Threat intelligence analysis support device and threat intelligence analysis support method

The threat information analysis support device addresses the lack of integrating security trends in system development by collecting and organizing SBOM, vulnerability, and attack data, facilitating efficient threat intelligence for effective security measures.

JP7869391B1Active Publication Date: 2026-06-02HITACHI INDUSTRY & CONTROL SOLUTIONS LTD

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
HITACHI INDUSTRY & CONTROL SOLUTIONS LTD
Filing Date
2025-09-22
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

Existing systems lack detailed methods for integrating the latest security trends into the development and construction of information processing systems, despite improving security-related responses and compliance rates.

Method used

A threat information analysis support device and method that collects and organizes security information such as SBOM, vulnerability, and attack data for information processing systems, using databases and AI models to generate threat intelligence analysis results.

Benefits of technology

Enables efficient analysis of security threats, allowing developers to implement effective security measures by providing comprehensive threat intelligence.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007869391000001_ABST
    Figure 0007869391000001_ABST
Patent Text Reader

Abstract

Supports the analysis of security threat intelligence. [Solution] The threat information analysis support device 100 includes a reception unit 111 that receives security-related questions about a target system, which is an information processing system to be subjected to security measures, and an analysis unit 112 that collects security information related to the questions and outputs threat information analysis results as answers to the questions in a predetermined format. The security information may include at least one of the following: design information of the target system, SBOM information of components constituting the target system, vulnerability information of components constituting the target system, attack information on the target system, and security-related standards information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a threat information analysis support device and a threat information analysis support method for assisting in the analysis of security threat information.

Background Art

[0002] Not only information systems but also factory facilities and embedded systems are being connected to the network, and countermeasures against security threats have become essential. As a technology for supporting security measures, there is a system described in Patent Document 1.

[0003] This system includes means for transmitting a security-related question input by a user to a server, and means for generating a prompt sentence for instructing the server to generate an optimal answer to the question. The system also includes a generation AI model that inputs the prompt sentence received from the server and generates an optimal answer to the question, and means for analyzing the answer received by the server from the generation AI model and presenting it to the user. Further, the system includes means for the server to evaluate security risks in real time and generate a warning when a security risk is detected, and means for the server to learn past security incidents and predict future risks.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] The system described in Patent Document 1 is said to have the effect of improving the accuracy of security-related responses and security compliance rates. However, regarding support for security measures in the development and construction of information processing systems, while it is stated that "the latest security trends are checked regularly and reflected in system development," there is no description of the content or methods of this support. This invention was made in view of the above background, and aims to provide a threat intelligence analysis support device and a threat intelligence analysis support method that assist in the analysis of security threat information. [Means for solving the problem]

[0006] To solve the above-mentioned problems, the threat information analysis support device according to the present invention comprises: a reception unit that receives security-related questions about a target system, which is an information processing system to which security measures are to be implemented; and an analysis unit that collects security information related to the questions and outputs threat information analysis results as answers to the questions in a predetermined format. The security information includes at least one of the following: design information of the target system, SBOM information of components constituting the target system, vulnerability information of components constituting the target system, attack information against the target system, and security-related standard information. The analysis unit collects the security information by repeatedly selecting and performing one of the following actions: obtaining SBOM information of a component based on the name of the component constituting the target system included in the question; obtaining vulnerability information of the component or components on which the component depends based on the identification information of the component included in the SBOM information of the component; obtaining attack information that utilizes the vulnerability of the component based on the vulnerability information of the component; obtaining design information of a component based on the component having vulnerability information; obtaining design information of a component related to a function of the target system included in the question; obtaining SBOM information of a component based on the design information of the component; obtaining attack information related to a function of the target system based on the function of the target system; and obtaining design information of a component related to a standard name, item name, or item number based on a standard name, item name, or item number of the standard included in the question. . [Effects of the Invention]

[0007] According to the present invention, it is possible to provide a threat information analysis support device and a threat information analysis support method that assist in the analysis of security threat information. Problems, configurations, and effects other than those described above will be clarified by the following description of embodiments. [Brief explanation of the drawing]

