Information processing system, information processing method and program

The information processing system improves software vulnerability identification by acquiring software information and employing identifier extraction and estimation techniques, enhancing accuracy in vulnerability detection and prediction.

JP7775524B1Active Publication Date: 2025-11-25BIZREACH INC
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
JP2025131946
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2025-08-07
Publication Date
2025-11-25
Estimated Expiration
2045-08-07

AI Technical Summary

Technical Problem

Existing technologies lack accuracy in identifying software vulnerabilities.

Method used

An information processing system that acquires software information, estimates identifiers based on reference information, and uses identifier extraction and estimation units to improve vulnerability identification accuracy.

Benefits of technology

Enhances the accuracy of identifying software vulnerabilities by utilizing a combination of identifier extraction and estimation methods, enabling precise determination and prediction of vulnerabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007775524000001_ABST
    Figure 0007775524000001_ABST
Patent Text Reader

Abstract

To provide an information processing system etc. that can improve the accuracy of identifying information regarding software vulnerabilities. [Solution] According to one aspect of the present invention, an information processing system is provided that includes at least one processor, and the processor is configured to execute the following steps by reading a program: in the information acquisition step, software information regarding software to be diagnosed for vulnerabilities is acquired; in the identifier estimation step, an identifier of the software is estimated based on the software information and first reference information, the identifier is information that can be associated with vulnerability information, and the first reference information is information regarding the correlation between the software information and the identifier.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an information processing system, an information processing method, and a program. [Background technology]

[0002] Patent Document 1 discloses a technique for identifying information related to software vulnerabilities. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2007-58514 Summary of the Invention [Problem to be solved by the invention]

[0004] There is a demand for technology that can improve the accuracy of identifying information about software vulnerabilities.

[0005] In view of the above circumstances, the present invention provides an information processing system and the like that can improve the accuracy of identifying information related to software vulnerabilities. [Means for solving the problem]

[0006] According to one aspect of the present invention, there is provided an information processing system comprising at least one processor, the processor being configured to execute each of the following steps by reading a program, wherein in the information acquisition step, software information relating to software to be diagnosed for vulnerability is acquired, and in the identifier estimation step, an identifier of the software is estimated based on the software information and first reference information, the identifier being information that can be associated with vulnerability information, and the first reference information being information relating to the correlation between the software information and the identifier.

[0007] According to this aspect, it is possible to improve the accuracy of identifying information related to software vulnerabilities. [Brief explanation of the drawings]

[0008] [Figure 1] 1 is a configuration diagram illustrating an information processing system 1. FIG. [Figure 2] 1 is a block diagram showing a hardware configuration of an information processing device 10. FIG. [Figure 3] FIG. 2 is a block diagram showing the hardware configuration of the user terminal 20. [Figure 4] 1 is a block diagram showing functions realized by an information processing device 10 (controller 11) and a user terminal 20 (controller 21). [Figure 5] 10 is a flowchart showing an example of the flow of a vulnerability diagnosis process executed by the control unit 11. FIG. [Figure 6] FIG. 10 is a flowchart showing an example of the flow of an identifier extraction process, which is a subroutine of the vulnerability diagnosis process. [Figure 7] FIG. 10 is a flowchart showing an example of the flow of an identifier estimation process, which is a subroutine of the vulnerability diagnosis process. [Figure 8] 1 is an activity diagram showing an example of the flow of information processing (software diagnostic processing) executed by the information processing system 1. FIG. DETAILED DESCRIPTION OF THE INVENTION

[0009] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS The present invention will be described below with reference to the accompanying drawings. Various features shown in the following embodiments can be combined with each other.

[0010] Incidentally, the program for realizing the software appearing in one embodiment may be provided as a non-transitory computer-readable medium, or may be provided so that it can be downloaded from an external server, or may be provided so that the program is started on an external computer and its functions are realized on a client terminal (so-called cloud computing).

[0011] Furthermore, various information processing according to an embodiment may realize input and output corresponding to the input. Here, the form of information referenced in such information processing (hereinafter referred to as reference information) is not limited as long as an output is obtained as a result of the input. The reference information may be, for example, rule-based information such as a database, a lookup table, or a predetermined function (including a decision formula such as a regression formula constructed using a statistical method), a trained model that has previously learned the correlation between input and output, or a generative AI such as a large-scale language model (these models include parameters that establish the correlation between input and output) or a visual language model that can output a desired result in response to a prompt.

[0012] In one embodiment, a "unit" may include, for example, a combination of hardware resources implemented by a circuit in the broad sense and software information processing that can be specifically realized by these hardware resources. In one embodiment, various information is handled, and this information is represented, for example, by physical values ​​of signal values ​​representing voltage and current, high and low signal values ​​as a binary bit set consisting of 0 or 1, or quantum superposition (so-called quantum bits), and communication and calculations can be performed on a circuit in the broad sense.

[0013] Furthermore, a circuit in the broad sense is a circuit realized by at least an appropriate combination of a circuit, circuitry, processor, memory, etc. The processor may be a general-purpose processor or a dedicated circuit. That is, it includes an application specific integrated circuit (ASIC), a programmable logic device (e.g., a simple programmable logic device (SPLD), a complex programmable logic device (CPLD), and a field programmable gate array (FPGA)), etc.

[0014] 1. Hardware Configuration This section explains the hardware configuration.

[0015] <Information Processing System 1> 1 is a configuration diagram showing an information processing system 1. The information processing system 1 includes a communication line 2, an information processing device 10, a plurality of user terminals 20, a plurality of managed servers 30, and a vulnerability information server 40. The information processing device 10, the user terminal 20, the managed servers 30, and the vulnerability information server 40 are configured to be able to communicate with each other via the communication line 2. The information processing device 10, the user terminal 20, the managed servers 30, and the vulnerability information server 40 may be connected via a wired or wireless connection. Furthermore, the information processing device 10, the user terminal 20, the managed servers 30, and the vulnerability information server 40 are each an example of an information processing device.

[0016] The information processing system 1 constitutes, for example, at least a part of a vulnerability management system that manages vulnerabilities of the managed server 30. The information processing system 1 mainly detects vulnerabilities of the managed server 30 used or managed by a user U. In one embodiment, the information processing system 1 is made up of one or more devices or components. These components will be described below.

[0017] <Information processing device 10> 2 is a block diagram showing the hardware configuration of the information processing device 10. The information processing device 10 is a vulnerability diagnosis device (server) that scans, identifies, manages, etc. vulnerability information of a system (e.g., software). The information processing device 10 may be provided by a provider of a vulnerability diagnosis service that scans, identifies, manages, etc. vulnerability information, and may be used by a user (user U) of the vulnerability diagnosis service. As shown in FIG. 2, the information processing device 10 includes a control unit 11, a storage unit 12, a communication unit 13, and a communication bus 14. The control unit 11, the storage unit 12, and the communication unit 13 are electrically connected within the information processing device 10 via the communication bus 14.

