Information processing system, information processing method and program
The information processing system addresses the challenge of managing system risks by detecting and assigning vulnerability information across multiple systems, facilitating centralized risk management and reducing redundant efforts.
Patent Information
- Application Number
- JP2025170631
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2025-10-09
- Publication Date
- 2026-02-04
- Estimated Expiration
- 2045-10-09
AI Technical Summary
There is a demand for technology that can easily manage system risks, particularly in detecting and managing vulnerabilities across multiple systems in a system group.
An information processing system that includes a vulnerability detection unit to identify vulnerabilities in a system group, an information reception unit to input management information for detected vulnerabilities, and an information assignment unit to assign this information to vulnerabilities of the same type across other systems in the group, using a processor to execute these steps.
This system enables easy and centralized management of system risks by detecting and assigning vulnerability information across multiple systems, enhancing security and reducing the need for individual management of similar vulnerabilities.
Smart Images

Figure 0007811301000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to an information processing system, an information processing method, and a program. [Background technology]
[0002] Patent Document 1 discloses a technology for diagnosing risks in a system. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2015-138509 Summary of the Invention [Problem to be solved by the invention]
[0004] There is a demand for technology that can easily manage system risks.
[0005] In view of the above circumstances, the present invention provides an information processing system and the like that can easily manage system risks. [Means for solving the problem]
[0006] According to one aspect of the present invention, there is provided an information processing system comprising at least one processor, the processor being configured to execute each of the following steps by reading a program, wherein in a vulnerability detection step, vulnerabilities of a plurality of detection target systems included in a system group are detected; in an information reception step, input of management information for vulnerabilities detected in an input target system among the plurality of detection target systems included in the system group is accepted; and in an information assignment step, the accepted input management information is assigned to vulnerabilities for which input of the management information of the input target system is accepted and to vulnerabilities of the same type as the vulnerability in detection target systems other than the input target system included in the system group.
[0007] According to this embodiment, risks to the system can be easily managed. [Brief explanation of the drawings]
[0008] [Figure 1] 1 is a configuration diagram illustrating an information processing system 1. FIG. [Figure 2] 1 is a block diagram showing a hardware configuration of an information processing device 10. FIG. [Figure 3] FIG. 2 is a block diagram showing the hardware configuration of a user terminal 20. [Figure 4] 1 is a block diagram showing functions realized by an information processing device 10 (controller 11) and a user terminal 20 (controller 21). [Figure 5] 10 is a diagram showing an example of a project editing screen PD displayed on the user terminal 20. FIG. [Figure 6] 10 is a diagram showing an example of a project list screen LD displayed on the user terminal 20. FIG. [Figure 7] FIG. 10 is a diagram showing an example of a project details screen SD displayed on the user terminal 20. [Figure 8] 1 is an activity diagram showing an example of the flow of information processing (vulnerability management processing) executed by the information processing system 1. FIG. [Figure 9] 1 is an activity diagram showing an example of the flow of information processing (support end deadline management processing) executed by the information processing system 1. FIG. DETAILED DESCRIPTION OF THE INVENTION
[0009] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS The present invention will be described below with reference to the accompanying drawings. Various features shown in the following embodiments can be combined with each other.
[0010] Incidentally, the program for realizing the software appearing in one embodiment may be provided as a non-transitory computer-readable medium, or may be provided so that it can be downloaded from an external server, or may be provided so that the program is started on an external computer and its functions are realized on a client terminal (so-called cloud computing).
[0011] Furthermore, various information processing according to an embodiment may realize input and output corresponding to the input. Here, the form of information referenced in such information processing (hereinafter referred to as reference information) is not limited as long as an output is obtained as a result of the input. The reference information may be, for example, rule-based information such as a database, a lookup table, or a predetermined function (including a decision formula such as a regression formula constructed using a statistical method), a trained model that has previously learned the correlation between input and output, or a generative AI such as a large-scale language model (these models include parameters that establish the correlation between input and output) or a visual language model that can output a desired result in response to a prompt.
[0012] In one embodiment, a "unit" may include, for example, a combination of hardware resources implemented by a circuit in the broad sense and software information processing that can be specifically realized by these hardware resources. In one embodiment, various information is handled, and this information is represented, for example, by physical values of signal values representing voltage and current, high and low signal values as a binary bit set consisting of 0 or 1, or quantum superposition (so-called quantum bits), and communication and calculations can be performed on a circuit in the broad sense.
[0013] Furthermore, a circuit in the broad sense is a circuit realized by at least an appropriate combination of a circuit, circuitry, processor, memory, etc. The processor may be a general-purpose processor or a dedicated circuit. That is, it includes an application specific integrated circuit (ASIC), a programmable logic device (e.g., a simple programmable logic device (SPLD), a complex programmable logic device (CPLD), and a field programmable gate array (FPGA)), etc.
[0014] 1. Hardware Configuration This section explains the hardware configuration.
[0015] <Information Processing System 1> 1 is a configuration diagram showing an information processing system 1. The information processing system 1 includes a communication line 2, an information processing device 10, a plurality of user terminals 20, a plurality of managed servers 30, and a vulnerability information server 40. The information processing device 10, the user terminal 20, the managed servers 30, and the vulnerability information server 40 are configured to be able to communicate with each other via the communication line 2. The information processing device 10, the user terminal 20, the managed servers 30, and the vulnerability information server 40 may be connected via a wired or wireless connection. Furthermore, the information processing device 10, the user terminal 20, the managed servers 30, and the vulnerability information server 40 are each an example of an information processing device.
[0016] The information processing system 1 constitutes, for example, at least a part of a vulnerability management system that manages vulnerabilities of the managed server 30. The information processing system 1 mainly detects vulnerabilities of the managed server 30 used or managed by a user U, manages software, etc. In one embodiment, the information processing system 1 is made up of one or more devices or components. These components will be described below.
[0017] <Information processing device 10> 2 is a block diagram showing a hardware configuration of the information processing device 10. The information processing device 10 is a vulnerability diagnosis device (a server having a processor) that scans, identifies, manages, etc. vulnerability information of a system (e.g., software). The information processing device 10 may be provided, for example, by a provider of a vulnerability diagnosis service that scans, identifies, manages, etc. vulnerability information, and may be used by a user (user U) of the vulnerability diagnosis service. As shown in FIG. 2, the information processing device 10 includes a control unit 11, a storage unit 12, a communication unit 13, and a communication bus 14. The control unit 11, the storage unit 12, and the communication unit 13 are electrically connected within the information processing device 10 via the communication bus 14.
[0018] <Control unit 11> The control unit 11 processes and controls the overall operations related to the information processing device 10. The control unit 11 is, for example, a central processing unit (CPU). The control unit 11 realizes various functions related to the information processing device 10 by reading out predetermined programs stored in the storage unit 12. In other words, information processing by software stored in the storage unit 12 is specifically realized by the control unit 11, which is an example of hardware, and can be executed as each functional unit included in the control unit 11. These will be described in more detail in the next section. Note that the control unit 11 is not limited to being a single unit, and the information processing device 10 may have multiple control units 11 for each function. Furthermore, the information processing device 10 may be configured with a combination of these.
[0019] <Storage section 12> The memory unit 12 stores various pieces of information defined above. This can be implemented, for example, as a storage device such as a solid state drive (SSD) that stores various programs and the like related to the information processing device 10 executed by the control unit 11, or as a memory such as a random access memory (RAM) that stores temporarily required information (arguments, arrays, etc.) related to the program operations. The memory unit 12 stores various programs, variables, etc. related to the information processing device 10 executed by the control unit 11.
[0020] <Communications Department 13> The communication unit 13 is preferably a wired communication means such as USB, IEEE1394, Thunderbolt (registered trademark), wired LAN network communication, etc., but may also include wireless LAN network communication, mobile communication such as LTE / 5G, BLUETOOTH (registered trademark) communication, etc. as necessary. That is, the communication unit 13 may be implemented as a collection of these multiple communication means. Furthermore, the information processing device 10 may communicate various information with the outside via the communication unit 13 and the network.
