Evaluation device, operator terminal, evaluation system, evaluation method, and program
The evaluation device and system address the lack of uniformity in network equipment trustworthiness assessments by using user-specific indicators to inspect and validate the trustworthiness of network devices, ensuring reliable evaluations.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- NEC CORP
- Filing Date
- 2022-09-29
- Publication Date
- 2026-04-21
AI Technical Summary
Existing vulnerability scoring methods for network equipment lack a uniform standard that considers the perspective of the user business operator, leading to inconsistent trustworthiness evaluations.
An evaluation device and system that acquires trust evaluation indicators from the user's perspective, inspects network devices based on these indicators, and outputs a certificate with an electronic signature to validate the trustworthiness evaluation results.
Provides a standardized method for evaluating network equipment trustworthiness from the user's viewpoint, ensuring reliable and consistent assessment of network equipment trustworthiness.
Smart Images

Figure 0007848881000001 
Figure 0007848881000002 
Figure 0007848881000003
Abstract
Description
Technical Field
[0006] , ,
[0007] , ,
[0001] The present disclosure relates to an evaluation device, a business operator terminal, an evaluation system, an evaluation method, and a recording medium.
Background Art
[0002] The performance regarding the safety and reliability of network equipment delivered from the developer of the network equipment is uniformly evaluated according to predetermined guidelines.
[0003] For example, Patent Document 1 discloses a technique for individually quantifying the vulnerability of each of at least one network device based on the result of the network device being attacked and deriving a vulnerability score.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] However, in the invention described in Patent Document 1, the vulnerability score is calculated based on the judgment criteria from the perspective of the side evaluating the vulnerability. The trustworthiness (reliability) of network equipment varies depending on the evaluation perspective and concept, and cannot be properly evaluated with a uniform standard. It is necessary to evaluate based on the indicators considered by the user business operator who introduces the network equipment into the system.
[0006] An example of the object of the present disclosure is to provide an evaluation device capable of evaluating the trustworthiness required by each user business operator.
Means for Solving the Problems
[0007] An evaluation apparatus in one aspect of this disclosure includes: an evaluation index acquisition means for acquiring a trust evaluation index for evaluating the trustworthiness of a user business operator; an equipment information acquisition means for acquiring equipment information of a network device to be evaluated; an inspection means for inspecting the network device using the equipment information based on the trust evaluation index; an evaluation means for evaluating trustworthiness based on the inspection results; and an output means for outputting the trustworthiness evaluation results.
[0008] An evaluation system in one aspect of the present disclosure is an evaluation system comprising a device information storage device for storing device information of network devices and the evaluation device described above, wherein the evaluation device includes: an evaluation index acquisition means for acquiring a trust evaluation index for evaluating the trustworthiness according to the user business operator; an information acquisition means for acquiring device information of network devices to be evaluated from the device information storage device; an inspection means for inspecting network devices using the device information based on the trust evaluation index; an evaluation means for evaluating trustworthiness based on the inspection results; and an output means for issuing a certificate to prove the trustworthiness evaluation result, and storing the certificate with an electronic signature in the device information storage device.
[0009] An evaluation method in one aspect of this disclosure involves a computer acquiring trust evaluation indicators for evaluating trustworthiness according to the user business operator, acquiring device information of the network equipment to be evaluated, inspecting the network equipment using the device information based on the trust evaluation indicators, evaluating trustworthiness based on the inspection results, and outputting the trustworthiness evaluation results.
[0010] A recording medium in one aspect of this disclosure stores a program that causes a computer to perform the following actions: acquire trust evaluation indicators for evaluating trustworthiness according to the user business operator; acquire device information of network equipment to be evaluated; inspect the network equipment using the device information based on the trust evaluation indicators; evaluate trustworthiness based on the inspection results; and output the trustworthiness evaluation results. [Effects of the Invention]
[0011] One example of the benefits of this disclosure is the ability to provide an evaluation device that can assess the level of trust required by user businesses. [Brief explanation of the drawing]
[0012] [Figure 1] Figure 1 is a block diagram showing the configuration of the evaluation system in the first embodiment. [Figure 2] Figure 2 shows the hardware configuration of the evaluation device in the first embodiment, which is implemented using a computer and its peripheral devices. [Figure 3] Figure 3 is a flowchart of the evaluation system in the first embodiment. [Modes for carrying out the invention]
[0013] Next, embodiments will be described in detail with reference to the drawings.
