Information providing device, information providing method, and program
The data processing device addresses the challenge of identifying security risks in large-scale communication systems by integrating component identification, relationship, and safety information display, enhancing risk assessment and mitigation capabilities.
Patent Information
- Application Number
- JP2023556051
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-10-29
- Publication Date
- 2025-05-20
- Estimated Expiration
- 2041-10-29
AI Technical Summary
Large-scale communication systems face challenges in accurately identifying security risks due to the mixing of components from multiple manufacturers with varying security standards and susceptibility to cyber attacks, making it difficult to assess and mitigate vulnerabilities effectively.
A data processing device that acquires identification information for specific component devices, collects relationship and safety information, and displays this information together with the relationship information to facilitate the identification of security risks.
Enables accurate identification of security risks by visually presenting the connections and safety information of system components, allowing for better risk assessment and mitigation in communication systems.
Smart Images

Figure 0007679886000001 
Figure 0007679886000002 
Figure 0007679886000003
Abstract
Description
[Technical field]
[0001] The present invention relates to a data processing device, a data processing method, and a recording medium, and more particularly to a data processing device, a data processing method, and a recording medium for information communication devices constituting a communication system. [Background technology]
[0002] There is provided a communication system that enables remote control of industrial equipment by a control system by connecting devices such as sensors, cameras, IoT (Internet of Things) equipment, and communication terminals in a factory, as well as industrial equipment such as manufacturing equipment and transport equipment, to the control system via a communication network. For example, the communication system is an IoT system, an OT (Operational Technology) control system, or an ICT (Information Communication Technology) system. In recent years, the possibility (threat) of these communication systems being subjected to cyber attacks from outside or inside has been increasing.
[0003] To operate a communication system safely, it is also important to take measures against vulnerabilities in the software running within the communication system. A software vulnerability is an information security flaw caused by a program malfunction or a design error. Alternatively, cyber attacks may be carried out using backdoors invisible to the user. If software vulnerabilities are left unattended, not only will the communication system be more likely to be subject to cyber attacks, but the business damage caused by a cyber attack will also be greater. Therefore, related technologies for determining the impact of software vulnerabilities have been developed (for example, Patent Document 1). [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Patent No. 5781616 Summary of the Invention [Problem to be solved by the invention]
[0005] Generally, the larger the scale of a communication system, the more products from multiple manufacturers are mixed in that system. Different manufacturers may have different standards for the confidentiality (security) of information. Also, different manufacturers or products have different susceptibility to being targeted by attackers. As a result, the cost of checking whether each component device in the communication system is secure increases, and the security risk of the communication system becomes greater. Particularly in large-scale communication systems, it is difficult to accurately identify the factors (threats) that manifest security risks.
[0006] The present invention has been made in view of the above-mentioned problems, and has as its object to provide a technique that makes it possible to accurately identify factors (threats) that manifest security risks. [Means for solving the problem]
[0007] A data processing device according to one embodiment of the present invention includes an acquisition means for acquiring identification information that identifies a specific component device of a communication system, a collection means for using the identification information to collect relationship information indicating components that have a connection or relationship with the specific component device and safety information related to the information security safety of the specific component device and the components, and a display means for displaying the safety information together with or in association with the relationship information.
[0008] In one embodiment of the data processing method of the present invention, identification information that identifies a specific component of a communication system is obtained, and the identification information is used to collect relationship information indicating components that have a connection or relationship with the specific component, and safety information related to the information security safety of the specific component and the components, and the safety information is displayed together with or in association with the relationship information.
[0009] A recording medium according to one embodiment of the present invention stores a program for causing a computer to obtain identification information that identifies a specific component device of a communication system, use the identification information to collect relationship information indicating components that have a connection or relationship with the specific component device and safety information related to the safety of the specific component device and the components in terms of information security, and display the safety information together with or in association with the relationship information. Effect of the Invention
[0010] According to one aspect of the present invention, it is possible to accurately identify factors (threats) that manifest security risks in a communication system. [Brief description of the drawings]
[0011] [Figure 1] FIG. 1 is a diagram illustrating an example of a communication system that is the substance of a virtual model generated by a data processing device according to any one of the first to third embodiments. [Diagram 2] 1 is a block diagram showing a configuration of a data processing device according to a first embodiment. [Diagram 3] 4 is a flowchart showing the operation of the data processing device according to the first embodiment. [Figure 4] FIG. 11 is a diagram showing an example of relationship information and safety information displayed by a display unit of a data processing device according to a second embodiment. [Diagram 5] FIG. 11 is a block diagram showing a configuration of a data processing device according to a third embodiment. [Figure 6] 11 is a flowchart showing the operation of a data processing device according to a third embodiment. [Figure 7] FIG. 11 is a diagram showing a first example of relationship information and safety information displayed by the display unit of the data processing device according to the third embodiment. [Figure 8] FIG. 11 is a diagram showing a second example of the relationship information and safety information displayed by the display unit of the data processing device according to the third embodiment. [Figure 9]FIG. 13 is a diagram showing a third example of relationship information and safety information displayed by the display unit of the data processing device according to the third embodiment. [Figure 10] FIG. 1 is a diagram illustrating an example of a hardware configuration of a data processing device according to any one of the first to third embodiments. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0012] Some embodiments of the present invention are described below with reference to the drawings.