[0018] <Control unit 11> The control unit 11 processes and controls the overall operations related to the information processing device 10. The control unit 11 is, for example, a central processing unit (CPU). The control unit 11 realizes various functions related to the information processing device 10 by reading out predetermined programs stored in the storage unit 12. In other words, information processing by software stored in the storage unit 12 is specifically realized by the control unit 11, which is an example of hardware, and can be executed as each functional unit included in the control unit 11. These will be described in more detail in the next section. Note that the control unit 11 is not limited to being a single unit, and the information processing device 10 may have multiple control units 11 for each function. Furthermore, the information processing device 10 may be configured with a combination of these.

[0019] <Storage section 12> The memory unit 12 stores various pieces of information defined above. This can be implemented, for example, as a storage device such as a solid state drive (SSD) that stores various programs and the like related to the information processing device 10 executed by the control unit 11, or as a memory such as a random access memory (RAM) that stores temporarily required information (arguments, arrays, etc.) related to the program operations. The memory unit 12 stores various programs, variables, etc. related to the information processing device 10 executed by the control unit 11.

[0020] <Communications Department 13> The communication unit 13 is preferably a wired communication means such as USB, IEEE1394, Thunderbolt (registered trademark), wired LAN network communication, etc., but may also include wireless LAN network communication, mobile communication such as LTE / 5G, BLUETOOTH (registered trademark) communication, etc. as necessary. In other words, it is more preferable to implement it as a collection of multiple communication means. Furthermore, the information processing device 10 may communicate various information from the outside via the communication unit 13 and the network.

[0021] The information processing device 10 may be an on-premise type or a cloud type. The cloud type information processing device 10 may provide the above-described functions and processes in the form of, for example, SaaS (Software as a Service) or cloud computing.

[0022] <User terminal 20> Fig. 3 is a block diagram showing the hardware configuration of the user terminal 20. The user terminal 20 is an information processing terminal used by a user U (administrator) who manages the managed server 30, and is able to access the information processing device 10. As shown in Fig. 3, the user terminal 20 includes a control unit 21, a storage unit 22, a communication unit 23, an input unit 24, an output unit 25, and a communication bus 26. The control unit 21, the storage unit 22, the communication unit 23, the input unit 24, and the output unit 25 are electrically connected via the communication bus 26 inside the user terminal 20. The description of the control unit 21, the storage unit 22, and the communication unit 23 is omitted because they are the same as the description of each unit in the information processing device 10.

[0023] <Input section 24> The input unit 24 accepts operation inputs made by the user. The operation inputs are transferred as command signals to the control unit 21 via the communication bus 26. The control unit 21 can execute predetermined control or calculations based on the transferred command signals as necessary. The input unit 24 may be included in the housing of the user terminal 20 or may be attached externally. For example, the input unit 24 may be implemented as a touch panel integrated with the output unit 25. When the input unit 24 is implemented as a touch panel, the user can input tap operations, swipe operations, etc. to the input unit 24. Instead of a touch panel, a switch button, a mouse, a trackpad, a QWERTY keyboard, etc. can be used as the input unit 24.

[0024] <Output section 25> The output unit 25 displays a screen of a graphical user interface (GUI) that can be operated by the user. The output unit 25 may be included in the housing of the user terminal 20 or may be attached externally. Specifically, the output unit 25 may be implemented as a display device such as a CRT display, a liquid crystal display, an organic EL display, or a plasma display. It is preferable that these display devices are used appropriately depending on the type of user terminal 20.

[0025] <Managed Server 30> The managed server 30 is a server including a detection target system (a system including software for performing vulnerability diagnosis) for which the information processing device 10 detects vulnerability information, or a server whose entirety is the detection target system. The managed server 30 may be a physical server, or may be a virtual server built on a cloud platform provided by a cloud service provider. In other words, the detection target system may be a virtual server. The cloud platform may be, for example, a platform that allows access to services such as databases, storage, and applications via the Internet.

[0026] <Vulnerability Information Server 40> The vulnerability information server 40 is a server that manages software vulnerability information. The vulnerability information server 40 may be configured with multiple servers. Examples of the vulnerability information server 40 include management servers for vulnerability information websites (vulnerability information databases) such as CVE (Common Vulnerabilities and Exposures), NVD (National Vulnerability Database), ICAT (IPA Cybersecurity Alert Service) Metabase, JVN (Japan Vulnerability Notes), JVN iPedia, and OSVDB (Open Source Vulnerability Database). The vulnerability information server 40 may also include a server that stores vulnerability information (e.g., security advisories) provided independently by software suppliers. The software for which vulnerability information is managed may include OSS (Open Source Software).

[0027] 2. Functional configuration This section describes the functional configuration of this embodiment. Information processing by software stored in the storage unit 12 is specifically realized by the control unit 11, which is an example of hardware, and can be executed as each functional unit included in the control unit 11 (at least one processor included in the information processing system 1).

[0028] FIG. 4 is a block diagram showing functions realized by the information processing device 10 (controller 11) and the user terminal 20 (controller 21).

[0029] As shown in Figure 4A, the information processing device 10 (control unit 11) includes a basic display control unit 111, an information acquisition unit 112, an identifier extraction unit 113, an identifier estimation unit 114, a vulnerability determination unit 115, a vulnerability prediction unit 116, and an artificial intelligence unit 120.

[0030] As shown in FIG. 4B, the user terminal 20 (control unit 21) includes a display unit 211 and an operation acquisition unit 212.

[0031] <Basic display control unit 111> The basic display control unit 111 is configured to display various information on the user terminal 20. For example, the basic display control unit 111 displays vulnerability information determined by the vulnerability determination unit 115 on the display unit 211 of the user terminal 20.

[0032] <Information acquisition unit 112> The information acquisition unit 112 is configured to acquire software information relating to software that is the target of vulnerability diagnosis.

[0033] The software (hereinafter also referred to as “diagnosed software”) about which the information acquisition unit 112 acquires software information is software that is stored in the managed server 30 or runs on the managed server 30, for example.

[0034] "Software information" is information that is referenced to diagnose vulnerabilities in the software being diagnosed. "Software information" includes, for example, information on the components (software parts) that make up the software being diagnosed, the name of the software being diagnosed, version information of the software being diagnosed, and information on the supplier of the software being diagnosed.

[0035] The software information may include a software bill of materials (SBOM) for the software to be diagnosed. The SBOM is a list of components that make up the software to be diagnosed (software bill of materials). The components included in the SBOM may include OSS, third-party modules, and the like that are used within the software to be diagnosed. The software information may also include a list of components in a format such as Software Package Data Exchange (SPDX).

[0036] The SBOM includes individual information about each component and dependency information that indicates the dependency relationships between components. Individual component information includes, for example, the component name, supplier name, version, author, hash value, identifier, etc. The component name is the name of the component. The supplier name is the name of the provider of the component. The version is information that indicates the release history of the component. The author is the name of the author of the SBOM for the component. The hash value is information that uniquely identifies the component. The identifier is information that uniquely identifies the software (package) to be diagnosed. Details of identifiers will be provided later.

[0037] Dependency information includes information indicating other components on which a component is functionally or syntactically dependent. Dependency information may also include information indicating direct dependencies and information indicating indirect dependencies. The SBOM may include, for example, a tree structure indicating dependencies between multiple components.

[0038] The SBOM is written in, for example, a json format, an xml format, etc. The SBOM may also include a timestamp indicating the date and time when the SBOM was created.

