Information Processing Apparatus, Information Processing Method, and Program

The information processing apparatus addresses the inefficiencies in security risk assessments by analyzing network logs and calculating severity scores, enabling effective and cost-efficient vulnerability management.

JP7687521B2Active Publication Date: 2025-06-03NEC CORP
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
JP2024507454
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-03-18
Publication Date
2025-06-03
Estimated Expiration
2042-03-18

AI Technical Summary

Technical Problem

Existing security risk assessment methods require system modification to address identified vulnerabilities, leading to increased man-hours for coding and testing, and lack cost-effectiveness in addressing high-severity vulnerabilities.

Method used

An information processing apparatus and method that extracts protocol information from vulnerability descriptions, analyzes network logs to determine communication events, and calculates a severity score based on actual attack presence and exploit case information.

Benefits of technology

Enables comprehensive recognition of actual attacks and accurate evaluation of vulnerability severity, reducing man-hours for addressing vulnerabilities and improving cost-effectiveness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007687521000002
    Figure 0007687521000002
  • Figure 0007687521000003
    Figure 0007687521000003
  • Figure 0007687521000004
    Figure 0007687521000004
Patent Text Reader

Abstract

This information processing device comprises: an extraction unit that extracts a first protocol and a port number from vulnerability explanation information; a first determination unit that (a) extracts a second protocol and a destination port number from a log obtained by an observation device performing communication using the first protocol and the port number, (b) uses the second protocol and the destination port number to find, during a preset determination period, the number of communication events in each of a plurality of sampling periods set in advance, and generates frequency distribution information, (c) calculates curve information by executing a smoothing process on the frequency distribution information, (d) calculates a processing result by executing a definite integral process on the curve information, and (e) determines the presence or absence of an actual attack using the processing result and a threshold; and a severity evaluation unit that calculates severity on the basis of abuse case presence / absence information included in vulnerability information, and the result of determining the presence or absence of an actual attack.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The technical field relates to an information processing apparatus, an information processing method used for risk assessment in cyber security, and further to a program for realizing these. In the case of Related thereto.

Background Art

[0002] Cyber attacks by unauthorized access targeting countries, critical infrastructure, companies, organizations, etc. have become a social problem. In Japan, due to the revised Personal Information Protection Act in June 2020, regardless of the number of cases of personal information leakage due to cyber attacks, reporting to the victims and the Personal Information Protection Commission has been made mandatory.

[0003] That is, the victim organization must announce the leakage of customer information and the occurrence of system failures. However, when these are reported by the mass media, for example, in the case of a company, it incurs a great deal of cost for post-incident response such as a decline in stock price and an investigation of the affected range.

[0004] Therefore, in order to grasp such business risks in advance, a security risk assessment is carried out to identify the vulnerabilities inherent in the information system.

[0005] As a related technology, Patent Document 1 discloses an unauthorized access integrated response system. According to the unauthorized access integrated response system of Patent Document 1, first, for each site connected to a wide-area computer network, various log information of sensors and constituent devices related to multiple types of unauthorized access within the site is aggregated in a general-purpose log format. Next, the unauthorized access integrated response system correlates the logs between multiple types of sensors and constituent devices from the aggregated logs to integrally detect unauthorized access.

[0006] As a related technology, Patent Document 2 discloses a security management device. According to the security management device of Patent Document 2, in intrusion detection based on an anomaly detection method, when an anomaly related to some unauthorized access is detected, it specifies what kind of unauthorized access has been detected.

[0007] As a related technology, Patent Document 3 discloses an information processing device that efficiently controls a device according to the severity of a vulnerability in consideration of an actual operation environment. According to the information processing device of Patent Document 3, it calculates the severity based on the actual operation environment information and the vulnerability information, and controls the information processing device according to the severity.

[0008] As a related technology, Patent Document 4 discloses a business process system monitoring device that detects an attack on a business process system including a plurality of computers and analyzes the impact caused by the detected attack. According to the business process system monitoring device of Patent Document 4, it analyzes the impact of an attack on any one or more of the computers based on the importance of the information processing activities executed on each computer, the system configuration of each computer, and the detection result of an attack on each computer.

Prior Art Documents

Patent Documents

[0009]

Patent Document 1

Patent Document 2

Patent Document 3

Patent Document 4

Summary of the Invention

Problems to be Solved by the Invention

[0010] However, according to Patent Documents 1 to 4, in order to address the vulnerabilities identified by security risk assessment, system modification is required. Also, as the number of vulnerabilities to be eliminated increases, the man-hours required for coding and testing increase. Therefore, in order to effectively address vulnerabilities, it is necessary to accurately determine the severity of the vulnerabilities.

[0011] As an evaluation method for measuring the severity of vulnerabilities, a method using CVSS (Common Vulnerability Scoring System) which determines using attackability etc. is known. However, among the vulnerabilities determined to have a high severity, only a part is used in actual attacks, so sufficient cost-effectiveness cannot be obtained for addressing vulnerabilities.

[0012] For example, the presence or absence of an actual attack can be determined based on observation data. Also, for a vulnerability that can be remotely attacked, if there are a certain number of attack attempts on a specific communication port, it can be determined that there has been an actual attack.

[0013] However, in order to observe multiple actual attacks, a large number of observation devices are required. However, it is difficult to easily increase the number of observation devices. Therefore, for example, it is conceivable to open multiple communication ports using a single observation device. However, since attackers are wary that a device with multiple open communication ports is likely to be an observation device, there is a possibility of interrupting attack attempts.