[0021] The information processing device 10 may be an on-premise type or a cloud type. The cloud type information processing device 10 may provide the above-described functions and processes in the form of, for example, SaaS (Software as a Service) or cloud computing.
[0022] <User terminal 20> 3 is a block diagram showing the hardware configuration of the user terminal 20. The user terminal 20 is an information processing terminal used by a user U (administrator) who manages the managed server 30, and is able to access the information processing device 10 as a server. As shown in FIG. 3, the user terminal 20 includes a control unit 21, a storage unit 22, a communication unit 23, an input unit 24, an output unit 25, and a communication bus 26. The control unit 21, the storage unit 22, the communication unit 23, the input unit 24, and the output unit 25 are electrically connected via the communication bus 26 inside the user terminal 20. The description of the control unit 21, the storage unit 22, and the communication unit 23 is omitted because they are the same as the description of each unit in the information processing device 10.
[0023] <Input section 24> The input unit 24 accepts operation inputs made by the user. The operation inputs are transferred as command signals to the control unit 21 via the communication bus 26. The control unit 21 can execute predetermined control, calculations, etc. based on the transferred command signals as necessary. The input unit 24 may be included in the housing of the user terminal 20 or may be externally attached. For example, the input unit 24 may be implemented as a touch panel integrated with the output unit 25. When the input unit 24 is implemented as a touch panel, the user can input tap operations, swipe operations, etc. to the input unit 24. Instead of a touch panel, a switch button, a mouse, a trackpad, a QWERTY keyboard, etc. can be used as the input unit 24.
[0024] <Output section 25> The output unit 25 displays a screen of a graphical user interface (GUI) that can be operated by the user. The output unit 25 may be included in the housing of the user terminal 20 or may be attached externally. Specifically, the output unit 25 may be implemented as a display device such as a CRT display, a liquid crystal display, an organic EL display, or a plasma display. It is preferable that these display devices are used appropriately depending on the type of user terminal 20.
[0025] <Managed Server 30> The managed server 30 is a server including a detection target system (a system including software for performing vulnerability diagnosis) for which the information processing device 10 detects vulnerability information, or a server whose entirety is the detection target system. The managed server 30 may be a physical server, or may be a virtual server (cloud asset) built on a cloud platform provided by a cloud service provider. In other words, the detection target system may be a virtual server. The cloud platform may be, for example, a platform that allows access to services such as databases, storage, and applications via the Internet.
[0026] <Vulnerability Information Server 40> The vulnerability information server 40 is a server that manages software vulnerability information. The vulnerability information server 40 may be configured with multiple servers. Examples of the vulnerability information server 40 include management servers for vulnerability information websites (vulnerability information databases) such as CVE (Common Vulnerabilities and Exposures), NVD (National Vulnerability Database), ICAT (IPA Cybersecurity Alert Service) Metabase, JVN (Japan Vulnerability Notes), JVN iPedia, and OSVDB (Open Source Vulnerability Database). The vulnerability information server 40 may also include a server that stores vulnerability information (e.g., security advisories) provided independently by software suppliers. The software for which vulnerability information is managed may include OSS (Open Source Software).
[0027] 2. Functional configuration This section describes the functional configuration of this embodiment. Information processing by software stored in the storage unit 12 is specifically realized by the control unit 11, which is an example of hardware, and can be executed as each functional unit included in the control unit 11 (at least one processor included in the information processing system 1).
[0028] FIG. 4 is a block diagram showing functions realized by the information processing device 10 (controller 11) and the user terminal 20 (controller 21).
[0029] As shown in Figure 4A, the information processing device 10 (control unit 11) includes a basic display control unit 111, a group management unit 112, a vulnerability detection unit 113, an information reception unit 114, an information assignment unit 115, a setting information acquisition unit 116, an operation information estimation unit 117, an editing reception unit 118, a deadline determination unit 119, and an artificial intelligence unit 120.
[0030] As shown in FIG. 4B, the user terminal 20 (control unit 21) includes a display unit 211 and an operation acquisition unit 212.
[0031] <Basic display control unit 111> The basic display control unit 111 is configured to display various information on the user terminal 20. For example, the basic display control unit 111 displays vulnerability information detected by the vulnerability detection unit 113 on the display unit 211 of the user terminal 20.
[0032] <Group Management Department 112> The group management unit 112 is configured to manage a system group including a plurality of systems to be detected.
[0033] The group management unit 112 may associate an identifier indicating a system group with a detection target system included in the system group and register the association in the management database, thereby enabling centralized management of vulnerability information for any system group.
[0034] The group management unit 112 may, for example, accept input of information for identifying each of the multiple managed servers 30 (for example, information such as the network address (URL, etc.) of the system to be detected, and an identifier indicating the resource to be scanned), and register the registration information of the system to be detected in the management database. The group management unit 112 may also link this registration information with information indicating a system group.
[0035] The "system group" may be created (registered) by a user, or may be constructed by a management entity of the detection target system (for example, a server management system that manages the managed server 30). The server management system is provided by, for example, a virtual server provider, a cloud service provider, a system administrator, etc.
[0036] A system group may include a detection target system that is a base server and a detection target system that is a duplicate server that is a duplicate of the base server. This allows, for example, centralized management of vulnerabilities for a server group consisting of the base server and the duplicate server.
[0037] The replicated servers may be created by, for example, auto-scaling the base server. Auto-scaling is a function that automatically increases or decreases server resources (number of servers, processing capacity, etc.) according to the environment, such as the server load. With auto-scaling, for example, when the load on the system group increases, the number of replicated servers increases (scales out), and when the load decreases, the number of replicated servers decreases (scales in).
[0038] When a system group is a combination of a base server and a replicated server that are configured by auto-scaling, the identifier of the system group is created by the entity that executes the auto-scaling (for example, a server management system). In this case, the group management unit 112 acquires the identifier of the system group and information about the detection target systems (detection target systems included in the system group) that are linked to the identifier from, for example, the server management system, and registers them in the management database.
[0039] The group management unit 112 may accept a selection of detection target systems included in one system group from the user terminal 20, and may associate the identifier of the system group with the selected detection target systems and register them in the management database. This allows the user to arbitrarily set a system group for centrally managing vulnerabilities.
[0040] For example, the group management unit 112 may accept selection or creation of a system group in which to register a detection target system, and selection of a detection target system to be included in the system group or input of information about the detection target system from the user terminal 20. For example, a user may group multiple detection target systems according to the network configuration, use, etc.
[0041] When a new detection target system is added to a system group, the group management unit 112 may associate the system with the identifier of the system group. This allows the configuration of the system group to be updated in response to the addition of a detection target system by the user or the control unit 11.
[0042] For example, if a system group is a combination of a base server and a replicated server using auto-scaling, when a replicated server is added to the system group, the group management unit 112 associates the added replicated server with the identifier of the system group.
[0043] <Vulnerability detection unit 113> The vulnerability detection unit 113 is configured to detect vulnerabilities (specifically, vulnerability information) of a plurality of detection target systems included in a system group managed by the group management unit 112.
[0044] "Vulnerability information" includes, for example, information on vulnerabilities such as usage defects and bugs in software, programs, applications, components, etc. Vulnerability information may also include vulnerability identifiers that uniquely identify software vulnerabilities, information on software affected by vulnerabilities (e.g., identifiers, versions, etc.), whether attack code for software vulnerabilities is in circulation, score information indicating the level of software vulnerabilities, and security information such as misconfigurations and omissions in cloud services.
[0045] The vulnerability detection unit 113 may scan for vulnerability information on a snapshot that saves the state of at least a part of the detection target system. A snapshot is, for example, information that records the state of assets included in the detection target system (detection target resource). Typically, a snapshot includes information that allows the detection target system (detection target resource) at the time the snapshot was created to be restored by mounting it on a virtual server, an operating system (OS), or the like.
