Information processing device, risk visualization method, and program
Patent Information
- Application Number
- JP2024575983
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-07-23
- Publication Date
- 2025-10-03
- Estimated Expiration
- 2043-02-09
AI Technical Summary
Current systems struggle to provide a comprehensive and visual representation of security risks across multiple systems, making it difficult for administrators to understand overall risks and prioritize countermeasures effectively.
An information processing device and method that aggregates risk analysis results from multiple systems using predetermined evaluation indices, allowing for the visualization of aggregated risk information, enabling administrators to grasp risks and prioritize countermeasures more efficiently.
Facilitates easy understanding of risks across multiple systems, allowing administrators to prioritize countermeasures based on aggregated risk data, improving overall security risk management.
Abstract
Description
Information processing device, risk visualization method, and computer-readable medium
[0001] The present disclosure relates to an information processing device, a risk visualization method, and a computer-readable medium.
[0002] In recent years, the threat of cyberattacks has not only been limited to the field of ICT (Information and Communication Technology), but also has resulted in cases of damage in the fields of control systems and IoT (Internet of Things). In particular, there have been cases of control systems threatening the operation of critical infrastructure, such as the shutdown of power systems and factories. To combat the threat of cyberattacks, it is important to clarify the security risks posed by systems, implement countermeasures, and reduce those risks.
[0003] As a related technique, Patent Document 1 discloses a security design support system. In the security design support system described in Patent Document 1, a security officer distributes a security status confirmation checklist to an industrial cluster made up of multiple organizations. Each of the multiple organizations has its own unique system, such as a design support system, a production planning system, or a manufacturing system. An organization officer is assigned to each of the multiple organizations, and the organization officer of each organization creates a response to the checklist and sends the created response and system configuration information data to the security officer. The response includes the security status of the system of the organization they are responsible for.
[0004] The security officer receives responses and system configuration information data from each of the multiple organization officers. The security officer inputs the received responses and system configuration information data into the security design support device. The security design support device outputs security-related countermeasure information using the input responses and system configuration information data. The countermeasure information includes cluster-common baseline requirement list data, organization-specific requirement list data, and inter-organizational collaboration requirement list data. The cluster-common baseline requirement list data is data indicating security requirements and countermeasures that are common to the cluster of systems of each organization in the industrial cluster. The organization-specific requirement list data is data indicating individual security requirements and countermeasures for the systems of each organization. The inter-organizational collaboration requirement list data is data indicating security requirements and countermeasures when the systems of each organization in the industrial cluster collaborate.
[0005] Japanese Patent Application Laid-Open No. 2019-021161
[0006] Recently, the visualization of risk analysis results has become important, and there is a growing need for dashboard-like visualization of security risks across all factories and departments. Consultants also have a growing need to compare analysis results with those of other industries or within the same industry. However, it is difficult to grasp the security risks across all factories or departments, determine the priority of countermeasures, and monitor which countermeasures are being implemented. Administrators who manage multiple systems want to know the overall risks and whether countermeasures should be implemented, but find it difficult to understand detailed attack routes and vulnerability information for each system.
[0007] In Patent Document 1, an administrator can determine whether each system satisfies the cluster-common baseline requirements, organization-specific requirements, and inter-organization collaboration requirements. However, in Patent Document 1, analysis results are obtained individually for each system. Therefore, in Patent Document 1, for multiple systems, each operator must understand the risks for each individual system they are responsible for, understand the countermeasures, and determine the priority of the countermeasures.
[0008] In view of the above circumstances, the present disclosure aims to provide an information processing device, a risk visualization method, and a computer-readable medium that enable system administrators who manage multiple systems to easily understand the risks in the multiple systems.
[0009] To achieve the above object, the present disclosure provides, as a first aspect, an information processing device including an analysis result acquisition unit that acquires multiple risk analysis results that are results of risk analyses performed on multiple systems, an aggregation unit that aggregates the multiple risk analysis results using a predetermined evaluation index, and a visualization unit that presents information on the aggregated risk analysis results to a user.
[0010] In a second aspect, the present disclosure provides a risk visualization method, which includes acquiring a plurality of risk analysis results that are the results of risk analyses performed on a plurality of systems, aggregating the acquired plurality of risk analysis results using a predetermined evaluation index, and presenting information on the aggregated risk analysis results to a user.
[0011] In a third aspect, the present disclosure provides a computer-readable medium storing a program for causing a computer to execute a process including acquiring a plurality of risk analysis results that are the results of risk analyses performed on a plurality of systems, aggregating the acquired plurality of risk analysis results using a predetermined evaluation index, and presenting information on the aggregated risk analysis results to a user.
[0012] The information processing device, risk visualization method, and computer-readable medium according to the present disclosure can enable a system administrator who manages multiple systems to easily grasp the risks in the multiple systems.
[0013] 1 is a block diagram showing a schematic configuration of an information processing device according to the present disclosure. FIG. 1 is a block diagram showing an information processing device according to a first embodiment of the present disclosure. FIG. 2 is a schematic diagram showing the relationship between a plurality of systems, an individual system administrator, and an overall system administrator. FIG. 2 is a diagram showing an example of visualization in a first specific example. FIG. 3 is a diagram showing an example of a notification sent to an individual system administrator. FIG. 4 is a diagram showing an example of visualization in a fourth specific example. FIG. 5 is a diagram showing an example of visualization in a sixth specific example. FIG. 6 is a diagram showing an example of visualization in a seventh specific example. FIG. 8 is a diagram showing an example of visualization in an eighth specific example. A flowchart showing an operation procedure of an information processing device. A block diagram showing an information processing device according to a second embodiment of the present disclosure. A diagram showing example of information stored in a countermeasure cost DB. A diagram showing a specific example of visualization in this embodiment. A block diagram showing an example of the configuration of a computer device.
[0014] Prior to describing embodiments of the present disclosure, an overview of the present disclosure will be described. FIG. 1 shows a schematic configuration of an information processing device according to the present disclosure. The information processing device 10 includes an analysis result acquisition unit 11, an aggregation unit 12, and a visualization unit 13. The analysis result acquisition unit 11 acquires multiple risk analysis results 20 for each of multiple systems to be analyzed. The aggregation unit 12 aggregates the acquired multiple risk analysis results 20 using a predetermined evaluation index. The visualization unit 13 presents the aggregated risk analysis results to a user, such as a system administrator who manages multiple systems.
