Software information management device, software information management method

The software information management device optimizes vulnerability assessment by using databases and search processing to identify and secure software devices, addressing the challenge of incomplete configuration data across multiple information devices.

JP7835641B2Active Publication Date: 2026-03-25HITACHI LTD
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-08-03
Publication Date
2026-03-25

AI Technical Summary

Technical Problem

Existing systems struggle to determine the impact of software vulnerabilities across multiple information devices within an information system due to incomplete software configuration data, making it difficult to assess and manage vulnerabilities effectively.

Method used

A software information management device and method that includes a configuration information database, impact range database, and search processing units to identify and prioritize software devices affected by vulnerabilities, using encryption and searchable encryption to secure and optimize the search process.

Benefits of technology

Enables efficient determination of vulnerability impacts across multiple information devices, reducing processing load, ensuring security, and facilitating secure updates and searches within the information system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007835641000001
    Figure 0007835641000001
  • Figure 0007835641000002
    Figure 0007835641000002
  • Figure 0007835641000003
    Figure 0007835641000003
Patent Text Reader

Abstract

To provide technology for determining the presence or absence of influence on vulnerability information, in relation to an information system composed of a large number of information apparatuses.SOLUTION: A software information management device 1 includes: a configuration information database 71 that stores configuration information indicating software configurations of a plurality of information apparatuses; a communication unit 50 that receives, from a user, vulnerability search information 90 pertaining to vulnerability of a search target and transmits, to the user, a search result based on the vulnerability search information 90; and a search processing unit 63 that searches, on the basis of the vulnerability search information 90 received by the communication unit 50, the configuration information database 71 for an information apparatus which has software related to the vulnerability, and outputs information on the information apparatus found by the search to the communication unit 50 as the search result.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0005]

[0001] The present invention relates to an apparatus and method for managing software information regarding software used in an information system.

Background Art

[0002] Software used in an information system has security defects called vulnerabilities. If the operation of the information system continues while leaving the vulnerabilities unattended, there is a risk of being attacked, such as unauthorized access, by malicious third parties. Therefore, when operating an information system, it is required to continuously collect vulnerability information regarding software vulnerabilities and take countermeasures as necessary.

[0003] In the case of an information system configured by combining one or more software and / or one or more information devices provided by one or more suppliers, the manufacturing company of the information system may not always be able to grasp the software configurations of all information devices in the entire information system. Therefore, there is a need for a technology to appropriately determine the presence or absence of an impact on vulnerability information based on the software configurations of each information device possessed by the information system at the manufacturing company or the operation destination of the information system.

[0004] As a technology for determining the presence or absence of an impact on vulnerability information, for example, Patent Document 1 is known. Patent Document 1 describes a vulnerability determination device that determines whether configuration information of an electronic computer has a relationship with vulnerability information, determines whether configuration information having a relationship with the vulnerability information has a relationship with service setting information, and as a result of this determination, outputs configuration information having a relationship with the service setting information and notifies the system administrator.

Prior Art Documents

Patent Documents

[0005]

Patent Document 1

[0006] In the technology described in Patent Document 1, a computer possesses configuration information about its own software, and a vulnerability assessment device acquires this configuration information to determine whether or not it is related to vulnerability information. However, in the case of an information system consisting of many information devices, it is not always possible to acquire the software configuration information of each information device within the information system, making it difficult to apply the technology described in Patent Document 1.

[0007] This invention is based on the above background and aims to provide a technology for determining whether or not an information system, which is composed of one or more software programs and / or one or more information devices, is affected by vulnerability information. [Means for solving the problem]

[0008] The software information management device according to the present invention is a device for managing software information of an information system having multiple information devices, and includes a configuration information database in which configuration information representing the software configuration of the multiple information devices is stored, Entered into the search information terminal Vulnerability search information related to the vulnerability being searched The aforementioned search information terminal It receives from and the search results based on the vulnerability search information Search information terminal A communication unit that transmits to the communication unit, and a search processing unit that, based on the vulnerability search information received by the communication unit, searches the configuration information database for information devices having software related to the vulnerability, and outputs the information of the searched information devices to the communication unit as the search results, An impact range database storing attribute information representing the software attributes of each of the aforementioned multiple information devices, and an impact range estimation unit that estimates the scope of the vulnerability in the information system based on the impact range database, Equipped with The search processing unit prioritizes the configuration information stored in the configuration information database that corresponds to the scope of impact estimated by the scope of impact estimation unit, and searches for information devices having software containing the vulnerability. . The software information management method according to the present invention provides software information of an information system having multiple information devices. By computer A method of management, The computer inputs the search information into the search terminal. Vulnerability search information related to the vulnerability being searched The aforementioned search information terminal Received from, The computer estimates the scope of the vulnerability in the information system based on an impact database containing attribute information representing the software attributes of each of the multiple information devices, and the computer then...Based on the vulnerability scan information received, Among the configuration information representing the software configurations of the multiple information devices stored in the configuration information database, the configuration information corresponding to the estimated scope of influence is given priority. The aforementioned vulnerability including Information devices with software The aforementioned Search the configuration information database, The aforementioned computer, The information of the information device that was searched is described above Search information terminal Send to: [Effects of the Invention]