[0008] [Figure 1] This is a functional block diagram of the threat information analysis support device according to this embodiment. [Figure 2] This figure shows an example of SBOM information according to this embodiment. [Figure 3] This figure shows an example of vulnerability information according to this embodiment. [Figure 4] This figure shows an example of vulnerability information according to this embodiment. [Figure 5]This figure shows an example of attack information according to this embodiment. [Figure 6] This figure shows an example of attack information according to this embodiment. [Figure 7] This figure shows an example of design information according to this embodiment. [Figure 8] This figure shows an example of standard information according to this embodiment. [Figure 9] This figure shows the configuration of the analysis instruction prompt according to this embodiment. [Figure 10] This figure shows an example of the threat intelligence analysis results according to this embodiment. [Figure 11] This is a flowchart of the threat intelligence analysis process according to this embodiment. [Figure 12] This is a hardware configuration diagram showing an example of a computer that implements the functions of the threat information analysis support device according to the above embodiment. [Modes for carrying out the invention]

[0009] ≪Overview of Threat Intelligence Analysis Support Device≫ The following describes the outline of a threat information analysis support device in an embodiment for carrying out the present invention. The threat information analysis support device collects information related to security threats to the information processing system being developed or constructed, organizes the information, and outputs it. In more detail, the user first inputs questions related to the target system, which is the information processing system to be analyzed for threats. The questions include information indicating the components that make up the target system, the functions (specifications) that the target system has, and the standards related to the target system.

[0010] Next, the threat intelligence analysis support device collects SBOM information and design information for components related to the parts, functions, and standards included in the question. Furthermore, the threat intelligence analysis support device repeatedly collects related vulnerability information and attack information based on the SBOM information, and collects related component SBOM information based on the design information. Finally, the threat intelligence analysis support device organizes the collected information in a predetermined format and outputs it.

[0011] By using such a threat information analysis support device, the developer of the target system can easily collect information related to security threats and efficiently analyze security threats. Consequently, the developer can implement effective security measures for the target system within a limited time. Note that the information processing system is not limited to a system composed of a server, terminal, software, etc. that provide network services. The information processing system includes devices, systems, and software that perform information processing (data processing), including embedded systems such as automobiles and home appliances, and equipment and devices installed in factories.

[0012] <<Configuration of Threat Information Analysis Support Device>> FIG. 1 is a functional block diagram of a threat information analysis support device 100 according to the present embodiment. The threat information analysis support device 100 is a computer and includes a control unit 110, a storage unit 120, and an input / output unit 180. User interface devices such as a display, keyboard, and mouse are connected to the input / output unit 180. The input / output unit 180 includes a communication device and can transmit and receive data to and from the language model server 210. Further, a media drive may be connected to the input / output unit 180 to enable data exchange using a recording medium.

[0013] The language model server 210 is a server that provides services such as an AI chatbot and interactive AI. When the threat information analysis support device 100 transmits a question or instruction called a prompt to the language model server 210, the language model server 210 returns an answer to the question, a response to the instruction, or an execution result. Note that the language model server 210 generates answers, responses, and execution results using a language model.

[0014] <<Threat Information Analysis Support Device: Storage Unit>> The storage unit 120 is configured to include storage devices such as a ROM (Read Only Memory), a RAM (Random Access Memory), and an SSD (Solid State Drive). The storage unit 120 stores a standard information database 130, a design information database 140, a component information database 150, a vulnerability information database 160, an attack information database 170, and a program 128. The program 128 includes descriptions of processes executed by functional units provided in the control unit 110 described later. Note that various stored contents of the storage unit 120 may be read as necessary from those stored in an external storage device such as a cloud server.

[0015] ≪Storage Unit: Standard Information Database≫ The standard information database 130 stores standards, guidelines, laws, etc. related to the security of the information processing system. The standard information database 130 can perform searches for similar texts (sentences) in addition to keyword searches. Specifically, the standard information database 130 includes a vector database that stores embedding vectors obtained by numerically vectorizing text data included in standards and guidelines. By referring to the vector database, it is possible to obtain items of standards and guidelines that include contents similar to the text to be searched. Examples of standards, guidelines, and laws include the SP800 series issued by the US NIST, ISO / SAE 21434, and the European Cyber Resilience Act.

