IT asset management system

The IT asset management system uses an LLM to streamline the identification and management of IT assets, addressing inefficiencies in existing systems by integrating domain lists and interview results, thereby enhancing accuracy and reducing personnel burden.

JP7778269B1Active Publication Date: 2025-12-01UB SECURE CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2025172411
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2025-10-14
Publication Date
2025-12-01
Estimated Expiration
2045-05-22

AI Technical Summary

Technical Problem

Existing IT asset management systems face challenges in accurately and efficiently discovering and understanding IT assets within a company or organization, particularly in merging results from ASM tools and internal interviews, which places a heavy burden on security personnel.

Method used

An IT asset management system utilizing a management target identification unit and an attribute information collection unit, equipped with a Large Language Model (LLM), to systematically identify, manage, and collect information on IT assets by integrating domain lists, interview results, and accessing URLs to determine asset management and attributes.

Benefits of technology

Enables accurate and efficient discovery and understanding of IT assets, reducing the burden on personnel by systematically merging and managing IT asset information through LLM-based processes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007778269000001_ABST
    Figure 0007778269000001_ABST
Patent Text Reader

Abstract

It discovers and identifies IT assets to be managed within a company or organization, and collects management information for these IT assets accurately and efficiently. The system has a management target specification unit 11 that collects management information on IT assets 2 and specifies those that should be managed. The management target specification unit 11 creates a list of IT assets 2 based on at least one of URL candidates created based on a domain list 6 and URL candidates identified from interviews with asset managers 4, accepts input of management information from asset managers 4 for each URL in the list, and has an LLM 5 determine whether the IT asset 2 is a management target.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to IT security technology, and more particularly to technology that is effective when applied to an IT asset management system that collects and manages information on IT (Information Technology) assets owned by companies and organizations. [Background technology]

[0002] From a security perspective, it is important for companies to understand the IT assets they own (servers (including web applications running on them), network devices, IoT (Internet of Things) devices, etc.) and appropriately manage the risks associated with each.

[0003] However, it is not uncommon for companies to not have a full grasp of the IT assets they own. In such cases, companies can discover and understand their IT assets by conducting internal interviews, referring to internal management ledgers, and using ASM (Attack Surface Management) tools and services to collect information about their company's IT assets that is publicly available.

[0004] As an example of a technology for understanding such IT assets, Patent Publication No. 6785087 (Patent Document 1) describes a website inventory system that, in the inventory process of identifying and extracting websites that a target company or other entity should manage from the many websites publicly available on the Internet, uses machine learning to mechanically make the decision on whether or not a website should be managed, which is difficult to do manually, thereby significantly reducing the workload and processing time and improving accuracy.

[0005] After discovering and understanding IT assets, information on the asset's status and attributes is collected, risks are identified based on the management information for each asset, and security measures are planned. Security measures include the implementation of a Web Application Firewall (WAF), vulnerability assessment (tool assessment, manual assessment, etc.), and personnel development (training, development guideline development, etc.), but there are also cases where it is decided that nothing is necessary (nothing is required). Corporate security personnel need to consider security measures for each IT asset based on the management information for the IT assets. [Prior art documents] [Patent documents]

[0006] [Patent Document 1] Patent No. 6785087 Summary of the Invention [Problem to be solved by the invention]

[0007] When using ASM tools or services to identify IT assets, the output is often limited to FQDNs (Fully Qualified Domain Names), open ports, service information, etc. From the output, security personnel must investigate management information such as whether a website is running, what its Uniform Resource Locator (URL) is, and which department manages it.

[0008] Even when conducting internal interviews, if the desired answer is not obtained, it is necessary to repeatedly communicate with the on-site department and confirm whether the answer is correct. It is desirable to discover IT assets using both ASM tools and internal interviews, but depending on the size of the company, merging the results of these can be difficult, and these tasks place a heavy burden on security personnel.

[0009] Furthermore, in order to efficiently manage IT assets, it is sometimes necessary to assign a priority to each IT asset. To do this, it is necessary to collect management information such as whether each IT asset handles personal information, whether vulnerability assessments are conducted regularly, and whether a WAF has been implemented. However, making this determination is not easy, and requires, for example, actually checking the status of each IT asset or interviewing on-site asset management personnel. Depending on the size of a company, there may be hundreds or even thousands of IT assets, so the task of collecting management information for these IT assets places a heavy burden on both security personnel and asset management personnel.

[0010] Therefore, an object of the present invention is to provide an IT asset management system that enables the discovery and understanding of IT assets to be managed in a company or organization and the accurate and efficient collection of management information for these IT assets. The above and other objects and novel features of the present invention will become apparent from the description of this specification and the accompanying drawings. [Means for solving the problem]

[0011] Among the inventions disclosed in this application, the outline of representative inventions will be briefly explained as follows.

[0012] The IT asset management system, which is a representative embodiment of the present invention, is an IT asset management system that collects and manages information on IT assets that are managed by an organization, and has a management target identification unit that collects management information on IT assets that can be accessed via a network, and identifies and records those that should be managed by the organization.

[0013] The management target identification unit accepts input of a domain list related to IT assets, accepts input of URL candidates created based on each domain in the domain list and input of the results of interviews with each asset management officer related to the IT assets to be managed, and creates a list related to IT assets based on at least one of the URL candidates identified from the interview results, accepts and records input of specified management information from the asset management officer for each URL in the list, and has an LLM (large scale language model) determine whether the IT asset related to the URL is under management by the organization based on specified information including the results of accessing the URL. [Effects of the Invention]

[0014] The effects obtained by the representative inventions disclosed in this application can be briefly explained as follows: That is, the representative embodiments of the present invention enable accurate and efficient discovery and understanding of IT assets to be managed in a company or organization, and collection of management information for these IT assets. [Brief explanation of the drawings]