[0014] [First Embodiment] The evaluation device 100 in the first embodiment is a device for evaluating the trustworthiness of network equipment, for example, for a user business that is considering introducing specific network equipment into its system. The evaluation device 100 may evaluate trustworthiness not only when a user business newly purchases specific network equipment, but also when the configuration of network equipment changes, such as when the software version of the network equipment is upgraded. Network equipment refers to devices that relay or transfer data on a network, such as routers, hubs, gateways, or switches.
[0015] The evaluation system 10 in this embodiment includes an evaluation device 100, a business terminal 200 of a user business that requests the evaluation device 100 to inspect network equipment, and a device information storage device 300 that stores device information for each network device. The device information storage device 300 is owned by a platform business that manages the device information for each network device. The user business may, for example, request a third-party evaluation organization to evaluate the trustworthiness of the network equipment through the platform business.
[0016] The operator terminal 200 includes an evaluation index transmission unit 201, a matching unit 202, and a determination unit 203, which transmit trust evaluation indicators adopted by the user operator.
[0017] The device information storage device 300 stores at least the configuration information and inspection information of the network equipment as device information. The device information stored in the device information storage device 300 is updated in accordance with the version upgrade of the network equipment.
[0018] Figure 1 is a block diagram showing the configuration of the evaluation device 100 in the first embodiment. Referring to Figure 1, the evaluation device 100 includes an evaluation index acquisition unit 101, an equipment information acquisition unit 102, an inspection unit 103, an evaluation unit 104, and an output unit 105. The evaluation device 100, which is an essential component of this embodiment, will be described in detail below.
[0019] Figure 2 shows an example of a hardware configuration in which the evaluation device 100 in the first embodiment of this disclosure is realized with a computer device 500 including a processor. As shown in Figure 2, the evaluation device 100 includes a CPU (Central Processing Unit) 501, memory such as ROM (Read Only Memory) 502 and RAM (Random Access Memory) 503, a storage device 505 such as a hard disk for storing a program 504, a communication I / F (Interface) 508 for network connection, and an input / output interface 511 for input and output of data. In the first embodiment, the trust evaluation index acquired by the evaluation index acquisition unit 101 mark It is input into the evaluation device 100 via, for example, the communication I / F 508.
[0020] The CPU 501 operates the operating system to control the entire evaluation device 100 according to the first embodiment of the present invention. Further, the CPU 501 reads programs and data from the recording medium 506 mounted on, for example, the drive device 507 into the memory. Also, the CPU 501 functions as the evaluation index acquisition unit 101, the device information acquisition unit 102, the inspection unit 103, the evaluation unit 104, the output unit 105 in the first embodiment, and executes the processes or instructions in the flowchart shown in FIG. 3 described later based on the program.
[0021] The recording medium 506 is, for example, an optical disk, a flexible disk, a magneto-optical disk, an external hard disk, or a semiconductor memory. A part of the recording medium of the storage device is a non-volatile storage device, and a program is recorded therein. Further, the program may be downloaded from an external computer (not shown) connected to the communication network.
[0022] The input device 509 is realized by, for example, a mouse, a keyboard, a built-in key button, etc., and is used for input operations. The input device 509 is not limited to a mouse, a keyboard, or a built-in key button, and may be, for example, a touch panel. The output device 510 is realized by, for example, a display and is used to confirm the output.
[0023] As described above, the first embodiment shown in Figure 1 is realized by the computer hardware shown in Figure 2. However, the means for realizing each part of the evaluation device 100 in Figure 1 are not limited to the configuration described above. The evaluation device 100 may also be realized by a single physically coupled device, or by two or more physically separated devices connected by wired or wireless connections. For example, the input device 509 and the output device 510 may be connected to the computer device 500 via a network. Furthermore, the evaluation device 100 in the first embodiment shown in Figure 1 can also be configured using cloud computing or the like.
