Estimation device, estimation method, and estimation program

The estimation device accurately identifies the software targeted by an SBOM by applying URL estimation methods, addressing the challenge of incorrect software recognition and enhancing security by providing precise software component information.

WO2025109681A1PCT designated stage expired Publication Date: 2025-05-30NT T INC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2023/041800
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-11-21
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

Existing technologies face challenges in correctly recognizing the software targeted by a Software Bill of Materials (SBOM), due to the lack of a standardized method for expressing the target software, which can lead to incorrect identification of software components.

Method used

An estimation device, method, and program that receive an SBOM input, identify relevant items, and apply multiple URL estimation methods to accurately determine the URL of the software repository targeted by the SBOM.

Benefits of technology

Enables correct recognition of the software targeted by the SBOM, thereby reducing security risks by providing accurate information about the software components.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2023041800_30052025_PF_FP_ABST
    Figure JP2023041800_30052025_PF_FP_ABST
Patent Text Reader

Abstract

An estimation device (10) specifies an item in which information of target software in an SBOM is written in accordance with the format of the SBOM. The estimation device (10) estimates and outputs the URL of a repository of the target software, the URL being estimated by sequentially executing a plurality of URL estimation methods with respect to the value of the specified item. For example, when the value of the specified item is determined to be the URL of a repository service, the estimation device (10) estimates that the URL is the URL of the target software. When the value of the specified item is determined to be a PURL, the estimation device (10) estimates the URL of the repository of the software using management information of a software package in an ecosystem (for example, pypi or the like).
Need to check novelty before this filing date? Find Prior Art

Description

Estimation device, estimation method, and estimation program

[0001] The present invention relates to an estimation device, an estimation method, and an estimation program for estimating software that is the subject of an SBOM (Software Bill of Materials).

[0002] In order to reduce software security risks, it is necessary to understand the components that make up the software. SBOM contains information about the software components and the target software. By referring to this SBOM, users can obtain more information about the software they use, which can reduce security risks. SBOM formats are broadly divided into SPDX format and CycloneDX format.

[0003] NTIA, “SBOM at a Glance,” [online], [accessed November 6, 2023], Internet <URL: https: / / www.ntia.gov / files / ntia / publications / sbom_at_a_glance_ja.pdf>, <URL: https: / / www.ntia.gov / files / ntia / publications / sbom_at_a_glance_apr2021.pdf> PwC, “Full-scale adoption of SBOM: Structural challenges and solutions in the software supply chain,” [online], [accessed November 6, 2023], Internet <URL: https: / / www.pwc.com / jp / ja / knowledge / column / awareness-cyber-security / vulnerability-management-sbom1.html>

[0004] However, there is no strict definition of how to express which software information an SBOM represents. Therefore, there is a possibility that an SBOM may contain strings of information that are completely unrelated to the target software name, different information, or a string that is a modified version of the target software name. This makes it difficult to correctly identify the software that the SBOM targets.

[0005] Therefore, an object of the present invention is to solve the above-mentioned problems and correctly recognize software targeted by SBOM.

[0006] In order to solve the above-mentioned problems, the present invention is characterized by comprising a receiving unit that receives input of an SBOM (Software Bill of Materials), and an estimation unit that identifies an item in the SBOM in which information about the target software is described in accordance with the format of the SBOM, and sequentially executes a plurality of URL (Uniform Resource Locator) estimation methods on the information described in the identified item, thereby estimating and outputting the URL of a repository of the target software.

[0007] According to the present invention, the software targeted by the SBOM can be correctly recognized.

[0008] FIG. 1 is a diagram for explaining an overview of an estimation device. FIG. 2 is a diagram showing an example of the configuration of the estimation device. FIG. 3 is a diagram showing an example of an SBOMDB. FIG. 4 is a flowchart showing an example of a processing procedure executed by the estimation device. FIG. 5 is a diagram showing an example of a processing procedure executed by an estimation unit. FIG. 6 is a diagram showing an example of a process for determining a URL of a software repository. FIG. 7 is a diagram showing an example of the configuration of a computer that executes an estimation program.