[0013] (Communication System 1) An example of the configuration of a communication system 1 will be described with reference to Fig. 1. Fig. 1 is a diagram that illustrates an example of the configuration of the communication system 1. For example, the communication system 1 is any one of an IoT (Internet Of Things) system, an ICT (Information and Communication Technology) system, a LAN (Local Area Network), an infrastructure system, and an industrial control system (ICS). However, the communication system 1 may be other than these examples.
[0014] The communication system 1 is an entity of a virtual model generated by data processing devices 10, 20, and 30 according to embodiments 1 to 3 described below. That is, the data processing devices 10, 20, and 30 execute data processing for generating the virtual model of the communication system 1.
[0015] As shown in Fig. 1, the communication system 1 includes a control server 100, a client terminal 200 (hereinafter referred to as nodes 100 and 200), a switch 300, and a firewall 400. The communication system 1 establishes a communication network such as a local area network (LAN) or a wide area network (WAN). In Fig. 1, the lines connecting the constituent devices of the communication system 1 (nodes 100 and 200, the switch 300, and the firewall 400) indicate that the constituent devices can communicate with each other.
[0016] The nodes 100 and 200 are hardware devices or software having communication functions and information processing functions (computing functions). For example, the nodes 100 and 200 are personal computers, HMIs (Human Machine Interfaces), control servers, log servers, PLCs (Programmable Logic Controllers), APIs (Application Programming Interfaces), IoT (Internet of Things) devices, or mobile devices. Here, it is assumed that the node 100 is a client terminal (e.g., a personal computer), and the node 200 is a control server.
[0017] The switch 300 is a network device that realizes a routing function by hardware processing, such as Ethernet. As shown in FIG. 1, the switch 300 has a role of transferring communications between the constituent devices of the communication system 1.
[0018] Firewall 400 is provided between the constituent devices of communication system 1 and between communication system 1 and an external network (the Internet in FIG. 1), and restricts data communication or communication connections for reasons of computer security, etc. Firewall 400 may be implemented in a router, or may be realized as application software (a so-called application firewall).
[0019] The configuration of the communication system 1 shown in Fig. 1 is merely an example. For example, the communication system 1 may further include an industrial facility that is an object to be controlled by the PLC. In addition, the number of the nodes 100 and the number of the nodes 200 may be one, or may be two or more.
[0020] In the following description, "node 100 (200)" means at least one of node 100 and node 200. In the following, the route of a cyber-attack is called an "attack path," and the procedure of a cyber-attack is called an "attack scenario."
[0021] [Embodiment 1] The first embodiment will be described with reference to FIG. 2 and FIG.
[0022] (Data processing device 10) The configuration of the data processing device 10 according to the first embodiment will be described with reference to Fig. 2. Fig. 2 is a block diagram showing the configuration of the data processing device 10.
[0023] As shown in FIG. 2, the data processing device 10 includes an acquisition unit 11, a collection unit 12, and a display unit 13.
[0024] The acquisition unit 11 acquires identification information for identifying a specific component device of the communication system 1. The acquisition unit 11 is an example of an acquisition means.
[0025] For example, the acquisition unit 11 accepts an operation to specify or select a specific component device from among the component devices (nodes 100, 200, switch 300, firewall 400) of the communication system 1 (FIG. 1) via an input device (not shown).
[0026] The acquisition unit 11 receives information indicating the content of an operation on an input device (not shown). The acquisition unit 11 identifies a specific component device based on the information indicating the content of the operation. For example, the acquisition unit 11 searches for and acquires information identifying a specified or selected specific component device (e.g., an identifier of the component device) from a first database (not shown).
[0027] Alternatively, the acquisition unit 11 may acquire identification information for identifying a specific component device selected from among the component devices displayed on the network configuration diagram of the communication system 1 (FIG. 4).
[0028] The acquisition unit 11 outputs, to the collection unit 12, identification information for identifying a specific component device.
[0029] The collection unit 12 collects relationship information and safety information using the identification information. The relationship information indicates components that have a connection or relationship with a specific component. The safety information is related to the safety of the components and components in terms of information security. The collection unit 12 is an example of a collection means.
[0030] For example, the collection unit 12 receives from the acquisition unit 11 identification information that identifies a particular component device of the communication system 1 (for example, a device identifier).
[0031] First, the collection unit 12 acquires relationship information indicating a connection or relationship between a specific component device and other component devices of the communication system 1 (FIG. 1). A component device having a connection or relationship may be included in a single attack path, and therefore has a connection or relationship in terms of information security. The component devices include hardware and software components, as well as parts and modules that constitute them. Here, hardware parts are replaceable parts such as processors and memories. Software parts are components other than modules, such as functions and libraries. A hardware module is a set of replaceable parts that are configured to perform a function. A software module is a part of software and an independent program.