[0009] According to the present invention, it is possible to provide a technology for determining whether or not there is an impact on vulnerability information in an information system composed of one or more software programs and / or one or more information devices. [Brief explanation of the drawing]

[0010] [Figure 1] This is a block diagram showing the functional configuration of a software information management system according to one embodiment of the present invention. [Figure 2] This figure shows an example of a configuration information database. [Figure 3] This figure shows an example of an impact scope database. [Figure 4] This figure shows an example of a vulnerability-attribute information mapping database. [Figure 5] This is a diagram showing an example of a supplier database. [Figure 6] This is a sequence diagram showing the processing flow when registering configuration information in a software information management device. [Figure 7] This sequence diagram shows the process flow when specifying software containing vulnerabilities as the target of a search and searching for the impact that software has on the managed information system. [Figure 8] This sequence diagram shows the process flow when a user specifies vulnerability information they have obtained as the search target and searches for the impact that vulnerability information has on the managed information system. [Figure 9]It is a sequence diagram showing the process flow when a supplier of information equipment designates software including vulnerabilities as a search target and searches for the impact of the software on the information equipment. [Figure 10] It is a diagram showing an example of a registration screen for configuration information. [Figure 11] It is a diagram showing an example of a search screen for configuration information.

Mode for Carrying Out the Invention

[0011] Hereinafter, embodiments of the present invention will be described with reference to the drawings.

[0012] FIG. 1 is a block diagram showing the functional configuration of a software information management system according to an embodiment of the present invention. The software information management system S shown in FIG. 1 is a system for managing software information of an information system configured by combining one or more software and / or one or more information devices, such as an automobile. The software information management device 1, the registration information terminal 2, and the search information terminal 3 are connected to each other via a network 4.

[0013] The software information management device 1 includes a control unit 10, an encryption control unit 20, an input unit 30, an output unit 40, a communication unit 50, a program storage unit 60, and a data storage unit 70.

[0014] The control unit 10 is configured using, for example, a CPU (Central Processing Unit) or a GPU (Graphics Processing Unit), and functions as a registration processing unit 61, an impact range estimation unit 62, and a search processing unit 63 by executing a program stored in the program storage unit 60. Details of the registration processing unit 61, the impact range estimation unit 62, and the search processing unit 63 will be described later. In Figure 1, the program storage unit 60 is shown to have the registration processing unit 61, the impact range estimation unit 62, and the search processing unit 63, but in reality, programs corresponding to these functions are stored in the program storage unit 60, and the control unit 10 executes these programs to realize the registration processing unit 61, the impact range estimation unit 62, and the search processing unit 63 in the software information management device 1. Alternatively, programs and data for making the control unit 10 function as the registration processing unit 61, the impact range estimation unit 62, and the search processing unit 63 may be introduced into the software information management device 1 from an external device or a non-volatile storage medium and used in the software information management device 1.

[0015] The encryption control unit 20 performs encryption of input information and decryption of encrypted information. The encryption control unit 20 can perform encryption and decryption processing of information using, for example, well-known encryption algorithms. The encryption control unit 20 may be implemented as hardware independent of the control unit 10, or it may be incorporated into the software information management device 1 as part of the functions of the control unit 10.

[0016] The input unit 30 receives input operations performed by the administrator of the software information management device 1 and outputs the content of those input operations to the control unit 10. The output unit 40, under the control of the control unit 10, outputs predetermined information to the administrator of the software information management device 1, providing the administrator with necessary information. The input unit 30 and the output unit 40 are configured using, for example, a mouse, keyboard, and display.

[0017] The communication unit 50 operates in accordance with the control unit 10 and performs communication interface processing for sending and receiving various types of information between the software information management device 1 and the registration information terminal 2 and the search information terminal 3. Through the communication interface processing performed by the communication unit 50, registration configuration information 80 is transmitted from the registration information terminal 2 and vulnerability search information 90 is transmitted from the search information terminal 3 to the software information management device 1 via the network 4, and information transmitted from the software information management device 1 is transmitted to the registration information terminal 2 and the search information terminal 3 via the network 4.

[0018] The program storage unit 60 and the data storage unit 70 are configured using, for example, large-capacity non-temporary magnetic storage devices such as HDDs (Hard Disk Drives) or SSDs (Solid State Drives), or semiconductor storage devices. The program storage unit 60 stores various programs executed by the control unit 10, and the data storage unit 70 stores various data used in the processing of the control unit 10. The program storage unit 60 and the data storage unit 70 may be implemented using a single common storage device, or they may be implemented using separate storage devices.

[0019] The program storage unit 60 stores programs corresponding to the registration processing unit 61, the impact scope estimation unit 62, and the search processing unit 63, respectively. The registration processing unit 61 acquires the registration configuration information 80 transmitted from the registration information terminal 2 to the software information management device 1 and registers the acquired registration configuration information 80 in the configuration information database 71 held by the data storage unit 70. The impact scope estimation unit 62 estimates the impact scope of the vulnerability represented by the vulnerability information specified by the user in the managed information system. The search processing unit 63 acquires the vulnerability search information 90 transmitted from the search information terminal 3 and searches the configuration information database 71 held by the data storage unit 70 for information devices related to the vulnerability specified in the acquired vulnerability search information 90. The operation of each of these functional blocks in the software information management device 1 realizes the software information management system S of this embodiment.