[0046] The assets of a system to be discovered include all system environments, entities, and services that can be managed by the user (in the case of a virtual server, that can be managed on a cloud platform). The assets may include, for example, virtual machines, virtual disks, virtual networks, storage accounts, software such as web applications, databases, roles, policies, etc. included in the system to be discovered. Here, roles and policies are information that define who has what authority to resources.
[0047] The vulnerability detection unit 113 extracts asset information from a snapshot, for example, and determines whether the asset information contains vulnerability information based on vulnerability master information (reference information for vulnerability information scanning) of the vulnerability information. "Asset information" is information that indicates the status of an asset. Asset information includes, for example, application libraries, hosts, container images, and SBOMs (Software Bill of Material).
[0048] The vulnerability detection unit 113 may indirectly access a snapshot in the detection target system and perform a scan by sending a request to an API (Application Programming Interface) provided by the detection target system, the provider of the cloud platform, etc.
[0049] The vulnerability master information is, for example, information acquired by the information processing device 10 from the vulnerability information server 40, and is stored in a vulnerability information database in the storage unit 12. The vulnerability master information includes, for example, security vulnerabilities (defects) contained in hardware or software, the types of defects, countermeasures for the defects, severity (level of vulnerability), etc. Examples of the severity include a score value (e.g., base score) defined by the Common Vulnerability Scoring System (CVSS). The vulnerability master information may also include the version of the CVSS.
[0050] Furthermore, the vulnerability master information may include information indicating the vulnerability level set by a third-party organization, information indicating whether or not the vulnerability is accessible from the outside, information indicating the extent of the impact on business of an attack against the vulnerability, information indicating whether or not attack code against the vulnerability is in circulation, information indicating whether or not exploitation of the vulnerability has been confirmed, etc. If attack code against the vulnerability is in circulation, the vulnerability master information may include the attack code.
[0051] The vulnerability master information may be information obtained by processing information acquired from the vulnerability information server 40. Examples of processing the information acquired from the vulnerability information server 40 include extracting parts of the information, correcting the information, and adding new information. These processes may be performed by the user, or may be performed mechanically by text analysis by the control unit 11, processing using a learning model, or the like. The vulnerability master information may be information acquired from a website such as a security-related news site or blog, or may be information entered by the user from the user terminal 20 and registered in the vulnerability information database.
[0052] The vulnerability detection unit 113 may determine the priority of the identified vulnerability information (i.e., triage the vulnerability) based on at least one of the following information contained in the vulnerability master information: information indicating the vulnerability level set by a third-party organization; information indicating whether the vulnerability is accessible from outside; information indicating the extent of the impact on business operations of an attack against the vulnerability; information indicating whether attack code against the vulnerability is in circulation; and information indicating whether exploitation of the vulnerability has been confirmed.
[0053] For example, a score value defined by CVSS is used as information indicating the vulnerability level. For example, the vulnerability detection unit 113 determines vulnerability information whose score value is less than a predetermined threshold to be level 0, which is the lowest priority. Vulnerability information of level 0 is defined as information about a vulnerability for which no particular countermeasures need be taken. Vulnerability information whose score value is equal to or greater than the threshold is determined to be level 1 or greater.
[0054] For example, the vulnerability detection unit 113 determines that vulnerability information with a score value equal to or greater than a threshold value, which is inaccessible from outside the system targeted for attack code detection (i.e., accessible only from inside the system targeted for detection) and which has little impact on business operations when attacked, is level 1. Level 1 vulnerability information is defined as information on vulnerabilities for which countermeasures should be implemented during regular maintenance of the system targeted for detection (e.g., once a month). The priority of responding to level 1 vulnerability information is higher than the priority of responding to level 0 vulnerability information.
[0055] For example, the vulnerability detection unit 113 determines that vulnerability information with a score value equal to or greater than a threshold, which relates to a vulnerability that is accessible from the outside or a vulnerability that will have a significant impact on business operations if attacked, is level 2 (excluding vulnerability information that corresponds to levels 3 or 4, which will be described later). Level 2 vulnerability information is defined as information on a vulnerability for which countermeasures should be implemented within a first deadline (for example, within two weeks). The priority of responding to level 2 vulnerability information is higher than the priority of responding to level 1 vulnerability information.
[0056] For example, the vulnerability detection unit 113 determines that vulnerability information that satisfies the determination conditions for level 2 and that relates to vulnerabilities for which attack code is circulating is level 3 (excluding vulnerability information that corresponds to level 4, which will be described later). Level 3 vulnerability information is defined as information about vulnerabilities for which countermeasures should be implemented within a second deadline (for example, within one day) that is shorter than the first deadline. The priority of responding to level 3 vulnerability information is higher than the priority of responding to level 2 vulnerability information.
[0057] For example, the vulnerability detection unit 113 determines that, among vulnerability information that satisfies the determination conditions for level 3, vulnerability information related to vulnerabilities for which attacks have been observed and exploitation of the vulnerability has been confirmed is the highest level, level 4. Level 4 vulnerability information is defined as information related to vulnerabilities for which countermeasures should be implemented within a third deadline (for example, immediately) that is shorter than the second deadline. The priority of responding to level 4 vulnerability information is higher than the priority of responding to level 3 vulnerability information.
[0058] Apart from the above level determination, the vulnerability detection unit 113 may set the highest priority to vulnerability information for which exploitation of the vulnerability has been confirmed and for which the vulnerability is accessible from the outside.
[0059] In addition, the vulnerability detection unit 113 may, for example, set a first rank as a priority for vulnerability information for which attack code against the vulnerability is circulating, and may set a second rank, which is higher than the first rank, as a priority for vulnerability information for which exploitation of the vulnerability has been confirmed and the vulnerability is accessible from outside.
[0060] Furthermore, the vulnerability detection unit 113 may set a third rank as a priority for vulnerability information for which attack code for the vulnerability is in circulation and the vulnerability is accessible from outside, and may set a fourth rank, which is lower than the third rank, as a priority for vulnerability information for which exploitation of the vulnerability has been confirmed but the vulnerability is not accessible from outside.
[0061] The vulnerability detection unit 113 may display the vulnerability determination result on the user terminal 20. The determination result includes, for example, the content of the identified vulnerability information, the type or priority (level) of the vulnerability information (for example, whether or not attack code is in circulation), and whether or not countermeasures are required (alert).
[0062] In addition, the vulnerability detection unit 113 may cause an agent installed in the system to be detected (managed server 30) that collects system configuration information to acquire configuration information of at least a portion of the system to be detected (resources to be detected), receive the configuration information acquired by the agent, and further perform a scan of the configuration information for vulnerability information.
[0063] An agent is a resident program installed in a detection target system (e.g., a virtual server) for monitoring the detection target system. The configuration information collected by the agent includes, for example, the hardware configuration of the detection target system (e.g., the CPU model, etc.), the name and version of the OS installed in the detection target system, the name, version, and settings of software installed in the detection target system, the user account and account privileges of the detection target system, the network to which the detection target system is connected, the Internet Protocol (IP) address of the detection target system, devices connected to the detection target system, devices communicating with the detection target system, the content of communication and communication protocols, and information indicating the status of ports (open ports) of the detection target system. The configuration information collected by the agent may also include asset information obtained from the snapshot described above.
[0064] Furthermore, the vulnerability detection unit 113 may reconstruct at least a part of the system to be detected as a scanning system based on a snapshot that saves the state of at least a part of the system to be detected (resources to be detected), and perform a scan of vulnerability information on this scanning system.
[0065] The vulnerability detection by the vulnerability detection unit 113 may be performed, for example, at a timing selected by the user (for example, at the timing when an instruction to execute vulnerability detection is input to the user terminal 20), or may be performed periodically at a predetermined period. Furthermore, vulnerability detection for multiple detection target systems included in one system group may be performed at the same timing (i.e., synchronously), or may be performed at individual timings.
[0066] <Information Reception Department 114> The information receiving unit 114 is configured to receive, from the user terminal 20, an input of management information for vulnerabilities detected by the vulnerability detection unit 113 in an input target system among a plurality of detection target systems included in one system group.
