Diagnostic support device, diagnostic support system, diagnostic support method, and program

JP2026142599APending Publication Date: 2026-09-08NEC CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2025029661
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-02-27
Publication Date
2026-09-08

AI Technical Summary

Benefits of technology

【0010】 本開示には、監視対象にセキュリティのリスクが実際に存在するか否かの診断の重要性の高さを把握できるという効果がある。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026142599000001_ABST
    Figure 2026142599000001_ABST
Patent Text Reader

Abstract

This invention provides a diagnostic support device, diagnostic support method, and program that enable users to understand the importance of diagnosing whether or not an incident is likely to actually occur in the monitored area. [Solution] A diagnostic support device according to one aspect of the present disclosure includes: characteristic extraction means for extracting device characteristics representing information related to the security of a target device from information of the target device; determination means for determining the magnitude of device risk, which is a risk that may exist in the target device, based on the magnitude of risk for each security item, which is a predetermined item related to security, from the device characteristics; and output means for outputting the magnitude of the device risk.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to a diagnostic support apparatus, a diagnostic support system, a diagnostic support method, and a program. [Background Art]

[0002] The importance of understanding vulnerabilities in network devices such as switches and routers, as well as in devices such as information processing devices, has been increasing year by year.

[0003] Patent Document 1 describes an incident response support apparatus and the like that, when an incident occurs in a monitored target, identifies the incident, creates a response procedure corresponding to the identified incident, and selects a display range of the response procedure according to the progress of the response. [Prior Art Documents] [Patent Documents]

[0004] [Patent Document 1] Japanese Unexamined Patent Publication No. 2019-114172 [Summary of the Invention] [Problem to be Solved by the Invention]

[0005] With the technology of Patent Document 1, it is possible to know the procedure for responding to an incident that has occurred. However, with the technology of Patent Document 1, it is not possible to grasp the high importance of diagnosing whether or not a security risk actually exists in the monitored target.

[0006] One object of the present disclosure is to provide a diagnostic support apparatus, a diagnostic support system, a diagnostic support method, and a program that can grasp the high importance of diagnosing whether or not a security risk actually exists in a monitored target. [Means for Solving the Problem]

[0007] A diagnostic support device according to one aspect of the present disclosure includes: characteristic extraction means for extracting device characteristics representing information related to the security of a target device from information of the target device; determination means for determining the magnitude of device risk, which is a risk that may exist in the target device, based on the magnitude of risk for each security item, which is a predetermined item related to security, from the device characteristics; and output means for outputting the magnitude of the device risk.

[0008] A diagnostic support method according to one aspect of this disclosure extracts device characteristics representing information related to the security of the target device from information about the target device, determines the magnitude of the device risk, which is a risk that may exist in the target device, based on the magnitude of the risk for each security item, which is a predetermined item related to security, from the device characteristics, and outputs the magnitude of the device risk.

[0009] A program according to one aspect of this disclosure causes a computer to perform the following: a characteristic extraction process that extracts device characteristics representing information related to the security of the target device from information about the target device; a determination process that determines the magnitude of device risk, which is a risk that may exist in the target device, based on the magnitude of risk for each security item, which is a predetermined item related to security, from the device characteristics; and an output process that outputs the magnitude of the device risk. [Effects of the Invention]

[0010] This disclosure has the effect of highlighting the importance of diagnosing whether or not security risks actually exist in the monitored area. [Brief explanation of the drawing]

[0011] [Figure 1] Figure 1 is a block diagram showing an example of the configuration of the diagnostic support device related to this disclosure. [Figure 2] Figure 2 is a flowchart illustrating an example of the operation of the diagnostic support device related to this disclosure. [Figure 3] Figure 3 is a block diagram showing the configuration of the diagnostic support system related to this disclosure. [Figure 4] Fig. 4 is a block diagram illustrating the configuration of a diagnosis support apparatus according to the present disclosure. [Figure 5] Fig. 5 is a flowchart illustrating an example of the operation of the diagnosis support apparatus according to the present disclosure. [Figure 6] Fig. 6 is a block diagram illustrating the configuration of the diagnosis support apparatus according to the present disclosure. [Figure 7] Fig. 7 is a flowchart illustrating an example of the operation of the diagnosis support apparatus according to the present disclosure. [Figure 8] Fig. 8 is a block diagram illustrating the configuration of the diagnosis support apparatus according to the present disclosure. [Figure 9] Fig. 9 is a flowchart illustrating an example of the overall operation of the diagnosis support apparatus according to the present disclosure. [Figure 10] Fig. 10 is a flowchart illustrating an example of the operation of determination processing performed by the diagnosis support apparatus according to the present disclosure. [Figure 11] Fig. 11 is a diagram illustrating an example of a hardware configuration of a computer that can implement the diagnosis support apparatus according to an embodiment of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION

[0012] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the drawings.

[0013] <First Embodiment> First, the first embodiment of the present disclosure will be described in detail with reference to the drawings.

[0014] <Configuration> Fig. 1 is a block diagram illustrating an example of the configuration of the diagnosis support apparatus according to the present disclosure.

[0015] Hereinafter, the configuration of the diagnosis support apparatus according to the first embodiment of the present disclosure will be described in detail with reference to Fig. 1.

[0016] In the example shown in Figure 1, the diagnosis support apparatus 10 according to one aspect of the present disclosure includes a characteristic extraction unit 120, a determination unit 130, and an output unit 160. The characteristic extraction unit 120 extracts apparatus characteristics representing information related to security of the target apparatus from information of the target apparatus. The determination unit 130 determines the level of apparatus risk, which is a risk that may exist in the target apparatus, based on the level of risk for each security item, which is a predetermined item related to security, from the apparatus characteristics. The output unit 160 outputs the level of apparatus risk.

[0017] <Description> The target apparatus is an apparatus for which apparatus risk is determined. The target apparatus is, for example, an information processing apparatus such as a server, or a network apparatus. The information processing apparatus is, for example, an information processing apparatus such as a server. The information processing apparatus may be another information processing apparatus. The network apparatus is an apparatus such as a router or a switch. The target apparatus may be another apparatus.

[0018] The information of the target apparatus is, for example, any one of information including the type of the target apparatus, the specifications of the target apparatus, the functions of the target apparatus, the usage of the target apparatus, the settings of the target apparatus, the status of countermeasures related to security of the target apparatus, and the management entity of the target apparatus.

[0019] The apparatus characteristics are information of the target apparatus regarding predetermined items related to security, obtained from any one of information including the type of the target apparatus, the specifications of the target apparatus, the functions of the target apparatus, the usage of the target apparatus, the settings of the target apparatus, the status of countermeasures related to security of the target apparatus, and the management entity of the target apparatus, for example. An item is information representing a certain state related to security. The information of the target apparatus regarding an item is, for example, information indicating whether or not the target apparatus is in the state represented by the item.

[0020] The risks associated with the target device include, for example, the risk of security-related events occurring on the target device, or in other words, the risk of the existence or occurrence of security-related events on the target device. Specifically, the risks associated with the target device may include, for example, the risk that vulnerabilities may exist in the target device. The risks associated with the target device may include, for example, the risk that the settings of the target device may lead to vulnerabilities. The risks associated with the target device may also include the risk that security-related events (incidents) may occur on the target device due to an attack or accident that compromises the confidentiality, integrity, or availability of the target device or the information it holds. Examples of security-related incidents include network outages, external intrusions, and the leakage of various types of information. The risks associated with the target device may be any combination of these examples.

[0021] The potential risks present in the target device (i.e., device risks) are those that may exist in the target device, determined from its device characteristics. These potential risks are determined based on the state represented by security items, which are predetermined security-related items obtained as part of the device characteristics. The potential risks present in the target device can also be described as the risks that may occur in the diagnostic device.

[0022] The magnitude of risk represents the degree of probability of the existence or occurrence of security-related events. The magnitude of risk may represent the degree of probability of the existence of security-related events. The magnitude of risk may represent the degree of probability of security-related events occurring. For example, the magnitude of risk may be set such that the greater the magnitude of risk, the higher the probability of the above-mentioned events occurring. Also, for example, the magnitude of risk may be predetermined for each predetermined security-related item obtained as a device characteristic. The magnitude of risk may be expressed numerically. The magnitude of risk may be expressed by letters, strings of characters, symbols, colors, etc., that represent the degree of magnitude.

[0023] Specific examples of information on the target device, device characteristics, and device risks will be described in detail in the description of the second embodiment below.

[0024] The output unit 160 outputs the magnitude of the device risk, for example, to the display of the diagnostic support device 10. The output unit 160 may also output the magnitude of the device risk, for example, to a user's terminal device that is communicatively connected to the diagnostic support device 10. The output unit 160 may also output the magnitude of the device risk, for example, to another information processing device such as a storage device or server that the diagnostic support device 10 can access.

[0025] <Operation> Figure 2 is a flowchart illustrating an example of the operation of the diagnostic support device related to this disclosure.

[0026] The operation of the diagnostic support device according to the first embodiment of this disclosure will be described in detail below with reference to Figure 2.

[0027] In the example shown in Figure 2, the characteristic extraction unit 120 extracts device characteristics representing information related to the security of the target device from the information of the target device (step S11). The determination unit 130 determines the device risk, which is a risk that may exist in the target device, from the device characteristics (step S12). In step S12, the determination unit 130 may determine the magnitude of the device risk, which is a risk that may exist in the target device, from the device characteristics based on the magnitude of the risk for each predetermined item related to security of the device characteristics. The output unit 160 outputs the magnitude of the device risk (step S13).

[0028] <Effects> The embodiment described above has the effect of enabling, for example, the recognition of the importance of diagnosing whether or not a risk actually exists in the monitored object.