[0015] In the present disclosure, the aggregation unit 12 aggregates multiple risk analysis results using a predetermined evaluation index. The visualization unit 13 presents the aggregated risk analysis results to a user. In the present disclosure, by viewing the aggregated risk analysis results, a user can understand to some extent the risks in multiple systems without having to examine each individual risk analysis result in detail. Therefore, a system administrator who manages multiple systems can easily understand the risks in the multiple systems.
[0016] Hereinafter, embodiments of the present disclosure will be described in detail. Note that the following description and drawings have been omitted and simplified as appropriate for clarity of explanation. In addition, in each drawing, the same or similar elements are designated by the same reference numerals, and duplicate explanations are omitted as necessary.
[0017] FIG. 2 shows an information processing device according to the first embodiment of the present disclosure. The information processing device 100 includes a collection unit 101, a common information aggregation unit 102, a risk visualization unit 103, an attack information DB (database) 120, a countermeasure compromise DB 130, and an aggregated information DB 140. The information processing device 100 is configured as a device including, for example, one or more processors and one or more memories. At least a portion of the functions of each unit in the information processing device 100 can be realized by the processor executing instructions read from the memory. The information processing device 100 corresponds to the information processing device 10 shown in FIG. 1. The information processing device 100 may also be referred to as a risk visualization device.
[0018] In this embodiment, the attack information DB 120, the countermeasure information DB 130, and the aggregated information DB 140 only need to be accessible from the information processing device 100, and these DBs do not necessarily have to be part of the information processing device 100. For example, at least one of the attack information DB 120, the countermeasure information DB 130, and the aggregated information DB 140 may be located on a cloud. In this case, the information processing device 100 may access at least one of the attack information DB 120, the countermeasure information DB 130, and the aggregated information DB 140 via a network.
[0019] The collection unit 101 collects multiple risk analysis results 201 performed on multiple systems. The risk analysis results 201 include, for example, a risk value when an attack is carried out on each system and information on vulnerabilities used in the attack. The risk analysis results 201 may be the result of a business damage-based risk analysis performed on the system to be analyzed (hereinafter also referred to as a business damage-based risk analysis result). The business damage-based risk analysis includes, for example, creating a virtual model from configuration information of a system in a real environment, inputting information on an attack scenario to be analyzed, generating attack routes in accordance with the attack scenario, and calculating a risk value for the generated attack routes.
[0020] The results of the business damage-based risk analysis indicate the risk assessment results when an attack is carried out along an attack route that runs from an entry point included in the system being analyzed to the target of attack. The attack route includes one or more attack steps. An attack step is the smallest unit of an attack route and includes an attack source, an attack destination, and an attack method. The attack method indicates the attack type of the attack step. The attack method is also called an attack pattern. The attack information may include information on vulnerabilities used in the attack pattern. The results of the business damage-based risk analysis include the attack steps when an attack is carried out along the attack route, and a risk value that assesses the risk for the entire attack route. The risk value is assessed, for example, on a five-point scale from A to E.
[0021] Alternatively, the risk analysis result 201 may be a result of performing an asset-based risk analysis on the system to be analyzed (hereinafter also referred to as an asset-based risk analysis result). The asset-based risk analysis includes, for example, evaluating the risk of each of the assets that make up the system to be analyzed using three evaluation indicators: its importance (value), the likelihood of a potential threat occurring, and its vulnerability to the threat.
[0022] The asset-based risk analysis result indicates the result of assessing the risk to the assets that constitute the system being analyzed. The asset-based risk analysis result includes a risk value that evaluates the risk when an attack is carried out on the asset using one or more assumed attack patterns. The risk value is evaluated, for example, on a five-point scale from A to E. The risk analysis result 201 may include a business damage-based risk analysis result and an asset-based risk analysis result for one system. The collection unit 101 corresponds to the analysis result acquisition unit 11 shown in FIG. 1.
[0023] 3 shows the relationship between multiple systems to be analyzed, individual system administrators who manage each system, and an overall system administrator who manages the entire system. For example, assume that a system is built for each of multiple departments in a company. Systems 200-1 to 200-N shown in FIG. 3 are systems for which risk analysis is performed. By performing risk analysis individually on each of systems 200-1 to 200-N, multiple risk analysis results 201 are obtained.
[0024] Each of the multiple individual system administrators is in charge of one of the multiple systems 200-1 to 200-N and is an administrator who manages the system for which they are responsible. The individual system administrator manages asset information, vulnerability information, and system risk for the system for which they are responsible. The number of systems for which an individual system administrator is responsible is not limited to one, and one individual system administrator may be in charge of multiple systems. The overall system administrator is an administrator who manages the entire multiple systems 200-1 to 200-N. The overall system administrator manages the system risk and vulnerability of all systems. In general, overall system administrators often do not have a full grasp of the asset details of each system.
[0025] Returning to FIG. 2 , the attack information DB 120 stores, for each attack route, attack steps, attack patterns, vulnerability information used in the attack patterns, and risk values. The countermeasure information DB 130 stores vulnerability information and countermeasure information. The collection unit 101 registers various information contained in the collected multiple risk analysis results 201 in the attack information DB 120. The collection unit 101 also collects vulnerability information for each asset against attacks in each of the systems to be analyzed. Specifically, the collection unit 101 collects information such as vulnerability identification information and possible attack patterns for vulnerabilities in the assets to be attacked. Here, CVE (Common Vulnerabilities and Exposures) can be used as the vulnerability identification information. The collection unit 101 also acquires information such as a CVSS (Common Vulnerability Scoring System) score, the presence or absence of a PoC (Proof of Concept) code, and the presence or absence of damage cases. The CVSS score, the presence or absence of a PoC code, and the presence or absence of a damage case can be obtained from an external server or the like via a network such as the Internet. The collection unit 101 registers the collected vulnerability information in the vulnerability information DB 130.
[0026] The common information aggregating unit 102 aggregates risk analysis results 201 of multiple systems 200-1 to 200-N (see FIG. 3 ) using a predetermined evaluation index, using information stored in the attack information DB 120 and information stored in the countermeasure information DB 130. The common information aggregating unit 102 aggregates multiple risk analysis results by, for example, counting the number of systems, the number of attack routes, the number of attack patterns, or the number of vulnerabilities according to predetermined conditions. The common information aggregating unit 102 registers the aggregated information in the aggregated information DB 140. The common information aggregating unit 102 corresponds to the aggregating unit 12 shown in FIG. 1 .