[0032] The collection unit 12 uses information identifying a specific component device of the communication system 1 to search for and acquire, from a second database (not shown), relationship information indicating connections or relationships between the components of the communication system 1. For example, the relationship information is information indicating the manufacturing process of the communication system 1, information indicating attack paths that are intrusion routes in cyber-attacks obtained by risk analysis or the like, or information indicating an attack scenario including multiple possible attack paths in cyber-attacks.
[0033] Secondly, the collection unit 12 collects safety information related to the safety of the constituent devices in terms of information security. The collection unit 12 is an example of a collection means. The safety information includes the inspection results of the information security inspection of the constituent devices (e.g., source code inspection, backdoor inspection). The safety information also includes information identifying the product or manufacturer of the constituent devices (e.g., manufacturer name).
[0034] For example, the collector 12 acquires from the acquirer 11 relationship information indicating connections or relationships between the constituent devices of the communication system 1 (in FIG. 1, the nodes 100, 200, the switch 300, and the firewall 400).
[0035] The collection unit 12 acquires information about the constituent equipment of the communication system 1 from a third database (not shown) that stores information about the constituent equipment of the communication system 1 (e.g., product identifiers, manufacturer names, whether or not there are results of information security inspections, etc.).
[0036] Next, the collection unit 12 collects safety information related to the safety in terms of information security of the constituent devices of the communication system 1 from a fourth database (not shown) that stores software analysis information. The software analysis includes, for example, source code analysis, binary code analysis, OSS (Open Source Software) analysis, coding check, port scan, and installed software scan.
[0037] For example, safety information related to the safety of the constituent devices of the communication system 1 in terms of information security includes the inspection results of an information security inspection of the constituent devices of the communication system 1.
[0038] Alternatively, the collection unit 12 may obtain, from a software analysis device (not shown), the inspection result of the information security inspection for a specific component device of the communication system 1. The data processing device 10 may include, as a part thereof, a software analysis unit that performs an analysis of the specific component device.
[0039] Alternatively, the safety information relating to the safety of a particular component device of the communication system 1 in terms of information security may include the results of a backdoor inspection.
[0040] The collection unit 12 outputs to the display unit 13 relationship information regarding a specific component device of the communication system 1 and safety information related to the safety of the specific component device of the communication system 1 in terms of information security.
[0041] The display unit 13 displays the safety information together with or in association with the relationship information about a specific component device of the communication system 1. The display unit 13 is an example of a display means.
[0042] The display unit 13 may display safety information together with the manufacturing process diagram of the communication system 1 or on top of the manufacturing process diagram.
[0043] Alternatively, the display unit 13 may display the safety information on top of a manufacturing process diagram of the communication system 1.
[0044] Alternatively, the display unit 13 may display the manufacturing process diagram on which the safety information is displayed, together with the network configuration diagram of the communication system 1.
[0045] For example, the display unit 13 receives from the collection unit 12 relationship information indicating connections or relationships between the constituent devices of the communication system 1. In addition, the display unit 13 receives from the collection unit 12 safety information related to the safety of the constituent devices of the communication system 1 in terms of information security.
[0046] The display unit 13 generates first image data including the relationship information, and also generates second image data including the safety information.
[0047] Then, the display unit 13 generates the third image data by synthesizing the first image data and the second image data to form a single screen. For example, the third image is obtained by arranging the first image and the second image side by side (embodiment 2).
[0048] The display unit 13 outputs the third image data to a display device (not shown) (for example, a monitor), and then the display unit 13 displays the third image on the screen of the display device.
[0049] The third image presents the relationship information contained in the first image data and the safety information contained in the second image data that presents the safety information. The relationship information and the safety information are displayed together on the same screen, rather than separately, so that the information can be viewed at a glance.
[0050] The ability to view the information at a glance allows the connections or relationships between the constituent devices as well as the security of those constituent devices to be grasped at a glance, making it possible to accurately identify factors (threats) that expose security risks in communication system 1.
[0051] The display unit 13 may store the relationship information and the safety information in a fifth database (not shown) in association with each other.
[0052] (Operation of data processing device 10) The operation of the data processing device 10 according to the first embodiment will be described with reference to Fig. 3. Fig. 3 is a flowchart showing the flow of processes executed by each unit of the data processing device 10.
[0053] 3, first, the acquiring unit 11 acquires identification information for identifying a specific component device of the communication system 1 (S101). The acquiring unit 11 outputs the identification information for identifying the specific component device to the collecting unit 12.
[0054] The collection unit 12 receives, from the acquisition unit 11, identification information that identifies a specific component device.
[0055] Next, the collection unit 12 uses the identification information to obtain relationship information indicating components having a connection or relationship with a specific component device. The collection unit 12 also uses the identification information to collect safety information related to the safety of the specific component device and component device in terms of information security (S102).
[0056] The collection unit 12 outputs the relationship information and safety information regarding a specific component device of the communication system 1 to the display unit 13.
[0057] The display unit 13 receives relationship information and safety information about specific components of the communication system 1 from the collection unit 12 .
