Support system, method, and program
The support system addresses the inefficiencies in cloud service design by integrating security monitoring into the infrastructure, reducing costs and enhancing security through early alignment of security requirements with cloud infrastructure design.
Patent Information
- Application Number
- JP2021083584
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-05-18
- Publication Date
- 2026-01-21
- Estimated Expiration
- 2041-05-18
AI Technical Summary
Existing cloud service designs separately consider service design, infrastructure construction, application development, and security monitoring, leading to increased costs and inefficiencies when security monitoring functions are introduced after the design or development stage.
A support system that extracts security requirements and cloud infrastructure functions, designs a cloud infrastructure to meet these requirements, and introduces security monitoring functions into the cloud infrastructure using monitored data, thereby integrating security monitoring from the outset.
Enables the construction of a cloud service with integrated security monitoring at a lower cost by aligning security requirements with infrastructure design, reducing the need for costly modifications and enhancing security against evolving cyber threats.
Smart Images

Figure 0007803045000001 
Figure 0007803045000002 
Figure 0007803045000003
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to an assistance system and the like. [Background technology]
[0002] In recent years, cloud services have become popular due to their ability to reduce the cost of equipment such as servers and to provide flexible service usage. However, because cloud services can be accessed from anywhere via the Internet, they are at risk of cyberattacks. Therefore, companies that provide or use cloud services must consider countermeasures against cyberattacks, which are becoming more sophisticated every day.
[0003] Specifically, companies that use cloud services may use services to monitor the security of the entire system after the start of operation and services to deal with security incidents as security measures for the cloud services.
[0004] As a technology related to the present disclosure, Patent Document 1 discloses a system for evaluating the security of a system that combines multiple and heterogeneous cloud services. In Patent Document 1, security is evaluated at the system design stage, since evaluating security after building the system would require rework. In particular, the security of the entire system is evaluated at the stage of performing cloud-based design according to the required specifications. [Prior art documents] [Patent documents]
[0005] [Patent Document 1] Japanese Patent Application Laid-Open No. 2015-103212 Summary of the Invention [Problem to be solved by the invention]
[0006] Generally, when building a cloud service, the design of the service, the construction of the cloud infrastructure, the development of applications, and the construction of a monitoring function for the entire service are all considered separately. Specifically, the service to be provided on the cloud is designed first, followed by the construction of the cloud infrastructure, the development of applications, and the construction of a security monitoring function for the entire service, in that order.
[0007] If a procedure is adopted in which security monitoring functions for the entire service are built later, it would take time and effort to understand and modify the service design, which could result in significant costs.
[0008] Patent Document 1 does not disclose the design or development of a function for monitoring the entire system after operation has begun.
[0009] The present disclosure aims to provide a support system etc. that reduces the cost of introducing a security monitoring function compared to when the security monitoring function is introduced for the entire system after the design or development of the service. [Means for solving the problem]
[0010] The support system according to the present disclosure comprises an extraction means for extracting security requirements to be complied with and the functions of the cloud infrastructure provided by the cloud service provider, an infrastructure design instruction means for instructing the design of a cloud infrastructure that adjusts the extracted security requirements and the functions of the cloud infrastructure, and an introduction instruction means for introducing security monitoring functions based on monitored data collected from monitored devices into the cloud infrastructure.
[0011] The method disclosed herein extracts the security requirements to be complied with and the functions of the cloud infrastructure provided by the cloud service provider, instructs the design of a cloud infrastructure that adjusts the extracted security requirements and the functions of the cloud infrastructure, and introduces security monitoring functions into the cloud infrastructure based on monitored data collected from monitored devices.