[0027] The risk visualization unit 103 presents the risk analysis results aggregated by the common information aggregation unit 102 to the user. For example, the risk visualization unit 103 uses information stored in the countermeasure information DB 130 and the risk information DB 140 to display information such as what risks the system as a whole contains on the screen of a display device. By looking at the display screen, the overall system administrator can know information such as what risks the system as a whole contains. The risk visualization unit 103 corresponds to the visualization unit 13 shown in FIG. 1 .
[0028] The operation of the common information aggregation unit 102 and the risk visualization unit 103 will be described below using a specific example of aggregation. In a first specific example of visualization, the common information aggregation unit 102 aggregates risk analysis results of multiple systems by counting the number of systems that meet predetermined conditions based on risk values and vulnerabilities used in attacks. For example, the common information aggregation unit 102 counts the number of systems that have attack routes related to a predetermined number of high-risk vulnerabilities. The common information aggregation unit 102 may classify attack routes related to vulnerabilities by their risk values and count the number of systems for each risk value. Furthermore, the common information aggregation unit 102 may count the number of systems depending on whether the attack routes exploiting the vulnerabilities have been addressed, are being addressed, or are not yet addressed.
[0029] FIG. 4 shows an example of visualization in the first specific example. The common information aggregation unit 102, for example, identifies the risk level for each of multiple vulnerabilities exploited in a predetermined number or more systems. The common information aggregation unit 102 selects a predetermined number of vulnerabilities as dangerous vulnerabilities from among the multiple vulnerabilities in descending order of risk level according to the risk level. The common information aggregation unit 102 selects, for example, the top five vulnerabilities exploited in two or more systems and with the highest CVSS scores as dangerous vulnerabilities. The common information aggregation unit 102 counts the number of systems having attack routes related to the vulnerabilities selected as dangerous vulnerabilities for each risk value. The common information aggregation unit 102 also classifies each attack route as either addressed, being addressed, or not addressed, and counts the number of systems for each classification. The common information aggregation unit 102 registers the number of systems counted for each vulnerability and risk value in the aggregated information DB 140.
[0030] The risk visualization unit 103 acquires information from the aggregated information DB 140 and displays the table shown in FIG. 4 . In displaying the table shown in FIG. 4 , the risk visualization unit 103 may change the color of the vulnerability column according to the vulnerability risk level. For example, the risk visualization unit 103 may classify the CVSS scores of each vulnerability into multiple levels and display the vulnerability column in a color corresponding to the classification level. By referring to the table, the overall system administrator can see that, for example, for the combination of "CVE-XXX0," which has the highest risk level, and "A," the number of systems that have been addressed, i.e., for which countermeasures have already been implemented against the attack route, is "0." Furthermore, the overall system administrator can see that for that combination, the number of systems that are being addressed, i.e., systems for which countermeasures are being implemented, is "5," and the number of systems that have not yet been addressed is "10." Furthermore, the overall system administrator can see that for the combination of "CVE-XXX0," which has the second highest risk level, and "B," the number of systems that have not yet been addressed is "1."
[0031] If multiple risk analysis results are not aggregated in the common information aggregation unit 102, the responsible operator, such as the individual system administrator shown in FIG. 3, must address vulnerabilities on a system-by-system basis. Furthermore, if costs are limited, the overall system administrator must interview the individual system administrators about the status of each system and consider the priority of the response. In contrast, in the first specific example, the overall system administrator can plan to implement countermeasures in order, starting with systems with attack routes associated with vulnerabilities that are highly dangerous and have a high risk value if attacked. In this way, by referring to the table shown in FIG. 4, the system administrator can understand the order in which to implement countermeasures for dangerous vulnerabilities when reducing risk to the entire system.
[0032] The overall system administrator can select a combination of vulnerability and risk value that counts the number of systems in the table displayed in FIG. 4 . The risk visualization unit 103 may identify systems related to the selected combination and send a notification to the individual system administrators in charge of the identified systems. For example, the risk visualization unit 103 may identify a system corresponding to "Unaddressed" in the table shown in FIG. 4 as a system related to the selected combination. The risk visualization unit 103 sends a notification to the individual system administrators in charge of the identified systems. For example, if the combination of "CVE-XXX0" and the risk value "A" is selected in the table shown in FIG. 4 , the risk visualization unit 103 may send a notification to the individual system administrators in charge of each of the 10 unaddressed systems.
[0033] FIG. 5 shows an example of a notification sent to an individual system administrator. The notification shown in FIG. 5 includes vulnerability information, related system information, and countermeasure information. The vulnerability information includes the CVSS score of the vulnerability, whether or not a PoC code has been detected, and whether or not there have been any damage cases. The related system information includes information identifying a vulnerable asset in the system managed by the individual system administrator, such as the asset name, and the number of related attack routes. The related system information may differ for each individual system administrator to whom the notification is sent. The countermeasure information is information indicating a general countermeasure against the vulnerability. In the example of FIG. 5, the countermeasure information includes countermeasure A, which is a permanent measure, and countermeasure B, which is a mitigation measure. Instead of or in addition to sending a notification when the overall system administrator selects a combination, the risk visualization unit 103 may periodically send a notification to the individual system administrator for each combination.
[0034] Next, a second specific example of visualization will be described. FIG. 6 shows an example of visualization in the second specific example. In the second specific example, similar to the first specific example, the common information consolidation unit 102 selects a predetermined number of vulnerabilities as dangerous vulnerabilities from among multiple vulnerabilities in descending order of risk. Furthermore, the common information consolidation unit 102 selects a predetermined number of systems from among multiple systems in descending order of system risk value as high-risk systems based on the system risk value of each system. The system risk value may be, for example, the maximum value of the risk values for multiple attack routes or multiple assets in each system. For example, the common information consolidation unit 102 selects five vulnerabilities as dangerous vulnerabilities and five systems as high-risk systems.