[0016] ≪Storage Unit: Design Information Database≫ The design information database 140 stores design information of the target system. Examples of design information include documents such as system requirements, architecture, layout diagrams, use cases, components, sequence diagrams, state transition diagrams, activity diagrams, class diagrams, source code, and test cases. The design information database 140 can perform searches based on the content of diagrams (e.g., inheritance relationships and dependency relationships between classes) in addition to keyword searches and searches for similar texts.

[0017] ≪Memory Unit: Parts Information Database≫ The component information database 150 contains information about the software components that make up the target system. This component information, also known as SBOM (Software Bill of Materials) information, includes the component name, identification information, version, license information, supplier information, and dependencies. The component information database 150 allows for keyword searches and similar text searches. Common Platform Enumeration (CPE) is generally used as the identification information. Dependencies indicate which components are dependent on each other and which components (libraries) are used (called).

[0018] ≪Memory Unit: Vulnerability Information Database≫ The vulnerability information database 160 stores vulnerability information for information processing systems, including the target system. Vulnerability information includes vulnerability identification information, an overview, reference information, anticipated impact, and countermeasures. The identification information generally used is what is called CVE (Common Vulnerabilities and Exposures). In addition to keyword searches, the vulnerability information database 160 allows searching for vulnerability information containing content similar to the searched text. Examples of vulnerability information include CVE and CWE (Common Weakness Enumeration) provided by MITRE, Inc., KEV (Known Exploited Vulnerabilities) provided by CISA, Inc., and JVN (Japan Vulnerability Notes) provided by JPCERT / CC and the Information-technology Promotion Agency, Japan.

[0019] ≪Memory Unit: Attack Information Database≫ The attack information database 170 stores information related to attacks on information processing systems, including the target system. Attack information is classified based on the tactics, techniques, and methods of attacks on information processing systems. In addition to keyword searches, the attack information database 170 can also search for attack information containing similar content to the text being searched. Examples of attack information include MITRE's ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) and CAPEC (Common Attack Pattern Enumeration and Classification).

[0020] ≪Threat Intelligence Analysis Support Device: Control Unit≫ The control unit 110 includes a CPU (Central Processing Unit) and is equipped with a reception unit 111 and an analysis unit 112. The control unit 110 may also include a GPU (Graphics Processing Unit), an NPU (Neural (network) Processing Unit), an FPGA (Field Programmable Gate Array), an ASIC (Application Specific Integrated Circuit), etc.

[0021] ≪Control Unit: Reception Department≫ The reception unit 111 receives questions entered by the user of the threat intelligence analysis support device 100 (the developer of the target system). The questions include the names of the components that make up the target system, the functions (function names) that the target system has, and the names of the standards and item names / item numbers related to the target system. Hereafter, the component names, functions, standards and item names / item numbers included in the questions will also be referred to as question items.

[0022] As described above, the threat information analysis support device 100 includes a reception unit 111 that receives security-related questions about the target system, which is an information processing system to which security measures are to be implemented.

[0023] ≪Control Unit: Analysis Department≫ The analysis unit 112 extracts question items from the questions and obtains standard information, design information, component information (SBOM information), vulnerability information, and attack information related to those question items. The analysis unit 112 also outputs a threat information analysis result 520 in a predetermined format (see Figure 10 below) as an answer to the questions. Question items can be extracted using natural language processing technology. The analysis unit 112 may also generate prompts to extract component names and functions from the questions, send them to the language model server 210, and extract question items as an answer. Note that standard information, design information, component information (SBOM information), vulnerability information, and attack information are collectively referred to as security information. The following describes the method by which the analysis unit 112 acquires and collects security information, with reference to Figures 2 to 8.

[0024] As described above, the threat information analysis support device 100 includes an analysis unit 112 that collects security information related to a question and outputs a threat information analysis result 520 as an answer to the question, which is the security information in a predetermined format. Security information includes at least one of the following: design information of the target system, SBOM information of the components constituting the target system, vulnerability information of the components constituting the target system, attack information on the target system, and security-related standards information.

[0025] ≪Control Unit: Analysis Unit: SBOM Information from Part Name≫ The analysis unit 112 searches the component information database 150 using the component name as a key to obtain SBOM information 410 (see Figure 2 below). Figure 2 shows an example of SBOM information 410 according to this embodiment. SBOM information 410 includes component name, version, identification information (CPE), dependencies, etc. The "Depends on AAA" in the Relationship section indicates that a component named "Command Center Server" uses a component named "AAA".

