Vulnerability analysis support system and vulnerability analysis support method

The vulnerability analysis support system leverages deep learning to process product and vulnerability information, addressing the complexity of embedded products and enhancing the detection and analysis of software vulnerabilities, thereby improving vulnerability identification and reporting.

WO2025115055A1PCT designated stage expired Publication Date: 2025-06-05HITACHI SOLUTIONS TECH LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2023/042314
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-11-27
Publication Date
2025-06-05

AI Technical Summary

Technical Problem

The increasing complexity of embedded products with integrated software and hardware makes it difficult for operators to accurately identify vulnerabilities, leading to challenges in discovering and addressing potential cyber threats.

Method used

A vulnerability analysis support system that collects and processes product specification information and vulnerability case information using deep learning techniques to identify relevant vulnerability cases and extract related product specification phrases, thereby assisting in the wide collection of information on software vulnerabilities.

Benefits of technology

The system effectively aids in the identification and analysis of software vulnerabilities in embedded products, facilitating the creation of detailed reports and improving the accuracy and efficiency of vulnerability detection and mitigation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2023042314_05062025_PF_FP_ABST
    Figure JP2023042314_05062025_PF_FP_ABST
Patent Text Reader

Abstract

A vulnerability analysis support system 100 which: identifies vulnerability cases associated with the specifications of a product to be analyzed in which software is incorporated into hardware by calculating the degree of similarity between each text in product specification information, which is information including text representing the specifications of the product to be analyzed, and each text in vulnerability case information, which is information including text representing each vulnerability case of each product in which software is incorporated into hardware; generates information about the identified vulnerability cases as first similar past case information; and calculates the degree of similarity between each text associated with the generated first similar past case information and each text registered in the product specification information or text associated with each text registered in the product specification information and thereby generates first product specification-related phrase information, which is information about the degree of similarity and phrases of the specifications of the product to be analyzed that are associated with the vulnerabilities indicated by the first similar past case information.
Need to check novelty before this filing date? Find Prior Art

Description

Vulnerability analysis support system and vulnerability analysis support method

[0001] The present invention relates to a vulnerability analysis support system and a vulnerability analysis support method.

[0002] With the development of so-called IoT (Internet of Things) technology, software embedded in various products such as in-vehicle devices (car navigation systems, etc.) and mobile phones is now conducting various communications, which increases the risk of cyber attacks due to vulnerabilities in the software.

[0003] As a system for assessing vulnerabilities in such products (embedded products), for example, Patent Document 1 discloses a vulnerability risk assessment system that includes a vulnerability detection unit that detects vulnerabilities in equipment based on system configuration information and vulnerability case information, an equipment risk assessment model generation unit that generates an equipment risk assessment model that evaluates the risk that vulnerabilities may pose to equipment by associating vulnerability nodes with equipment nodes, and a business-related risk assessment model generation unit that generates a business-related risk assessment model for evaluating the risk that detected vulnerabilities may pose to a specified business process by additionally arranging business-related nodes in the equipment risk assessment model and associating the business-related nodes with the equipment nodes.

[0004] JP 2017-224053 A

[0005] However, because these products integrate software and hardware to achieve their functions, their designs are becoming specialized and complex. This makes it difficult for businesses wanting to implement vulnerability countermeasures to accurately determine the product configuration required to identify the vulnerabilities they need to address. As a result, identifying vulnerabilities is also becoming more difficult. For example, it may be impossible to find information about vulnerabilities that need to be discovered, or the effort required to discover vulnerabilities may be excessive.

[0006] The present invention has been made in light of the above background, and its purpose is to provide a vulnerability analysis support system and a vulnerability analysis support method that can support the wide collection of vulnerability information in software embedded in products.

[0007] One aspect of the present invention for solving the above problem is a vulnerability analysis support system including: a storage device that stores product specification information, which is information including text that represents the specifications of a product to be analyzed, in which software is embedded in hardware; and vulnerability case information, which is information including text that represents each case of a vulnerability in each product in which software is embedded in hardware; and a control device that executes a similar past case extraction process that calculates a similarity between each text in the product specification information and each text in the vulnerability case information to identify a case of vulnerability related to the specifications of the product to be analyzed and generate information on the identified case of vulnerability as first similar past case information; and a related term similarity extraction process that calculates a similarity between each text associated with the generated first similar past case information and each text registered in the product specification information or text associated with the each text, to generate first product specification-related term information that is information on the similarity between the text and the text.

[0008] According to the present invention, it is possible to support the wide collection of vulnerability information in software embedded in products. Configurations and effects other than those described above will become clear from the following description of the embodiments.

[0009] 1 is a diagram illustrating an example of the configuration of a vulnerability analysis support system according to an embodiment of the present invention. FIG. 1 is a diagram illustrating an example of hardware included in a deep learning process management device. FIG. 2 is a diagram illustrating an example of hardware included in a support information output device. FIG. 3 is a diagram illustrating an example of data constituting a vulnerability case information DB. FIG. 4 is a diagram illustrating an example of the data structure of threat vulnerability standard information. FIG. 5 is a diagram illustrating an example of the data structure of classification-based vulnerability standard information. FIG. 6 is a diagram illustrating an example of the data structure of type-based attack standard information. FIG. 7 is a diagram illustrating an example of the data structure of vulnerability countermeasure standard information. FIG. 8 is a diagram illustrating an example of the data structure of attack pattern standard information. FIG. 9 is a diagram illustrating an example of the data structure of a threat vulnerability analysis primary report. FIG. 10 is a diagram illustrating an example of data constituting a product specification information DB. FIG. 11 is a diagram illustrating an example of the data structure of a product-related term list. FIG. 12 is a diagram illustrating an example of the data structure of a software parts bill. FIG. 13 is a diagram illustrating an example of the data structure of security requirements. FIG. 14 is a diagram illustrating an example of the data structure of a product block diagram. FIG. 15 is a diagram illustrating an example of functions included in a deep learning process management device. FIG. 16 is a diagram illustrating an example of functions included in a support information output device. FIG. 17 is a flow chart illustrating an example of deep learning processing (first half). FIG. 18 is a flow chart illustrating an example of deep learning processing (second half). FIG. 19 is a diagram illustrating an example of a first learned similar past case DB. FIG. 19 is a diagram illustrating an example of the data structure of a first learned product-related term list DB. FIG. 19 is a diagram illustrating an example of the data structure of a first learned software parts bill DB. FIG. 1 is a diagram showing an example of the data configuration of a first learned security requirement DB. FIG. 2 is a diagram showing an example of the data configuration of a first learned product system component DB. FIG. 3 is a diagram showing an example of a second learned similar past case DB to be created. FIG. 4 is a diagram showing an example of a second learned product related term list DB to be created. FIG. 5 is a diagram showing an example of a second learned software parts bill DB to be created. FIG. 6 is a diagram showing an example of a second learned security requirement DB to be created. FIG. 7 is a diagram showing an example of a second learned system component DB to be created. FIG. 8 is a flow diagram explaining an example of support information output processing. FIG. 9 is a diagram showing an example of a threat vulnerability analysis secondary report to be created.