[0035] The common information aggregation unit 102 counts the number of assets having the vulnerability for each selected vulnerability and for each selected system. Furthermore, the common information aggregation unit 102 counts the number of assets having the selected vulnerability that are used in attacks. The risk visualization unit 103 displays the ratio of assets used in attacks to assets having dangerous vulnerabilities. For example, if the number of assets having the vulnerability "CVE-XXX0" in system 1 is "10" and the number of assets used in attacks is "3," the risk visualization unit 103 displays "3 / 10" for the combination of vulnerability "CVE-XXX0" and system 1. Instead of displaying the ratio, the risk visualization unit 103 may simply display the number of assets used in attacks.
[0036] The common information collecting unit 102 may count the number of attack routes associated with a vulnerability for each selected vulnerability and for each selected system. Furthermore, the common information collecting unit 102 may count the total number of attack routes for each system. In this case, the risk visualization unit 103 may display, for each system, the ratio of the number of attack routes using dangerous vulnerabilities to the total number of attack routes. Instead of displaying the ratio, the risk visualization unit 103 may simply display the number of attack routes using dangerous vulnerabilities. The risk visualization unit 103 may display the counted numerical value in a color corresponding to the maximum risk value of the asset having the dangerous vulnerability or the maximum risk value of the attack route using the dangerous vulnerability. Furthermore, in the display of the table shown in FIG. 6 , the risk visualization unit 103 may change the color of the vulnerability column according to the risk level of the vulnerability.
[0037] The overall system administrator can select a combination of a vulnerability and a system in the table displayed in FIG. 6 . The risk visualization unit 103 may send a notification including information about the selected vulnerability to the individual system administrator in charge of the selected system. The risk visualization unit 103 sends, for example, a notification similar to the notification shown in FIG. 5 to the individual system administrator in charge of the selected system. In the second specific example, the related system information in the sent notification may include, for example, the number of attack routes via host A and the number of attack routes via host A in which the selected vulnerability is used. In the second specific example, instead of or in addition to sending a notification when the overall system administrator selects a combination, the risk visualization unit 103 may periodically send a notification to the individual system administrator for each combination.
[0038] In the second specific example, by referring to the table shown in Figure 6, the overall system administrator can plan to implement countermeasures in order, starting with systems that have high-risk vulnerabilities and pose high risks. When countermeasures are implemented for high-risk systems, the risk value of the systems to which the countermeasures have been implemented decreases, and as a result, the ranking of the high-risk systems changes. After the ranking changes, the overall system administrator can re-plan to implement countermeasures in order, starting with systems that have high-risk vulnerabilities and pose high risks.
[0039] Next, a third specific example of visualization will be described. FIG. 7 shows an example of visualization in the third specific example. In the third specific example, the common information consolidation unit 102 identifies high-risk systems and counts the number of attack routes for each risk value of the attack route and for each high-risk system. The method for identifying high-risk systems may be similar to the method for identifying high-risk systems in the second specific example. For example, for system 1, the common information consolidation unit 102 counts the number of attack routes with a risk value of "A," the number of attack routes with a risk value of "B," the number of attack routes with a risk value of "C," the number of attack routes with a risk value of "D," and the number of attack routes with a risk value of "E." The common information consolidation unit 102 also counts the number of attack routes for each risk value for other systems.
[0040] The risk visualization unit 103 displays the number of attack routes for each risk value of the attack route and for each high-risk system. The risk visualization unit 103 may display the average number of attack routes in high-risk systems for each risk value of the attack route. Furthermore, if the number of attack routes for each system is equal to or greater than the average number of attack routes, the risk visualization unit 103 may highlight the number of attack routes. For example, the risk visualization unit 103 may display the number of attack routes equal to or greater than the average in a predetermined color such as red or a predetermined background color. Instead of using the average value of the risk value, a predetermined threshold value for the risk value may be used.
[0041] In the third specific example, the overall system administrator can grasp the number of attack routes in a list for each high-risk system and for each risk value. Therefore, the overall system administrator can easily compare the number of attack routes between systems and for each risk value. Therefore, even if the overall system administrator does not have knowledge of individual systems, he or she can easily grasp which systems among all systems are at risk and for which countermeasures need to be implemented. Instead of visualization using a table, the risk visualization unit 103 may visualize the number of attack routes counted for each risk value and for each high-risk system using a bar graph or radar chart.
[0042] The overall system administrator can select a combination of a risk value and a system in the table displayed in Fig. 7. The risk visualization unit 103 may send a notification including information about the attack route of the selected risk value to the individual system administrator in charge of the selected system. For example, if a combination of risk value "A" and system 1 is selected in the table shown in Fig. 7, the risk visualization unit 103 may send a notification including information about the attack route of risk value "A" to the individual system person in charge of system 1.
[0043] FIG. 8 shows an example of a notification sent to an individual system administrator. The notification shown in FIG. 8 includes attack route information and information about the vulnerability used. The attack route information includes information about the asset that is the starting point of the attack, the asset that is the final target of the attack, the assets via which the attack is initiated from the starting point to the final target, and the attack pattern used in the attack. The vulnerability information includes the asset having the vulnerability, information identifying the vulnerability, and the number of associated attack routes. In the third specific example, the notification sent to the individual system administrator may include countermeasure information, i.e., information indicating general countermeasures against vulnerabilities. In the third specific example, the risk visualization unit 103 can also periodically send notifications to the individual system administrator for each combination, instead of or in addition to sending a notification when the overall system administrator selects a combination.
[0044] Next, a fourth specific example of visualization will be described. FIG. 9 shows an example of visualization in the fourth specific example. In the fourth specific example, a bar graph is used to visualize the number of attack routes. As in the third specific example, the common information consolidation unit 102 counts the number of attack routes for each risk value of the attack route and for each high-risk system. Furthermore, in the fourth specific example, the common information consolidation unit 102 checks the countermeasure multiplicity for each attack route. The countermeasure multiplicity indicates the number of countermeasures implemented for one attack route. For each risk value, the common information consolidation unit 102 counts the number of attack routes for which the countermeasure multiplicity is equal to or greater than a predetermined number and the number of attack routes for which the countermeasure multiplicity is less than the predetermined number.
[0045] For example, the common information aggregation unit 102 counts, for each risk value, the number of attack routes with a countermeasure multiplicity of 3 or more and the number of attack routes with a countermeasure multiplicity of 2 or less. In a fourth specific example, the risk visualization unit 103 visualizes the number of attack routes for systems A-C in a bar graph according to the risk value of the attack route and the number of countermeasure multiplicities. In the bar graph shown in FIG. 9, for example, "A3-" represents an attack route with a risk value of "A" and a countermeasure multiplicity of 3 or more. Furthermore, "A-2" represents an attack route with a risk value of "A" and a countermeasure multiplicity of 2 or less.