[0015] [Figure 1] 1 is a diagram illustrating an overview of a configuration example of an IT asset management system according to an embodiment of the present invention. [Figure 2] 10 is a flowchart outlining an example of a processing flow for collecting information on an IT resource to be managed in an embodiment of the present invention. [Figure 3] FIG. 10 is a diagram showing an outline of an example of an IT asset list creation process according to an embodiment of the present invention. [Figure 4] 10 is a flowchart outlining an example of the flow of an IT asset list creation process according to an embodiment of the present invention. [Figure 5] 10 is a flowchart outlining an example of the flow of a website list creation process according to an embodiment of the present invention. [Figure 6]FIG. 10 is a diagram showing an outline of an example of processing for creating a website list from a domain list in an embodiment of the present invention. [Figure 7] 10A and 10B are diagrams outlining an example of a prompt and its output for causing an LLM to determine whether a URL is a website in one embodiment of the present invention. [Figure 8] FIG. 10 is a diagram showing an outline of an example of processing for creating a website list based on the results of a hearing from an asset manager in one embodiment of the present invention. [Figure 9] 10 is a flowchart outlining an example of the flow of same-site merge processing in one embodiment of the present invention. [Figure 10] FIG. 10 is a diagram illustrating an example of a process for merging identical URLs according to an embodiment of the present invention. [Figure 11] FIG. 10 is a diagram illustrating an example of a process for grouping FQDNs according to an embodiment of the present invention. [Figure 12] FIG. 1 is a diagram illustrating an example of a process for merging identical websites according to an embodiment of the present invention. [Figure 13] 10A and 10B are diagrams outlining an example of a prompt and its output for causing an LLM to determine whether or not the websites are the same in one embodiment of the present invention. [Figure 14] 10 is a flowchart outlining an example of the flow of a process for determining a company-managed site according to an embodiment of the present invention. [Figure 15] FIG. 10 is a diagram showing an outline of an example of a process for determining a company-managed site according to an embodiment of the present invention. [Figure 16] 10 is a diagram outlining an example of a prompt and its output for causing an LLM to determine whether a site is managed by the company in one embodiment of the present invention. FIG. [Figure 17] 10 is a diagram outlining an example of a prompt and its output for causing an LLM to determine whether a site is managed by the company in one embodiment of the present invention. FIG. [Figure 18]10 is a flowchart outlining an example of the flow of a manager hearing process according to an embodiment of the present invention. [Figure 19] FIG. 10 is a diagram showing an outline of an example of a manager hearing process according to an embodiment of the present invention. [Figure 20] FIG. 10 is a diagram showing an outline of an example of an IT resource importance determination process according to an embodiment of the present invention. [Figure 21] 10 is a flowchart outlining an example of the flow of an IT resource importance determination process according to an embodiment of the present invention. [Figure 22] 10 is a flowchart outlining an example of the flow of attribute information collection processing in one embodiment of the present invention. [Figure 23] FIG. 10 is a diagram showing an outline of an example of customization processing of attribute information according to an embodiment of the present invention. [Figure 24] FIG. 10 is a diagram showing an outline of an example of automatic determination processing of attribute information in an embodiment of the present invention. [Figure 25] FIG. 10 is a diagram outlining an example of a prompt and its output for causing an LLM to evaluate page attributes in one embodiment of the present invention. [Figure 26] FIG. 10 is a diagram showing an outline of an example of attribute information hearing processing in one embodiment of the present invention. [Figure 27] 10 is a flowchart outlining an example of the flow of importance determination processing in one embodiment of the present invention. [Figure 28] FIG. 10 is a diagram showing an outline of an example of a weighting customization process according to an embodiment of the present invention. [Figure 29] FIG. 10 is a diagram illustrating an example of an importance determination process according to an embodiment of the present invention. [Figure 30] FIG. 1 is a diagram showing an overview of an example of a data configuration for site management according to an embodiment of the present invention. [Figure 31] FIG. 2 is a diagram showing an overview of an example of a data configuration for page management according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0016] Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings. In all drawings used to explain the embodiments, the same parts are generally designated by the same reference numerals, and repeated explanations will be omitted. However, parts that have been designated and explained in one drawing may be referred to by the same reference numerals in the explanation of other drawings, although they will not be shown again.

[0017] <Summary> As mentioned above, the workflow for security personnel to identify the IT assets owned by a company or organization involves, for example, first referencing existing IT asset management ledgers or the output of ASM tools to identify a list of domains that are believed to be managed by the company. However, in many cases, the administrators of IT assets identified from the domain list are unknown, and it is often necessary to interview relevant parties to identify the administrators.

[0018] Therefore, security personnel interview people they believe to be asset managers (developers, business managers, etc.) to obtain information such as lists of IT assets managed by each of them, but the task of merging the asset lists and domain lists obtained from each asset manager to create and manage a list of IT assets is extremely cumbersome.In addition, if the IT asset is a web application, it may need to be managed as a separate IT asset even if the FQDN is the same, and one IT asset may contain multiple FQDNs, making it difficult to determine whether the IT assets are the same or not.

[0019] Security personnel must check the status of each IT asset in the list obtained. For example, they must actually access a website to check whether it is up and running, what kind of site it is, etc. However, there are many cases where the URL is unknown even when trying to access the website.

[0020] When the management information for IT assets is unknown, the asset management officer for the relevant IT assets is interviewed, but this may require interviewing multiple officers, which often makes it difficult to keep track of responses.In addition, the officer interviewed may introduce another officer, which may require a new interview.

[0021] If the interview results from the person in charge are satisfactory, that's fine, but if they are not, the security person will need to actually access the IT assets in question and check the management information. Depending on the size of the company, the number of IT assets in question may be enormous, which may require a great deal of effort.

[0022] In response to this situation, an IT asset management system, which is one embodiment of the present invention, enables a company to discover and understand the IT assets that it manages, including accessing each IT asset, interviewing asset management personnel and obtaining the results, and collecting management information for these IT assets in a systematic, accurate and efficient manner, using LLMs (Large Language Models).

[0023] <System configuration> 1 is a diagram showing an overview of an example of the configuration of an IT asset management system according to one embodiment of the present invention. The IT asset management system 1 is configured to include, for example, server devices and virtual servers built on a cloud computing service, and is accessed by information processing terminals such as personal computers (PCs) used by users, such as security officers 3 in a company or organization and asset managers 4 who manage IT assets 2, via networks such as the Internet, VPNs (Virtual Private Networks), and LANs (Local Area Networks), all of which are not shown, using web browsers or dedicated applications, all of which are not shown.

[0024] The IT asset management system 1, for example, uses a CPU (Central Processing Unit) not shown to execute middleware such as an OS (Operating System), DBMS (DataBase Management System), and web server program deployed in memory from a storage device such as an HDD (Hard Disk Drive) or SSD (Solid State Drive), as well as software running on top of them, thereby realizing various functions related to the discovery and understanding of IT assets accessible via a network, the collection of management information, etc.

[0025] This IT asset management system 1 has various units, such as a management target identification unit 11 and an attribute information collection unit 12, implemented by software. Each of these units can use an LLM5 such as GPT (Generative Pretrained Transformer, registered trademark). The LLM5 may be an external service or tool, or may be independently developed by the system itself. The IT asset management system 1 also has various data stores, such as a site management unit 13 and a page management unit 14, implemented using databases, file tables, etc.

[0026] The management target identification unit 11 has the function of discovering, grasping, and identifying IT assets 2 that should be managed by the company, and registering them in the site management 13. When identifying the IT assets 2 to be managed, for example, a domain list 6 based on the output results of an existing management ledger or ASM tool, or the results of a hearing entered by the asset management officer 4 for each IT asset 2, is used as input.

[0027] The IT assets 2 include servers accessible via a network (including web applications running on them), network devices, IoT devices, etc., but this embodiment will focus on web applications (websites and the web pages contained therein). Other types of IT assets 2 (e.g., server devices, network devices, IoT devices, virtual machines, containers, cloud services, etc.) can also be processed in the same way within the scope of obtainable information (e.g., whois information, IP addresses, digital certificates, NS (Name Server) records, etc.).

[0028] The attribute information collection unit 12 has a function of collecting attribute information for each IT asset 2 identified as a management target within the company, and registering it in the site management 13 and page management 14. Details of the attribute information registered in the site management 13 and page management 14 will be described later, but it includes information on the presence or absence of predetermined attributes and functions possessed by the target IT asset 2, such as whether or not the website or web page has an "authentication function" or "payment function," whether or not it is a "dynamic site," and whether or not it contains "personal information."

