Determination device, determination method, and program

JP2026142598APending Publication Date: 2026-09-08NEC CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2025029660
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-02-27
Publication Date
2026-09-08

AI Technical Summary

Benefits of technology

【0010】 本開示によれば、情報セキュリティに関する規範に沿って、脆弱性対応における作業者の意思決定を支援する判定結果を提示できる判定装置、判定方法、およびプログラムを提供することが可能になる。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026142598000001_ABST
    Figure 2026142598000001_ABST
Patent Text Reader

Abstract

This invention provides a determination device that can present determination results to support workers' decision-making in vulnerability response, in accordance with information security standards. [Solution] The determination device comprises: an acquisition unit that acquires a vulnerability identifier that uniquely identifies a vulnerability; a search unit that searches for vulnerability information identified by the vulnerability identifier by referring to a database in which vulnerability information for each vulnerability identifier is registered; a generation unit that generates an instruction to determine whether or not action is required for the vulnerability identified by the vulnerability identifier, using the vulnerability information identified by the vulnerability identifier and standards concerning information security; and an output unit that outputs determination data including the determination result output from the model in accordance with the instruction.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to a determination apparatus, a determination method, and a program. [Background Art]

[0002] With the increasing importance of information security, vulnerability countermeasures in compliance with various norms such as guidelines, standards, laws and regulations, and internal rules are required. These norms play an important role in strengthening an organization's security posture and protecting the organization from potential threats. Security personnel in an organization need to analyze these guidelines and the like in detail, evaluate their relevance to vulnerabilities existing in their own organization, and determine whether countermeasures are necessary. However, the contents of guidelines and the like are often complex and diverse, and considerable time and effort are required for their understanding and application.

[0003] Patent Document 1 discloses an information processing apparatus that supports investigation of vulnerabilities in target software. The apparatus of Patent Document 1 includes a vulnerability database, a matching unit, a causal factor identification unit, a type determination unit, and an output unit. The vulnerability database stores one or more pieces of vulnerability information including a vulnerability identifier that uniquely identifies a vulnerability, a software identifier that uniquely identifies software containing the vulnerability, and a vulnerability description indicating the content of the vulnerability. The matching unit identifies, in the vulnerability database, vulnerability information that matches the software identifier of target software installed in a target device. The causal factor identification unit identifies a causal factor that causes a vulnerability from the vulnerability description in the vulnerability information identified by the matching unit. The type determination unit determines the type of the causal factor from the name of the identified causal factor. The output unit determines an investigation method for a vulnerability in the target software based on the software identifier of the target software and the type of the causal factor, and outputs information indicating the investigation method. [Prior Art Documents] [Patent Documents]

[0004] [Patent Document 1] Japanese Patent Publication No. 2024-042396 [Overview of the project] [Problems that the invention aims to solve]

[0005] The method described in Patent Document 1 focuses on identifying vulnerabilities and determining investigation methods. However, the method in Patent Document 1 does not evaluate the relationship with various guidelines, standards, laws, internal regulations, and other norms. Therefore, with the method in Patent Document 1, workers were unable to make decisions in accordance with information security norms when addressing vulnerabilities.

[0006] The purpose of this disclosure is to provide a determination device, determination method, and program that can present determination results that support worker decision-making in vulnerability response in accordance with information security standards. [Means for solving the problem]

[0007] A determination device according to one aspect of this disclosure includes: an acquisition unit that acquires a vulnerability identifier that uniquely identifies a vulnerability; a search unit that searches for vulnerability information identified by a vulnerability identifier by referring to a database in which vulnerability information for each vulnerability identifier is registered; a generation unit that generates an instruction to determine whether or not action is required for the vulnerability identified by the vulnerability identifier, using the vulnerability information identified by the vulnerability identifier and standards relating to information security; and an output unit that outputs determination data including the determination result output from the model in accordance with the instruction.

[0008] In one aspect of the determination method of this disclosure, a computer obtains a vulnerability identifier that uniquely identifies a vulnerability, searches for vulnerability information associated with the vulnerability identifier by referring to a database in which vulnerability information for each vulnerability identifier is registered, generates an instruction to determine whether action is required for the vulnerability identified by the vulnerability identifier using the vulnerability information identified by the vulnerability identifier and standards concerning information security, and outputs determination data including the determination result output from the model in accordance with the instruction.

[0009] A program in one aspect of this disclosure causes a computer to perform the following processes: obtaining a vulnerability identifier that uniquely identifies a vulnerability; searching for vulnerability information associated with a vulnerability identifier by referring to a database in which vulnerability information for each vulnerability identifier is registered; generating instructions to determine whether action is required for the vulnerability identified by the vulnerability identifier, using the vulnerability information identified by the vulnerability identifier and information security standards; and outputting determination data including the determination result output from the model in response to the instructions. [Effects of the Invention]

[0010] This disclosure makes it possible to provide a determination device, determination method, and program that can present determination results that support worker decision-making in vulnerability response in accordance with information security standards. [Brief explanation of the drawing]

[0011] [Figure 1] This block diagram shows an example of the configuration related to the determination device in this disclosure. [Figure 2] This block diagram shows an example of the configuration of the determination device in this disclosure. [Figure 3] This table shows an example of vulnerability information stored in the database referenced by the determination device in this embodiment. [Figure 4] This information shows an example of the normative information referenced by the determination device in this embodiment. [Figure 5] This is a conceptual diagram showing an example of a prompt generated by the determination device in this disclosure. [Figure 6] This is a conceptual diagram showing an example of a prompt generated by the determination device in this disclosure. [Figure 7] This is a conceptual diagram showing an example of how attack information output from the detection device in this disclosure is displayed. [Figure 8] This flowchart shows an example of the operation of the determination device in this disclosure. [Figure 9] It is a flowchart showing an example of determination processing by a determination device according to the present disclosure. [Figure 10] It is a conceptual diagram showing an example of normative information referred to by a determination device according to the present disclosure. [Figure 11] It is a conceptual diagram showing an example of a prompt generated by a determination device according to the present disclosure. [Figure 12] It is a conceptual diagram showing an example of a prompt generated by a determination device according to the present disclosure. [Figure 13] It is a conceptual diagram showing an example where a user interface that accepts input of an answer to a question output from a determination device according to the present disclosure is displayed on a screen of a terminal device. [Figure 14] It is a conceptual diagram showing an example of a prompt generated by a determination device according to the present disclosure. [Figure 15] It is a conceptual diagram showing an example of normative information referred to by a determination device according to the present disclosure. [Figure 16] It is a conceptual diagram showing an example of a prompt generated by a determination device according to the present disclosure. [Figure 17] It is a conceptual diagram showing an example of a prompt generated by a determination device according to the present disclosure. [Figure 18] It is a conceptual diagram showing an example of normative information referred to by a determination device according to the present disclosure. [Figure 19] It is a conceptual diagram showing an example of a prompt generated by a determination device according to the present disclosure. [Figure 20] It is a conceptual diagram showing an example of a prompt generated by a determination device according to the present disclosure. [Figure 21] It is a block diagram showing an example of the configuration of a determination device according to the present disclosure. [Figure 22] It is a conceptual diagram showing an example of a vulnerability diagnosis report acquired by a determination device according to the present disclosure. [Figure 23] It is a conceptual diagram showing an example in which a determination device according to the present disclosure extracts a vulnerability identifier from a vulnerability diagnosis report. [Figure 24] It is a flowchart showing an example of the operation of a determination device according to the present disclosure. [Figure 25] This flowchart shows an example of the determination process performed by the determination device in this disclosure. [Figure 26] This block diagram shows an example of the configuration of the determination device in this disclosure. [Figure 27] This flowchart shows an example of the operation of the determination device in this disclosure. [Figure 28] A diagram showing an example of a hardware configuration for performing the processing described in this disclosure. [Modes for carrying out the invention]

[0012] The embodiments for carrying out this disclosure will be described below with reference to the drawings. In this disclosure, the drawings used in the description of each embodiment are associated with one or more embodiments. Also, the elements included in each drawing may apply to one or more embodiments. The embodiments described below have technically preferred limitations for carrying out this disclosure, but the scope of the disclosure is not limited thereto. In all the drawings used in the description of the embodiments below, the same parts are denoted by the same reference numerals unless there is a specific reason not to. In the embodiments below, repeated descriptions of similar configurations and operations may be omitted. The direction of the arrows in the drawings is an example of the flow of signals, data, etc., and does not limit the flow of signals, data, etc.