[0010] Hereinafter, an embodiment of the present invention will be described with reference to the drawings.

[0011] 1 is a diagram illustrating an example of the configuration of a vulnerability analysis support system 100 according to this embodiment. The vulnerability analysis support system 100 includes a vulnerability case information DB 326, a product specification information DB 327, an intermediate processing DB 321, a deep learning completed DB 322, a deep learning process management device 323, and a support information output device 324.

[0012] The vulnerability analysis support system 100 is an information processing system that supports the analysis of software vulnerabilities in products (embedded products, such as in-vehicle devices (car navigation devices), mobile phones, and parts or product manufacturing equipment) that operate to perform predetermined functions by incorporating software into hardware. The vulnerability analysis support system 100 is used, for example, by a user who wants to know information about vulnerabilities that exist in a target embedded product (hereinafter referred to as the target product).

[0013] The vulnerability case information DB 326 is a database that accumulates information on software vulnerability cases (such as explanations of the cases) in various products. As will be described later, the vulnerability case information DB 326 includes vulnerability information from various data sources.

[0014] The product specification information DB 327 is a database that stores information related to the specifications of the target product. The product specification information DB 327 is created by a user based on interviews with the owner, vendor, etc. of the target product, or is automatically created using a predetermined tool, etc. However, the amount of information stored in the product specification information DB 327 is limited.

[0015] In this embodiment, the product specification information DB 327 stores a database of hardware components and their configurations, software configurations, and security requirements as specifications of the target product, but may also include other specification information that is useful for identifying the product specifications.

[0016] The deep learning process management device 323 extracts vulnerability cases related to the target product based on the vulnerability case information DB 326 and the product specification information DB 327, and also extracts product terms related to the target product, and outputs each extracted information to the intermediate processing DB 321.

[0017] In addition, the deep learning process management device 323 further extracts vulnerability cases related to the target product based on the vulnerability case information DB 326 and the output intermediate processing DB 321, etc., and also further extracts product terms related to the target product, and outputs each of the extracted information to the deep learning DB 322.

[0018] The support information output device 324 creates report data (secondary threat vulnerability analysis report) regarding vulnerabilities of the target product based on the output deep learned DB 322.

[0019] The vulnerability case information DB 326, product specification information DB 327, deep learning process management device 323, intermediate processing DB 321, deep learned DB 322, and support information output device 324 are communicatively connected to each other via wired or wireless communication networks 325, 328, such as the Internet, a LAN (Local Area Network), a WAN, or a dedicated line.

[0020] 2 is a diagram illustrating an example of hardware included in the deep learning process management device 323. The deep learning process management device 323 includes a processor 301 (control device) such as a central processing unit (CPU), a memory 302 such as a random access memory (RAM) or a read only memory (ROM), a storage 303 such as a hard disk drive (HDD) or a solid state drive (SSD), a communication I / F 305 configured with a network interface card (NIC), a wireless communication module, a universal serial interface (USB) module, a serial communication module, or the like, and an input / output I / F 306 such as a keyboard, a mouse, a touch panel, or a display.

[0021] 3 is a diagram showing an example of hardware included in the support information output device 324. The support information output device 324 includes a processor 311 (control device) such as a CPU (Central Processing Unit), a memory 312 such as a RAM (Random Access Memory) or a ROM (Read Only Memory), a storage 313 such as a HDD (Hard Disk Drive) or an SSD (Solid State Drive), a communication I / F 315 configured with a NIC (Network Interface Card), a wireless communication module, a USB (Universal Serial Interface) module, a serial communication module, or the like, and an input / output I / F 316 such as a keyboard, a mouse, a touch panel, or a display.

[0022] (Vulnerability Case Information DB) Fig. 4 is a diagram showing an example of data constituting the vulnerability case information DB 326. The vulnerability case information DB 326 includes databases for threat vulnerability standard information 1, classification-specific vulnerability standard information 9, type-specific attack standard information 10, vulnerability countermeasure standard information 11, attack pattern standard information 12, and threat vulnerability analysis primary report 201.

[0023] (Threat Vulnerability Standard Information) FIG. 5 is a diagram illustrating an example of the data configuration of the threat vulnerability standard information 1. The threat vulnerability standard information 1 is information in which standard cases of publicly known vulnerabilities are classified by vulnerability category. Specifically, the threat vulnerability standard information 1 includes information on each vulnerability, a description of each vulnerability, a risk value of each vulnerability, a classification of each vulnerability, a platform of each vulnerability, a publication date and last update date of each vulnerability, the source of advisory data for each vulnerability (URL of the description), and a URL where information on each vulnerability is disclosed (URL of the description). Note that the term "description" used in this specification includes not only a description but also any text such as a word, a phrase, or a summary.

[0024] In this embodiment, individual vulnerabilities are identified by CVE (Common Vulnerabilities and Exposures) numbers, vulnerability classifications are identified by CWE (Common Weakness Enumeration) numbers, vulnerability risk values ​​are evaluation values ​​based on CVSS (Common Vulnerability Scoring System), and platforms are identified based on CPE (Common Platform Enumeration).

[0025] (Classification-Based Vulnerability Standard Information) FIG. 6 is a diagram illustrating an example of the data configuration of the classification-based vulnerability standard information 9. The classification-based vulnerability standard information 9 is information provided by a predetermined business operator, in which vulnerability cases are classified by vulnerability category. Specifically, the classification-based vulnerability standard information 9 includes information such as the classification (CWE) of each vulnerability, the name of each classification, a description of each classification, a subordinate classification (child ID) of each classification, a superior classification number (parent ID) of each classification, the phase in which the vulnerability related to each classification was developed, the platform of the vulnerability related to each classification, observed examples of vulnerabilities common to the vulnerabilities related to each classification, a description of mitigation measures (countermeasures) for the vulnerability related to each classification, a description of detection methods for the vulnerability related to each classification, the attack pattern number of the vulnerability related to each classification, the creation date of the information of each classification, the update date of the information of each classification, and the URL where the information of the vulnerability related to each classification is made public (the URL of the description).

[0026] (Standard Attack Information by Type) FIG. 7 is a diagram illustrating an example of the data configuration of the standard attack information by type 10. The standard attack information by type 10 is information on examples of attacks against vulnerabilities, provided by a predetermined provider (which may be the same provider as the standard vulnerability information by category 9). Specifically, the standard attack information by type 10 includes information on each attack, the name of each attack, a description of each attack (summary and additional description), factors that cause the possibility of each attack (attack possibility), the severity of each attack, attacks (child IDs) subordinate to each attack, attacks (parent IDs) superior to each attack, a description of the prerequisites (causes) for each attack, skills required to respond to each attack, a description of resources required to discover each attack, the classification (CWE) to which the vulnerability related to each attack belongs, the creation date of each attack information, the update date of each attack information, and the URL where the information on each attack is made public (URL of the description).