[0029] For IT assets other than websites and web pages (for example, server equipment, network equipment, IoT devices, virtual machines, containers, cloud services, etc.), open / closed port information and banner information may be collected by port scanning, and the software configuration (OS, middleware, applications, and their versions, etc.) may be identified from that information mechanically or by inputting that information into LLM. Furthermore, vulnerability information for the software used by the IT asset may be collected from the software configuration of the IT asset based on vulnerability information published on the Internet.

[0030] Furthermore, the IT asset type (email server, database server, VPN device, etc.) may be identified automatically from the software configuration, open / close port information, and banner information of the IT asset, or by inputting this information into the LLM. The information obtained here, such as open / close port information, banner information, software configuration, vulnerability information, and IT asset type, may be recorded as attribute information. Note that this recorded attribute information can be confirmed and corrected by the asset management officer 4, just like attribute information for websites and web pages.

[0031] <Processing flow (overall)> 2 is a flowchart outlining an example of the overall flow of management processing for IT assets 2 in one embodiment of the present invention. The management processing is broadly divided into two processes: an IT asset list creation process (S1) in which the management target specification unit 11 specifies the IT assets 2 to be managed by the company and creates a list of them, and an IT asset importance determination process (S2) in which the attribute information collection unit 12 acquires attribute information for each IT asset 2 in the list and determines its importance based on this information.

[0032] <Process flow (IT asset list creation process)> 3 is a diagram outlining an example of the IT asset list creation process (step S1 in FIG. 2) in one embodiment of the present invention. The top section of the diagram shows an example of a domain list 6, and the middle section shows an example of the results of interviews with asset managers 4. The bottom section shows an example of a list of managed IT assets 2 that should be created based on these details. This list can be implemented, for example, as site management 13.

[0033] In the example of Site Management 13 in the figure, identical websites are merged into one. For example, "shopping.example" and "www.shopping.example" in Domain List 6 are merged as the same site. Also, "https: / / corporate.example / " and "https: / / corporate.example / product" in the interview results are merged as the same site. On the other hand, different websites with the same FQDN are not merged. For example, "https: / / system.example / hrm" and "https: / / system.example / accounting" in the interview results are not merged as they are different websites. Site Management 13 also includes only websites that are ultimately determined to be managed by the company, indicating that the management departments and administrators have been identified.

[0034] Figure 4 is a flowchart outlining an example of the flow of the IT asset list creation process (step S1 in Figure 2) in one embodiment of the present invention. The IT asset list creation process first performs a website list creation process (S11) to create a list of candidate websites for management, followed by a same site merge process (S13) to merge identical websites in the list. Then, for each merged website, a company-managed site determination process (S15) is performed to delete any websites not under the company's management from the list, and then a manager interview process (S17) is performed to interview the asset manager 4, thereby terminating the IT asset list creation process.

[0035] 5 is a flowchart outlining an example of the flow of the website list creation process (step S11 in FIG. 4) in one embodiment of the present invention. This process can be broadly divided into two processes: creating a website list from the domain list 6, and creating a website list from the results of interviews with the asset management officer 4.

[0036] First, in the process of creating a website list from the domain list 6, the management target identification unit 11 accepts input of the domain list 6 (S111) and starts a loop process that repeats for each unconfirmed FQDN in the list (S112). In the loop process, a list of URL candidates is created based on the target FQDN using a predetermined procedure described below (S113). Then, a loop process that repeats for each URL candidate is started (S114).

[0037] In this loop, the target URL candidate is actually accessed to check for connectivity (S115), and based on the results, it is determined whether the URL is a website (S116). If it is a website (Yes in step S116), the URL is added to the website list (site management 13) (S117), and processing moves on to the next URL candidate (S118, S114). When processing has been completed for all URL candidates, processing moves on to the next FQDN (S119, S112).

[0038] FIG. 6 is a diagram outlining an example of the process (steps S111 to S119 in FIG. 5) of creating a website list from the domain list 6 in one embodiment of the present invention. An example of the domain list 6 is shown in the upper part of the diagram. As described above, this domain list 6 is created based on the output results of an existing management ledger or ASM tool, for example. Some FQDNs registered in the domain list 6 are known only by their FQDN, and the URL is not known, so URL candidates are created for each of these FQDNs.

[0039] In this embodiment, URL candidates are created by combining predefined path candidates (frequently used patterns) with the FQDN, and by actually searching publicly available URLs using a search engine such as Google (registered trademark, the same applies below) based on the FQDN, but other methods may also be used. In the example of Figure 6, for the FQDN "shopping.example" in domain list 6, the middle diagram shows an example of a list of URL candidates combined with predefined paths (" / ", " / admin", " / login", ...), and a list of URL candidates obtained as a result of searching "site:shopping.example" on Google.

[0040] Then, each URL candidate is actually accessed and the access results (HTTP response or screen capture, hereinafter sometimes simply referred to as "response") are used to determine whether it is a website or not. For example, Will a response be returned? - Whether the response status code is in the 200 or 300 range - Is the response size greater than or equal to a specified value? -Does it match the keywords of the predefined default site? ·Whether the response is determined to be website content by LLM5 If the site satisfies all or part of the above conditions, it is determined to be a website. Note that these conditions are merely examples, and other conditions may also be used.

[0041] FIG. 7 shows an example of a method for determining whether a URL is a website using an LLM in accordance with an embodiment of the present invention. This figure shows an overview of prompts for making judgments using LLM5 and examples of their output. Here, a website judgment prompt like the one shown in the upper figure is generated from a template and input into LLM5, and judgment result information like that shown in the lower figure is obtained as output from LLM5.

[0042] Returning to Figure 6, those URL candidates that are determined to be websites are registered in the website list (site management 13) as shown in the lower diagram. At this time, for example, if all of the FQDNs of the URL candidates are determined not to be websites, one of the URLs is registered in site management 13 as a representative. This makes it possible to prompt confirmation by interviewing the asset management officer 4.

[0043] On the other hand, since there may be multiple websites with the same FQDN, multiple path candidates will be verified for one FQDN. However, if the number of targets to be verified becomes too large, it is possible to terminate the verification midway and move on to verifying the next FQDN by setting a certain upper limit or determining that the responses are identical based on the similarity between the responses, etc.

[0044] 5, once processing for all FQDNs has been completed in step S119, the process then proceeds to create a website list from the results of interviews with asset managers 4. First, a form for interviewing asset managers 4 in each department regarding the websites they manage is sent (S120), and management information for the websites is accepted (S121). Management information includes, for example, items such as the URL, site name, management department, and administrator.

[0045] Then, a loop process is started that repeats for each input / answered URL (S122). In the loop process, the target URL is actually accessed and communication is confirmed as in step S115 (S123), and the result is presented to the asset manager 4, who then accepts input and response to confirm whether it is a website or not (S124). If it is confirmed to be a website (Yes in step S125), the URL is added to the site management 13, and processing moves to the next URL (S127, S122). On the other hand, if it cannot be confirmed to be a website (No in step S125), the process returns to step S121 and the entered management information is corrected. When processing has been completed for all input / answered URLs, the website list creation process ends.