[0013] (First Embodiment) First, the determination device according to the first embodiment will be described with reference to the drawings. The determination device of this embodiment presents the worker performing vulnerability management with a vulnerability determination result in accordance with information security standards. Information security standards are matters to be implemented or followed regarding information security. For example, information security standards include guidelines, standards, laws and regulations, and internal rules. The content of these standards is complex. Therefore, understanding these standards requires considerable effort. The determination device of this embodiment reduces the effort required of the worker by supporting the worker's decision-making in vulnerability response in accordance with information security standards.

[0014] In the following, the criteria for vulnerabilities that need to be addressed, as described in guidelines, standards, laws, internal regulations, and other norms, will also be referred to as vulnerability assessment indicators. The base value, current value, and environmental value of CVSS (Common Vulnerability Scoring System) are examples of vulnerability assessment indicators. EPSS (Exploit Prediction Scoring System) and VPR (Vulnerability Priority Rating) are examples of vulnerability assessment indicators. Flags indicating the presence or absence of a public PoC (Proof of Concept) and flags indicating the presence or absence of an attack are examples of vulnerability assessment indicators. These vulnerability assessment indicators may be defined individually or in combination.

[0015] (composition) Figure 1 is a block diagram showing an example of the configuration related to the determination device in this disclosure. The determination device 10 is connected to the terminal device 180 and the LLM system 150 via a network such as the Internet or an intranet. The determination device 10 is a device that performs processing related to vulnerability management. For example, the determination device 10 has functions such as analyzing the results of vulnerability management, evaluating vulnerabilities, and proposing security measures. Details of the determination device 10 will be described later.

[0016] Terminal device 180 is an information processing device (computer) used for vulnerability management in managed systems. Terminal device 180 provides an interface for operators to access the results of vulnerability assessments and penetration tests, as well as the asset register. Application software for performing vulnerability management is installed on terminal device 180. Terminal device 180 identifies vulnerabilities in managed systems by executing processes set by the operator. For example, terminal device 180 identifies vulnerabilities by performing vulnerability scans or penetration tests on managed systems. The functionality of the application software for performing vulnerability scans and penetration tests may be built on a server or cloud accessible from terminal device 180. Also, for example, terminal device 180 identifies vulnerabilities in managed systems by referring to an asset register that lists the software and / or software versions used within the managed systems. The asset register that lists the software and / or software versions used within the managed systems may be built on a server or cloud accessible from terminal device 180. Terminal device 180 may be implemented as a general-purpose computer. Furthermore, the terminal device 180 may be implemented by a dedicated computer for performing vulnerability identification.

[0017] The terminal device 180 outputs information (vulnerability identifiers) indicating vulnerabilities identified in the managed system to the determination device 10. The vulnerability identifier is an identifier used to uniquely identify vulnerabilities in the system. For example, the vulnerability identifier may be a CVE (Common Vulnerabilities and Exposures) number or the ID (Identifier) ​​of a detection item by a vulnerability scanner. The vulnerability identifier may be something other than a CVE number or a detection item ID by a vulnerability scanner, as long as it can uniquely identify the vulnerability. Vulnerabilities in a broad sense also include configuration defects. For example, one example of a configuration defect is when anonymous FTP (File Transfer Protocol) is enabled. Information about vulnerabilities for each vulnerability identifier (vulnerability information) is stored in advance in the database (described later) of the determination device 10.

[0018] For example, terminal device 180 may be configured to output the attack history of the penetration test performed by the operator to judgment device 10. The attack history of the attack performed in the penetration test includes at least one attack method performed for each attack step and the attack details relating to the results of the performed attack method. The attack method is selected by the operator. For example, the attack method may be one of Tactic, Technique, Procedure, or tool name. For example, the attack method may be defined as a combination of Tactic, Technique, Procedure, or tool name. For example, the attack details may be the command used in the attack, its options, and the result of executing the command.

[0019] For example, attack methods include network attacks, web application attacks, authentication / access control attacks, social engineering, system-level attacks, and highly targeted attacks. For example, network attacks include port scanning, man-in-the-middle attacks, denial-of-service attacks, and DNS (Domain Name System) poisoning. For example, network attacks include ARP (Address Resolution Protocol) spoofing and wireless network attacks. For example, web application attacks include SQL (Structured Query Language) injection, cross-site scripting, session hijacking, and directory traversal. For example, authentication / access control attacks include password cracking and privilege escalation. For example, social engineering includes phishing. For example, system-level attacks include buffer overflow attacks, memory corruption attacks, and reverse shells. For example, highly targeted attacks include exploiting zero-day vulnerabilities, ransomware attack simulations, and supply chain attack simulations.

[0020] The LLM system 150 is a system that performs processing using a large-scale language model (not shown). The large-scale language model (also called the model) is a deep learning model trained on a large-scale language dataset. The LLM system 150 uses the large-scale language model to output text information corresponding to the content of text information composed of natural language. The LLM system 150 uses the large-scale language model to provide vulnerability management results in easily understandable text information. In other words, the LLM system 150 converts complex security information into a format that is easy for humans to understand. For example, the LLM system 150 outputs an answer in response to a question input. The LLM system 150 may also be a model capable of inputting and outputting images and audio. For example, the LLM system 150 is a system that can be used via an API (Application Programming Interface). The LLM system 150 may be configured to use a dedicated model built for performing vulnerability management. As long as it can be accessed from the judgment device 10, there are no limitations on the type of large-scale language model used by the LLM system 150 or the location where the LLM system 150 is deployed.

[0021] [Judgment device] Next, an example of the configuration of the determination device 10 will be described with reference to the drawings. Figure 2 is a block diagram showing an example of the configuration of the determination device in this disclosure. The determination device 10 includes an acquisition unit 11, a search unit 13, an instruction unit 15, and an output unit 17. The determination device 10 also includes a database 130. The database 130 may be configured outside the determination device 10, provided that it is accessible from the determination device 10. The instruction unit 15 is connected to the LLM system 150.

[0022] The acquisition unit 11 is connected to a terminal device 180 used by the worker. The acquisition unit 11 acquires vulnerability identifiers from the terminal device 180 used by the worker, indicating vulnerabilities identified in vulnerability management. For example, the acquisition unit 11 acquires vulnerability identifiers indicating vulnerabilities detected by a vulnerability scanner. For example, vulnerability identifiers may include CVE numbers or vulnerability scanner plug-in IDs.

[0023] Database 130 is configured as a storage device that can be connected to by the determination device 10. Database 130 stores vulnerability information and normative information. Database 130 may be an external database in which vulnerability information for each vulnerability identifier is publicly available. In that case, database 130 does not need to be included in the determination device 10. For example, database 130 is configured as a dedicated database specifically for vulnerability assessment of managed systems. For example, using a dedicated database in which paid information purchased from another vendor is registered can lead to more accurate determinations. In such cases, database 130 may be configured inside or outside the device. For example, the determination device 10 may be configured to refer to both an external database and a dedicated database. In that case, the determination device 10 can more accurately determine responses to vulnerabilities by referring to publicly available data stored in the external database and private data stored in the dedicated database. For example, database 130 may use a relational database management system that enables high-speed query processing and efficient management of large amounts of data. If attack history information is normalized and stored using multiple tables, data integrity is maintained, and flexible searching and analysis become possible.