[0029] The reason is that the characteristic extraction unit 120 extracts device characteristics representing information related to the security of the target device from the information of the target device. In this embodiment, the monitored object is, for example, the target device described above. The determination unit 130 then determines the device risk, which is a risk that may exist in the target device, from the device characteristics. The output unit 160 then outputs the magnitude of the device risk. In general, in order to maintain the security of a target device, if it is determined that a risk may exist in the target device, a diagnosis is made to determine whether or not that risk actually exists, and if the diagnosis shows that the risk exists, that risk is removed. The greater the magnitude of the device risk, which is a risk that may exist in the target device, the greater the importance of confirming the existence of that device risk and removing it if it exists. In other words, the greater the magnitude of the device risk, which is a risk that may exist in the target device, the greater the importance of diagnosing whether or not that device risk actually exists. The magnitude of the device risk allows us to understand the importance of diagnosing whether or not that device risk actually exists.

[0030] <Second Embodiment> Next, a second embodiment of the present disclosure will be described in detail with reference to the drawings.

[0031] <Structure> Figure 3 is a block diagram showing the configuration of the diagnostic support system related to this disclosure.

[0032] The configuration of the diagnostic support system according to the second embodiment of this disclosure will be described in detail with reference to Figure 3. The diagnostic support system 1 illustrated in Figure 3 includes a diagnostic support device 100 that is communicatively connected to a communication network 300. The diagnostic support device 100 may be able to communicate with a large language model server 200 via the communication network 300. In the following description, the large language model server 200 will be referred to as the LLM (Large Language Model) server 200.

[0033] <Large-scale language model server 200> The Large-Scale Language Model Server 200 is a server that provides services using a Large-Scale Language Model (LLM). An LLM service is, for example, a service that receives text-based instructions, generates output according to the received instructions using the LLM, and provides the generated output.

[0034] In the diagnostic support system 1 shown in Figure 3 in the above description, the diagnostic support device 100 has a physically different configuration from the LLM server 200. In other words, the diagnostic support device 100 and the LLM server 200 are implemented as different devices that are connected to each other in a communicative manner. However, the diagnostic support device 100 may be configured to provide LLM services. In other words, in the example shown in Figure 3, the LLM functions provided by the LLM server 200 may be implemented in the diagnostic support device 100. Furthermore, the diagnostic support device 100 may also be configured to operate as the LLM server 200.

[0035] <Diagnostic support device 100> Figure 4 is a block diagram showing the configuration of the diagnostic support device related to this disclosure.

[0036] The configuration of the diagnostic support device according to the second embodiment of this disclosure will be described in detail with reference to Figure 4. In the example shown in Figure 4, the diagnostic support device 100 includes an instruction receiving unit 110, a characteristic extraction unit 120, an extraction instruction unit 121, a determination unit 130, an output unit 160, and an information storage unit 170. The characteristic extraction unit 120, the determination unit 130, and the output unit 160 of this embodiment have the same functions as the characteristic extraction unit 120, the determination unit 130, and the output unit 160 of the first embodiment.

[0037] <Instruction receiving unit 110> The instruction receiving unit 110 receives a determination instruction, which is an instruction to make a determination regarding the target device, and information about the target device. The instruction receiving unit 110 may receive a determination instruction that includes information about the target device. The instruction receiving unit 110 may receive information about the target device as a determination instruction. In other words, the information about the target device may be a determination instruction. The information about the target device is the same as the information about the target device in the first embodiment. The information about the target device may include information that identifies the target device.

[0038] <Characteristic extraction unit 120> The characteristic extraction unit 120 extracts device characteristics from the information of the target device that represent information related to the security of the target device. Device characteristics are represented, for example, using security items that represent matters related to security. Matters related to security are, for example, specific information related to the security of the target device that is in a specific state. The characteristic extraction unit 120 determines whether the information of the target device indicates matters represented by predetermined security items. Information that represents the relationship between the information of the target device and predetermined security items is also referred to as characteristic reference data. In the following explanation, the information that indicates whether the information of the target device indicates matters represented by security items is referred to as the applicability status of security items. In other words, the characteristic extraction unit 120 identifies the applicability status of security items in the information of the target device from the information of the target device. The characteristic extraction unit 120 does not need to identify the applicability status of all predetermined security items. The characteristic extraction unit 120 may identify the applicability status of security items that can be identified from the information of the target device among all predetermined security items. In this way, the characteristic extraction unit 120 extracts device characteristics from the information of the target device by identifying the applicability status of security items in the information of the target device. In this case, the device characteristics are represented by the applicability status of security items indicated by the information of the target device (i.e., information indicating whether or not the information of the target device indicates the matters represented by the security items), which is identified from the information of the target device by the characteristic extraction unit 120. More specific examples of the information of the target device and device characteristics will be described in detail later. Note that in this disclosure, the applicability status of security items may also be simply referred to as the status of security items.

[0039] The characteristic extraction unit 120 may also send an instruction (hereinafter also referred to as an execution instruction) to the extraction instruction unit 121 to cause the LLM server 200 to perform a process of extracting at least a portion of the device characteristics from at least a portion of the information of the target device, as will be explained later. In this case, the characteristic extraction unit 120 receives the device characteristics information extracted by the LLM server 200 from the extraction instruction unit 121. In other words, the characteristic extraction unit 120 receives the device characteristics information extracted by the LLM server 200 from the LLM server 200 via the extraction instruction unit 121.

[0040] <Extraction instruction section 121> The extraction instruction unit 121 sends an instruction (hereinafter also referred to as an extraction instruction) to the LLM server 200 to execute a process to extract at least a portion of the device characteristics from at least a portion of the information of the target device. For example, in response to receiving the above execution instruction from the characteristic extraction unit 120, the extraction instruction unit 121 sends the above extraction instruction to the LLM server 200. The extraction instruction unit 121 receives the device characteristic information that the LLM server 200 has extracted according to the extraction instruction from the LLM server 200. The extraction instruction unit 121 sends the device characteristic information received from the LLM server 200 to the characteristic extraction unit 120.

[0041] <Judgment unit 130> The determination unit 130 uses the item risk information, which represents possible security risks, defined for the applicability status of security items identified by the characteristic extraction unit 120, to determine the magnitude of the device risk, which is a risk that may exist in the target device, based on the device characteristics.

[0042] As described above, the device characteristics are represented by the applicability status of security items indicated by the information of the target device, which is identified from the information of the target device by the characteristic extraction unit 120. The applicability status of security items is information that indicates whether or not the information of the target device indicates the item that the security item represents. The applicability status of security items indicated by the information of the target device indicates one of two states (i.e., the information of the target device indicates the item that the security item represents, and the information of the target device does not indicate the item that the security item represents). The state in which the information of the target device indicates the item that the security item represents is referred to as the applicable state. The state in which the information of the target device does not indicate the item that the security item represents is referred to as the non-applicable state. Either the applicable state or the non-applicable state represents a state that may lead to security risks in the target device. For example, if the security item represents an item that reduces security risks, the non-applicable state in which the information of the target device does not indicate the item that the security item represents represents represents a state that may lead to security risks in the target device. For example, if a security item represents something that increases security risk, then the relevant state of the target device, as indicated by the security item, represents a state that could lead to security risk in the target device. Of the applicable and inapplicable states indicated by the security item's status, the state that could lead to security risk in the target device is the item risk. For each item risk of a security item, a risk value is associated, which is a value that represents the magnitude of the risk (in other words, the level of risk). The magnitude of the risk is predetermined. The item risk information described above includes, for example, information that includes a combination of item risk and its risk value; in other words, information that associates the item risk of a security item with the risk value of the item list. The information that represents the risk value associated with the item risk of a security item (in other words, information that associates security items with risk values) is also referred to as judgment criterion data.

[0043] Specifically, the determination unit 130 first determines, for each security item whose applicability status has been identified from the state of the target device, whether the applicability status of the security item is a state that could lead to a security risk in the target device.

[0044] For example, if the state of the target device corresponds to the item represented by the security item, the state of the target device may be a state that could lead to a security risk (for example, a state that increases the security risk). In other words, the item represented by the security item that corresponds to the state may be a state that could lead to a security risk in the target device. Also, if the state of the device does not correspond to the item represented by the security item, the state of the target device may be a state that could lead to a security risk. In other words, the item represented by the security item that does not correspond to the state may be a state that could lead to a security risk in the target device. For each security item, a predetermined risk value representing the magnitude of the security risk is associated with the state that could lead to a security risk, among the corresponding and non-corresponding states. Each security item may be defined so that the corresponding state is a state that could lead to a security risk. Each security item may be defined so that the non-corresponding state is a state that could lead to a security risk. There may be a mix of security items where the corresponding state is a state that could lead to a security risk and security items where the non-corresponding state is a state that could lead to a security risk.

[0045] One or more specific risks may be associated with either the applicable or non-applicable state of a security item. In this case, the risks associated with either the applicable or non-applicable state of a security item are called item risks. Each item risk may be associated with a risk value. For example, suppose a security item is "the password must be at least 8 characters long." In this case, the non-applicable state is a state that could lead to a security risk. In this case, risks such as "the password must be less than 8 characters long, which is a vulnerable state" and "the password must be less than 4 characters long and only numbers can be used, which is extremely vulnerable" may be associated with the non-applicable state. Different risk values ​​may be associated with these risks. For example, the risk of "the password must be less than 8 characters long, which is a vulnerable state" may be associated with a risk value of, for example, "5." The risk of "the password must be less than 4 characters long and only numbers can be used, which is extremely vulnerable" may be associated with a risk value of, for example, "10." Also, for example, suppose a security item is "the device must have database functionality." In this case, the applicable state is a state that could lead to a security risk. Furthermore, the relevant state may be associated with risks such as, for example, "the information held is trade secret information, and its leakage would have a significant impact," "the information held is personal information, and its leakage would have a major impact," or "the information held is customer information, and its leakage would have a significant impact." These risks may also be associated with risk values ​​that are not necessarily the same. In such cases, the determination unit 130 determines whether a risk is associated with the state indicated by the applicable state or the non-applicable state of the security item, whose applicable state was identified from the state of the target device. The determination unit 130 identifies the risk associated with the state indicated by the applicable state or the non-applicable state of the security item, whose applicable state was identified from the state of the target device, as an item risk.