[0058] Thereafter, the display unit 13 displays the safety information together with or in association with the relationship information (S103).
[0059] For example, the display unit 13 generates third image data including the relationship information and the safety information by combining the first image data including the relationship information and the second image data including the safety information. Then, the display unit 13 displays the generated third image data on a screen of a display device (not shown).
[0060] The display unit 13 may store the relationship information and the safety information in a fifth database (not shown) in association with each other.
[0061] This is the end of the operation of the data processing device 10 according to the first embodiment.
[0062] (Effects of this embodiment) According to the configuration of this embodiment, the acquisition unit 11 acquires identification information that identifies a specific component device of the communication system 1. The collection unit 12 uses the identification information to collect relationship information indicating components having a connection or relationship with the specific component device, and safety information related to the safety of the specific component device and its components in terms of information security. The collection unit 12 inputs the relationship information indicating the connection or relationship between the components of the communication system 1. The display unit 13 displays the safety information together with or in association with the relationship information.
[0063] Since the relationship information and the safety information are displayed together, rather than separately, the information can be viewed at a glance. The information can be viewed at a glance to grasp the connections or relationships between the component devices as well as the safety of those component devices, so that factors (threats) that manifest security risks in the communication system 1 can be accurately identified.
[0064] [Embodiment 2] A second embodiment will be described with reference to FIG. 4. In the second embodiment, an example of the relationship information and safety information described in the first embodiment will be described. The configuration and operation of a data processing device 20 according to the second embodiment are the same as the configuration and operation of the data processing device 10 (FIG. 2) according to the first embodiment. In the second embodiment, the description in the first embodiment will be cited and the description of the configuration and operation of the data processing device 20 will be omitted.
[0065] (Examples of relationship and safety information) Here, an example in which safety information is displayed together with relationship information will be described. In this example, the relationship information and the safety information are simultaneously displayed in the same image. Alternatively, a first image displaying the relationship information and a second image displaying the safety information may be displayed in a switching manner.
[0066] An example of the third image displayed by the display unit 13 (FIG. 2) of the data processing device 20 will be described with reference to Fig. 4. As described in the first embodiment, the third image is, for example, a first image and a second image arranged side by side, left and right or up and down. The first image presents relationship information, and the second image presents safety information.
[0067] Fig. 4 is a diagram showing an example of the third image. As shown in Fig. 4, in one example, the third image includes a network configuration diagram corresponding to the first image and a process diagram corresponding to the second image. The network configuration diagram shows the network configuration of the communication system 1. The process diagram shows a supply chain from procurement of components of the communication system 1 to systemization (integration) of the communication system 1.
[0068] As shown in Fig. 4, the network configuration diagram of the communication system 1 is intended to display the network topology. It represents the connections or relationships between the constituent devices of the communication system 1 (for example, an OA (Office Automation) terminal and a log server). On the other hand, the process diagram of the communication system 1 represents the processes through which the communication system 1 was constructed.
[0069] The components shown in the network configuration diagram in Fig. 4 correspond to the components shown in the construction process in the process diagram. However, some of the components are omitted in the process diagram. In Fig. 4, safety information is displayed in the manufacturing process diagram of the communication system 1.
[0070] When an input operation is performed using an input device (not shown) to select one of the constituent devices ("log server" in FIG. 4) in the network configuration diagram shown in FIG. 4, the display unit 13 highlights only the parts and modules that make up the selected constituent device ("log server") in the process diagram shown in FIG. 4.
[0071] In Figure 4, the "Standard server" and "Production management software" shown in the manufacturing process are highlighted with a mesh pattern in the process diagram. In addition, the "CPU (Central Processing Unit)" and other components shown in the procurement process are also highlighted because they are parts or modules that make up the "Standard server."
[0072] In FIG. 4, component devices (e.g., "OA terminal" in the construction process) unrelated to the selected component device ("log server") are also displayed. However, the display unit 13 may display only the component devices related to the selected component device ("log server"). In this case, the display unit 13 does not need to highlight the component devices related to the selected component device ("log server"). This is because there is no need to distinguish the component devices related to the selected component device ("log server") from the component devices unrelated to the selected component device ("log server").
[0073] (Effects of this embodiment) According to the configuration of this embodiment, the acquisition unit 11 acquires identification information that identifies a specific component device of the communication system 1. The collection unit 12 uses the identification information to collect relationship information indicating components having a connection or relationship with the specific component device, and safety information related to the safety of the specific component device and its components in terms of information security. The collection unit 12 inputs the relationship information indicating the connection or relationship between the components of the communication system 1. The display unit 13 displays the safety information together with or in association with the relationship information.
[0074] Since the relationship information and the safety information are displayed together, rather than separately, the information can be viewed at a glance. The information can be viewed at a glance to grasp the connections or relationships between the component devices as well as the safety of those component devices, so that factors (threats) that manifest security risks in the communication system 1 can be accurately identified.