[0020] The data storage unit 70 stores a configuration information database 71, an impact scope database 72, a vulnerability-attribute information correspondence database 73, and a supplier database 74. The configuration information database 71 is a database that stores configuration information (SBOM: Software Bill of Materials) representing the software configuration of multiple information devices owned by the managed information system. The impact scope database 72 is a database that stores attribute information representing the software attributes of each of the multiple information devices owned by the information system. The vulnerability-attribute information correspondence database 73 is a database that stores vulnerability-attribute information representing the correspondence between publicly available vulnerability information and the attribute information stored in the impact scope database 72. The supplier database 74 is a database that stores supplier information representing the suppliers that provide each of the multiple information devices owned by the information system. Details of these databases will be described later.

[0021] The registration information terminal 2 is an information terminal used by suppliers of each information device constituting the managed information system to register their respective configuration information with the software information management device 1. The configuration information entered by the supplier into the registration information terminal 2 is used in the registration information terminal 2 to create the registered configuration information 80, either in an encrypted state or in an unencrypted state. The created registered configuration information 80 is transmitted from the registration information terminal 2 to the software information management device 1 via the network 4 and registered in the configuration information database 71.

[0022] The search information terminal 3 is an information terminal operated by a user of the software information management system S. For example, the manufacturer or administrator of a managed information system can, as a user of the software information management system S, input information about vulnerabilities to be searched for in that information system into the search information terminal 3. The vulnerability information entered by the user into the search information terminal 3 is transmitted as vulnerability search information 90 to the software information management device 1 via the network 4 and used for searches performed by the software information management device 1.

[0023] Network 4 is configured using, for example, a LAN (Local Area Network), a WAN (Wide Area Network), or the Internet, and transmits data between the software information management device 1, the registration information terminal 2, and the search information terminal 3. The software information management device 1, the registration information terminal 2, and the search information terminal 3 may be installed in the same location or in physically separate locations. Furthermore, these may be implemented on a single computer, or on a virtual computer or cloud service.

[0024] Next, the details of the configuration information database 71, the scope of impact database 72, the vulnerability-attribute information correspondence database 73, and the supplier database 74 will be explained with reference to Figures 2 to 5.

[0025] Figure 2 shows an example of a configuration information database 71. As shown in Figure 2, the configuration information database 71 is configured such that information shown in columns 711 and 712, for example, is recorded for each of the multiple records set for each information device of the managed information system.

[0026] Column 711 records information about the target device name, which is information used to identify each information device. For example, information about the target device name corresponding to the function and role of each information device in the information system is recorded in column 711.

[0027] Column 712 records configuration information representing the software configuration of each information device. The configuration information may be recorded in an encrypted state to prevent easy viewing by third parties, or it may be recorded in an unencrypted state. Furthermore, in order to enable the search processing of the configuration information performed by the search processing unit 63 to be carried out in an encrypted state, the configuration information may be recorded encrypted using a well-known searchable encryption method.

[0028] Figure 3 shows an example of the impact scope database 72. As shown in Figure 3, the impact scope database 72 is configured such that information shown in each column, for example, 721 to 724, is associated with and recorded for multiple records set for each piece of software owned by multiple information devices belonging to the information system being managed.

[0029] Column 721 records information about the parent class representing the classification of the information device corresponding to each software.

[0030] Column 722 records information about the target device name of the information equipment corresponding to each software. This includes information that is the same as, for example, column 711 in Figure 2.

[0031] Column 723 records information representing the supplier name of the information equipment corresponding to each software.

[0032] Column 724 records attribute information representing the attributes of each software.

[0033] Figure 4 shows an example of a vulnerability-attribute information database 73. As shown in Figure 4, the vulnerability-attribute information database 73 is configured such that for each publicly available vulnerability information, multiple records are set up, and the information shown in columns 731 and 732, for example, is recorded.

[0034] Column 731 records the CVE-ID (Common Vulnerabilities and Exposures ID), which is a unique identifier assigned to each vulnerability.

[0035] Column 732 records attribute information representing the attributes of the software affected by each vulnerability. This includes information that is common to, for example, column 724 in Figure 3.

[0036] Figure 5 shows an example of a supplier database 74. As shown in Figure 5, the supplier database 74 is configured such that information shown in columns 741 and 742, for example, is recorded for each of the multiple records set up for each supplier that supplies information equipment installed in the managed information system.

[0037] Column 741 records information representing the name of each supplier. This includes information that is the same as, for example, column 723 in Figure 3.

[0038] Column 742 records information about the target device names of the information equipment supplied by each supplier. This column contains information that is common to, for example, column 711 in Figure 2 and column 722 in Figure 3.

[0039] Next, the processes executed in the software information management system S will be explained with reference to Figures 6 to 9. In the following example, we will describe a case where supplier A supplies the TCU (Telematics Control Unit), one of the various information devices installed in the information system, and this TCU has a TCP / IP stack manufactured by company X implemented on it.

[0040] Figure 6 is a sequence diagram showing the processing flow when registering configuration information in the software information management device 1. The processing shown in the sequence diagram of Figure 6 is executed by the software information management device 1 and the registration information terminal 2 when, for example, the configuration information of the TCU supplied by Company A is input to the registration information terminal 2.