[0046] Either the applicable or non-applicable state of a security item may represent a state that could lead to a security risk in the target device. For example, a security item may indicate that the device has a certain function, and the device having that function may be a state that could lead to a security risk in the device. In this case, the applicable state of the security item represents a state that could lead to a security risk in the target device. For example, a security item may indicate that the version of the software installed on the device is a specified version, and the fact that the software version is not the specified version may be a state that could lead to a security risk in the device. In this case, the non-applicable state of the security item represents a state that could lead to a security risk in the target device. For example, a security item may indicate that the administrator has a certain security-related qualification, and the fact that the administrator does not have a certain security-related qualification may be a state that could lead to a security risk in the device. In this case, the non-applicable state of the security item represents a state that could lead to a security risk in the target device. In such cases, either the applicable or non-applicable state of the security item may be associated with a risk value rather than a specific risk. Then, of the applicable and non-applicable states of the security item, the state to which a risk value is associated represents the item risk. The determination unit 130 determines, based on the status of the target device, that the item is an item risk if, among the applicable and non-applicable states of the security item, a risk value rather than a specific risk is associated with it.

[0047] Furthermore, security items may be represented by a combination of a predetermined type of information about the target device (e.g., attributes or other types of information) and one of several conditions for the value of that predetermined type of information. This value may be, for example, a number, digit, character, or string. The condition may be that the value of the predetermined type of information is a certain value. The condition may be that the value of the predetermined type of information is included in a predetermined set of values ​​(i.e., it is the same as any value included in the set of values). The condition may be that the value of the predetermined type of information is included in a predetermined range of values ​​(e.g., a range of numbers or a range of characters). One of the multiple conditions may be that none of the other conditions are met. This predetermined type of information may be the number of events, etc., related to the target device. This predetermined type of information may be the version of software or hardware, etc., related to the target device (e.g., installed software or mounted hardware). This predetermined type of information may be the name of software or hardware, etc., related to the target device. This predetermined type of information may be the name of an attribute of a person or organization related to the target device (e.g., a qualification or security management certification held by the person or organization). The predetermined type of information and values ​​are not limited to the examples above.

[0048] Furthermore, each of the above-mentioned conditions may have an item risk to which a risk value is associated, or a risk value may be associated with each of the conditions. In this case, the risk value associated with each of the conditions (for example, the risk value directly associated with the condition) may include the risk value that indicates the smallest risk (hereinafter referred to as the minimum risk value). A security item that indicates that a value of a predetermined type of information satisfies the condition associated with the minimum risk value does not have to represent an item risk. A security item that indicates that a predetermined type of information satisfies the condition associated with a risk value that is not the minimum risk value may represent an item risk.The characteristic extraction unit 120 then identifies which conditions the value of the predetermined type of information indicated by the security item satisfies based on the information of the target device.The determination unit 130 then identifies the item risk associated with the condition that the value of the predetermined type of information indicated by the security item, as indicated by the information of the target device, satisfies, and the risk value associated with that item risk.If a risk value is directly associated with the condition that the value of the predetermined type of information indicated by the security item, as indicated by the information of the target device, satisfies, the determination unit 130 identifies that risk value.

[0049] A security item that is represented by a combination of a predetermined type of information of the target device and one of several conditions for the value of that predetermined type of information is referred to here as a conditional security item. A conditional security item can be considered as a combination of security items that indicate that the value of the predetermined type of information of the target device satisfies each of the multiple conditions. For example, suppose a conditional security item is represented by a combination of an attribute of the target device (referred to as attribute A) and several conditions for the value of that attribute (e.g., condition A1, condition A2, condition A3). In this case, this conditional security item can be considered as a combination of three security items: "the value of attribute A satisfies condition A1", "the value of attribute A satisfies condition A2", and "the value of attribute A satisfies condition A3". The risk value associated with each of the conditions of a conditional security item can be considered as the risk value associated with the corresponding state of these security items.

[0050] The equipment risk is represented by the identified item risks. The determination unit 130 identifies the risk values ​​of the identified item risks. The determination unit 130 determines the magnitude of the equipment risk as a statistical value of the identified risk values. This statistical value may be, for example, the maximum value or the sum. The statistical value is not limited to these examples. This statistical value may also be the mean, median, or intermediate value. Specific examples of determining equipment risk from equipment characteristics will be explained in detail later.

[0051] <Output section 160> The output unit 160 outputs the magnitude of the device risk. In addition to the magnitude of the device risk, the output unit 160 may also output information representing the identified item risk and the risk value of that item risk (i.e., a value representing the magnitude of the risk). In this case, the output unit 160 may output the information representing the identified item risk and the risk value of that item risk in order of the magnitude of the risk. The output destination to which the output unit 160 outputs the magnitude of the device risk and other information (hereinafter referred to as the output destination of the output unit 160) may be, for example, the display of the diagnostic support device 100. The output destination of the output unit 160 may also be a user's terminal device that is communicatively connected to the diagnostic support device 100. The output destination of the output unit 160 may also be a storage device or other information processing device such as a server that the diagnostic support device 100 can access.

[0052] <Information storage section 170> The information storage unit 170 stores characteristic criterion data and judgment criterion data.

[0053] <Specific example> The following sections provide a detailed explanation of the target equipment, its characteristics, and specific examples of equipment risks.

[0054] <First specific example> In the first specific example, the information on the target device includes information that identifies the target device. The information on the target device further includes information on the check results. The information on the target device may further include information on either the function or the application of the target device.

[0055] Information that identifies the target device may include, for example, the device name, IP (Internet Protocol) address, the type of target device, and any other identifying information.

[0056] The functional information of the target device refers to the functions that the target device possesses. The usage information of the target device refers to the usage information of the target device. Specifically, the functional information of the target device includes, for example, information on functions for implementing a web server, functions of a communication interface, and storage that can be accessed from outside the target device. The usage information of the target device includes, for example, information on web servers, connections to external lines, retention of confidential information, retention of personal information, etc. The functional information of the target device is not limited to these examples.

[0057] The information in the check results includes information such as the results of vulnerability scans and configuration checks. The vulnerability scan is the result of a prior scan for vulnerabilities present in the target device. The method for scanning for vulnerabilities present in the target device may be one of various existing methods. The configuration check results are the result of a prior check of predetermined types of configuration items on the target device. Configuration items are items that define restrictions, conditions, or rules for at least one of predetermined types of operations and predetermined types of functions of the target device. Each predetermined type of configuration item has predetermined settings that are recommended as countermeasures against the occurrence of security-related events. If the predetermined types of configuration items on the target device are set to the recommended settings, the possibility of security-related events occurring on the target device can be reduced. The more configuration items of the predetermined types on the target device that are set to the recommended settings, the more the possibility of security-related events occurring on the target device can be reduced. In the description of the embodiments of this disclosure, settings that are not recommended for the above-mentioned predetermined types of configuration items are referred to as vulnerable settings, as settings that may lead to the occurrence of security-related events. The method for checking the settings of specific types of settings on the target device may be one of various existing methods. Furthermore, the information on the target device may include, for example, information about the type of business of the organization (company or other organization) to which the administrator of the target device belongs.

[0058] In this specific example, security items are items of security-related guidelines (also referred to as guideline items). Guideline items represent matters that should be observed and recommended in the state of the target device, in other words, the state that the target device should maintain. The state of security items is represented by whether or not the matters represented by the guideline items are observed. In other words, the state of security items is represented by whether or not the state of the target device is in the state represented by the matters represented by the guideline items. Device characteristics are represented, for example, by information indicating whether or not security-related guideline items are observed. In describing the embodiments of this disclosure, security-related guidelines are also simply referred to as guidelines. Guidelines may include guidelines established regardless of the type of business (in other words, business field or industry, etc.). Guidelines may include guidelines established as standards for each type of business, and guidelines established by the organization or group to which the administrator of the target device belongs. If the information on the target device includes information on the type of business of the organization or group to which the administrator of the target device belongs, the characteristic extraction unit 120 may select guidelines established in the type of business represented by the information on the target device. The characteristic extraction unit 120 may further select guidelines established regardless of the type of business. If the information on the target device does not include information on the type of business of the organization or group to which the administrator of the target device belongs, the characteristic extraction unit 120 may select guidelines established regardless of the type of business. In this specific example, the characteristic criteria data includes information on the guidelines. That is, the characteristic criteria data is information representing the content of the items in the guidelines.

[0059] Furthermore, guidelines may be defined for each function of the target device. In this case, the characteristic extraction unit 120 may select the guidelines defined for the function of the target device from the guidelines.

[0060] The characteristic extraction unit 120 may, for example, identify the impact of at least one of the detected vulnerabilities and the aforementioned vulnerability settings in the information of the check results (i.e., the results of the vulnerability scan and the results of the configuration check). The impact of a vulnerability is, for example, the impact that may occur if the vulnerability is exploited. The impact of a vulnerability setting is, for example, the impact that is more likely to occur due to the vulnerability setting. This impact is, for example, events such as unauthorized access, information leakage, system downtime, and network downtime that may occur due to the vulnerability and the aforementioned vulnerability setting. In the following explanation, vulnerabilities and vulnerability settings will be collectively referred to as vulnerability items. In other words, a vulnerability item is, for example, either a vulnerability or a vulnerability setting. A vulnerability item may include a vulnerability, a vulnerability setting, a combination of multiple vulnerabilities, a combination of multiple vulnerability settings, and a combination of one or more vulnerabilities and one or more vulnerability settings. Furthermore, events that may occur due to a vulnerability item, in other words, events that are expected to be more likely to occur due to a vulnerability item, will be referred to as expected occurrence events. The combination of a vulnerability item and its expected occurrence event may be obtained in advance.

[0061] Furthermore, information on the anticipated occurrence of each vulnerability is also referred to as vulnerability-related information. This vulnerability-related information is pre-stored in the information storage unit 170.