[0067] The "input target system" may be selected by the user from among multiple detection target systems, or may be preset for each system group. For example, if a system group includes a base server and a replication server, the base server may be set as the input target system. Even if the input target system is preset, the information receiving unit 114 may receive a change to the input target system from the user terminal 20.
[0068] "Management information" is information assigned by the user for the combination of a detected vulnerability and a detection target system. Management information indicates, for example, the severity (level) of the vulnerability, whether notification is required, whether a response is required, and the response status. Management information includes, for example, classification information such as labels and tags, and additional information such as comments and notes.
[0069] The management information may include information indicating whether or not a vulnerability notification is required (notification required). This allows the notification requirement for each detected vulnerability to be set collectively for each system group. This eliminates the need to individually set whether or not a notification is required for the same type of vulnerability in multiple systems that are detected and included in the system group.
[0070] The "information indicating whether or not a notification is required" is, for example, control information referenced by the information processing device 10, which indicates whether or not to notify the user when a vulnerability linked to management information including the information is detected in a detection target system. The information may be expressed as a label that allows the user to recognize the setting status of whether or not a notification is required.
[0071] When a vulnerability is detected, a notification (alert) of the vulnerability is sent to the user terminal 20 in the form of, for example, an email, a push notification, or the like. The notification may include only content indicating that a vulnerability has been detected, or may include content of the detected vulnerability.
[0072] The management information may also include information indicating whether a response to a vulnerability is necessary (response necessity). The "information indicating whether a response is necessary" is, for example, information for a user indicating whether a response to a vulnerability by the user is necessary or not when a vulnerability linked to management information including the information is detected in a detection target system. The information may be expressed as a label indicating whether a response is necessary or not. Note that the information (label) indicating that a response is not necessary may include information indicating a false detection of a vulnerability.
[0073] Furthermore, the management information may include information indicating the status of response to a vulnerability (response status). The "information indicating the response status" is information for user management that indicates, for example, a state in which a response has not yet been made, a state in which a response is being made, a state in which a response has been completed, or the like, for a vulnerability linked to the management information including the information. The information may be expressed as a label indicating the response status.
[0074] The management information may be configured by a combination of first information indicating whether a vulnerability notification is required and second information indicating whether a response is required or the status of the response. Furthermore, the information receiving unit 114 may receive input of the second information from the user terminal 20, determine the first information corresponding to the input second information, and receive this first information and second information as management information. The determination of the first information is performed, for example, using information (a table) that predefines the correspondence between the first information and the second information.
[0075] For example, for a vulnerability for which "action completed," "action not required," "false positive detection," etc. have been input as the second information, the information receiving unit 114 may receive management information in which the first information of "notification not required" has been combined with the second information. Furthermore, for example, for a vulnerability for which "action in progress," "not yet actioned," etc. have been input as the second information, the information receiving unit 114 may receive management information in which the first information of "notification required" has been combined with the second information.
[0076] <Information providing unit 115> The information assigning unit 115 is configured to assign the management information received by the information receiving unit 114 to a vulnerability received as input in the management information of the input target system and to a vulnerability of the same type as the vulnerability in a detection target system other than the input target system included in the system group. Here, "a vulnerability of the same type" means, for example, a vulnerability with the same vulnerability identifier.
[0077] The information assigning unit 115 may determine a detection target system to which management information is to be assigned, based on an identifier representing a system group registered by the group managing unit 112. In other words, the information assigning unit 115 may determine that a detection target system associated with the same identifier as an input target system is a detection target system to which management information input to the input target system is to be assigned.
[0078] For example, when a user inputs label B (e.g., a label indicating "response completed") for vulnerability A detected in an input target system, the information assigning unit 115 assigns label B to the detected vulnerability A for all detection target systems (including the input target system) included in the system group to which the input target system belongs. In other words, the information assigning unit 115 propagates the management information input for the input target system to detection target systems in the same system group.
[0079] For example, the information assigning unit 115 associates the vulnerability information with the management information for each detection target system and registers them in the management database. In addition, the information assigning unit 115 may cause the user terminal 20 to display the management information together with the corresponding vulnerability information.
[0080] The information assigning unit 115 may assign the management information input for the input target system only to a pre-designated or pre-set detection target system among the multiple detection target systems included in the system group. The detection target system to which the management information is assigned may be selected by the user, for example.
[0081] Furthermore, the information assignment unit 115 may register information (such as a code) indicating whether the management information was input directly by the user (i.e., input for a vulnerability in the input target system) or was copied (propagated) from what was input by the user (i.e., assigned for a vulnerability in a detection target system other than the input target system) by linking it to the management information.
[0082] <Setting information acquisition unit 116> The setting information acquisition unit 116 is configured to acquire setting information created during the development of software (hereinafter referred to as "estimation target software") whose operation information is to be estimated by the operation information estimation unit 117 described below.
[0083] The "estimated system" is a system including the estimated software. The estimated system is, for example, a system included in the managed server 30, and may be a virtual server. The estimated system may also be the same as the detection target system for which the vulnerability detection unit 113 detects vulnerability information. In other words, the setting information acquisition unit 116 may acquire setting information created during the development of the estimated software to be executed in the detection target system.
[0084] "Configuration information" includes at least information about the execution environment of the software to be estimated. Here, "execution environment" refers to the runtime, framework, operating system, or a combination thereof required to execute the software. Furthermore, "information about the execution environment of the software to be estimated" refers to information that represents the data (files), settings, conditions, etc. required to execute the software to be estimated. The configuration information may include information that directly indicates the execution environment, or may include only information that does not directly indicate the execution environment.
[0085] The setting information may include information that cannot be obtained in the production environment of the estimation target software. For example, the setting information may include information that cannot be obtained from a list of components constituting the estimation target software (software bill of materials), such as the SBOM (Software Bill of Materials) of the estimation target software. The "production environment" is a formal operating environment in which the estimation target software provided to the user runs, and is constructed, for example, in a system (managed server 30) accessed by the user.
[0086] The setting information is created and updated by a developer in the development environment of the software to be estimated, for example. The setting information acquisition unit 116 may acquire the setting information from a development environment file managed in the development environment of the software to be estimated. This makes it possible to easily and reliably acquire the setting information necessary for estimating the operation information.
[0087] A "development environment" is an environment that is accessible to the developer of the software to be estimated, but is inaccessible to users of the software to be estimated, and is not disclosed to those users. Examples of development environments include a repository management environment and a CI / CD (Continuous Integration / Continuous Delivery) environment.
[0088] A "repository management environment" is an environment that centrally manages versions of source code, related files (documents), etc. of the software to be estimated. In the repository management environment, the change history of the source code, related files, etc. is saved and / or shared. The repository management environment is provided by a repository hosting service (version management service) such as GitHub (registered trademark) or GitLab (registered trademark).
[0089] A "CI / CD environment" is an environment that continuously executes the processes of integrating (merging) the code of the estimated software into a shared repository, automatically building and testing it, and automatically preparing applications that have passed the tests so that they can be deployed to a production environment. A CI / CD environment is provided by a CI / CD tool that executes the CI / CD process.
[0090] Furthermore, a "development environment file" refers to a file that is created, updated, referenced, or the like in the development environment of the software to be estimated. The development environment file is, for example, a file that can be accessed by the information processing device 10 in the development environment (i.e., a file stored in the development environment) and a file that cannot be accessed by the information processing device 10 in the production environment (i.e., a file that is not stored in the production environment). The development environment file includes a source code file, a manifest file, and the like. The development environment file is, for example, stored in a database used in the development environment.
[0091] A typical example of the development environment file from which the setting information acquisition unit 116 acquires setting information is a manifest file. That is, the setting information acquisition unit 116 may acquire setting information from the manifest file of the software to be estimated. This can improve the accuracy of estimating operation information.