[0014] As one objective, to comprehensively recognize the presence or absence of actual attacks and accurately evaluate the severity of vulnerabilities, an information processing apparatus, an information processing method, and Program are provided.

Means for Solving the Problem

[0015] To achieve the above objective, an information processing apparatus in one aspect An extraction unit that extracts first protocol information representing a first protocol used for communication and port number information representing a port number from vulnerability description information representing an explanation of a vulnerability included in vulnerability information stored in a memory device; (a) From the log obtained by the observation device connected to the network communicating using the first protocol and the port number, extract second protocol information representing a second protocol and destination port number information representing a destination port number, (b) Using the extracted second protocol and the destination port number, determine the number of communication events in each of a plurality of preset sampling periods arranged in time series within a preset determination period, and generate frequency distribution information, (c) Execute a smoothing process on the generated frequency distribution information to calculate curve information representing a curve, (d) Execute a definite integral process on the generated curve information to calculate a processing result, (e) A first determination unit that determines the presence or absence of a real attack using the calculated processing result and a preset threshold value; Obtain exploit case presence / absence information indicating whether there is an exploit case where the target vulnerability is exploited, included in the vulnerability information, and calculate a severity level based on the exploit case presence / absence information and the determination result of the presence or absence of a real attack; a severity evaluation unit; characterized by having.

[0016] Also, to achieve the above object, an information processing method in one aspect is that an information processing device An extraction process of extracting first protocol information representing a first protocol used for communication and port number information representing a port number from vulnerability description information representing an explanation of a vulnerability included in vulnerability information stored in a memory device; (a) An observation device connected to a network extracts second protocol information representing a second protocol and destination port number information representing a destination port number from a log obtained by communicating using the first protocol and the port number. (b) Using the extracted second protocol and the destination port number, the number of communication events is determined for each of a plurality of preset sampling periods arranged in time series within a preset determination period to generate frequency distribution information. (c) Smoothing processing is performed on the generated frequency distribution information to calculate curve information representing a curve. (d) Definite integral processing is performed on the generated curve information to calculate a processing result. (e) A first determination process for determining the presence or absence of a real attack using the calculated processing result and a preset threshold value, obtain abuse case presence / absence information indicating whether there is a case where a target vulnerability included in the vulnerability information has been exploited, and a severity evaluation process for calculating severity based on the abuse case presence / absence information and the determination result of the presence or absence of a real attack, is characterized by performing the following.

[0017] Furthermore, to achieve the above object, in one aspect, a program In the case of , causes a computer to an extraction process of extracting first protocol information representing a first protocol used for communication and port number information representing a port number from vulnerability description information representing an explanation of a vulnerability included in vulnerability information stored in a storage device, (a) An observation device connected to a network extracts second protocol information representing a second protocol and destination port number information representing a destination port number from a log obtained by communicating using the first protocol and the port number. (b) Using the extracted second protocol and the destination port number, the number of communication events is determined for each of a plurality of preset sampling periods arranged in time series within a preset determination period, and frequency distribution information is generated. (c) Smoothing processing is performed on the generated frequency distribution information to calculate curve information representing a curve. (d) Definite integral processing is performed on the generated curve information to calculate a processing result. (e) A first determination process for determining the presence or absence of a real attack using the calculated processing result and a preset threshold value, Obtain exploit case presence / absence information indicating whether there is a case where a target vulnerability included in the vulnerability information has been exploited, and calculate a severity based on the exploit case presence / absence information and the determination result of the presence or absence of a real attack. A severity evaluation process, Causing to execute There is Characterized by

Advantages of the Invention

[0018] As one aspect, it is possible to comprehensively recognize the presence or absence of a real attack and accurately evaluate the severity of a vulnerability.

Brief Description of the Drawings

[0019]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

[0020] Hereinafter, embodiments will be described with reference to the drawings. In the drawings described below, elements having the same function or corresponding functions are denoted by the same reference numerals, and repeated descriptions thereof may be omitted.

[0021] (Embodiment 1) The configuration of the information processing apparatus 10 according to Embodiment 1 will be described with reference to FIG. 1. FIG. 1 is a diagram for explaining an example of an information processing apparatus.

[0022] [Device Configuration] The information processing apparatus 10 shown in FIG. 1 is an apparatus that comprehensively recognizes the presence or absence of a real attack and accurately evaluates the severity of a vulnerability. As shown in FIG. 1, the information processing apparatus 10 includes an extraction unit 11, a first determination unit 12, and a severity evaluation unit 13.

[0023] The extraction unit 11 extracts first protocol information representing a first protocol used for communication and port number information representing a port number from vulnerability description information representing a description of a vulnerability included in the vulnerability information stored in the storage device.

[0024] The storage device is a database or the like provided outside the information processing apparatus 10. The storage device stores one or more pieces of vulnerability information.

[0025] Vulnerability information is information that has been generated in advance using, for example, information on publicly disclosed vulnerabilities (information on vulnerabilities collected from a vulnerability information database or the like), information on zero-day vulnerabilities (vulnerabilities before they are publicly disclosed or before a patch program is released), and the like.

[0026] A vulnerability information database is a platform that generalizes information on vulnerabilities in a database, such as databases like CVE (Common Vulnerabilities and Exposures), NVD (National Vulnerability Database), JVN (Japan Vulnerability Notes), JVN iPedia, and OSVDB (Open Source Vulnerability Database).

[0027] Vulnerability information has at least vulnerability identification information, vulnerability publication date and time information, information on the existence of exploitation cases, information on the feasibility of remote attacks, vulnerability description information, exploit code information, exploit code publication date and time information, and the like.