[0062] In other words, the characteristic extraction unit 120 may, for example, use vulnerability-related information to identify anticipated events related to the information of the target device (particularly information on vulnerabilities detected in vulnerability scans and configuration check vulnerabilities).

[0063] Each of the guideline items (i.e., the guideline items mentioned above) may be associated with at least one hypothetical event.

[0064] In this case, the characteristic extraction unit 120 selects guideline items related to the assumed event from the guideline items included in the selected guideline described above. For example, if the assumed event is an information leak, the characteristic extraction unit 120 selects guideline items related to information leaks (for example, guideline items to prevent information leaks) from among the guideline items. For example, if the assumed event is unauthorized access, the characteristic extraction unit 120 may select guideline items related to unauthorized access (guideline items to prevent unauthorized access) from among the guideline items.

[0065] The characteristic extraction unit 120 identifies guideline items related to vulnerabilities from among the selected guideline items. Guideline items are, for example, information that should be protected. The characteristic extraction unit 120 extracts, for example, guideline items that are not protected by the target device (in other words, guideline items that the target device violates) from among the identified guideline items. A guideline item that is not protected is an item in which the state of the target device is different from the state described in that guideline item. For example, if a vulnerability is a vulnerability, that is, if a vulnerability is detected as a vulnerability as a result of a vulnerability scan included in the state of the target device, the guideline item related to the vulnerability may be a guideline item indicating that the vulnerability has been addressed. For example, if a vulnerability is a vulnerable setting, that is, if that vulnerable setting is detected as a vulnerability as a result of a setting check included in the state of the target device, the guideline item related to the vulnerability may be a guideline item indicating that that vulnerable setting will not be implemented. Such a setting is, for example, a setting that reduces security.

[0066] The method by which the characteristic extraction unit 120 identifies guideline items related to the information of the target device (i.e., items that the status of the target device indicates are not being followed, in other words, items that are not being followed by the target device, items that the target device is violating) may be any existing method. The characteristic extraction unit 120 may, for example, identify guideline items related to the information of the target device by vector search, where the status of the target device and the guideline items are represented by vectors. The characteristic extraction unit 120 may also, via the extraction instruction unit 121, cause the LLM server 200 to identify (i.e., extract) guideline items related to the information of the target device. The characteristic extraction unit 120 may consider guideline items that were not identified as being not being followed by the target device as guideline items being followed by the target device.

[0067] Furthermore, in this specific example, a risk value representing the level (in other words, magnitude) of risk for each guideline item is predetermined. In this specific example, the judgment criterion data includes information on the predetermined risk value for each guideline item. The judgment unit 130 identifies the risk value (magnitude of item risk) of the guideline item (corresponding to security item) related to the vulnerability. In this case, the item risk corresponds to the failure to comply with the guideline item. In this case, the item risk may indicate events predetermined as events that may occur as a result of the failure to comply with the guideline item (for example, information leakage, unauthorized access, and loss of social credibility). The events predetermined as events that may occur as a result of the failure to comply with the guideline item may be at least one of the assumed events described above.

[0068] The determination unit 130 uses the statistical value of the risk value of the guideline items related to the vulnerability as the magnitude of the device risk.

[0069] <Second specific example> In the second specific example, the information of the target device includes the information that identifies the target device, as described above. The information of the target device includes information that represents at least one of the type of function of the target device and the type of retained information. The retained information is the information that the target device holds (in other words, the information stored in the memory of the target device). The information of the target device may also include information such as the type of target device (e.g., server, switch, router, terminal, etc.) and the product name of the target device.

[0070] Information representing at least one of the function type of the target device and the type of information it holds may include, for example, text information written by the administrator of the target device that represents either the specifications and use of the target device, a specification document that represents the specifications of the target device, and the manual for the target device. The specifications of the target device include, for example, at least one of the names and types of software installed on the target device. This software may be, for example, software used when the target device is used for its intended purpose. The use of the target device is information that represents how the target device is used, such as the communication network to which the target device is connected (for example, whether or not the target device is connected to an external network), the management of customer information, the management of employee information, the management of sales information, and the dissemination of information to external parties. An external network is, for example, a communication network that is not managed by the entity that manages the target device. Text information representing either the specifications or use of the target device may include, for example, a document or string of characters that describes the specifications of the target device. A specification document is, for example, a document that describes either the specifications of the target device or how the target device is used. The manual for the target device is a document that describes at least one of the following: the specifications of the target device, the intended use of the target device, the operation of the target device when managing it, and the operation of the target device when using it for its intended purpose.

[0071] In this specific example, security items are items (hereinafter also referred to as device items) that represent matters defined for at least one of the types of functions and types of retained information. Characteristic standard data includes information for predetermined device items. Types of functions include, for example, external network connection, which is a type of function that indicates that the device is connected to an external network; database, which is a type of function that indicates that the device functions as a database; and terminal, which is a type of function that indicates that an employee is using the device as a terminal. Types of functions are not limited to these examples. Types of functions do not have to include these examples. Types of retained information include, for example, confidential information, personal information, and public information. Confidential information is, for example, information that is secret from anyone other than the entity that manages the target device. Personal information is, for example, information that requires special handling as information representing an individual, as required by law, etc. Public information is, for example, publicly available information (in other words, information that is publicly available to anyone other than the entity that manages the target device). Types of retained information are not limited to these examples. Types of retained information do not have to include these examples.

[0072] The characteristic extraction unit 120 extracts device characteristics (in other words, information representing device characteristics) from the device information by identifying device items from among predetermined device items that represent information representing at least one of the types of functions of the target device and the types of retained information included in the information of the target device. In this case, the device characteristics are represented by device items from among predetermined device items that represent information representing at least one of the types of functions of the target device and the types of retained information.

[0073] The characteristic extraction unit 120 may use characteristic reference data to estimate the function of the target device from the type and product name of the target device, etc. In this case, the characteristic reference data includes information that associates the type and product name of the target device, etc. with a device item that represents the type of function that the target device possesses.

[0074] The characteristic extraction unit 120 may, for example, use characteristic criterion data to determine if a keyword predetermined for each type of function is included in the information of the target device, and if so, determine that the function of the target device includes a function represented by the type of function associated with that keyword. The characteristic extraction unit 120 may, for example, use characteristic criterion data to determine if a keyword predetermined for each type of retained information is included in the information of the target device, and if so, determine that the retained information of the target device includes retained information represented by the type of retained information associated with that keyword. In this case, the characteristic criterion data includes the keyword and information associated with a device item representing either the type of function or the type of retained information. The characteristic extraction unit 120 may, via the extraction instruction unit 121, cause the LLM server 200 to estimate at least one of the type of function and the type of retained information of the target device from the information of the target device. In other words, the characteristic extraction unit 120 may, via the extraction instruction unit 121, transmit the information of the target device and an instruction to the LLM server 200 to estimate at least one of the type of function and the type of retained information of the target device from the information of the target device. The characteristic extraction unit 120 may receive, via the extraction instruction unit 121, at least one of the types of functions of the target device and the types of retained information estimated by the LLM server 200 from the LLM server 200.

[0075] Furthermore, if the characteristic extraction unit 120 cannot identify at least one of the device items representing the type of function and the device item representing the type of retained information from the information of the target device, it does not need to extract at least one of the device items representing the type of function and the device item representing the type of retained information that could not be identified. For example, if it cannot be identified from the information of the target device that information represented by any of the device items representing the type of retained information is stored in the target device, the characteristic extraction unit 120 does not need to extract the device item representing the type of retained information. Similarly, if it cannot be identified that the target device has a function represented by any of the device items representing the type of function, the characteristic extraction unit 120 does not need to extract the device item representing the type of function.

[0076] The characteristic extraction unit 120 may extract multiple device items for a single target device, each representing a different type of function. The characteristic extraction unit 120 may extract multiple device items for a single target device, each representing a different type of retained information.

[0077] For example, in the above example, if the information about the target device indicates that the target device is a web server connected to an external network for public relations outside the organization, the characteristic extraction unit 120 extracts a device item representing "external network connection" as the type of function. In this case, the characteristic extraction unit 120 further extracts an item representing "public information" as the type of retained information. For example, if the target device is a device that functions as a database and is not connected to an external network, the characteristic extraction unit 120 extracts a device item representing "database" as the type of function. In this case, the characteristic extraction unit 120 further extracts an item representing the type of information stored in the database as the type of retained information. For example, if the target device is a terminal device used by employees that is not connected to an external network and does not retain information, the characteristic extraction unit 120 extracts a device item representing "terminal" as the type of function. In this case, the characteristic extraction unit 120 does not need to extract a device item representing the type of retained information.

[0078] Each device item has a predetermined risk value that represents the magnitude of the risk. In this specific example, the judgment criterion data includes information on the predetermined risk values ​​for each device item.

[0079] The determination unit 130 identifies the risk value (i.e., the magnitude of the item risk) of the device item extracted as information representing the device characteristics. In this case, the item risk corresponds to the device possessing the type of function indicated by the device item and the device holding the type of information held by the device item. The risk value of the device item representing the type of function may be a value determined appropriately according to the degree of likelihood that the target device will be attacked as a result of the target device possessing that function (for example, by being connected to an external network, etc.), and the degree of damage if the target device is attacked. The risk value of the device item representing the type of information held may be a value determined appropriately according to the degree of damage to the entity managing the device and the impact on society as a result of the information being leaked.

[0080] The determination unit 130 uses the statistical value of the risk value of the device item extracted as information representing the device characteristics as the magnitude of the device risk.

[0081] <Third specific example> In the third specific example, the information on the target device includes information on the entity that manages the target device. The managing entity is, for example, either the person who manages the target device or the organization that manages the target device (for example, a company, government ministry, local government, other organization, or an internal organization within the organization). An internal organization within the organization is, for example, a department, division, or section, which is a group created within the organization.

[0082] When the managing entity is a person, the information about the managing entity includes information that identifies the person, information about incidents that have occurred in the past on the devices managed by that person, the qualifications the person holds, and their nationality. Incidents are security-related events such as intrusions from external networks or data breaches.