[0012] The program disclosed herein causes a computer to execute the following processes: extracting security requirements to be complied with and the functions of the cloud infrastructure provided by a cloud service provider; instructing the design of a cloud infrastructure that adjusts the extracted security requirements and the functions of the cloud infrastructure; and introducing security monitoring functions into the cloud infrastructure based on monitored data collected from monitored devices. [Effects of the Invention]
[0013] According to the present disclosure, a cloud service with security monitoring functionality can be built at low cost. [Brief explanation of the drawings]
[0014] [Figure 1] 1 is a block diagram showing an example of the configuration of a support system 100. FIG. [Figure 2] FIG. 1 is a schematic diagram illustrating an example of the system configuration of an entire cloud service system. [Figure 3] 10 is a flowchart showing an example of the operation of the support system 100. [Figure 4] FIG. 10 is a block diagram showing the configuration of a support system 100 according to a modified example. [Figure 5] 10 is a flowchart showing an example of the operation of the support system 100 according to a modified example. [Figure 6] FIG. 5 is a block diagram showing an example of the hardware configuration of a computer 500. DETAILED DESCRIPTION OF THE INVENTION
[0015] An embodiment of the present disclosure will be described using an example in which a system development company builds a cloud service at the request of a client company that wishes to use the cloud service. The system development company builds a cloud infrastructure using the service functions of the cloud infrastructure provided by the cloud service provider. The system development company designs and develops the cloud service desired by the client company on the built cloud infrastructure.
[0016] The cloud developed by the system development company may be any of a private cloud, a community cloud, a public cloud, and a hybrid cloud that combines these.
[0017] Note that building cloud infrastructure and designing and developing cloud services are not limited to system development companies. For example, companies that use cloud services may build the infrastructure and design and develop the services.
[0018] A support system 100 according to an embodiment supports the construction of a cloud infrastructure that serves as a foundation for designing cloud services. FIG. 1 is a block diagram showing an example configuration of the support system 100 according to an embodiment. The support system 100 includes an extraction unit 101, a platform design instruction unit 102, and an implementation instruction unit 103. The extraction unit 101, the platform design instruction unit 102, and the implementation instruction unit 103 are embodiments of an extraction means, a platform design instruction means, and an implementation instruction means, respectively.
[0019] Figure 2 is a schematic diagram showing an example of the overall system configuration of a cloud service system. The system includes at least one of a cloud server and an on-premise server used by the ordering company. A support system 100 supports the construction of a cloud infrastructure via a communication network.
[0020] The extraction unit 101 extracts security standard items that a cloud service must comply with.
[0021] The security requirements that cloud services must comply with may differ depending on the company ordering the cloud service. Examples of security requirements include various security standards, such as national standards (including Japan Industrial Standards (JIS Q 27000)) and international standards. Furthermore, cloud services have unique functions that differ from one cloud service provider to another, so security measures that correspond to these functions may be required.
[0022] Therefore, the extraction unit 101 may extract security standard items by referring to a list of security standard items used within an organization such as an ordering company. Alternatively, the extraction unit 101 may extract security standard items by referring to a list created with reference to security standards that are commonly referenced in a specific industry. For example, the extraction unit 101 may refer to a list created based on the "Common Standards for Information Security Measures for Government Agencies, etc." published by a Japanese government agency.
[0023] The extraction unit 101 further extracts service functions of the cloud infrastructure provided by the cloud service provider. The extraction unit 101 may extract the service functions based on input from a development staff member of the system development company. The extraction unit 101 may also extract the service functions by referring to a list of service functions to be extracted held by the ordering company or the system development company.
[0024] Before extraction by the extraction unit 101, the person in charge at the system development company may perform a predetermined operation. For example, the person in charge at the system development company may confirm with the ordering company which cloud service provider will provide the cloud service that the ordering company is considering using. The person in charge may also confirm whether the ordering company will use an on-premise server. Depending on the confirmed items, the person in charge may select a list of security requirements to be referred to by the extraction unit 101.
[0025] Furthermore, the person in charge may generate a list of security requirements based on the results of investigating and examining the security standards that need to be complied with. The extraction unit 101 may extract security standard items by referring to the list of security requirements created by the person in charge and a database maintained by the system development company that shows the correspondence between security requirements and security standard items. The person in charge may also create data of a list of security standard items that can be referenced by the extraction unit 101. Here, if a list of security standards that the person in charge wants to comply with has already been created previously, the list can be reused.