[0092] A "manifest file" is a metadata file that describes information necessary for the operation of the software to be estimated. The manifest file describes information such as program identification information (name, version, developer or publisher, etc.), the program development language, the program execution environment (runtime type and version, required libraries or modules, dependencies on external programs, entry point, etc.), program permissions, program distribution format, program compatibility, etc.
[0093] The setting information acquisition unit 116 may acquire the entire manifest file as the setting information, or may acquire a part of the manifest file (for example, only the description related to the program execution environment) as the setting information.
[0094] The setting information acquisition unit 116 may acquire attribute information of the development environment file as the setting information. "Attribute information of the development environment file" is information indicating the type of the development environment file, and is, for example, information acquired from the file name of the development environment file or information acquired by parsing the development environment file. Examples of information acquired from the file name include the file name itself and the file extension. Examples of information acquired by parsing include the file structure and keywords included in the file. The setting information acquisition unit 116 may acquire attribute information of multiple development environment files for one piece of estimation target software.
[0095] <Motion information estimation unit 117> The operation information estimation unit 117 is configured to estimate operation information of the estimation target software based on the setting information acquired by the setting information acquisition unit 116 and the reference information. "Operation information" is information that represents the execution environment or development language of the estimation target software. As a result, when the execution environment or development language of the estimation target software cannot be directly acquired, this information can be estimated from the setting information created during the development of the estimation target software, and the estimation target software can be managed. Therefore, for example, it becomes possible to uniformly manage the execution environments of multiple estimation target software developed in different languages.
[0096] The operation information may include at least one of the name and version of a runtime, framework, or operating system required to run the software, and the name and version of the development language for the software, thereby improving the manageability of the software based on the operation information.
[0097] The reference information is information relating to the correlation between the setting information and the operation information. The reference information is stored, for example, in the storage unit 12. The reference information may include, for example, a table, a function, a simple algorithm, or the like, which indicates the correlation between the setting information and the operation information. The correlation included in the reference information can be constructed, for example, by statistically analyzing data recording the setting information and the corresponding operation information.
[0098] The reference information may include a set of parameters for generating motion information from the setting information. For example, the reference information may include a learning model that uses the setting information as input and is machine-learned to be able to output motion information, or a motion information estimation model that is a generating AI. In this case, the motion information estimation unit 117 inputs the setting information to the motion information estimation model and causes the motion information estimation model to output motion information.
[0099] The motion information estimation model is included in the artificial intelligence unit 120. The motion information estimation model, which has been trained to be able to output motion information, is trained using, for example, setting information data and corresponding motion information data as training data. In such a motion information estimation model, parameters calculated, tuned, etc. by training establish a correlation between the setting information and the motion information.
[0100] When the motion information estimation model is a generation AI including a general-purpose natural language model (e.g., a language model such as a large-scale language model), the motion information estimation unit 117 inputs a prompt including setting information and an instruction to input the setting information and output motion information corresponding to the setting information to the motion information estimation model, causing the motion information estimation model to output the motion information. The motion information estimation unit 117 may generate a prompt that instructs the motion information estimation model to create motion information and input the prompt to the motion information estimation model. Furthermore, the motion information estimation unit 117 may input a prompt including, for example, one or more setting information samples and one or more corresponding motion information samples as examples, samples, or training data of input and output pairs to the motion information estimation model in addition to the setting information and the instruction to create and output the motion information. Here, the parameters for constructing the generation AI and the prompt including an instruction to output motion information corresponding to the setting information construct a correlation between the setting information and the motion information.
[0101] The reference information may include a motion information estimation model, which is a generating AI, and first correspondence data in which a correspondence between setting information and motion information is recorded. The motion information estimation unit 117 may input a prompt including an instruction to estimate motion information corresponding to the setting information based on the first correspondence data to the motion information estimation model, and cause the motion information estimation model to output the motion information. This allows motion information to be estimated based on correspondence data prepared in advance, thereby improving the accuracy of estimating the execution environment or development language of the software to be estimated.
[0102] The first correspondence data is, for example, a dictionary or table in which the correspondence between the information (character strings, numerical values, etc.) included in the manifest file, the name, extension, structure, contained keywords, etc. of the development environment file and the execution environment or development language is described (these are registered in association with each other). For example, if the manifest file contains binary data representing the keyword "go", the first correspondence data describes that the development language of the software to be estimated is "Go". The first correspondence data is recorded, for example, in the storage unit 12 of the information processing device 10, the vulnerability information server 40, etc., and is updated periodically.
[0103] When the setting information acquisition unit 116 acquires attribute information of a development environment file as setting information, the reference information may include second correspondence data in which a correspondence between the attribute information and operation information is recorded. The operation information estimation unit 117 may estimate the operation information based on the attribute information and the correspondence data. This makes it possible to estimate the execution environment or development language of the estimation target software on a rule basis, thereby reducing the load of the estimation process while maintaining estimation accuracy.
[0104] The second correspondence data is, for example, a dictionary or table in which the correspondence between the name, extension, structure, contained keywords, etc. of the development environment file and the execution environment or development language is described (the two are registered in association with each other). For example, the second correspondence data describes that when the name of the development environment file is "gemfile", the development language of the software to be estimated is "ruby". The second correspondence data is recorded, for example, in the storage unit 12 of the information processing device 10, the vulnerability information server 40, etc., and is updated periodically.
[0105] When the motion information cannot be estimated from the setting information acquired by the setting information acquisition unit 116, the motion information estimation unit 117 may generate a processing result (error data) indicating that fact. For example, when the motion information cannot be estimated even by referring to the first correspondence data, the motion information estimation unit 117 may provide a prompt to the motion information estimation model, which is the generation AI, including an instruction to output error data indicating that the motion information could not be acquired. Furthermore, when there is no motion information corresponding to the attribute information in the second correspondence data, the motion information estimation unit 117 may generate error data.
[0106] <Editing Reception Department 118> The edit receiving unit 118 is configured to receive an edit of the motion information estimated by the motion information estimating unit 117.
[0107] For example, the edit receiving unit 118 links the estimated software to the estimated operation information and displays it on the user terminal 20, and receives edits to the operation information (such as modifying content, adding content, deleting content, etc.) from the user terminal 20.
[0108] The editing reception unit 118 may accept editing of the operation information after the deadline determination unit 119 described below determines the end of support deadline based on the operation information estimated by the operation information estimation unit 117, or may accept editing of the operation information estimated by the operation information estimation unit 117 before the deadline determination unit 119 determines the end of support deadline.
[0109] 5 is a diagram showing an example of a project editing screen PD displayed on the user terminal 20. The project editing screen PD displays the status of one piece of estimation target software (project). Specifically, the project editing screen PD includes a property setting area PA, a runtime editing area RA, an EOL editing area EA, a save button B11, and a cancel button B12.
[0110] The property setting area PA is an area for setting the status (enabled or disabled) of the release, distribution, vulnerability scan, etc. of the software to be estimated. In the example of Figure 5, whether or not the software is released, whether or not it is distributed, whether or not it is security scanned, etc. can be set by inputting information into the check boxes provided for each status.
[0111] The runtime editing area RA accepts editing of runtime information (specifically, runtime name and version) included in the operation information estimated by the operation information estimation unit 117. In the initial state, the runtime information estimated by the operation information estimation unit 117 is displayed in the input field of the runtime editing area RA, and editing of the runtime name, version, etc. is accepted in the input field by input from the user terminal 20.
[0112] If the motion information estimated by the motion information estimation unit 117 does not include runtime information (i.e., if the motion information estimation unit 117 is unable to estimate the runtime), the input field of the runtime editing area RA is initially left blank, and input of runtime information is accepted from the user terminal 20. Also, for example, if the motion information estimation unit 117 estimates only the runtime name but is unable to estimate the runtime version, the input field of the runtime editing area RA initially displays only the runtime name, and accepts input of the runtime version from the user terminal 20. Furthermore, for example, if the motion information estimation unit 117 estimates only the runtime major version but is unable to estimate the minor version, the input field of the runtime editing area RA initially displays only the runtime name and major version, and accepts input of the minor version from the user terminal 20.