[0083] If the managing entity is an organization, the information about the managing entity includes the type of business or other activities of the managing entity (e.g., business field or industry), information on security management certifications obtained by the managing entity, and information on incidents that have occurred in the past on devices managed by that organization.

[0084] The incident information may include the date and time the incident occurred.

[0085] In this specific example, the security items include the administrator item, which represents matters defined for the administrator's information.

[0086] The management entity item may include items indicating, for example, the type of security management certification the management entity has received, and items indicating that the management entity has not received security management certification. The type of certification may be, for example, one or more predetermined types of certification. Different types of certification may be represented by different management entity items.

[0087] The managing entity item may include, for example, items indicating the type of qualifications the managing entity holds, and items indicating that the managing entity does not hold any qualifications. Different types of qualifications may be represented by different managing entity items.

[0088] The managing entity item may include, for example, items representing each of the types of businesses of the managing entity, which are predetermined as types of businesses of the managing entity. Different types of businesses may be represented by different managing entity items.

[0089] The managing entity item may include, for example, an item representing the nationality of the managing entity. Different nationalities may be represented by different managing entity items.

[0090] The management entity item may be represented by an item indicating whether or not an incident occurred in the device or system managed by the management entity within the most recent specified period. Multiple different specified periods may be defined. In that case, the management entity item may include items representing items indicating that an incident occurred in the device or system managed by the management entity within the most recent specified period, and items indicating that no incident occurred.

[0091] In this specific example, the characteristic criteria data includes information representing the items of the managing entity.

[0092] The characteristic extraction unit 120 may extract device characteristics from the information of the target device by identifying the management entity items that are valid in the information of the target device (specifically, the information of the management entity of the target device included in the information of the target device) from among the predetermined management entity items. In this case, the device characteristics are represented by the management entity items that are valid in the information of the target device (specifically, the information of the management entity of the target device included in the information of the target device) from among the predetermined management entity items. In this specific example, the item risk is represented by the management entity items that are valid in the information of the target device.

[0093] The characteristic criteria data may include information on incidents that occurred in devices managed by a management entity, such as a group or organization, information on security management certifications, and information on the type of business. In this case, the information on the target device does not need to include information on incidents that occurred, information on security management certifications, and information on the type of business. The characteristic extraction unit 120 identifies information on incidents that occurred, information on security management certifications, and information on the type of business of the management entity indicated by the information identifying the management entity (for example, information identifying the organization that is the management entity) included in the information on the target device (especially the information on the management entity of the target device) from the characteristic criteria data.

[0094] The characteristic extraction unit 120 may, via the extraction instruction unit 121, instruct the LLM server 200 to estimate from the information of the target device at least one of the following: information about incidents that occurred in devices managed by the management entity, information about security management certifications, information about the type of business, etc. In other words, the characteristic extraction unit 120 may, via the extraction instruction unit 121, transmit to the LLM server 200 information about the target device and an instruction to estimate from the information of the target device at least one of the following: information about incidents that occurred in devices managed by the management entity, information about security management certifications, information about the type of business, etc. The characteristic extraction unit 120 may then, via the extraction instruction unit 121, receive from the LLM server 200 at least one of the following: information about incidents that occurred in devices managed by the management entity, information about security management certifications, information about the type of business, etc., estimated by the LLM server 200.

[0095] The characteristic criteria data may include information on incidents that occurred in devices managed by a person who is a managing entity, as well as information on qualifications and nationality. In this case, the information on the target device does not need to include information on incidents that occurred in devices managed by the managing entity, as well as information on qualifications and nationality. The characteristic extraction unit 120 identifies information on incidents that occurred, information on qualifications and nationality, etc., of the managing entity indicated by the information that identifies the managing entity (for example, information that identifies the person who is the managing entity) included in the information on the target device (especially the information on the managing entity of the target device) from the characteristic criteria data.

[0096] The characteristic extraction unit 120 may, via the extraction instruction unit 121, instruct the LLM server 200 to estimate from the information of the target device at least one of the following: information about incidents that occurred in devices managed by the managing entity, qualification information, nationality information, etc. In other words, the characteristic extraction unit 120 may, via the extraction instruction unit 121, transmit to the LLM server 200 information about the target device and an instruction to estimate from the information of the target device at least one of the following: information about incidents that occurred in devices managed by the managing entity, qualification information, nationality information, etc. The characteristic extraction unit 120 may then, via the extraction instruction unit 121, receive from the LLM server 200 at least one of the following: information about incidents that occurred in devices managed by the managing entity, qualification information, nationality information, etc.

[0097] In this specific example, the judgment criteria data includes information on risk values ​​associated with the management entity items.

[0098] If the management entity item indicates whether or not an incident occurred in the equipment managed by the management entity within the most recent specified period, the risk value of the management entity item may be set such that the more recent the specified period in which the incident occurred, the greater the magnitude of the risk indicated by the risk value. Furthermore, the risk value of the management entity item indicating that no incident has occurred should be set such that the magnitude of the risk is smaller compared to the risk value of the management entity item indicating that an incident has occurred.

[0099] If the management entity item represents a security management certification received by the management entity, then a risk value indicating lower risk may be set for each certification represented by the management entity item, based on its higher credibility. In this case, the risk value for a management entity item indicating that it is not certified should be set to be greater than the risk value for a management entity item indicating that it is certified.

[0100] When the management entity item represents the type of business (i.e., industry) of the management entity, the risk value of the management entity item may be set such that the magnitude of the risk represented by the risk value increases as the strictness of the laws and regulations and security rules within the industry applicable to that industry increases. For example, in an industry where an incident would have a significant impact on the management entity managing the equipment involved, the laws and regulations and security rules within the industry applicable to that industry may be set more strictly. In such cases, the risk value of the management entity item may be set as described above. It can also be considered that the stricter the laws and regulations and security rules within the industry applicable to that industry, the higher the likelihood that the rules will be followed. The risk value of the management entity item may be set such that the magnitude of the risk represented by the risk value decreases as the strictness of the laws and regulations and security rules within the industry applicable to that industry increases, without considering the magnitude of the impact if an incident occurs. The risk value of the management entity item may be appropriately determined by the manager based on the strictness of the laws and regulations and security rules within the industry applicable to that industry and the general trend of the magnitude of impact if an incident occurs in that industry. The degree of severity may be determined according to the rules established as appropriate.

[0101] If the management entity item represents a security-related qualification acquired by the management entity, a risk value can be set that indicates lower risk, with higher credibility of the qualification represented by the management entity item. In this case, the risk value of the management entity item representing no qualification should be set to be greater than the risk value of the management entity item representing qualification.

[0102] If the managing entity item represents the nationality of a person who is a managing entity, the risk value of the managing entity item may be set such that the greater the strength of the power of command that country has over its citizens, as defined by the laws of that country, the greater the risk. The strength of this power of command may be determined appropriately depending on whether or not there are laws that allow the country to direct the behavior of its citizens, and the severity of the penalties for not complying with the country's instructions. If the managing entity item represents the nationality of a person who is a managing entity, the risk value of the managing entity item may be set such that the greater the number of security incidents per unit period that occur in the devices managed by the managing entity, for each nationality of the managing entity, the greater the risk.

[0103] The determination unit 130 uses the statistical value of the risk value of the management entity item extracted as information representing the device characteristics as the magnitude of the device risk.

[0104] <Fourth specific example> It is also possible to combine two or more of the first to third specific examples. In that case, the determination unit 130 uses the statistical value of the risk value of the security items extracted as information representing the device characteristics as the magnitude of the device risk.

[0105] Furthermore, in the above explanation, security items represent matters related to security. However, security items may also be represented by the type of target device and the value of information of that type regarding the target device or the entity that manages the target device.

[0106] <Operation> Next, the operation of the diagnostic support device 100 according to the second embodiment of this disclosure will be described in detail with reference to the drawings.

[0107] Figure 5 is a flowchart illustrating an example of the operation of the diagnostic support device related to this disclosure.

[0108] Below, an example of the operation of the diagnostic support device 100 according to the second embodiment of this disclosure will be described in detail with reference to Figure 5.

[0109] In the example shown in Figure 5, first, the instruction receiving unit 110 receives information about the target device as a determination instruction, which is, for example, an instruction to make a determination regarding the target device (step S101).

[0110] Next, the characteristic extraction unit 120 identifies security items related to the information of the target device (step S102). For example, if the information of the target device includes at least one of the results of a vulnerability scan and the results of a configuration check, the characteristic extraction unit 120 identifies the guideline items as security items. The characteristic extraction unit 120 may select the guideline to be used from a plurality of predetermined guidelines, as described above. Then, it may identify the items of the selected guideline as security items. If the information of the target device includes information representing at least one of the types of functions of the target device and the types of information held by the target device, the characteristic extraction unit 120 identifies the above-mentioned device items as security items. If the information of the target device includes information of the entity managing the target device, the characteristic extraction unit 120 selects the entity managing the target device as a security item. Note that security items related to the information of the target device may be predetermined. In other words, security items related to the information of the target device may be predetermined. In that case, the characteristic extraction unit 120 does not need to perform the operation in step S102. The characteristic extraction unit 120 extracts device characteristics represented by the identified security items from the information of the target device (step S103).

[0111] In step S103, the characteristic extraction unit 120 may, as described above, send an execution instruction to the extraction instruction unit 121 to cause the LLM server 200 to perform a process of extracting at least a portion of the device characteristics from at least a portion of the information of the target device. In this case, the characteristic extraction unit 120 receives the device characteristics information extracted by the LLM server 200 from the extraction instruction unit 121. In other words, the characteristic extraction unit 120 receives the device characteristics information extracted by the LLM server 200 from the LLM server 200 via the extraction instruction unit 121.

[0112] The determination unit 130 identifies the magnitude of the risk for each identified security item based on the extracted device characteristics (step S104). The determination unit 130 determines the magnitude of the device risk, which is a risk that may exist in the target device (step S105).