[0041] In step S10, the registration information terminal 2 encrypts the entered configuration information and combines it with the registrant information of Company A to create the registration configuration information 80. As mentioned above, encryption of the configuration information is not mandatory, and the registration configuration information 80 may be created by combining the configuration information and registrant information without encryption. When encrypting, a general encryption method may be used that makes it impossible to perform data searches such as keyword searches in the encrypted state, or a searchable encryption method may be used that enables data searches in the encrypted state. For example, a searchable encryption method such as the one described in Japanese Patent Publication No. 2021-39143 can be used.

[0042] In step S20, the registration configuration information 80 created in step S10 is transmitted from the registration information terminal 2 to the software information management device 1. The registration configuration information 80 transmitted in step S20 is received by the communication unit 50 in the software information management device 1 and passed to the registration processing unit 61. As a result, the configuration information to be registered in the configuration information database 71 is provided to the software information management device 1 from supplier Company A.

[0043] In step S30, the registration processing unit 61 of the software information management device 1 acquires the registration configuration information 80 transmitted from the registration information terminal 2 in step S20. Then, it identifies the target device name of the information equipment from the registrant information contained in the acquired registration configuration information 80. Here, for example, by referring to the scope of influence database 72, the target device name corresponding to the supplier name indicated in the registrant information can be identified. In the example in Figure 6, "TCU" is identified as the target device name in step S30.

[0044] In step S40, the registration processing unit 61 registers the target device name identified in step S30 and the configuration information contained in the registration configuration information 80 obtained in step S20 in the configuration information database 71, associating them with each other. Here, for example, a new record is added to the configuration information database 71 shown in Figure 2, and the target device name is stored in column 711 of this new record, and the configuration information corresponding to the registration configuration information 80 is registered in column 712. As a result, the configuration information obtained from the supplier is registered in the configuration information database 71 of the software information management device 1, either in an encrypted or unencrypted state.

[0045] Figure 7 is a sequence diagram showing the process flow when specifying software containing vulnerabilities as the target of a search and searching for the impact that software has on the managed information system. In the sequence diagram of Figure 7, for example, Company B, an information system manufacturer, obtains publicly available vulnerability information and inputs information such as the software name and version name from that vulnerability information into the search information terminal 3, at which point the software information management device 1 and the search information terminal 3 execute the process.

[0046] In step S110, the search information terminal 3 transmits the entered software name, version name, and other information to the software information management device 1 as vulnerability search information 90. The vulnerability search information 90 transmitted in step S110 is received by the communication unit 50 in the software information management device 1 and passed to the impact scope estimation unit 62 and the search processing unit 63. As a result, Company B, a user of the software information management system S, provides the software information management device 1 with vulnerability search information 90 regarding the vulnerability to be searched. In the example in Figure 7, vulnerability search information 90 indicating that the software name specified as the search target is "X Company TCP / IP stack" is transmitted from the search information terminal 3 to the software information management device 1.

[0047] In step S120, the impact scope estimation unit 62 of the software information management device 1 acquires the vulnerability search information 90 transmitted from the search information terminal 3 in step S110. Then, it extracts attribute information contained in the acquired vulnerability search information 90 and estimates the impact scope of the vulnerability specified in the vulnerability search information 90 based on this. The impact scope of the vulnerability estimated in step S120 is passed from the impact scope estimation unit 62 to the search processing unit 63. Here, for example, by referring to the impact scope database 72, the target device name corresponding to the extracted attribute information can be identified, and that target device name can be estimated as the impact scope of the vulnerability. In the example in Figure 7, in step S120, the attribute information "TCP / IP" is extracted from the vulnerability search information 90, and the target device names "TCU" and "IVI" (In-Vehicle Infotainment) corresponding to this attribute information are identified in the impact scope database 72, thereby estimating the impact scope of the vulnerability.

[0048] In step S130, the search processing unit 63 obtains the vulnerability search information 90 transmitted from the search information terminal 3 in step S110. Then, it searches the configuration information database 71 for configuration information including the name of the software to be searched, which is represented by the obtained vulnerability search information 90. As a result, information devices that have software related to the vulnerability specified as the search target are found in the configuration information database 71.

[0049] In step S130, the search processing unit 63 prioritizes the scope of the vulnerability estimated by the scope of impact unit 62 in step S120 when searching for configuration information. For example, the encryption control unit 20 decrypts only the configuration information corresponding to the scope of impact from the encrypted configuration information stored in the configuration information database 71, and searches for configuration information containing the name of the software to be searched, as represented by the vulnerability search information 90, among the decrypted configuration information. Alternatively, the search targets only the configuration information corresponding to the scope of impact from the configuration information encrypted using searchable encryption in the configuration information database 71, or from the unencrypted configuration information, and searches for configuration information containing the name of the software to be searched, as represented by the vulnerability search information 90. In this way, the search for information devices having software related to the vulnerability specified as the search target can be performed by prioritizing the configuration information corresponding to the scope of impact of the vulnerability estimated by the scope of impact unit 62 from among the configuration information stored in the configuration information database 71.