[0039] The software to be diagnosed may be software managed by a package management tool (package manager). A "package management tool" is a tool that manages components (parts) used in software development as packages, and has functions such as distributing software packages, providing means for installing, uninstalling, and upgrading software, and managing dependencies between packages. The package management tool may be provided, for example, by a third party other than the vendor or user of the software to be managed.

[0040] The information acquisition unit 112 may acquire software information by referring to a document indicating the components of the software to be diagnosed or by scanning the software to be diagnosed, thereby enabling accurate and reliable acquisition of software information necessary for vulnerability diagnosis.

[0041] The "document indicating the component" is, for example, a document including an SBOM (in which an SBOM is written), a document including management information for a package management tool, or the like.

[0042] The "scan of the software to be diagnosed" is performed, for example, by extracting information that matches information registered in a prepared extraction format (information to be extracted as software information) from the files that make up the software to be diagnosed. Also, the information acquisition unit 112 may automatically identify components (software parts) included in the software to be diagnosed by, for example, executing a scan using a software analysis tool or the like on the software to be diagnosed that runs on the managed server 30, and create an SBOM for the software to be diagnosed.

[0043] For example, when a document (SBOM or the like) indicating the components of the software to be diagnosed cannot be acquired (does not exist) from the managed server 30, the information acquisition unit 112 may scan the software to be diagnosed.

[0044] <Identifier Extraction Unit 113> The identifier extraction unit 113 is configured to extract an identifier from the software information acquired by the information acquisition unit 112. The "identifier" is information that can be associated with vulnerability information, which will be described later. In other words, the identifier extracted by the identifier extraction unit 113 is identification information of the software to be diagnosed, which is registered in a vulnerability database managed by the vulnerability information server 40.

[0045] The identifiers may include a first identifier and a second identifier. The first identifier and the second identifier have different naming rules. The first identifier has a higher software identification accuracy (uniqueness) than the second identifier.

[0046] The "first identifier" is an identifier managed by a package management tool. The first identifier includes, for example, at least information indicating the name of the package and information indicating the version of the package.

[0047] The first identifier may be a package universal resource locator (purl / Package URL), which increases the accuracy of vulnerability detection for the software to be assessed.

[0048] A purl is an identifier that uniquely identifies software managed by a package management tool based on unified rules for package notation. A purl includes, for example, the software package ecosystem (type), package name, package version, and other auxiliary information. For example, a purl is written as "pkg:aaa / bbb / ccc@ddd." Here, "aaa" is the ecosystem, "bbb" is the namespace, "ccc" is the package name, and "ddd" is the version. In this way, purl identifies the package ecosystem (type) and package name, allowing software to be uniquely identified.

[0049] The "second identifier" is an identifier that is assigned to multiple software names that indicate the same software. The second identifier includes, for example, at least information indicating the software name and information indicating the package version. The second identifier is also an identifier that is not managed by a package management tool.

[0050] The second identifier may be a Common Platform Enumeration (CPE). This allows for increased accuracy in diagnosing vulnerabilities in software being assessed, even when the first identifier, purl, cannot be extracted or estimated from software information.

[0051] CPE is an identifier that uniquely identifies software based on standardized rules for notating software names, software versions, etc. CPE includes, for example, the software type (application, OS, etc.), supplier name, product name, version, and other auxiliary information. CPE is written, for example, as "cpe:2.3:a:ppp:qqq:rrr:...", where "ppp" is the supplier name, "qqq" is the product name, and "rrr" is the version. The supplier name, product name, etc. included in CPE may be written using different spellings. Therefore, purl can be said to be an identifier with higher software identification accuracy (uniqueness) than CPE.

[0052] The identifier extraction unit 113 extracts an identifier (first identifier or second identifier) ​​from the software information by using, for example, an identifier database (a dictionary in which identifier information is registered). The identifier database is recorded, for example, in the storage unit 12 of the information processing device 10, the vulnerability information server 40, etc., and is updated periodically.

[0053] The identifier extraction unit 113 typically extracts an identifier (first identifier or second identifier) ​​from the SBOM. Alternatively, the identifier extraction unit 113 may extract an identifier from a file other than the SBOM that the information acquisition unit 112 has acquired as software information.

[0054] The identifier extraction unit 113 may extract the first identifier from the software information with priority over the second identifier. In this way, when both the first identifier and the second identifier can be extracted, the vulnerability of the software to be diagnosed can be determined using the first identifier, which has a higher accuracy of identifying the software.

[0055] For example, the identifier extraction unit 113 may first refer to the identifier database to extract a first identifier from the software information, and if the first identifier cannot be extracted, may refer to the identifier database to extract a second identifier from the software information.

[0056] The identifier extraction unit 113 may extract both the first identifier and the second identifier and refer them to the vulnerability determination unit 115, which will be described later. If the identifier extraction unit 113 is unable to extract either the first identifier or the second identifier, it may generate a processing result (flag) indicating that fact.

[0057] <Identifier estimation unit 114> The identifier estimation unit 114 is configured to estimate an identifier of the software to be diagnosed based on the software information acquired by the information acquisition unit 112 and the first reference information.

[0058] The first reference information is information relating to the correlation between the software information and the identifier. The first reference information is stored, for example, in the storage unit 12. The first reference information may include, for example, a table, a function, a simple algorithm, or the like, which indicates the correlation between the software information and the identifier. The correlation included in the first reference information can be constructed, for example, by statistically analyzing data recording the software information and the corresponding identifier.

[0059] The first reference information may include a set of parameters for generating an identifier from the software information. For example, the first reference information may include an identifier estimation model that is a machine-learned learning model that uses the software information as input and is capable of outputting an identifier, or a generative AI. In this case, the identifier estimation unit 114 inputs the software information to the identifier estimation model and causes the identifier estimation model to output an identifier.

[0060] The identifier estimation model is included in the artificial intelligence unit 120. The identifier estimation model, which has been trained to be able to output an identifier, is trained using, for example, software information data and corresponding identifier data as training data. In such an identifier estimation model, parameters calculated, tuned, etc. by training establish a correlation between the software information and the identifier.

[0061] When the identifier estimation model is a generative AI including a general-purpose natural language model (e.g., a language model such as a large-scale language model), the identifier estimation unit 114 inputs software information and a prompt including an instruction to input the software information and output an identifier corresponding to the software information to the identifier estimation model, causing the identifier estimation model to output the identifier. The identifier estimation unit 114 may generate a prompt that instructs the identifier estimation model to infer an identifier and input the prompt to the identifier estimation model. Furthermore, the identifier estimation unit 114 may input a prompt that inserts, for example, one or more software information samples and one or more corresponding identifier samples as examples, samples, or training data of input and output pairs in addition to the software information and the instruction to estimate and output the identifier to the identifier estimation model. Here, the parameters for constructing the generative AI and the prompt including an instruction to output an identifier corresponding to the software information construct a correlation between the software information and the identifier.

[0062] More specifically, the first reference information may include an identifier estimation model, which is a generation AI, and first correspondence data in which correspondences between software information and identifiers are recorded. In this case, the identifier estimation unit 114 inputs a prompt to the identifier estimation model, which includes an instruction to estimate an identifier corresponding to the software information based on the first correspondence data, and causes the identifier estimation model to output the identifier. This makes it possible to continuously estimate identifiers of software to be diagnosed that is installed on the managed server 30, for example, by updating the first correspondence data.

