Vulnerability management device, vulnerability management program, and vulnerability management method
The vulnerability management device efficiently identifies and addresses vulnerabilities in network terminals by utilizing stored information and history, enhancing network security through timely countermeasure implementation.
Patent Information
- Application Number
- JP2022006850
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-01-20
- Publication Date
- 2026-01-27
- Estimated Expiration
- 2042-01-20
AI Technical Summary
Existing vulnerability management systems face challenges in efficiently determining the presence of vulnerabilities and necessary countermeasures, particularly for network terminals, which can lead to security threats.
A vulnerability management device and method that includes a port information storage unit, vulnerability inspection unit, and port usage history storage unit to inspect and manage vulnerabilities by referencing stored information and history, enabling efficient determination of necessary countermeasures.
Enables quick and efficient identification of vulnerabilities and implementation of countermeasures, thereby preventing network threats and improving security.
Smart Images

Figure 0007806514000001 
Figure 0007806514000002 
Figure 0007806514000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to a vulnerability management device, a vulnerability management program, and a vulnerability management method, and can be applied to, for example, a management device that remotely monitors terminals on a network and performs vulnerability inspections and the like. [Background technology]
[0002] In computer operating systems (OS) and software (applications), program malfunctions or design errors can cause vulnerability issues, which are defects in information security. If a computer continues to be used with vulnerabilities remaining, there is a risk that it may be used for unauthorized access or infected with a virus.
[0003] Vulnerabilities like this have become one of the major issues in information security for computers connected to networks (such as the Internet).
[0004] As software for detecting vulnerabilities, there are vulnerability testing tools such as those disclosed in Non-Patent Documents 1 to 3. By using a vulnerability testing tool to detect and remove vulnerabilities, the risk of virus infection and the like can be reduced.
[0005] In a TCP / IP (Transmission Control Protocol / Internet Protocol) computer network, there are ports that serve as destinations in the communication protocol with external communication devices. Ports are determined for each protocol. The following port scan is a vulnerability test performed on these ports.
[0006] A port scan sends data specifying a port to a target terminal connected to the network and checks the response. By sending and receiving such data packets to the target port, it is possible to find out the services and OS used by the target terminal. [Prior art documents] [Non-patent literature]
[0007] [Non-Patent Document 1] “Nmap Changelog” [Retrieved December 22, 2021], [Online], INTERNET,<URL: https: / / nmap.org / changelog.html> [Non-patent document 2] “NESSUS” [Retrieved December 22, 2021], [Online], INTERNET,<URL: https: / / www.tenable.com / products / nessus> [Non-patent document 3] “OWASP ZAP(Zed Attack Proxy)” [Searched on December 22, 2021], [Online], INTERNET,<URL: https: / / owasp.org / www-project-zap / > Summary of the Invention [Problem to be solved by the invention]
[0008] After the port scan is conducted, the decision as to whether or not there are vulnerabilities and whether or not to take measures to address them is usually made by experts who are well versed in security measures.
[0009] Even for experts who are well versed in security measures, it is often difficult to determine whether a vulnerability exists or not and whether to take measures to address the vulnerability.