[0046] 5, the process of creating a website list from the domain list 6 (steps S111 to S119) is performed, followed by the process of creating a website list from the results of interviews with the asset manager 4 (steps S120 to S127), but this order may be reversed, or these steps may be performed in parallel. Also, the website list may be created from only either the domain list 6 or the results of interviews with the asset manager 4.

[0047] 8 is a diagram outlining an example of the process (S120 to S127 in FIG. 5) for creating a website list from the results of a hearing with the asset management personnel 4 in one embodiment of the present invention. The upper part of the diagram shows an example of a hearing form whose URL is sent by email to the asset management personnel 4 in each department. Through input into this form, the management target identification unit 11 can obtain management information for the IT assets 2 (websites) to be managed.

[0048] 8, the input of information on the site name, URL, management department, and administrator is accepted, but it is also possible to accept input of other authentication information (ID, password, etc.) for accessing the website. Also, instead of entering management information for each website individually, it is also possible to enter multiple items together in a tabular form, or to upload a data file in a specified format and enter all the information at once.

[0049] As with the method described above, the URL entered here is also accessed and a determination is made as to whether it is a website or not based on the response. Then, as shown in the middle part of Figure 8, a screen capture of the determination result and response is presented to the asset management officer 4, who is then asked to confirm the determination result or to correct the entered management information. If corrections are made, the officer returns to the form shown in the top part of Figure 8 and accepts the entry of new management information. If the input is confirmed, the target URL is registered in the website list (site management 13), as shown in the bottom part of the diagram.

[0050] The diagram on the left in the middle section of Figure 8 is an example of the screen displayed when it is determined to be a website, and the diagram on the right is an example of the screen displayed when it is determined not to be a website. However, if it is determined not to be a website, the reason for the determination may be displayed along with possible causes and countermeasures. For example, a message such as "The URL may be incorrect, so please check again" or "The IP address from which you are connecting may be restricted, so please allow access from XX" may be displayed.

[0051] Furthermore, even if the asset manager 4 determines that the website is not a website, there may be cases where the website is not publicly available and is only publicly available internally, so the website may be registered in the site manager 13 as shown in the lower diagram of Figure 8. At this time, it is desirable to also record information on the communication result ("status code 404" in the example of Figure 8) for management purposes.

[0052] 9 is a flowchart outlining an example of the flow of the same site merge process (step S13 in FIG. 4) in one embodiment of the present invention. This process can be broadly divided into a process of merging identical URLs in the website list (site management 13), a process of grouping FQDNs, and a process of merging identical websites.

[0053] First, as a process for merging identical URLs, a loop process is started (S131) ​​that repeats for each unconfirmed URL in the site management 13. In the loop process, it is determined (S132) whether or not there is another URL in the site management 13 that is identical to the URL to be processed, and if there is (Yes in step S132), these records in the site management 13 are merged (S133), and processing proceeds to the next URL (S134, S131).

[0054] 10 is a diagram outlining an example of the process of merging identical URLs (steps S131 to S134 in FIG. 9) in one embodiment of the present invention. The upper part of the diagram shows an example of a website list (site management 13) before identical URLs are merged. Of these, Nos. 1 to 6 are based on the output results of the ASM tool / service, and Nos. 7 to 11 are based on the results of interviews with each asset manager 4.

[0055] Here, it is determined whether or not there is another URL that is the same as the URL to be processed in the site management 13. For example, The two URLs match The redirect destinations of the two URLs match The redirect destination of one URL matches the redirect destination of another URL If any of the above conditions are met, the URLs will be treated as the same. Even if the URL schemes (http, https) are different, they will be considered the same as long as the rest of the URL matches.

[0056] If there are identical URLs, these records are merged, for example, - Information from the interview results of asset management officer 4 is output as an ASM tool / service result take priority If there is conflicting information from the interview results of asset management officer 4, Prioritize - URLs with "https" scheme have priority over those with "http" scheme. Set priorities such as and merge records accordingly.

[0057] In the example of Figure 10, when the URL to be processed in the upper diagram is No. 1 "https: / / shopping.example / ", No. 7 "https: / / shopping.example / " is determined to be the same URL, and the lower diagram shows that these records are merged (record No. 1, which was based on the output results of the ASM tool / service, is merged with record No. 7, which was based on the results of the interview with asset management officer 4, and then deleted).

[0058] 9, once processing for all URLs in site management 13 has been completed in step S134, the next step is to group the FQDNs by first creating a list of FQDNs associated with each URL in site management 13 (S135) and then starting a loop process that repeats for each FQDN in the list (S136). In the loop process, it is determined whether or not there are any FQDNs in the list that are similar to the FQDN being processed (S137), and if there are (Yes in step S137), these records in the FQDN list are grouped (S138), and processing moves to the next FQDN (S139, S136).

[0059] 11 is a diagram outlining an example of the process of grouping FQDNs (steps S135 to S139 in FIG. 9) in one embodiment of the present invention. The upper part of the diagram shows an example of a website list (site management 13) after identical URLs have been merged by the above-mentioned process, and the middle part of the diagram shows an example of an FQDN list created by extracting FQDNs from URL information in site management 13.

[0060] Here, it is determined whether there is another FQDN similar to the FQDN to be processed in the FQDN list. For example, One FQDN is a subdomain of the other In the example of Figure 11, when the FQDN to be processed in the middle FQDN list is No. 1 "www.shopping.example", No. 2 "shopping.example" is determined to be a similar FQDN, and the bottom diagram shows that these records are assigned group No. 1 and grouped.

[0061] 9, once processing for all FQDNs in the FQDN list has been completed in step S139, the process of merging identical sites begins by first starting a loop process that repeats for each group in the FQDN list (S140). In this loop process, URLs whose domains match the FQDNs in the group being processed are extracted from the website list (site management 13) (S141), and a loop process that repeats for each extracted URL is started (S142).

[0062] In this loop process, it is determined whether or not there is any URL extracted in step S141 that is on the same website as the URL being processed (S143). If there is any URL on the same website (Yes in step S143), these records in site management 13 are merged (S144), and processing moves on to the next URL (S145, S142). When processing has been completed for all extracted URLs, processing moves on to the next group (S146, S140). When processing has been completed for all groups, the same site merge process ends.

[0063] 12 is a diagram outlining an example of the process of merging identical websites (steps S140 to S146 in FIG. 9) in one embodiment of the present invention. The upper part of the diagram shows an example of an FQDN list after similar FQDNs have been grouped by the above-mentioned process, and the middle part of the diagram shows an example of a website list (site management 13) after identical URLs have been merged by the above-mentioned process. Of the URLs in this site management 13, URLs No. 3, 4, and 7 are extracted as URLs whose domains match the FQDNs grouped as group No. 1 in the FQDN list in the upper part of the diagram.

[0064] For each URL extracted here, it is determined whether it is the same site as other URLs. For example, Using LLM5, page information related to the URL (response, screen capture, Determine whether the site is the same based on the technical components, etc. Page information is obtained from the target URL and, if necessary, from the website. Automatically patrol and acquire Component technologies are determined mechanically from request / response information As will be described later, the method for determining whether or not the sites are the same is not limited to using LLM5 as described above.