[0028] Vulnerability identification information is information that identifies each piece of vulnerability information. For example, in the case of vulnerability information generated based on information obtained from CVE (a vulnerability information database), the vulnerability identification information may use the CVE-ID. Vulnerability publication date and time information is information that represents the year, month, day, and time when the vulnerability information was published.

[0029] Information on the existence of exploitation cases is information that indicates whether there is an exploitation case for the target vulnerability. If there is an exploitation case for the target vulnerability, for example, set "1" in the information on the existence of exploitation cases K. If there is no exploitation case for the target vulnerability, for example, set "0" in the information on the existence of exploitation cases K.

[0030] The remote attack feasibility information indicates whether a remote attack can be executed by exploiting the vulnerability of the target. If a remote attack is possible, for example, set "1" in the remote attack feasibility information R. If a remote attack is not possible, for example, set "0" in the remote attack feasibility information R.

[0031] The vulnerability description information represents information about the description of the target vulnerability. For example, if it is vulnerability information generated based on information obtained from CVE (Common Vulnerabilities and Exposures), the vulnerability description information is the text information described in the Description of the site where CVE is published.

[0032] The exploit code information represents information about the publication destination of the exploit code. The information representing the publication destination of the exploit code is, for example, the URL (Uniform Resource Locator) of the site where the exploit code is published. The exploit code publication date and time information represents the year, month, day, and time when the exploit code was published.

[0033] The first protocol information and port number information are extracted, for example, by general text extraction processing using regular expressions for the first protocol and port number included in the vulnerability description information.

[0034] In addition, if the first protocol and port number cannot be obtained from the vulnerability description information, for example, the first protocol and port number may be extracted from the text information of the publication destination of the exploit code corresponding to the target vulnerability.

[0035] The first determination unit 12 first extracts, from the log obtained by the observation device connected to the network communicating using the first protocol and port number, second protocol information representing the second protocol and destination port number information representing the destination port number.

[0036] A log is information representing the history of communication conducted using a socket corresponding to a first protocol and a port number. The log records at least the date and time when the communication was conducted, the source IP address, a second protocol, and the destination port number.

[0037] The second protocol information and the destination port number information are extracted from the log using, for example, a general text extraction process using regular expressions.

[0038] Next, the first determination unit 12 uses the extracted second protocol and destination port number to obtain the number of communication occurrences (communication count) for each of a plurality of preset sampling periods arranged in time series within a preset determination period, and generates frequency distribution information.

[0039] The determination period is a period represented using a preset start time t1 (date and time) and a preset period T or end time t2 (date and time). The start time t1 is, for example, a time (date and time) after the time when the exploit code for vulnerability information was made public. The start time t1 is, for example, set by the user. The period T or end time t2 is, for example, determined based on the results of experiments, simulations, or set by the user. Note that the determination period can be set to, for example, 30 days.

[0040] The frequency distribution information is information representing the number of communication occurrences (communication count) for each of a plurality of sampling periods Ts (intervals) arranged in time series within the determination period. The sampling period Ts is determined based on, for example, the results of experiments, simulations, etc. Note that the sampling period Ts can be set to, for example, one day.

[0041] Figure 2 is a diagram for explaining an example of the frequency distribution and smoothing of the communication count. Figure 2 shows a frequency distribution graph using the communication count (black circles) for each sampling period Ts.

[0042] Next, the first determination unit 12 performs a smoothing process on the generated frequency distribution information to calculate curve information representing a curve. The smoothing process is, for example, a process such as spline interpolation. The curve 21 in FIG. 2 is, for example, a curve interpolated using a polynomial for each sampling period Ts.

[0043] Next, the first determination unit 12 performs a definite integral process on the generated curve information to calculate a processing result D. The definite integral process is a process of performing a definite integral on the curve during the determination period. The region 22 (hatched range) in FIG. 2 represents the processing result D of the definite integral process.

[0044] Next, the first determination unit 12 determines the presence or absence of an actual attack using the calculated processing result D and a preset threshold Th. The threshold Th is information for determining the presence or absence of an actual attack. The threshold Th is a value determined based on, for example, the results of experiments, simulations, etc.

[0045] If the processing result D is equal to or greater than the threshold Th, it is determined that there is an actual attack, and "1" is set in the determination result A of the actual attack. If the result D of the definite integral process is less than the threshold Th, it is determined that there is no actual attack, and "0" is set in the determination result A of the actual attack.

[0046] The severity evaluation unit 13 calculates a severity S based on the presence / absence information K of exploited cases indicating whether there is an exploited case where the target vulnerability is exploited and the determination result A of the presence / absence of an actual attack.

[0047] Specifically, first, the severity evaluation unit 13 acquires the presence / absence information K of exploited cases and the determination result A of the presence / absence of an actual attack. Next, the severity evaluation unit 13 refers to the severity determination information for determining the severity S using the presence / absence information K of exploited cases and the determination result A of the presence / absence of an actual attack, and obtains the severity S.

[0048] The severity determination information is information for determining the severity S based on the presence / absence of exploited cases and the presence / absence of an actual attack. FIG. 3 is a diagram for explaining the data structure of the severity determination information.

[0049] When using the severity determination information 31 in FIG. 3, if the malicious use case presence / absence information indicates no malicious use case (K = 0) and the actual attack determination result indicates no actual attack (A = 0), since there is neither a malicious use case nor an actual attack, the severity is set to "0" (S = 0). Also, if the malicious use case presence / absence information indicates no malicious use case (K = 0) and the actual attack determination result indicates an actual attack (A = 1), although there is no malicious use case but there is an actual attack, the severity is set to "1" (S = 1).