[0027] In this embodiment, each attack is identified based on CAPEC (Common Attack Pattern Enumeration and Classification).

[0028] 8 shows an example of the data structure of the vulnerability countermeasure standard information 11. The vulnerability countermeasure standard information 11 is information on countermeasures for each vulnerability provided by a predetermined provider (a provider different from the providers of the classification-based vulnerability standard information 9 and the type-based attack standard information 10). Specifically, the vulnerability countermeasure standard information 11 includes an alert code for each vulnerability, a description of the overview of each vulnerability (summary description), a description of the risk assessment of each vulnerability, the products affected by each vulnerability, the classification (CWE) to which each vulnerability belongs, the publication date of each vulnerability information, a description of the countermeasures for each vulnerability, the URL of the advisory for each vulnerability (description URL), and the URL where each vulnerability information is published (description URL).

[0029] (Attack Pattern Standard Information) Figure 9 is a diagram showing an example of the data configuration of the attack pattern standard information 12. The attack pattern standard information 12 is information on standard attack patterns used against vulnerabilities, provided by a predetermined provider (which may be the same provider as the provider of the classification-based vulnerability standard information 9 and the type-based attack standard information 10). Specifically, the attack pattern standard information 12 includes information such as the ID of each attack pattern, the name of each attack pattern, a description of the overview of each attack pattern, case studies of vulnerabilities attacked using each attack pattern, a description of countermeasures (mitigation measures) for each attack pattern, a detection method for each attack pattern, reference literature related to each attack pattern, the tactical stage of each attack pattern, the target of attack for each attack pattern, the version of each attack pattern, the creation date and last update date of the information, and the URL where the information for each attack pattern is published (the URL of the description).

[0030] 10 is a diagram showing an example of the data configuration of a threat vulnerability analysis primary report 201. The threat vulnerability analysis primary report 201 is information on a draft report of vulnerability cases related to a target product that was previously created by a user. Specifically, the threat vulnerability analysis primary report 201 includes information such as the publication date of each report, the management number of each report, the title of each report, the risk score (CVSS) of the vulnerability reported in each report, a description of the vulnerability reported in each report, a description of the impact of the vulnerability reported in each report, systems affected by the vulnerability reported in each report, and a reference URL for each report (URL of the description).

[0031] The above-described data configuration of each database in the vulnerability case information DB 326 is an example. The vulnerability case information DB 326 may include, for example, academic papers reporting vulnerability cases, blogs, advisory data from vendors, or case data created by various media such as commercial sites. This case data includes explanatory text about vulnerability cases or information about their sources.

[0032] 11 is a diagram showing an example of data constituting the product specification information DB 327. The product specification information DB 327 includes databases for a product-related term list 5, a software parts list 6, security requirements 7, and a product block diagram 8.

[0033] (Product-Related Phrase List) Fig. 12 is a diagram showing an example of the data configuration of the product-related phrase list 5. The product-related phrase list 5 is a list of phrases related to hardware parts (for example, components or modules, or their functions) that make up a product. The product-related phrase list 5 includes information such as a list of phrases related to each hardware part (hereinafter referred to as product-related phrases), the name of each hardware configuration, the URL of the developer where information about each hardware part is disclosed (URL of the description), and the description of each hardware part.

[0034] (Software parts table) Fig. 13 is a diagram showing an example of the data structure of a software parts table 6. The software parts table 6 is information about the structure of software incorporated into products. The software parts table 6 includes information such as a list of software incorporated into each product, the name of each piece of software, the URL of the developer where information about each piece of software is disclosed (URL of the description), and the description of each piece of software.

[0035] 14 is a diagram showing an example of the data configuration of security requirements 7. The security requirements 7 are information on security requirements (security standards and security requirement definitions) for each product field. The security requirements 7 are data including identifiers of one or more requirements that make up each security requirement related to software, and descriptions of those requirements.

[0036] (Product Block Diagram) Fig. 15 is a diagram showing an example of the data configuration of a product block diagram 8. The product block diagram 8 is information about the hardware configuration of a product (for example, a list of module names or a list of information function assets). The product block diagram 8 includes information such as a list of the hardware configuration of each product (a list of databases in which hardware information is stored), the name of each hardware configuration, the URL of the developer where information about each hardware configuration is disclosed, and a description of each hardware configuration.

[0037] 16 is a diagram illustrating an example of functions included in the deep learning process management device 323. The deep learning process management device 323 includes functional units, namely, a similar past case extraction unit 3231, a related phrase similarity extraction unit 3232, a similar past case re-extraction unit 3233, and a related phrase similarity re-extraction unit 3234.

[0038] The similar past case extraction unit 3231 calculates the similarity between each text in the product specification information (product specification information DB 327) and each text in the vulnerability case information (vulnerability case information DB 326) to identify vulnerability cases related to the specifications of the product being analyzed, and generates information on the identified vulnerability cases (CVE information) as first similar past case information.

[0039] The similar past case extraction unit 3231 stores the various information and the first similar past case information generated in this process in a first learned similar past case DB 202 (described later) of the intermediate processing DB 321 .

[0040] The related phrase similarity extraction unit 3232 calculates the similarity between each text (sentences and phrases related to vulnerabilities) associated with the first similar past case information generated by the similar past case extraction unit 3231 and each text registered in the product specification information (product specification information DB 327) or text associated with each of the texts (for example, text of phrases indicating higher-level concepts), thereby generating first product specification related phrase information, which is information on the phrases in the specifications of the product being analyzed that are related to the vulnerabilities indicated by the first similar past case information and the degree of similarity.

[0041] The related term similarity extraction unit 3232 stores the various information and first product specification related term information generated in this process for each term category (hardware parts, hardware configuration, software configuration, security requirements) in the first learned product related term list DB203, first learned software parts table DB204, first learned security requirements DB205, and first learned product system component DB206 of the intermediate processing DB321, which are described below.

[0042] Next, the similar past case re-extraction unit 3233 calculates the similarity between each text in the first product specification related term information (first learned product related term list DB203, first learned software parts bill DB204, first learned security requirements DB205, and first learned product system component DB206) and each text (sentences and phrases related to vulnerabilities) associated with the first similar past case information, thereby identifying vulnerability cases related to the specifications of the product being analyzed, and generating information on the identified vulnerability cases (information on CVEs, etc.) as second similar past case information.

[0043] The similar past case re-extraction unit 3233 stores the various information and second similar past case information generated in this process in the second learned similar past case DB 207 of the deep learned DB 322 described later.

[0044] Next, the related phrase similarity re-extraction unit 3234 calculates the similarity between each text (sentences and phrases related to vulnerabilities) associated with the second similar past case information generated by the similar past case re-extraction unit 3233 and each text in the first product specification related phrase information (first learned product related phrase list DB203, first learned software parts bill DB204, first learned security requirements DB205, and first learned product system component DB206), thereby generating second product specification related phrase information, which is information on the phrases in the specifications of the product being analyzed that are related to the vulnerabilities indicated by the second similar past case information and the degree of similarity.