[0024] In Figure 1, the evaluation index acquisition unit 101 is a means for acquiring trust evaluation indicators to evaluate the trustworthiness of a user business. In this embodiment, the evaluation index acquisition unit 101 acquires trust evaluation indicators from the evaluation index transmission unit 201 via the network.
[0025] Trustworthiness refers to the reliability of an entire network composed of multiple network devices, for example, the reliability of maintaining the stable operation of the entire network. Trust evaluation indicators are perspectives for evaluating trustworthiness, and include the presence or absence of malicious functions in network devices, inspection status, and the visibility of configuration information.
[0026] Examples of trust evaluation indicators include the following (1) to (4): (1) the presence or absence of backdoors, (2) the status of risk assessment inspections, (3) the visibility of network equipment developers, and (4) the status of inspections along the supply chain.
[0027] In the examples (1) to (4) above, the evaluation criteria for the trust evaluation metrics may differ. For example, (1) regarding the presence or absence of backdoors, the evaluation criteria may be to analyze the binary code to ensure that no functions or processes that would constitute a backdoor are included, or to analyze the source code to ensure that no backdoors are included. A backdoor refers to a hidden or additional function that the user is unaware of, and is an unauthorized function within the software.
[0028] (2) Regarding the status of risk assessment inspections, the evaluation criteria may include eliminating all detected vulnerabilities, or it may be considered sufficient if the risks associated with the vulnerabilities and countermeasures are understood. Furthermore, these evaluation criteria may be set based on the degree of impact on the user business if the system with network equipment installed goes down. For example, if the system goes down, there is a risk of information leakage of confidential information or a risk to human life, so the evaluation criteria applied may be made stricter. Note that a vulnerability refers to a security flaw in the hardware or software of network equipment caused by design errors, program defects, etc., and includes publicly available information.
[0029] (3) Regarding the visibility of network equipment developers, the evaluation criteria may include clearly identifying all developer attributes, or it may be sufficient to identify areas where developer information is unclear. Alternatively, the evaluation criteria may include whether the developer belongs to a specific country or company, or whether it belongs to a specific country or company.
[0030] (4) Regarding the inspection status in the supply chain, the evaluation criteria may include clearly stating the inspection results of all businesses in the network equipment supply chain, or it may include identifying areas where inspection results are unavailable or where inspections have not been conducted. In addition, the number of inspections conducted during the development phase, rather than the final product, may be included as a trust evaluation metric.
[0031] Trust evaluation indicators are evaluation indicators for evaluating the trustworthiness of network equipment in accordance with the needs of user businesses. For example, trust evaluation indicators are evaluation indicators for the above-mentioned trustworthiness items, such as "presence or absence of backdoors." Trust evaluation indicators may be a single evaluation indicator, a set of multiple evaluation indicators, an integrated evaluation indicator, or an evaluation indicator calculated using multiple evaluation indicators such as an average. User businesses may create trust evaluation indicators in accordance with the trustworthiness they require for the network composed of the network equipment they will install, or they may obtain trust evaluation indicators from a third-party organization or platform provider. The evaluation indicator acquisition unit 101 outputs the acquired trust evaluation indicators to the inspection unit 103.
[0032] The device information acquisition unit 102 is a means for acquiring device information of network devices under evaluation. For example, the device information acquisition unit 102 acquires device information of network devices under evaluation from the device information storage device 300. Device information is information necessary for evaluating the trustworthiness of network devices and includes configuration information and inspection information. For example, the device information storage device 300 stores configuration information and inspection information associated with each network device.
[0033] Configuration information includes, for example, hardware and software information for network equipment. Hardware information includes developer information, model numbers of chips, boards, ports, etc. that make up the hardware, and identifiers assigned to the hardware. Software information includes developer information, the operating system (OS) that processes the hardware, the name of the software such as libraries or applications, the version information of that software, and the code information of the software. Configuration information is updated when the configuration information is updated, such as when the software is updated to a new version.
[0034] Inspection information refers to information regarding the results of inspections conducted by businesses in the supply chain, from the procurement of network equipment components to delivery, based on the configuration information of the network equipment. Inspection information includes the backdoor inspection or risk assessment inspection mentioned above. When the equipment information acquisition unit 102 acquires the equipment information of the network equipment to be evaluated, it outputs it to the inspection unit 103.