[0050] Also, if the malicious use case presence / absence information indicates a malicious use case (K = 1) and the actual attack determination result indicates no actual attack (A = 0), since the malicious use case has already been made public, the severity is set to "2" (S = 2). Further, if the malicious use case presence / absence information indicates a malicious use case (K = 1) and the actual attack determination result indicates an actual attack (A = 1), since the malicious use case has already been made public and an actual attack has also been observed, the severity is set to "3" (S = 3).

[0051] The severity is an indicator representing the degree of severity of the target vulnerability. In the example of FIG. 3, the severity is an indicator showing the security risk step by step. When representing the severity (S) with a four-level indicator, for example, the indicators of "3", "2", "1", "0" are set in descending order of severity. However, the severity (S) is not limited to four levels.

[0052] Each of the indicators, for example, represents that "3" means "urgent", "2" means "important", "1" means "warning", and "0" means "caution".

[0053] Urgent indicates, for example, a vulnerability where there is a possibility that an unauthorized program may be executed without the user's operation. Important indicates, for example, a vulnerability where there is a possibility that the confidentiality, integrity, and availability of the user's data may be violated. Warning indicates a vulnerability where the risk is mitigated due to reasons such as the difficulty of exploiting the vulnerability. Caution indicates, for example, a vulnerability where exploitation is very difficult and the impact is minimal.

[0054] Next, the severity evaluation unit 13 associates vulnerability identification information, presence / absence information K of exploitation cases, determination result A of actual attacks, severity S, and information indicating the date, time, and year when the severity S was evaluated, for the target vulnerability, and stores them in the storage device.

[0055] [System Configuration] Using FIG. 4, the configuration of the information processing apparatus 10 in Embodiment 1 will be described in more detail. FIG. 4 is a diagram for explaining an example of a system having the information processing apparatus of Embodiment 1.

[0056] As shown in FIG. 4, the system 100 in Embodiment 1 includes an information processing apparatus 10, a storage device 20, an observation device 30, and an output device 40. The observation device 30 is connected to the network 50.

[0057] The information processing apparatus 10 is, for example, a programmable device such as a CPU (Central Processing Unit), or an FPGA (Field-Programmable Gate Array), or a GPU (Graphics Processing Unit), or a circuit equipped with any one or more of them, a server computer, a personal computer, a mobile terminal, or the like.

[0058] The information processing apparatus 10 is an apparatus (information analysis apparatus) that analyzes information used for risk assessment in cyber security.

[0059] The storage device 20 is a database, a server computer, a circuit having a memory, or the like. The storage device 20 may use, for example, a vulnerability information database. In the example of FIG. 4, the storage device 20 is provided outside the information processing apparatus 10, but may also be provided inside the information processing apparatus 10.

[0060] The observation device 30 is a computer or the like on which software having a communication function is installed. The observation device 30 communicates using, for example, a first protocol and a port number, and stores at least the date and time when the communication was performed, the source IP address, the second protocol, and the destination port number as a log. Note that one or more observation devices 30 may be provided.

[0061] The output device 40 acquires the output information converted into an outputtable format by the output information generation unit 16, and outputs the generated image, voice, etc. based on the output information. The output device 40 is, for example, an image display device using a liquid crystal, an organic EL (Electro Luminescence), a CRT (Cathode Ray Tube). Further, the image display device may include a voice output device such as a speaker. Note that the output device 40 may be a printing device such as a printer.

[0062] The network 50 is a general network constructed using a communication line such as the Internet, a LAN (Local Area Network), a dedicated line, a telephone line, a corporate internal network, a mobile communication network, Bluetooth (registered trademark), WiFi (Wireless Fidelity).

[0063] The information processing apparatus will be described in detail. In the example of FIG. 4, the information processing apparatus 10 includes at least a vulnerability information acquisition unit 14, an extraction unit 11, a log acquisition unit 15, a first determination unit 12, a severity evaluation unit 13, and an output information generation unit 16. Note that the description of the extraction unit 11, the first determination unit 12, and the severity evaluation unit 13 has already been made, so those descriptions are omitted.

[0064] The vulnerability information acquisition unit 14 first acquires the target vulnerability information from the storage device 20. Next, the vulnerability information acquisition unit 14 outputs the acquired vulnerability information to the extraction unit 11.

[0065] The log acquisition unit 15 acquires logs from the observation device 30 that has communicated based on the first protocol and port number. Next, the log acquisition unit 15 outputs the acquired logs to the first determination unit 12.

[0066] The output information generation unit 16 generates output information for presenting to the user at least information regarding the target vulnerability and the severity S of the target vulnerability. Next, the output information generation unit 16 outputs the output information to the output device 40. Note that the output information generation unit 16 may generate output information for outputting graphs such as frequency distribution graphs and curves as shown in FIG. 2 to the output device 40.

[0067] [Device Operation] The operation of the information processing apparatus in Embodiment 1 will be described with reference to FIG. 5. FIG. 5 is a diagram for explaining an example of the operation of the information processing apparatus. In the following description, the drawings will be referred to as appropriate. Also, in Embodiment 1, an information processing method is implemented by operating the information processing apparatus. Therefore, the description of the information processing method in Embodiment 1 will be replaced with the following description of the operation of the information processing apparatus.