[0026] ≪Control Unit: Analysis Unit: Vulnerability Information from SBOM Information≫ The analysis unit 112 searches the vulnerability information database 160 using the identification information (CPE) in the SBOM information 410 as a key to obtain vulnerability information 420 and 430 (see Figures 3 and 4 below). If there are dependencies in the SBOM information 410, the analysis unit 112 obtains the SBOM information 410 of the dependent component and uses the identification information in that SBOM information 410 as a key to obtain vulnerability information 420 and 430. In this way, the analysis unit 112 obtains vulnerability information 420 and 430 by tracing the dependent components.

[0027] Figure 3 shows an example of vulnerability information 420 according to this embodiment. Vulnerability information 420 includes the name of the vulnerable part (component name), identification information (CVE), and CWE. The CWE is classified by the type of vulnerability (vulnerability type, common vulnerability type) in software and hardware, and identification information is assigned to each vulnerability type. Figure 4 shows an example of vulnerability information 430 according to this embodiment. Vulnerability information 430 indicates that no vulnerabilities have been found in part "ABC".

[0028] ≪Control Unit: Analysis Unit: Attack Information from Vulnerability Information≫ The analysis unit 112 searches the attack information database 170 using the vulnerability type contained in the vulnerability information 420 as a key to obtain attack information 440 and 450 (see Figures 5 and 6 below). Figure 5 shows an example of attack information 440 according to this embodiment. Attack information 440 includes identification information, mitigation measures, detection methods, etc. Figure 6 shows an example of attack information 450 according to this embodiment. Attack information 450 includes an example of an attack procedure.

[0029] ≪Control Unit: Analysis Unit: Design Information from Part Name≫ The analysis unit 112 searches the design information database 140 using the name of the vulnerable part as a key to obtain design information 460 (see Figure 7 below). Figure 7 is a diagram showing an example of design information 460 according to this embodiment. The design information 460 includes the name of the part, identification information of the diagram related to the part (e.g., a class diagram), and requirements. The requirements include requirements related to the specifications, functions, and performance of the part.

[0030] ≪Control Unit: Analysis Unit: From Function to Design Information≫ The analysis unit 112 searches the design information database 140 using function as the key to obtain design information 460. The requirements items in the design information 460 include requirements related to function, and the analysis unit 112 obtains the design information 460 based on function. The design information 460 also includes part names, and the analysis unit 112 obtains SBOM information 410 (see Figure 2) from the part names, then obtains vulnerability information 420, 430 (see Figures 3 and 4), and further obtains attack information 440, 450 (see Figures 5 and 6).

[0031] ≪Control Unit: Analysis Unit: Attack Information from Function≫ The analysis unit 112 searches the attack information database 170 using function as a key to obtain attack information 440 and 450. As described above, the analysis unit 112 obtains attack information 440 and 450 by traversing design information 460, SBOM information 410, and vulnerability information 420 based on function. However, as shown in vulnerability information 430 (see Figure 4), if there is no vulnerability in the component, the analysis unit 112 cannot obtain attack information 440 and 450. By searching the attack information database 170, the analysis unit 112 can obtain attack information 440 and 450 that are likely to occur against an information processing system with a function, regardless of individual components.

[0032] ≪Control Unit: Analysis Unit: Design Information from Specifications≫ The analysis unit 112 searches the standard information database 130 using the standard name, standard item name, and item number as keys to obtain standard information 470 (see Figure 8 below). Figure 8 is a diagram showing an example of standard information 470 according to this embodiment. Standard information 470 includes the standard name, item number and item name, and content.

[0033] Next, the analysis unit 112 extracts functional requirements from the content of the standard information 470, and uses these requirements as keys to search the design information database 140 and obtain the design information 460. The analysis unit 112 then obtains SBOM information 410 from the component names included in the design information 460, followed by vulnerability information 420, and further obtains attack information 440 and 450. The requirements can be extracted, for example, by sending a prompt to the language model server 210 that includes instructions to extract the requirements from the content of the standard information 470.