[0065] 13 is a diagram outlining an example of a prompt for causing the LLM 5 to determine whether the websites are the same or not, and its output, in one embodiment of the present invention. Here, by generating a same-website determination prompt such as that shown in the upper diagram from a template and inputting it into the LLM 5, the LLM 5 outputs information on the determination result such as that shown in the lower diagram.

[0066] Returning to FIG. 12, among the URLs extracted from the diagram in the middle, if they are determined to be the same website, these records are merged. In this case, similar to the process of merging the same URLs described above, for example, - Information from the interview results of asset management officer 4 is output as an ASM tool / service result take priority If there is conflicting information from the interview results of asset management officer 4, Prioritize - URLs with "https" scheme have priority over those with "http" scheme. Set priorities such as and merge records accordingly.

[0067] The example in Figure 12 shows that for URLs No. 3, 4, and 7 extracted in the middle diagram, these records have been merged (record No. 7, based on the results of the interview with asset management officer 4, took priority, and records No. 3 and 4 were merged with it and deleted).

[0068] As mentioned above, the same site merge process shown in the example of Figure 9 aims to merge URLs from the same website in the website list (site management 13). Here, in the process of determining whether a target URL is in the same site as another URL (step S143 in Figure 9), if a method such as using LLM5 to determine whether a URL is in the same site from page information related to the URL (response, screen capture, constituent technical elements, etc.) is used, the time and financial costs will be large if there are a large number of URLs in the website list.

[0069] 9, in order to reduce the number of comparisons between URLs by LLM5 using page information as input, the URLs in the website list are grouped in advance by performing a process of grouping FQDNs (steps S135 to S139 in FIG. 9), and the URLs in the group are compared to determine whether they belong to the same site (steps S140 to S146 in FIG. 9). Therefore, for example, if the number of URLs in the website list is less than a predetermined number, or if the process of determining whether URLs belong to the same site (step S143 in FIG. 9) uses another comparison and determination method, as described below, instead of the determination process by LLM5 that involves input of page information, the process of grouping FQDNs (steps S135 to S139 in FIG. 9) may be omitted.

[0070] As another comparison and determination method, for example, the page information of the URLs to be compared may be converted into vectors, the similarity between the vectors may be calculated, and if the similarity exceeds a predetermined threshold, it may be determined that the sites are the same. In this case, the predetermined threshold may be set to a fixed value by, for example, a security officer, or it may be determined in advance by inputting page information for several sample URLs to determine whether they are the same site, calculating the similarity between the vectors when they are determined to be the same site and the similarity when they are determined to be different sites, and setting an appropriate threshold from these values.

[0071] Alternatively, for example, the page information of all URLs can be vectorized in advance and stored in a database, and for the URL to be compared, a URL with a vector of page information close to that of the URL can be searched for, and the page information of both the obtained URLs can be used as input to determine whether they are the same site using LLM5.

[0072] 14 is a flowchart outlining an example of the flow of the company-managed site determination process (step S15 in FIG. 4) in one embodiment of the present invention. First, a loop process is started (S151) that repeats each URL in the website list (site management 13) after identical sites have been merged. In the loop process, it is determined whether the URL being processed is a company-managed site, and the confidence level is output (S152).

[0073] Thereafter, it is determined whether the certainty is equal to or greater than a predetermined threshold (S153), and if it is less than the threshold (No in step S153), a confirmation flag is set for the target URL to confirm with the asset management officer 4 whether it is managed by the company, and the process moves on to processing the next URL (S157, S151).On the other hand, if the certainty is equal to or greater than the predetermined threshold (Yes in step S153), it is determined whether the target URL was determined to be a company-managed site in step S152 (S155).

[0074] If it is determined to be a company-managed site (Yes in step S155), the process moves directly to processing the next URL (S157, S151), but if it is determined not to be a company-managed site (No in step S155), the target URL is deleted from the website list (site management 13) (S156) and the process moves to processing the next URL (S157, S151). When processing has been completed for all URLs, the company-managed site determination process ends.

[0075] Figure 15 is a diagram outlining an example of a process for determining whether a site is under your company's control in an embodiment of the present invention. The top section of the diagram shows an example of a website list (site management 13) after identical sites have been merged. For each URL in this list, a determination is made as to whether it is a site under your company's control, and the reliability is calculated. In this embodiment, for example, the LLM 5 receives the response when accessing the target URL, as well as information such as the FQDN's Whois information, IP address, certificate, and NS record, and compares this information with the company's information previously registered by the security officer 3. The result of the determination as to whether the site is under your company's control, along with the reliability and reason for the determination, is output.

[0076] 16 and 17 are diagrams outlining an example of a prompt for causing the LLM5 to determine whether a site is managed by the company in one embodiment of the present invention, and an example of the output from the prompt. Here, a prompt for determining whether a site is managed by the company, such as the example shown in FIG. 16, is generated from a template and input into the LLM5, and the determination result information, such as the example shown in FIG. 17, is obtained as output from the LLM5. The example shown in the figure indicates that the site is determined to be managed by the company, and the confidence value is calculated as "80."

[0077] Returning to Figure 15, for example, the middle diagram shows an example of Site Management 13 in the case where, as a result of having LLM 5 determine whether URL No. 6 in Site Management 13 in the top diagram is a site managed by the company, the confidence level is below a predetermined threshold. In this case, the "Verification Required Flag" for the relevant record (No. 6) in Site Management 13 is set to Y, and the asset management officer 4 is made the subject of a hearing.

[0078] 15 shows an example of the site management 13 when the confidence level is equal to or greater than a predetermined threshold and it is determined that the site is not managed by the company. In this case, as shown in the figure, the record (No. 6) is deleted from the site management 13. However, if the confidence level is equal to or greater than a predetermined threshold and it is determined that the site is managed by the company, nothing is done to the record and it is left as is in the site management 13.

[0079] Figure 18 is a flowchart outlining an example of the flow of the manager interview process (step S17 in Figure 4) in one embodiment of the present invention. First, URLs that are the subject of an interview with the asset manager 4 are extracted from the website list (site management 13) (S171). For example, as shown in the middle diagram of Figure 15, URLs for which the "Verification flag (indicating whether the site is managed by the company or not)" in site management 13 is set to Y, or URLs for which no value is set in the "Management department" or "Manager" fields and are blank, are extracted as URLs to be interviewed.

[0080] Returning to Fig. 18, thereafter, a loop process is started that repeats for each URL extracted as a hearing target (S172). In the loop process, the department and person in charge of inquiries regarding the URL to be processed are determined (S173), and a hearing form is sent to the determined person by email or the like (S174). Then, input of the hearing results (whether the target URL is managed by the company, information on the management department and administrator, etc.) is accepted from the asset management person 4 (S175), and it is determined whether the answer is that the target URL is a site managed by the company (S176).

[0081] If the answer is that the site is managed by the company (Yes in S176), the record to be processed is updated with the contents of the hearing result entered (S177), and the process moves on to processing the next URL (S179, S172). On the other hand, if the answer is that the site is not managed by the company (No in S176), the record to be processed is deleted from site management 13 (S178), and the process moves on to processing the next URL (S179, S172). When processing has been completed for all URLs, the administrator hearing process ends.