[0050] However, when performing a search for configuration information prioritizing the scope of the vulnerability's impact in step S130, the search scope does not necessarily have to be limited to the scope of the vulnerability's impact. For example, if, as a result of performing a search for configuration information prioritizing the scope of the vulnerability's impact, no information devices with software related to the specified vulnerability are found, the search may be extended to include configuration information outside the scope of the vulnerability.

[0051] In step S140, the search results obtained in step S130 are sent from the search processing unit 63 to the communication unit 50, which then sends a reply to the search information terminal 3 that sent the vulnerability search information 90 in step S110. As a result, the information of the information device searched in step S130 is sent from the software information management device 1 to the search information terminal 3 as information of an information device having software related to the vulnerability specified as the search target, and is provided to Company B, the user of the software information management system S. In the example in Figure 7, a TCU manufactured by Company A is searched as an information device having the "TCP / IP stack manufactured by Company X" specified as the search target, and the search results indicating that this TCU is affected by the vulnerability are provided to the user via the search information terminal 3.

[0052] Figure 8 is a sequence diagram showing the process flow when a user specifies vulnerability information they have obtained as the search target and searches for the impact that vulnerability information has on the managed information system. The process shown in the sequence diagram of Figure 8 is executed by the software information management device 1 and the search information terminal 3 when, for example, Company B, an information system manufacturer, obtains publicly available vulnerability information and inputs identification information such as the CVE-ID attached to that vulnerability information into the search information terminal 3.

[0053] In step S210, the search information terminal 3 transmits the input identification information, such as the CVE-ID, as vulnerability search information 90 to the software information management device 1. The vulnerability search information 90 transmitted in step S210 is received by the communication unit 50 in the software information management device 1 and passed to the impact scope estimation unit 62 and the search processing unit 63. As a result, Company B, a user of the software information management system S, provides the software information management device 1 with vulnerability search information 90 regarding the vulnerability to be searched. In the example in Figure 8, vulnerability search information 90 indicating that the CVE-ID of the vulnerability information designated as the search target is "CVE-2022-99999" is transmitted from the search information terminal 3 to the software information management device 1.

[0054] In step S220, the impact scope estimation unit 62 of the software information management device 1 acquires the vulnerability search information 90 transmitted from the search information terminal 3 in step S210. Then, using the identification information such as the CVE-ID contained in the acquired vulnerability search information 90, attribute information corresponding to the vulnerability to be searched is extracted from the vulnerability search information 90. Here, for example, by referring to the vulnerability-attribute information correspondence database 73, the attribute information corresponding to the CVE-ID represented by the vulnerability search information 90 can be identified and extracted as the attribute information corresponding to the vulnerability to be searched. In the example in Figure 8, the vulnerability-attribute information correspondence database 73 identifies that the attribute information corresponding to "CVE-2022-99999" is "TCP / IP", and this attribute information is extracted as the attribute information corresponding to the vulnerability to be searched.

[0055] In step S230, the impact scope estimation unit 62 estimates the impact scope of the vulnerability specified in the vulnerability search information 90 based on the attribute information extracted in step S220. The impact scope of the vulnerability estimated in step S230 is passed from the impact scope estimation unit 62 to the search processing unit 63. Here, for example, similar to step S120 in Figure 7, the target device name corresponding to the extracted attribute information can be identified by referring to the impact scope database 72, and that target device name can be estimated as the impact scope of the vulnerability. In the example in Figure 8, in step S230, the target device names "TCU" and "IVI" corresponding to "TCP / IP" extracted in step S220 are identified in the impact scope database 72, and the impact scope of the vulnerability is estimated.

[0056] In step S240, the search processing unit 63 obtains the vulnerability search information 90 transmitted from the search information terminal 3 in step S210. Then, using the identification information such as the CVE-ID contained in the obtained vulnerability search information 90, the software to be searched is identified. For example, the software to be searched can be identified by accessing the servers of public institutions or software companies that publish various vulnerability information and obtaining the vulnerability information corresponding to the identification information. In the example in Figure 8, the software to be searched is identified as "X Company's TCP / IP stack".

[0057] In step S250, the search processing unit 63 searches the configuration information database 71 for configuration information including the name of the software to be searched, which was identified in step S240. This searches the configuration information database 71 for information devices that have software related to the vulnerability specified as the search target.

[0058] In step S250, as in step S130 in Figure 7 above, the search processing unit 63 prioritizes the scope of the vulnerability estimated by the scope of impact estimation unit 62 in step S230 when searching for configuration information.

[0059] In step S260, the search results obtained in step S250 are sent from the search processing unit 63 to the communication unit 50, which then sends a reply to the search information terminal 3 that sent the vulnerability search information 90 in step S210. As a result, the information of the information device searched in step S250 is sent from the software information management device 1 to the search information terminal 3 as information of an information device having software related to the vulnerability specified as the search target, and is provided to Company B, the user of the software information management system S. In the example in Figure 8, a TCU manufactured by Company A is searched as an information device corresponding to the CVE-ID of the vulnerability information specified as the search target, "CVE-2022-99999", and the search results indicating that this TCU is affected by the vulnerability are provided to the user via the search information terminal 3.

[0060] Figure 9 is a sequence diagram showing the process flow when an information equipment supplier designates software containing vulnerabilities as a search target and searches for the impact that software has on the information equipment. In the sequence diagram of Figure 9, for example, supplier Company B obtains publicly available vulnerability information and inputs information such as the software name and version name from that vulnerability information into the search information terminal 3, which is then executed by the software information management device 1 and the search information terminal 3.

