal devices above the threshold Th, and 5 of those terminal devices have a number of vulnerabilities close to the threshold Th). However, if there are many terminal devices that are above the threshold Th and do not have a number of vulnerabilities close to the threshold Th, for example, if there are 5 terminal devices above the threshold Th, and 4 of those terminal devices have a number of vulnerabilities around 10, and one terminal device has more than 32 vulnerabilities, then score S3 cannot accurately represent the number of dangerous terminal devices. In such cases, the second evaluation method is effective.

[0042] The weights α, β, and γ mentioned above were pre-set to differentiate the system evaluation information for each risk level of System 100, as described later. In other words, the pre-set weights α, β, and γ are applied to calculate the first, second, and third evaluation information in order to differentiate the system evaluation information for each risk level of the system.

[0043] The weights α, β, and γ are set so that there is a case where the values ​​of scores S1, S2, and S3 are each at their maximum, in order to grasp the vulnerability trend. While adhering to the above policy, the weighting should be changed according to the situation of the deployment environment and the security response policy. For example, if there are a very large number of terminal devices managed by each system, and the risk is considered to be greater due to the large number of vulnerable terminal devices, the value of γ should be set high. Alternatively, if there are terminal devices that use special software, and it is desired to make it easier to identify vulnerabilities when they are found in that software, the value of β should be set high. As for α, it exists to assign weight to the case of a risk score of 80 compared to a risk score of 60 in the calculation of the score of how many vulnerabilities exist per device, so α must be > 1.0.

[0044] The calculation unit 13 integrates the base score BS, which corresponds to the risk level of the vulnerability set for system 100, and the evaluation result information (scores S1, S2, S3) for each evaluation method, to generate system evaluation information (total score ST), which represents the evaluation of the system.

[0045] The vulnerability severity is a risk score that represents the level of vulnerability present within System 100. Risk scores can be categorized into levels such as 100, 80, and 60. However, risk scores are not limited to those mentioned above.

[0046] The baseline evaluation information is a pre-set score (base score) for the degree of vulnerability (risk score). Figure 4 is a diagram illustrating an example of system evaluation information. In the example in Figure 4, if the risk score is "100", the baseline evaluation information is associated with "10000" as the base score; if the risk score is "80", the base score is associated with "100"; and if the risk score is "60" or less, the base score is associated with "0". However, the method of setting the baseline evaluation information is not limited to the method described above.

[0047] The base score is set such that, for example, it is extremely rare for more than 100 new vulnerabilities with a risk score of 60 to be detected on a single device within a month, and if left unattended for more than two months, vulnerabilities with a risk score of 80 are often detected. Therefore, the base score for a risk score of 80 is set to "100". Furthermore, when calculations were performed on actual systems with a risk score of 80 vulnerability, using weights of α=10, β=10, and γ=40, no systems exceeded a total score of "10000". Therefore, it is conceivable to set the base score for a risk score of 100 to "10000". In other words, the base score is set so that if even one instance of a risk score of 100 exists, the result will be greater than if there were a considerable number of instances of a risk score of 80.

[0048] In the example in Figure 4, if the risk score is "100", the system evaluation information (total score ST) is the base score BS. In that case, the total score ST will be "10000". Also, if the risk score is "80", the total score ST will be the sum of the base score BS and scores S1, S2, and S3 (=SB+S1+S2+S3). If the risk score is "60", the total score ST will be the sum of the base score BS and score S1 (=SB+S1).

[0049] The output unit 12 first determines vulnerability trend information, which represents the vulnerability trend, based on the evaluation result information (scores S1, S2, S3) for each evaluation method.

[0050] Next, the output unit 12 generates output information by converting at least the vulnerability trend information and system evaluation information (total score ST) for each system into an output-ready format, and transmits the output information to the output device 40, causing the vulnerability trend information and system evaluation information to be output to the output device 40. For each system, the system category name, risk score, and deadline for action may also be output to the output device 40. For example, the "category name" could be "Finance" or "Security."