[0026] Similar to the list of security requirements, the person in charge may generate a list of service functions of the cloud infrastructure. The person in charge may select the list of service functions to be referred to by the extraction unit 101. If a list of service functions to be extracted has already been created, the list can be reused.
[0027] The platform design instruction unit 102 instructs the design of a cloud platform that adjusts the security requirements extracted by the extraction unit 101 and the service functions of the cloud platform. The platform design instruction unit 102 may also instruct other elements, such as other systems, programs, or tools, so that the service functions conform to the security requirements. The platform design instruction unit 102 may also instruct a person in charge at the development company.
[0028] Specifically, for example, the platform design instruction unit 102 instructs other elements or personnel to map cloud platform service functions that meet security requirements. Function mapping may include installing tools, enabling various system settings, or instructing the setting of various parameters. The platform design instruction unit 102 may display the mapping results on any display.
[0029] The person in charge may build service functions onto the platform or install a program that realizes the functions, following instructions from the platform design instruction unit 102. Alternatively, the platform design instruction unit 102 may instruct other elements to design the cloud platform based on input from the person in charge at the system development company.
[0030] For security requirements that cannot be mapped by the platform design instruction unit 102, for example, after the platform design instruction unit 102 has finished mapping feasible security requirements, the person in charge at the system development company considers using other products. Security requirements that cannot be mapped are security requirements that cannot be met by the functions provided by the cloud service provider. Specifically, for example, the cloud service provider does not provide a function that can meet the security requirement of "securing the server so that it cannot be easily moved." Therefore, the person in charge at the system development company uses other products, such as security wire to secure the server.
[0031] The installation instruction unit 103 installs the security monitoring function of the cloud service system into the cloud infrastructure designed by the infrastructure design instruction unit 102. The security monitoring function is a function that collects, analyzes, or preserves monitoring target data from monitored devices. The installation instruction unit 103 may also instruct other elements, such as other systems, programs, or tools, to install the security monitoring function. Installing the security monitoring function includes, for example, a person in charge building the function into the infrastructure or installing a program that realizes the function.
[0032] Figure 2 shows an example of a security monitoring function that is added to the cloud infrastructure functions. The monitored devices are, for example, cloud servers or servers in an on-premise environment used by the ordering company. The security monitoring function collects logs generated by the monitored devices as monitored data. The security monitoring function may also collect logs from firewalls as monitored data. As shown in Figure 2, the logs are collected, for example, at a monitoring center.
[0033] The security monitoring function may be a function that continuously monitors the cloud service while it is running. Specifically, the security monitoring function may be a service function such as a managed security service (MSS) function that performs security monitoring, analysis, and response. In this service function, the monitored data is monitored and analyzed by monitoring equipment or by humans at a monitoring center, for example, to monitor for abnormalities. Furthermore, the monitoring center takes into account countermeasures against cyber attacks (such as vulnerability information) that are becoming more sophisticated every day.
[0034] Alternatively, the security monitoring function may be a function that monitors when an incident occurs. Specifically, for example, it is a service function that performs initial incident response when an abnormality such as a security incident occurs. In this service function, the monitored data may be preserved at a monitoring center when an abnormality occurs. For example, at the monitoring center, a minimum number of logs are preserved to quickly identify the cause and identify intrusion routes and unauthorized behavior, and a simple analysis is performed. The type and amount of logs to be preserved can be selected as appropriate.
[0035] The introduction instruction unit 103 may instruct the introduction of either or both of a function for analyzing monitoring target data and a function for preserving monitoring target data as a security monitoring function into the cloud infrastructure.
[0036] The introduction instruction unit 103 may select the necessary equipment and data to introduce the security monitoring function. The selection of the necessary equipment and data for the security monitoring function is included in the design of the security monitoring function. The design of the security monitoring function may be performed before the extraction unit 101 extracts the security criteria items.