[0082] 19 is a diagram outlining an example of manager interview processing in an embodiment of the present invention. The top row of the diagram shows an example of a website list (site management 13), and the second row of the diagram shows that records 6, 8, and 9 have been extracted from that list as websites that require an interview with the asset manager 4 (for example, the "verification required" flag is set to Y, or the "management department" and "manager" fields are blank, etc.).

[0083] The diagram further shows that, for record No. 6, for example, the contact person has been determined and a hearing form like the one shown in the third diagram has been sent by email to the contact person's asset management officer 4. In this case, if a value has been set in the "management department" or "administrator" field of site management 13, that value will be used as the contact person. If no value has been set, or if a value has been set but the contact person cannot be identified, the contact person will be presented to security officer 3 as a contact person, for example, from the contact person contained in the whois information related to the FQDN of the target record, or from the contact person contained in the response obtained by accessing the URL of the target record, and the contact person will be selected or entered by the security officer 3.

[0084] The hearing form shown in the third row of Figure 19 may be configured to display, for example, whois information or the reason for the determination that the site is managed by the company using LLM5. Based on the information entered by the asset management officer 4 through this form, the contents of the target record (site name, management department, and administrator of record No. 6 in the example in the figure) are updated to reflect the input information, as shown in the example of the website list (site management 13) at the bottom of the figure.

[0085] <Process flow (IT asset importance determination process)> 20 is a diagram outlining an example of the IT asset importance determination process (step S2 in FIG. 2) in one embodiment of the present invention. The top section of the diagram shows an example of a website list (site management 13) listing websites managed by the company, and the middle section shows that attribute information for each website in site management 13, such as the presence or absence of "authentication functions" and "payment functions," collected and analyzed through automatic determination or interviews with asset management personnel 4, has been recorded. The bottom section of the diagram shows that an importance level (S, A, B, C, D, ...) has been assigned to each website in site management 13 based on the content of the attribute information.

[0086] 21 is a flowchart outlining an example of the flow of the IT asset importance determination process (step S2 in FIG. 2) in one embodiment of the present invention. The IT asset importance determination process first performs an attribute information collection process (S21) in which attribute information about each website is collected and analyzed, then performs an importance determination process (S23) in which the importance of each website is determined based on the collected and analyzed attribute information, and then terminates the IT asset importance determination process.

[0087] 22 is a flowchart outlining an example of the flow of attribute information collection processing (step S21 in FIG. 21) in one embodiment of the present invention. Here, the processing can be broadly divided into attribute information customization processing, attribute information automatic determination processing, and attribute information hearing processing.

[0088] First, as a customization process for attribute information, the security officer 3 accepts input of attribute information to be collected that has been added and customized based on the situation of the company (S211).

[0089] 23 is a diagram outlining an example of attribute information customization processing in one embodiment of the present invention. The upper part of the diagram shows an example of an attribute information setting screen presented to the security officer 3. The setting screen sets predefined attribute information, including the attribute names ("authentication function," "payment function," "dynamic site," and "personal information"), the type of their values ​​("checkbox," etc.), and whether the attribute information is required.

[0090] Security officer 3 can edit or delete this information, and by pressing the "+" button, can add attribute information (in the example shown in the figure, the attribute names are "External Disclosure Status," "Contact Phone Number," "Employee Information," and "Vulnerability Assessment Date") via the screens shown in the middle figures. Value types can be set, for example, as text, checkboxes, dates, or pull-down menus. In the case of pull-down menus, the pull-down value (the options displayed) can also be set. It is also possible to specify whether or not a value must be set. The added attribute information is reflected in a list, as shown in the bottom figure. In addition to the attribute name, value type, and mandatory / unmanaged information shown in the figure, it is also possible to enter an optional description for each attribute. This can be used as input information when LLM5 automatically determines whether or not the added attribute information is present in the process described below.

[0091] 22, a loop process is then started that repeats for each website in the website list (site management 13) (S212). In the loop process, first, as an automatic attribute information determination process, the target website is automatically traversed to create a list of URLs (S213), and the page attributes of each acquired URL are evaluated using LLM5, and based on the evaluation results, it is automatically determined whether or not there is attribute information that should be collected from the target website (S124).

[0092] FIG. 24 is a diagram outlining an example of the automatic attribute information determination process in one embodiment of the present invention. The upper part of the diagram shows an example of a list of URLs obtained by automatically crawling the target IT asset 2 (website). The technology for automatically crawling the website is not particularly limited, and existing crawling technologies and tools can be used as appropriate. For each URL obtained here, the LLM 5 evaluates and determines whether it contains each of the page attributes defined in FIG. 23 above (which may include predefined attributes as well as attributes added or customized by the security officer 3).

[0093] 25 is a diagram outlining an example of a prompt for causing the LLM 5 to evaluate page attributes and its output in one embodiment of the present invention. Here, a page attribute evaluation prompt such as that shown in the upper diagram is generated from a template and input into the LLM 5, and the LLM 5 outputs evaluation result information on the presence or absence of each attribute as shown in the lower diagram.

[0094] 25, the evaluation is based on information about a single web page, but information about multiple web pages or the entire website, such as information about the responses of multiple pages, transition information about multiple pages within a website (for example, in the form of a transition diagram), and list information about the destinations to which each page transitions, may also be provided to LLM5. This makes it possible to appropriately evaluate the website as not including a payment function, for example, if a shopping cart icon is displayed on a certain page but clicking the icon takes you to another company's website to process a payment.

[0095] Returning to Figure 24, when the attribute information for the URL "https: / / example.com / profile" in the URL list in the top diagram is evaluated, the middle diagram shows that it is evaluated as including "personal information" and "payment function" (Y), but not including "authentication function" (N), and that this information is registered in page management 14.

[0096] The page management 14 in the middle diagram also shows that evaluation results for other pages (" / checkout", " / about", ...) within the website are also registered. For example, if any of these pages contains any of the attribute information, the website may be evaluated as containing that attribute information. In the example of FIG. 24, it is shown that each piece of attribute information ("personal information", "payment function", "authentication function") is contained (Y) on any page, and therefore it is determined that all of the attribute information is contained (Y). The determination results for each piece of attribute information are registered in the site management 13, as shown in the example of the middle diagram of FIG. 20 described above.

[0097] A website may be evaluated as including the attribute information only if the number of pages including each attribute information is equal to or greater than a certain number, or if the number of pages including each attribute information is equal to or greater than a certain percentage of the total number of pages. For example, since it is unusual and unnatural for a website with a payment function to have only one page with the payment function, if there is only one page within the website that is determined to have the "payment function," it may be determined that the determination that the page has the "payment function" was an erroneous determination, and that the website does not have the "payment function."

[0098] 22, thereafter, as a hearing process for attribute information, a hearing form is sent to the contact person for the website to be processed (S215), and attribute information is received from the contact person's asset management officer 4 (S216). Then, based on the input content, the attribute information of the target website in the site management 13 is updated (S217), and processing moves on to the next website (S218, S212). When processing for all websites has been completed, the attribute information collection process ends.