[0051] (Risk score 100) If the vulnerability has the highest risk level (risk score of 100), the output unit 12 outputs text information to the output device 40 indicating that immediate action is required as vulnerability trend information.

[0052] Figure 5 is a diagram illustrating the determination of vulnerability trend information. In the example in Figure 5, if the risk score is 100, "Urgent Action Required" is selected as the vulnerability trend information.

[0053] Figure 6 is a diagram illustrating an example of a system status display. In the example in Figure 6, the system identification information "G1" is associated with the system identification information used to identify the system, and the vulnerability trend information "Urgent Action Required" and system evaluation information (total score ST) are output to the output device 40. Furthermore, a deadline for action, such as "Within 7 days of the action request," may also be output.

[0054] (Risk score 80) (A) Vulnerability trends of score S1 If the first evaluation result information (score S1) has a higher evaluation value (higher score) than the second evaluation result information (score S2) and the third evaluation result information (score S3), and the second evaluation result information (score S2) and the third evaluation result information (score S3) are within a similar range, the output unit 12 will output the first vulnerability trend information corresponding to the first evaluation result information (score S1) to the output device 40.

[0055] The similarity range is a pre-defined range used to determine whether or not the scores are similar.

[0056] Specifically, even when S2 < S3 or S2 < S1, if S2 + ΔS2 ≥ S3 or S2 + ΔS2 ≥ S1 is satisfied, the message associated with S2 is displayed as a vulnerability trend. Here, ΔS2 is, for example, the value of S2 that increases in one month (ΔS2 = A1 × β).

[0057] Also, even when S3 < S1, if S3 + ΔS3 ≥ S1 is satisfied, the message associated with S3 is displayed as a vulnerability trend. Here, ΔS3 is defined as follows. ΔS3 is, for example, the value of S3 that increases in one month (ΔS3 = A2 × γ).

[0058] Note that S1 is a score calculated from the number of vulnerabilities of risk score 80 existing per unit. S2 is a score calculated from the number of vulnerabilities of risk score 80 existing in the most dangerous terminal. S3 is a score calculated based on the number of dangerous terminals.

[0059] Also, let β be the weight of S2, γ be the weight of S3, and Th be the threshold. A1 is the average number of detections of risk score 80 per month for one terminal device. A2 is the number of terminal devices in the system having [(Th - A1) or more and less than Th] vulnerability matching items of risk score 80. Note that ΔS2 and ΔS3 can be determined and changed according to the vulnerability situation (organizational vulnerability response maturity) of the target information processing device.

[0060] The first vulnerability trend information is text information indicating that the number of vulnerabilities is on average large. The first text information outputs text such as "on average large" or "on average high" to the output device 40, for example. However, the first text is not limited to the above-mentioned text.

[0061] In the example in Figure 5, if the risk score is 80, "Averagely High" is selected as the vulnerability tendency information. In the example in Figure 6, the vulnerability tendency information "Averagely High" and the system evaluation information (total score ST) "500" are output to the output device 40, associated with the system identification information "G2" used to identify the system. Furthermore, text such as "Within 14 days of the remediation request" may be displayed as the deadline for remediation.

[0062] (B) Vulnerability trends of score S2 If the second evaluation result information (score S2) has a higher evaluation value (higher score) than the first evaluation result information (score S1) and the third evaluation result information (score S3), and the first evaluation result information (score S1) and the third evaluation result information (score S3) are within a similar range, the output unit 12 will output the second vulnerability trend information corresponding to the second evaluation result information (score S2) to the output device 40.

[0063] The second vulnerability trend information is text information indicating that there are information processing devices 20 with a number of vulnerabilities in the critical range. This second text information may, for example, display text such as "Partially dangerous" on the output device 40. However, the second text is not limited to the text described above.

[0064] In the example in Figure 5, if the risk score is 80, "Partially dangerous" is selected as the vulnerability trend information. In the example in Figure 6, the vulnerability trend information "Partially dangerous" and the system evaluation information (total score ST) "180" are output to the output device 40, associated with the system identification information "G3" used to identify the system. Furthermore, text such as "Within 14 days of the request for action" may be displayed as the deadline for action.