[0009] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS Hereinafter, a description will be given of an embodiment of the present invention with reference to the drawings, but the present invention is not limited to the embodiment.

[0010] [Overview] First, an overview of an estimation device 10 according to this embodiment will be described with reference to Fig. 1. Based on an input SBOM, the estimation device 10 estimates a uniform resource locator (URL) of a repository of software targeted by the SBOM.

[0011] For example, the estimation device 10 estimates the URL (103) of a repository of software targeted by the SBOM based on information in the SBOM indicated by reference numeral 101. The estimation device 10 also estimates the URL (104) of a repository of software targeted by the SBOM based on information in the SBOM indicated by reference numeral 102.

[0012] In this way, if the URL of the repository of the software targeted by the SBOM can be estimated, the software targeted by the SBOM can be identified. Therefore, the estimation device 10 can correctly recognize the URL of the repository of the software targeted by the SBOM.

[0013] [Configuration Example] Next, a configuration example of the estimation device 10 will be described with reference to Fig. 2. The estimation device 10 includes, for example, an input / output unit 11, a communication unit 12, a storage unit 13, and a control unit 14.

[0014] The input / output unit 11 is an interface that controls input and output of various data. The communication unit 12 is a communication interface for performing data communication with external devices.

[0015] The storage unit 13 stores data, programs, etc. that are referenced when the control unit 14 executes various processes. The storage unit 13 is realized by a semiconductor memory element such as a random access memory (RAM) or a flash memory, or a storage device such as a hard disk or an optical disk. For example, the storage unit 13 includes an SBOMDB (SBOM database) or the like.

[0016] The SBOMDB stores an SBOM input via the input / output unit 11 in association with repository information (e.g., repository URL) of the software targeted by the SBOM, estimated by the control unit 14. For example, in the SBOM shown in Fig. 3, the URL of the repository of the software targeted by the SBOM with ID=1 is "https: / / github.com / AAA / aaa".

[0017] Returning to the description of Fig. 2, the control unit 14 controls the entire estimation device 10. The functions of the control unit 14 are realized, for example, by a CPU (Central Processing Unit) executing a program stored in the storage unit 13.

[0018] The control unit 14 includes, for example, an input receiving unit 141, an estimation unit 142, an inquiry receiving unit 143, and an estimation result reference unit 144. An information reference unit 145 indicated by a dashed line may or may not be provided, and the cases in which it is provided will be described later.

[0019] The input receiving unit 141 receives an SBOM input. The estimation unit 142 estimates repository information of the target software of the SBOM received by the input receiving unit 141. Then, the estimation unit 142 stores the estimated repository information (e.g., a URL of the repository) in the SBOMDB.

[0020] For example, the estimation unit 142 identifies an item in the SBOM that describes information about the target software, based on the format of the received SBOM (e.g., SPDX format or CycloneDX format).The estimation unit 142 then estimates the URL of the repository of the target software by sequentially executing multiple URL estimation methods on the identified item.Details of the processing executed by the estimation unit 142 will be described later using specific examples.

[0021] The inquiry reception unit 143 receives information about the SBOM that is the subject of an inquiry (for example, the ID of the SBOM) from the user. The estimation result reference unit 144 searches the SBOMDB using the information about the SBOM that is the subject of the inquiry as a key, and references repository information about the SBOM that is the subject of the inquiry and the software that is the subject of the inquiry.

[0022] For example, when the inquiry reception unit 143 receives an inquiry about an SBOM with ID=1, the estimation result reference unit 144 reads out and outputs the repository information for the SBOM with ID=1 and the software (target software) targeted by the SBOM from the SBOMDB shown in Figure 3.