[0099] 26 is a diagram outlining an example of attribute information hearing processing in one embodiment of the present invention. The upper part of the figure shows an example of a hearing form whose URL is sent by email to the asset management officer 4 who is the contact person. Through input into this form, the attribute information collection unit 12 can obtain attribute information of the target IT asset 2 (website).

[0100] In the example at the top of Fig. 26, in addition to displaying the content of attribute information automatically determined by the above-mentioned process (for example, predefined "authentication function," "payment function," "dynamic site," "personal information," etc.), it is also possible to input and set content of attribute information that has not been automatically determined (for example, "vulnerability assessment date," "employee information," "external disclosure status," "person in charge phone number," etc. that have been added through customization by the security officer 3). The automatically determined content of attribute information can also be edited and changed by the asset management officer 4.

[0101] When the asset manager 4 confirms the input of the attribute information, the contents of the corresponding record in the website list (site management 13) are updated based on the input, as shown in the lower diagram of FIG.

[0102] 27 is a flowchart outlining an example of the flow of importance determination processing (step S23 in FIG. 21) in one embodiment of the present invention. Here, the processing is roughly divided into a process for customizing weighting when determining importance and a process for determining importance.

[0103] First, as a customization process for weighting when determining importance, the security officer 3 inputs the weighting of scores for each attribute information set based on the situation of his or her company (S231).

[0104] FIG. 28 is a diagram outlining an example of the weighting customization process in one embodiment of the present invention. The upper part of the diagram shows an example of a screen for setting score weights for each attribute information presented to the security officer 3. In addition to displaying predefined score weights for predefined attribute information (e.g., "authentication function," "payment function," "dynamic site," "personal information," etc.), as shown in the lower part of the diagram, the screen also allows the security officer 3 to input and set score weights for attribute information added through customization (e.g., "vulnerability diagnosis date," "employee information," "external disclosure status," "person in charge phone number," etc.). It is also possible to change the score weights for predefined attribute information.

[0105] The weighting value of the score (in what cases should it be added (or subtracted)) differs depending on the type of value of the attribute information. For example, In the case of a "checkbox," if it is checked (if the value is Y), a weighting value is added. Also, if the value type is "date" or "text," a weighting value is added if a value indicating a date or text is entered. If the value type is "pull-down," if any of the pull-down values ​​(options) is entered, a corresponding weighting value is added. Note that the weighting score for each pull-down value can be set for each pull-down value (option), for example, as shown in the example of the "External Publication Status" settings screen in the lower diagram of Figure 28.

[0106] 27, a loop process is then started that repeats for each website in the website list (site management 13) (S232). In the loop process, the importance of the target website is determined based on the presence or absence of each attribute information and the score weighting set in step S231 (S233), and the importance of the record of the target website in site management 13 is updated based on the determination result (S234), and processing moves to the next website (S235, S232). When processing for all websites has been completed, the importance determination process ends.

[0107] 29 is a diagram outlining an example of importance determination processing in an embodiment of the present invention. The top part of the diagram shows an excerpt of the attribute information portion of the website list (site management 13) and the score weighting set for each attribute information. The middle part of the diagram shows the total weighted score calculated for each website based on the presence or absence of each attribute information and the weighting of each score.

[0108] Specifically, for example, in the case of the "shopping site" in the figure, 50 (Authentication function = Y) +80 ("Payment function" = Y) +100 ("Dynamic Site" = Y) +50(“Personal Information”=Y) -30 ("Vulnerability Assessment Date" = Value) +60 (External access status = Public access) = 310 Similarly, in the case of a "personnel system," 50 (Authentication function = Y) +100 ("Dynamic Site" = Y) +50(“Personal Information”=Y) +40("Employee Information" = Y) = 240 This becomes:

[0109] Then, the importance score for each website is calculated from the total weighted score calculated for each website, as shown in the lower diagram. This score value may be used as the importance directly, but in this embodiment, it is used as the importance ranked as S, A, B, C, D, etc. depending on the value range.

[0110] The importance score value can be calculated, for example, by converting and normalizing the total value of the weighted scores calculated by the above-mentioned method so that it falls within the range of 0 to 1, multiplying this value by 100, and rounding off to the nearest whole number. If this importance score value is, for example, 0 to 19, it is ranked as importance D, 20 to 39 as importance C, 40 to 59 as importance B, 60 to 79 as importance A, and 80 to 100 as importance S.

[0111] The formula for calculating the importance score from the total weighted score is, for example, the following, using the minimum and maximum values ​​that the total weighted score can take: Importance score value = (Total weighted score value - Minimum value) / (Maximum value - Minimum value) x 100 This can be calculated using the formula (rounded to the nearest integer).

[0112] Specifically, for example, in the case of the score weighting settings shown in the upper diagram of FIG. 29, the minimum value of the weighted score total is -30 and the maximum value is 380. Therefore, for example, in the case of "Shopping Site" in the diagram, Importance score value = (310-(-30)) / (380-(-30))×100 = 83 The importance ranking is S. Similarly, for "Human Resources System", Importance score value = (240-(-30)) / (380-(-30))×100 = 66 So the importance rank is A.

[0113] In addition to setting the importance rank based on the total value of the weighted score as described above, it is also possible to set a condition such as "if certain attribute information is present, the rank will automatically be S." The importance rank determined by the above process may be edited or changed individually by the security officer 3. In this case, it is desirable to have the reason for editing or changing entered, record this, and display it together with the importance rank.

[0114] By reflecting the importance obtained here in the website list (site management 13), the security officer 3 can obtain the IT assets 2 that his company must manage in a form that includes an evaluation of their importance, which greatly reduces the burden of collection, investigation, and confirmation through interviews.

[0115] <Data structure> 30 is a diagram outlining an example of the data configuration of the site management 13 in one embodiment of the present invention. The site management 13 is a data store that holds management information and attribute information of the IT asset 2 (website), and is made up of tables such as domain, interview result site, management site, and site management information.

[0116] The domain table is a table that holds domain information, and has fields such as domain ID, FQDN, open port, and service. The domain ID field holds information about an ID that uniquely identifies the target domain, and the FQDN field holds information about the FQDN of the target domain. The open port and service fields hold information about open port numbers in the target domain and services available in the target domain, respectively.

[0117] The Interview Result Site Table is a table that holds website management information obtained based on the interview results of each asset management officer 4, and has fields such as Interview Result Site ID, Site Name, URL, Management Department, and Administrator. The Interview Result Site ID and Site Name fields hold information on an ID and site name that uniquely identify the target website, respectively. The URL field holds information on the URL of the target website. The Management Department and Administrator fields hold information on the management department and administrator related to the target website, respectively.

[0118] The managed site table is a table that holds management information for websites that are managed by the company and are candidates for management, and includes items such as site ID, site name, URL, redirect URL, management department, administrator, ASM output FQDN, interview result site ID, company management confirmation flag, importance score, and importance.

[0119] The Site ID and Site Name fields hold information about the ID and site name that uniquely identify the target website, respectively. The URL and Redirect URL fields hold information about the URL of the target website and the URL of the redirect destination, respectively. The Management Department and Administrator fields hold information about the management department and administrator related to the target website and URL, respectively. The ASM Output FQDN field holds information about the FQDN that was identified when the target website was identified by the ASM tool / service. The Interview Result Site ID field holds information about the site ID when the target website was identified as a result of an interview with the asset management officer 4.