[0065] (C) Vulnerability trends of score S3 If the third evaluation result information (score S3) has a higher evaluation value (higher score) than the first evaluation result information (score S1) and the second evaluation result information (score S2), and the first evaluation result information (score S1) and the second evaluation result information (score S2) are within a similar range, the output unit 12 will output the third vulnerability trend information corresponding to the third evaluation result information (score S3) to the output device 40.

[0066] The third type of vulnerability trend information is text information indicating that there are more than a predetermined number of information processing devices 20 with a high number of vulnerabilities. This third type of text information displays text such as "Many are dangerous" on the output device 40. However, the third type of text is not limited to the text described above.

[0067] In the example in Figure 5, if the risk score is 80, "Many dangerous vulnerabilities" is selected as the vulnerability trend information. In the example in Figure 6, the vulnerability trend information is not displayed, and instead, the system evaluation information (total score ST) "60" is output to the output device 40, associated with the system identification information "G4" used to identify the system. Furthermore, text such as "Within 14 days of the remediation request" may be displayed as the deadline for remediation.

[0068] (D) Vulnerability trends when scores are similar If the first evaluation result information, the second evaluation result information, and the third evaluation result information are the same, the output unit 12 outputs the second vulnerability trend information corresponding to the second evaluation result information. For example, it displays text such as "Partially dangerous" on the output device 40. Furthermore, it may display text such as "Within 14 days of the request for action" as a deadline for action. Depending on the risk value, the priority when they are the same is "Partially dangerous" > "Many dangerous" > "Generally high."

[0069] (Risk score 60) If the vulnerability has the highest risk level (risk score of 60), the output unit 12 outputs the deadline for remediation to the output device 40, but does not output the vulnerability trend. The deadline for remediation may be text such as "Within 30 days of the remediation request." However, the vulnerability trend may also be output to the output device 40.

[0070] [Device operation] Next, the operation of the system evaluation device in the embodiment will be described using Figure 7. Figure 7 is a diagram illustrating an example of the operation of the system evaluation device. In the following description, the diagram will be referred to as appropriate. In this embodiment, the system evaluation method is performed by operating the system evaluation device. Therefore, the explanation of the system evaluation method in this embodiment will be replaced by the following explanation of the operation of the system evaluation device.

[0071] As shown in Figure 7, first, the generation unit 11 acquires detection result information, which represents the detection results of vulnerabilities present in multiple information processing devices 20 included in the system 100, stored in the memory device 30 (step A1).

[0072] Next, the generation unit 11 uses the acquired detection result information to evaluate the vulnerability status in the system 100 for each different type of evaluation method and generates evaluation result information representing the evaluation result for each evaluation method (step A2). In step A2, evaluation result information (scores S1, S2, S3) is generated using the evaluation methods (1), (2), and (3) described above, respectively.

[0073] Next, the calculation unit 13 integrates the base score BS, which corresponds to the risk level of the vulnerability set for the system 100, and the evaluation result information for each evaluation method (scores S1, S2, S3), to generate system evaluation information (total score ST), which represents the evaluation of the system (step A3).

[0074] Next, the output unit 12 determines vulnerability trend information representing the vulnerability trend based on the evaluation result information (scores S1, S2, S3) for each evaluation method (step A4).

[0075] Next, the output unit 12 generates output information by converting at least the vulnerability trend information and system evaluation information (total score ST) for each system into an output-ready format, and transmits the output information to the output device 40 (step A5). Subsequently, the vulnerability trend information and system evaluation information are output to the output device 40. In addition, the system category name, risk score, and deadline for remediation may also be output to the output device 40 for each system.

[0076] [Effects of the Embodiment] As described above, according to the embodiment, by presenting vulnerability trend information that represents the trend of vulnerabilities corresponding to the evaluation results for each evaluation method, and system evaluation information (total score ST), it is possible to easily allow system users (e.g., managers, security personnel, etc.) to understand the detection and response status of system security, and to facilitate security measures.