[0035] The inspection unit 103 is a means of inspecting network equipment using equipment information based on trust evaluation indicators. The specific inspection method is as follows: The inspection unit 103 creates inspection items for network equipment to evaluate the trustworthiness of the network based on configuration information and trust evaluation indicators. For example, the inspection unit 103 creates inspection items to evaluate the trust evaluation indicators for the network equipment to be evaluated.
[0036] For example, if the trust evaluation metric is the presence or absence of a backdoor, the inspection unit 103 will create an inspection item to check for the possibility of a backdoor in the equipment being inspected. The inspection unit 103 may create multiple inspection items for a single trust evaluation metric, or it may create one inspection item for multiple trust evaluation metrics.
[0037] Next, the inspection unit 103 inspects the network equipment for each created inspection item using the evaluation criteria of the trust evaluation index. The inspection unit 103 may indicate the inspection results for each trust evaluation index as a binary value of 0 or 100, or as a specific rank such as A to C. Alternatively, the inspection unit 103 may indicate the inspection results for each trust evaluation index as a numerical value (score) such as 0 to 100%.
[0038] The evaluation unit 104 is a means of evaluating trustworthiness based on the inspection results. The evaluation unit 104 comprehensively evaluates the trustworthiness of network equipment based on the inspection results of each trust evaluation index.
[0039] The evaluation unit 104 evaluates trustworthiness, for example, by calculating the sum or average value of the inspection results for each trust evaluation indicator. The evaluation unit 104 may also determine that trustworthiness is not met if the inspection result for any of the trust evaluation indicators is 0, or if the inspection result for a predetermined trust evaluation indicator falls below a certain level. However, the evaluation method of trustworthiness by the evaluation unit 104 is not limited to these.
[0040] The output unit 105 is a means for outputting the trustworthiness evaluation results of network equipment. For example, the output unit 105 displays the trustworthiness evaluation results on an output device 510 such as a display. The output unit 105 may also output the trustworthiness evaluation results of network equipment to the user business operator. The output unit 105 may also issue a certificate to prove the trustworthiness evaluation results. The certificate is issued to a third party, including the user business operator, to prove the trustworthiness evaluation results of the network equipment. In this case, the output unit 105 electronically signs the certificate containing the trustworthiness evaluation results and stores it in the device information storage device 300 along with the public key.
[0041] Next, the configuration of the carrier terminal 200 will be described. The carrier terminal 200 performs the processing up to the decision on the operation of the network equipment when a certificate of trust evaluation results is issued by the output unit 105. The verification unit 202 is a means of verifying whether the delivered network equipment is the same as the evaluated network equipment using the issued certificate after the network equipment has been delivered. Specifically, the verification unit 202 decrypts the hash value of the electronic signature contained in the certificate in the equipment information storage device 300 using a public key and compares it with the hash value distributed by the network equipment developer to verify the identity with the network equipment delivered by the developer. If the two network devices are not the same, the verification unit 202 requests the developer to deliver network equipment that is the same as the evaluated network equipment.
[0042] The decision unit 203 is a means for determining the operation of network equipment based on the trust evaluation results. The decision unit 203 may decide to operate network equipment if the trust evaluation results are above a predetermined threshold. Alternatively, the decision unit 203 may decide to operate the network equipment with the highest trust evaluation result from among multiple network equipment.
[0043] The operation of the evaluation device 100, configured as described above, will be explained with reference to the flowchart in Figure 3.
[0044] Figure 3 is a flowchart outlining the operation of the evaluation device 100 in the first embodiment. Note that the processing shown in this flowchart may be executed based on the program control by the processor described above.
[0045] As shown in Figure 3, first, the evaluation index transmission unit 201 in the carrier terminal 200 transmits trust evaluation indexes to the evaluation device 100 for evaluating trustworthiness (step S101). Next, the evaluation index acquisition unit 101 in the evaluation device 100 acquires the trust evaluation indexes from the carrier terminal 200 (step S102). Next, the equipment information acquisition unit 102 acquires equipment information of the network equipment to be evaluated (step S103). Next, the inspection unit 103 inspects the network equipment based on the trust evaluation indexes (step S104). Next, the evaluation unit 104 evaluates trustworthiness based on the inspection results (step S105). Next, the output unit 105 issues a certificate to prove the trustworthiness evaluation result (step S106).