[0063] The first correspondence data is a dictionary that describes correspondences between identifiers (first identifiers or second identifiers), such as software names, software versions, and software suppliers. The first correspondence data is recorded in, for example, the storage unit 12 of the information processing device 10, the vulnerability information server 40, etc., and is updated periodically.

[0064] The identifier extraction unit 113 may input a prompt to the identifier estimation model, the prompt including an instruction to estimate an identifier taking into consideration spelling variations in the name of the software, for example. Spelling variations include, for example, differences in character types (uppercase and lowercase, half-width and full-width characters, etc.), typos, synonyms, and the like.

[0065] The identifier extraction unit 113 may estimate the identifier by using external information (website) related to the software to be diagnosed that is published on a network. Examples of such external information include supplier information (information on the development company or provider company) of the software to be diagnosed, product information of the software to be diagnosed, vulnerability information of the software to be diagnosed, etc.

[0066] The identifier estimation unit 114 may estimate the first identifier as an identifier with priority over the second identifier. In this way, when both the first identifier and the second identifier can be estimated, it is possible to determine the vulnerability of the software to be diagnosed using the first identifier, which has a higher accuracy in identifying the software.

[0067] The identifier estimation unit 114 may, for example, input a prompt including an instruction to estimate the first identifier based on software information to the identifier estimation model, which is a generation AI, or input software information to the identifier estimation model trained to extract the first identifier, thereby causing the identifier estimation model to estimate the first identifier. Furthermore, if the first identifier cannot be extracted, the identifier estimation unit 114 may input a prompt including an instruction to estimate the second identifier based on software information to the identifier estimation model, which is a generation AI, or input software information to the identifier estimation model trained to extract the second identifier, thereby causing the identifier estimation model to estimate the second identifier. Furthermore, the identifier estimation unit 114 may, for example, input a prompt including a collective instruction to estimate the first identifier based on software information and, if the first identifier cannot be estimated, to the identifier estimation model, which is a generation AI, to estimate the second identifier based on the software information.

[0068] The identifier estimation unit 114 may estimate both the first identifier and the second identifier and refer to them in the vulnerability determination unit 115, which will be described later. If the identifier estimation unit 114 is unable to estimate either the first identifier or the second identifier, it may generate a processing result (flag) indicating that fact.

[0069] When the identifier extraction unit 113 is unable to extract an identifier from the software information, the identifier estimation unit 114 may estimate an identifier based on the software information and the first reference information. That is, the identifier estimation unit 114 may estimate an identifier only when the software information does not contain an identifier (when the identifier cannot be identified in the software information). This enables highly accurate vulnerability diagnosis using an identifier when an identifier can be extracted from the software information, and reduces the processing load on the information processing device 10 for estimating the identifier.

[0070] In addition, the identifier estimation unit 114 may also estimate an identifier when the identifier extraction unit 113 is able to extract an identifier from the software information, and may refer this identifier together with the identifier extracted by the identifier extraction unit 113 to the vulnerability determination unit 115 described below.

[0071] <Vulnerability determination unit 115> The vulnerability determination unit 115 is configured to identify vulnerability information of the software to be diagnosed based on the identifier extracted by the identifier extraction unit 113 or the identifier estimated by the identifier estimation unit 114. This makes it possible to accurately determine the vulnerability of the software to be diagnosed.

[0072] "Vulnerability information" includes, for example, information on vulnerabilities such as usage defects and bugs in software, programs, applications, components, etc. Vulnerability information may also include vulnerability identifiers that uniquely identify software vulnerabilities, information on software affected by vulnerabilities (e.g., identifiers, versions, etc.), whether attack code for software vulnerabilities is in circulation, score information indicating the level of software vulnerabilities, and security information such as misconfigurations and omissions in cloud services.

[0073] When the first identifier is extracted or estimated by the identifier extraction unit 113 or the identifier estimation unit 114, the vulnerability determination unit 115 identifies vulnerability information using the first identifier. Furthermore, when the second identifier is extracted or estimated by the identifier extraction unit 113 or the identifier estimation unit 114, the vulnerability determination unit 115 identifies vulnerability information using the second identifier. Furthermore, when both the first identifier and the second identifier are extracted or estimated by the identifier extraction unit 113 or the identifier estimation unit 114, the vulnerability determination unit 115 may identify vulnerability information using only the first identifier (i.e., by using the first identifier preferentially), or may identify vulnerability information based on both the first identifier and the second identifier.

[0074] The vulnerability determination unit 115 extracts vulnerability information of the target software (vulnerability information associated with the identifier serving as the search key) from the master information regarding vulnerabilities, for example, using as a search key the first identifier or the second identifier acquired by the identifier extraction unit 113 or the identifier estimation unit 114. For example, the vulnerability determination unit 115 identifies the vulnerability information by comparing the software name, software version, etc. included in the first identifier or the second identifier with information registered in the master information.

[0075] The master information is, for example, information acquired by the information processing device 10 from the vulnerability information server 40, and is stored in the vulnerability information database of the storage unit 12. The master information includes, for example, security vulnerabilities (defects) contained in hardware or software, the types of defects, countermeasures for the defects, severity (level of vulnerability), etc. Examples of the severity include a score value (e.g., base score) defined by the Common Vulnerability Scoring System (CVSS). The master information may also include the version of the CVSS.

[0076] Furthermore, the master information may include information indicating the vulnerability level set by a third-party organization, information indicating whether or not the vulnerability is accessible from the outside, information indicating the extent of the impact on business operations due to an attack on the vulnerability, information indicating whether or not attack code for the vulnerability is in circulation, information indicating whether or not exploitation of the vulnerability has been confirmed, etc. If attack code for the vulnerability is in circulation, the master information may include the attack code.

[0077] The master information may be information obtained by processing the information acquired from the vulnerability information server 40. Examples of processing the information acquired from the vulnerability information server 40 include extracting parts of the information, correcting the information, and adding new information. These processes may be performed by the user, or may be performed mechanically by text analysis by the control unit 11, processing using a learning model, or the like. The master information may be information acquired from a website such as a security-related news site or blog, or may be information entered by the user from the user terminal 20 and registered in the vulnerability information database.

[0078] The vulnerability determination unit 115 may determine the priority of the identified vulnerability information (i.e., triage the vulnerability) based on at least one of the following information contained in the master information: information indicating the vulnerability level set by a third-party organization; information indicating whether the vulnerability is accessible from outside; information indicating the extent of the impact on business operations of an attack against the vulnerability; information indicating whether attack code against the vulnerability is in circulation; and information indicating whether exploitation of the vulnerability has been confirmed.

[0079] For example, a score value defined by CVSS is used as information indicating the vulnerability level. For example, the vulnerability determination unit 115 determines vulnerability information whose score value is less than a predetermined threshold to be level 0, which is the lowest priority. Vulnerability information of level 0 is defined as information about a vulnerability for which no particular countermeasures need be taken. Vulnerability information whose score value is equal to or greater than the threshold is determined to be level 1 or higher.