[0077] [program] The program in this embodiment can be any program that causes a computer to execute steps A1 to A5 shown in Figure 7. By installing and running this program on a computer, the system evaluation device and system evaluation method in this embodiment can be realized. In this case, the computer's processor functions as a generation unit 11, an output unit 12, and a calculation unit 13, and performs the processing.

[0078] Furthermore, the program in the embodiment may be executed by a computer system constructed by multiple computers. In this case, for example, each computer may function as either the generation unit 11, the output unit 12, or the calculation unit 13.

[0079] [Physical configuration] Here, a computer that implements a system evaluation device by executing the program in the embodiment will be described using Figure 8. Figure 8 is a diagram illustrating an example of a computer that implements a system evaluation device in the embodiment.

[0080] As shown in Figure 8, the computer 110 comprises a CPU (Central Processing Unit) 111, main memory 112, storage device 113, input interface 114, display controller 115, data reader / writer 116, and communication interface 117. These components are connected to each other via a bus 121, enabling data communication. In addition to the CPU 111, or in place of the CPU 111, the computer 110 may also include a GPU or FPGA.

[0081] The CPU 111 loads the program in the embodiment, which consists of a set of codes stored in the storage device 113, into the main memory 112, and performs various calculations by executing each code in a predetermined order. The main memory 112 is typically a volatile storage device such as DRAM (Dynamic Random Access Memory).

[0082] Furthermore, the program in this embodiment is provided stored on a computer-readable recording medium 120. The program in this embodiment may also be distributed over the Internet via a communication interface 117.

[0083] Specific examples of the storage device 113 include hard disk drives and semiconductor storage devices such as flash memory. The input interface 114 mediates data transmission between the CPU 111 and input devices 118 such as a keyboard and mouse. The display controller 115 is connected to the display device 119 and controls the display on the display device 119.

[0084] The data reader / writer 116 mediates data transmission between the CPU 111 and the recording medium 120, reads programs from the recording medium 120, and writes processing results from the computer 110 to the recording medium 120. The communication interface 117 mediates data transmission between the CPU 111 and other computers.

[0085] Specific examples of the recording medium 120 include general-purpose semiconductor memory devices such as CF (Compact Flash®) and SD (Secure Digital), magnetic recording media such as Flexible Disks, and optical recording media such as CD-ROMs (Compact Disk Read Only Memory).

[0086] Furthermore, the system evaluation device 10 in this embodiment can be implemented not by a computer with a program installed, but by using hardware corresponding to each part, such as electronic circuits. Moreover, the system evaluation device 10 may be partially implemented by a program and the remaining parts by hardware. In this embodiment, the computer is not limited to the computer shown in Figure 8.

[0087] [Note] The following additional notes are disclosed regarding the embodiments described above. Some or all of the embodiments described above can be expressed by (Note 1) to (Note 33) below, but are not limited to the following descriptions.

[0088] (Note 1) A generation unit that uses detection result information representing the detection results of vulnerabilities in multiple information processing devices included in the system to evaluate the vulnerability status in the system for each different type of evaluation method, and generates evaluation result information representing the evaluation results for each evaluation method, An output unit that outputs vulnerability trend information, which represents the vulnerability trend corresponding to the worst evaluation result among the evaluation result information for each of the evaluation methods, to an output device; A system evaluation device having the following features.

[0089] (Note 2) Furthermore, the system includes a calculation unit that integrates standard evaluation information corresponding to the risk level of the vulnerability set for the system and the evaluation result information for each evaluation method to generate system evaluation information representing the evaluation of the system. The system evaluation device described in Appendix 1.

[0090] (Note 3) The evaluation result information for each of the evaluation methods is, A first evaluation result information representing a value calculated using the number of information processing devices and the number of vulnerabilities in the system, In the aforementioned system, a second evaluation result information representing the number of vulnerabilities in the most vulnerable information processing device, The system includes a third evaluation result information representing the number of information processing devices whose number of vulnerabilities is equal to or greater than a predetermined threshold, The system evaluation device described in Appendix 2.