[0045] The related term similarity re-extraction unit 3234 stores the various information and second product specification related term information generated in this process for each term category in the second learned product related term list DB208, second learned software parts bill DB209, second learned security requirements DB210, and second learned product system component DB211 of the deep learned DB322 described below.

[0046] 17 is a diagram illustrating an example of functions provided in the support information output device 324. The support information output device 324 includes a search unit 3241 and a report creation unit 3242.

[0047] The search unit 3241 searches for text registered in the product specification information (product specification information DB 327) from the second similar past case information and second product specification related phrase information (deep learned DB 322) generated by the similar past case re-extraction unit 3233 and the related phrase similarity re-extraction unit 3234, and outputs the searched information to an output device.

[0048] The report creation unit 3242 accepts input of vulnerability information of the target product from the user and outputs the input information to the output device while displaying the second similar past case information and second product specification related phrase information generated by the similar past case re-extraction unit 3233 and the related phrase similarity re-extraction unit 3234. The report creation unit 3242 creates a secondary threat vulnerability analysis report 213 including the input information.

[0049] The functions of the functional units of each information processing device in the vulnerability analysis support system 100 described above are realized by the processors 301 and 311 reading programs from the memories 302 and 312 or the storages 303 and 313. Furthermore, each program can be recorded on, for example, a portable or fixed recording medium and distributed. Note that all or part of these programs may be realized using virtual information processing resources provided using virtualization technology, process space separation technology, or the like, such as a virtual server provided by a cloud system. Furthermore, all or part of these programs may be realized by a service provided by the cloud system via, for example, an API (Application Programming Interface). Next, the processing performed in the vulnerability analysis support system 100 will be described.

[0050] 18 and 19 are flow diagrams illustrating an example of a process (hereinafter referred to as deep learning process s1) for creating the deep learning-completed DB 322. The deep learning process s1 is started, for example, when the deep learning process management device 323 receives a predetermined instruction input from a user.

[0051] First, as shown in FIG. 18, the similar past case extraction unit 3231 of the deep learning process management device 323 stores cases having text related to product specifications registered in the product specification information DB 327 and information on attacks related to those cases from the vulnerability case information DB 326, taking into consideration the context of the text of the case, etc., in the first learned similar past case DB 202 (first similar past case information) of the intermediate processing DB 321 (s101).

[0052] Specifically, first, the similar past case extraction unit 3231 creates vectors of text (sentences or words) for each record (for each vulnerability and attack type) in each database (Threat Vulnerability Standard Information 1, Classification-Specific Vulnerability Standard Information 9, Type-Specific Attack Standard Information 10, Vulnerability Countermeasure Standard Information 11, Attack Pattern Standard Information 12, and Threat Vulnerability Analysis Primary Report 201) in the vulnerability case information DB 326 (creation of distributed representation data). This creates vectors representing each vulnerability and each attack.

[0053] In this embodiment, this vectorization extracts words whose frequency of occurrence exceeds a predetermined threshold due to the context (corpus analysis). In this case, conversion of words into distributed representations can be achieved by, for example, acquiring embedding vectors from an intermediate layer using Word2Vec or BERT (Bidirectional Encoder Representations from Transformers), which have a neural network structure. However, this vectorization method is merely an example. For example, the similar past case extraction unit 3231 may create vectors for each sentence in the vulnerability case information DB 326 for each vulnerability and each attack. To create these vectors, for example, Doc2Vec or SentenceBERT, which perform contextual analysis (morphological analysis, syntactic analysis, and semantic analysis), can be used.

[0054] Furthermore, the similar past case extraction unit 3231 creates vectors for each piece of text related to each hardware component, software component, software requirement, and hardware configuration in the product specification information DB 327 (product-related term list 5, software components table 6, security requirements 7, product block diagram 8), just as in the case of the vulnerability case information DB 326. For example, the similar past case extraction unit 3231 creates vectors for each record in each database in the product specification information DB 327. This creates vectors that represent the specifications (hardware components, software components, software requirements, and hardware configuration) of the target product.

[0055] Then, the similar past case extraction unit 3231 calculates the similarity (for example, cosine similarity) between the calculated target product specification vector and each vulnerability and attack vector.

[0056] The similar past case extraction unit 3231 then identifies vulnerability cases and attack vectors whose similarity to vectors of words in the specifications of the target product exceeds a predetermined threshold (for example, 0.95), and stores information on some or all of the records in the vulnerability case information DB 326 related to the identified vectors, together with the similarity, in the first learned similar past case DB 202 (first similar past case information). In this way, by using a deep learning technique, the similar past case extraction unit 3231 can extract information on vulnerability cases and attacks that are highly relevant to the target product (first similar past case information).

[0057] 20 is a diagram showing an example of the first learned similar past case DB 202. The first learned similar past case DB 202 has records of vulnerability cases (CVEs) extracted from each database (Threat Vulnerability Standard Information 1, Classification-Based Vulnerability Standard Information, Type-Based Attack Standard Information 10, and Vulnerability Countermeasure Standard Information 11) related to vulnerability cases created by each media in the vulnerability case information DB 326.

[0058] Specifically, the first learned similar past case DB 202 has, for each record, data including the management number of a vulnerability case, the information source (such as a URL) of the case, the title of the information source, the name of the vulnerability, a phrase in the information source of the vulnerability (for example, a phrase describing an overview of the vulnerability), the risk score (CVSS) of the vulnerability, the information source (such as a URL) of advisory data for the vulnerability case, the vulnerability classification (CWE), a list 2021 of phrases in the information source that are similar to the above phrase, a list 2022 of combinations of phrases whose similarity exceeds a predetermined threshold, the corresponding vulnerability classification (CWE), and a list 2023 of numbers of vulnerability cases that are highly similar to each combination of phrases (here, CVEs). Note that the similarity is calculated using, for example, the average value of the dot product of vectors.

[0059] In addition to the above information, the first learned similar past case DB 202 may also contain records extracted from a database related to blogs, papers, etc. that describe vulnerabilities.

[0060] Next, as shown in FIG. 18, for each record in each database (product-related term list 5, software parts table 6, security requirements 7, and product block diagram 8) of the product specification information DB 327, the related term similarity extraction unit 3232 extracts product-related terms registered in that record from the sentences of vulnerability cases related to the first learned similar past case DB 202 (first similar past case information) generated in s101, and stores the information on the extracted terms (first product specification-related term information) in each corresponding database (first learned product-related term list DB 203, learned first software parts table DB 204, first learned security requirements DB 205, and first learned product system component DB 206) (s102).

[0061] For example, in the case of the product-related phrase list 5, the related phrase similarity extraction unit 3232 extracts words from each record of the product-related phrase list 5 that appear with a predetermined frequency or more (in terms of context). Meanwhile, the related phrase similarity extraction unit 3232 extracts each word from the record of the vulnerability case information DB 326 corresponding to each case (identified by CVE, etc.) in the first learned similar past case DB 202 generated in s101. The related phrase similarity extraction unit 3232 extracts, from the extracted words in the vulnerability case information DB 326, words whose similarity to any word in the product-related phrase list 5 exceeds a predetermined threshold (e.g., 0.95). This extracts words related to the specifications of the target product from the vulnerability case information (first learned similar past case DB 202). Note that, because the first learned similar past case DB 202 includes words from the product specification information DB 327, words from the product specification information DB 327 are also extracted here.