[0075] [Embodiment 3] A third embodiment will be described with reference to Fig. 5 to Fig. 9. In the third embodiment, a configuration will be described in which an attack path or an attack scenario of a cyber attack obtained by risk analysis or the like against the communication system 1 (Fig. 1) is set, and only relationship information and safety information related thereto are displayed.
[0076] In the third embodiment, the same components as those described in the first and second embodiments are denoted by the same reference numerals, and the description thereof will be omitted.
[0077] (Data processing device 30) The configuration of a data processing device 30 according to the third embodiment will be described with reference to Fig. 5. Fig. 5 is a block diagram showing the configuration of the data processing device 30.
[0078] 5, the data processing device 30 includes an acquisition unit 11, a collection unit 12, and a display unit 13. The data processing device 30 further includes a setting unit .
[0079] The setting unit 34 sets an attack path or an attack scenario of a cyber attack obtained by risk analysis on the communication system 1 (FIG. 1). The setting unit 34 is an example of a setting means.
[0080] For example, the setting unit 34 accepts an operation to input information indicating the attack path or the contents of an attack scenario of a cyber attack, which is a result of risk analysis on the communication system 1, to an input device (not shown). For example, the information indicating the attack path or the contents of an attack scenario of a cyber attack includes information specifying an entry point and a target of the attack path. Or, the information indicating the attack path or the contents of an attack scenario of a cyber attack includes information indicating an attack step (procedure) of the attack scenario.
[0081] The setting unit 34 outputs, to the acquisition unit 11, information indicating an attack path or an attack scenario of a cyber attack obtained by risk analysis of the communication system 1.
[0082] The acquisition unit 11 selects a specific component device from among the component devices related to the attack path or the attack scenario, and acquires the identification information of the selected component device. For example, the acquisition unit 11 displays a diagram showing the attack path or the attack scenario on the screen of a display device (not shown).
[0083] The acquisition unit 11 then accepts an operation to specify or select a specific component device from among the components (nodes 100, 200, switch 300, firewall 400) of the communication system 1 (FIG. 1) via an input device (not shown). At this time, the acquisition unit 11 only accepts an operation to specify or select a specific component device from among the components related to an attack path or attack scenario.
[0084] After a specific component device is selected or specified, the acquisition unit 11 outputs, to the collection unit 12, identification information for identifying the specific component device, in the same manner as in the first embodiment.
[0085] (Operation of data processing device 30) The operation of the data processing device 30 according to the third embodiment will be described with reference to Fig. 6. Fig. 6 is a flowchart showing the flow of processes executed by each unit of the data processing device 30.
[0086] 6, first, the setting unit 34 sets an attack path or an attack scenario of a cyber attack obtained by risk analysis of the communication system 1 (S301). The setting unit 34 outputs information indicating the attack path or the attack scenario of the cyber attack obtained by risk analysis of the communication system 1 to the acquisition unit 11.
[0087] The acquisition unit 11 receives information indicating an attack path or an attack scenario of a cyber attack obtained by risk analysis of the communication system 1 from the setting unit 34. The acquisition unit 11 selects a specific component device from among the component devices related to the attack path or the attack scenario based on the information indicating the attack path or the attack scenario of the cyber attack. Then, the acquisition unit 11 acquires identification information identifying the specific component device of the communication system 1 (S302). The acquisition unit 11 outputs the identification information identifying the specific component device to the collection unit 12.
[0088] The collection unit 12 receives, from the acquisition unit 11, identification information that identifies a specific component device.
[0089] The collection unit 12 acquires relationship information indicating components having a connection or relationship with a specific component device using the identification information. The collection unit 12 also collects safety information related to the safety of the specific component device and component device in terms of information security (S303).
[0090] The collection unit 12 outputs the relationship information and safety information regarding a specific component device of the communication system 1 to the display unit 13.
[0091] The display unit 13 receives relationship information and safety information about specific components of the communication system 1 from the collection unit 12 .
[0092] Thereafter, the display unit 13 displays the safety information together with or in association with the relationship information (S304).
[0093] For example, the display unit 13 generates third image data including the relationship information and the safety information by combining the first image data including the relationship information and the second image data including the safety information. Then, the display unit 13 displays the generated third image data on a screen of a display device (not shown).
[0094] The display unit 13 may store the relationship information and the safety information in a fifth database (not shown) in association with each other.
[0095] For example, the display unit 13 generates third image data including the relationship information and the safety information by combining the first image data including the relationship information and the second image data including the safety information. Then, the display unit 13 displays the generated third image data on a display device (not shown).
[0096] In addition, the display unit 13 may display information indicating the attack path or attack scenario set by the setting unit 34 together with or in association with the relationship information (FIGS. 7 to 9).
[0097] The display unit 13 may store the relationship information and the safety information in a fifth database (not shown) in association with each other.
[0098] This is the end of the operation of the data processing device 30 according to the third embodiment.
[0099] Hereinafter, some specific examples of the relationship information and safety information displayed by the display unit 13 according to the third embodiment will be described with reference to FIGS.