[0023] [Example of Processing Procedure] Next, an example of processing procedure executed by the estimation device 10 will be described with reference to Fig. 4. For example, when the input receiving unit 141 of the estimation device 10 receives an SBOM input (S1), the estimation unit 142 estimates repository information of target software of the SBOM (S2). Then, the estimation unit 142 stores the estimated repository information of the target software in the SBOMDB (S3).

[0024] Thereafter, when the inquiry reception unit 143 receives information about the SBOM that is the subject of the inquiry from the user (e.g., the ID of the SBOM), the estimation result reference unit 144 reads out the estimation results of the repository information for the SBOM and the target software of the SBOM from the SBOMDB and makes the results referenced.

[0025] [Estimation of Repository Information] Next, an example of processing in which the estimation unit 142 estimates repository information (for example, repository URL) of target software from SBOM will be described with reference to FIG. 5 .

[0026] For example, the estimation unit 142 estimates the repository URL of the target software of the SBOM by sequentially executing the repository URL estimation method shown in S11 to S15 below.

[0027] First, the estimation unit 142 identifies an item (target item) in which information about the target software is described in accordance with the format of the input SBOM (S11).

[0028] For example, if the SBOM format is the CycloneDX format, the target items are metadata / component / name, and if the SBOM format is the SPDX format, the target items are name, documentName, documentNamespace, etc. Therefore, if the estimation unit 142 determines that the SBOM format is the CycloneDX format, it identifies metadata / component / name as the target item. On the other hand, if the estimation unit 142 determines that the SBOM format is the SPDX format, it identifies name, documentName, documentNamespace, etc. as the target items.

[0029] Next, the estimation unit 142 determines whether the value of the item (target item) identified in S11 is in URL format (S12).

[0030] In S12, if the estimation unit 142 determines that the value of the target item is in URL format (for example, if it is in the format shown by reference numeral 501 in FIG. 5), it determines whether the URL corresponds to the URL of a repository service. If the estimation unit 142 determines that the URL corresponds to the URL of a repository service, it identifies the URL as the repository URL of the target software.

[0031] For example, if the estimation unit 142 determines that the host name part of the URL corresponds to github.com, gitlab.com, or the like, it determines that the URL is a URL of a repository service.

[0032] On the other hand, if the estimation unit 142 determines that the host name part of the URL does not correspond to github.com, gitlab.com, or the like, it determines whether the URL is a repository URL as follows.

[0033] For example, consider a case where the value of the target item is https: / / AAA.com / shown in Fig. 6. In this case, the estimation unit 142 accesses https: / / AAA.com / multiple times and acquires a group of URLs indicated by reference numeral 601.

[0034] Next, the estimation unit 142 determines the structure of the URLs based on the acquired set of URLs. For example, the estimation unit 142 collects the values ​​of the first and second layers of the URL paths of the set of URLs indicated by reference numeral 601 (see reference numeral 602). Next, the estimation unit 142 determines the types of values ​​to be included in each layer based on the values ​​of each layer of the collected URLs.

[0035] For example, if the value in the first layer of the URL path is "1.0, 1.1, 2.0," the estimation unit 142 determines that the value in the first layer is a version name (see reference numeral 603). Also, if the value in the second layer is a file name with an extension specific to a programming language, such as "setup.py, main.java," the estimation unit 142 determines that the type of the value in the second layer is a software file name (see reference numeral 603).

[0036] Then, if the estimation unit 142 determines that a file name and version name exist in the URL path (or URL parameters) based on the types of values ​​contained in each layer of the URL, it determines that the URL is the URL of a software repository.

[0037] Returning to the description of Fig. 5, on the other hand, if the estimation unit 142 determines that the value of the target item is not in URL format, it determines whether the URL is in PURL (Persistent Uniform Resource Locator) format (S13).

[0038] In S13, if the estimation unit 142 determines that the value of the target item is in PURL format (see reference numeral 502 in FIG. 5), the URL of the software repository is identified using management information of the software package in the ecosystem (e.g., pypi, etc.).