[0062] The related phrase similarity extraction unit 3232 also executes the above process for the software parts table 6, the security requirements 7, and the product block diagram 8.

[0063] (First Learned Product-Related Phrases List DB) Figure 21 is a diagram showing an example of the data configuration of the first learned product-related phrase list DB203. In addition to the data contained in the product-related phrase list 5, the first learned product-related phrase list DB203 contains data including a list 2031 of phrases for each hardware component registered in the product specification information DB327 (product-related phrase list 5), a list 2032 of similarities between mutually similar phrases, a list 2033 of phrases that are superordinate concepts of each phrase, and a list 2034 of phrases and their similarities for vulnerability cases related to the first learned similar past case DB202 whose similarities to those phrases exceed a predetermined threshold. Note that the similarities are calculated using the dot product of vectors, etc.

[0064] The term that is the higher concept may be set by input by the user, or may be extracted from a predetermined database (public information such as manufacturer specifications).Furthermore, the similarity may be calculated without using the term that is the higher concept.

[0065] (First Learned Software Components Table DB) FIG. 22 is a diagram showing an example of the data configuration of the first learned software components table DB 204. In addition to the data of the software components table 6, the first learned software components table DB 204 is data that includes a list 2041 of terms registered in the product specification information DB 327 (e.g., the software components table 6), a list 2042 of terms in the vulnerability case information DB 326 or the first learned similar past case DB 202 that are similar to those terms and the similarities between those terms, a list 2043 of terms that are superordinate concepts of each term, and a list 2044 of terms of vulnerability cases related to the first learned similar past case DB 202 whose similarities to those terms exceed a predetermined threshold and their similarities. Note that the similarities are calculated using an inner product of vectors, etc.

[0066] (First Learned Security Requirement DB) FIG. 23 is a diagram showing an example of the data configuration of the first learned security requirement DB 205. In addition to the data of security requirement 7, the first learned security requirement DB 205 is data that includes a list 2051 of terms registered in the product specification information DB 327 (e.g., security requirement 7), a list 2052 of terms in the vulnerability case information DB 326 or the first learned similar past case DB 202 that are similar to those terms and the similarities between those terms, a list 2053 of terms that are superordinate concepts of each term, and a list 2054 of terms of vulnerability cases related to the first learned similar past case DB 202 whose similarities to those terms exceed a predetermined threshold and their similarities. Note that the similarities are calculated using an inner product of vectors, etc.

[0067] (First Learned Product System Component DB) FIG. 24 is a diagram showing an example of the data configuration of the first learned product system component DB 206. In addition to the data of the product block diagram 8, the first learned product system component DB 206 is data that includes a list 2061 of terms registered in the product specification information DB 327 (e.g., product block diagram 8), a list 2062 of terms in the vulnerability case information DB 326 or the first learned similar past case DB 202 that are similar to those terms and the similarities between those terms, a list 2063 of terms that are superordinate concepts of each term, and a list 2064 of terms of vulnerability cases related to the first learned similar past case DB 202 whose similarities to those terms exceed a predetermined threshold and their similarities. Note that the similarities are calculated using an inner product of vectors, etc.

[0068] Next, in deep learning process s1, the similar past case re-extraction unit 3233 sets a threshold value for similarity (for example, 0.95, hereinafter referred to as the similarity threshold value) for re-extracting similar cases in process s104 described below.

[0069] Then, as shown in FIG. 19, the similar past case re-extraction unit 3233, in a process similar to s101, stores cases having text related to product specifications registered in the first product specification related term information (first learned product related term list DB203, first learned software parts bill DB204, first learned security requirements DB205, and first learned product system component DB206) and information on attacks related to those cases from the first similar past case information (first learned similar past case DB202) generated in s101, taking into consideration the context of the text of the case, etc., in the second learned similar past case DB207 (second similar past case information) of the deep learned DB322 (s103).

[0070] Specifically, the similar past case re-extraction unit 3233 creates, for each record (for each silent case and attack), a vector of text in each database (threat vulnerability standard information 1, classification-specific vulnerability standard information 9, type-specific attack standard information 10, vulnerability countermeasure standard information 11, attack pattern standard information 12, and threat vulnerability analysis primary report 201) of the vulnerability case information DB 326 corresponding to the first similar past case information (first learned similar past case DB 202). Furthermore, the similar past case re-extraction unit 3233 creates a vector of text for each hardware component, software component, software requirement, and hardware configuration in the first product specification related term information (first learned product related term list DB 203, first learned software parts bill DB 204, first learned security requirements DB 205, and first learned product system component DB 206).

[0071] Then, the similar past case re-extraction unit 3233 calculates the similarity between the vectors of the words in the target product specifications (hardware components, software components, software requirements, and hardware configuration) calculated above and the vectors of each vulnerability case and attack.

[0072] Next, the similar past case re-extraction unit 3233 identifies vulnerability cases and attack vectors whose similarity to the vectors of words in the specifications of the target product exceeds the current similarity threshold, and stores information on some or all of the records in the first similar past case information (first learned similar past case DB 202) related to the identified vectors, together with the similarity, in the second learned similar past case DB 207 (second similar past case information). In this way, by using a deep learning technique, the similar past case re-extraction unit 3233 can extract vulnerability cases (second similar past case information) that are highly relevant to the target product.

[0073] In addition, as described below, when executing this process for the second time or later, the similar past case re-extraction unit 3233 may use, in addition to the first similar past case information (first learned similar past case DB 202), data from the deep learned DB 322 that has already been created and includes the second learned similar past case DB 207.

[0074] Next, similar to the processing of s102, the related phrase similarity re-extraction unit 3234 extracts product-related phrases registered in the databases for the first product specification related phrase information (first learned product related phrase list DB203, learned first software parts table DB204, first learned security requirements DB205, and first learned product system component DB206) from the vulnerability case sentences, etc. (vulnerability case information DB326) related to the second learned similar past case DB208 (second similar past case information) generated in s103, and stores the information of the extracted phrases (second product specification related phrase information) in each corresponding database (second learned product related phrase list DB208, second learned software parts table DB209, second learned security requirements DB210, and second learned product system component DB211) (s104).

[0075] For example, in the case of the first learned product-related phrase list DB203, the related phrase similarity re-extraction unit 3234 extracts words from each record in the first learned product-related phrase list DB203 that appear with a predetermined frequency or more (in terms of context). Meanwhile, the related phrase similarity re-extraction unit 3234 extracts each word from the record in the vulnerability case information DB326 corresponding to each case (identified by CVE, etc.) in the second learned similar past case DB207 generated in s103. The related phrase similarity extraction unit 3232 extracts, from each of the extracted words in the vulnerability case information DB326, words whose similarity to any of the words in the product-related phrase list 5 exceeds the current similarity threshold. As a result, words related to the specifications of the target product are extracted from the vulnerability case information (second learned similar past case DB207).