[0034] As described above, the analysis unit 112 collects security information by repeating at least one of the following: Obtaining SBOM information for a component based on the name of that component that makes up the target system included in the question. Obtaining vulnerability information for a component or components on which it depends, based on the component's identification information contained in the component's SBOM information. Obtaining attack information that exploits vulnerabilities in a component, based on vulnerability information of that component. Obtaining design information for a component based on a component that has vulnerability information. Obtaining design information for components related to the functions of the target system, based on the functions included in the question. Obtaining SBOM information for a component based on its design information. Obtaining attack information related to the target system's functions, based on the functions of that function. Obtaining design information for parts related to a standard name, item name, or item number, based on the standard name, item name, or item number included in the question.

[0035] ≪Control Unit: Analysis Department: Threat Intelligence Analysis Results≫ Up to this point, the analysis unit 112 has explained the method of collecting security information by starting with the question items and repeatedly performing searches. Below, we will explain the method of organizing the security information and obtaining the threat intelligence analysis results 520 (see Figure 10 below).

[0036] The analysis unit 112 organizes security information using the language model server 210. More specifically, the analysis unit 112 generates an analysis instruction prompt 510 (see Figure 9 below) and sends it to the language model server 210, and obtains a threat information analysis result 520 as a response.

[0037] Figure 9 shows the configuration of the analysis instruction prompt 510 according to this embodiment. Element 511 includes an instruction to organize the component information in element 512, the vulnerability information in element 513, the attack information in element 514, and the design information in element 515 into the format in element 516 and output it as a threat information analysis result 520.

[0038] Element 512 contains the collected component information (SBOM information 410). Element 513 contains the collected vulnerability information 420, 430. Element 514 contains the collected attack information 440, 450. Element 515 contains the collected design information 460. Element 516 contains the format of the threat intelligence analysis results 520.

[0039] Figure 10 shows an example of the threat information analysis results 520 according to this embodiment. The threat information analysis results 520 include information that has been organized and summarized according to the format described in element 516, based on security information acquired by the analysis unit 112. The threat information analysis results 520 include the name of the vulnerable component, identification information of the vulnerability, the name of the OSS related to the component, the design information of the component, and attack information related to the component.

[0040] As described above, the analysis unit 112 generates an analysis instruction prompt 510 that includes the format, the collected security information, and instructions to organize and output the security information according to the format, and outputs the threat information analysis result 520 by processing the analysis instruction prompt 510 using a language model (see language model server 210). Threat intelligence analysis result 520 includes at least one of the following: the name of the vulnerable component, identification information of the vulnerability, the name of the OSS associated with the component, the design information of the component, and attack information related to the component.

[0041] ≪Threat Intelligence Analysis Processing≫ Figure 11 is a flowchart of the threat information analysis process according to this embodiment. Referring to Figure 11, the process from when the threat information analysis support device 100 receives a question to when it outputs the threat information analysis result 520 will be explained. In step S11, the reception unit 111 receives questions from users. In step S12, the analysis unit 112 repeatedly acquires and collects security information, such as component information (SBOM information 410), vulnerability information 420, 430, attack information 440, 450, and design information 460, starting from question items such as component names and functions included in the question.

[0042] In step S13, the analysis unit 112 generates an analysis instruction prompt 510. In step S14, the analysis unit 112 sends an analysis instruction prompt 510 to the language model server 210 to obtain a threat information analysis result 520 as a response, and outputs it to the display connected to the input / output unit 180.

[0043] Features of the Threat Intelligence Analysis Support Device The threat intelligence analysis support device 100 repeatedly acquires component information (SBOM information 410) related to input components, functions, and standards, vulnerability information 420, 430, attack information 440, 450, and design information 460, and collects security information. Next, the threat intelligence analysis support device 100 outputs a threat intelligence analysis result 520 in which the security information is organized into a predetermined format using the language model server 210.

[0044] The developer of the target system can obtain threat intelligence analysis results 520 by inputting, for example, components that are easily targeted for attacks because they accept input from the internet, functions that require security measures, and standards that must be complied with. By referring to the threat intelligence analysis results 520, the developer can implement effective security measures for the target system. In this way, the threat intelligence analysis support device 100 supports the target system developer in taking measures against security threats.

[0045] ≪Variation: Question≫ In the embodiment described above, the analysis unit 112 collects security information starting from question items such as part names and functions included in the question. Security information may also be collected starting from other question items. For example, instead of part names, the SBOM information of the part itself may be used as a question item.