[0039] For example, if the estimation unit 142 determines that the URL of the repository of the software exists in the reference information of the management information of the software package, it determines that this URL is the URL of the repository of the target software.

[0040] For example, the estimation unit 142 uses the package manager pypi to acquire a URL from reference information in management information of a software package. Then, the estimation unit 142 determines whether the acquired URL corresponds to the URL of a software repository using the same method as described above. If the estimation unit 142 determines that the acquired URL corresponds to the URL of a software repository, it determines that the URL is the URL of the repository of the target software.

[0041] On the other hand, if the estimation unit 142 determines that the value of the target item is neither URL format nor PURL format, it determines whether there is information in URL format / PURL format in items other than the target item (reference information items) (S14).

[0042] For example, the estimation unit 142 determines whether the value of the reference information item of the SBOM (see symbol 503 in Figure 5) is a software repository URL, as in S12 and S13, and if it determines that it is a software repository URL, it identifies this URL as the repository URL of the target software.

[0043] On the other hand, if the estimation unit 142 is unable to identify the URL of the repository for the target software using any of the methods S12 to S14 above, it searches the repository using the target name of the SBOM and determines whether or not there is a hit (S15).

[0044] For example, the estimation unit 142 normalizes the name of the target in the SBOM (for example, by removing spaces, standardizing to lowercase letters, etc.) and then searches the repository service. If the estimation unit 142 finds the most famous repository among the repositories that exactly match the name as a result of the search, it identifies the URL of that repository as the URL of the repository of the target software.

[0045] For example, as shown by reference numeral 504 in Fig. 5, if the name of the target of the SBOM is "aaa," a search is performed in the repository service using a search query using the name "aaa." If the search result identifies the most famous repository that exactly matches the name "aaa," the estimation unit 142 identifies the URL of that repository as the URL of the repository of the target software.

[0046] If the estimation unit 142 cannot identify the URL of the repository of the target software even after executing the above steps S11 to S15, it determines that the URL of the repository of the target software cannot be identified and ends the process.

[0047] The estimation unit 142 performs the above process to identify the URL of the repository of the SBOM target software. If the URL of the repository of the SBOM target software can be identified, information about the SBOM target software can be obtained by accessing the URL of the repository.

[0048] The estimation device 10 may further include an information reference unit 145 (see FIG. 2 ). In response to a request from a user, the information reference unit 145 accesses the URL of the repository of the target software of the SBOM estimated by the estimation unit 142 and causes the information of the target software to be referenced. This allows the user to check the information of the target software of the SBOM.

[0049] [System Configuration, etc.] The components of each unit shown in the figure are conceptual functional units and do not necessarily have to be physically configured as shown. In other words, the specific form of distribution and integration of each device is not limited to that shown, and all or part of them can be functionally or physically distributed and integrated in any unit depending on various loads, usage conditions, etc. Furthermore, all or any part of the processing functions performed by each device can be realized by a CPU and a program executed by the CPU, or can be realized as hardware using wired logic.

[0050] Furthermore, among the processes described in the above embodiments, all or part of the processes described as being performed automatically can be performed manually, or all or part of the processes described as being performed manually can be performed automatically using a known method.In addition, the information including the processing procedures, control procedures, specific names, various data and parameters shown in the above documents and drawings can be changed as desired unless otherwise specified.

[0051] [Program] The above-described estimation device 10 can be implemented by installing a program (estimation program) as package software or online software on a desired computer. For example, by executing the above-described program on an information processing device, the information processing device can function as the estimation device 10. The information processing device referred to here includes mobile communication terminals such as smartphones, mobile phones, and PHS (Personal Handyphone Systems), and terminals such as PDAs (Personal Digital Assistants).