[0010] Therefore, there is a demand for a vulnerability management device, a vulnerability management program, and a vulnerability management method that can efficiently determine whether there are vulnerabilities and whether to take measures against the vulnerabilities, and prevent threats to networks. [Means for solving the problem]
[0011] The first aspect of the present invention is a vulnerability management device that inspects the vulnerability of a port of a terminal on a network, comprising: (1) the terminal 1 of or (2) a port information storage unit that stores port information and information on whether vulnerability countermeasures are necessary for each of a plurality of ports to be inspected; and (3) a vulnerability inspection unit that inspects the terminal for vulnerability based on the information in the port information storage unit. (3) a port usage history storage unit that stores history information of vulnerability inspections and vulnerability countermeasures performed on the inspection target ports of the terminal, and (4) the vulnerability inspection unit determines whether vulnerability countermeasures are necessary based on the information in the port usage history storage unit. It is characterized by:
[0012] A vulnerability management program according to a second aspect of the present invention includes a computer installed in a vulnerability management device that inspects the vulnerability of ports of terminals on a network, the computer including: (1) a vulnerability management program for the terminal; 1 of or (2) a port information storage unit that stores port information and information on whether vulnerability countermeasures are necessary for each of a plurality of ports to be inspected; and (3) a vulnerability inspection unit that inspects the terminal for vulnerability based on the information in the port information storage unit. (3) functioning as a port usage history storage unit that stores history information of vulnerability inspections and vulnerability countermeasures performed on the inspection target ports of the terminal; and (4) the vulnerability inspection unit determines whether vulnerability countermeasures are necessary based on the information in the port usage history storage unit. It is characterized by:
[0013] The third aspect of the present invention is a vulnerability management method used in a vulnerability management device that inspects the vulnerability of ports of terminals on a network, comprising: the vulnerability management device includes a port information storage unit, a vulnerability inspection unit, and a port usage history storage unit; (1) The aforementioned The port information storage unit 1 of Or, for each of multiple ports to be inspected, port information and information on whether vulnerability countermeasures are necessary are stored, and (2) The aforementioned a vulnerability inspection unit that inspects the vulnerability of the terminal based on the information in the port information storage unit; (3) The port usage history storage unit stores history information of vulnerability tests and vulnerability countermeasures performed on the test target ports of the terminal, and (4) the vulnerability inspection unit determines whether vulnerability countermeasures are necessary based on the information in the port usage history storage unit. It is characterized by: [Effects of the Invention]
[0014] According to the present invention, it is possible to efficiently determine whether there is a vulnerability and whether to take measures against the vulnerability, thereby preventing threats to the network. [Brief explanation of the drawings]
[0015] [Figure 1] 1 is a block diagram showing an internal configuration of a vulnerability testing device according to an embodiment; [Figure 2] 1 is an overall configuration diagram showing the overall configuration of a vulnerability testing system according to an embodiment; [Figure 3] FIG. 10 is an explanatory diagram illustrating an example of a port information storage unit according to the embodiment; [Figure 4] FIG. 2 is an explanatory diagram illustrating an example of an examination information storage unit according to the embodiment. [Figure 5] FIG. 10 is an explanatory diagram illustrating an example of a countermeasure management information storage unit according to the embodiment; [Figure 6] FIG. 10 is an explanatory diagram illustrating an example of a used port history storage unit according to the embodiment; [Figure 7] 1 is a flowchart showing the overall operation of vulnerability management in a vulnerability testing system (mainly a vulnerability testing device) according to an embodiment. [Figure 8] 10 is a flowchart showing detailed processing of vulnerability countermeasures in the vulnerability testing device according to the embodiment; [Figure 9] FIG. 10 is an explanatory diagram illustrating an example of a vulnerability inspection result according to the embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0016] (A) Main embodiment Hereinafter, an embodiment of a vulnerability management device, a vulnerability management program, and a vulnerability management method according to the present invention will be described in detail with reference to the drawings.
[0017] (A-1) Configuration of the embodiment (A-1-1) Overall composition FIG. 2 is a diagram showing the overall configuration of a vulnerability testing system according to an embodiment.
[0018] 2, the vulnerability testing system 100 includes a vulnerability testing device 1, a traffic monitoring device 2, a vulnerability result output device 3, and multiple test target terminals 4 (4-1 to 4-n), and each device (terminal) is connected via a network N. The vulnerability management device is composed of, for example, the vulnerability testing device 1, the traffic monitoring device 2, and the vulnerability result output device 3 (or the vulnerability testing device 1 and the vulnerability result output device 3).
[0019] The network N may be any communication network to which each device can be connected, and its type is not limited. In addition, there may be multiple types of networks intervening between each device, and the network N may be composed of multiple types of networks (Ethernet, Internet, etc.).
[0020] The vulnerability testing device 1 tests whether or not a vulnerability is present in the test target terminal 4, and when it detects a test target terminal 4 that has a vulnerability, it has the function of taking action on the test target terminal 4 and the function of issuing a warning to the administrator of the test target terminal 4.