[0068] The vulnerability information acquisition unit 14 first acquires the target vulnerability information from the storage device 20 (step A1). Next, in step A1, with reference to the remote attack possibility information R and the existence / nonexistence information K of exploitation cases of the target vulnerability information, if the remote attack possibility information is not possible (R = 0), or if the remote attack possibility information is possible (R = 1) and the existence / nonexistence information of exploitation cases is present (K = 1), the processing after step A2 is not executed and the processing ends.

[0069] The reason is that vulnerabilities that cannot be attacked remotely cannot be observed at the network layer, so they are excluded. Also, even when it is possible to attack remotely, if there is information on the existence / nonexistence of exploitation cases, there is no need to investigate it deliberately, so this is also excluded.

[0070] In step A1, when the remote attack availability information is available (R = 1) and the exploitation case presence / absence information is not available (K = 0), the processing after step A2 is executed. Then, the vulnerability information acquisition unit 14 outputs the acquired vulnerability information to the extraction unit 11.

[0071] Next, the extraction unit 11 executes text extraction processing on the vulnerability description information included in the acquired target vulnerability information to extract the first protocol information and the port number information (step A2).

[0072] Next, the log acquisition unit 15 acquires a log from the observation device 30 that communicated based on the first protocol and the port number (step A3). Next, in step A3, the log acquisition unit 15 outputs the acquired log to the first determination unit 12.

[0073] Next, the first determination unit 12 acquires the log from the log acquisition unit 15. Next, the first determination unit 12 executes text extraction processing on the acquired log to extract the second protocol information and the destination port number information (step A4).

[0074] Next, the first determination unit 12 uses the extracted second protocol and the destination port number to obtain the number of communications (communication count) performed in each of a plurality of sampling periods arranged in time series during the determination period, and generates frequency distribution information (step A5).

[0075] Next, the first determination unit 12 executes smoothing processing on the generated frequency distribution information to calculate curve information (step A6). Next, the first determination unit 12 executes definite integral processing on the generated curve information to calculate a processing result D (step A7).

[0076] Next, the first determination unit 12 determines the presence or absence of an actual attack using the processing result D and a preset threshold Th (step A8). Then, in step A8, the first determination unit 12 outputs the determination result A of the presence or absence of an actual attack to the severity evaluation unit 13.

[0077] The severity evaluation unit 13 acquires the presence / absence information K of abuse cases and the determination result A of the presence / absence of actual attacks. Next, the severity evaluation unit 13 refers to the severity determination information 31 for determining the severity S by using the presence / absence information K of abuse cases and the determination result A of the presence / absence of actual attacks, and obtains the severity S (step A9).

[0078] Next, the severity evaluation unit 13 associates the vulnerability identification information, the presence / absence information K of abuse cases, the determination result A of actual attacks, the severity S, and the information indicating the date and time when the severity S was evaluated, and stores them in the storage device 20 or the like (step A10).

[0079] Next, the output information generation unit 16 generates output information for presenting to the user at least the information regarding the target vulnerability and the severity S of the target vulnerability (step A11). Next, in step A11, the output information generation unit 16 outputs the output information to the output device 40.

[0080] The processes of steps A1 to A11 described above are executed for each of the one or more vulnerability information stored in the storage device 20. Also, the processes of steps A1 to A11 are repeatedly executed at a preset fixed interval or irregularly.

[0081] [Effect of Embodiment 1] As described above, according to Embodiment 1, without increasing the number of observation devices 30, it is possible to comprehensively recognize the presence / absence of actual attacks and accurately evaluate the severity of vulnerabilities.

[0082] Also, since the severity of vulnerabilities can be accurately evaluated, even if the number of vulnerabilities to be addressed in the system increases in dealing with the vulnerabilities identified by the security risk assessment, the man-hours required for coding and testing can be suppressed.

[0083] Also, since the severity of vulnerabilities used in actual attacks can be accurately evaluated compared to the determination of severity using CVSS or the like, sufficient cost-effectiveness can be obtained for dealing with vulnerabilities.

[0084] [Program] The program in Embodiment 1 may be any program that causes a computer to execute Steps A1 to A11 shown in FIG. 5. By installing and executing this program on a computer, the information processing apparatus and the information processing method in Embodiment 1 can be realized. In this case, the processor of the computer functions as the vulnerability information acquisition unit 14, the extraction unit 11, the log acquisition unit 15, the first determination unit 12, the severity evaluation unit 13, and the output information generation unit 16, and performs processing.

[0085] Also, the program in Embodiment 1 may be executed by a computer system constructed by a plurality of computers. In this case, for example, each computer may function as any one of the vulnerability information acquisition unit 14, the extraction unit 11, the log acquisition unit 15, the first determination unit 12, the severity evaluation unit 13, and the output information generation unit 16.

[0086] (Modification Example 1) In the first determination unit 12 of Embodiment 1, the presence or absence of an actual attack was determined using the calculated processing result D of the definite integral processing and a preset threshold Th.

[0087] In the first determination unit 12 (second determination unit) of Modification Example 1, the difference in the determination period T is obtained using the model curve information representing the model curve created in advance and the calculated curve information, and the processing result D 1 is set.

[0088] FIG. 6 is a diagram for explaining an example of the difference between the model curve and the curve in the determination period. Specifically, as shown in FIG. 6, using the model curve 60 and the curve 21, the difference in the determination period T (the sum of the areas of the region 61 (hatched range) and the region 62 (hatched range) in FIG. 6) is obtained and used as the processing result D1.

[0089] The model curve 60 is determined using the results of experiments, simulations, etc. Alternatively, the model curve 60 may be generated using machine learning or the like.