[0046] The risk visualization unit 103 may display the average value of the number of attack routes in the bar graph. In this case, the overall system administrator can recognize a system with a number of attack routes exceeding the average value as a high-risk system and can prioritize countermeasures for that system. The risk visualization unit 103 may also weight the number of attack routes with a weight according to the risk value and change the length of each block in the bar graph according to the weight. For example, the risk visualization unit 103 may increase the length of the block per "1" attack route as the risk value increases. In this case, the height of the bar graph increases as the number of attack routes with a high risk value increases.
[0047] A fifth specific example of visualization will be described. FIG. 10 shows an example of visualization in the fifth specific example. In the fifth specific example, a radar chart is used to visualize the number of attack routes. As in the third specific example, the common information aggregation unit 102 counts the number of attack routes for each risk value of the attack route and for each high-risk system. In the fifth specific example, the risk visualization unit 103 visualizes the number of attack routes for systems 1-3 using a radar chart according to the risk value of the attack route.
[0048] The risk visualization unit 103 may display the average value of the number of attack routes for each risk value in the radar chart. In this case, the risk visualization unit 103 may highlight the number of attack routes that exceeds the average value in red, for example. The overall system administrator can recognize a system with a number of attack routes that exceeds the average value as a high-risk system, and can prioritize the development of countermeasures for that system. In the fifth specific example, the risk visualization unit 103 may also weight the number of attack routes with a weight according to the risk value.
[0049] A sixth specific example of visualization will be described. FIG. 11 shows an example of visualization in the sixth specific example. The common information aggregation unit 102 extracts attack patterns used in attack routes from the risk analysis results of all systems. For each of the extracted attack patterns, the common information aggregation unit 102 identifies the vulnerability most frequently exploited by the attack pattern from the risk analysis results. The common information aggregation unit 102 also counts the number of exploits of each attack pattern, i.e., the number of times each attack pattern was used, in the attack routes of all systems. If the risk analysis results include the amount of damage, the common information aggregation unit 102 obtains the maximum amount of damage from the risk analysis results. Instead of or in addition to the amount of damage, the common information aggregation unit 102 may obtain the number of news articles, cases, or PoCs related to the vulnerability.
[0050] The risk visualization unit 103 displays the attack patterns used in the attack routes, the vulnerabilities used, the number of exploits in the attack routes, and the amount of damage. In the item "Number of exploits in the attack routes," the number in parentheses indicates the total number of attack patterns. The risk visualization unit 103 may sort the attack patterns, for example, by the number of exploits in the attack routes, and display the attack patterns with the most exploits in the attack routes at the top. By referring to the table shown in FIG. 11, the overall system administrator can know which attack patterns should be addressed across multiple systems. If countermeasures are implemented for attack patterns with a high number of exploits in the attack routes, countermeasures will be implemented for many attack routes. This allows the overall system administrator to plan countermeasures efficiently.
[0051] The overall system administrator can select an attack pattern in the table displayed in FIG. 11 . The risk visualization unit 103 may identify systems in which the selected attack pattern is used in the attack route, and send a notification including information about the attack pattern to the individual system administrator in charge of the identified system. The information about the attack pattern includes, for example, information about vulnerabilities used by the selected attack pattern and countermeasure information. The vulnerability information may be the same as the vulnerability information included in the notification shown in FIG. 5 . The countermeasure information may be the same as the countermeasure information included in the notification shown in FIG. 5 .
[0052] A seventh specific example of visualization will be described. FIG. 12 shows an example of visualization in the seventh specific example. The common information collection unit 102 extracts attack patterns used in attack routes from the risk analysis results of all systems. The common information collection unit 102 identifies attack routes related to the attack patterns and counts the number of identified attack routes. The common information collection unit 102 also obtains risk values for the identified attack routes and obtains a maximum risk value and an average risk value. The common information collection unit 102 also obtains countermeasures against the attack patterns.
[0053] The risk visualization unit 103 displays the attack patterns used in the attack routes, the number of associated attack routes, the maximum risk value, the average risk value, and countermeasures. The risk visualization unit 103 may sort the attack patterns, for example, by the number of attack routes, and display the attack patterns with the largest number of associated attack routes at the top. Alternatively, the risk visualization unit 103 may display a ranking of countermeasures that are effective for the entire system at the top. The risk visualization unit 103 may allow the overall system administrator to select a countermeasure from a pull-down menu, and display information about the attack patterns related to the selected countermeasure.
[0054] By referring to the table shown in Figure 12, the overall system administrator can understand attack patterns that have a large number of associated attack routes across multiple systems and that will have a significant impact if exploited. This allows the overall system administrator to efficiently consider countermeasures for the entire system. In other words, when vulnerabilities exist in various systems, the overall system administrator can efficiently consider what countermeasures should be implemented overall to reduce risk.
[0055] The overall system administrator can select an attack pattern in the table displayed in FIG. 12 . The risk visualization unit 103 may identify systems in which the selected attack pattern is used in an attack route, and send a notification including information about the attack pattern to the individual system administrator in charge of the identified system. The information about the attack pattern includes, for example, information about the attack route related to the selected attack pattern, information about the vulnerability used, and countermeasure information. The attack route information may be the same as the attack route information included in the notification shown in FIG. 8 . The vulnerability information may be the same as the vulnerability information included in the notification shown in FIG. 8 . The countermeasure information may be the same as the countermeasure information included in the notification shown in FIG. 5 .
[0056] An eighth specific example of visualization will be described. FIG. 13 shows an example of visualization in the eighth specific example. The common information aggregation unit 102 extracts vulnerabilities that can be exploited in attacks from the risk analysis results of all systems. The common information aggregation unit 102 identifies attack routes in which vulnerabilities appear, i.e., attack routes in which vulnerabilities are exploited, and counts the number of identified attack routes. The common information aggregation unit 102 also obtains the maximum risk value of the identified attack routes. For each extracted vulnerability, the common information aggregation unit 102 obtains the presence or absence of exploitation cases, the presence or absence of attack code, the presence or absence of verification code, and the CVSS score. These various pieces of information regarding vulnerabilities may be obtainable from an external server, for example, via the Internet.