[0024] Vulnerability information is information associated with vulnerability identifiers. For example, vulnerability information is information summarized in a table format, associated with vulnerability identifiers. For example, vulnerability information includes base values, current values, and environmental values ​​from the Common Vulnerability Scoring System (CVSS). For example, vulnerability information includes EPSS (Exploit Prediction Scoring System) and VPR (Vulnerability Priority Rating). For example, vulnerability information includes flags indicating the presence or absence of a public Proof of Concept (PoC) or the occurrence of an attack. For example, vulnerability information is the category of the vulnerability.

[0025] Figure 3 is a table showing an example of vulnerability information stored in the database referenced by the detection device in this embodiment. The vulnerability information table V stores multiple data for each vulnerability identifier, with a key indicating vulnerability information and a corresponding value associated with that key in a one-to-one correspondence. As shown in the example in Figure 3, each key is associated with a unique value. For example, the value of "CVSS base score" for vulnerability identifier CVE-aaaa-bbbbb is "8.1". For example, the value of "Public PoC" for vulnerability identifier CVE-aaaa-bbbbb is the flag "Yes". For example, the value of "Attack Occurred" for vulnerability identifier CVE-aaaa-bbbbb is the flag "Yes". For example, the value of "Description" for vulnerability identifier CVE-aaaa-ddddd is the information that "This is a vulnerability in a device called DD, and if this vulnerability is exploited, a remote attacker may be able to cause a DoS state."

[0026] Normative information includes information about norms such as guidelines, standards, laws, and internal regulations related to information security. For example, normative information may be documents related to norms such as guidelines, standards, laws, and internal regulations related to information security. For example, normative information may be information extracted from documents related to norms such as guidelines, standards, laws, and internal regulations related to information security. Vulnerability information and normative information may be stored in databases constructed on different storage devices.

[0027] Figure 4 shows an example of normative information referenced by the determination device in this embodiment. For example, normative information N is a document relating to norms such as guidelines, standards, laws, and internal regulations concerning information security. For example, normative information N includes norms concerning cybersecurity vulnerabilities. For example, normative information N is a norm concerning cybersecurity operations.

[0028] The search unit 13 searches the database 130 for vulnerability information associated with vulnerability identifiers. For example, the search unit 13 retrieves data including key-value pairs as vulnerability information. The search unit 13 also searches the database 130 for normative information referenced in vulnerability management. For example, the search unit 13 may be configured to search for vulnerability information and normative information via the internet.

[0029] The instruction unit 15 acquires vulnerability information and normative information retrieved by the search unit 13. The instruction unit 15 generates prompts (also called instructions) using the acquired vulnerability information and normative information. The functional configuration of the instruction unit 15 that generates prompts (instructions) is also called the generation unit. The instruction unit 15 inputs the generated prompts to the LLM system 150. In this embodiment, the instruction unit 15 generates a first prompt and a second prompt.

[0030] The instruction unit 15 generates a first prompt for inputting the content of the normative information into the LLM system 150. The first prompt includes the content of the normative information. The instruction unit 15 generates the first prompt using a pre-configured template. The template for generating the first prompt includes an instruction statement that instructs setting the content of the normative information as a prerequisite. The instruction unit 15 inputs the generated first prompt into the LLM system 150.

[0031] The instruction unit 15 acquires text information output from the LLM system 150 in response to the input of the first prompt. The text information output from the LLM system 150 in response to the input of the first prompt corresponds to the answer to the first prompt. The answer to the first prompt becomes a trigger for the determination device 10 to input the second prompt to the LLM system 150.

[0032] Figure 5 is a conceptual diagram showing an example of a prompt generated by the determination device in this disclosure. Figure 5 shows an example of a first prompt P1 generated by the determination device 10. The first prompt P1 includes information indicating an instruction and a norm. The instruction includes the text information, "Please understand the following norm." The norm includes the sentence relating to the norm exemplified in Figure 4. Figure 5 also shows the response A1 output from the LLM system 150 in response to the input of the first prompt P1. Response A1 includes the text information, "I understand," indicating that the content of the first prompt P1 has been set as a prerequisite in the LLM system 150.

[0033] Furthermore, the instruction unit 15 generates a second prompt that instructs the LLM system 150 to determine whether or not action is required for the vulnerability indicated by the vulnerability identifier. The second prompt includes an instruction to determine whether or not action is required for the vulnerability indicated by the vulnerability identifier. The instruction unit 15 generates the second prompt using a pre-configured template. The instruction unit 15 inputs the generated second prompt to the LLM system 150. The instruction unit 15 may be configured to generate a prompt in which the contents of the first prompt and the second prompt are unified. In that case, the prompt includes an instruction to set the contents of normative information as a prerequisite and an instruction to determine whether or not action is required for the vulnerability indicated by the vulnerability identifier.

[0034] The instruction unit 15 acquires text information (judgment result) output from the LLM system 150 in response to the input of the second prompt. The text information output from the LLM system 150 in response to the input of the second prompt corresponds to the answer to the second prompt. The answer to the second prompt includes the judgment result regarding whether or not action is required for the vulnerability indicated by the vulnerability identifier.

[0035] Figure 6 is a conceptual diagram showing an example of a prompt generated by the determination device in this disclosure. Figure 6 shows an example of a second prompt P2 generated by the determination device 10. The second prompt P2 includes an instruction and vulnerability information associated with a vulnerability identifier. The instruction includes the text information, "Determine whether action is required for the following vulnerability according to the guidelines." The vulnerability information includes multiple data with one-to-one key-value pairs corresponding to the vulnerability identifier. Figure 6 also shows the response A2 output from the LLM system 150 in response to the input of the second prompt P2. Response A2 includes the text information, "A patch application is required." Response A2 includes the determination result of whether action is required for the vulnerability indicated by the vulnerability identifier, based on the information input by the first prompt P1.

[0036] In the above description, the instruction unit 15 inputs information to the LLM system 150 using the first prompt and the second prompt and obtains the result of the determination of whether or not action is required for the vulnerability, but is not limited to this. For example, instead of the first prompt in the above description, the instruction unit 15 may input information to the LLM system 150 using RAG (Retrieval-Augmented Generation) or fine tuning. For example, the instruction unit 15 may generate a single prompt that includes both the information included in the first prompt and the information included in the second prompt. In that case, the instruction unit 15 inputs the single prompt to the LLM system 150 and obtains text information regarding the result of the determination of whether or not action is required for the vulnerability output from the LLM system 150.

[0037] The output unit 17 is connected to a terminal device 180 used by the operator. The output unit 17 obtains the determination result regarding whether or not action is required for the vulnerability indicated by the vulnerability identifier from the instruction unit 15. The output unit 17 outputs the determination data, including the obtained determination result, to the terminal device 180. The determination result included in the determination data output to the terminal device 180 is displayed on the screen of the terminal device 180.

[0038] Figure 7 is a conceptual diagram showing an example of the display of attack information output from the detection device in this disclosure. At the top of the terminal device 180 screen, a vulnerability identifier indicating the vulnerability identified in vulnerability management is displayed. The terminal device 180 screen displays text information indicating the detection result, "Patch application is required." The terminal device 180 screen also displays patch information, "Security Patch SP1." Furthermore, the terminal device 180 screen displays a link to the patch information. In addition, the terminal device 180 screen displays a UI (User Interface) that accepts patch application. In the example in Figure 7, a button for applying the patch is displayed. A cursor for selecting the button is hovered over the button for applying the patch. The operator can consider applying the patch by viewing the information displayed on the terminal device 180 screen.

[0039] (operation) Next, an example of the operation of the determination device in this disclosure will be described with reference to the drawings. Figure 8 is a flowchart of an example of the operation of the determination device in this disclosure. In the explanation of the process according to the flowchart in Figure 8, the components of the determination device 10 will be considered the main operating entities. The main operating entities of the process according to the flowchart in Figure 8 may also be the determination device 10. For example, the process according to the flowchart in Figure 8 is realized by a processor executing a program stored in the memory installed in a computer (not shown) on which the determination device 10 is implemented.

[0040] In Figure 8, first, the acquisition unit 11 acquires the vulnerability identifier identified in the managed system (step S11).

