Threat and vulnerability assessment methods, threat and vulnerability assessment programs, and threat and vulnerability assessment systems

The method improves vulnerability assessment for IoT devices by using CPE data format conversion and fuzzy matching to accurately determine the impact scope of threats and vulnerabilities, addressing notation inconsistencies.

JP7833387B2Active Publication Date: 2026-03-19HITACHI LTD
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-11-09
Publication Date
2026-03-19

AI Technical Summary

Technical Problem

Existing vulnerability assessment methods for IoT devices struggle with inaccurate estimation of threat and vulnerability impact due to variations in keyword notation between threat and vulnerability information and software configuration data.

Method used

A threat/vulnerability determination method involving a matching phrase extraction, configuration information label acquisition, and ambiguous matching processing to enhance accuracy by using CPE data format conversion and related estimation information.

Benefits of technology

Accurately estimates the scope of impact of threats and vulnerabilities on IoT devices, including secondary damage assessment through CPE matching and fuzzy matching processes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007833387000001
    Figure 0007833387000001
  • Figure 0007833387000002
    Figure 0007833387000002
  • Figure 0007833387000003
    Figure 0007833387000003
Patent Text Reader

Abstract

To accurately estimate an influence range of threat and vulnerability on software implemented on a device.SOLUTION: A threat and vulnerability determination method includes: a matching phrase extraction step of extracting a matching phrase from threat / vulnerability information related to vulnerability of software implemented on a device against threat, collected from an external information source; a configuration information label acquisition step of acquiring product configuration information from product information including product configuration information representing instance information for software that was created on the basis of a software component table and a configuration information label which classifies multiple pieces of product configuration information and groups the pieces of instance information; and an ambiguity matching processing step of referencing relevance estimation information in which the product configuration information associated with the configuration information label is listed, converting the configuration information label acquired in the configuration information label acquisition step to the product configuration information, and determining whether or not a matching phrase agreeing with the converted product configuration information exists.SELECTED DRAWING: Figure 8
Need to check novelty before this filing date? Find Prior Art

Citation Information

Patent Citations

  • Vulnerability management system and program

    JP2020021309A

  • Method for verifying vulnerabilities of network devices using CVE entries

    JP2022105474A

  • System and method for extracting information from binary files for vulnerability database queries

    US10762214B1