[0090] Specifically, first, the first determination unit 12 (second determination unit) of Modification 1 calculates the result Da of the definite integral processing of the model curve 60 and the result Db of the definite integral processing of the curve 21 from time point t1 to time point t3 (intersection) during the determination period, and subtracts the result Da from the result Db to obtain a difference Dsa (Db - Da: the area of region 61 (hatched range) in FIG. 6).

[0091] Next, the first determination unit 12 (second determination unit) of Modification 1 calculates the result Dc of the definite integral processing of the model curve 60 and the result Dd of the definite integral processing of the curve 21 from time point t3 (intersection) to time point t2 during the determination period, and subtracts the result Dd from the result Dc to obtain a difference Dsb (Dc - Dd: the area of region 62 (hatched range) in FIG. 6).

[0092] Next, the first determination unit 12 (second determination unit) of Modification 1 obtains the sum of the difference Dsa and the difference Dsb to obtain a processing result D1 (= Dsa + Dsb).

[0093] When there are multiple t3 (intersections), when the model curve is the function f(t) and the curve 21 is the function g(t), D1 is the result of definite integration of the "absolute value" of f(t) - g(t) from t1 to t2.

[0094] Next, the first determination unit 12 (second determination unit) of Modification 1 determines the presence or absence of an actual attack using the calculated processing result D1 and a preset threshold Th1. The threshold Th1 is information for determining the presence or absence of an actual attack. The threshold Th1 is a value determined based on the results of, for example, experiments, simulations, etc.

[0095] When the processing result D1 is greater than or equal to the threshold Th1, it is determined that there is an actual attack, and "1" is set in the actual attack determination result A. When the processing result D1 is less than the threshold Th1, it is determined that there is no actual attack, and "0" is set in the actual attack determination result A.

[0096] As described above, according to Modification 1, it is possible to perform determination considering the epidemic characteristics in which the number of times the vulnerability is exploited changes over time.

[0097] (Modification Example 2) In the severity evaluation unit 13 of Embodiment 1, severity determination information 31 for determining the severity S is referred to using the presence / absence information K of abuse cases and the determination result A of the presence / absence of actual attacks, and the severity S is obtained.

[0098] In the severity evaluation unit 13 of Modification Example 2, first, the severity S is obtained using severity determination information 71 as shown in FIG. 7. FIG. 7 is a diagram for explaining the data structure of the severity determination information of Modification Example 2. The severity determination information 71 is information for determining the severity S based on the combination of the presence / absence information K of abuse cases and the determination result A of the presence / absence of actual attacks, and the presence / absence information L of damage cases.

[0099] The presence / absence information L of damage cases is information indicating the presence / absence of damage cases for the target vulnerability information, which is generated based on damage information such as news articles provided by the mass media and damage information such as security reports. The presence / absence information L of damage cases can be stored in, for example, the storage device 20 or the like.

[0100] When using the severity determination information 71 in FIG. 7, when the presence / absence information of damage cases is no damage case (L = 0), the presence / absence information of abuse cases is no abuse case (K = 0), and the determination result of the actual attack is no actual attack (A = 0), the severity is "0" (S = 0).

[0101] When the presence / absence information of damage cases is a damage case (L = 1), the presence / absence information of abuse cases is no abuse case (K = 0), and the determination result of the actual attack is no actual attack (A = 0), the severity is "1" (S = 1).

[0102] When the presence / absence information of damage cases is damage case None (L = 0), the presence / absence information of abuse cases is abuse case Yes (K = 1), and the determination result of the actual attack is actual attack None (A = 0), the severity is "2" (S = 2).

[0103] When the information on the existence of a damage case indicates that there is a damage case (L = 1), the information on the existence of an abuse case indicates that there is an abuse case (K = 1), and the determination result of an actual attack is an actual attack None (A = 0), the severity is "3" (S = 3).

[0104] The information on the existence of a damage case indicates a damage case None (L = 0), the information on the existence of an abuse case indicates an abuse case None (K = 0), and the determination result of an actual attack is an actual attack Yes (A = 1), the severity is "1" (S = 1).

[0105] The information on the existence of a damage case indicates that there is a damage case (L = 1), and the information on the existence of an abuse case indicates an abuse case None (K = 0), and when the determination result of an actual attack is no actual attack (A = 1), the severity is "2" (S = 2).

[0106] The information on the existence of a damage case indicates a damage case None (L = 0), the information on the existence of an abuse case indicates that there is an abuse case (K = 1), and the determination result of an actual attack is an actual attack Yes (A = 1), the severity is "3" (S = 3).

[0107] The information on the existence of a damage case indicates that there is a damage case (L = 1), the information on the existence of an abuse case indicates that there is an abuse case (K = 1), and the determination result of an actual attack is an actual attack Yes (A = 1), the severity is "3" (S = 3).

[0108] Next, the severity evaluation unit 13 of the second modification example associates the vulnerability identification information, the information K on the existence of an abuse case, the determination result A of an actual attack, the severity S, and the information indicating the year, month, day, and time when the severity S was evaluated, which are related to the target vulnerability, and stores them in the storage device 20.

[0109] According to the second modification example, without increasing the number of observation devices 30, it is possible to more comprehensively recognize the presence or absence of an actual attack and accurately evaluate the severity of the vulnerability compared to the first embodiment.

[0110] (Modification Example 3) In the severity evaluation unit 13 of Modification Example 2, the severity S is obtained using severity determination information 71 as shown in FIG. 7.