[0061] In step S310, the search information terminal 3 transmits the entered software name, version name, and other information as vulnerability search information 90 to the software information management device 1, similar to step S110 in Figure 7. The vulnerability search information 90 transmitted in step S310 is received by the communication unit 50 in the software information management device 1 and passed to the impact scope estimation unit 62 and the search processing unit 63.

[0062] In step S320, the impact scope estimation unit 62 of the software information management device 1 acquires the vulnerability search information 90 transmitted from the search information terminal 3 in step S310. Then, similar to step S120 in Figure 7, attribute information contained in the acquired vulnerability search information 90 is extracted, and based on this, the impact scope database 72 is referred to estimate the impact scope of the vulnerability specified in the vulnerability search information 90.

[0063] In step S330, the impact scope estimation unit 62 sets a search scope limited to each supplier (user) based on the vulnerability's impact scope estimated in step S320. The search scope set in step S330 is passed from the impact scope estimation unit 62 to the search processing unit 63. Here, for example, by referring to the supplier database 74, the search processing unit identifies the target device names of the information equipment supplied to the information system by the supplier that sent the vulnerability search information 90 using the search information terminal 3. Then, only the identified target device names from the target device names estimated as the vulnerability's impact scope in step S320 are set as the search scope for that supplier. In the example in Figure 9, of the target device names "TCU" and "IVI" estimated as the vulnerability's impact scope in step S320, only "TCU" is set as the search scope for company B.

[0064] In step S340, the search processing unit 63 obtains the vulnerability search information 90 transmitted from the search information terminal 3 in step S310. Then, it searches the configuration information database 71 for the configuration information, including the name of the software to be searched, which is represented by the obtained vulnerability search information 90, limiting the search range to the range set by the impact range estimation unit 62 in step S330. As a result, information devices having software related to the vulnerability specified as the search target are found in the configuration information database 71.

[0065] In step S350, the search results obtained in step S340 are sent from the search processing unit 63 to the communication unit 50, and the communication unit 50 sends a reply to the search information terminal 3 that sent the vulnerability search information 90 in step S310. As a result, the information of the information device searched in step S340 is sent from the software information management device 1 to the search information terminal 3 as information of an information device having software related to the vulnerability specified as the search target, and is provided to Company B, the user of the software information management system S. In the example in Figure 9, as in the case of Figure 7 above, a TCU manufactured by Company A is searched as an information device having the "TCP / IP stack manufactured by Company X" specified as the search target, and the search results indicating that this TCU is affected by the vulnerability are provided to the user via the search information terminal 3.

[0066] In the software information management system S of this embodiment, the software information of an information system having multiple information devices is managed by the software information management device 1, the registration information terminal 2, and the search information terminal 3, respectively, performing the processes described above. This makes it possible for users such as the manufacturer, administrator, and suppliers of information devices to easily determine whether or not there is an impact on vulnerability information for an information system consisting of many information devices.

[0067] Next, an example of a display screen in the software information management system S will be described below with reference to Figures 10 and 11.

[0068] Figure 10 shows an example of a configuration information registration screen. The registration screen 100 shown in Figure 10 is a screen displayed on the registration information terminal 2 when a supplier inputs configuration information for the information equipment they provide, for example, before the start of the process shown in the sequence diagram in Figure 6. This registration screen 100 is presented to the supplier, for example, by being displayed on a display (not shown) of the registration information terminal 2, and functions as a user interface for inputting configuration information to be registered in the configuration information database 71.

[0069] The registration screen 100 includes input fields 101 to 103 and a registration button 104. Input field 101 is for entering the file name of the configuration information to be registered. Input field 102 is for entering the supplier name from the registrant information. Input field 103 is for entering the target device name from the registrant information. The supplier can input the configuration information to be registered in the configuration information database 71 by operating an input device (not shown, such as a mouse or keyboard) on the registration information terminal 2 and entering this information in input fields 101 to 103.

[0070] The registration button 104 is an operation button used to instruct the registration of the entered configuration information. When the supplier enters the necessary information into input fields 101 to 103 on the registration screen 100 and selects the registration button 104, the entered information is registered on the registration information terminal 2, the registered configuration information 80 is created and sent to the software information management device 1.

[0071] Figure 11 shows an example of a configuration information search screen. The search screen 110 shown in Figure 11 is a screen displayed on the search information terminal 3 when a user, such as the manufacturer or administrator of the information system, specifies the software to be searched, for example, before the start of the process shown in the sequence diagram in Figure 7. This search screen 110 is presented to the user, for example, by being displayed on a display (not shown) of the search information terminal 3, and functions as a user interface for inputting search conditions for software that may contain vulnerabilities.

[0072] The search screen 110 includes an input field 111, a search results display field 112, and a confirmation button 113. The input field 111 is for entering search conditions as a query to the software information management device 1. The confirmation button 113 is an operation button that instructs the user to confirm whether or not the vulnerability based on the entered search conditions will have an impact on the information system. When a user enters search conditions in the input field 111 on the search screen 110 and selects the confirmation button 113, vulnerability search information 90 corresponding to those search conditions is created and sent to the software information management device 1.