[0076] In addition, the related term similarity re-extraction unit 3234 may also use the terms in the first learned product related term list DB203, the first learned software parts list DB204, the first learned security requirements DB205, and the first learned product system component DB206 of the intermediate processing DB321 as terms to be compared for similarity, in addition to the second similar past case information (second learned similar past case DB207).

[0077] Next, the related term similarity re-extraction unit 3234 determines whether to extract similar past cases and related terms (s103, s104) again (s105). For example, the related term similarity re-extraction unit 3234 determines whether the current similarity threshold is equal to or greater than a predetermined threshold (e.g., 0.7).

[0078] If similar past cases and related phrases are not to be extracted again (s105: NO), the related phrase similarity re-extraction unit 3234 ends the deep learning process s1.

[0079] If extraction of similar past cases and related phrases is to be performed again (s105: YES), the related phrase similarity re-extraction unit 3234 reduces the current similarity threshold by a predetermined value (e.g., 0.05) and repeats the processing from s103 onwards. Note that the processing for determining whether to repeat the processing described here is one example. The related phrase similarity re-extraction unit 3234 may set the number of times the processing will be repeated in advance and determine whether or not to extract similar past cases and related phrases again based on the number of times the processing will be repeated.

[0080] 25 is a diagram showing an example of the created second trained similar past case DB 207. In the second trained similar past case DB 207, data on the calculation process and calculation results in the processing of step S103 are added to the data in the first trained similar past case DB 202.

[0081] For example, the second learned similar past case DB 207 additionally stores, for each vulnerability case, data including a list 2071 of each phrase constituting the description of the vulnerability information source, a list 2072 of mutually similar phrases, a list 2073 of similarities between each similar phrase, and a list 2074 of numbers of vulnerability cases (here, CVEs) that are highly similar to each combination of phrases and their similarities. Note that the similarities are calculated using, for example, the average value of the dot products of vectors. These data are added the number of times the process of step S103 is repeated.

[0082] 26 is a diagram showing an example of the created second learned product-related phrase list DB 208. In the second learned product-related phrase list DB 208, data on the calculation process and calculation results in the processing of step S104 is added to the first learned product-related phrase list DB 203.

[0083] For example, the second learned product-related phrase list DB208 additionally includes data for each phrase related to a hardware part of a product, including a list 2081 of phrases in the explanation of the phrase for each hardware part in the list 2034 of phrases and similarities, a list 2082 of mutually similar phrases and similarities between phrases in list 2081, and a list 2083 of phrases in the second learned similar past case DB207 whose similarity to each phrase exceeds a predetermined threshold and their similarities. Phrases related to the product's hardware are set in this list 2083. Data in the above lists 2081 to 2083 is added the number of times the process of step S104 is repeated.

[0084] 27 is a diagram showing an example of the created second trained software components table DB 209. In the second trained software components table DB 209, data on the calculation process and calculation results in the processing of s104 is added to the first trained software components table DB 204.

[0085] For example, the second learned software components table DB 209 additionally stores data including, for each term related to a software component, a list 2091 of terms in the description of each software component in the list 2044 of terms and similarities, a list 2092 of terms similar to each other in list 2091 and similarities between the terms, and a list 2093 of terms in the second learned similar past case DB 207 whose similarity to each term exceeds a predetermined threshold and their similarities. Terms related to the software components of the product are set in this list 2093. Data in the above lists 2091 to 2093 is added the number of times the process of step S104 is repeated.

[0086] 28 is a diagram showing an example of the created second learned security requirement DB 210. In the second learned security requirement DB 210, data on the calculation process and calculation results in the processing of step s104 is added to the first learned security requirement DB 205.

[0087] For example, the second learned security requirement DB 210 additionally stores data for each term related to a security requirement, including a list 2101 of terms in the description of each security requirement in the list 2054 of terms and similarities, a list 2102 of terms similar to each other in list 2101 and similarities between the terms, and a list 2103 of terms in the second learned similar past case DB 207 whose similarity to each term exceeds a predetermined threshold and their similarities. Terms related to the security requirements of the product are set in list 2103. Data in the above lists 2101 to 2103 is added the number of times the process of step S104 is repeated.

[0088] 29 is a diagram showing an example of the created second trained system component DB 211. In the second trained system component DB 211, data on the calculation process and calculation results in the processing of s104 is added to the first trained system component DB 206.

[0089] For example, the second learned system component DB 211 additionally stores data for each term related to hardware configuration, including a list 2111 of terms in the description of each hardware configuration in the list 2064 of terms and similarities, a list 2112 of terms similar to each other in list 2111 and similarities between the terms, and a list 2113 of terms in the second learned similar past case DB 207 whose similarity to each term exceeds a predetermined threshold and their similarities. Terms related to the hardware configuration of the product are set in list 2113. Data in the above lists 2111 to 2113 is added the number of times the process of step S104 is repeated.

[0090] 30 is a flow diagram illustrating an example of the support information output process s2. The support information output process s2 is started at a predetermined timing after the deep learning process s1 is executed, or when a predetermined instruction is input to the support information output process s2 by the user.

[0091] First, the support information output device 324 copies the contents of the threat vulnerability analysis primary report 201 to create initial data for the threat vulnerability analysis secondary report 213 .

[0092] Then, the support information output device 324 uses each term in each database of the second learned product-related term list DB208 and the second learned software parts table DB209, which contain information related to the hardware and software of the target product, as a keyword, and searches for vulnerability cases (e.g., CVE) in the vulnerability case information DB326 that contain a predetermined percentage or all of the keywords, for example, by word matching search (s201).

[0093] For example, the support information output device 324 may accept input of the above keywords from the user while displaying the contents of the vulnerability case information DB 326, the second learned similar past case DB 207, the second learned product-related term list DB 208, or the second learned software parts table DB 209 on the screen, or may automatically extract and search each term in each database of the second learned product-related term list DB 208 and the second learned software parts table DB 209.

[0094] In addition to the second learned product-related phrase list DB208 and the second learned software parts table DB209, a search may be performed again using the phrases in the product-related phrase list 5 and the software parts table 6 as keywords.

[0095] Then, the support information output device 324 adds (s202) the vulnerability information searched in s201 (information in the vulnerability case information DB 326) to the threat vulnerability analysis secondary report 213. As a result, the contents of the second learned product-related term list DB 208 and the second learned software parts bill DB 209 are reflected in the threat vulnerability analysis secondary report 213.

[0096] For example, the support information output device 324 may add information about vulnerabilities that the user inputs based on the information displayed on the screen in s201 to the secondary threat vulnerability analysis report 213, or may automatically add the content searched for in s201 to the secondary threat vulnerability analysis report 213.

[0097] Next, the support information output device 324 adds information such as the cause of the vulnerability and countermeasures for the vulnerability to the secondary threat vulnerability analysis report 213 (s203).