[0091] (Note 4) The output unit is, If the first evaluation result information, the second evaluation result information, and the third evaluation result information are the same, a second vulnerability trend information corresponding to the second evaluation result information is output. The system evaluation device described in Appendix 3.

[0092] (Note 5) The output unit is, If the first evaluation result information has a higher evaluation value than the second and third evaluation result information, and the second and third evaluation result information are within a similar range, then the first vulnerability trend information corresponding to the first evaluation result information is output. The system evaluation device described in Appendix 3.

[0093] (Note 6) The output unit is, If the second evaluation result information has a higher evaluation value than the first evaluation result information and the third evaluation result information, and the first evaluation result information and the third evaluation result information are within a similar range, then a second vulnerability trend information corresponding to the second evaluation result information is output. The system evaluation device described in Appendix 3.

[0094] (Note 7) The output unit is, If the evaluation value of the third evaluation result information is higher than that of the first evaluation result information and the second evaluation result information, and the first evaluation result information and the second evaluation result information are within a similar range, a third vulnerability trend information corresponding to the third evaluation result information is output. The system evaluation device described in Appendix 3.

[0095] (Note 8) The generating unit is In order to differentiate the system evaluation information for each risk level of the aforementioned system, a predetermined weight is applied to calculate the first evaluation result information, the second evaluation result information, and the third evaluation result information. The system evaluation device described in Appendix 3.

[0096] (Note 9) The aforementioned first vulnerability trend information is text information indicating that the average number of vulnerabilities is high. The system evaluation device described in Appendix 5.

[0097] (Note 10) The second vulnerability trend information is text information indicating that there is an information processing device with a number of vulnerabilities in the critical range. The system evaluation device described in Appendix 6.

[0098] (Note 11) The third vulnerability trend information includes text information indicating that there are more than a predetermined number of information processing devices with a large number of vulnerabilities. The system evaluation device described in Appendix 7.

[0099] (Note 12) Computers Using detection result information representing the detection results of vulnerabilities in multiple information processing devices included in the system, the vulnerability status in the system is evaluated for each different type of evaluation method, and evaluation result information representing the evaluation results for each evaluation method is generated. The output device outputs vulnerability trend information, which represents the vulnerability trend corresponding to the worst evaluation result among the evaluation result information for each of the aforementioned evaluation methods. System evaluation method.

[0100] (Note 13) Furthermore, the computer, System evaluation information representing an evaluation of the system is generated by integrating the standard evaluation information corresponding to the risk level of the vulnerability set for the system and the evaluation result information for each evaluation method. The system evaluation method described in Appendix 12.

[0101] (Note 14) The evaluation result information for each of the evaluation methods is, A first evaluation result information representing a value calculated using the number of information processing devices and the number of vulnerabilities in the system, In the aforementioned system, a second evaluation result information representing the number of vulnerabilities in the most vulnerable information processing device, The system includes a third evaluation result information representing the number of information processing devices whose number of vulnerabilities is equal to or greater than a predetermined threshold, The system evaluation method described in Appendix 13.

[0102] (Note 15) The aforementioned computer, If the first evaluation result information, the second evaluation result information, and the third evaluation result information are the same, a second vulnerability trend information corresponding to the second evaluation result information is output. The system evaluation method described in Appendix 14.

[0103] (Note 16) The aforementioned computer, If the first evaluation result information has a higher evaluation value than the second and third evaluation result information, and the second and third evaluation result information are within a similar range, then the first vulnerability trend information corresponding to the first evaluation result information is output. The system evaluation method described in Appendix 14.

[0104] (Note 17) The aforementioned computer, If the second evaluation result information has a higher evaluation value than the first evaluation result information and the third evaluation result information, and the first evaluation result information and the third evaluation result information are within a similar range, then a second vulnerability trend information corresponding to the second evaluation result information is output. The system evaluation method described in Appendix 14.