[0113] The EOL editing area EA accepts editing of the EOL (end of support date for the software) determined by the later-described deadline determining unit 119. In the initial state, the EOL determined by the deadline determining unit 119 is displayed in the input field of the EOL editing area EA, and editing of the EOL is accepted in the input field by input from the user terminal 20.
[0114] When an input operation is performed on the Save button B11, the contents entered in the property setting area PA, runtime editing area RA, and EOL editing area EA are registered in the project database that manages the project, and the project editing screen PD is closed. When an input operation is performed on the Cancel button B12, the edited contents in the property setting area PA, runtime editing area RA, and EOL editing area EA are discarded, and the project editing screen PD is closed.
[0115] <Deadline determination section 119> The expiration date determination unit 119 is configured to determine the end of support date of the estimation target software based on the operation information estimated by the operation information estimation unit 117. This makes it possible to manage the end of support date for estimation target software for which information for determining the end of support date cannot be directly acquired (particularly, for software for which information cannot be acquired in a production environment).
[0116] The expiration date determination unit 119 may determine the end of support date of the estimation target software based on the operation information edited by the edit receiving unit 118. This allows the end of support date to be determined based on more accurate operation information, thereby improving the accuracy of determining the end of support date. Note that if the edit receiving unit 118 receives an edit of the operation information after the expiration date determination unit 119 determines the end of support date based on the operation information estimated by the operation information estimation unit 117, the expiration date determination unit 119 will determine the end of support date again based on the edited operation information.
[0117] The expiration determination unit 119 extracts the support end date of the target software (the support end date associated with the operation information serving as the search key) from the expiration master information, for example, using the operation information as a search key. For example, the expiration determination unit 119 identifies the support end date by comparing the runtime name, runtime version, etc. included in the operation information with the information registered in the expiration master information.
[0118] The deadline master information is, for example, information acquired by the information processing device 10 from a runtime provider or the like, and is stored in the deadline information database of the storage unit 12. Note that the deadline master information may be information integrated with vulnerability master information.
[0119] The deadline determination unit 119 displays the determined support end deadline on the user terminal 20 together with the operation information used to determine the support end deadline (in the example of FIG. 5, runtime information in the runtime editing area RA), as in the project editing screen PD of Fig. 5. The deadline determination unit 119 may also display the remaining period until the support end deadline (expiration date), whether support has ended (for example, support has expired), and the like, together with the determined support end deadline, on the user terminal 20.
[0120] Furthermore, when there is estimated target software for which the remaining period until the support end deadline is less than a predetermined period (for example, one month, three months, six months, etc.), the deadline determination unit 119 may transmit a notification alerting the user terminal 20 about the remaining period. For example, the notification may be displayed as a pop-up on the user terminal 20 when the user logs in to the software management service provided by the information processing device 10.
[0121] 6 is a diagram showing an example of a project list screen LD displayed on the user terminal 20. The project list screen LD includes an operation input area OA, a list display area LA, and a page switching object PO.
[0122] The operation input area OA is an area for searching and narrowing down the projects (estimated target software) displayed in the list display area LA, and for accepting input of collective operations for selected projects. The operation input area OA has input fields or objects corresponding to each operation.
[0123] The deadline selection object DO located in the operation input area OA accepts the setting of a filter for projects based on the remaining period until the end of support deadline. For example, the deadline selection object DO accepts the selection of one or more options from among options such as "All" (no filtering), "Expired," "Due within 3 months," and "Due within 6 months." When a deadline is selected in the deadline selection object DO, only the projects corresponding to the selected deadline are displayed in the list display area LA.
[0124] The list display area LA displays a list of projects registered in the project database. The project information displayed in the list display area LA includes the project name, whether or not there are any vulnerabilities (especially high-level ones) detected by the vulnerability detection unit 113, whether or not the project has been made public, whether or not it has been distributed, whether or not it has been scanned, the end of life (EOL), the last registration date, etc. Each project is also assigned a label LB indicating the expiration date until the end of life or the end of the support period. Furthermore, each project is assigned a check box CB for selection.
[0125] The page switching object PO is an object that accepts switching of pages in the list display area LA. An input operation to the page switching object PO switches the project displayed in the list display area LA.
[0126] 7 is a diagram showing an example of a project details screen SD displayed on the user terminal 20. The project details screen SD is displayed, for example, when an input operation is performed on any of the projects displayed in the list display area LA in FIG.
[0127] The project details screen SD displays whether it has been released, whether it has been distributed, whether it has been scanned, the last registration date, runtime information (runtime name and version), end of life (EOL), expiration date until end of life or end of support period, etc. In the example of Figure 7, a label LB indicating the expiration date until end of life or end of support period is attached to EOL.
[0128] <Artificial Intelligence Department 120> The artificial intelligence unit 120 is configured to receive input from each functional unit and return the instructed output. The artificial intelligence used by each functional unit of the information processing device 10 may be a common one, or may be prepared individually for each functional unit.
[0129] The artificial intelligence unit 120 may be an AI (Artificial Intelligence) equipped with a learning model such as a language model, such as a Transformer (including GPT (Generative Pretrained Transformer, including GPT-1 to GPT-5)), BERT (Bidirectional Encoder Representations from Transformers), BART (Bidirectional and Auto-regressive Transformer), or a Recurrent Neural Network (RNN). The artificial intelligence unit 120 may be, for example, a generative AI or an AI agent including a large-scale language model. A large-scale language model is a type of generative AI and includes models provided by services such as OpenAI's GPT, Google's Gemini, and Microsoft's Azure AI Studio. The generative AI may be, for example, a text generation AI, an image generation AI, or a multimodal generation AI. The learning model may be referred to as an artificial intelligence model, a machine learning model, a trained model, or a deep learning model. Alternatively, the artificial intelligence unit 120 may include any learning model.
[0130] The language model is an example of a learning model based on a machine learning algorithm. Specific examples of machine learning algorithms include nearest neighbor methods, naive Bayes methods, decision trees, support vector machines, and deep learning using neural networks. The artificial intelligence unit 120 can apply the above algorithms as appropriate.
[0131] The artificial intelligence unit 120 may have a trained model constructed by a learning method such as supervised learning, unsupervised learning, or self-supervised learning. In supervised learning, machine learning is performed using training data (training data). The training data consists of pairs of input data for learning and output data (correct answer data). Furthermore, the language model may not only be trained for a specific task, but also be a general-purpose model that can be used for a wide range of tasks.
[0132] The artificial intelligence unit 120 may include a natural language model as its artificial intelligence, or may be a general-purpose natural language processing trained model such as a large-scale language model (LLM). An LLM is a learning model that has previously trained a large amount of data, such as text data (e.g., (i) web content on the Internet, or (ii) data stored in a specified database). It can perform various language processing tasks when given a task, and can perform a wide range of natural language processing tasks, such as understanding sentence patterns and contexts, answering questions, and generating sentences, according to given prompts. Such a general-purpose learning model includes a language model that can handle various tasks without fine-tuning, using one-shot learning or few-shot learning. A general-purpose learning model may also be configured to handle various tasks using zero-shot learning. The artificial intelligence used in each functional unit of the control unit 11 may be a separate learning model, or a common general-purpose learning model. The artificial intelligence unit 120 may also include a small-scale language model or a medium-scale language model, which are smaller in scale than a large-scale language model, as its learning model. Small-scale language models and medium-scale language models are natural language processing models trained based on less data than large-scale language models (constructed with fewer parameters than large-scale language models).
[0133] The learning models included in the artificial intelligence unit 120 (learning models used in each functional unit, such as the motion information estimation model) can undergo additional learning using techniques such as transfer learning and fine tuning. For example, each time new data is registered, the artificial intelligence unit 120 may perform additional learning and fine tuning using the new data as new training data. This improves the accuracy of the information output from the learning models.