[0073] The search results display frame 112 is the section for displaying search results. When the software information management device 1 performs a search for configuration information based on the vulnerability search information 90 transmitted from the search information terminal 3, and the results are transmitted from the software information management device 1 to the search information terminal 3, the contents of the transmitted search results are displayed in the search results display frame 112. By checking the contents of the search results display frame 112, the user can confirm whether or not the vulnerability corresponding to the specified search conditions has an impact on the information system, and if so, the scope of the impact on the information system.

[0074] According to the embodiment of the present invention described above, the following effects can be obtained.

[0075] (1) The software information management device 1 is a device that manages software information for an information system having multiple information devices. The software information management device 1 includes a configuration information database 71 in which configuration information representing the software configuration of multiple information devices is stored, a communication unit 50 that receives vulnerability search information 90 related to the vulnerability to be searched from the user and transmits search results based on the vulnerability search information 90 to the user, and a search processing unit 63 that searches the configuration information database 71 for information devices having software related to the vulnerability based on the vulnerability search information 90 received by the communication unit 50 and outputs the information of the searched information devices to the communication unit 50 as a search result. In this way, it is possible to determine whether or not there is an impact on the vulnerability information for an information system consisting of a large number of information devices.

[0076] (2) The software information management device 1 includes an impact range database 72 in which attribute information representing the attributes of software possessed by multiple information devices is stored, and an impact range estimation unit 62 that estimates the impact range of a vulnerability in an information system based on the impact range database 72. The search processing unit 63 searches for information devices that have software related to the vulnerability, prioritizing the configuration information from the configuration information database 71 that corresponds to the impact range estimated by the impact range estimation unit 62 (steps S130, S250). In this way, the scope of the search for configuration information from the configuration information database 71 can be narrowed, thereby reducing the processing load.

[0077] (3) The search processing unit 63 searches for information devices having software related to the vulnerability, limiting the search to configuration information corresponding to the scope of impact from the configuration information database 71. Specifically, the software information management device 1 includes a supplier database 74 in which supplier information representing suppliers that provide multiple information devices is stored. If the user is a supplier of one of the multiple information devices, the scope of impact estimation unit 62 sets the search scope for that supplier within the scope of impact based on the supplier database 74 (step S330). The search processing unit 63 searches for information devices having software related to the vulnerability, limiting the search to configuration information corresponding to the search scope set in step S330 from the configuration information database 71 (step S340). In this way, if the user is a supplier, the scope of the search for configuration information from the configuration information database 71 can be limited to the scope of information devices provided by that supplier, thereby preventing the erroneous disclosure of configuration information of information devices unrelated to that supplier and ensuring security.

[0078] (4) The software information management device 1 includes a registration processing unit 61 that acquires configuration information provided by each supplier of multiple information devices and registers the acquired configuration information in the configuration information database 71. In this way, the contents of the configuration information database 71 can be updated as appropriate using the configuration information provided sequentially by the suppliers.

[0079] (5) The registration processing unit 61 can obtain encrypted configuration information from the supplier and register it in the configuration information database 71. In this way, the leakage of configuration information can be prevented and security can be ensured.

[0080] (6) The software information management device 1 includes an encryption control unit 20 that decrypts the configuration information registered in the configuration information database 71 in an encrypted state, within the scope of its impact. The search processing unit 63 can search for information devices having software related to the vulnerability from the configuration information decrypted by the encryption control unit 20 (step S130). In this way, when the configuration information is registered in the configuration information database 71 in an encrypted state, only the necessary configuration information can be decrypted and searched. Therefore, the processing load can be reduced and speed can be increased, and security can be improved by further strengthening the prevention of leakage of configuration information.

[0081] (7) The registration processing unit 61 can also obtain configuration information encrypted using searchable encryption from the supplier and register it in the configuration information database 71. In this case, the search processing unit 63 searches for information devices having software related to the vulnerability from the configuration information that is included in the scope of impact among the configuration information registered in the configuration information database 71 in an encrypted state (step S130). In this way, even if the configuration information is registered in the configuration information database 71 in an encrypted state, a search can be performed without decryption. Therefore, the processing load can be further reduced and the speed can be increased.

[0082] (8) The software information management device 1 includes a vulnerability-attribute information correspondence database 73 in which vulnerability-attribute information representing the correspondence between publicly available vulnerability information and attribute information is stored. The impact scope estimation unit 62 extracts attribute information corresponding to the vulnerability information specified in the vulnerability search information 90 from the vulnerability-attribute information correspondence database 73 (step S220), and estimates the impact scope based on the extracted attribute information (step S230). In this way, when a search is performed using publicly available vulnerability information, the impact scope of the vulnerability represented by that vulnerability information can be appropriately estimated.

[0083] It should be noted that the present invention is not limited to the embodiments described above, and various modifications are possible without departing from the spirit of the invention. For example, the embodiments described above are described in detail for the purpose of clearly illustrating the present invention, and are not necessarily limited to those having all the configurations described. Furthermore, it is possible to add, delete, or replace some of the configurations of the above embodiments with other configurations.