[0113] The output unit 160 outputs the magnitude of the device risk (step S106). In step S106, as described above, the output unit 160 may output, in addition to the magnitude of the device risk, information representing the identified item risk and the risk value of that item risk (i.e., a value representing the magnitude of the risk). In this case, the output unit 160 may output the information representing the identified item risk and the risk value of that item risk in order of the magnitude of the risk.

[0114] <Effects> The embodiment described above has the same effects as the first embodiment. The reason for this is the same as the reason for the effects of the first embodiment.

[0115] <Third Embodiment> Next, a third embodiment of the present disclosure will be described in detail with reference to the drawings.

[0116] <Structure> Figure 6 is a block diagram showing the configuration of the diagnostic support device related to this disclosure.

[0117] The configuration of the diagnostic support device according to the third embodiment of this disclosure will be described in detail with reference to Figure 6.

[0118] <Diagnostic support device 101> In the example shown in Figure 6, the diagnostic support device 101 includes an instruction receiving unit 110, a characteristic extraction unit 120, an extraction instruction unit 121, a determination unit 130, a diagnostic procedure extraction unit 140, an output unit 160, and an information storage unit 170.

[0119] The instruction receiving unit 110, characteristic extraction unit 120, extraction instruction unit 121, determination unit 130, output unit 160, and information storage unit 170 of this embodiment each have the same functions as the instruction receiving unit 110, characteristic extraction unit 120, extraction instruction unit 121, determination unit 130, output unit 160, and information storage unit 170 of the second embodiment. The instruction receiving unit 110, characteristic extraction unit 120, extraction instruction unit 121, determination unit 130, output unit 160, and information storage unit 170 of this embodiment each perform operations similar to those of the instruction receiving unit 110, characteristic extraction unit 120, extraction instruction unit 121, determination unit 130, output unit 160, and information storage unit 170 of the second embodiment. The diagnostic support device 101 of this embodiment is the same as the diagnostic support device 100 of the second embodiment, except for the differences which will be described below.

[0120] The diagnostic support system according to this embodiment is a system in which the diagnostic support device 100 is replaced by the diagnostic support device 101 in the example shown in Figure 3.

[0121] <Information storage section 170> The information storage unit 170 further stores information about diagnostic procedures associated with the combination of the type of device to be diagnosed and the security items extracted as device characteristics. The diagnostic procedure is a procedure for diagnosing whether or not a target device is in a state where a risk actually exists (in other words, whether or not a risk actually exists in the target device) when the state of the target device is the state represented by the security items extracted as device characteristics. The diagnostic procedure may be a predetermined procedure for diagnosing the presence or absence of risks that have been identified as possible risks in the target device when the state of the target device is the state represented by the security items extracted as device characteristics.

[0122] <Diagnostic procedure extraction unit 140> The diagnostic procedure extraction unit 140 extracts diagnostic procedures for diagnosing the actual state of risks in the target device. Diagnosing the actual state of risks in the target device means, for example, diagnosing whether or not risks actually exist in the target device. Diagnosing the actual state of risks in the target device may also be a diagnosis of whether or not the target device is in a state where risks could actually occur, based on, for example, the settings of the target device's OS, software, hardware, etc., and various conditions in the system environment including the target device. The diagnostic procedure extraction unit 140 extracts information on diagnostic procedures associated with the combination of the type of target device and the security items extracted as device characteristics from the diagnostic procedure information stored in the information storage unit 170.

[0123] <Output section 160> The output unit 160 further outputs information on the extracted diagnostic procedures. When outputting the diagnostic procedure information, the output unit 160 may output the magnitude of the risk for each identified security item (in other words, item risk) and the combination of the diagnostic procedure associated with that security item, for example, in order from the security item with the greatest risk. In that case, the output unit 160 may output the above-mentioned risk value as the magnitude of the risk. The output destination to which the output unit 160 outputs the magnitude of the device risk and other information (for example, the diagnostic procedure information) (hereinafter referred to as the output destination of the output unit 160) may be, for example, the display of the diagnostic support device 101. The output destination of the output unit 160 may also be a user's terminal device that is communicably connected to the diagnostic support device 101. The output destination of the output unit 160 may also be a storage device or other information processing device such as a server that the diagnostic support device 101 can access.

[0124] <Operation> Figure 7 is a flowchart illustrating an example of the operation of the diagnostic support device related to this disclosure.

[0125] Below, an example of the operation of the diagnostic support device 101 according to the third embodiment of this disclosure will be described in detail with reference to Figure 7.

[0126] In the example shown in Figure 7, the operations from step S101 to step S105 are the same as the operations from step S101 to step S105 in the example shown in Figure 5.

[0127] Following step S105, the diagnostic procedure extraction unit 140 extracts a diagnostic procedure for diagnosing whether a risk actually exists in the target device (step S116).

[0128] Next, the output unit 160 outputs information on the magnitude of the device risk and the diagnostic procedure (step S117).

[0129] <Effects> The embodiment described above has the same effects as the first embodiment. The reason for this is the same as the reason for the effects of the first embodiment. Furthermore, this embodiment has the effect of enabling early identification through early diagnosis whether a risk actually exists in the monitored target or whether a risk is likely to occur, and taking countermeasures as necessary. The reason for this is that in this embodiment, the output unit 160 outputs the diagnostic procedure associated with the identified security item. Moreover, this embodiment also has the effect of enabling identification and countermeasures to be taken starting with the security items with the highest risk among the identified security items. The reason for this is that the output unit 160 outputs the combination of the risk level of the identified security item and the diagnostic procedure. This makes it possible to perform a diagnosis according to the diagnostic procedure, starting with the security items with the highest risk. If the diagnosis confirms that a risk actually exists, countermeasures against that risk can be taken.

[0130] <Fourth Embodiment> Next, a fourth embodiment of this disclosure will be described in detail with reference to the drawings.

[0131] <Structure> Figure 8 is a block diagram showing the configuration of the diagnostic support device related to this disclosure.

[0132] The configuration of the diagnostic support device according to the fourth embodiment of this disclosure will be described in detail with reference to Figure 8.

[0133] <Diagnostic support device 102> In the example shown in Figure 8, the diagnostic support device 102 includes an instruction receiving unit 110, a characteristic extraction unit 120, an extraction instruction unit 121, a determination unit 130, a diagnostic procedure extraction unit 140, a priority determination unit 150, an output unit 160, and an information storage unit 170.

[0134] The instruction receiving unit 110, characteristic extraction unit 120, extraction instruction unit 121, determination unit 130, diagnostic procedure extraction unit 140, output unit 160, and information storage unit 170 of this embodiment each have the same functions as the instruction receiving unit 110, characteristic extraction unit 120, extraction instruction unit 121, determination unit 130, diagnostic procedure extraction unit 140, output unit 160, and information storage unit 170 of the third embodiment. The instruction receiving unit 110, characteristic extraction unit 120, extraction instruction unit 121, determination unit 130, diagnostic procedure extraction unit 140, output unit 160, and information storage unit 170 of this embodiment each perform operations similar to those of the instruction receiving unit 110, characteristic extraction unit 120, extraction instruction unit 121, determination unit 130, diagnostic procedure extraction unit 140, output unit 160, and information storage unit 170 of the third embodiment. The diagnostic support device 102 of this embodiment is the same as the diagnostic support device 101 of the third embodiment, except for the differences described below.

[0135] The diagnostic support system according to this embodiment is a system in which the diagnostic support device 100 is replaced by the diagnostic support device 102 in the example shown in Figure 3.

[0136] <Instruction receiving unit 110> The instruction receiving unit 110 receives a determination instruction, which is an instruction to make a determination regarding multiple target devices.

[0137] <Characteristic extraction unit 120> The characteristic extraction unit 120 extracts device characteristics representing security-related information for each of the multiple target devices from the information of the multiple target devices.

[0138] <Judgment unit 130> The determination unit 130 determines the magnitude of the device risk, which is a risk that may exist for each of the multiple target devices, based on the device characteristics of the multiple target devices. <Diagnostic procedure extraction unit 140> The diagnostic procedure extraction unit 140 extracts a diagnostic procedure for each of the multiple target devices to diagnose whether a risk actually exists in that device.

[0139] <Priority determining unit 150> The priority determination unit 150 determines the priority of the diagnostics of multiple diagnostic devices using the magnitude of the device risk of multiple target devices. The priority determination unit 150 determines the priority so that the greater the magnitude of the device risk of a target device, the higher the priority of the diagnostics of the diagnostic device.

[0140] <Output section 160> The output unit 160 outputs the magnitude of device risk and diagnostic procedure information for multiple target devices in the order of determined priority. In this case, the output unit 160 may output the combination of the magnitude of risk for each identified security item (in other words, item risk) for each target device and the diagnostic procedure associated with that security item, for example, in order from the security item with the greatest risk. In this case, the output unit 160 may output the above-mentioned risk value as the magnitude of the security item's risk. The output destination to which the output unit 160 outputs the magnitude of device risk and diagnostic procedure information for multiple target devices (hereinafter referred to as the output destination of the output unit 160) may be, for example, the display of the diagnostic support device 102. The output destination of the output unit 160 may also be a user's terminal device that is communicably connected to the diagnostic support device 102. The output destination of the output unit 160 may also be a storage device or other information processing device such as a server that the diagnostic support device 102 can access.

[0141] <Operation> Figure 9 is a flowchart illustrating an example of the overall operation of the diagnostic support device related to this disclosure.

[0142] Hereinafter, an overall example of the operation of the diagnostic support device 102 according to the fourth embodiment of this disclosure will be described in detail with reference to Figure 9.

[0143] In the example shown in Figure 9, the instruction receiving unit 110 receives information on multiple devices that are the target devices (step S121).

[0144] Next, for example, the characteristic extraction unit 120 selects one device as the target device from among the multiple devices that have not been selected (step S122).

[0145] Next, the diagnostic support device 102 performs a determination process (step S123). The determination process will be explained in detail later.