[0080] For example, the vulnerability determination unit 115 determines that vulnerability information with a score value equal to or greater than a threshold value, which is inaccessible from outside the system targeted for attack code detection (i.e., accessible only from inside the system targeted for detection) and which has little impact on business operations when attacked, is level 1. Level 1 vulnerability information is defined as information on vulnerabilities for which countermeasures should be implemented during regular maintenance of the system targeted for detection (e.g., once a month). The priority of responding to level 1 vulnerability information is higher than the priority of responding to level 0 vulnerability information.

[0081] For example, the vulnerability determination unit 115 determines that vulnerability information with a score value equal to or greater than a threshold, which relates to a vulnerability that is accessible from the outside or a vulnerability that would have a significant impact on business operations if attacked, is level 2 (excluding vulnerability information that corresponds to levels 3 or 4, which will be described later). Level 2 vulnerability information is defined as information on a vulnerability for which countermeasures should be implemented within a first deadline (for example, within two weeks). The priority of responding to level 2 vulnerability information is higher than the priority of responding to level 1 vulnerability information.

[0082] For example, the vulnerability determination unit 115 determines that vulnerability information that satisfies the determination conditions for level 2, and that relates to vulnerabilities for which attack code is circulating, is level 3 (excluding vulnerability information that corresponds to level 4, which will be described later). Level 3 vulnerability information is defined as information on vulnerabilities for which countermeasures should be implemented within a second deadline (for example, within one day) that is shorter than the first deadline. The priority of responding to level 3 vulnerability information is higher than the priority of responding to level 2 vulnerability information.

[0083] For example, the vulnerability determination unit 115 determines that, among vulnerability information that satisfies the determination conditions for level 3, vulnerability information related to vulnerabilities for which attacks have been observed and exploitation of the vulnerability has been confirmed is the highest level, level 4. Level 4 vulnerability information is defined as information related to vulnerabilities for which countermeasures should be implemented within a third deadline (for example, immediately) that is shorter than the second deadline. The priority of responding to level 4 vulnerability information is higher than the priority of responding to level 3 vulnerability information.

[0084] Apart from the above level determination, the vulnerability determination unit 115 may set the highest priority to vulnerability information for which exploitation of the vulnerability has been confirmed and for which the vulnerability is accessible from the outside.

[0085] In addition, the vulnerability determination unit 115 may, for example, set a first rank as a priority for vulnerability information for which attack code against the vulnerability is circulating, and may set a second rank, which is higher than the first rank, as a priority for vulnerability information for which exploitation of the vulnerability has been confirmed and the vulnerability is accessible from outside.

[0086] Furthermore, the vulnerability determination unit 115 may set a third rank as a priority for vulnerability information for which attack code for the vulnerability is in circulation and the vulnerability is accessible from outside, and may set a fourth rank, which is lower than the third rank, as a priority for vulnerability information for which exploitation of the vulnerability has been confirmed and the vulnerability is not accessible from outside.

[0087] The vulnerability determination unit 115 may display the vulnerability determination result on the user terminal 20. The determination result includes, for example, the content of the identified vulnerability information, the type or priority (level) of the vulnerability information (for example, whether or not attack code is in circulation), and whether or not countermeasures are required (alert).

[0088] <Vulnerability Prediction Unit 116> The vulnerability prediction unit 116 is configured to predict vulnerabilities of the software to be diagnosed based on the software information and the second reference information acquired by the information acquisition unit 112 when the identifier estimation unit 114 is unable to estimate an identifier. This makes it possible to present information about vulnerabilities in the software to be diagnosed to the user even when neither the identifiers (first identifier and second identifier) ​​can be extracted nor estimated.

[0089] The "vulnerability" predicted by the vulnerability prediction unit 116 may be vulnerability information identified by the vulnerability determination unit 115, or may be information having content (format) different from that of the vulnerability information identified by the vulnerability determination unit 115. For example, the vulnerability prediction unit 116 may identify vulnerability information associated with an identifier based on information other than the identifier (for example, the name or version of the software), and output this to the user terminal 20 as a predicted vulnerability.

[0090] Furthermore, the vulnerability prediction unit 116 may generate unique information regarding vulnerabilities and output it to the user terminal 20. Examples of such unique information include information indicating the vulnerability level set by a third-party organization, information indicating whether or not a vulnerability is accessible from the outside, information indicating the extent of the impact that an attack against the vulnerability will have on business operations, information indicating whether or not attack code against the vulnerability is in circulation, and information indicating whether or not exploitation of the vulnerability has been confirmed.

[0091] The second reference information is information regarding the correlation between the software information and vulnerabilities of the software to be diagnosed. The second reference information is stored, for example, in the storage unit 12. The second reference information may include, for example, a table, a function, a simple algorithm, or the like, which indicates the correlation between the software information and the vulnerabilities of the software to be diagnosed. The correlation included in the second reference information can be constructed, for example, by statistically analyzing data that records the software information and information regarding the corresponding vulnerabilities.

[0092] The second reference information may include a set of parameters for generating vulnerability information from the software information. For example, the second reference information may include a vulnerability prediction model that is a learning model trained by machine learning to receive software information and output vulnerability information, or a generative AI. In this case, the vulnerability prediction unit 116 inputs the software information into the vulnerability prediction model and causes the vulnerability prediction model to output vulnerability information.

[0093] The vulnerability prediction model is included in the artificial intelligence unit 120. A vulnerability prediction model trained to be able to output information related to vulnerabilities is trained using, for example, software information data and corresponding vulnerability data as training data. In such a vulnerability prediction model, parameters calculated, tuned, etc. through training establish a correlation between the software information and the vulnerabilities of the software to be diagnosed.

[0094] When the vulnerability prediction model is a generative AI including a general-purpose natural language model (e.g., a language model such as a large-scale language model), the vulnerability prediction unit 116 inputs software information and a prompt including an instruction to input the software information and output information about vulnerabilities corresponding to the software information to the vulnerability prediction model, causing the vulnerability prediction model to output the information about vulnerabilities. The vulnerability prediction unit 116 may generate a prompt that instructs the vulnerability prediction model to predict vulnerabilities in the software to be diagnosed and input the prompt to the vulnerability prediction model. Furthermore, the vulnerability prediction unit 116 may input a prompt that includes, in addition to the software information and the instruction to predict and output vulnerabilities in the software to be diagnosed, examples, samples, or training data of input and output pairs, such as one or more software information samples and one or more corresponding vulnerability information samples to the vulnerability prediction model. Here, the parameters for constructing the generative AI and the prompt including an instruction to output information about vulnerabilities corresponding to the software information construct a correlation between the software information and the vulnerabilities of the software to be diagnosed.

[0095] More specifically, the second reference information may include a vulnerability prediction model, which is a generation AI, and second correspondence data in which correspondences between software information and information about vulnerabilities are recorded. In this case, the vulnerability prediction unit 116 inputs a prompt including an instruction to predict vulnerabilities in the software to be diagnosed based on the second correspondence data to the vulnerability prediction model, and causes the vulnerability prediction model to output information about vulnerabilities in the software to be diagnosed. This makes it possible to continuously predict vulnerabilities in software to be diagnosed that is installed on the managed server 30, for example, by updating the second correspondence data.