[0111] In the severity evaluation unit 13 of Modification Example 3, the severity S is obtained using the function shown in Equation 1. The function min(x, y) returns the smaller of x and y.

[0112] [Equation]

[0113] Rather than representing the presence / absence information of damage cases, the presence / absence information of abuse cases, and the determination result of the presence / absence of actual attacks as 1 or 0, they may be expressed as risk values including decimal points, and the severity S may be obtained. For example, the user sets the reliability of the information sources of damage, abuse, and actual attacks for each source and uses it as a risk value. Also, the ratio of the area where damage, abuse, or actual attacks occurred to the whole world may be used as a risk value.

[0114] According to Modification Example 3, the risk value can be set flexibly, and the severity value can be calculated without overly regarding minor events as serious.

[0115] [Physical Configuration] Here, a computer that realizes an information processing apparatus by executing the programs in Embodiment 1 and Modification Examples 1 to 3 will be described with reference to FIG. 8. FIG. 8 is a diagram showing an example of a computer that realizes the information processing apparatus in Embodiment 1 and Modification Examples 1 to 3.

[0116] As shown in FIG. 8, the computer 110 includes a CPU (Central Processing Unit) 111, a main memory 112, a storage device 113, an input interface 114, a display controller 115, a data reader / writer 116, and a communication interface 117. These components are connected to each other via a bus 121 so as to be capable of data communication. Note that the computer 110 may include a GPU or an FPGA in addition to or instead of the CPU 111.

[0117] The CPU 111 expands the programs (codes) in Embodiment 1 and Modifications 1 to 3 stored in the storage device 113 into the main memory 112 and executes them in a predetermined order, thereby performing various operations. The main memory 112 is typically a volatile storage device such as a DRAM (Dynamic Random Access Memory). Also, the programs in Embodiment 1 and Modifications 1 to 3 are provided in a state stored in a computer-readable recording medium 120. Note that the programs in Embodiment 1 and Modifications 1 to 3 may be distributed on the Internet connected via the communication interface 117. Note that the recording medium 120 is a non-volatile recording medium.

[0118] Specific examples of the storage device 113 include a hard disk drive and a semiconductor storage device such as a flash memory. The input interface 114 mediates data transmission between the CPU 111 and input devices 118 such as a keyboard and a mouse. The display controller 115 is connected to a display device 119 and controls the display on the display device 119.

[0119] The data reader / writer 116 mediates data transmission between the CPU 111 and the recording medium 120 and executes reading of a program from the recording medium 120 and writing of a processing result in the computer 110 to the recording medium 120. The communication interface 117 mediates data transmission between the CPU 111 and other computers.

[0120] Further, specific examples of the recording medium 120 include general-purpose semiconductor memory devices such as CF (Compact Flash (registered trademark)) and SD (Secure Digital), magnetic recording media such as Flexible Disk, or optical recording media such as CD-ROM (Compact Disk Read Only Memory).

[0121] Note that the information processing apparatus 10 in Embodiment 1 and Modifications 1 to 3 can also be realized by using hardware corresponding to each part, instead of a computer installed with a program. Further, part of the information processing apparatus 10 may be realized by a program and the remaining part may be realized by hardware.

[0122] As described above, the invention has been described with reference to the embodiments, but the invention is not limited to the above-described embodiments. Various changes that can be understood by those skilled in the art can be made to the configuration and details of the invention within the scope of the invention.

Industrial Applicability

[0123] According to the above description, it is possible to comprehensively recognize the presence or absence of actual attacks and accurately evaluate the severity of vulnerabilities. It is also useful in fields where attack analysis is required.

Description of Symbols

[0124] 10 Information processing apparatus 11 Extraction unit 12 First determination unit 13 Severity evaluation unit 14 Vulnerability information acquisition unit 15 Log acquisition unit 16 Output information generation unit 20 Storage device 30 Observation device 40 Output device 50 Network 110 Computer 111 CPU 112 Main Memory 113 Memory Device 114 Input Interface 115 Display Controller 116 Data Reader / Writer 117 Communication Interface 118 Input Device 119 Display Device 120 Recording Medium 121 Bus

Claims

1. extraction means for extracting first protocol information representing a first protocol used for communication and port number information representing a port number from vulnerability description information representing an explanation regarding a vulnerability included in vulnerability information stored in a storage device; (a) an observation device connected to a network extracts second protocol information representing a second protocol and destination port number information representing a destination port number from a log obtained by communicating using the first protocol and the port number, (b) using the extracted second protocol and the destination port number, the number of communication occurrences is determined for each of a plurality of preset sampling periods arranged in time series within a preset determination period to generate frequency distribution information, (c) smoothing processing is performed on the generated frequency distribution information to calculate curve information representing a curve, (d) definite integral processing is performed on the generated curve information to calculate a processing result, and (e) first determination means for determining the presence or absence of an actual attack using the calculated processing result and a preset threshold value; severity evaluation means for obtaining exploit case presence / absence information indicating whether there is an exploit case in which the target vulnerability has been exploited, included in the vulnerability information, and calculating a severity based on the exploit case presence / absence information and the determination result of the presence or absence of an actual attack; An information processing apparatus having the above.

2. The information processing apparatus according to claim 1, wherein the severity evaluation means further obtains damage case presence / absence information indicating whether there is a damage case for the target vulnerability information, and calculates a severity based on the damage case presence / absence information, the exploit case presence / absence information, and the determination result of the presence or absence of an actual attack. An information processing apparatus.