[0037] The introduction instruction unit 103 may select the necessary devices and data based on input from a person in charge at the system development company. The introduction instruction unit 103 selects, for example, devices required for introducing the security monitoring function from a system configured with a cloud platform and an on-premise server. Alternatively, the introduction instruction unit 103 selects, for example, monitoring target data or logs that need to be collected from the entire system to implement the security monitoring function. When operation of the cloud service begins, the security monitoring function collects the selected monitoring target data or logs from the selected monitoring target devices.
[0038] Before the introduction of the function by the introduction instruction unit 103, a person in charge at the system development company may perform a predetermined operation to realize the security monitoring function. For example, the person in charge may establish a service system at the monitoring center. The person in charge may also establish devices, functions, and systems required for the service at the monitoring center. The introduction instruction unit 103 introduces the service system and the service monitoring function using the environment established by the person in charge into the cloud infrastructure.
[0039] The following describes the operation of the support system 100. Figure 3 is a flowchart showing an example of the operation of the support system 100.
[0040] First, the extraction unit 101 extracts security requirements to be complied with and functions of the cloud infrastructure provided by the cloud service provider (step S1).
[0041] The infrastructure design instruction unit 102 instructs the design of a cloud infrastructure that adjusts the extracted security requirements and the functions of the cloud infrastructure (step S2).
[0042] The introduction instruction unit 103 introduces a security monitoring function based on the monitoring target data collected from the monitoring target devices into the cloud infrastructure (step S3).
[0043] Through the above processing, a cloud infrastructure is constructed that serves as a foundation for designing a cloud service, that satisfies the security requirements extracted by the extraction unit 101, and that has a security monitoring function implemented. After step S3, the cloud service is designed and implemented, and then operation of the cloud service begins. After operation of the service begins, monitored data is collected from the monitored devices, and analysis of the monitored data is performed.
[0044] Note that the security monitoring function may be designed before step S3 and before or after step S1.
[0045] Steps S1 to S3 may also be performed as needed even after the service has started operating, allowing the cloud infrastructure, security monitoring function, and cloud service to be updated as needed even after the service has started operating.
[0046] According to this embodiment, the cost of introducing a security monitoring function can be reduced compared to introducing a security monitoring function for the entire system after the design or development of the service. This is because the introduction instruction unit 103 introduces the security monitoring function into a cloud infrastructure in which security requirements and cloud infrastructure functions have been adjusted. Also, this is because a cloud service can be designed on a cloud infrastructure in which a security monitoring function has been introduced.
[0047] Cyberattacks are becoming more sophisticated every year, and the importance of incident response is increasing, so the implementation of security monitoring functions is required as a security measure. However, these functions are not considered in the early stages of cloud service design, and are often considered only in the later stages of cloud service design, when security measures are considered, or after a cyberattack has occurred.
[0048] Implementing security functions after designing a cloud infrastructure and a cloud service can be costly. It can also be costly to address any issues that arise when modifying the design of a cloud service to incorporate security monitoring functions. According to this embodiment, as described above, security monitoring functions are applied to the cloud infrastructure, making it possible to build cloud services with security monitoring functions at low cost.
[0049] Furthermore, according to this embodiment, it is possible to design and build a cloud infrastructure that complies with security standards, because the extraction unit 101 extracts security requirements that should be complied with, and the infrastructure design instruction unit 102 instructs the design of a cloud infrastructure that adjusts the extracted security requirements and the service functions of the cloud infrastructure.
[0050] If security standards are not met, damage from cyber attacks may occur after the service begins operation. Therefore, it is preferable to avoid designing and building cloud services that do not comply with security standards. However, cloud service configurations become complex when combined with on-premise servers, which can lead to inadequate security measures.
[0051] According to this embodiment, as described above, security requirements are taken into consideration, so that a secure cloud infrastructure that complies with security standards can be designed and constructed.