[0021] The traffic monitoring device 2 monitors packets sent and received by the test target terminal 4 on the network N (performing static monitoring), and has the function of notifying the vulnerability testing device 1 of the monitoring contents.
[0022] The vulnerability result output device 3 has a function to output and display the results of the vulnerability test. For example, the vulnerability result output device 3 has a web browser inside the device, and can use the browser to display information (the results of the vulnerability test) sent from the vulnerability test device 1 on a screen, or can send input information to the vulnerability test device 1 by inputting information into the displayed screen.
[0023] The test target terminal 4 is a communication terminal to be tested for vulnerability, which is assigned an IP (Internet Protocol) address and a MAC (Media Access Control) address and can be connected to the network N. For example, the test target terminal 4 is an information processing terminal with a communication function, such as a PC (Personal Computer), a tablet, or a smartphone.
[0024] (A-1-2) Detailed configuration of vulnerability inspection device 1 FIG. 1 is a block diagram showing the internal configuration of a vulnerability testing device according to an embodiment.
[0025] 1, vulnerability testing device 1 includes test control unit 11, vulnerability testing unit 12, vulnerability treatment unit 13, vulnerability countermeasure program 14, vulnerability testing result generation unit 15, port information storage unit 16, test information storage unit 17, countermeasure management information storage unit 18, and used port history storage unit 19. Here, each storage unit is configured, for example, with a general database table.
[0026] The vulnerability testing device 1 may be configured entirely in hardware (for example, using a dedicated semiconductor chip), or may be configured partially or entirely in software.
[0027] The test control unit 11 controls each unit in the vulnerability test device 1 at a predetermined monitoring timing, and has a function of monitoring the vulnerability of the test target terminal 4.
[0028] The vulnerability inspection unit 12 has a function of monitoring the terminal 4 to be inspected by referring to the information in the port information storage unit 16 and the inspection information storage unit 17 for the designated port (or protocol) of the terminal 4 to be inspected.
[0029] The vulnerability treatment unit 13 has the function of referring to the information in the countermeasure management information storage unit 18 for the specified port (or protocol) of the test target terminal 4 and using the vulnerability countermeasure program 14 to take countermeasures on the corresponding port of the test target terminal 4.
[0030] The vulnerability test result generating unit 15 has a function of generating vulnerability test and countermeasure results and transmitting them to the vulnerability result output device 3 .
[0031] The port information storage unit 16 stores information about the inspection and measures to be taken for each port of the terminal 4 to be inspected.
[0032] Fig. 3 is an explanatory diagram showing an example of a port information storage unit according to an embodiment. As shown in Fig. 3, port information storage unit 16 has the following items: "Port Number," "Protocol," "Authorization ID (Identify)," "Inspection ID," and "Countermeasure ID." Note that Fig. 3 is just an example, and various configurations can be applied to the configuration of the port information storage unit.
[0033] A port number is a number used to identify a protocol in TCP / IP communication, and can be any numeric value (integer) between 0 and a maximum of 65535 for each protocol. The numeric value should be a port number managed by the Internet Assigned Numbers Authority (IANA). It is also possible to write a port number that has been independently assigned within the managed network.
[0034] The protocol is the name of the network application protocol. The protocol and the port number are managed as a pair.
[0035] The permission ID is set in advance by the network administrator to determine whether the port number (protocol) is permitted to be used. For example, the permission ID can be written as "OK" if the port number (protocol) is permitted to be used, or "NG" if it is not permitted. Also, if it has not been decided whether to permit or not, it does not need to be written, and in that case it can be treated as permitted.
[0036] The inspection ID specifies a program (and arguments to the program) for inspecting detailed port information for the corresponding protocol.
[0037] The inspection ID (inspection method) can be changed depending on the protocol. For example, if the protocol is SSH (Secure Shell), a password scan is performed. In addition, it is also possible to check whether a port is in use. In any case, there are no particular restrictions on the inspection method (inspection ID) to be written for each protocol.