[0046] Alternatively, the analysis unit 112 may use devices such as servers connected to the Internet as question items and collect security information starting from those devices. In this case, the analysis unit 112 can search the design information database 140 using the device as a key to obtain the parts (components) placed on the device and collect security information related to those parts. The layout diagram included in the design information describes the software components (parts) placed on the hardware (device).

[0047] ≪Variation: Database≫ In the embodiment described above, the analysis unit 112 searches databases such as the design information database 140 and the parts information database 150 depending on the search target. The standards information database 130, the design information database 140, the parts information database 150, the vulnerability information database 160, and the attack information database 170 may be integrated into a single database. The analysis unit 112 may perform keyword searches or similar text searches in the integrated database.

[0048] ≪Torture: Parts Information≫ If the threat intelligence analysis result 520 (see Figure 10) includes software components procured from external sources such as open-source software, the analysis unit 112 may also include the commit and release (version upgrade) status of the source code of those components. The commit and release status can be obtained by accessing the source code repository. The analysis unit 112 may also include graphs showing the release status and the number of commits per month in the threat intelligence analysis result 520. Knowing the commit and release status allows the developers of the target system to understand the development status of the components. For example, a high release frequency suggests that security patches are likely to be provided quickly, and new features immediately after release are likely to contain vulnerabilities, so their use should be refrained from for the time being.

[0049] As explained above, the threat intelligence analysis result 520 includes at least one of the following: the commit status and / or the release status of the vulnerable software component.

[0050] <<Other variations>> Although several embodiments of the present invention have been described above, these embodiments are merely illustrative and do not limit the technical scope of the present invention. For example, in the embodiments described above, the analysis unit 112 sends an analysis instruction prompt 510 to the language model server 210 to obtain the threat information analysis result 520. Alternatively, the analysis unit 112 may process the analysis instruction prompt 510 using a language model stored in the storage unit 120 to obtain the threat information analysis result 520.

[0051] The present invention can take on various other embodiments, and furthermore, various modifications such as omissions and substitutions can be made without departing from the spirit of the invention. These embodiments and their variations are included in the scope and spirit of the invention as described herein, and are also included in the scope of the invention and its equivalents as described in the claims.

[0052] Hardware Configuration The threat information analysis support device 100 according to the above embodiment is implemented by a computer 900 having a configuration such as that shown in Figure 12. Figure 12 is a hardware configuration diagram showing an example of a computer 900 that implements the functions of the threat information analysis support device 100 according to the above embodiment. The computer 900 includes a CPU 901, ROM 902, RAM 903, SSD 904, and an input / output interface 905 (labeled as input / output I / F (Interface) in Figure 12). Furthermore, the computer 900 includes a communication interface 906 (labeled as communication I / F in Figure 12) and a media interface 907 (labeled as media I / F in Figure 12). The computer 900 may be equipped with an HDD (Hard Disk Drive) instead of the SSD 904, or it may be equipped with an HDD in addition to the SSD 904.

[0053] The CPU 901 operates based on programs stored in the ROM 902 or SSD 904 and is controlled by the control unit 110 in Figure 1. The ROM 902 stores boot programs executed by the CPU 901 when the computer 900 starts up, as well as programs related to the computer 900's hardware.

[0054] The CPU 901 controls input devices 910, such as a mouse and keyboard, and output devices 911, such as a display and printer, via the input / output interface 905. The CPU 901 acquires data from the input devices 910 and outputs the generated data to the output devices 911 via the input / output interface 905.

[0055] SSD904 stores programs executed by CPU901 and data used by those programs. Communication interface906 receives data from other devices (e.g., language model server210) not shown via the communication network and outputs it to CPU901, and also transmits data generated by CPU901 to other devices via the communication network.

[0056] The media interface 907 reads a program or data stored in the recording medium 912 and outputs it to the CPU 901 via the RAM 903. The CPU 901 loads the program from the recording medium 912 onto the RAM 903 via the media interface 907 and executes the loaded program. The recording medium 912 can be an optical recording medium such as a DVD (Digital Versatile Disk), a magneto-optical recording medium such as an MO (Magneto Optical Disk), a magnetic recording medium, a conductive memory tape medium, or a semiconductor memory.