[0041] Next, the search unit 13 searches the database 130 for vulnerability information associated with the vulnerability identifier (step S12). The search unit 13 may be configured to search for vulnerability information via the internet.

[0042] Next, the instruction unit 15 executes a determination process (step S13). Details of the determination process in step S13 will be described later.

[0043] Next, the output unit 17 outputs judgment data including the documented judgment result (step S14). The judgment result output from the judgment device 10 is displayed on the screen of the terminal device 180 used for vulnerability management.

[0044] [Decision process] Next, an example of the determination process by the determination device in this disclosure (step S13 in Figure 8) will be described with reference to the drawings. Figure 9 is a flowchart of an example of the determination process by the determination device in this disclosure. In the explanation of the process according to the flowchart in Figure 9, the components of the determination device 10 (instruction unit 15) will be considered the main operating entity. The main operating entity of the process according to the flowchart in Figure 9 may also be the determination device 10.

[0045] In Figure 9, first, the instruction unit 15 generates a first prompt for setting normative information in the LLM system 150 (step S131).

[0046] Next, the instruction unit 15 inputs the generated first prompt to the LLM system 150 (step S132). The instruction unit 15 then retrieves the text information output from the LLM system 150 in response to the input of the first prompt.

[0047] Next, the instruction unit 15 generates a second prompt instructing the LLM system 150 to determine whether or not action is required to address the vulnerability (step S133).

[0048] Next, the instruction unit 15 inputs the generated second prompt to the LLM system 150 (step S134).

[0049] Next, the instruction unit 15 acquires text information including the judgment result output from the LLM system 150 (step S135). Following step S135, the process proceeds to step S14 in the flowchart of Figure 8.

[0050] (modified version) Next, modifications of this embodiment will be described with reference to the drawings. Three modifications are given below. The following modifications are examples of processing by the determination device of this embodiment and do not limit the processing by the determination device of this embodiment.

[0051] [Variation 1] Figures 10 to 14 are conceptual diagrams relating to Modification 1. This modification is an example in which the LLM system 150 presents a user interface to the operator that requests input of auxiliary information for determining whether or not action is required for a vulnerability. The auxiliary information is information that is missing or that helps to make a more appropriate determination in determining whether or not action is required for a vulnerability. The auxiliary information is requested from the determination device 10 by the LLM system 150 in order to determine whether or not action is required for a vulnerability.

[0052] Figure 10 is a conceptual diagram showing an example of normative information referenced by the determination device in this disclosure. Normative information N-1 specifies that when a software vulnerability is discovered on a server, a decision should be made on whether or not to apply a patch based on the value of the vulnerability assessment index. For example, when a software vulnerability is discovered on an externally accessible server, the CVSS base value of the vulnerability should be checked, and if the CVSS base value is 7.0 or higher, a patch should be applied. For example, when a software vulnerability is discovered on another server, the CVSS base value of the vulnerability should be checked, and if the CVSS base value is 9.0 or higher, a patch should be applied.

[0053] Figure 11 is a conceptual diagram showing an example of a prompt generated by the determination device in this disclosure. Figure 11 shows an example of a first prompt P1-1 generated by the determination device 10. The first prompt P1-1 includes information indicating an instruction and a norm. The instruction includes the text information, "Please understand the following norm." The norm includes the sentence relating to the norm exemplified in Figure 10. Figure 11 also shows the response A1-1 output from the LLM system 150 in response to the input of the first prompt P1-1. Response A1-1 includes the text information, "I understand," indicating that the content of the first prompt P1-1 has been set as a prerequisite in the LLM system 150.

[0054] Figure 12 is a conceptual diagram showing an example of a prompt generated by the determination device in this disclosure. Figure 12 shows the second prompt P2-1-1 generated by the determination device 10. The second prompt P2-1-1 includes an instruction and vulnerability information associated with a vulnerability identifier. The instruction includes text information such as, "Determine whether action is required for the following vulnerability according to the guidelines. If you lack the information necessary to make a decision, please ask a question." The vulnerability information includes multiple data points in which keys and values ​​corresponding to vulnerability identifiers are associated one-to-one. Figure 12 also shows the response A2-1-1 output from the LLM system 150 in response to the input of the second prompt P2-1-1. Response A2-1-1 includes text information indicating a question to the operator, "Is the server containing this vulnerability an externally exposed server?" Response A2-1-1 also includes text information requesting input of auxiliary information to determine whether action is required for the vulnerability.

[0055] Figure 13 is a conceptual diagram showing an example of a user interface displayed on the screen of a terminal device that accepts input of answers to questions output from the determination device in this disclosure. The IP address and port number of the target of the attack are displayed at the top of the screen of terminal device 180. Text information requesting input of supplementary information, "Is the server containing this vulnerability an externally exposed server?" is displayed on the screen of terminal device 180. A user interface for inputting supplementary information (supplementary information reception UI) is also displayed on the screen of terminal device 180. The supplementary information reception UI displays a text area for inputting supplementary information. If the number of characters that can be entered is small, a text box may be placed instead of a text area. The supplementary information reception UI also displays a button for sending the supplementary information entered by the worker to the determination device 10. For example, a worker who has viewed the information prompting input of supplementary information displayed on the screen of terminal device 180 enters the supplementary information in response to the request from the LLM system 150 into the text area. The supplementary information entered into the text area is sent to the determination device 10 when the button labeled "Send" is clicked. If there is no supplementary information to enter, the operator does not need to enter any. In that case, the operator can simply click the button labeled "Submit" with the text area left blank. If the button labeled "Submit" is clicked without any supplementary information entered in the text area, the system may be configured to send information indicating that there is no supplementary information to the determination device 10. Alternatively, if the button labeled "Submit" is clicked without any supplementary information entered in the text area, the system may be configured to display a pop-up on the terminal device 180 screen containing a message requesting the input of supplementary information.

[0056] Figure 14 is a conceptual diagram showing an example of a prompt generated by the determination device in this disclosure. Figure 14 shows the second prompt P2-1-2 generated by the determination device 10. The second prompt P2-1-2 contains the answer entered by the operator to the question included in answer A2-1-1 in Figure 13. The second prompt P2-1-2 includes text information indicating the answer entered by the operator, "No". The "No" information included in the second prompt P2-1-2 corresponds to the auxiliary information that "the server containing the vulnerability is not an externally exposed server". Figure 14 also shows the answer A2-1-2 output from the LLM system 150 in response to the input of the second prompt P2-1-2. Answer A2-1-2 includes the text information that "No patch application is required." Based on the auxiliary information, answer A2-1-2 includes the determination result of whether or not action is required for the vulnerability indicated by the vulnerability identifier.

[0057] In this modified version, the operator is required to input any missing information or information necessary for a more accurate determination of whether or not to take action against a vulnerability. In this modified version, the operator's inputted supplementary information is used to determine whether or not to take action against a vulnerability. According to this modified version, by using the supplementary information input by the operator, it becomes possible to present the operator with a more accurate response.

[0058] [Variation 2] Figures 15-17 are conceptual diagrams relating to Modification 2. This modification is an example of generating a prompt that includes instructions to suggest a response method for a vulnerability identified by a vulnerability identifier. For example, a response method for a vulnerability may include avoiding, mitigating, transferring, or accepting the risks caused by the vulnerability.

[0059] Figure 15 is a conceptual diagram showing an example of normative information referenced by the determination device in this disclosure. Normative information N-2 specifies the response for each risk caused by vulnerabilities. For example, for vulnerabilities in the system that have been confirmed to be targeted by attacks, it is specified that a patch should be applied. For example, even for vulnerabilities that have not been confirmed to be targeted by attacks, it is specified that a patch should be applied or the risk reduced by virtual patching if the CVSS base score is 7.0 or higher.

[0060] Figure 16 is a conceptual diagram showing an example of a prompt generated by the determination device in this disclosure. Figure 16 shows an example of a first prompt P1-2 generated by the determination device 10. The first prompt P1-2 includes information indicating an instruction and a norm. The instruction includes the text information, "Please understand the following norm." The norm includes the sentence relating to the norm exemplified in Figure 15. Figure 16 also shows the response A1-2 output from the LLM system 150 in response to the input of the first prompt P1-2. Response A1-2 includes the text information, "I understand," indicating that the content of the first prompt P1-2 has been set as a prerequisite in the LLM system 150.