[0057] The risk visualization unit 103 displays the vulnerability that can be exploited, whether or not the vulnerability has been exploited, the maximum risk value in the attack route, whether or not there is attack code, whether or not there is verification code, the CVSS score, and the number of times the vulnerability appears in the attack route.By referring to the table shown in Figure 13, the overall system administrator can grasp the vulnerabilities that are at high risk of being exploited across multiple systems.This allows the overall system administrator to efficiently consider countermeasures for the entire system.
[0058] The overall system administrator can select a vulnerability in the table displayed in FIG. 13 . The risk visualization unit 103 may identify systems having attack routes in which the selected vulnerability appears, and send a notification including information about the vulnerability to the individual system administrator in charge of the identified system. The information about the vulnerability includes, for example, information about related systems and countermeasure information. The information about related systems may be the same as the information about related systems shown in FIG. 5 . The countermeasure information may be the same as the countermeasure information included in the notification shown in FIG. 5 .
[0059] Next, the operation procedure will be explained. Figure 14 shows the operation procedure of the information processing device 100. The operation procedure of the information processing device 100 is also called a risk visualization method. The collection unit 101 collects a plurality of risk analysis results 201 performed on a plurality of systems 200-1 to 200-N (see Figure 3) (step S1). The collection unit 101 registers information about attacks acquired from the plurality of risk analysis results 201 in the attack information DB 120. In addition, the collection unit 101 registers information about countermeasures acquired from the risk analysis results 201 in the countermeasure information DB 130.
[0060] The common information aggregation unit 102 aggregates multiple risk analysis results, for example, by aggregating information common to multiple systems based on information about attacks registered in the attack information DB 120 and information about countermeasures registered in the countermeasure information DB 130 (step S2). The common information aggregation unit 102 aggregates multiple risk analysis results, for example, from the perspective of systems, attack routes, attack steps, or vulnerabilities. The common information aggregation unit 102 registers the aggregated information in the aggregated information DB 140. The risk visualization unit 103 reads the registered information from the aggregated information DB 140 and visualizes the risks present in the multiple systems based on the read information (step S3). The risk visualization unit 103 visualizes the risks contained in the multiple systems as a whole, for example, using the visualization methods of the first to eighth specific examples described above.
[0061] In this embodiment, the common information aggregation unit 102 aggregates multiple risk analysis results from a predetermined perspective, and the risk visualization unit 103 displays the aggregated risk analysis results. For example, the common information aggregation unit 102 aggregates multiple risk analysis results to count the number of systems related to a specific vulnerability, the number of assets related to a specific vulnerability in multiple systems, the number of attack routes, or the number of attack routes for each risk value. The risk visualization unit 103 provides the information aggregated across multiple systems to an overall system administrator. By using the information provided by the risk visualization unit 103, the overall system administrator can easily grasp the risk of multiple systems as a whole. Furthermore, the overall system administrator can consider the priority of countermeasures, etc.
[0062] Furthermore, in this embodiment, the risk visualization unit 103 can send a notification related to the selected information to the individual system administrator. The individual system administrator can analyze threats contained in the system for which he is responsible by referring to the information contained in the notification. Furthermore, the individual system administrator can plan countermeasures against threats.
[0063] Next, a second embodiment of the present disclosure will be described. Fig. 15 shows an information processing device according to the second embodiment of the present disclosure. The information processing device 100a according to this embodiment has a countermeasure cost DB 150 in addition to the configuration of the information processing device 100 described in the first embodiment shown in Fig. 2. The countermeasure cost DB 150 stores the cost or expense of introducing a countermeasure for each of a plurality of countermeasures that can be introduced into a plurality of systems. The countermeasure cost DB 150 is also referred to as a countermeasure cost information storage unit.
[0064] FIG. 16 shows an example of information stored in the countermeasure cost DB 150. In this example, the countermeasure cost DB 150 stores countermeasure costs of "10k" and "1M" for countermeasure 0 and countermeasure 1, respectively. The countermeasure cost may be measured in a currency unit such as Japanese yen. When a volume discount is applied to the implementation of a countermeasure, the countermeasure cost DB 150 may further store the discount rate and the number of units to which the discount is applied. In the example of FIG. 16, the countermeasure cost DB 150 stores information indicating that a 10% discount is applied to countermeasure 1 when 20 units are implemented at once.
[0065] In this embodiment, the common information aggregation unit 102 aggregates information about multiple systems for each countermeasure that can be implemented based on the risk analysis results for the multiple systems. The risk visualization unit 103 visualizes the aggregated information about the countermeasures. In visualizing the aggregated information about the countermeasures, the risk visualization unit 103 obtains the countermeasure costs from the countermeasure cost DB 150 and displays the costs if the countermeasures are implemented. In addition to the countermeasure costs, the risk visualization unit 103 may also display the number of units to which a volume discount is applied and the discount rate.
[0066] 17 shows a specific example of visualization in this embodiment. For example, the common information aggregation unit 102 aggregates, for each countermeasure that can be implemented, the number of attack patterns that can be countered, the number of systems to which the countermeasure will be implemented, and the number of countermeasure locations. The risk visualization unit 103 displays the number of attack patterns that can be countered, the number of systems to which the countermeasure will be implemented, and the number of countermeasure locations. In addition, the risk visualization unit 103 obtains the countermeasure cost of each countermeasure from the countermeasure cost DB 150 and displays the obtained countermeasure cost of each countermeasure.
[0067] In this embodiment, the risk visualization unit 103 provides the overall system administrator with information on the number of attack patterns that can be countered, the number of systems to which countermeasures will be implemented, the number of countermeasure locations, and the cost of countermeasures. In this case, the overall system administrator can know information such as how much the countermeasures will cost if countermeasures are implemented, how many attack patterns can be countered, and how many systems can be countermeasures. Therefore, the overall system administrator can prioritize the most efficient countermeasures, taking into consideration the cost of the countermeasures, the number of attack patterns that can be countered, and the number of systems. Furthermore, in this embodiment, if a volume discount is available, the overall system administrator can know the number of units to which the volume discount will be applied and the discount rate, and can use such information in planning countermeasures.