[0146] If there is a device among the multiple devices that has not been selected (YES in step S124), the diagnostic support device 102 repeats the operations from step S122 onward.

[0147] If there are no unselected devices among the multiple devices (NO in step S124), that is, if all of the multiple devices are selected as target devices, the priority determination unit 150 determines the priority of the multiple devices using the magnitude of the device risk (step S125).

[0148] Then, the output unit 160 outputs information on the device risk and diagnostic procedure for multiple devices in order of priority (step S126).

[0149] Next, the operation of the determination process of the diagnostic support device 102 according to the fourth embodiment of this disclosure will be described in detail with reference to the drawings.

[0150] Figure 10 is a flowchart illustrating an example of the operation of the determination process of the diagnostic support device relating to this disclosure.

[0151] In the following, an example of the operation of the determination process of the diagnostic support device 102 according to the fourth embodiment of this disclosure will be described in detail with reference to Figure 10. The operations of steps S102 to S105 and step S116 shown in Figure 10 are the same as the operations of steps S102 to S105 and step S116 shown in Figure 7, respectively.

[0152] <Effects> The embodiment described above has the same effects as the third embodiment. The reason for this is the same as the reason for the effects of the third embodiment. In addition, this embodiment has the effect of allowing diagnosis to be started with the device that should be diagnosed first among the multiple devices. This is because the priority determination unit 150 determines the priority based on the magnitude of the device risk of the multiple devices. Then, the output unit 160 outputs the device risk and diagnostic procedure information of the multiple devices in the order of the determined priority.

[0153] <Other Embodiments> Each of the diagnostic support devices according to the embodiments of this disclosure can be implemented by a computer and a program to control the computer, dedicated hardware, or a combination of a computer and a program to control the computer and dedicated hardware.

[0154] Figure 11 is a diagram showing an example of the hardware configuration of a computer 1000 that can realize a diagnostic support device according to the embodiment of this disclosure. In the example shown in Figure 11, the computer 1000 includes a processor 1001, a memory 1002, a storage device 1003, and an I / O (Input / Output) interface 1004. The computer 1000 can also access a storage medium 1005. The memory 1002 and the storage device 1003 are, for example, storage devices such as RAM (Random Access Memory) and hard disks. The storage medium 1005 is, for example, a storage device such as RAM and hard disks, ROM (Read Only Memory), and a portable storage medium. The storage device 1003 may also be the storage medium 1005. The processor 1001 can read and write data and programs to the memory 1002 and the storage device 1003. The processor 1001 can access, for example, an LLM server 200 via the I / O interface 1004. The processor 1001 can access the storage medium 1005. The storage medium 1005 stores a program that causes the computer 1000 to operate as a diagnostic support device according to the embodiment of this disclosure.

[0155] The processor 1001 loads a program stored in the storage medium 1005 into the memory 1002 that causes the computer 1000 to operate as a diagnostic support device according to the embodiment of this disclosure. The processor 1001 then executes the program loaded into the memory 1002, causing the computer 1000 to operate as a diagnostic support device according to the embodiment of this disclosure.

[0156] The instruction receiving unit 110, characteristic extraction unit 120, extraction instruction unit 121, determination unit 130, diagnostic procedure extraction unit 140, priority determination unit 150, and output unit 160 can be implemented, for example, by a processor 1001 that executes a program loaded into memory 1002. The information storage unit 170 can be implemented by a storage device 1003 such as memory 1002 or hard disk included in the computer 1000. Some or all of the instruction receiving unit 110, characteristic extraction unit 120, extraction instruction unit 121, determination unit 130, diagnostic procedure extraction unit 140, priority determination unit 150, output unit 160, and information storage unit 170 can be implemented by dedicated circuits that realize their respective functions.

[0157] Furthermore, some or all of the above embodiments may also be described as follows, but are not limited to the following.

[0158] (Note 1) A characteristic extraction means for extracting device characteristics representing information related to the security of the target device from the information of the target device, A determination means for determining the magnitude of device risk, which is a risk that may exist in the target device, based on the device characteristics and the magnitude of risk for each security item, which is a predetermined item related to security. An output means for outputting the magnitude of the device risk, A diagnostic support device equipped with the following features.

[0159] (Note 2) Procedure extraction means for extracting diagnostic procedures for diagnosing the actual state of risk in the target device. Furthermore, The output means outputs the extracted information of the diagnostic procedure. The diagnostic support device described in Appendix 1.

[0160] (Note 3) The characteristic extraction means extracts the device characteristics from the information of each of the multiple target devices, The determination means determines the device risk of each of the plurality of target devices, The output means outputs the magnitude of the device risk for the plurality of target devices and the diagnostic procedure information in order of the magnitude of the device risk. Diagnostic support device as described in Appendix 2.

[0161] (Note 4) The characteristic extraction means extracts the device characteristics represented by security items that represent matters related to security from the information of the target device, The determination means uses item risk information, which represents possible security risks defined for the state of the security item, to determine the device risk from the device characteristics. A diagnostic support device as described in any one of the items 1 to 3 of the appendix.

[0162] (Note 5) The determination means determines the magnitude of the item risk of the identified security item as the magnitude of the device risk. Diagnostic support device as described in Appendix 4.

[0163] (Note 6) The information of the target device includes information representing at least one of the results of a vulnerability scan of the target device and the results of a check of the settings of the target device. The aforementioned security items include guideline items that represent matters to be observed, as defined in the security guidelines. The characteristic extraction means uses the information of the target device to extract information representing the guideline items that are not followed in the target device, as the device characteristics. Diagnostic support device as described in Appendix 4.

[0164] (Note 7) The characteristic extraction means identifies the impact of at least one of the vulnerabilities indicated by the scan results and the settings indicated by the check results, and sets the guideline items related to the impact as guideline items that are not being followed. Diagnostic support device as described in Appendix 6.

[0165] (Note 8) The information of the target device includes information representing at least one of the type of function of the target device and the type of retained information which is the information to be retained. The security item includes a device item that represents a matter specified for at least one of the type of function and the type of retained information, The characteristic extraction means uses the information of the target device to extract, as the device characteristics, information representing the device item that represents at least one of the type of function of the target device and the type of retained information of the target device from among the device items. Diagnostic support device as described in Appendix 4.

[0166] (Note 9) The information of the target device includes, as information representing at least one of the type of function of the target device and the type of retained information, information representing at least one of the specifications and use of the target device. The characteristic extraction means estimates at least one of the function type and the retained information type from the information representing at least one of the specifications and use of the target device, and determines the device item that represents at least one of the estimated function and the retained information type from the predetermined device items. Diagnostic support device as described in Appendix 8.

[0167] (Note 10) The information of the target device includes information of the managing entity that manages the target device, The aforementioned security items include the administrator items, which represent matters specified for the administrator's information. The characteristic extraction means uses the information of the target device to extract information representing the management entity item, which represents the information of the management entity, from the predetermined management entity item, as the device characteristic. Diagnostic support device as described in Appendix 4.

[0168] (Note 11) The information of the managing entity includes any of the following: information representing the attributes of the managing entity; information on security events that have occurred in the past within the managed area controlled by the managing entity; information indicating whether or not the managing entity has received security certification or holds security qualifications; and information on the business field of the managing entity or the organization to which the managing entity belongs. Diagnostic support device as described in Appendix 10.

[0169] (Note 12) From the information of the target device, device characteristics representing information related to the security of the target device are extracted. Based on the device characteristics, the magnitude of the device risk, which is a risk that may exist in the target device, is determined based on the magnitude of the risk for each security item, which is a predetermined item related to security. Output the magnitude of the risk associated with the aforementioned device. Diagnostic support methods.

[0170] (Note 13) A diagnostic procedure for diagnosing the actual state of risk in the aforementioned target device is extracted. Output the extracted information from the diagnostic procedure. Diagnostic support methods as described in Appendix 12.

[0171] (Note 14) From the information of each of the multiple target devices, the device characteristics are extracted, The device risk of each of the aforementioned multiple target devices is determined, The magnitude of the device risk for the multiple target devices and the information of the diagnostic procedure are output in order of the magnitude of the device risk. Diagnostic support methods as described in Appendix 13.

[0172] (Note 15) From the information of the target device, the device characteristics represented by the security items that represent matters related to security are extracted, The device risk is determined from the device characteristics using item risk information, which represents the possible security risks defined for the status of the aforementioned security items. A diagnostic support method described in any one of the items 12 to 14 of the appendix.

[0173] (Note 16) The statistical value of the magnitude of the risk for the identified security item is determined as the magnitude of the device risk. Diagnostic support methods as described in Appendix 15.

[0174] (Note 17) The information of the target device includes information representing at least one of the results of a vulnerability scan of the target device and the results of a check of the settings of the target device. The aforementioned security items include guideline items that represent matters to be observed, as defined in the security guidelines. Using the information of the target device, information representing the guideline items that are not followed in the target device is extracted as the device characteristics. Diagnostic support methods as described in Appendix 15.

[0175] (Note 18) Identify the impact of at least one of the vulnerabilities indicated by the scan results and the settings indicated by the check results, and mark the guideline items related to the impact as unfollowed guideline items. Diagnostic support methods as described in Appendix 17.

[0176] (Note 19) The information of the target device includes information representing at least one of the type of function of the target device and the type of retained information which is the information to be retained. The security item includes a device item that represents a matter specified for at least one of the type of function and the type of retained information, Using the information of the target device, information representing the device item that represents at least one of the type of function of the target device and the type of retained information is extracted as the device characteristic. Diagnostic support methods as described in Appendix 15.

[0177] (Note 20) The information of the target device includes, as information representing at least one of the type of function of the target device and the type of retained information, information representing at least one of the specifications and use of the target device. From the information representing at least one of the specifications and uses of the target device, the type of function and at least one of the retained information are estimated, and from the predetermined device items, the device item representing at least one of the estimated function and the type of retained information is determined. Diagnostic support methods as described in Appendix 19.