[0105] (Note 18) The aforementioned computer, If the evaluation value of the third evaluation result information is higher than that of the first evaluation result information and the second evaluation result information, and the first evaluation result information and the second evaluation result information are within a similar range, a third vulnerability trend information corresponding to the third evaluation result information is output. The system evaluation method described in Appendix 14.

[0106] (Note 19) The aforementioned computer, In order to differentiate the system evaluation information for each risk level of the aforementioned system, a predetermined weight is applied to calculate the first evaluation result information, the second evaluation result information, and the third evaluation result information. The system evaluation method described in Appendix 14.

[0107] (Note 20) The aforementioned first vulnerability trend information is text information indicating that the average number of vulnerabilities is high. The system evaluation method described in Appendix 16.

[0108] (Note 21) The second vulnerability trend information is text information indicating that there is an information processing device with a number of vulnerabilities in the critical range. The system evaluation method described in Appendix 17.

[0109] (Note 22) The third vulnerability trend information includes text information indicating that there are more than a predetermined number of information processing devices with a large number of vulnerabilities. The system evaluation method described in Appendix 18.

[0110] (Note 23) On the computer, Using detection result information representing the detection results of vulnerabilities in multiple information processing devices included in the system, the vulnerability status in the system is evaluated for each different type of evaluation method, and evaluation result information representing the evaluation results for each evaluation method is generated. The output device outputs vulnerability trend information, which represents the vulnerability trend corresponding to the worst evaluation result among the evaluation result information for each of the aforementioned evaluation methods. program.

[0111] (Note 24) Furthermore, the computer, System evaluation information representing an evaluation of the system is generated by integrating the standard evaluation information corresponding to the risk level of the vulnerability set for the system and the evaluation result information for each evaluation method. The program described in Appendix 23.

[0112] (Note 25) The evaluation result information for each of the evaluation methods is, A first evaluation result information representing a value calculated using the number of information processing devices and the number of vulnerabilities in the system, In the aforementioned system, a second evaluation result information representing the number of vulnerabilities in the most vulnerable information processing device, The system includes a third evaluation result information representing the number of information processing devices whose number of vulnerabilities is equal to or greater than a predetermined threshold, The program described in Appendix 24.

[0113] (Note 26) To the aforementioned computer, If the first evaluation result information, the second evaluation result information, and the third evaluation result information are the same, the second vulnerability trend information corresponding to the second evaluation result information is output. The program described in Appendix 25.

[0114] (Note 27) To the aforementioned computer, If the first evaluation result information has a higher evaluation value than the second and third evaluation result information, and the second and third evaluation result information are within a similar range, then the first vulnerability trend information corresponding to the first evaluation result information is output. The program described in Appendix 25.

[0115] (Note 28) To the aforementioned computer, If the second evaluation result information has a higher evaluation value than the first and third evaluation result information, and the first and third evaluation result information are within a similar range, then a second vulnerability trend information corresponding to the second evaluation result information is output. The program described in Appendix 25.

[0116] (Note 29) To the aforementioned computer, If the evaluation value of the third evaluation result information is higher than that of the first and second evaluation result information, and the first and second evaluation result information are within a similar range, a third vulnerability trend information corresponding to the third evaluation result information is output. The program described in Appendix 25.

[0117] (Note 30) To the aforementioned computer, In order to differentiate the system evaluation information for each risk level of the aforementioned system, a predetermined weight is applied to calculate the first evaluation result information, the second evaluation result information, and the third evaluation result information. The program described in Appendix 25.

[0118] (Note 31) The aforementioned first vulnerability trend information is text information indicating that the average number of vulnerabilities is high. The program described in Appendix 27.

[0119] (Note 32) The second vulnerability trend information is text information indicating that there is an information processing device with a number of vulnerabilities in the critical range. The program described in Appendix 28.

[0120] (Note 33) The third vulnerability trend information includes text information indicating that there are more than a predetermined number of information processing devices with a large number of vulnerabilities. The program described in Appendix 29.