[0134] The learning model included in the artificial intelligence unit 120 may be a learning model (distilled model) obtained by knowledge distillation using an original learning model. In knowledge distillation, a trained model such as a large-scale language model is used as a teacher model, and the parameters of the student model are adjusted to reduce the output loss (Soft Target Loss) of the student model (distilled model) relative to the output (Soft Target) of the teacher model, thereby learning the student model, which becomes the distilled model. Alternatively, the student model may be learned to reduce the output loss (Hard Target Loss) of the student model relative to the correct label (Hard Target) of the teacher data (combination of input data and output data of the learning model). Compared to the original learning model (teacher model), the distilled model has a smaller number of parameters and a smaller processing load while maintaining performance similar to the learning model. Therefore, using a distilled model can reduce the cost of the information processing system 1.
[0135] For example, the learning model used in each functional unit may be a distilled model trained using a combination of input data and output data in a large-scale language model as training data. Furthermore, when the information processing system 1 is introduced, a large-scale language model may be used as the learning model used in each functional unit, and when training data from the large-scale language model is accumulated, a distilled model obtained by knowledge distillation using the training data may be used as the learning model used in each functional unit.
[0136] An AI agent (which may also be called an autonomous agent) is a model that, when given a goal (purpose, objective, etc.) such as "teach me XX" or a task such as "output XX," breaks down the processing required to reach the goal or accomplish the task into subtasks, actions, etc., and performs the necessary data collection and analysis, program generation, and execution. The AI agent targets information and instructions input by a user, autonomously selects and executes tasks and actions according to the goal, and outputs information according to the goal, without requiring user intervention (operational input). The AI agent may also autonomously learn to achieve its goal by autonomously creating and executing plans and evaluating the execution results. For example, the AI agent may be autonomously updated based on the results of subtask execution (e.g., collected information, information analysis results, etc.).
[0137] <Display> The display unit 211 of the user terminal 20 shown in FIG. 4B displays a screen (information) indicated by the data transmitted from the information processing device 10.
[0138] <Operation acquisition section> The operation acquisition unit 212 of the user terminal 20 accepts operations by the user who uses the user terminal 20 .
[0139] 3. Information Processing Method This section describes an information processing method of the information processing device 10. This information processing method is executed by a computer, with each unit of the information processing device 10 acting as each step.
[0140] A first information processing method of the present disclosure includes a vulnerability detection step, an information receiving step, and an information assignment step. In the vulnerability detection step, vulnerabilities are detected in multiple detection target systems included in a system group. In the information receiving step, input of management information for vulnerabilities detected in an input target system among multiple detection target systems included in the system group is accepted. In the information assignment step, the accepted input management information is assigned to vulnerabilities for which input of the management information for the input target system was accepted and to vulnerabilities of the same type as the vulnerability in detection target systems included in the system group other than the input target system.
[0141] 8 is an activity diagram showing an example of the flow of information processing (vulnerability management processing) executed by the information processing system 1. Below, the information processing will be described along with each activity in this activity diagram.
[0142] The vulnerability management process starts with the detection of a vulnerability by the information processing device 10. The information processing device 10 detects vulnerabilities in detection target systems included in a system group at a predetermined timing or in response to an instruction from the user terminal 20 (activity A101). Next, the information processing device 10 outputs the detected vulnerabilities to the user terminal 20 (activity A102). As a result, the vulnerabilities of the detection target systems included in the system group are displayed on the user terminal 20 (activity A103).
[0143] The user inputs management information for vulnerabilities in the displayed input target system (one of the detection target systems included in the system group) on the user terminal 20 (activity A104). The information processing device 10 accepts the management information input on the user terminal 20 (activity A105). Furthermore, the information processing device 10 assigns the accepted management information to vulnerabilities of the same type in the detection target systems (including the input target system) included in the system group (activity A106).
[0144] A second information processing method of the present disclosure includes a setting information acquisition step, an operation information estimation step, and an expiration date determination step. In the setting information acquisition step, setting information created during software development is acquired for software executed in a detection target system. In the operation information estimation step, operation information of the software is estimated based on the setting information and reference information. In the expiration date determination step, the support end date for the software is determined based on the operation information.
[0145] 9 is an activity diagram showing an example of the flow of information processing (support end deadline management processing) executed by the information processing system 1. Below, the information processing will be described along with each activity in this activity diagram.
[0146] The support end deadline management process starts with the acquisition of setting information by the information processing device 10. The information processing device 10 acquires setting information of the estimation target software designated by the user (activity A201). Next, the information processing device 10 estimates operation information of the estimation target software based on the acquired setting information (activity A202).
[0147] After estimating the operation information, the information processing device 10 determines the end of support date of the estimation target software based on the operation information (activity A203). Subsequently, the information processing device 10 outputs the determined end of support date to the user terminal 20 (activity A204). As a result, the end of support date is displayed on the user terminal 20 (activity A205).
[0148] 4. Effect The effects of this embodiment can be summarized as follows: That is, the risks of the system can be easily managed.
[0149] Although the embodiment of the present invention has been described above, the present invention is not limited to this and can be modified as appropriate within the scope of the technical idea of the invention.
[0150] 5.Other In the above embodiment, the information processing device 10 performs various storage and control functions. However, multiple external devices may be used instead of the information processing device 10. That is, various pieces of information and programs may be distributed and stored in multiple external devices using blockchain technology or the like. In particular, the artificial intelligence unit 120 may be an external component of the information processing device 10. In this case, the external artificial intelligence unit 120 may be provided, for example, by an artificial intelligence service server and configured to receive inputs from each functional unit of the information processing device 10, receive requests to execute artificial intelligence services, and return the instructed output as a processing result to the information processing device 10. The artificial intelligence service server may be a server that provides services using a language model as a learning model, or a server that executes language processing tasks using a language model. The artificial intelligence service server may be constructed using LLM. The artificial intelligence service server receives inputs of prompts such as text, images, and voice, and generates and responds to the prompts.
[0151] At least one of the devices included in the information processing system 1 may be installed outside the country in which the functions of the information processing system 1 are performed.
[0152] The aspect of this embodiment is not limited to the information processing system 1, and may be an information processing method or a program. In the information processing method, an information processing device executes each step of the information processing system 1. The program causes a computer to execute each step of the information processing system 1.
[0153] The control unit 11 does not necessarily have to include the setting information acquisition unit 116, the operation information estimation unit 117, the edit reception unit 118, and the deadline determination unit 119. For example, the information processing system 1 may have only a vulnerability detection function and a management information assignment function for a system group.
[0154] The control unit 11 does not necessarily have to include the group management unit 112, the vulnerability detection unit 113, the information reception unit 114, and the information assignment unit 115. In other words, the present disclosure may include the following information processing system (an information processing system including at least a setting information acquisition unit 116 and an operation information estimation unit 117).
[0155] An information processing system comprising at least one processor; The processor is configured to execute the following steps by reading the program: In the setting information acquisition step, setting information created during development of software executed in the estimation target system is acquired, wherein the setting information includes at least information regarding an execution environment of the software; In the operation information estimation step, operation information of the software is estimated based on the setting information and reference information, wherein the operation information is information representing the execution environment or development language of the software, and the reference information is information regarding the correlation between the setting information and the operation information.
[0156] Furthermore, this information processing system may include an edit receiving unit 118 and / or a deadline determining unit 119.
[0157] It may be provided in the following manner.
[0158] (1) An information processing system comprising at least one processor, the processor being configured to execute each of the following steps by reading a program: a vulnerability detection step detecting vulnerabilities in a plurality of detection target systems included in a system group; an information receiving step receiving input of management information for vulnerabilities detected in an input target system among the plurality of detection target systems included in the system group; and an information assignment step assigning the received input management information to vulnerabilities for which the input of the management information of the input target system was received and to vulnerabilities of the same type as the vulnerability in the detection target systems other than the input target system included in the system group.
[0159] (2) In the information processing system described in (1) above, the management information includes information indicating whether or not a vulnerability notification is required.