[0038] There is a possibility that the communication of the test target terminal 4 does not use a general port number assigned to the protocol. If the protocol and port number match a general pair based on the communication characteristics, the protocol is also used to estimate the protocol.
[0039] The countermeasure ID specifies a program (and arguments to the program: information such as port numbers and timeout settings) for implementing detailed countermeasures against vulnerabilities. Countermeasures are implemented according to the protocol. For the test target terminal 4 for which the above-mentioned permission ID is NG, communication may be blocked or communication using the port may be monitored. Other measures may also be taken, such as writing a program to notify the administrator of the test target terminal 4. In any case, the programs (countermeasure IDs) written according to each protocol are not particularly limited.
[0040] Note that multiple inspection IDs and countermeasure IDs may be written, allowing multiple investigations and countermeasures to be carried out. Also, the same inspection ID or countermeasure ID may be written using different protocols. While port numbers are used to distinguish between inspections and countermeasures, other information may be added. For example, by adding a "terminal type" item to the port information storage unit 16 and adding and distinguishing between types such as "server terminal" or "client terminal," "PC" or "terminal," it is possible to permit certain device types but not others.
[0041] The inspection information storage unit 17 stores vulnerability inspection information (detailed inspection information) to be applied to the inspection target terminal 4.
[0042] 4 is an explanatory diagram showing an example of the test information storage unit according to the embodiment. As shown in FIG. 4, the test information storage unit 17 has items of "test ID" and "test program".
[0043] The test ID is an identifier for identifying a test program, and is the same as the test ID described above with reference to FIG.
[0044] The inspection program describes a program (and its arguments) for performing detailed inspection of a port. When an inspection ID in the port information storage unit 16 is specified, the inspection program with the corresponding inspection ID in the vulnerability countermeasure program 14 can be referenced according to the information in the inspection information storage unit 17.
[0045] The countermeasure management information storage unit 18 stores vulnerability countermeasure information to be applied to the test target terminal 4 .
[0046] 5 is an explanatory diagram showing an example of a countermeasure management information storage unit according to the embodiment. As shown in FIG. 5, the countermeasure management information storage unit 18 has items of "countermeasure ID" and "countermeasure program."
[0047] The countermeasure ID is an identifier for identifying the countermeasure program, and is the same as the countermeasure ID described above with reference to FIG.
[0048] The countermeasure program describes the program (and the arguments of the program) for implementing vulnerability countermeasures. When a countermeasure ID in the port information storage unit 16 is specified, the countermeasure program with the corresponding countermeasure ID in the vulnerability countermeasure program 14 can be referenced according to the information in the countermeasure management information storage unit 18.
[0049] For example, a vulnerable port countermeasure program is a program that checks detailed port information, checks for other port-related vulnerabilities such as password scanning, etc. It also includes programs that take countermeasures when it is determined that a port is vulnerable, such as forcibly closing the port or notifying the user of the terminal 4 being tested with an alert.
[0050] The port usage history storage unit 19 stores history information such as inspections and countermeasures taken on each port of the terminal 4 under inspection.
[0051] 6 is an explanatory diagram showing an example of a port usage history storage unit according to an embodiment. As shown in Fig. 6, the port usage history storage unit 19 has the following fields: "timestamp," "IP address," "port number," "status," "detailed information," and "countermeasure information."
[0052] The timestamp indicates the time when the port of each test target terminal 4 was detected by the vulnerability test performed by the vulnerability test device 1.
[0053] The IP address indicates the IP address of the test target terminal 4 that has been tested. Here, any identification information other than the IP address may be used as long as it can identify the test target terminal 4. For example, a MAC address or the like may be used instead of the IP address.
[0054] The port number is the port number detected by the vulnerability check (port scan).
[0055] The state of the port is described in the state field. Here, the port state is indicated by open or closed, but the description method is not limited to this.
[0056] Detailed information is written as information showing the results of a detailed port information inspection. In the example of Figure 6, the results are written to a file and the file name is written. If detailed port information inspection is not performed, there is no need to write this information.