[0096] The second correspondence data is a dictionary that describes correspondence between information about vulnerabilities and software names, software versions, software suppliers, etc. The second correspondence data is recorded in, for example, the storage unit 12 of the information processing device 10, the vulnerability information server 40, etc., and is updated periodically.

[0097] The vulnerability prediction unit 116 may estimate the identifier by using external information (website) related to the software to be diagnosed that is publicly available on the network. Examples of such external information include supplier information (information on the developer or provider) of the software to be diagnosed, product information of the software to be diagnosed, etc.

[0098] <Processing flow> 5 is a flow diagram showing an example of the flow of vulnerability diagnosis processing executed by the control unit 11. In the vulnerability diagnosis processing, first, the control unit 11 acquires software information of software to be diagnosed (step S110). Next, the control unit 11 extracts an identifier from the software information (step S120).

[0099] 6 is a flow diagram showing an example of the flow of the identifier extraction process, which is a subroutine of the vulnerability diagnosis process. In the identifier extraction process, first, the control unit 11 extracts first identifier information from the software information (step S121). Next, the control unit 11 determines whether or not the extraction of the first identifier information was successful (step S122). If the extraction of the first identifier was successful (extraction was possible) (S122: YES), the control unit 11 stores the extracted first identifier in a predetermined storage area (step S123) and ends the subroutine.

[0100] On the other hand, if the extraction of the first identifier is not successful (extraction was not possible) (S122: NO), the control unit 11 extracts second identifier information from the software information (step S124). Subsequently, the control unit 11 determines whether the extraction of the second identifier information was successful (step S125). If the extraction of the second identifier is successful (extraction was possible) (S125: YES), the control unit 11 stores the extracted second identifier in a predetermined storage area (step S126) and ends the subroutine. On the other hand, if the extraction of the second identifier is not successful (extraction was not possible) (S125: NO), the control unit 11 stores an unextracted flag indicating that the identifier was not extracted in a predetermined storage area (step S127) and ends the subroutine.

[0101] 5, after the identifier extraction process (S120), the control unit 11 determines whether extraction of the identifier (first identifier or second identifier) ​​was successful by referring to a predetermined storage area (step S130). If extraction of the identifier was successful (extraction was possible) (S130: YES), the control unit 11 uses the identifier stored in the storage area to identify vulnerability information of the software to be diagnosed (step S140), and ends the vulnerability diagnosis process.

[0102] On the other hand, if extraction of the identifier has not been successful (extraction has not been possible) (S130: NO), the control unit 11 estimates the identifier based on the software information (step S150).

[0103] 7 is a flow diagram showing an example of the flow of the identifier estimation process, which is a subroutine of the vulnerability diagnosis process. In the identifier estimation process, first, the control unit 11 estimates first identifier information based on the software information (step S131). Next, the control unit 11 determines whether the estimation of the first identifier information was successful (step S132). If the estimation of the first identifier was successful (estimated) (S132: YES), the control unit 11 stores the estimated first identifier in a predetermined storage area (step S133) and ends the subroutine.

[0104] On the other hand, if the estimation of the first identifier is not successful (estimate is not possible) (S132: NO), the control unit 11 estimates second identifier information based on the software information (step S134). Subsequently, the control unit 11 determines whether the estimation of the second identifier information is successful (step S135). If the estimation of the second identifier is successful (estimate is possible) (S135: YES), the control unit 11 stores the estimated second identifier in a predetermined storage area (step S136) and ends the subroutine. On the other hand, if the estimation of the second identifier is not successful (estimate is not possible) (S135: NO), the control unit 11 stores an unestimated flag indicating that the identifier estimation was not possible in a predetermined storage area (step S137) and ends the subroutine.

[0105] 5, after the identifier estimation process (S150), the control unit 11 determines whether or not the estimation of the identifier (first identifier or second identifier) ​​was successful by referring to a predetermined storage area (step S160). If the estimation of the identifier was successful (S160: YES), the control unit 11 uses the identifier stored in the storage area to identify vulnerability information of the software to be diagnosed (step S140), and ends the vulnerability diagnosis process.

[0106] On the other hand, if the estimation of the identifier is not successful (the estimation is not possible) (S160: NO), the control unit 11 predicts the vulnerability of the software to be diagnosed based on the software information (step S170), and ends the vulnerability diagnosis process.

[0107] <Artificial Intelligence Department 120> The artificial intelligence unit 120 is configured to receive input from each functional unit and return the instructed output. The artificial intelligence used by each functional unit of the information processing device 10 may be a common one, or may be prepared individually for each functional unit.

[0108] The artificial intelligence unit 120 may be an AI (Artificial Intelligence) equipped with a learning model such as a language model, such as a Transformer (including GPT (Generative Pretrained Transformer, including GPT-1, GPT-2, GPT-3, and GPT-4)), a Recurrent Neural Network (RNN), or a Transformer (including BERT (Bidirectional Encoder Representations from Transformers) and a Bidirectional and Auto-regressive Transformer (BART)). The artificial intelligence unit 120 may be, for example, a generative AI or an AI agent including a large-scale language model. A large-scale language model is a type of generative AI and includes models provided by services such as OpenAI's GPT, Google's Gemini, and Microsoft's Azure AI Studio. The generative AI may be, for example, a text generation AI, an image generation AI, or a multimodal generation AI. The learning model may be referred to as an artificial intelligence model, a machine learning model, a trained model, or a deep learning model. Alternatively, the artificial intelligence unit 120 may include any learning model.

[0109] The language model is an example of a learning model based on a machine learning algorithm. Specific examples of machine learning algorithms include nearest neighbor methods, naive Bayes methods, decision trees, support vector machines, and deep learning using neural networks. The artificial intelligence unit 120 can apply the above algorithms as appropriate.

[0110] The artificial intelligence unit 120 may have a trained model constructed by a learning method such as supervised learning, unsupervised learning, or self-supervised learning. In supervised learning, machine learning is performed using training data (training data). The training data consists of pairs of input data for learning and output data (correct answer data). Furthermore, the language model may not only be trained for a specific task, but also be a general-purpose model that can be used for a wide range of tasks.

[0111] The artificial intelligence unit 120 may include a natural language model as its artificial intelligence, or may be a general-purpose natural language processing trained model such as a large-scale language model (LLM). An LLM is a learning model that has previously trained a large amount of data, such as text data (e.g., (i) web content on the Internet, or (ii) data stored in a specified database). It can perform various language processing tasks when given a task, and can perform a wide range of natural language processing tasks, such as understanding sentence patterns and contexts, answering questions, and generating sentences, according to given prompts. Such a general-purpose learning model includes a language model that can handle various tasks without fine-tuning, using one-shot learning or few-shot learning. A general-purpose learning model may also be configured to handle various tasks using zero-shot learning. The artificial intelligence used in each functional unit of the control unit 11 may be a separate learning model, or a common general-purpose learning model. The artificial intelligence unit 120 may also include a small-scale language model or a medium-scale language model, which are smaller in scale than a large-scale language model, as its learning model. Small-scale language models and medium-scale language models are natural language processing models trained based on less data than large-scale language models (constructed with fewer parameters than large-scale language models).