[0084] Furthermore, each of the above-mentioned configurations, functional units, processing units, processing means, etc., may be implemented in hardware, in whole or in part, for example, by designing them as integrated circuits. Alternatively, each of the above-mentioned configurations, functions, etc., may be implemented in software by having the processor interpret and execute programs that realize each function. Information such as programs, tables, and files that realize each function can be stored in memory, hard disks, SSDs, or other recording devices, or in recording media such as IC cards, SD cards, or DVDs.

[0085] Furthermore, in the diagrams above, the control lines and information lines shown are those deemed necessary for explanation and do not necessarily represent all control lines and information lines that would be present in a real-world implementation. For example, it can be assumed that almost all components are interconnected in practice.

[0086] Furthermore, the arrangement of the various functional units, processing units, and databases described above is merely an example. The arrangement of the various functional units, processing units, and databases can be changed to the optimal arrangement from the perspective of the performance, processing efficiency, and communication efficiency of the hardware and software of these devices. [Explanation of symbols]

[0087] 1: Software information management device, 2: Registration information terminal, 3: Search information terminal, 4: Network, 10: Control unit, 20: Cryptographic control unit, 30: Input unit, 40: Output unit, 50: Communication unit, 60: Program storage unit, 61: Registration processing unit, 62: Impact scope estimation unit, 63: Search processing unit, 70: Data storage unit, 71: Configuration information database, 72: Impact scope database, 73: Vulnerability-attribute information correspondence database, 74: Supplier database, 80: Registered configuration information, 90: Vulnerability search information

Claims

1. A device for managing software information of an information system having multiple information devices, A configuration information database containing configuration information representing the software configurations of the aforementioned multiple information devices, A communication unit that receives vulnerability search information regarding the target vulnerability entered into the search information terminal from the search information terminal and transmits search results based on the vulnerability search information to the search information terminal, A search processing unit, based on the vulnerability search information received by the communication unit, searches the configuration information database for information devices having software containing the vulnerability, and outputs the information of the searched information devices to the communication unit as the search results. A database of influence containing attribute information representing the software attributes of each of the aforementioned multiple information devices, The system includes an impact range estimation unit that estimates the impact range of the vulnerability in the information system based on the impact range database, The search processing unit is a software information management device that searches for information devices having software containing the vulnerability, prioritizing the configuration information among the configuration information stored in the configuration information database that corresponds to the scope of impact estimated by the scope of impact estimation unit.

2. A software information management device according to claim 1, The search processing unit is a software information management device that searches for information devices having software containing the vulnerability, limited to the configuration information corresponding to the scope of impact among the configuration information stored in the configuration information database.

3. A software information management device according to claim 2, The system includes a supplier database containing supplier information representing each of the suppliers that provide the aforementioned multiple information devices, The impact scope estimation unit, if the user who entered the vulnerability search information into the search information terminal is a supplier of one of the multiple information devices, sets the search scope for that supplier within the impact scope based on the supplier database. The search processing unit is a software information management device that searches for information devices having software containing the vulnerability, limited to the configuration information corresponding to the search range among the configuration information stored in the configuration information database.

4. A software information management device according to claim 1, A software information management device comprising a registration processing unit that acquires the configuration information entered into a registration information terminal from the registration information terminal and registers the acquired configuration information in the configuration information database.

5. A software information management device according to claim 4, The registration processing unit is a software information management device that obtains the encrypted configuration information from the registration information terminal and registers it in the configuration information database.

6. A software information management device according to claim 5, The system includes an encryption control unit that decrypts the configuration information registered in the configuration information database in an encrypted state with respect to the scope of influence, The search processing unit is a software information management device that searches for information devices having software containing the vulnerability from the configuration information decrypted by the encryption control unit.

7. A software information management device according to claim 5, The registration processing unit obtains the configuration information encrypted using searchable encryption from the registration information terminal and registers it in the configuration information database. The search processing unit is a software information management device that searches for information devices having software containing the vulnerability from among the configuration information registered in the configuration information database in an encrypted state, which is included in the scope of influence.

8. A software information management device according to claim 1, The system includes a vulnerability-attribute information correspondence database in which vulnerability-attribute information is stored, representing the correspondence between publicly available vulnerability information and the attribute information. The impact scope estimation unit is a software information management device that extracts attribute information corresponding to the vulnerability information specified in the vulnerability search information from the vulnerability-attribute information correspondence database and estimates the impact scope based on the extracted attribute information.

9. A method for managing software information of an information system having multiple information devices using a software information management device, The aforementioned software information management device receives vulnerability search information regarding the target vulnerability entered into the search information terminal from the search information terminal, The software information management device estimates the scope of the vulnerability in the information system based on an impact scope database in which attribute information representing the attributes of the software each of the multiple information devices has is stored. Based on the vulnerability search information received, the software information management device searches the configuration information database for information devices having software containing the vulnerability, prioritizing the configuration information corresponding to the estimated scope of impact among the configuration information representing the software configuration of the plurality of information devices stored in the configuration information database. A software information management method comprising transmitting the information of the information device retrieved by the software information management device to the search information terminal.

Citation Information

Patent Citations

  • Vulnerability determination device and program

    JP2010067216A

  • Vulnerability coping priority display device and program

    JP2010086311A

  • Information processor, information processing method, and program

    JP2018163537A

  • Asset information management system, and asset information management method

    JP2021144639A