[0068] Next, a description will be given of the physical configuration of the information processing device 100. Fig. 18 shows an example configuration of a computer device that can be used as the information processing device 100. The computer device 500 has a control unit (CPU: Central Processing Unit) 510, a storage unit 520, a ROM (Read Only Memory) 530, a RAM (Random Access Memory) 540, a communication interface (IF: Interface) 550, and a user interface 560. The control unit 501 is also called a processor.
[0069] The communication interface 550 is an interface for connecting the computer device 500 to a communication network via wired communication means, wireless communication means, etc. The user interface 560 includes a display unit such as a display, and an input unit such as a keyboard, a mouse, and a touch panel.
[0070] The storage unit 520 is an auxiliary storage device that can store various types of data. The storage unit 520 does not necessarily have to be a part of the computer device 500, but may be an external storage device or cloud storage connected to the computer device 500 via a network. The storage unit 520 can be used, for example, as at least one of the attack information DB 120, the countermeasure information DB 130, and the aggregate information DB 140 shown in FIG. 2 .
[0071] The ROM 530 is a non-volatile storage device. For example, a semiconductor storage device with a relatively small capacity, such as a flash memory, is used for the ROM 530. The programs executed by the CPU 510 can be stored in the storage unit 520 or the ROM 530. The storage unit 520 or the ROM 530 stores various programs for realizing the functions of each unit in the information processing device 100, for example.
[0072] The program includes instructions (or software code) that, when loaded into a computer, cause the computer to perform one or more functions described in the embodiments. The program may be stored in a non-transitory computer-readable medium or a tangible storage medium. By way of example and not limitation, computer-readable media or tangible storage media include RAM, ROM, flash memory, solid-state drive (SSD) or other memory technologies, compact discs (CDs), digital versatile discs (DVDs), Blu-ray discs or other optical disc storage, magnetic cassettes, magnetic tapes, magnetic disk storage or other magnetic storage devices. The program may also be transmitted on a transitory computer-readable medium or a communication medium. By way of example and not limitation, transitory computer-readable media or communication media include electrical, optical, acoustic, or other forms of propagated signals.
[0073] The RAM 540 is a volatile storage device. Various semiconductor memory devices such as a dynamic random access memory (DRAM) or a static random access memory (SRAM) are used for the RAM 540. The RAM 540 can be used as an internal buffer for temporarily storing data and the like. The CPU 510 loads a program stored in the storage unit 520 or the ROM 530 into the RAM 540 and executes the program. The CPU 510 executes the program, thereby realizing the functions of each unit of the information processing device 100. The CPU 510 may have an internal buffer for temporarily storing data and the like.
[0074] Although the embodiments of the present disclosure have been described in detail above, the present disclosure is not limited to the above-described embodiments, and changes and modifications to the above-described embodiments that do not deviate from the spirit of the present disclosure are also included in the present disclosure.
[0075] For example, some or all of the above embodiments can be described as, but are not limited to, the following supplementary notes.
[0076] [Supplementary Note 1] An information processing device comprising: an analysis result acquisition unit that acquires multiple risk analysis results that are the results of risk analysis performed on each of multiple systems; an aggregation unit that aggregates the multiple risk analysis results using a predetermined evaluation index; and a visualization unit that presents information on the aggregated risk analysis results to a user.
[0077] [Supplementary Note 2] The information processing device according to Supplementary Note 1, wherein the risk analysis result includes a risk value in the event that an attack is carried out and a vulnerability used in the attack.
[0078] [Supplementary Note 3] The information processing device according to Supplementary Note 2, wherein the predetermined evaluation index is the number of systems, the aggregation unit counts the number of systems in which the vulnerability is used in an attack for each of a predetermined number of vulnerabilities, and the visualization unit displays the counted number of systems for each of the predetermined number of vulnerabilities.
[0079] [Supplementary Note 4] The information processing device according to Supplementary Note 3, wherein the aggregation unit selects the predetermined number of vulnerabilities based on the risk levels of the vulnerabilities.
[0080] [Supplementary Note 5] The information processing device according to Supplementary Note 2, wherein the risk analysis results include risk analysis results that evaluate the risk when an attack is carried out using one or more expected attack patterns against assets of the system being analyzed, the predetermined evaluation index is the number of assets included in the system, the aggregation unit counts the number of assets in the system that are used in attacks by the vulnerabilities for each of a predetermined number of vulnerabilities and for each of a predetermined number of systems, and the visualization unit displays the number of assets counted for each of the predetermined number of vulnerabilities and for each of the predetermined number of systems.
[0081] [Supplementary Note 6] The information processing device according to Supplementary Note 2, wherein the risk analysis results include risk analysis results that evaluate the risk when an attack is made against the system along an attack route, the predetermined evaluation index is the number of attack routes, the aggregation unit counts the number of attack routes associated with the vulnerabilities for each of a predetermined number of vulnerabilities and for each of a predetermined number of systems, and the visualization unit displays the number of attack routes counted for each of the predetermined number of vulnerabilities and for each of the predetermined number of systems.
[0082] [Supplementary Note 7] The information processing device described in Supplementary Note 2, wherein the risk analysis result includes a risk analysis result that evaluates the risk when an attack is made against the system along an attack route, the predetermined evaluation index is the number of the attack routes, the aggregation unit counts the number of the attack routes for each risk value of the attack route and for each predetermined number of systems, and the visualization unit displays the number of attack routes counted for each risk value of the attack route and for each predetermined number of systems.
[0083] [Supplementary Note 8] The information processing device according to Supplementary Note 7, wherein the visualization unit displays the number of attack routes counted for each risk value of the attack route and for each predetermined number of systems using a table, a bar graph, or a radar chart.
[0084] [Supplementary Note 9] The information processing device according to Supplementary Note 2, wherein the risk analysis result includes a risk analysis result that evaluates the risk in the event of an attack being made against the system along an attack route that is an attack route from an entry point included in the system to be analyzed to a target of attack, the attack route including one or more attack steps each including an attack source, an attack destination, and an attack pattern, the predetermined evaluation index is the number of the attack routes, the aggregation unit identifies vulnerabilities used in each of a plurality of attack patterns and counts the number of attack routes related to the identified vulnerabilities, and the visualization unit displays the identified vulnerabilities and the number of counted attack routes for each of the plurality of attack patterns.