[0121] Although the invention has been described above with reference to embodiments, the invention is not limited to the embodiments described above. Various modifications to the structure and details of the invention can be made that will be understood by those skilled in the art within the scope of the invention. [Industrial applicability]

[0122] As described above, it makes it easy to understand the detection and response status of system security, and simplifies security measures. It is also useful in areas where vulnerability analysis is necessary. [Explanation of Symbols]

[0123] 10 System evaluation device 11 Generation part 12 Output section 13 Calculation Section 20, 20a, 20b, 20c Terminal devices 30 Storage device 40 Output device 50 Networks 100 Systems 110 Computer 111 CPU 112 Main Memory 113 Storage device 114 Input Interface 115 Display Controller 116 Data Readers / Writers 117 Communication Interface 118 Input devices 119 Display device 120 recording media 121 Bus

Claims

1. A generation means that uses detection result information representing the detection results of vulnerabilities in multiple information processing devices included in the system to evaluate the vulnerability status in the system for each different type of evaluation method, and generates evaluation result information representing the evaluation results for each evaluation method, An output means that causes an output device to output vulnerability trend information representing the vulnerability trend corresponding to the worst evaluation result among the evaluation result information for each of the evaluation methods, A system evaluation device having the following features.

2. Furthermore, the system has a calculation means that integrates standard evaluation information corresponding to the risk level of the vulnerability set for the system and the evaluation result information for each evaluation method to generate system evaluation information representing the evaluation of the system. The system evaluation apparatus according to claim 1.

3. The evaluation result information for each of the evaluation methods is, A first evaluation result information representing a value calculated using the number of information processing devices and the number of vulnerabilities in the system, In the aforementioned system, a second evaluation result information representing the number of vulnerabilities in the most vulnerable information processing device, The system includes a third evaluation result information representing the number of information processing devices whose number of vulnerabilities is equal to or greater than a predetermined threshold, The system evaluation apparatus according to claim 2.

4. The output means is If the first evaluation result information, the second evaluation result information, and the third evaluation result information are the same, a second vulnerability trend information corresponding to the second evaluation result information is output. The system evaluation apparatus according to claim 3.

5. The output means is If the first evaluation result information has a higher evaluation value than the second and third evaluation result information, and the second and third evaluation result information are within a similar range, then the first vulnerability trend information corresponding to the first evaluation result information is output. The system evaluation apparatus according to claim 4.

6. The output means is If the second evaluation result information has a higher evaluation value than the first evaluation result information and the third evaluation result information, and the first evaluation result information and the third evaluation result information are within a similar range, then a second vulnerability trend information corresponding to the second evaluation result information is output. The system evaluation apparatus according to claim 5.

7. The output means is If the evaluation value of the third evaluation result information is higher than that of the first evaluation result information and the second evaluation result information, and the first evaluation result information and the second evaluation result information are within a similar range, a third vulnerability trend information corresponding to the third evaluation result information is output. The system evaluation apparatus according to claim 6.

8. The aforementioned first vulnerability trend information is text information indicating that the average number of vulnerabilities is high. The second vulnerability trend information is text information indicating that there is an information processing device with a number of vulnerabilities in the critical range. The third vulnerability trend information includes text information indicating that there are more than a predetermined number of information processing devices with a large number of vulnerabilities. The system evaluation apparatus according to claim 7.

9. Computers Using detection result information representing the detection results of vulnerabilities in multiple information processing devices included in the system, the vulnerability status in the system is evaluated for each different type of evaluation method, and evaluation result information representing the evaluation results for each evaluation method is generated. The output device outputs vulnerability trend information, which represents the vulnerability trend corresponding to the worst evaluation result among the evaluation result information for each of the aforementioned evaluation methods. System evaluation method.

10. On the computer, Using detection result information representing the detection results of vulnerabilities in multiple information processing devices included in the system, the vulnerability status in the system is evaluated for each different type of evaluation method, and evaluation result information representing the evaluation results for each evaluation method is generated. The output device outputs vulnerability trend information, which represents the vulnerability trend corresponding to the worst evaluation result among the evaluation result information for each of the aforementioned evaluation methods. program.