[0178] (Note 21) The information of the target device includes information of the managing entity that manages the target device, The aforementioned security items include the administrator items, which represent matters specified for the administrator's information. Using the information of the target device, information representing the management entity item, which represents the information of the management entity, is extracted from the predetermined management entity item as the device characteristic. Diagnostic support methods as described in Appendix 15.

[0179] (Note 22) The information of the managing entity includes any of the following: information representing the attributes of the managing entity; information on security events that have occurred in the past within the managed area controlled by the managing entity; information indicating whether or not the managing entity has received security certification or holds security qualifications; and information on the business field of the managing entity or the organization to which the managing entity belongs. Diagnostic support methods as described in Appendix 21.

[0180] (Note 23) A characteristic extraction process that extracts device characteristics representing information related to the security of the target device from the information of the target device, A determination process that determines the magnitude of device risk, which is a risk that may exist in the target device, based on the device characteristics and the magnitude of risk for each security item, which is a predetermined item related to security. Output processing to output the magnitude of the device risk, A program that causes a computer to execute something.

[0181] (Note 24) The aforementioned program, Procedure extraction process for extracting diagnostic procedures for diagnosing the actual state of risk in the aforementioned target device. Further, have the computer execute it, The output process outputs the extracted information of the diagnostic procedure. The program described in Appendix 23.

[0182] (Note 25) The characteristic extraction process extracts the device characteristics from the information of each of the multiple target devices, The aforementioned determination process determines the device risk for each of the multiple target devices, The output process outputs the magnitude of the device risk for the multiple target devices and the diagnostic procedure information in order of the magnitude of the device risk. The program described in Appendix 24.

[0183] (Note 26) The characteristic extraction process extracts the device characteristics represented by the security items that represent matters related to security from the information of the target device, The aforementioned determination process uses item risk information, which represents possible security risks defined for the state of the security item, to determine the device risk from the device characteristics. The program described in any one of the items 23 to 25 of the appendix.

[0184] (Note 27) The determination process determines the magnitude of the item risk of the identified security item as the magnitude of the device risk. The program described in Appendix 26.

[0185] (Note 28) The information of the target device includes information representing at least one of the results of a vulnerability scan of the target device and the results of a check of the settings of the target device. The aforementioned security items include guideline items that represent matters to be observed, as defined in the security guidelines. The characteristic extraction process uses the information of the target device to extract information representing the guideline items that are not followed in the target device, as the device characteristics. The program described in Appendix 26.

[0186] (Note 29) The characteristic extraction process identifies the impact of at least one of the vulnerabilities indicated by the scan results and the settings indicated by the check results, and identifies the guideline items related to the impact as guideline items that are not being followed. The program described in Appendix 28.

[0187] (Note 30) The information of the target device includes information representing at least one of the type of function of the target device and the type of retained information which is the information to be retained. The security item includes a device item that represents a matter specified for at least one of the type of function and the type of retained information, The characteristic extraction process uses the information of the target device to extract, as the device characteristics, information representing the device item that represents at least one of the type of function of the target device and the type of retained information of the target device from among the device items. The program described in Appendix 26.

[0188] (Note 31) The information of the target device includes, as information representing at least one of the type of function of the target device and the type of retained information, information representing at least one of the specifications and use of the target device. The characteristic extraction process estimates at least one of the function type and the retained information type from the information representing at least one of the specifications and use of the target device, and determines the device item that represents at least one of the estimated function and the retained information type from the predetermined device items. The program described in Appendix 30.

[0189] (Note 32) The information of the target device includes information of the managing entity that manages the target device, The aforementioned security items include the administrator items, which represent matters specified for the administrator's information. The characteristic extraction process uses the information of the target device to extract information representing the management entity item, which represents the information of the management entity, from the predetermined management entity item, as the device characteristic. The program described in Appendix 26.

[0190] (Note 33) The information of the managing entity includes any of the following: information representing the attributes of the managing entity; information on security events that have occurred in the past within the managed area controlled by the managing entity; information indicating whether or not the managing entity has received security certification or holds security qualifications; and information on the business field of the managing entity or the organization to which the managing entity belongs. The program described in Appendix 32.

[0191] (Note 34) A diagnostic support device described in any one of the items 1 to 3 of the appendix, A large-scale language model server that provides services using large-scale language models, Includes, The diagnostic support device is, Extraction instruction means transmits an instruction to the large-scale model server to perform a process of extracting at least a portion of the device characteristics from at least a portion of the information of the target device. Equipped with, Upon receiving the instruction, the large-scale language model server uses the large-scale language model to extract at least a portion of the device characteristics from at least a portion of the information of the target device. The determination means determines the magnitude of the device risk from the device characteristics, including at least a portion of the device characteristics extracted by the large-scale language model server. Diagnostic support system.

[0192] Although the present invention has been described above with reference to embodiments, the present invention is not limited to the above embodiments. Various modifications to the configuration and details of the present invention can be made that will be understood by those skilled in the art within the scope of the present invention. [Explanation of Symbols]

[0193] 1. Diagnostic support system 10 Diagnostic support devices 100 Diagnostic support devices 101 Diagnostic support device 102 Diagnostic support device 110 Instruction receiving unit 120 Characteristic Extraction Unit 121 Extraction instruction section 130 Judgment section 140 Diagnostic Procedure Extraction Unit 150 Priority determination section 160 Output section 170 Information storage section 200 LLM servers 300 Communication Networks 1000 computers 1001 Processor 1002 memory 1003 Storage device 1004 I / O Interface 1005 Storage medium

Claims

1. A characteristic extraction means for extracting device characteristics representing information related to the security of the target device from the information of the target device, A determination means for determining the magnitude of device risk, which is a risk that may exist in the target device, based on the device characteristics and the magnitude of risk for each security item, which is a predetermined item related to security. An output means for outputting the magnitude of the device risk, A diagnostic support device equipped with the following features.

2. Procedure extraction means for extracting diagnostic procedures for diagnosing the actual state of risk in the target device. Furthermore, The output means outputs the extracted information of the diagnostic procedure. The diagnostic support device according to claim 1.

3. The characteristic extraction means extracts the device characteristics from the information of each of the multiple target devices, The determination means determines the device risk of each of the plurality of target devices, The output means outputs the magnitude of the device risk for the plurality of target devices and the diagnostic procedure information in order of the magnitude of the device risk. The diagnostic support device according to claim 2.

4. The characteristic extraction means extracts the device characteristics represented by the security items that represent matters related to security from the information of the target device, The determination means uses item risk information, which represents possible security risks defined for the state of the security item, to determine the device risk from the device characteristics. A diagnostic support device according to any one of claims 1 to 3.

5. The determination means determines the magnitude of the item risk of the identified security item as the magnitude of the device risk. The diagnostic support device according to claim 4.

6. The information of the target device includes information representing at least one of the results of a vulnerability scan of the target device and the results of a check of the settings of the target device. The aforementioned security items include guideline items that represent matters to be observed, as defined in the security guidelines. The characteristic extraction means uses the information of the target device to extract information representing the guideline items that are not followed in the target device, as the device characteristics. The diagnostic support device according to claim 4.

7. The characteristic extraction means identifies the impact of at least one of the vulnerabilities indicated by the scan results and the settings indicated by the check results, and sets the guideline items related to the impact as guideline items that are not being followed. The diagnostic support device according to claim 6.

8. The information of the target device includes information representing at least one of the type of function of the target device and the type of retained information which is the information to be retained. The security item includes a device item that represents a matter defined for at least one of the type of function and the type of retained information, The characteristic extraction means uses the information of the target device to extract, as the device characteristics, information representing the device item that represents at least one of the type of function of the target device and the type of retained information of the target device from among the device items. The diagnostic support device according to claim 4.

9. The information of the target device includes, as information representing at least one of the type of function of the target device and the type of retained information, information representing at least one of the specifications and use of the target device. The characteristic extraction means estimates at least one of the function type and the retained information type from the information representing at least one of the specifications and use of the target device, and determines the device item that represents at least one of the estimated function and the retained information type from the predetermined device items. The diagnostic support device according to claim 8.

10. The information of the target device includes information of the managing entity that manages the target device, The aforementioned security items include the administrator items, which represent matters defined for the administrator's information. The characteristic extraction means uses the information of the target device to extract information representing the management entity item, which represents the information of the management entity, from the predetermined management entity item, as the device characteristic. The diagnostic support device according to claim 4.

11. The information of the managing entity includes any of the following: information representing the attributes of the managing entity; information on security events that have occurred in the past within the managed area controlled by the managing entity; information indicating whether or not the managing entity has received security certification or holds security qualifications; and information on the business field of the managing entity or the organization to which the managing entity belongs. The diagnostic support device according to claim 10.

12. A diagnostic support device according to any one of claims 1 to 3, A large-scale language model server that provides services using large-scale language models, Includes, The diagnostic support device is Extraction instruction means transmits an instruction to the large-scale language model server to perform a process of extracting at least a portion of the device characteristics from at least a portion of the information of the target device. Equipped with, Upon receiving the instruction, the large-scale language model server uses the large-scale language model to extract at least a portion of the device characteristics from at least a portion of the information of the target device. The determination means determines the magnitude of the device risk from the device characteristics, including at least a portion of the device characteristics extracted by the large-scale language model server. Diagnostic support system.

13. From the information of the target device, device characteristics representing information related to the security of the target device are extracted. Based on the device characteristics, the magnitude of the device risk, which is a risk that may exist in the target device, is determined based on the magnitude of the risk for each security item, which is a predetermined item related to security. Output the magnitude of the risk associated with the aforementioned device. Diagnostic support methods.

14. A characteristic extraction process that extracts device characteristics representing information related to the security of the target device from the information of the target device, A determination process that determines the magnitude of device risk, which is a risk that may exist in the target device, based on the device characteristics and the magnitude of risk for each security item, which is a predetermined item related to security. Output processing to output the magnitude of the device risk, A program that causes a computer to execute something.

Citation Information

Patent Citations

  • Incident handling support apparatus

    JP2019114172A