[0120] The Merge Destination Site ID field holds information about the site ID of the record to be merged when a record related to the target website is merged with another record during processing such as that shown in the example of Figure 10 above (when merging records, the record to be merged is not deleted but is retained so that the merge destination record can be identified). The In-house Management Verification Flag field holds information about whether or not it is necessary to interview the asset management officer 4 about the target website to determine whether it is an IT asset 2 managed by the company. The Importance Score and Importance fields hold information about the importance score calculated for the target website using processing such as that shown in the example of Figure 29 above, and the importance ranked based on that score.

[0121] The site management information table is a table that holds information about each attribute information set for the target website by processing such as that shown in the example of Figure 26 above, and has items such as site ID, attribute name, value type, value, mandatory flag, and score weight. The site ID item holds information about an ID that uniquely identifies the target website. The attribute name item holds information about the name of the attribute information that the target website has. The value type and value items each hold information about the value type (text, pull-down, etc.) and value of the target attribute information. The mandatory flag item holds information about whether setting the target attribute information is mandatory. The score weight item holds information about the weighting of the importance score when the target attribute information is present.

[0122] 31 is a diagram outlining an example of the data configuration of the page management 14 in one embodiment of the present invention. The page management 14 is a data store that holds information about each web page included in the IT asset 2 (website), and is made up of tables such as pages and page management information.

[0123] The page table is a table that holds management information for each web page included in a website, and includes items such as page ID, site ID, page name, URL, request, response, screen capture, and constituent technical elements.

[0124] The page ID and site ID fields hold ID information that uniquely identifies the target web page and the website to which it belongs, respectively. The page name and URL fields hold information about the page name and URL of the target web page, respectively. The request and response fields hold information about the HTTP request and the response when browsing the target web page, respectively. The screen capture field holds information about data captured from the screen display of the target web page. The constituent technical elements field holds information about the constituent technical elements of the target web page (for example, payment functions, authentication functions, etc.).

[0125] The page management information table is a table that holds attribute information of a target web page, and has, for example, fields for page ID, attribute name, value type, and value. The page ID field holds ID information that uniquely identifies the target web page. The attribute name field holds the name of the attribute information that the target web page has. The value type and value fields each hold the value type (text, pull-down, etc.) of the target attribute information and information about its value.

[0126] It goes without saying that the data structure and data items of the site management 13 and page management 14 described above are merely examples, and other data structures or data stores may be used as long as they can hold equivalent data.

[0127] As explained above, the IT asset management system 1, which is one embodiment of the present invention, makes it possible to discover and understand the IT assets 2 that are to be managed within the company, including processes such as accessing each IT asset 2, interviewing asset management personnel 4 and obtaining the results, and to collect management information and attribute information for these IT assets 2 in a systematic, accurate and efficient manner, by using the LLM 5 as well.

[0128] The invention made by the inventor has been specifically described above based on the embodiments, but it goes without saying that the present invention is not limited to the above embodiments and can be modified in various ways without departing from the spirit of the invention. Furthermore, the above embodiments have been described in detail to clearly explain the present invention, and the present invention is not necessarily limited to those having all of the described configurations. Furthermore, it is possible to add, delete, or replace part of the configuration of the above embodiments with other configurations.

[0129] Furthermore, the above-described configurations, functions, processing units, processing means, etc. may be partially or entirely implemented in hardware, for example, by designing them as integrated circuits. The above-described configurations, functions, etc. may also be implemented in software, with a processor interpreting and executing a program that implements each function. Information such as the programs, tables, and files that implement each function can be stored in a storage device such as a memory, hard disk, or SSD, or in a storage medium such as an IC card, SD card, or DVD.

[0130] In addition, in the above figures, the control lines and information lines shown are those that are considered necessary for explanation, and do not necessarily show all the control lines and information lines that are actually implemented. In reality, it can be assumed that almost all components are interconnected. [Industrial Applicability]

[0131] The present invention can be used in an IT asset management system that collects and manages information about IT assets owned by a company or organization. [Explanation of symbols]

[0132] 1...IT asset management system, 2...IT assets, 3...security officer, 4...asset management officer, 5...LLM, 6...domain list, 11...Management target identification unit, 12...Management information collection unit, 13...Site management, 14...Page management

Claims

1. An IT asset management system that collects and manages information on IT assets to be managed in an organization, a management target specifying unit that collects management information of IT assets accessible via a network, and specifies and records those that should be managed by the organization; an attribute information collection unit that collects predetermined attribute information related to IT assets to be managed in the organization, and determines and records the importance of the IT assets based on the collected attribute information; the management target specification unit receives an input of a domain list related to IT assets, creates a list related to IT assets based on each domain in the domain list, and causes an LLM (Large Scale Language Model) to determine whether each IT asset in the list is a management target of the organization; The attribute information collection unit has the LLM determine whether or not an IT asset has each of the attribute information based on specified information including the results of accessing an IT asset determined to be managed by the organization, and determines the importance of the IT asset based on the presence or absence of each of the attribute information.

2. An IT asset management system that collects and manages information on IT assets to be managed in an organization, a management target specifying unit that collects management information of IT assets accessible via a network, and specifies and records those that should be managed by the organization; The management target identification unit receives input of a domain list related to IT assets, creates a list of IT assets based on each domain in the domain list, uses an LLM (large scale language model) to determine whether each IT asset in the list is subject to management by the organization, and outputs a certainty factor related to the determination when making the determination.If the certainty factor is less than a predetermined threshold, the management target identification unit receives input of the results of a hearing from an asset management officer regarding whether the IT asset is subject to management by the organization and records the input in the list.

3. An IT asset management system that collects and manages information on IT assets to be managed in an organization, a management target specifying unit that collects management information of IT assets accessible via a network, and specifies and records those that should be managed by the organization; The management target identification unit receives input of a domain list related to IT assets, creates a list related to IT assets based on each domain in the domain list, has an LLM (large scale language model) determine whether each IT asset in the list is subject to management by the organization, and in creating the list related to IT assets, has the LLM determine whether there are records that are treated as the same URL based on specified information including the results of accessing each URL and redirect destination, and merges records that are treated as the same URL.

4. An IT asset management system that collects and manages information on IT assets to be managed in an organization, a management target specifying unit that collects management information of IT assets accessible via a network, and specifies and records those that should be managed by the organization; The management target identification unit receives input of a domain list related to IT assets, creates a list of IT assets based on each domain in the domain list, has an LLM (large scale language model) determine whether each IT asset in the list is subject to management by the organization, and in creating the list of IT assets, has the LLM determine whether a URL candidate created based on each domain in the domain list relates to a specified IT asset based on information resulting from accessing the URL candidate, and adds those determined to relate to the specified IT asset to the list.

Citation Information

Patent Citations

  • Counterfeit website detection method and device based on large language model

    CN119341819A

  • Web-based inventory system

    JP6785087B2

  • Multi-layer navigation based security certificate checking

    US20210367928A1

  • Ad-HOC graph processing for security explainability

    WO2024228874A1

  • JPP6785087B