[0052] (Variation) In a modified example, the support system 100 according to the above embodiment may also support the design of cloud services on a cloud platform. FIG. 4 is a block diagram showing the configuration of the support system 100 according to the modified example. In the modified example, the support system 100 further includes a service design instruction unit 104. The service design instruction unit 104 is an embodiment of a service design instruction means.
[0053] The service design instruction unit 104 instructs the design of a cloud service on a cloud platform that has security monitoring functions installed. Specifically, the service design instruction unit 104 instructs the design of a service that is tailored to the settings of the monitored data and the security monitoring functions, for example. The service design instruction unit 104 may instruct the design of a service for other elements, or may instruct a person in charge at a development company to design a service.
[0054] When building a monitoring function for the entire service after completing the service design, cloud infrastructure construction, and application development, the development company's personnel will design the service using a design method that is easy to implement or that they are familiar with. As a result, when building the monitoring function, it may be necessary to modify the service design. In this embodiment, the development company's personnel will design the service to match the cloud infrastructure with the security monitoring function built in. This reduces the amount of work required to build the monitoring function, and reduces the cost of cloud service design.
[0055] 5 is a flowchart showing an example of the operation of the support system 100 according to the modified example. The operations from step S1 to step S3 are the same as those in the flowchart of FIG. 3, and therefore will not be described again. After step S3, the service design instruction unit 104 instructs the design of a cloud service on a cloud platform that has security monitoring functions installed (step S4). After step S4, the cloud service is implemented, and then operation of the cloud service begins.
[0056] According to this modification, a cloud service that takes into account the security monitoring function for the entire service can be designed at low cost because the service design instruction unit 104 instructs the cloud service to be designed on a cloud platform that has the security monitoring function installed.
[0057] [Hardware configuration] In the above-described embodiment, each component of the support system 100 is represented by a functional block. Some or all of the components of each device may be realized by any combination of a computer 500 and a program.
[0058] Fig. 6 is a block diagram showing an example of the hardware configuration of a computer 500. Referring to Fig. 6, the computer 500 includes, for example, a CPU (Central Processing Unit) 501, a ROM (Read Only Memory) 502, a RAM (Random Access Memory) 503, a program 504, a storage device 505, a drive device 507, a communication interface 508, an input device 509, an input / output interface 511, and a bus 512.
[0059] The program 504 includes instructions for realizing each function of each device. The program 504 is stored in advance in the ROM 502, RAM 503, or storage device 505. The CPU 501 executes the instructions included in the program 504 to realize each function of each device. For example, the CPU 501 of the assistance system 100 executes the instructions included in the program 504 to realize the functions of the assistance system 100. The RAM 503 may also store data to be processed in each function of each device. For example, the RAM 503 of the computer 500 may store a list of security requirements for the assistance system 100 and a list of cloud-based service functions.
[0060] The drive device 507 reads and writes data from and to the recording medium 506. The communication interface 508 provides an interface with a communication network. The input device 509 is, for example, a mouse or keyboard, and receives information input from a person in charge of the system development company, etc. The output device 510 is, for example, a display, and outputs (displays) information to the person in charge, etc. The input / output interface 511 provides an interface with peripheral devices. The bus 512 connects these hardware components. The program 504 may be supplied to the CPU 501 via a communication network, or may be stored in advance on the recording medium 506, read by the drive device 507, and supplied to the CPU 501.
[0061] It should be noted that the hardware configuration shown in FIG. 6 is an example, and other components may be added, or some components may not be included.
[0062] There are various variations in the method of realizing each device. For example, each device may be realized by any combination of a different computer and a program for each component. Furthermore, multiple components of each device may be realized by any combination of a single computer and a program.
[0063] Furthermore, some or all of the components of each device may be realized by general-purpose or dedicated circuits including a processor, etc., or a combination of these. These circuits may be configured by a single chip, or may be configured by multiple chips connected via a bus. Some or all of the components of each device may be realized by a combination of the above-mentioned circuits, etc., and a program.