[0100] (Example 1 of Relationship Information and Safety Information) Here, an example in which safety information is displayed together with relationship information will be described. In this example, the relationship information and the safety information are simultaneously displayed in the same image. Alternatively, a first image displaying the relationship information and a second image displaying the safety information may be displayed in a switching manner.
[0101] A first example of the third image displayed by the display unit 13 of the data processing device 30 will be described with reference to Fig. 7. The display unit 13 displays only the relationship information and safety information associated with the attack path from among the relationship information received from the collection unit 12 and the safety information received from the collection unit 12. Here, the third image is a first image and a second image arranged side by side. The first image data includes the relationship information, and the second image data includes the safety information.
[0102] 7 is a diagram showing an example of the third image. As shown in FIG. 7, in one example, the third image includes a network configuration diagram corresponding to the first image on the left side, and a process diagram corresponding to the second image on the right side.
[0103] The network configuration diagram shows the network configuration of the communication system 1. Furthermore, an example of an attack path showing a route from an intrusion point to a target by a cyber attack obtained by risk analysis of the communication system 1 is superimposed on the network configuration diagram shown in FIG.
[0104] As described above, the setting unit 34 sets an attack path or an attack scenario of a cyber attack obtained by risk analysis of the communication system 1. In Fig. 7, the attack path of a cyber attack obtained by risk analysis of the communication system 1, which is set by the setting unit 34, is superimposed on the network configuration diagram.
[0105] The process diagram shows the supply chain from procurement of components of the communication system 1 to systemization (integration) of the communication system 1.
[0106] In the process diagram, "XXX" in "Inspection: XXX" indicates the content of the software analysis carried out for the inspection. For example, software analysis includes source code analysis, binary code analysis, OSS (Open Source Software) analysis, coding check, port scan, and installed software scan.
[0107] In Fig. 7, "log server" is selected on the network configuration diagram. In response to this, only the constituent devices of the communication system 1 related to the selected "log server" are displayed on the process diagram (embodiment 2). As shown in Fig. 7, the process diagram displays, as safety information, the names of the manufacturers of these constituent devices and the presence or absence of the inspection results of the information security inspection of these constituent devices.
[0108] (Example 2 of Relationship Information and Safety Information) Here, an example will be described in which safety information is displayed in association with relationship information. In this example, the relationship information and the safety information are simultaneously displayed within the same image. Within the image, the position or range in which the relationship information is displayed and the position or range in which the safety information is displayed are mutually related.
[0109] A second example of the third image displayed by the display unit 13 of the data processing device 30 will be described with reference to Fig. 8. The third image shown in Fig. 8 is a diagram in which the first image and the second image are arranged side by side on the left and right. The first image is a diagram showing an attack scenario, which is an example of relationship information, and the second image is a diagram showing safety information.
[0110] An attack scenario represents a cyber attack program obtained through risk analysis of the communication system 1, which is created based on settings such as the target of attack (entry point), purpose of attack (goal), means of attack, and resulting events (business damage).
[0111] In Fig. 8, the attack scenario is represented in the form of an attack tree that shows a series of steps in a cyber attack. Each step has an attack target, an attack purpose, and an attack method.
[0112] The safety information is information related to the safety in terms of information security of the constituent devices of the communication system 1. In Fig. 8, safety information is shown for the constituent devices that are the target or purpose of an attack.
[0113] In Fig. 8, "Intrusion into the log server" is selected on the attack tree. In response to this, only the constituent devices of the communication system 1 related to the selected attack procedure of "Intrusion into the log server" are displayed in the process diagram. Specifically, Fig. 8 illustrates "Log server," "Standard server," "Production management software," "BIOS," and "Library A" as the constituent devices of the communication system 1 related to the attack procedure of "Intrusion into the log server." In addition, as safety information, the names of the manufacturers of these constituent devices and whether or not they have been inspected for vulnerabilities are displayed.
[0114] (Example 3 of Relationship Information and Safety Information) Here, an example will be described in which safety information is displayed in association with relationship information. In this example, the relationship information and the safety information are simultaneously displayed within the same image. Within the image, the position or range in which the relationship information is displayed and the position or range in which the safety information is displayed are mutually related.
[0115] A third example of the third image displayed by the display unit 13 of the data processing device 30 will be described with reference to Fig. 9. The third image shown in Fig. 9 is a diagram in which the first image and the second image are arranged side by side on the left and right. The first image is a diagram showing an attack scenario, which is an example of relationship information, and the second image is a diagram showing safety information.
[0116] In Fig. 9, the attack scenario shows a series of steps (attack steps) of a cyber attack. Each step has an attack target, an attack purpose, and an attack method. In the diagram showing the attack scenario, the direction from left to right represents the progression of time. The steps shown on the left side are executed earlier, and the steps shown on the right side are executed later.
[0117] The safety information is information related to the safety in terms of information security of the constituent devices of the communication system 1. In Fig. 9, safety information about the constituent devices that are the target or purpose of an attack is shown.
[0118] 9, the attack step "A malicious third party illegally accesses the log server from an OA terminal" in the second row from the top is selected. The display unit 13 acquires attack step selection information from an input device (not shown) or the like, and in response thereto, displays only the constituent devices of the communication system 1 related to the selected attack step on the process diagram.