[0057] If a vulnerability countermeasure has been implemented, the results should be described in the countermeasure information. If a vulnerability countermeasure has not been implemented, there is no need to write this information.
[0058] (A-2) Operation of the embodiment Next, the characteristic operations of the vulnerability testing system 100 according to the embodiment will be described in detail with reference to the drawings.
[0059] (A-2-1) Overall operation of vulnerability management FIG. 7 is a flowchart showing the overall operation of vulnerability management in a vulnerability inspection system (mainly a vulnerability inspection device) according to an embodiment.
[0060] The timing for starting this flowchart (vulnerability inspection) is not particularly limited. For example, a user designates the IP address of the inspection target terminal 4 from the vulnerability result output device 3 or the like and starts the vulnerability inspection. Or, the vulnerability inspection device 1 may automatically start the vulnerability inspection, such as starting the process when the specified time arrives.
[0061] <S101: Acquisition of inspection target port number> When starting the vulnerability inspection, first, the vulnerability inspection unit 12 refers to the port information storage unit 16 to acquire the inspection target port. The means for acquiring the inspection target port is not limited to the port information storage unit 16. For example, the user may specify the vulnerability target port.
[0062] In addition, there is a possibility that port numbers other than those described in the port information storage unit 16 are being used. Therefore, if such a case is to be inspected, port numbers other than those described are also targeted for port scanning. For example, by targeting all port numbers up to 65535, used ports can be reliably detected.
[0063] <S102: Port scanning> The vulnerability inspection unit 12 performs a port scan of the inspection target port for the IP address of the inspection target terminal 4 and collects information such as the detected port number and status. Here, for example, the techniques described in Non-Patent Documents 1 and 2 above can be applied to the port scan.
[0064] The vulnerability inspection unit 12 writes the collected information to each item (inspection time, IP address, port, protocol, status) of the used port history storage unit 19. Note that if the protocol is unknown even after scanning, the protocol item does not need to be written.
[0065] <S103: Have all ports been confirmed?> The vulnerability inspection unit 12 checks whether vulnerability countermeasures are necessary for all the detected port numbers. When the vulnerability inspection unit 12 has checked all ports, it proceeds to step S107 described later. On the other hand, when there are unconfirmed ports, it performs the process of step S104.
[0066] <S104: Is the port open?> Based on the information collected in the port scan performed in step S102 above (the information written to the used port history storage unit 19), the vulnerability inspection unit 12 checks the status of the port.
[0067] If the port is in a state where access from the outside is impossible, such as being closed, there is no need for vulnerability countermeasures. Therefore, the vulnerability inspection unit 12 checks whether the status of the detected port (port number) is open. When the status of the port is open, the vulnerability inspection unit 12 proceeds to the next step S105. On the other hand, if the status is other than open, it returns to step S103 above and checks the next unconfirmed port number.
[0068] <S105: Refer to the inspection information storage unit> For the ports with an open status among the detected port numbers, the vulnerability inspection unit 12 refers to the inspection information storage unit 17 to check whether a detailed inspection is necessary. For example, the vulnerability inspection unit 12 searches the inspection information storage unit 17 using the inspection ID related to the detected port number (the inspection ID in the port information storage unit 16) as a key. If the corresponding data (inspection program) exists, it determines that a detailed inspection is necessary. Here, the following explanation is given on the premise that a detailed inspection is necessary. Note that when a detailed inspection is not required, the vulnerability inspection unit 12 may return to step S103 above and check the next unconfirmed port number.
[0069] <S106: Vulnerability countermeasures> The vulnerability inspection unit 12 and the vulnerability handling unit 13 perform vulnerability countermeasures for the ports that require a detailed inspection. The details of this step S106 will be described later using FIG.
[0070] <S107: Display of Vulnerability Inspection Results (Vulnerability Countermeasure Results)> Based on the used port history storage unit 19, the vulnerability inspection result generation unit 15 generates the vulnerability inspection results to be displayed on the vulnerability result output device 3. The vulnerability inspection result generation unit 15 transmits the generated vulnerability inspection results to the vulnerability result output device 3.