[0061] Figure 17 is a conceptual diagram showing an example of a prompt generated by the determination device in this disclosure. Figure 17 shows the second prompt P2-2 generated by the determination device 10. The second prompt P2-2 includes an instruction and vulnerability information associated with a vulnerability identifier. The instruction includes the text information, "Please provide a response method (avoid, mitigate, transfer, or accept) for the following vulnerability in accordance with the standard." The vulnerability information includes multiple data points in which keys and values ​​corresponding to the vulnerability identifier are associated one-to-one. Figure 17 also shows the response A2-2 output from the LLM system 150 in response to the input of the second prompt P2-2. Response A2-2 includes a response method for the vulnerability, "Risk avoidance by patching or risk reduction by virtual patching is required."

[0062] In this modified version, a prompt is generated that includes instructions to propose a course of action for the vulnerability identified by the vulnerability identifier. The worker needs to determine, based on the established criteria, not only whether or not action is required for the identified vulnerability, but also whether to avoid, mitigate, transfer, or accept it. This modified version makes it possible to present the worker with specific methods for addressing the vulnerability.

[0063] [Example 3] Figures 18-20 are conceptual diagrams relating to Modification 3. This modification is an example of generating a prompt that includes instructions to extract information on how to address vulnerabilities from the standard.

[0064] Figure 18 is a conceptual diagram showing an example of normative information referenced by the judgment device in this disclosure. Normative information N-3 describes countermeasures for vulnerabilities. The countermeasures for vulnerabilities described in normative information N-3 are scattered throughout the text of the norm. Therefore, it takes a lot of effort for an ordinary worker to extract the countermeasures for vulnerabilities. For example, normative information N-3 may specify that for vulnerabilities in the system that attacks targeting those vulnerabilities have been confirmed, patches should be applied. For example, normative information N-3 may specify that even for vulnerabilities for which attacks have not been confirmed, patches should be applied if the CVSS base score is 7.0 or higher.

[0065] Figure 19 is a conceptual diagram showing an example of a prompt generated by the determination device in this disclosure. Figure 19 shows an example of the first prompt P1-3 generated by the determination device 10. The first prompt P1-3 includes information indicating instructions and norms. The instructions include the text information, "Extract the section relating to vulnerability management from the following security norms." The norms include the text relating to the norms exemplified in Figure 18. Figure 19 also shows the response A1-3 output from the LLM system 150 in response to the input of the first prompt P1-3. Response A1-3 includes text information indicating the response to the vulnerability extracted from the norm, "When a software vulnerability is discovered, check the CVSS base value of the vulnerability, and if the CVSS base value is 7.0 or higher, apply a patch."

[0066] Figure 20 is a conceptual diagram showing an example of a prompt generated by the determination device in this disclosure. Figure 20 shows the second prompt P2-3 generated by the determination device 10. The second prompt P2-3 includes instructions, the relevant section of the standard regarding vulnerability management, and vulnerability information associated with a vulnerability identifier. The instructions include the text information, "Determine whether action is required for the following vulnerability according to the relevant section of the standard. If you lack the information necessary to make a decision, please ask a question." The relevant section of the standard regarding vulnerability management is indicated by the text information, "A software vulnerability has been discovered..." The vulnerability information includes multiple data points in which key-value pairs corresponding to vulnerability identifiers are associated one-to-one. Figure 20 also shows the response A2-3 output from the LLM system 150 in response to the input of the second prompt P2-3. Response A2-3 includes the determination result for the vulnerability, "No patch application is required."

[0067] In this modified version, descriptions related to vulnerabilities are extracted from the standard. In this modified version, the need for action against vulnerabilities is determined by referring to the extracted descriptions. In this modified version, sentences related to vulnerabilities are extracted from many descriptions in the standard that also include matters other than vulnerabilities. Therefore, according to this modified version, matters other than vulnerabilities in the standard are not examined, making the determination of the need for action against vulnerabilities more efficient.

[0068] As described above, the determination device of this embodiment comprises an acquisition unit, a search unit, an instruction unit, and an output unit. The acquisition unit acquires a vulnerability identifier that uniquely identifies a vulnerability. The search unit searches for vulnerability information identified by the vulnerability identifier by referring to a database in which vulnerability information for each vulnerability identifier is registered. The instruction unit generates a prompt that includes an instruction to determine whether action is required for the vulnerability identified by the vulnerability identifier, using the vulnerability information identified by the vulnerability identifier and norms related to information security. The norms are at least one of the following: guidelines, standards, laws and regulations, and internal rules related to information security. The output unit outputs determination data including the determination result output from the large-scale language model in response to the prompt.

[0069] In this embodiment, the necessity of addressing vulnerabilities is determined using information security standards. Therefore, according to this embodiment, a determination result can be presented that supports the worker's decision-making in addressing vulnerabilities in accordance with information security standards.

[0070] In one embodiment of this system, the search unit refers to an external database where vulnerability information for each vulnerability identifier is publicly available, and searches for vulnerability information associated with that vulnerability identifier. According to this embodiment, using the publicly available vulnerability information for each vulnerability identifier, a determination result can be presented to support the worker's decision-making.

[0071] In one embodiment of this system, vulnerability information associated with a vulnerability identifier is searched by referring to a dedicated database containing vulnerability information for each vulnerability identifier specifically tailored to vulnerability assessments of managed systems. According to this embodiment, a judgment result suitable for the operation of the managed system can be presented using vulnerability information for each vulnerability identifier specifically tailored to vulnerability assessments of managed systems.

[0072] In one embodiment of this system, the instruction unit receives a request from the large-scale language model for auxiliary information to determine whether or not action is required for a vulnerability identified by a vulnerability identifier. The output unit outputs a user interface requesting input of auxiliary information. The acquisition unit acquires the auxiliary information input via the user interface. The instruction unit inputs a prompt containing the acquired auxiliary information to the large-scale language model. According to this embodiment, by using the auxiliary information input by the operator, it becomes possible to present the operator with a more accurate response.

[0073] In one embodiment of this design, the instruction unit generates a prompt that includes instructions to present a method for addressing a vulnerability identified by a vulnerability identifier, in accordance with a set of guidelines. This design makes it possible to present specific actions to the operator to avoid the risks associated with the vulnerability.

[0074] In one embodiment of this design, the instruction unit generates a prompt that includes an instruction to extract from the standard the description of the vulnerability identified by the vulnerability identifier. According to this design, since the standard does not verify anything other than vulnerabilities, the determination of whether or not action is required for a vulnerability is made more efficient.

[0075] (Second Embodiment) Next, the determination device according to the second embodiment will be described with reference to the drawings. The determination device of this embodiment differs from the first embodiment in that it determines whether or not action is required for a vulnerability based on a vulnerability assessment report, instead of a vulnerability identifier identified in the managed system. A vulnerability assessment report is a list of vulnerabilities contained in a specific host or system. The vulnerability assessment report includes vulnerability identifiers that indicate vulnerabilities contained in a specific host or system. For example, a vulnerability assessment report is the result of a scan by a vulnerability scanner. A vulnerability assessment report includes multiple vulnerability identifiers. Therefore, the determination device of this embodiment also differs from the second embodiment in that it handles multiple vulnerability identifiers.

[0076] The determination device of this embodiment is connected to a terminal device and LLM system similar to those of the first embodiment via a network such as the Internet or an intranet. In this embodiment, details of the terminal device and LLM system will not be described. In addition, in this embodiment, content that overlaps with the first embodiment will be described in a simplified manner.

[0077] (composition) Figure 21 is a block diagram showing an example of the configuration of the determination device in this disclosure. The determination device 20 comprises an acquisition unit 21, a search unit 23, an instruction unit 25, and an output unit 27. The determination device 20 also comprises a database 230. The database 230 may be configured outside the determination device 20, provided that it is accessible from the determination device 20. The instruction unit 25 is connected to the LLM system 250.