[0119] Specifically, in Fig. 9, the "Log Server," "Standard Server," "Production Management Software," "BIOS," and "Library A" are shown as components of the communication system 1 related to the attack step of "A malicious third party illegally accesses the log server from an OA terminal." In addition, as safety information, the names of the manufacturers of these components and whether or not they have been inspected for vulnerabilities are shown.
[0120] Furthermore, a "risk value" is shown on the right side of the attack scenario shown in Fig. 9. The risk value is an example of an index indicating the magnitude of a security risk. The "risk value" may be calculated by an evaluation unit (not shown) of the data processing device 30.
[0121] In Fig. 9, the "risk value" is displayed as D. There are no limitations on how the risk value is calculated, but in one example, it follows the security risk evaluation method according to the IPA (Information-technology Promotion Agency) method. According to the IPA method, the magnitude of security risk depends on the threat level (likelihood of an attack occurring), the vulnerability level (likelihood of accepting an occurring threat), and the importance of the asset (e.g., the economic value of the asset).
[0122] (Effects of this embodiment) According to the configuration of this embodiment, the acquisition unit 11 acquires identification information that identifies a specific component device of the communication system 1. The collection unit 12 uses the identification information to collect relationship information indicating components having a connection or relationship with the specific component device, and safety information related to the safety of the specific component device and its components in terms of information security. The collection unit 12 inputs the relationship information indicating the connection or relationship between the components of the communication system 1. The display unit 13 displays the safety information together with or in association with the relationship information.
[0123] Since the relationship information and the safety information are displayed together, rather than separately, the information can be viewed at a glance. The information can be viewed at a glance to grasp the connections or relationships between the component devices as well as the safety of those component devices, so that factors (threats) that manifest security risks in the communication system 1 can be accurately identified.
[0124] Furthermore, according to the configuration of this embodiment, the setting unit 34 sets an attack path or an attack scenario of a cyber-attack obtained by risk analysis on the communication system 1. The display unit 13 displays relationship information and safety information related to the attack path or the attack scenario. This makes it possible to predict factors (threats) that will manifest security risks of the communication system in the event of a cyber-attack on the communication system 1.
[0125] (Hardware configuration) Each of the components of the data processing devices 10, 20, and 30 described in the first to third embodiments is represented by a functional block. Some or all of these components are realized by an information processing device 900 as shown in Fig. 10. Fig. 10 is a block diagram showing an example of the hardware configuration of the information processing device 900.
[0126] As shown in FIG. 10, an information processing device 900 includes, for example, the following configuration.
[0127] ·CPU(Central Processing Unit)901 ROM (Read Only Memory) 902 ·RAM(Random Access Memory)903 Program 904 loaded into RAM 903 A storage device 905 for storing a program 904 A drive device 907 for reading and writing data from the recording medium 906 A communication interface 908 for connecting to a communication network 909 An input / output interface 910 for inputting and outputting data Bus 911 connecting each component Each of the components of the data processing devices 10, 20, and 30 described in the first to third embodiments is realized by the CPU 901 reading and executing a program 904 that realizes these functions. The program 904 that realizes the functions of each component is, for example, stored in advance in the storage device 905 or the ROM 902, and is loaded into the RAM 903 by the CPU 901 and executed as necessary. The program 904 may be supplied to the CPU 901 via the communication network 909, or may be stored in advance in the recording medium 906, and the drive device 907 may read out the program and supply it to the CPU 901.
[0128] According to the above configuration, the data processing devices 10, 20, and 30 described in the first to third embodiments are realized as hardware, and therefore it is possible to achieve the same effects as those described in any one of the first to third embodiments.
[0129] [Additional Notes] One embodiment of the present invention can be described as follows, but is not limited to the following.
[0130] (Appendix 1) An acquisition means for acquiring identification information for identifying a specific component device of the communication system; A collection means for collecting relationship information indicating components having a connection or relationship with the specific component device using the identification information, and safety information related to safety in terms of information security for the specific component device and the component parts; a display means for displaying the safety information together with or in association with the relationship information; An information providing device comprising:
[0131] (Appendix 2) The display means displays the safety information within a manufacturing process diagram of the communication system. 2. An information providing device according to claim 1.
[0132] (Appendix 3) The display means displays the manufacturing process diagram showing the safety information together with a network configuration diagram of the communication system. 3. An information providing device according to claim 2.
[0133] (Appendix 4) The acquiring means acquires the identification information for identifying the specific component device selected from among the component devices displayed on a network configuration diagram of the communication system. 4. An information providing device according to claim 3.
[0134] (Appendix 5) A setting unit is further provided for setting an attack path or an attack scenario of a cyber attack obtained by risk analysis of the communication system, The acquisition means selects or designates the specific component device from among the component devices related to the attack path or the attack scenario. 5. The information providing device according to claim 1,
[0135] (Appendix 6) The specific components include hardware and software, as well as the parts and modules that constitute them. 6. An information providing device according to any one of claims 1 to 5.