[0071] The vulnerability result output device 3 displays the received vulnerability inspection results.
[0072] FIG. 9 is an explanatory diagram showing an example of the vulnerability inspection results according to the embodiment.
[0073] In FIG. 9, the vulnerability inspection result display screen 200 includes a display column 210 that displays the vulnerability inspection time and the IP address of the inspection target terminal 4, a display column 220 that displays each item of the vulnerability inspection results for each port (information such as the detected port, the state such as open, whether it is a countermeasure target, and whether a countermeasure has been taken), a vulnerability countermeasure button 230 that accepts the execution of vulnerability countermeasures from the administrator, a display column 240 that shows the state change of the ports that require vulnerability countermeasures, and a display column 250 that shows the communication history of the terminal. Note that FIG. 9 is an example, and the content to be displayed, the layout, etc. are not limited to this.
[0074] The administrator can know information such as which ports are open, whether the ports that require countermeasures have been countered, and the communication status through the vulnerability inspection result display screen 200. When the administrator determines whether to take countermeasures, if it is indicated that countermeasures are required, the administrator can check the countermeasure method and take actions. A link for automatic execution can be provided in the countermeasure method, and clicking on it can provide support for countermeasures. It is also possible not to let the administrator determine whether to take countermeasures and automatically execute (such as closing the port).
[0075] (A-2-2) Details of Step S106 FIG. 8 is a flowchart showing the detailed processing of vulnerability countermeasures in the vulnerability inspection device according to the embodiment.
[0076] <S106-1: Reference to the Used Port History> The vulnerability inspection unit 12 refers to the used port history storage unit 19 for the corresponding port and investigates the time when the state of the port changed.
[0077] For example, assume that for the inspection target terminal 4 with the IP address "11.111.1.10", the currently detected port numbers are "22", "23", and "80".
[0078] And in FIG. 6, assuming that the used port history up to the previous time is described, the vulnerability inspection time for the previous IP address "11.111.1.10" is "2021.XX.XX XX:XX:XX". Then, it can be seen that the port numbers "21" and "22" have changed this time.
[0079] Note that although the countermeasure IDs are described in the port information storage unit 16 for the port numbers "23" and "80", since these are not the ports that have changed this time (not newly opened ports), the processing after S106-2 is not applicable (i.e., return to step S103).
[0080] <S106-2: Confirmation of Whether the Port is Newly Opened> The vulnerability inspection unit 12 checks whether the corresponding port is a port that was opened after the previous inspection. For example, in the example of the current vulnerability inspection for the IP address "11.111.1.10" shown in S106-1 above, the port "22" is a newly opened port. If the corresponding port is a newly opened port, the vulnerability inspection unit 12 proceeds to the next step S106-3.
[0081] On the other hand, if the corresponding port is not a newly opened port, the vulnerability inspection unit 12 returns to step S103 without performing vulnerability countermeasures. This ensures that once vulnerability countermeasures have been taken, they are not performed again, thus avoiding overloading the terminal. However, it is also possible to force the execution of the processing in step S106-3. For example, by referring to the countermeasure information in the used port history storage unit 19, if the vulnerability countermeasures have not been performed (information such as the countermeasure ID is described in the countermeasure information) hand If not (in the case of not existing), the process of step S106-3 is forcibly performed.
[0082] For example, in the example of the current vulnerability check where the IP address shown in S106-1 above is "11.111.1.10", the port "21" is a port that has been closed and not detected (not a newly opened port). Therefore, in this case, the vulnerability check unit 12 returns to step S103.
[0083] <S106-3: Detailed Inspection> The vulnerability check unit 12 refers to the port information storage unit 16 for the corresponding port and obtains the inspection ID for the port number. Subsequently, the vulnerability check unit 12 refers to the inspection information storage unit 17 using the obtained inspection ID as a key and obtains the program name for the inspection ID. Then, the vulnerability check unit 12 executes the corresponding program (inspection program) within the vulnerability countermeasure program 14.