[0078] The acquisition unit 21 acquires a vulnerability assessment report that includes a list of vulnerabilities contained in a specific host or system. The vulnerability assessment report includes multiple vulnerability identifiers. For example, the acquisition unit 21 acquires a vulnerability assessment report that includes the scan results of a vulnerability scanner. For example, the acquisition unit 21 may be configured to acquire a publicly available vulnerability assessment report. The vulnerability assessment report includes vulnerability identifiers that indicate vulnerabilities contained in a specific host or system. For example, vulnerability identifiers may include CVE numbers or vulnerability scanner plug-in IDs.

[0079] Figure 22 is a conceptual diagram showing an example of a vulnerability assessment report obtained by the assessment device in this disclosure. The vulnerability assessment report R includes a list of vulnerabilities on host H. For example, the vulnerability assessment report R includes vulnerabilities with vulnerability identifier CVE-aaaa-bbbbb and vulnerabilities with vulnerability identifier CVE-aaaa-ddddd.

[0080] The extraction unit 22 extracts vulnerability identifiers included in the vulnerability assessment report. For example, the extraction unit 22 extracts CVE numbers and vulnerability scanner plugin IDs included in the vulnerability assessment report.

[0081] Figure 23 is a conceptual diagram showing an example of how the determination device in this disclosure extracts vulnerability identifiers from a vulnerability assessment report. The extraction unit 22 extracts vulnerability identifiers from a list of vulnerabilities in host H included in the vulnerability assessment report. For example, the extraction unit 22 extracts vulnerability identifiers such as vulnerability identifier CVE-aaaa-bbbbb and vulnerability identifier CVE-aaaa-ddddd from vulnerability assessment report R.

[0082] Database 230 has the same configuration as database 130 in the first embodiment. Database 230 stores vulnerability information and normative information. Vulnerability information is information associated with vulnerability identifiers. For example, vulnerability information is information compiled in a table format, with information associated with vulnerability identifiers. Normative information includes information on norms such as guidelines, standards, laws, and internal regulations related to information security. For example, normative information is a document relating to norms such as guidelines, standards, laws, and internal regulations related to information security. For example, normative information may be information extracted from a document relating to norms such as guidelines, standards, laws, and internal regulations related to information security.

[0083] The search unit 23 has the same configuration as the search unit 13 in the first embodiment. The search unit 23 searches the database 230 for vulnerability information associated with each vulnerability identifier. For example, the search unit 23 retrieves data including key and value as vulnerability information. The search unit 23 also searches the database 230 for normative information referenced in vulnerability management. For example, the search unit 23 may be configured to search for vulnerability information and normative information via the internet.

[0084] The instruction unit 25 obtains vulnerability information and normative information retrieved for each vulnerability identifier by the search unit 23. The instruction unit 25 generates a first prompt for inputting the contents of the normative information into the LLM system 250. The first prompt contains the contents of the normative information. The instruction unit 25 generates the first prompt using a pre-configured template. The template for generating the first prompt includes an instruction statement that instructs setting the contents of the normative information as a prerequisite. For example, the instruction unit 25 may be configured to generate a first prompt and a second prompt for each vulnerability identifier to obtain whether action is required for each vulnerability identifier. Alternatively, the instruction unit 25 may be configured to generate a first prompt and a second prompt for all target vulnerability identifiers at once to obtain whether action is required for each vulnerability identifier. In this case, the second prompt contains the vulnerability information for all vulnerability identifiers. The instruction unit 25 inputs the generated first prompt into the LLM system 250.

[0085] The instruction unit 25 acquires text information output from the LLM system 250 in response to the input of the first prompt. The text information output from the LLM system 250 in response to the input of the first prompt corresponds to the answer to the first prompt. The answer to the first prompt becomes a trigger for the determination device 20 to input the second prompt to the LLM system 250.

[0086] Furthermore, the instruction unit 25 generates a second prompt that instructs the LLM system 250 to determine whether or not action is required for the vulnerability indicated by the vulnerability identifier. The second prompt includes an instruction to determine whether or not action is required for the vulnerability indicated by the vulnerability identifier. The instruction unit 25 generates the second prompt using a pre-configured template. The instruction unit 25 inputs the generated second prompt to the LLM system 250. The instruction unit 25 may be configured to generate a prompt in which the contents of the first prompt and the second prompt are unified. In that case, the prompt includes an instruction to set the contents of normative information as a prerequisite and an instruction to determine whether or not action is required for the vulnerability indicated by the vulnerability identifier.

[0087] The instruction unit 25 acquires text information (judgment result) output from the LLM system 250 in response to the input of the second prompt. The text information output from the LLM system 250 in response to the input of the second prompt corresponds to the answer to the second prompt. The answer to the second prompt includes the judgment result of whether or not action is required for the vulnerability indicated by the vulnerability identifier.

[0088] In the above description, the instruction unit 25 inputs information to the LLM system 250 using the first prompt and the second prompt and obtains the result of the determination of whether or not action is required for the vulnerability, but is not limited to this. For example, instead of the first prompt in the above description, the instruction unit 25 may input information to the LLM system 250 using RAG (Retrieval-Augmented Generation) or fine tuning. For example, the instruction unit 25 may generate a single prompt that includes both the information included in the first prompt and the information included in the second prompt. In that case, the instruction unit 25 inputs the single prompt to the LLM system 250 and obtains text information regarding the result of the determination of whether or not action is required for the vulnerability output from the LLM system 250.

[0089] The output unit 27 is connected to a terminal device (not shown) used by the operator. For each vulnerability identifier, the output unit 27 obtains the determination result of whether or not action is required for the vulnerability indicated by the vulnerability identifier from the instruction unit 25. The output unit 27 outputs the determination data, including the obtained determination result, to the terminal device. The determination result included in the determination data output to the terminal device is displayed on the screen of that terminal device.

[0090] (operation) Next, an example of the operation of the determination device in this disclosure will be described with reference to the drawings. Figure 24 is a flowchart of an example of the operation of the determination device in this disclosure. In the explanation of the process according to the flowchart in Figure 24, the components of the determination device 20 will be considered the main operating entities. The main operating entities of the process according to the flowchart in Figure 24 may also be the determination device 20. For example, the process according to the flowchart in Figure 24 is realized by a processor executing a program stored in the memory installed in a computer (not shown) on which the determination device 20 is implemented.

[0091] In Figure 24, first, the acquisition unit 21 acquires a vulnerability assessment report (step S21). For example, the acquisition unit 21 acquires a vulnerability assessment report that includes the scan results of a vulnerability scanner. For example, the acquisition unit 21 may be configured to acquire a publicly available vulnerability assessment report.

[0092] Next, the extraction unit 22 extracts vulnerability identifiers included in the vulnerability assessment report (step S22). The vulnerability assessment report contains multiple vulnerability identifiers.

[0093] Next, the search unit 23 searches the database 230 for vulnerability information associated with each of the multiple vulnerability identifiers (step S23). The search unit 23 may be configured to search for vulnerability information via the internet.

[0094] Next, the instruction unit 25 executes a determination process (step S24). Details of the determination process in step S24 will be described later.

[0095] Next, the output unit 27 outputs judgment data including the documented judgment result (step S25). The judgment result output from the judgment device 20 is displayed on the screen of the terminal device used to perform vulnerability management.

[0096] [Decision process] Next, an example of the determination process by the determination device in this disclosure (step S24 in Figure 24) will be described with reference to the drawings. Figure 25 is a flowchart showing an example of the determination process by the determination device in this disclosure. In the explanation of the process according to the flowchart in Figure 25, the components of the determination device 20 (instruction unit 25) will be considered the main operating entity. The main operating entity of the process according to the flowchart in Figure 25 may also be the determination device 20.

[0097] In Figure 25, first, the instruction unit 25 generates a first prompt for setting normative information in the LLM system 250 (step S241).