3. The information processing apparatus according to claim 1 or 2, Instead of the first determination means, (a) an observation device connected to the network extracts second protocol information representing a second protocol and destination port number information representing a destination port number from a log obtained by communicating using the first protocol and the port number, (b) using the extracted second protocol and the destination port number, the number of communication occurrences is obtained for each of a plurality of preset sampling periods arranged in time series within a preset determination period to generate frequency distribution information, (c) smoothing processing is performed on the generated frequency distribution information to calculate curve information representing a curve, (f) the difference between a model curve generated in advance and the curve within the determination period is calculated using model curve information representing the model curve and the curve information, and (g) a second determination means for determining the presence or absence of a real attack using the calculated difference and a preset threshold value; An information processing apparatus having the same. **Claim 4** The information processing apparatus according to claim 1, wherein when the extraction means cannot extract the first protocol information and the port number information from the vulnerability description information, the extraction means extracts the first protocol and the port number from text information of a disclosure destination of an exploit code corresponding to the target vulnerability. An information processing apparatus. **Claim 5** An information processing apparatus performs an extraction process of extracting first protocol information representing a first protocol used for communication and port number information representing a port number from vulnerability description information included in vulnerability information stored in a storage device, the vulnerability description information representing an explanation regarding the vulnerability; and a first determination process of (a) an observation device connected to the network extracts second protocol information representing a second protocol and destination port number information representing a destination port number from a log obtained by communicating using the first protocol and the port number, (b) using the extracted second protocol and the destination port number, the number of communication occurrences is obtained for each of a plurality of preset sampling periods arranged in time series within a preset determination period to generate frequency distribution information, (c) smoothing processing is performed on the generated frequency distribution information to calculate curve information representing a curve, (d) definite integral processing is performed on the generated curve information to calculate a processing result, and (e) determining the presence or absence of a real attack using the calculated processing result and a preset threshold value; Obtain information on whether there is an exploitation case indicating whether there is an exploitation case of the vulnerability of the target included in the vulnerability information, and a severity evaluation process for calculating the severity based on the information on whether there is an exploitation case and the determination result of the presence or absence of an actual attack. An information processing method for executing.

6. The information processing method according to claim 5, The severity evaluation process further obtains information on whether there is a damage case indicating whether there is a damage case for the vulnerability information of the target, and calculates the severity based on the information on whether there is a damage case, the information on whether there is an exploitation case, and the determination result of the presence or absence of an actual attack. An information processing method.

7. The information processing method according to claim 5 or 6, Instead of the first determination process, (a) an observation device connected to the network extracts second protocol information representing a second protocol and transmission destination port number information representing a transmission destination port number from a log obtained by communicating using the first protocol and the port number, (b) using the extracted second protocol and the transmission destination port number, the number of communication times is obtained for each of a plurality of preset sampling periods arranged in time series within a preset determination period to generate frequency distribution information, (c) smoothing processing is performed on the generated frequency distribution information to calculate curve information representing a curve, (f) the difference between a model curve generated in advance and the curve within the determination period is calculated using the model curve information representing the model curve and the curve information, (g) a second determination process for determining the presence or absence of an actual attack using the calculated difference and a preset threshold value An information processing method for executing.

8. In a computer, An extraction process for extracting first protocol information representing a first protocol used for communication and port number information representing a port number from vulnerability description information representing an explanation of a vulnerability included in vulnerability information stored in a storage device. (a) An observation device connected to a network extracts second protocol information representing a second protocol and destination port number information representing a destination port number from a log obtained by communicating using the first protocol and the port number. (b) Using the extracted second protocol and the destination port number, the number of communication events is determined for each of a plurality of preset sampling periods arranged in time series within a preset determination period to generate frequency distribution information. (c) Smoothing processing is performed on the generated frequency distribution information to calculate curve information representing a curve. (d) Definite integral processing is performed on the generated curve information to calculate a processing result. (e) A first determination process for determining the presence or absence of a real attack using the calculated processing result and a preset threshold value, obtaining exploit case presence / absence information indicating whether there is an exploit case in which the target vulnerability included in the vulnerability information is exploited, and calculating a severity based on the exploit case presence / absence information and the determination result of the presence or absence of a real attack; a severity evaluation process; A program for causing the execution.

9. The program according to claim 8, wherein the severity evaluation process further obtains damage case presence / absence information indicating whether there is a damage case for the target vulnerability information, and calculates the severity based on the damage case presence / absence information, the exploit case presence / absence information, and the determination result of the presence or absence of a real attack. Program.

10. The program according to claim 8 or 9, to the computer, Instead of the first determination process, (a) an observation device connected to a network extracts second protocol information representing a second protocol and destination port number information representing a destination port number from a log obtained by communicating using the first protocol and the port number, (b) using the extracted second protocol and the destination port number, the number of communication occurrences is obtained for each of a plurality of preset sampling periods arranged in time series within a preset determination period to generate frequency distribution information, (c) smoothing processing is executed on the generated frequency distribution information to calculate curve information representing a curve, (f) the difference between a model curve generated in advance and the curve within the determination period is calculated using model curve information representing the model curve and the curve information, and (g) a second determination process for determining the presence or absence of a real attack is performed using the calculated difference and a preset threshold value A program for causing the above to be executed.

Citation Information

Patent Citations

  • Network attack behavior prediction method and device, electronic equipment and storage medium

    CN113591077A

  • Unauthorized access integration correspondence system

    JP2005202664A

  • Device and method for managing security, and program

    JP2008167099A

  • Information processing apparatus and control method thereof

    JP2014174678A

  • Business processing system monitoring device and monitoring method

    JP2017211978A