[0112] The learning models included in the artificial intelligence unit 120 (learning models used in each functional unit, such as an identifier estimation model) can undergo additional learning using techniques such as transfer learning and fine tuning. For example, each time new data is registered, the artificial intelligence unit 120 may perform additional learning and fine tuning using the new data as new training data. This improves the accuracy of the information output from the learning models.

[0113] The learning model included in the artificial intelligence unit 120 may be a learning model (distilled model) obtained by knowledge distillation using an original learning model. In knowledge distillation, a trained model such as a large-scale language model is used as a teacher model, and the parameters of the student model are adjusted to reduce the output loss (Soft Target Loss) of the student model (distilled model) relative to the output (Soft Target) of the teacher model, thereby learning the student model, which becomes the distilled model. Alternatively, the student model may be learned to reduce the output loss (Hard Target Loss) of the student model relative to the correct label (Hard Target) of the teacher data (combination of input data and output data of the learning model). Compared to the original learning model (teacher model), the distilled model has a smaller number of parameters and a smaller processing load while maintaining performance similar to the learning model. Therefore, using a distilled model can reduce the cost of the information processing system 1.

[0114] For example, the learning model used in each functional unit may be a distilled model trained using a combination of input data and output data in a large-scale language model as training data. Furthermore, when the information processing system 1 is introduced, a large-scale language model may be used as the learning model used in each functional unit, and when training data from the large-scale language model is accumulated, a distilled model obtained by knowledge distillation using the training data may be used as the learning model used in each functional unit.

[0115] An AI agent (which may also be called an autonomous agent) is a model that, when given a goal (purpose, objective, etc.) such as "teach me XX" or a task such as "output XX," breaks down the processing required to reach the goal or accomplish the task into subtasks, actions, etc., and performs the necessary data collection and analysis, program generation, and execution. The AI ​​agent targets information and instructions input by a user, autonomously selects and executes tasks and actions according to the goal, and outputs information according to the goal, without requiring user intervention (operational input). The AI ​​agent may also autonomously learn to achieve its goal by autonomously creating and executing plans and evaluating the execution results. For example, the AI ​​agent may be autonomously updated based on the results of subtask execution (e.g., collected information, information analysis results, etc.).

[0116] <Display section> The display unit 211 of the user terminal 20 shown in FIG. 4B displays a screen (information) indicated by the data transmitted from the information processing device 10.

[0117] <Operation acquisition part> The operation acquisition unit 212 of the user terminal 20 accepts operations by the user who uses the user terminal 20 .

[0118] 3. Information Processing Method This section describes an information processing method of the information processing device 10. This information processing method is executed by a computer, with each unit of the information processing device 10 acting as each step.

[0119] The above-mentioned information processing method includes an information acquisition step, an identifier extraction step, an identifier estimation step, a vulnerability determination step, and a vulnerability prediction step. In the information acquisition step, software information related to software to be diagnosed for vulnerability is acquired. In the identifier extraction step, an identifier is extracted from the software information. In the identifier estimation step, if an identifier cannot be extracted in the identifier extraction step, an identifier of the software is estimated based on the software information and first reference information. In the vulnerability determination step, vulnerability information of the software is identified based on the identifier. In the vulnerability prediction step, if an identifier cannot be estimated in the identifier estimation step, vulnerability of the software is predicted based on the software information and second reference information.

[0120] 8 is an activity diagram showing an example of the flow of information processing (software diagnostic processing) executed by the information processing system 1. Below, the information processing will be described along with each activity in this activity diagram.

[0121] The software diagnosis process starts with the user specifying the software to be diagnosed (detection target system). The user inputs or selects the software to be diagnosed on the user terminal 20 (activity A101). The information processing device 10 accepts the software to be diagnosed that has been input or selected on the user terminal 20 (activity A102).

[0122] Next, the information processing device 10 executes a vulnerability diagnosis process for the designated software to be diagnosed (activity A103). Specifically, the information processing device 10 acquires software information about the software to be diagnosed, extracts or estimates an identifier, identifies vulnerability information using the identifier, or predicts vulnerabilities based on the software information. After executing the vulnerability diagnosis process, the information processing device 10 outputs the vulnerability diagnosis result to the user terminal 20 (activity A104). As a result, the vulnerability diagnosis result is displayed on the user terminal 20 (activity A105).

[0123] 4. Effect The operation of this embodiment can be summarized as follows: By estimating the identifier, it is possible to improve the accuracy of identifying information related to vulnerabilities in software to be diagnosed.

[0124] Although the embodiment of the present invention has been described above, the present invention is not limited to this and can be modified as appropriate within the scope of the technical idea of ​​the invention.

[0125] 5.Other In the above embodiment, the information processing device 10 performs various storage and control functions. However, multiple external devices may be used instead of the information processing device 10. That is, various pieces of information and programs may be distributed and stored in multiple external devices using blockchain technology or the like. In particular, the artificial intelligence unit 120 may be an external component of the information processing device 10. In this case, the external artificial intelligence unit 120 may be provided by, for example, an artificial intelligence service server and configured to receive inputs from each functional unit of the information processing device 10, receive requests to execute artificial intelligence services, and return the instructed output as a processing result to the information processing device 10. The artificial intelligence service server may be a server that provides services using a language model as a learning model, or a server that executes language processing tasks using a language model. The artificial intelligence service server may be constructed using LLM. The artificial intelligence service server receives inputs of prompts such as text, images, and voice, and generates and responds to the prompts.

[0126] At least one of the devices included in the information processing system 1 may be installed outside the country in which the functions of the information processing system 1 are performed.

[0127] The aspect of this embodiment is not limited to the information processing system 1, and may be an information processing method or a program. The information processing method includes steps executed by the information processing system 1. The program causes a computer to execute the steps of the information processing system 1.

[0128] The control unit 11 does not necessarily have to include the identifier extraction unit 113. For example, the information processing system 1 may not extract an identifier but may only estimate the identifier. Furthermore, the control unit 11 does not necessarily have to include the vulnerability determination unit 115. For example, the information processing system 1 may only extract or estimate an identifier, and a device or system external to the information processing system 1 may perform vulnerability determination using the identifier. Furthermore, the control unit 11 does not necessarily have to include the vulnerability prediction unit 116. For example, the information processing system 1 may perform vulnerability diagnosis only when an identifier is extracted or estimated.

[0129] It may be provided in the following manner.

[0130] (1) An information processing system comprising at least one processor, the processor being configured to execute each of the following steps by reading a program: in an information acquisition step, software information relating to software to be diagnosed for vulnerability is acquired; and in an identifier estimation step, an identifier of the software is estimated based on the software information and first reference information, wherein the identifier is information that can be associated with vulnerability information, and the first reference information is information relating to the correlation between the software information and the identifier.

[0131] (2) In the information processing system described in (1) above, the processor is configured to further perform the following steps, and in the vulnerability determination step, the vulnerability information of the software is identified based on the identifier.