[0052] 7 is a diagram showing an example of a computer that executes an estimation program. The computer 1000 includes, for example, a memory 1010 and a CPU 1020. The computer 1000 also includes a hard disk drive interface 1030, a disk drive interface 1040, a serial port interface 1050, a video adapter 1060, and a network interface 1070. These components are connected by a bus 1080.

[0053] The memory 1010 includes a read-only memory (ROM) 1011 and a random access memory (RAM) 1012. The ROM 1011 stores a boot program such as a basic input / output system (BIOS). The hard disk drive interface 1030 is connected to a hard disk drive 1090. The disk drive interface 1040 is connected to a disk drive 1100. A removable storage medium such as a magnetic disk or optical disk is inserted into the disk drive 1100. The serial port interface 1050 is connected to a mouse 1110 and a keyboard 1120, for example. The video adapter 1060 is connected to a display 1130, for example.

[0054] The hard disk drive 1090 stores, for example, an OS 1091, an application program 1092, a program module 1093, and program data 1094. That is, the programs that define the processes executed by the above-described estimation device 10 are implemented as program modules 1093 in which computer-executable code is written. The program modules 1093 are stored, for example, in the hard disk drive 1090. For example, the program modules 1093 for executing processes similar to those of the functional configuration of the estimation device 10 are stored in the hard disk drive 1090. Note that the hard disk drive 1090 may be replaced with an SSD (Solid State Drive).

[0055] Data used in the processing of the above-described embodiment is stored as program data 1094, for example, in the memory 1010 or the hard disk drive 1090. The CPU 1020 then reads the program module 1093 or the program data 1094 stored in the memory 1010 or the hard disk drive 1090 into the RAM 1012 as necessary and executes them.

[0056] The program module 1093 and program data 1094 may not necessarily be stored in the hard disk drive 1090, but may also be stored in a removable storage medium and read by the CPU 1020 via the disk drive 1100 or the like. Alternatively, the program module 1093 and program data 1094 may be stored in another computer connected via a network (such as a local area network (LAN) or a wide area network (WAN)). The program module 1093 and program data 1094 may then be read by the CPU 1020 from the other computer via the network interface 1070.

[0057] REFERENCE SIGNS LIST 10 Estimation device 11 Input / output unit 12 Communication unit 13 Storage unit 14 Control unit 141 Input reception unit 142 Estimation unit 143 Inquiry reception unit 144 Estimation result reference unit 145 Information reference unit

Claims

1. A estimating device, comprising: a receiving unit that receives an input of an SBOM (Software Bill of Materials); and an estimating unit that identifies an item in the SBOM in which information of target software is described according to the format of the SBOM, and sequentially executes a plurality of URL (Uniform Resource Locator) estimation methods on the information described in the identified item, thereby estimating and outputting a URL of a repository of the target software.

2. The estimating device according to claim 1, wherein when the information described in the identified item is a URL and the URL is determined to be a URL of a software repository from a host name or a path name of the URL, the estimating unit estimates the URL as the URL of the repository of the target software; and when the information described in the identified item is a PURL (Persistent Uniform Resource Locator) and it is determined that a URL of a software repository exists in management information of a software package of an ecosystem described in the PURL, the estimating unit estimates the URL of the repository as the URL of the repository of the target software.

3. An estimating method executed by an estimating device, the method comprising: receiving an input of an SBOM (Software Bill of Materials); identifying an item in the SBOM in which information of target software is described according to the format of the SBOM, and sequentially executing a plurality of URL (Uniform Resource Locator) estimation methods on the information described in the identified item, thereby estimating and outputting a URL of a repository of the target software.

4. A estimating program for causing a computer to execute: receiving an input of an SBOM (Software Bill of Materials); identifying an item in the SBOM in which information of target software is described according to the format of the SBOM, and sequentially executing a plurality of URL (Uniform Resource Locator) estimation methods on the information described in the identified item, thereby estimating and outputting a URL of a repository of the target software.

Citation Information

Patent Citations

  • System for automated malicious software detection

    US11436330B1