[0098] For example, the support information output device 324 displays the contents of the secondary threat vulnerability analysis report 213 created up to step s202 while accepting input of each piece of information from the user. At this time, the support information output device 324 may display information from the second learned similar past case DB 207 on the screen as reference information. As a result, the contents of the second learned similar past case DB 207 are reflected in the secondary threat vulnerability analysis report 213.

[0099] The support information output device 324 then stores the input information in association with information about security requirements already registered in the secondary threat vulnerability analysis report 213, using each security requirement in the second learned security requirement DB 210 as a keyword. At this time, the support information output device 324 may display the security requirement 7 or the information about the security requirement stored in the second learned security requirement DB 210 on the screen as reference information. As a result, the contents of the security requirement 7 or the second learned security requirement DB 210 are reflected in the secondary threat vulnerability analysis report 213.

[0100] Next, the support information output device 324 adds information on the attack pattern related to the vulnerability to the threat vulnerability analysis secondary report 213 (s204).

[0101] For example, the support information output device 324 displays the contents of the threat vulnerability analysis secondary report 213 created up to s203 (particularly the contents corresponding to the second learned similar past case DB 207) while accepting input of each piece of information from the user. At this time, the support information output device 324 may display on the screen as reference information information on the product hardware configuration stored in the product block diagram 8 or the second learned product system component DB 211. As a result, the contents of the product block diagram 8 or the second learned product system component DB 211 are reflected in the threat vulnerability analysis secondary report 213.

[0102] Next, the support information output device 324 recalculates the risk value of each vulnerability based on the threat vulnerability analysis secondary report 213 created so far, and reflects the calculated risk value in the threat vulnerability analysis secondary report 213 (s205).

[0103] For example, the support information output device 324 reflects the attack pattern information added in s204 in a predetermined calculation formula (e.g., CVSS v.3.1) to recalculate the risk value automatically or in response to user data input. At this time, the support information output device 324 may display the contents of the threat vulnerability analysis secondary report 213 created up to s203 (e.g., the contents corresponding to the second learned product system component DB 211) as reference information.

[0104] Next, the support information output device 324 adds additional information (comments) to the threat vulnerability analysis secondary report 213 (s206).

[0105] For example, the support information output device 324 displays the contents of the threat vulnerability analysis secondary report 213 created up to step s205, while accepting input of each piece of information from the user. The additional information may be, for example, information about similar past cases, information about related vulnerabilities, or information about the specific impact of vulnerabilities on the product.

[0106] In the above, we have described a case where the support information output device 324 supports the creation of the secondary threat vulnerability analysis report 213 by displaying the deep learning DB 322 created in the deep learning process s1, but it may also support the creation of the secondary threat vulnerability analysis report 213 by displaying the intermediate processing DB 321 (without executing the processes of s103 to s105).

[0107] 31 is a diagram showing an example of a created threat vulnerability analysis secondary report 213. This threat vulnerability analysis secondary report 213 includes, as added or updated data items to the threat vulnerability analysis primary report 201, the following: source of information on the related vulnerability 2131 (e.g., CVE number), keywords related to the vulnerability 2132, a report on the vulnerability (CVE) 2133, reasons why the risk value (CVSS score) was determined to be what it was 2134, cases related to the vulnerability 2135, comments on the impact of the vulnerability on the industry 2136, causes of the vulnerability 2137, countermeasures for the vulnerability 2138, classification of related vulnerabilities 2139 (CWE), a diagram 2140 showing attack patterns against the vulnerability, attack sequence of the vulnerability 2141, a recalculated risk value 2142 (CVSS score), reasons for the recalculated risk value 2143, statements regarding the possibility of attack by industry 2144, statements regarding an assessment of the impact of the vulnerability by industry 2145, and statements regarding countermeasures for the vulnerability by industry 2146.

[0108] As described above, the vulnerability analysis support system 100 according to this embodiment calculates the similarity between each text in the product specification information DB 327 and each text in the vulnerability case information DB 326, thereby identifying cases of vulnerabilities (vulnerabilities in software incorporated in the product) related to the specifications of the product to be analyzed, generating information on the identified vulnerability cases as first similar past case information (first learned similar past case DB 202) (s101), and further generating information on each text associated with the first similar past case information (first learned similar past case DB 202) (s102). By calculating the similarity between each text registered in the product specification information DB327 (such as a sentence of a vulnerability case) and each text registered in the product specification information DB327 or a text associated with each text (such as a superordinate term), information on the terms and similarity of the specifications of the product being analyzed that are related to the vulnerability indicated by the first similar past case information (first product specification related term information; first learned product related term list DB203, first learned software parts list DB204, first learned security requirements DB205, and first learned product system component DB206) is generated (s102).

[0109] As a result, even if the information on terms related to the specifications of the product being analyzed is limited, by utilizing each term in the vulnerability case information DB326 (performing deep learning), it is possible to widely extract information on vulnerability cases and terms related to the product specifications of the product being analyzed, as well as information on the degree of that relationship.

[0110] In this way, the vulnerability analysis support system 100 of this embodiment can collect a wide range of vulnerability information in software embedded in products. Based on this information, the user can create materials and the like that include a wide range of vulnerability information related to the target product.

[0111] Furthermore, the vulnerability analysis support system 100 according to this embodiment calculates the similarity between each text in the first product specification related phrase information (the first learned product related phrase list DB203, the first learned software parts list DB204, the first learned security requirement DB205, and the first learned product system component DB206) and each text (the text in the vulnerability case information DB326) associated with the first similar past case information (the first learned similar past case DB202), thereby identifying cases of vulnerabilities (vulnerabilities in software incorporated in the product) related to the specifications of the product to be analyzed, and The information is generated as second similar past case information (s103), and further, by calculating the similarity between each text (such as the sentence of the vulnerability case in the vulnerability case information DB326) associated with the generated second similar past case information and each text in the first product specification related phrase information, information on the phrases and similarity of the specifications of the product to be analyzed that are related to the vulnerability indicated by the second similar past case information (second product specification related phrase information; second learned product related phrase list DB208, second learned software parts bill DB209, second learned security requirements DB210, and second learned product system component DB211) is generated (s104).

[0112] In this way, by further performing similar deep learning based on the first product specification related term information (first learned product related term list DB203, first learned software parts list DB204, first learned security requirements DB205, and first learned product system component DB206) created through deep learning, etc., and the first similar past case information (first learned similar past case DB202), it is possible to extract a wider range of information on vulnerability cases and terms related to the product specifications of the product being analyzed, as well as information on the degree of that relationship.

[0113] In addition, the vulnerability analysis support system 100 of this embodiment includes, as product specification information (product specification information DB327), information on the hardware, software, and security requirements that make up the product to be analyzed, and from this, first product specification related term information and second product specification related term information are generated.

[0114] In this way, by taking into consideration important factors in the specifications of the embedded product, it is possible to accurately extract information on vulnerabilities in the software embedded in the product.