[0046] Meanwhile, the verification unit 202 in the carrier terminal 200 verifies, using a certificate issued after the network equipment has been delivered, whether the delivered network equipment is identical to the evaluated network equipment (step S107). Finally, the decision unit 203, after verification, decides on the operation of the network equipment based on the trust evaluation result (step S108). With this, the evaluation device 100 terminates its operation.
[0047] In this embodiment, the evaluation device 100 includes an evaluation index acquisition unit 101 that acquires trust evaluation indexes from the user business operator, an inspection unit 103 that inspects network equipment based on the trust evaluation indexes, and an evaluation unit 104 that evaluates the trustworthiness based on the inspection results. This makes it possible to evaluate the trustworthiness required by the user business operator.
[0048] Furthermore, in this embodiment, the output unit 105 issues a certificate by attaching an electronic signature to the trustworthiness evaluation result. This ensures the legitimacy of the trustworthiness evaluation result. User businesses that have obtained a trustworthiness certificate can use legitimate trustworthiness evaluation results and therefore consider introducing network equipment based on highly reliable trustworthiness evaluation results.
[0049] A modified version of this embodiment will be described, focusing on the differences from the first embodiment. In the first embodiment, the evaluation index acquisition unit 101 acquired trust evaluation indicators from the user business. In contrast, in the modified version, the evaluation index acquisition unit 101 may evaluate the validity of the trust evaluation indicators acquired from the user business, and if they are valid, use those trust evaluation indicators. That is, the evaluation index acquisition unit 101 outputs the trust evaluation indicators to the inspection unit 103 if the trust evaluation indicators acquired from the user business are valid.
[0050] Furthermore, the evaluation indicator acquisition unit 101 may acquire trust evaluation indicators created by trend analysis of trust evaluation indicators adopted by other businesses that are similar to the user business in terms of size, business type, industry, or business type. These trust evaluation indicators are created by trend analysis based on trust evaluation indicators submitted by other user businesses, tailored to the size, business type, industry, or business type of each user company, and are stored, for example, in the storage device 505. As an example of the created trust evaluation indicators, for example, if a certain percentage of businesses in the same industry use a specific trust evaluation indicator to evaluate trustworthiness, that trust evaluation indicator will be included. More specifically, if a particular industry places importance on the visibility of network equipment developers and uses the fact that the developer's attributes are not from a specific country as an evaluation criterion, such a trust evaluation indicator will be included. In particular, if the trust evaluation indicators acquired from the user business are not appropriate, the evaluation indicator acquisition unit 101 may present the above-mentioned trust evaluation indicators to the user business and have them adopted.
[0051] Although the present invention has been described above with reference to the embodiments described, the present invention is not limited to the above embodiments. Various modifications to the configuration and details of the present invention can be made that will be understood by those skilled in the art within the scope of the present invention.
[0052] For example, although multiple operations are described sequentially in flowchart format, the order in which they are described does not limit the order in which the operations must be performed. Therefore, when implementing each embodiment, the order of the operations can be changed as long as it does not impair the content. In the flowchart of Figure 3, in step S106, the output unit 105 issued a certificate to prove the trustworthiness evaluation result. However, the output unit 105 could simply output the trustworthiness evaluation result to the output device 510. In this case, no further processing would be performed at the operator terminal 200. [Explanation of symbols]
[0053] 10. Evaluation System 100 Evaluation device 101 Evaluation Metric Acquisition Section 102 Device information acquisition section 103 Inspection Department 104 Evaluation Department 105 Output section 200 carrier terminals 300 Equipment information storage device
Claims
1. A means for obtaining trust evaluation metrics to assess the trustworthiness of a user business, A means for acquiring device information of network devices to be evaluated, An inspection means for inspecting network equipment using the equipment information based on the aforementioned trust evaluation index, An evaluation means for evaluating trustworthiness based on the results of the aforementioned inspection, The system includes an output means for outputting the trust evaluation results, The evaluation indicator acquisition means acquires the trust evaluation indicator from the user business operator, and further evaluates the validity of the trust evaluation indicator acquired from the user business operator. The inspection means is an evaluation device that inspects network equipment based on the trust evaluation index when the trust evaluation index is deemed valid.