[0064] Furthermore, when some or all of the components of each device are realized by a plurality of computers, circuits, etc., the plurality of computers, circuits, etc. may be centrally located or distributed.
[0065] Furthermore, at least a part of the assistance system 100 may be provided in a software as a service (SaaS) format. That is, at least a part of the functions for realizing the assistance system 100 may be executed by software executed via a network.
[0066] Although the present disclosure has been described above with reference to the embodiments, the present disclosure is not limited to the above embodiments. Various modifications that can be understood by those skilled in the art can be made to the configuration and details of the present disclosure within the scope of the present disclosure. [Explanation of symbols]
[0067] 100 Support System 101 Extraction part 102 Foundation Design Instruction Department 103 Introduction instruction section 104 Service Design Instruction Department 500 computers
Claims
1. An extraction means for extracting security requirements that a system realizing a cloud service to be designed should comply with and functions of a cloud infrastructure provided by a cloud service provider; a platform design instruction means for instructing one of other elements including other systems, programs, or tools, and a person in charge of a development company to map the functions of the cloud platform, including installing tools, enabling the settings of the system, and setting parameters, thereby instructing the other elements or the person in charge to design a cloud platform that adjusts the extracted security requirements and the functions of the cloud platform, and further displaying the results of the mapping; an introduction instruction means for introducing a security monitoring function that monitors the system based on monitoring target data collected from monitoring target devices of the system, including a cloud server and an on-premise server, into the cloud infrastructure in which the security requirements and functions have been adjusted; and a service design instruction means for instructing the other elements or the person in charge to design the cloud service on the cloud platform on which the security monitoring function is installed. Support system.
2. the introduction instruction means selects the monitoring target device and the monitoring target data to be collected from the monitoring target device; The assistance system according to claim 1 .
3. The monitored data is data that is continuously monitored while the cloud service is running in order to monitor for abnormalities. The assistance system according to claim 1 or 2.
4. The monitored data is data that is preserved when an abnormality occurs and is used for analysis when an abnormality occurs. The assistance system according to any one of claims 1 to 3.
5. The computer Extract the security requirements that the system implementing the cloud service to be designed must comply with and the cloud infrastructure functions provided by the cloud service provider, Instructing either another system, program, or other element including a tool or a person in charge of the development company to map the functions of the cloud infrastructure, including installing a tool, enabling the settings of the system, and setting parameters, to design a cloud infrastructure that adjusts the extracted security requirements and the functions of the cloud infrastructure to the other element or the person in charge, and further displaying the results of the mapping; A security monitoring function that monitors the system based on monitoring target data collected from monitoring target devices of the system, including a cloud server and an on-premise server, is introduced into the cloud infrastructure whose security requirements and functions have been adjusted; and instructing the other element or the person in charge to design the cloud service on the cloud infrastructure in which the security monitoring function is installed.
6. A process of extracting security requirements that a system realizing a cloud service to be designed must comply with and cloud infrastructure functions provided by a cloud service provider; a process of instructing either another system, program, or other element including a tool or a person in charge of a development company to map the functions of the cloud infrastructure, including installing a tool, enabling the settings of the system, and setting parameters, thereby instructing the other element or the person in charge to design a cloud infrastructure that adjusts the extracted security requirements and the functions of the cloud infrastructure, and further displaying the results of the mapping; A process of introducing a security monitoring function that monitors the system based on monitoring target data collected from monitoring target devices of the system, including a cloud server and an on-premise server, into the cloud infrastructure in which the security requirements and functions have been adjusted; a process of instructing the other element or the person in charge to design the cloud service on the cloud platform on which the security monitoring function is installed; A program that causes a computer to execute the following.
Citation Information
Patent Citations
Information processing terminal and history information saving method
JP2004310514A
System and method for supervising state of terminal
JP2004355450A
Management device, management method, and program
JP2011192187A
Information processing equipment, information processing system and information processing method
JP2013191042A
Security evaluation system and security evaluation method
JP2015103212A