[0084] The inspection program can estimate the protocol and understand the usage status of the port. Also, it may analyze the communication status and packets using the port measured by the traffic monitoring device 2.
[0085] For example, in the case of the port number 22 (newly opened port) shown in step S106-2 above, the inspection ID "2" of port number 22 in the port information storage unit 16 of FIG. 3 is extracted, and the inspection program bbb of inspection ID 2 is extracted from the inspection information storage unit 17 of FIG. 4, and this program will be executed.
[0086] <S106-4: Determination of Whether Port and Protocol Match> The vulnerability check unit 12 determines whether the port number and the estimated protocol match based on the execution result of step S106-3 above. Here, for example, for port numbers up to 1023, which are called well-known ports and are particularly famous and frequently used port numbers (standard protocols), the correspondence between the port number and the protocol may be trusted and considered to match.
[0087] If the correspondence between the port and the estimated protocol matches, the vulnerability inspection unit 12 proceeds to step S106-6 described later. On the other hand, if the correspondence between the port and the protocol does not match, the process of the next step S106-5 is performed.
[0088] <S106-5: Investigation of the necessity of vulnerability countermeasures> The vulnerability inspection unit 12 determines that vulnerability countermeasures are necessary for ports whose permitted ID (the permitted ID in the port information storage unit 16) of the corresponding port is NG. For example, for port number 22, since the permitted ID is NG, vulnerability countermeasures are necessary.
[0089] Also, in step S106-4 described above, it is investigated whether vulnerability countermeasures are necessary for ports where the port number and the estimated protocol do not match. For example, the estimated protocol is determined based on whether vulnerability countermeasures are necessary or the like.
[0090] <S106-5: Judgment of the necessity of countermeasures> If the vulnerability inspection unit 12 determines that the protocol does not require vulnerability countermeasures through the process of step S106-5 described above, it returns to step S103.
[0091] On the other hand, if the vulnerability inspection unit 12 determines that the protocol requires vulnerability countermeasures, it performs the next S106-7 process. For example, since port number 22 requires vulnerability countermeasures, the process of S106-7 is performed.
[0092] <S106-7: Vulnerability countermeasures> The vulnerability handling unit 13 performs vulnerability countermeasures for ports that require vulnerability countermeasures. Vulnerability countermeasures such as forcibly closing the port specified in the countermeasure management information storage unit 18 and notifying the user of the inspection target terminal 4 with an alert are performed.
[0093] For example, for port number 22, the countermeasure ID 101 is specified from the port information storage unit 16 in FIG. 3, and the countermeasure program a111 of 101 in the countermeasure management information storage unit 18 in FIG. 5 is specified and executed.
[0094] (A-3) Effects of the embodiment According to the present invention, the following effects are achieved.
[0095] The vulnerability testing device 1 investigates the open ports of the test target terminal 4, and then checks the protocol (application) used by the port, usage information, status, and whether or not there is a vulnerability, and then outputs and displays the results such as vulnerability countermeasures and port usage history, thereby achieving the effect of enabling quick decision-making on how to respond when a vulnerability is found.
[0096] In addition, by specifying the correspondence between ports and countermeasures in advance and automatically taking countermeasures if the relevant port is open, threats to the network can be prevented quickly.
[0097] Furthermore, by using detailed port inspection programs and inferring protocols from communication content, it becomes easier to take measures against vulnerabilities in proprietary protocols and protocols that do not use standard port numbers.
[0098] (B) Other embodiments Although various modified embodiments have been mentioned in the above-described embodiment, the present invention can also be applied to the following modified embodiments.
[0099] (B-1) In the example of Figure 2 described above, the vulnerability testing device 1, traffic monitoring device 2, and vulnerability result output device 3 are shown as separate devices, but these three devices may also be realized as a single device within the same hardware.