[0115] Furthermore, after executing the processes of s103 and s104 (extraction of second similar past case information and extraction of second product specification related term information), the vulnerability analysis support system 100 according to this embodiment reduces the similarity threshold value for those processes by a predetermined value, and if it determines that the similarity threshold value is equal to or greater than the judgment value, executes the processes of s103 and s104 again.

[0116] This allows the collection of words and phrases related to the relationship between the specifications of the target product and vulnerabilities to be limited to an appropriate range.

[0117] In addition, the vulnerability analysis support system 100 according to this embodiment searches for text registered in the product specification information (product specification information DB 327) of the target product from the second similar past case information or the second product specification related phrase information (deep learned DB 322), and displays the searched information.

[0118] This makes it possible to reliably extract words and phrases related to the relationship between the specifications of the target product and vulnerabilities.

[0119] Furthermore, the vulnerability analysis support system 100 according to this embodiment displays the contents of the second similar past case information and the second product specification related phrase information (deep learned DB 322) on the screen, accepts input of vulnerability information for the target product from the user, and outputs the input information to the secondary threat vulnerability analysis report 213.

[0120] This allows users to create detailed and relevant reports about vulnerabilities in the target products.

[0121] At this time, the vulnerability analysis support system 100 according to this embodiment displays on the screen the vulnerability cases, causes, and countermeasures for the vulnerabilities associated with the second similar past case information (second learned similar past case DB 207).

[0122] This allows the user to more reliably create reports that will help resolve vulnerability issues in the target product.

[0123] The present invention is not limited to the above-described embodiments, and can be implemented using any components within the scope of the present invention. The above-described embodiments and modifications are merely examples, and the present invention is not limited to these contents as long as the characteristics of the invention are not impaired. Furthermore, although various embodiments and modifications have been described above, the present invention is not limited to these contents. Other aspects conceivable within the scope of the technical idea of ​​the present invention are also included within the scope of the present invention.

[0124] For example, part of the hardware provided in each device of this embodiment may be provided in another device.

[0125] Furthermore, each program of each device may be provided in another device, a program may consist of multiple programs, or multiple programs may be integrated into one program.

[0126] 100 Vulnerability analysis support system, 326 Vulnerability case information DB, 327 Product specification information DB, 321 Intermediate processing DB, 322 Deep learning DB, 323 Deep learning process management device, 324 Support information output device

Claims

1. A vulnerability analysis support system comprising: a storage device that stores product specification information, which is information including text representing the specifications of a product to be analyzed in which software is incorporated into hardware, and vulnerability case information, which is information including text representing each case of vulnerability of each product in which software is incorporated into hardware; and a control device that executes a similar past case extraction process of calculating the similarity between each text in the product specification information and each text in the vulnerability case information to identify cases of vulnerability related to the specifications of the product to be analyzed, and generating information on the identified cases of vulnerability as first similar past case information, and a related phrase similarity extraction process of calculating the similarity between each text associated with the generated first similar past case information and each text registered in the product specification information or text associated with each of the texts to generate first product specification related phrase information, which is information on the phrases of the specifications of the product to be analyzed related to the vulnerability indicated by the first similar past case information and the similarity thereof.

2. The vulnerability analysis support system according to claim 1, wherein the control device executes a similar past case re-extraction process of calculating the similarity between each text in the first product specification related phrase information and each text associated with the first similar past case information to identify cases of vulnerability related to the specifications of the product to be analyzed, and generating information on the identified cases of vulnerability as second similar past case information, and a related phrase similarity re-extraction process of calculating the similarity between each text associated with the generated second similar past case information and each text in the first product specification related phrase information to generate second product specification related phrase information, which is information on the phrases of the specifications of the product to be analyzed related to the vulnerability indicated by the second similar past case information and the similarity thereof.

3. The memory device includes information on the hardware, software, and security requirements that constitute the product to be analyzed as the product specification information. In the similar past case extraction process, the first similar past case information is generated by calculating the similarity between each text related to the hardware, software, and security requirements in the product specification information and each text in the vulnerability case information. In the related phrase similarity extraction process, the first product specification related phrase information is generated by calculating the similarity between each text in the generated first similar past case information and the vulnerability case information and each text regarding the hardware, software, and security requirements registered in the product specification information. The vulnerability analysis support system according to claim 1.

4. The memory device includes information on the hardware, software, and security requirements that constitute the product to be analyzed as the product specification information. In the similar past case re-extraction process, the second similar past case information is generated by calculating the similarity between each text related to the hardware, software, and security requirements in the first product specification related phrase information and each text in the vulnerability case information and the first similar past case information. In the related phrase similarity re-extraction process, the second product specification related phrase information is generated by calculating the similarity between each text in the generated second similar past case information and the first similar past case information and each text regarding the hardware, software, and security requirements registered in the first product specification related phrase information. The vulnerability analysis support system according to claim 2.

5. After executing the similar past case re-extraction process and the related phrase similarity re-extraction process, the control device decreases the value of the threshold related to the second similar past case information and the second product specification related phrase information by a predetermined value, determines whether the decreased threshold value is equal to or greater than a predetermined determination value, and if it is determined that the decreased threshold value is equal to or greater than the determination value, executes the similar past case re-extraction process and the related phrase similarity re-extraction process again. The vulnerability analysis support system according to claim 2.

6. The control device executes a search process of searching for the text registered in the product specification information from the generated second similar past case information or second product specification related phrase information, and outputs the searched information to an output device. The vulnerability analysis support system according to claim 2.

7. The control device executes a report creation process of receiving an input of information on the vulnerability of the product to be analyzed from a user while displaying the generated second similar past case information or second product specification related phrase information, and outputs the input information to an output device. The vulnerability analysis support system according to claim 2.

8. The storage device stores information including text representing a vulnerability case, a cause, and a countermeasure against the vulnerability as the vulnerability case information. In the report creation process, the control device displays the vulnerability case, the cause, and the countermeasure against the vulnerability associated with the second similar past case information. The vulnerability analysis support system according to claim 7.

9. A vulnerability analysis support method by an information processing device including a storage device that stores product specification information including text representing the specification of a product to be analyzed in which software is incorporated into hardware, and vulnerability case information including text representing each case of vulnerability of each product in which software is incorporated into hardware, and a control device. The control device executes a similar past case extraction process of calculating the similarity between each text in the product specification information and each text in the vulnerability case information to identify a vulnerability case related to the specification of the product to be analyzed, and generating information on the identified vulnerability case as first similar past case information, and a related phrase similarity extraction process of calculating the similarity between each text associated with the generated first similar past case information and each text registered in the product specification information or text associated with each text to generate first product specification related phrase information which is information on the phrases of the specification of the product to be analyzed related to the vulnerability indicated by the first similar past case information and the similarity.

Citation Information

Patent Citations

  • Brittleness information generator and brittleness evaluation device

    JP2019192101A

  • Vulnerability estimation device and vulnerability estimation method

    JP2020052767A

  • Automated mapping for identifying known vulnerabilities in software products

    US20220004643A1