[0136] (Appendix 7) The safety information includes the results of an information security inspection of the specific component device. 7. The information providing device according to claim 1,
[0137] (Appendix 8) The safety information includes information identifying the product or manufacturer of the particular component. 7. The information providing device according to claim 1,
[0138] (Appendix 9) obtaining identification information that identifies a particular component of the communication system; Using the identification information, collect relationship information indicating components having a connection or relationship with the specific component device and safety information related to the safety of the specific component device and the component parts in terms of information security; Displaying the safety information together with or in association with the relationship information. Methods of providing information, including:
[0139] (Appendix 10) Setting an assumed attack path or attack scenario in the event of a cyber attack against the communication system, Displaying the relationship information and the safety information associated with the attack path or the attack scenario. 10. The information providing method according to claim 9,
[0140] (Appendix 11) Obtaining identification information that identifies a particular component of a communication system; Using the identification information, collect relationship information indicating components having a connection or relationship with the specific component device, and safety information related to safety in terms of information security for the specific component device and the component parts; displaying said safety information together with or in association with said relationship information; A non-transitory recording medium that stores a program for causing a computer to execute the above.
[0141] (Appendix 12) The program is Setting an assumed attack path or attack scenario in the event of a cyber attack against the communication system, Displaying the relationship information and the safety information associated with the attack path or the attack scenario. 12. The recording medium according to claim 11, which causes a computer to execute the steps.
[0142] Although the present invention has been described above with reference to the embodiments (and examples), the present invention is not limited to the above-mentioned embodiments (and examples). Various modifications that can be understood by a person skilled in the art can be made to the configurations and details of the above-mentioned embodiments (and examples) within the scope of the present invention. [Industrial Applicability]
[0143] The present invention can be used for security inspection of a communication system, for example, diagnosing vulnerabilities of information and communication devices constituting the communication system, and evaluating security risks of the communication system. [Explanation of symbols]
[0144] 1. Communication Systems 10 Data Processing Device 11 Acquisition Department 12 Collection Department 13 Display section 20 Data Processing Device 30 Data processing device 34 Setting section 100 nodes (control server) 200 nodes (client terminals) 300 Switch 400 Firewall
Claims
1. An acquisition means for acquiring identification information for identifying a specific component device of the communication system; A collection means for collecting relationship information indicating components having a connection or relationship with the specific component device using the identification information, and safety information related to safety in terms of information security for the specific component device and the component parts; a display means for displaying the safety information together with or in association with the relationship information; Equipped with The display means displays the safety information in a manufacturing process diagram of the communication system. Information provision device.
2. The display means displays the manufacturing process diagram showing the safety information together with a network configuration diagram of the communication system.
2. The information providing device according to claim 1 .
3. The acquiring means acquires the identification information for identifying the specific component device selected from among the component devices displayed on a network configuration diagram of the communication system.
3. The information providing device according to claim 2.
4. A setting unit is further provided for setting an attack path or an attack scenario of a cyber attack obtained by risk analysis of the communication system, The acquisition means selects or designates the specific component device from among the component devices related to the attack path or the attack scenario.
4. The information providing device according to claim 1, wherein the information providing device is a device for providing information to a user.
5. The specific components include hardware and software, as well as the parts and modules that constitute them.
5. The information providing device according to claim 1, wherein the information providing device is a device for providing information to a user.
6. The safety information includes the results of an information security inspection of the specific component device.
6. The information providing device according to claim 1,
7. The safety information includes information identifying the product or manufacturer of the particular component.
6. The information providing device according to claim 1,
8. A computer comprising: obtaining identification information that identifies a particular component of the communication system; Using the identification information, collect relationship information indicating components having a connection or relationship with the specific component device and safety information related to the safety of the specific component device and the component parts in terms of information security; Displaying the safety information together with or in association with the relationship information. Including, The computer displays the safety information within a manufacturing process diagram of the communication system. Information provision method.
9. The computer, Setting an assumed attack path or attack scenario in the event of a cyber attack against the communication system, Displaying the relationship information and the safety information associated with the attack path or the attack scenario.
9. The information providing method according to claim 8,
10. Obtaining identification information that identifies a particular component of a communication system; Using the identification information, collect relationship information indicating components having a connection or relationship with the specific component device, and safety information related to safety in terms of information security for the specific component device and the component parts; displaying said safety information together with or in association with said relationship information; A program for causing a computer to execute the above, causing the computer to display the safety information within a manufacturing process diagram of the communication system; program.
11. Setting an assumed attack path or attack scenario in the event of a cyber attack against the communication system, Displaying the relationship information and the safety information associated with the attack path or the attack scenario.
11. The program according to claim 10, which causes a computer to execute the steps of:
Citation Information
Patent Citations
Control method of main vapor pressure for first cut back
JP1982081616A
Method and apparatus for managing security in computer networks
JP2018521430A
Security Assessment System
JP2021515943A
Security force automation
US20060191007A1
Vulnerability information management device, vulnerability information management method, and program
WO2020050355A1