[0132] (3) In the information processing system described in (1) or (2) above, the first reference information includes an identifier estimation model, which is a generation AI, and first correspondence data in which a correspondence between the software information and the identifier is recorded, and in the identifier estimation step, a prompt including an instruction to estimate the identifier corresponding to the software information based on the first correspondence data is input to the identifier estimation model, and the identifier is output to the identifier estimation model.

[0133] (4) In the information processing system described in any one of (1) to (3) above, in the identifier estimation step, a first identifier is estimated as the identifier in preference to a second identifier, wherein the first identifier and the second identifier have different naming rules, and the first identifier is an identifier managed by a package management tool.

[0134] (5) In the information processing system described in (4) above, the second identifier is an identifier given to the names of multiple pieces of software that indicate the same software.

[0135] (6) In the information processing system described in (5) above, the first identifier is purl, and the second identifier is CPE.

[0136] (7) In the information processing system described in any one of (1) to (6) above, the processor is configured to further perform the following steps: in the identifier extraction step, extracting the identifier from the software information; and in the identifier estimation step, if the identifier cannot be extracted in the identifier extraction step, estimating the identifier based on the software information and the first reference information.

[0137] (8) In the information processing system described in (7) above, in the identifier extraction step, a first identifier is extracted as the identifier in preference to a second identifier, wherein the first identifier and the second identifier have different naming rules, and the first identifier is an identifier managed by a package management tool.

[0138] (9) In the information processing system described in any one of (1) to (8) above, the processor is configured to further perform the following steps: in a vulnerability prediction step, if the identifier cannot be estimated in the identifier estimation step, predict the vulnerability of the software based on the software information and second reference information, wherein the second reference information is information regarding the correlation between the software information and the vulnerability of the software.

[0139] (10) In the information processing system described in (9) above, the second reference information includes a vulnerability prediction model which is a generating AI and second correspondence data in which a correspondence between the software information and information relating to vulnerabilities is recorded, and in the vulnerability prediction step, a prompt including an instruction to predict the vulnerability of the software based on the second correspondence data is input to the vulnerability prediction model, and information relating to the vulnerability of the software is output to the vulnerability prediction model.

[0140] (11) In the information processing system described in any one of (1) to (10) above, in the information acquisition step, the software information is acquired by referring to a document indicating the software components or by scanning the software.

[0141] (12) The information processing system according to any one of (1) to (11) above, further comprising: a server having the processor; and a terminal that can access the server.

[0142] (13) An information processing method, in which an information processing device executes each step of the information processing system described in any one of (1) to (12) above.

[0143] (14) A program for causing a computer to execute each step of the information processing system described in any one of (1) to (12) above. Of course, this is not the case.

[0144] Finally, while various embodiments of the present disclosure have been described, they are presented as examples and are not intended to limit the scope of the invention. The novel embodiments may be embodied in various other forms, and various omissions, substitutions, and modifications may be made without departing from the spirit of the invention. Such embodiments and modifications are intended to be included within the scope and spirit of the invention, as well as within the scope of the inventions and their equivalents as defined in the claims. [Explanation of symbols]

[0145] 1: Information processing system 2: Communication line 10: Information processing device 11: Control section 111: Basic display control section 112: Information acquisition department 113: Identifier extraction unit 114: Identifier estimation unit 115: Vulnerability determination section 116: Vulnerability prediction section 120: Artificial Intelligence Department 12: Storage section 13: Communications Department 14: Communication bus 20: User terminal 21: Control unit 211:Display section 212: Operation acquisition section 22: Storage section 23: Communications Department 24: Input section 25: Output section 26: Communication bus 30: Managed server 40: Vulnerability Information Server

Claims

1. An information processing system, at least one processor; The processor is configured to execute the following steps by reading the program: In the information acquisition step, software information about the software to be diagnosed for vulnerabilities is acquired, In the identifier estimation step, an identifier of the software is estimated based on the software information and first reference information, wherein the identifier is information that can be associated with vulnerability information, and the first reference information is information regarding a correlation between the software information and the identifier; In a vulnerability prediction step, if the identifier cannot be estimated in the identifier estimation step, the vulnerability of the software is predicted based on the software information and second reference information, wherein the second reference information is information regarding the correlation between the software information and the vulnerability of the software.

2. 2. The information processing system according to claim 1, The processor is further configured to perform the steps of: In the vulnerability determination step, the vulnerability information of the software is identified based on the identifier.

3. 2. The information processing system according to claim 1, the first reference information includes an identifier estimation model, which is a generation AI, and first correspondence data in which a correspondence between the software information and the identifier is recorded; In the identifier estimation step, a prompt including an instruction to estimate the identifier corresponding to the software information based on the first correspondence data is input to the identifier estimation model, and the identifier is output to the identifier estimation model.

4. An information processing system, at least one processor; The processor is configured to execute the following steps by reading the program: In the information acquisition step, software information about the software to be diagnosed for vulnerabilities is acquired, In the identifier estimation step, an identifier of the software is estimated based on the software information and first reference information, wherein the identifier is information that can be associated with vulnerability information, and the first reference information is information regarding a correlation between the software information and the identifier; In the identifier estimation step, a first identifier is estimated as the identifier in preference to a second identifier, wherein the first identifier and the second identifier have different naming rules, the first identifier is purl, and the second identifier is an identifier given to the names of multiple software programs that indicate the same software.

5. 5. The information processing system according to claim 4, The second identifier is a CPE.

6. An information processing system, at least one processor; The processor is configured to execute the following steps by reading the program: In the information acquisition step, software information about the software to be diagnosed for vulnerabilities is acquired, In the identifier extraction step, an identifier of the software is extracted from the software information, and the identifier is information that can be associated with vulnerability information; in the identifier estimation step, when the identifier cannot be extracted in the identifier extraction step, estimating the identifier based on the software information and first reference information, wherein the first reference information is information relating to a correlation between the software information and the identifier; In the identifier extraction step, a first identifier is extracted as the identifier in preference to a second identifier, wherein the first identifier and the second identifier have different naming rules, the first identifier is purl, and the second identifier is an identifier given to the names of multiple software programs that indicate the same software.

7. 2. The information processing system according to claim 1, the second reference information includes a vulnerability prediction model, which is a generating AI, and second correspondence data in which a correspondence between the software information and information on vulnerabilities is recorded; In the vulnerability prediction step, a prompt including an instruction to predict the vulnerability of the software based on the second correspondence data is input to the vulnerability prediction model, and information regarding the vulnerability of the software is output to the vulnerability prediction model.

8. 2. The information processing system according to claim 1, In the information acquisition step, the software information is acquired by referring to a document indicating the software components or by scanning the software.

9. 2. The information processing system according to claim 1, a server having the processor; a terminal that can access the server; An information processing system comprising:

10. An information processing method, comprising: An information processing method, wherein an information processing device executes each step of the information processing system according to any one of claims 1 to 9.

11. A program, A program for causing a computer to execute each step of the information processing system according to any one of claims 1 to 9.

Citation Information

Patent Citations

  • Information processing device and information processing method

    JP7470856B1

  • Information processing system, information processing method, and program

    JP7581560B1

  • Inline package name based supply chain attack detection and prevention

    US20240073244A1

  • Information collection device, information collection method, and information collection program

    WO2024241547A1

  • Information complementing device and information complementing method

    WO2025115162A1