[0057] For example, when computer 900 functions as a threat information analysis support device 100 according to the above embodiment, the CPU 901 of computer 900 realizes the functions of the threat information analysis support device 100 by executing a program 128 (see Figure 1) loaded on RAM 903. The CPU 901 reads the program from the recording medium 912 and executes it. In addition, the CPU 901 may read the program from another device via a communication network, or it may install the program 128 from the recording medium 912 to the SSD 904 and execute it. [Explanation of Symbols]

[0058] 100 Threat Intelligence Analysis Support Device 111 Reception Department 112 Analysis Department 130 Standards Information Database 140 Design Information Database 150 Parts Information Database 160 Vulnerability Information Database 170 Attack Information Database 210 Language Model Servers 410 SBOM Information 420,430 Vulnerability information 440,450 Attack Information 460 Design information 470 Standard Information 510 Analysis Instruction Prompt 520 Threat Intelligence Analysis Results

Claims

1. A reception desk that accepts security-related questions regarding the target system, which is the information processing system to which security measures are to be implemented, The system includes an analysis unit that collects security information related to the aforementioned question and outputs threat information analysis results as answers to the aforementioned question, in a predetermined format based on the security information. The aforementioned security information is This includes at least one of the following: design information of the target system, SBOM information of the components constituting the target system, vulnerability information of the components constituting the target system, attack information on the target system, and security-related standards information. The aforementioned analysis unit is Based on the names of the components that make up the target system included in the aforementioned question, acquisition of SBOM information of said component, Obtaining vulnerability information of the component or components on which the component depends, based on the identification information of the component included in the SBOM information of the component. Based on vulnerability information of the said component, acquisition of attack information that utilizes the vulnerability of said component. Based on the component having the aforementioned vulnerability information, acquisition of the design information of the said component, Based on the functions of the target system included in the above question, acquisition of the design information of the components related to said functions, Acquisition of SBOM information for the said part based on the design information of the said part, Based on the functions of the aforementioned target system, acquisition of attack information related to said functions, and, The security information is collected by repeatedly selecting and performing one of the following actions based on the standard name, standard item name, or standard item number included in the aforementioned question: obtaining design information for the component related to the said standard name, item name, or item number. Threat intelligence analysis support device.

2. The aforementioned threat intelligence analysis results are: The information includes at least one of the following: the name of the vulnerable component, identification information of the vulnerability, the name of the OSS associated with the component, the design information of the component, and attack information relating to the component. The threat information analysis support device according to claim 1.

3. The aforementioned threat intelligence analysis results are: The commit status and / or release status of the component which is the vulnerable software include at least one of these. The threat information analysis support device according to claim 1.

4. The aforementioned analysis unit is The system generates an analysis instruction prompt that includes the aforementioned format, the collected security information, and instructions to organize and output the security information according to the aforementioned format. The threat intelligence analysis results are output by processing the analysis instruction prompt using a language model. The threat information analysis support device according to claim 2 or 3.

5. The threat intelligence analysis support device, A step to receive security-related questions about the target system, which is the information processing system to which security measures will be implemented, The steps include collecting security information related to the aforementioned question, and outputting threat intelligence analysis results as answers to the aforementioned question in a predetermined format based on the security information, The aforementioned security information is This includes at least one of the following: design information of the target system, SBOM information of the components constituting the target system, vulnerability information of the components constituting the target system, attack information on the target system, and security-related standards information. In the step of outputting the threat intelligence analysis results, Based on the names of the components that make up the target system included in the aforementioned question, acquisition of SBOM information of said component, Obtaining vulnerability information of the component or components on which the component depends, based on the identification information of the component included in the SBOM information of the component. Based on vulnerability information of the said component, acquisition of attack information that utilizes the vulnerability of said component. Based on the component having the aforementioned vulnerability information, acquisition of the design information of the said component, Based on the functions of the target system included in the above question, acquisition of the design information of the components related to said functions, Acquisition of SBOM information for the said part based on the design information of the said part, Based on the functions of the aforementioned target system, acquisition of attack information related to said functions, and, The security information is collected by repeatedly selecting and performing one of the following actions based on the standard name, standard item name, or standard item number included in the aforementioned question: obtaining design information for the component related to the said standard name, item name, or item number. Methods for supporting threat intelligence analysis.