[0100] (B-2) The data types handled in the device information, determination information, and vulnerability testing information may include content other than that described in the above-described embodiments. Also, some of the above-described information may be omitted. [Explanation of symbols]
[0101] 1...Vulnerability testing device, 2...Traffic monitoring device, 3...Vulnerability result output device, 4...Test target terminal, 11...Test control unit, 12...Vulnerability testing unit, 13...Vulnerability treatment unit, 14...Vulnerability countermeasure program, 15...Vulnerability testing result generation unit, 16...Port information storage unit, 17...Test information storage unit, 18...Countermeasure management information storage unit, 19...Port usage history storage unit, 100...Vulnerability testing system, 200...Vulnerability testing result display screen, 210, 220, 240, 250...Display column, 230...Vulnerability countermeasure button, N...Network
Claims
1. A vulnerability management device that inspects the vulnerabilities of ports of terminals on a network, a port information storage unit that stores port information and vulnerability countermeasure necessity information for each of one or more inspection target ports of the terminal; a vulnerability inspection unit that inspects the vulnerability of the terminal based on the information in the port information storage unit; a port usage history storage unit for storing history information of vulnerability inspections and vulnerability countermeasures performed on the inspection target ports of the terminal, The vulnerability management device is characterized in that the vulnerability inspection unit determines whether or not vulnerability countermeasures are necessary based on the information in the port usage history storage unit.
2. The vulnerability management device according to claim 1 , wherein the vulnerability inspection unit determines that a vulnerability countermeasure should be taken if the port to be inspected is open.
3. The vulnerability management device according to claim 1 or 2, characterized in that the vulnerability inspection unit refers to pair information between a port number and a standard protocol, and determines whether a protocol matches a standard protocol or is an unknown protocol, thereby determining whether vulnerability countermeasures are necessary.
4. 4. The vulnerability management device according to claim 1, wherein the vulnerability inspection unit determines whether or not vulnerability countermeasures are required, taking into account device information of the terminal.
5. 5. The vulnerability management device according to claim 1, wherein the vulnerability inspection unit determines whether or not a vulnerability countermeasure is required by taking into account static monitoring information of network traffic.
6. 6. The vulnerability management device according to claim 1, further comprising a vulnerability treatment unit that implements predetermined vulnerability countermeasures for ports that require vulnerability countermeasures as inspection targets.
7. The vulnerability management device according to claim 6 , further comprising a vulnerability result output unit that outputs a vulnerability inspection result including the inspection result of the vulnerability inspection unit.
8. The vulnerability management device according to claim 7 , wherein the vulnerability inspection result includes details of the vulnerability countermeasures taken by the vulnerability treatment unit.
9. A computer installed in a vulnerability management device that inspects the vulnerabilities of ports on terminals on a network is a port information storage unit that stores port information and vulnerability countermeasure necessity information for each of one or more inspection target ports of the terminal; a vulnerability inspection unit that inspects the vulnerability of the terminal based on the information in the port information storage unit; functioning as a port usage history storage unit for storing history information of vulnerability inspections and vulnerability countermeasures performed on the inspection target ports of the terminal; The vulnerability inspection unit determines whether or not vulnerability countermeasures are necessary based on the information in the port usage history storage unit. A vulnerability management program characterized by:
10. A vulnerability management method used in a vulnerability management device that inspects the vulnerability of ports of terminals on a network, comprising: the vulnerability management device includes a port information storage unit, a vulnerability inspection unit, and a port usage history storage unit; the port information storage unit stores port information and vulnerability countermeasure necessity information for each of one or more inspection target ports of the terminal, the vulnerability inspection unit inspects the vulnerability of the terminal based on the information in the port information storage unit, the port usage history storage unit stores history information of vulnerability tests and vulnerability countermeasures performed on the test target ports of the terminal; The vulnerability inspection unit determines whether or not vulnerability countermeasures are necessary based on the information in the port usage history storage unit. A vulnerability management method comprising:
Citation Information
Patent Citations
Network relay device and method for inspecting security
JP2005025269A
Security management system, relay device, and program
JP2007272396A
Network quarantine system
JP2009169781A
Vulnerability management device, vulnerability management method and program
JP2020004006A
Method and system for identifying vulnerability levels in devices operated on a given network
US20220060500A1