[0098] Next, the instruction unit 25 inputs the generated first prompt to the LLM system 250 (step S242). The instruction unit 25 then retrieves the text information output from the LLM system 250 in response to the input of the first prompt.

[0099] Next, the instruction unit 25 generates a second prompt instructing the LLM system 250 to determine whether or not action is required to address the vulnerability (step S243).

[0100] Next, the instruction unit 25 inputs the generated second prompt to the LLM system 250 (step S244).

[0101] Next, the instruction unit 25 acquires text information containing the judgment result output from the LLM system 250 (step S245). Following step S245, the process proceeds to step S25 in the flowchart of Figure 24.

[0102] As described above, the determination device of this embodiment comprises an acquisition unit, an extraction unit, a search unit, an instruction unit, and an output unit. The acquisition unit acquires a vulnerability assessment report containing a vulnerability identifier that uniquely identifies a vulnerability. The extraction unit extracts at least one vulnerability identifier from the vulnerability assessment report. The search unit searches for vulnerability information identified by the vulnerability identifier by referring to a database in which vulnerability information for each vulnerability identifier is registered. The instruction unit generates a prompt that includes an instruction to determine whether action is required for the vulnerability identified by the vulnerability identifier, using the vulnerability information identified by the vulnerability identifier and norms related to information security. The norms are at least one of the following: guidelines, standards, laws and regulations, and internal rules related to information security. The output unit outputs determination data including the determination result output from the large-scale language model in response to the prompt.

[0103] In this embodiment, the necessity of taking action against a vulnerability is determined using vulnerability identifiers extracted from a vulnerability assessment report and standards related to information security. Therefore, according to this embodiment, even if a specific vulnerability identifier is not identified, a determination result that supports the worker's decision-making regarding vulnerability response can be presented based on the vulnerability assessment report. Furthermore, according to this embodiment, a determination result that supports the worker's decision-making can be presented regarding vulnerabilities indicated by multiple vulnerability identifiers included in the vulnerability assessment report.

[0104] (Third embodiment) Next, the determination device in the third embodiment will be described with reference to the drawings. The determination device in this embodiment has a simplified configuration compared to the determination devices in the first and second embodiments. For example, the functions of the components of the determination device in this embodiment are realized by the functions of the components of the determination devices in the first and second embodiments.

[0105] (composition) Figure 26 is a block diagram showing an example of the configuration of the determination device in this disclosure. The determination device 30 comprises an acquisition unit 31, a search unit 33, a generation unit 35, and an output unit 37.

[0106] The acquisition unit 31 acquires a vulnerability identifier that uniquely identifies the vulnerability. The search unit 33 searches for vulnerability information identified by the vulnerability identifier by referring to a database in which vulnerability information for each vulnerability identifier is registered. The generation unit 35 uses the vulnerability information identified by the vulnerability identifier and the standards concerning information security to generate an instruction to determine whether or not action is required for the vulnerability identified by the vulnerability identifier. The output unit 37 outputs judgment data, including the judgment result output from the model in accordance with the instruction.

[0107] (operation) Figure 27 is a flowchart showing an example of the operation of the determination device in this disclosure. In the explanation of the process according to the flowchart in Figure 27, the components of the determination device 30 are considered the main operating entities. The main operating entities of the process according to the flowchart in Figure 27 may also be the determination device 30.

[0108] The acquisition unit 31 acquires a vulnerability identifier that uniquely identifies the vulnerability (step S31).

[0109] The search unit 33 refers to a database in which vulnerability information for each vulnerability identifier is registered and searches for vulnerability information identified by the vulnerability identifier (step S32).

[0110] The generation unit 35 uses the vulnerability information identified by the vulnerability identifier and the norms concerning information security to generate instructions for determining whether or not action is required for the vulnerability identified by the vulnerability identifier (step S33).

[0111] The output unit 37 outputs judgment data, including the judgment result output from the model, in accordance with the instruction (step S34).

[0112] In this embodiment, the necessity of addressing vulnerabilities is determined using information security standards. Therefore, according to this embodiment, a determination result can be presented that supports the worker's decision-making in addressing vulnerabilities in accordance with information security standards.

[0113] (Hardware) Next, the hardware configuration for performing the processing described in this disclosure will be described with reference to the drawings. Figure 28 is a block diagram showing an example of a hardware configuration for performing the processing described in this disclosure. Here, an information processing device 90 (computer) is shown as an example of a hardware configuration. The information processing device in Figure 28 is an example configuration for performing the processing described in this disclosure and does not limit the scope of this disclosure.

[0114] As shown in Figure 28, the information processing device 90 comprises a processor 91, memory 92, auxiliary storage device 93, input / output interface 95, and communication interface 96. In Figure 28, interface is abbreviated as I / F (Interface). The information processing device 90 may include at least one or more of the processor 91, memory 92, auxiliary storage device 93, input / output interface 95, and communication interface 96. The processor 91, memory 92, auxiliary storage device 93, input / output interface 95, and communication interface 96 are connected to each other via a bus 98 so that they can communicate data. In addition, the processor 91, memory 92, auxiliary storage device 93, and input / output interface 95 are connected to a network such as the Internet or an intranet via the communication interface 96.

[0115] The processor 91 loads a program (instruction) stored in an auxiliary storage device 93 or the like into memory 92. For example, the program is a software program for executing the processing described in this disclosure. The processor 91 executes the program loaded into memory 92. The processor 91 executes the processing described in this disclosure by executing the program. The processor 91 may be composed of a single piece of hardware or of multiple pieces of hardware.

[0116] Memory 92 is a storage device having an area where programs are deployed. The processor 91 deploys programs stored in auxiliary storage devices 93, etc., into memory 92. Memory 92 can be implemented using volatile memory such as DRAM (Dynamic Random Access Memory). Alternatively, non-volatile memory such as MRAM (Magnetoresistive Random Access Memory) may be used as memory 92. Memory 92 may be composed of a single piece of hardware or multiple pieces of hardware.

[0117] The auxiliary storage device 93 stores various data, such as programs. For example, the auxiliary storage device 93 can be implemented by a local disk such as a hard disk or flash memory. The auxiliary storage device 93 may be configured by a single piece of hardware or by multiple pieces of hardware. The auxiliary storage device 93 may also be configured as external hardware. It is also possible to configure the system to store various data in memory 92 and omit the auxiliary storage device 93.

[0118] The input / output interface 95 is an interface for connecting the information processing device 90 to peripheral devices based on standards and specifications. The communication interface 96 is an interface for connecting to external systems and devices via a network such as the Internet or an intranet, based on standards and specifications. The input / output interface 95 may be composed of a single piece of hardware or multiple pieces of hardware. The input / output interface 95 and the communication interface 96 may be common as interfaces for connecting to external devices.

[0119] The information processing device 90 may be connected to input devices such as a keyboard, mouse, or touch panel, as needed. These input devices are used to input information and settings. When a touch panel is used as an input device, the screen with touch panel functionality serves as the interface. The processor 91 and the input devices are connected via an input / output interface 95.

[0120] The information processing device 90 may be equipped with a display device for displaying information. If a display device is provided, the information processing device 90 is equipped with a display control device (not shown) for controlling the display of the display device. The information processing device 90 and the display device are connected via an input / output interface 95.

[0121] The information processing device 90 may be equipped with a drive device. The drive device mediates between the processor 91 and the recording medium (program recording medium) by reading data and programs stored on the recording medium and writing the processing results of the information processing device 90 to the recording medium. The information processing device 90 and the drive device are connected via an input / output interface 95.

[0122] The above is an example of a hardware configuration that enables the processing described in this disclosure. The hardware configuration in Figure 28 is an example of a hardware configuration for executing the processing described in this disclosure and does not limit the scope of this disclosure. A program that causes a computer to execute the processing described in this disclosure is also included in the scope of this disclosure.