2. A means for obtaining trust evaluation metrics to assess the trustworthiness of a user business, A means for acquiring device information of network devices to be evaluated, An inspection means for inspecting network equipment using the equipment information based on the aforementioned trust evaluation index, An evaluation means for evaluating trustworthiness based on the results of the aforementioned inspection, The system includes an output means for outputting the trust evaluation results, The trust evaluation index is a trust evaluation index created by trend analysis of trust evaluation indexes adopted by other businesses that are similar to the user business in terms of size, business type, industry, or business category, and is provided as an evaluation device.
3. The evaluation apparatus according to claim 1 or 2, wherein the output means issues a certificate for certifying the trustworthiness evaluation result.
4. The evaluation apparatus according to claim 1 or 2, wherein the equipment information includes the configuration information and inspection information of the network equipment.
5. A verification means for verifying whether the delivered network equipment is identical to the evaluated network equipment based on a certificate issued by the evaluation device described in claim 3, A carrier terminal comprising: a determination means for determining the operation of the network equipment based on the trust evaluation results after the aforementioned verification.
6. A device information storage device that stores device information of the aforementioned network device, An evaluation system comprising an evaluation device as described in claim 1 or 2, The evaluation device includes an evaluation index acquisition means for acquiring trust evaluation indices for evaluating the trustworthiness of a user business, Information acquisition means for acquiring device information of network devices to be evaluated from the aforementioned device information storage device, An inspection means for inspecting network equipment using the equipment information based on the aforementioned trust evaluation index, An evaluation means for evaluating trustworthiness based on the results of the aforementioned inspection, An evaluation system comprising: an output means for issuing a certificate to prove the results of the trustworthiness evaluation, and storing the certificate with an electronic signature in the device information storage device.
7. Computers Trust evaluation indicators for assessing trustworthiness according to the user business are obtained from the user business, Obtain device information of the network equipment to be evaluated, The validity of the trust evaluation indicators obtained from the user business operator is evaluated. If the aforementioned trust evaluation index is deemed appropriate, the network equipment is inspected using the equipment information based on the aforementioned trust evaluation index. Based on the results of the aforementioned inspection, we evaluated the trustworthiness. An evaluation method for outputting the results of the trustworthiness evaluation.
8. Computers We obtain trust evaluation metrics to assess the level of trust appropriate to the user business. Obtain device information of the network equipment to be evaluated, Based on the aforementioned trust evaluation indicators, network equipment is inspected using equipment information. Based on the results of the aforementioned inspection, we evaluated the trustworthiness. Output the trust evaluation results, The aforementioned trust evaluation index is a trust evaluation index created by trend analysis of trust evaluation indexes adopted by other businesses that are similar to the user business in terms of size, business type, industry, or business category.
9. Trust evaluation indicators for assessing trustworthiness according to the user business are obtained from the user business, Obtain device information of the network equipment to be evaluated, The validity of the trust evaluation indicators obtained from the user business operator is evaluated. If the aforementioned trust evaluation index is deemed appropriate, the network equipment is inspected using the equipment information based on the aforementioned trust evaluation index. Based on the results of the aforementioned inspection, we evaluated the trustworthiness. A program that causes a computer to output the results of the trustworthiness evaluation.
10. We obtain trust evaluation metrics to assess the level of trust appropriate to the user business. Obtain device information of the network equipment to be evaluated, Based on the aforementioned trust evaluation indicators, network equipment is inspected using equipment information. Based on the results of the aforementioned inspection, we evaluated the trustworthiness. The computer is instructed to output the results of the trustworthiness evaluation. The aforementioned trust evaluation index is a program that creates a trust evaluation index by performing a trend analysis on trust evaluation indexes adopted by other businesses that are similar to the user business in terms of size, business type, industry, or sector.
Citation Information
Patent Citations
Security configuration verification device and security configuration verification method, and network system using said device
JP2014504388A
Risk evaluation system and risk evaluation method
JP2016143299A
Information processing device, network apparatus, information processing method and information processing program
JP2021064046A
JPP6815576B
System, method, and non-transitory computer-readable medium
WO2021245939A1