[0160] (3) In the information processing system described in (1) or (2) above, in the group management step, an identifier indicating the system group is linked to the detection target system included in the system group and registered, and in the information assignment step, the detection target system to which the management information is assigned is determined based on the identifier.
[0161] (4) In the information processing system described in (3) above, in the group management step, a selection of the detection target systems included in the system group is accepted, and the identifier is linked to the detection target system whose selection has been accepted and registered.
[0162] (5) In the information processing system described in (3) or (4) above, in the group management step, when a new detection target system is added to the system group, the detection target system is linked to the identifier.
[0163] (6) In the information processing system described in any one of (1) to (5) above, the system group includes the detection target system which is a base server and the detection target system which is a replicated server that replicates the base server.
[0164] (7) In an information processing system described in any one of (1) to (6) above, in the setting information acquisition step, setting information created during the development of software executed in the detection target system is acquired, wherein the setting information includes at least information regarding the execution environment of the software; and in the operation information estimation step, operation information of the software is estimated based on the setting information and reference information, wherein the operation information is information representing the execution environment or development language of the software, and the reference information is information regarding the correlation between the setting information and the operation information.
[0165] (8) In the information processing system described in (7) above, in the expiration determination step, an expiration date of support for the software is determined based on the operation information.
[0166] (9) In the information processing system described in (7) or (8) above, the reference information includes a motion information estimation model, which is a generating AI, and correspondence data in which a correspondence between the setting information and the motion information is recorded, and in the motion information estimation step, a prompt including an instruction to estimate the motion information corresponding to the setting information based on the correspondence data is input to the motion information estimation model, and the motion information is output to the motion information estimation model.
[0167] (10) In the information processing system according to any one of (7) to (9) above, in the setting information acquisition step, the setting information is acquired from a manifest file of the software.
[0168] (11) In the information processing system according to any one of (7) to (10) above, the setting information acquisition step acquires the setting information from a file managed in a development environment of the software.
[0169] (12) In the information processing system described in (11) above, in the setting information acquisition step, attribute information of the file is acquired as the setting information, the reference information includes correspondence data in which a correspondence between the attribute information and the operation information is recorded, and in the operation information estimation step, the operation information is estimated based on the attribute information and the correspondence data.
[0170] (13) In the information processing system described in any one of (7) to (12) above, in the edit receiving step, edits to the operation information are received, and in the expiration determination step, the end of support period for the software is determined based on the edited operation information.
[0171] (14) In the information processing system described in any one of (7) to (13) above, the operational information includes at least one of the name and version of the runtime, framework, or operating system required to execute the software, and the name and version of the development language of the software.
[0172] (15) The information processing system according to any one of (1) to (14) above, further comprising: a server having the processor; and a terminal that can access the server.
[0173] (16) An information processing method, in which an information processing device executes each step of the information processing system described in any one of (1) to (15) above.
[0174] (17) A program for causing a computer to execute each step of the information processing system described in any one of (1) to (15) above. Of course, this is not the case.
[0175] Finally, while various embodiments of the present disclosure have been described, they are presented as examples and are not intended to limit the scope of the invention. The novel embodiments may be embodied in various other forms, and various omissions, substitutions, and modifications may be made without departing from the spirit of the invention. Such embodiments and modifications are intended to be included within the scope and spirit of the invention, as well as within the scope of the inventions and their equivalents as defined in the claims. [Explanation of symbols]
[0176] 1: Information processing system 2: Communication line 10: Information processing device 11: Control section 111: Basic display control section 112: Group Management Department 113: Vulnerability detection unit 114: Information Reception Department 115: Information assignment section 116: Setting information acquisition unit 117: Motion information estimation unit 118: Editorial Reception 119: Deadline determination section 120: Artificial Intelligence Department 12: Storage section 13: Communications Department 14: Communication bus 20: User terminal 21: Control unit 211:Display section 212: Operation acquisition section 22: Storage section 23: Communications Department 24: Input section 25: Output section 26: Communication bus 30: Managed server 40: Vulnerability Information Server B11: Save button B12: Cancel button DO: Deadline selection object EA: EOL Editing Area LA: List display area LB: Label LD: Project list screen OA: Operation input area PA: Property setting area PD: Project Edit Screen PO: Page Switching Object RA: Runtime Editing Area SD: Project details screen
Claims
1. An information processing system, at least one processor; The processor is configured to execute the following steps by reading the program: In the vulnerability detection step, vulnerabilities are detected in multiple target systems included in the system group. In the information receiving step, an input of management information regarding a vulnerability detected in an input target system among the plurality of detection target systems included in the system group is received, and In the information assignment step, the information processing system assigns the management information that has been input to the vulnerability for which the management information has been input in the input target system and to vulnerabilities of the same type as the vulnerability in the detection target system other than the input target system that is included in the system group.
2. 2. The information processing system according to claim 1, An information processing system, wherein the management information includes information indicating whether or not a vulnerability notification is required.
3. 2. The information processing system according to claim 1, In the group management step, an identifier indicating the system group and the detection target system included in the system group are associated with each other and registered; In the information assigning step, the detected system to which the management information is to be assigned is determined based on the identifier.
4. 4. The information processing system according to claim 3, In the group management step, a selection of the detection target systems included in the system group is accepted, and the identifiers are associated with the selected detection target systems and registered.
5. 4. The information processing system according to claim 3, In the group management step, in response to addition of a new detection target system to the system group, the information processing system associates the detection target system with the identifier.
6. 2. The information processing system according to claim 1, The information processing system includes the system to be detected, which is a base server, and the system to be detected, which is a duplicate server obtained by duplicating the base server.
7. 2. The information processing system according to claim 1, In the setting information acquisition step, setting information created during development of software executed in the detection target system is acquired, wherein the setting information includes at least information regarding an execution environment of the software; In the operation information estimation step, operation information of the software is estimated based on the setting information and reference information, wherein the operation information is information representing the execution environment or development language of the software, and the reference information is information regarding the correlation between the setting information and the operation information.
8. 8. The information processing system according to claim 7, In the expiration determination step, the information processing system determines an expiration date of support for the software based on the operation information.
9. 8. The information processing system according to claim 7, the reference information includes a motion information estimation model, which is a generation AI, and correspondence data in which a correspondence between the setting information and the motion information is recorded; In the motion information estimation step, a prompt including an instruction to estimate the motion information corresponding to the setting information based on the correspondence data is input to the motion information estimation model, and the motion information is output to the motion information estimation model.
10. 8. The information processing system according to claim 7, In the setting information acquisition step, the setting information is acquired from a manifest file of the software.
11. 8. The information processing system according to claim 7, In the setting information acquisition step, the setting information is acquired from a file managed in a development environment of the software.
12. 12. The information processing system according to claim 11, In the setting information acquisition step, attribute information of the file is acquired as the setting information; the reference information includes correspondence data in which a correspondence between the attribute information and the action information is recorded, In the motion information estimating step, the motion information is estimated based on the attribute information and the correspondence data.
13. 8. The information processing system according to claim 7, In the edit receiving step, edits of the operation information are received, In the expiration determination step, the information processing system determines an expiration date of support for the software based on the edited operation information.
14. 8. The information processing system according to claim 7, An information processing system, wherein the operational information includes at least one of the name and version of a runtime, framework, or operating system required to execute the software, and the name and version of a development language for the software.
15. 2. The information processing system according to claim 1, a server having the processor; a terminal that can access the server; An information processing system comprising:
16. An information processing method, comprising: An information processing method, wherein an information processing device executes each step of the information processing system according to any one of claims 1 to 15.
17. A program, A program for causing a computer to execute each step of the information processing system according to any one of claims 1 to 15.
Citation Information
Patent Citations
Data packaging method and device, equipment and computer storage medium
CN118054917A
LLM-based ASOC vulnerability assessment method, apparatus and device, and medium
CN118395457A
Diagnostic result integration device and diagnostic result integration program
JP2017167766A
Information processing device, and processing method and program thereof
JP2018055340A
Cyber attack detector
JP2020149390A