[0123] A program recording medium that stores a program for performing the processing in this embodiment is also included in the scope of the present invention. For example, the program recording medium is a computer-readable, non-transient recording medium. The recording medium can be implemented as an optical recording medium such as a CD (Compact Disc) or DVD (Digital Versatile Disc). The recording medium may also be implemented as a semiconductor recording medium such as a USB (Universal Serial Bus) memory or an SD (Secure Digital) card. Furthermore, the recording medium may be implemented as a magnetic recording medium such as a flexible disk, or other recording media.

[0124] The components in this disclosure may be combined in any way. The components in this disclosure may be implemented by software. The components in this disclosure may be implemented by circuitry. The components in this disclosure may be implemented by cloud computing.

[0125] Although the present disclosure has been described above with reference to embodiments, the present disclosure is not limited to the embodiments described above. Various modifications to the structure and details of the present disclosure can be made as can be understood by those skilled in the art within the scope of the present disclosure. Furthermore, each embodiment can be combined with other embodiments as appropriate.

[0126] Some or all of the above embodiments may also be described as follows, but are not limited to the following. In the following appendices, the dependents of each category may also be dependent on other categories. The descriptions included in the following appendices are significant as grounds for amendment. (Note 1) An acquisition unit that obtains a vulnerability identifier that uniquely identifies the vulnerability, A search unit that searches for vulnerability information identified by a vulnerability identifier by referring to a database in which vulnerability information for each vulnerability identifier is registered, A generation unit generates instructions for determining whether action is required for a vulnerability identified by the vulnerability identifier, using vulnerability information identified by the vulnerability identifier and standards concerning information security. A determination device comprising: an output unit that outputs determination data including the determination result output from the model in accordance with the aforementioned instructions. (Note 2) The aforementioned norm is the determination device described in Appendix 1, which is at least one of the following: information security guidelines, standards, laws and regulations, and internal rules. (Note 3) The aforementioned search unit, The determination device described in Appendix 2 searches for vulnerability information associated with a vulnerability identifier by referring to an external database in which vulnerability information for each vulnerability identifier is publicly available. (Note 4) The aforementioned search unit, The determination device described in Appendix 2 searches for vulnerability information associated with a vulnerability identifier by referring to a dedicated database containing vulnerability information for each vulnerability identifier, which is specialized for vulnerability assessment of managed systems. (Note 5) It includes an extraction unit that extracts vulnerability identifiers from vulnerability assessment reports, The acquisition unit is, Obtaining the aforementioned vulnerability assessment report, The extraction unit is The determination device described in Appendix 1, which extracts at least one vulnerability identifier from the acquired vulnerability assessment report. (Note 6) The generating unit is The model receives a request for auxiliary information to determine whether action is required for the vulnerability identified by the vulnerability identifier, The output unit is, Output a user interface that requests the input of auxiliary information. The acquisition unit is, The auxiliary information entered via the user interface is acquired, The generating unit is A determination device according to any one of appendices 1 to 5 that generates a prompt including the acquired auxiliary information. (Note 7) The generating unit is A determination device according to any one of the appendices 1 to 5 that generates instructions to provide a method for addressing the vulnerability identified by the vulnerability identifier, in accordance with the aforementioned standards. (Note 8) The generating unit is A determination device according to any one of the appendices 1 to 5 that generates instructions for extracting a description of a vulnerability identified by the vulnerability identifier from the standard. (Note 9) Computers Obtain a vulnerability identifier that uniquely identifies the vulnerability, Referencing a database containing vulnerability information for each vulnerability identifier, search for vulnerability information associated with the said vulnerability identifier. Using the vulnerability information identified by the vulnerability identifier and the standards concerning information security, an instruction is generated to determine whether or not action is required for the vulnerability identified by the vulnerability identifier. A determination method that outputs determination data including the determination result output from the model in accordance with the above instructions. (Note 10) On the computer, The process of obtaining a vulnerability identifier that uniquely identifies a vulnerability, A process of searching for vulnerability information associated with a vulnerability identifier by referring to a database in which vulnerability information for each vulnerability identifier is registered, A process that generates an instruction to determine whether action is required for the vulnerability identified by the vulnerability identifier, using the vulnerability information identified by the vulnerability identifier and the standards concerning information security. A program that causes a computer to perform a process that outputs judgment data, including the judgment result output from the model in accordance with the aforementioned instructions. Furthermore, some or all of the configurations described in Appendices 2 to 8, which are subordinate to Appendice 1 above, may also be subordinate to Appendices 9 and 10 in the same way as those described in Appendices 2 to 8. Moreover, not limited to Appendices 1, 9, and 10, some or all of the configurations described as appendices may also be subordinate to various hardware, software, various recording means for recording software, or systems, without departing from the embodiments described above. [Explanation of Symbols]

[0127] 10, 20, 30 Judgment device 11, 21, 31 Acquisition part 13, 23, 33 Search section 15, 25 Instruction section 17, 27, 37 Output section 22 Extraction part 35 Generation part 130, 230 databases 150, 250 LLM system 180 Terminal devices

Claims

1. An acquisition unit that obtains a vulnerability identifier that uniquely identifies the vulnerability, A search unit that searches for vulnerability information identified by a vulnerability identifier by referring to a database in which vulnerability information for each vulnerability identifier is registered, A generation unit generates an instruction to determine whether or not action is required for a vulnerability identified by the vulnerability identifier, using the vulnerability information identified by the vulnerability identifier and the standards for information security. A determination device comprising: an output unit that outputs determination data including the determination result output from the model in accordance with the aforementioned instructions.

2. The determination device according to claim 1, wherein the aforementioned norm is at least one of the following: guidelines, standards, laws and regulations, and internal rules concerning information security.

3. The aforementioned search unit, The determination device according to claim 2, which searches for vulnerability information associated with a vulnerability identifier by referring to an external database in which vulnerability information for each vulnerability identifier is publicly available.

4. The aforementioned search unit, The determination device according to claim 2, which searches for vulnerability information associated with a vulnerability identifier by referring to a dedicated database that stores vulnerability information for each vulnerability identifier, which is specialized for vulnerability assessment of managed systems.

5. It includes an extraction unit that extracts vulnerability identifiers from vulnerability assessment reports, The acquisition unit is, Obtaining the aforementioned vulnerability assessment report, The extraction unit is The determination device according to claim 1, which extracts at least one vulnerability identifier from the acquired vulnerability assessment report.

6. The generating unit is The model receives a request for auxiliary information to determine whether action is required for the vulnerability identified by the vulnerability identifier, The output unit is, Output a user interface that requests the input of auxiliary information. The acquisition unit is, The auxiliary information entered via the user interface is acquired, The generating unit is A determination device according to any one of claims 1 to 5 that generates a prompt including the acquired auxiliary information.

7. The generating unit is A determination device according to any one of claims 1 to 5, which generates instructions to provide a method for addressing a vulnerability identified by the vulnerability identifier, in accordance with the aforementioned standards.

8. The generating unit is A determination device according to any one of claims 1 to 5, which generates instructions for extracting a description of a vulnerability identified by the vulnerability identifier from the standard.

9. Computers Obtain a vulnerability identifier that uniquely identifies the vulnerability, Referencing a database containing vulnerability information for each vulnerability identifier, search for vulnerability information associated with the said vulnerability identifier. Using the vulnerability information identified by the vulnerability identifier and the standards concerning information security, an instruction is generated to determine whether or not action is required for the vulnerability identified by the vulnerability identifier. A determination method that outputs determination data including the determination result output from the model in accordance with the above instructions.

10. On the computer, The process of obtaining a vulnerability identifier that uniquely identifies a vulnerability, A process of searching for vulnerability information associated with a vulnerability identifier by referring to a database in which vulnerability information for each vulnerability identifier is registered, A process that generates an instruction to determine whether action is required for the vulnerability identified by the vulnerability identifier, using the vulnerability information identified by the vulnerability identifier and the standards concerning information security. A program that causes a computer to perform a process that outputs judgment data, including the judgment result output from the model in accordance with the aforementioned instructions.

Citation Information

Patent Citations

  • Information processing apparatus, information processing method, and computer program

    JP2024042396A