[0085] [Supplementary Note 10] The information processing device described in Supplementary Note 2, wherein the risk analysis result includes a risk analysis result that evaluates the risk when an attack is made against the system along an attack route, the predetermined evaluation index is the number of the attack routes, the aggregation unit counts the number of attack routes associated with each vulnerability used in attacks against the multiple systems, and the visualization unit displays the number of attack routes counted for each vulnerability.
[0086] [Supplementary Note 11] The information processing device according to Supplementary Note 1 or 2, wherein the risk analysis result includes a risk analysis result that evaluates the risk in the event of an attack being made against a system along an attack route that is an attack route from an entry point included in the system to be analyzed to a target of attack, the attack route including one or more attack steps each including an attack source, an attack destination, and an attack pattern, the predetermined evaluation index is the number of the attack routes, the aggregation unit identifies attack patterns used in the attack routes and counts the number of attack routes related to the identified attack patterns, and the visualization unit displays the identified attack patterns and the number of the counted attack routes.
[0087] [Supplementary Note 12] The information processing device according to any one of Supplementary Notes 1 to 11, wherein the aggregation unit further aggregates the plurality of risk analysis results for each countermeasure against attacks on the system, and the visualization unit further displays information on the risk analysis results aggregated for each countermeasure.
[0088] [Supplementary Note 13] The information processing device according to Supplementary Note 12, wherein the aggregation unit counts the number of systems in which the countermeasure can be introduced and the number of locations where the countermeasure will be introduced, and the visualization unit displays, for each of the countermeasures, the number of systems in which the countermeasure can be introduced and the number of locations where the countermeasure will be introduced.
[0089] [Supplementary Note 14] The information processing device according to Supplementary Note 12 or 13, wherein the visualization unit acquires the countermeasure costs from a countermeasure cost information storage unit that stores countermeasure costs indicating the cost when the countermeasure is implemented, and displays the countermeasure costs for each of the countermeasures.
[0090] [Supplementary Note 15] The information processing device according to Supplementary Note 14, wherein the countermeasure cost information storage unit further stores the number of discounts to be implemented and a discount rate, and the visualization unit further displays the number of discounts to be implemented and the discount rate for each of the countermeasures.
[0091] [Supplementary Note 16] A risk visualization method comprising: acquiring multiple risk analysis results that are the results of risk analysis performed on each of multiple systems; aggregating the acquired multiple risk analysis results using a predetermined evaluation index; and presenting information on the aggregated risk analysis results to a user.
[0092] [Supplementary Note 17] A non-transitory computer-readable medium that stores a program for causing a computer to execute a process including acquiring multiple risk analysis results that are the results of risk analysis performed on each of multiple systems, aggregating the acquired multiple risk analysis results using a predetermined evaluation index, and presenting information on the aggregated risk analysis results to a user.
[0093] 10: Information processing device 11: Analysis result acquisition unit 12: Aggregation unit 13: Visualization unit 20: Risk analysis result 100: Information processing device 101: Collection unit 102: Common information aggregation unit 103: Risk visualization unit 120: Attack information DB 130: Countermeasure information DB 140: Aggregated information DB 200: System 201: Risk analysis result 500: Computer device 510: CPU 520: Storage unit 530: ROM 540: RAM 550: Communication IF 560: User IF
Claims
1. an analysis result acquisition unit that acquires a plurality of risk analysis results that are results of risk analysis performed on each of a plurality of systems; an aggregation unit that aggregates multiple risk analysis results using a predetermined evaluation index; and a visualization unit that presents the aggregated risk analysis result information to a user.
2. The information processing device according to claim 1 , wherein the risk analysis result includes a risk value in the event that an attack is carried out and a vulnerability used in the attack.
3. the predetermined evaluation index is the number of the systems; the aggregation unit counts the number of systems in which the vulnerability is used in an attack for each of a predetermined number of vulnerabilities; The information processing apparatus according to claim 2 , wherein the visualization unit displays the number of systems counted for each of the predetermined number of vulnerabilities.
4. the risk analysis result includes a risk analysis result that evaluates the risk when an attack is carried out against the assets of the system to be analyzed using one or more assumed attack patterns; the predetermined evaluation index is the number of assets included in the system; the aggregation unit counts, for each of a predetermined number of vulnerabilities and for each of a predetermined number of systems, the number of assets in the systems that are used in attacks using the vulnerabilities; The information processing apparatus according to claim 2 , wherein the visualization unit displays the number of assets counted for each of the predetermined number of vulnerabilities and for each of the predetermined number of systems.
5. the risk analysis result includes a risk analysis result that evaluates a risk in the event that an attack is made against the system along an attack route; the predetermined evaluation index is the number of attack routes; the aggregation unit counts the number of attack routes associated with the vulnerabilities for each of a predetermined number of vulnerabilities and for each of a predetermined number of systems; The information processing device according to claim 2 , wherein the visualization unit displays the number of attack routes counted for each of the predetermined number of vulnerabilities and for each of the predetermined number of systems.
6. the risk analysis result includes a risk analysis result that evaluates a risk in the event that an attack is made against the system along an attack route; the predetermined evaluation index is the number of attack routes; the aggregation unit counts the number of attack routes for each risk value of the attack route and for each predetermined number of systems; The information processing device according to claim 2 , wherein the visualization unit displays the number of attack routes counted for each risk value of the attack route and for each predetermined number of systems.
7. The aggregation unit further aggregates the plurality of risk analysis results for each countermeasure against an attack on the system, The information processing device according to claim 1 , wherein the visualization unit further displays information on the risk analysis results summarized for each of the countermeasures.
8. the aggregation unit counts the number of systems to which the countermeasures can be introduced and the number of locations to which the countermeasures can be introduced; The information processing device according to claim 7 , wherein the visualization unit displays, for each of the countermeasures, the number of systems in which the countermeasure can be introduced and the number of locations where the countermeasure can be introduced.
9. obtaining a plurality of risk analysis results that are results of risk analyses performed on each of the plurality of systems; aggregating the acquired multiple risk analysis results using a predetermined evaluation index; A risk visualization method comprising presenting information of the aggregated risk analysis results to a user.
10. obtaining a plurality of risk analysis results that are results of risk analyses performed on each of the plurality of systems; aggregating the acquired multiple risk analysis results using a predetermined evaluation index; A program for causing a computer to execute processing including presenting the aggregated risk analysis result information to a user.