Countermeasure assistance device, countermeasure assistance method, and storage medium

The countermeasure support device and method address the challenge of inefficient security measure implementation in complex information systems by assessing risk and difficulty to optimize countermeasure selection and deployment.

WO2025141836A1PCT designated stage expired Publication Date: 2025-07-03NEC CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2023/047148
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-28
Publication Date
2025-07-03

AI Technical Summary

Technical Problem

Existing systems struggle to efficiently implement security countermeasures in information processing systems with multiple devices, as the impact of stopping facilities is significant, leading to a lack of implementation of necessary security measures.

Method used

A countermeasure support device and method that acquires risk and difficulty information, calculates efficiency values for security measures, and outputs information on countermeasures to improve the efficiency of reducing attack risks in information processing systems with multiple devices.

Benefits of technology

Enhances the efficiency of selecting and implementing security countermeasures by providing risk and difficulty assessments, allowing for informed decision-making to reduce attack risks effectively.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2023047148_03072025_PF_FP_ABST
    Figure JP2023047148_03072025_PF_FP_ABST
Patent Text Reader

Abstract

Provided is a countermeasure assistance device and the like which make it possible to perform assistance for enhancing efficiency in reducing risks of attacks when selecting an information processing device for performing a security countermeasure in an information processing system including a plurality of information processing devices. A countermeasure assistance device according to one embodiment of the present disclosure comprises: a risk information acquisition means for acquiring risk information representing an attack risk level change which is for a communication path connecting an intrusion entrance device and an attack target device in an information network including a plurality of information processing devices and a communication network connecting the plurality of information processing devices and which is obtained when a security countermeasure is taken for an information processing device on the communication path; a difficulty information reception means for receiving difficulty information indicating a difficulty level of the countermeasure; an efficiency calculation means for calculating, as an efficiency value, the value of the difficulty level of the countermeasure per prescribed change amount of the attack risk level change on the basis of the attack risk level change and the difficulty level; and an output means for outputting information on the countermeasure in a manner according to the efficiency degree indicated by the efficiency value.
Need to check novelty before this filing date? Find Prior Art

Description

Countermeasure support device, countermeasure support method, and storage medium

[0001] The present disclosure relates to a countermeasure support device, a countermeasure support method, and a storage medium that support security-related countermeasures.

[0002] In recent years, the importance of security measures for information processing systems and the like has been increasing. However, for information processing systems in factories, hospitals, and other critical infrastructures, for example, the impact of shutting down the equipment of the information processing system is significant. Even if it is necessary to shut down the equipment to implement security measures for such information systems, the impact of shutting down the equipment is so great that it can be difficult to implement security measures. As a result, there are cases where security measures are not implemented for such information systems.

[0003] Patent Literature 1 discloses a system that determines candidate security measures for attack methods against a user device and displays the effectiveness, impact, and cost of the determined candidate security measures. The effectiveness of the measures is the ratio of the number of attack methods that can be reduced by implementing the candidate security measures to the total number of attack methods. The impact is the ratio of business scenarios that will fail due to the implementation of the candidate security measures, out of multiple business scenarios. The cost is the expense required to implement the candidate security measures.

[0004] Japanese Patent Application Laid-Open No. 2018-045327

[0005] The technology of Patent Document 1 can compare the effectiveness, impact, and cost of multiple security countermeasure candidates for individual user devices. However, there are information processing systems, such as the above-mentioned critical infrastructure information processing systems, that include multiple information processing devices and in which security countermeasures for each information processing device are not necessarily easy. The technology of Patent Document 1 cannot help improve the efficiency of reducing the risk of attacks when selecting information processing devices for which security countermeasures should be implemented in such information processing systems.

[0006] One of the objectives of the present disclosure is to provide a countermeasure support device, a countermeasure support method, and a storage medium that can support improving the efficiency of reducing risks posed by attacks when selecting an information processing device to implement security measures in an information processing system that includes multiple information processing devices.

[0007] A countermeasure support device according to one aspect of the present disclosure includes: a risk information acquisition means for acquiring risk information representing a change in the attack risk level of a communication path connecting an entry device and an attack target device when security measures are taken on an information processing device on the communication path connecting an entry device and an attack target device in an information network including a plurality of information processing devices and a communication network connecting the plurality of information processing devices; a difficulty information receiving means for receiving difficulty information indicating the difficulty level of the countermeasure; an efficiency calculation means for calculating, from the change in the attack risk level and the difficulty level, the value of the difficulty level of the countermeasure per predetermined amount of change in the attack risk level as an efficiency value; and an output means for outputting information about the countermeasure in a manner corresponding to the level of efficiency indicated by the efficiency value.

[0008] A countermeasure support method according to one aspect of the present disclosure, in an information processing system including a plurality of information processing devices and a communication network connecting the plurality of information processing devices, acquires risk information representing a change in the attack risk level of a communication path connecting an intrusion device and an attack target device when security measures are taken for an information processing device on the communication path connecting an intrusion device and an attack target device, receives difficulty information indicating the difficulty level of the countermeasure, calculates an efficiency value for the difficulty level of the countermeasure per a predetermined amount of change in the attack risk level from the change in the attack risk level and the difficulty level, and outputs information about the countermeasure in a manner corresponding to the level of efficiency indicated by the efficiency value.

[0009] A storage medium according to one aspect of the present disclosure stores a program that causes a computer to execute the following steps in an information processing system including a plurality of information processing devices and a communication network connecting the plurality of information processing devices: a risk information acquisition process that acquires risk information representing a change in the attack risk level of a communication path connecting an entry device and an attack target device when security measures are taken on information processing devices on the communication path connecting the entry device and the attack target device; a difficulty information receiving process that receives difficulty information indicating the difficulty level of the measure; an efficiency calculation process that calculates, from the change in the attack risk level and the difficulty level, the value of the difficulty level of the measure per predetermined amount of change in the attack risk level as an efficiency value; and an output process that outputs information about the measure in a manner corresponding to the level of efficiency indicated by the efficiency value.

[0010] One aspect of the present disclosure is also realized by a program stored in the above-mentioned storage medium.

[0011] The present disclosure has an effect of being able to support improving the efficiency of reducing the risk of attacks when selecting an information processing device for which security measures are to be taken in an information processing system including a plurality of information processing devices.

[0012] Fig. 1 is a block diagram showing an example of the configuration of a countermeasure support device according to the present disclosure. Fig. 2 is a flowchart showing an example of the operation of the countermeasure support device according to the present disclosure. Fig. 3 is a block diagram showing an example of the configuration of a countermeasure support device according to the present disclosure. Fig. 4 is a flowchart showing an example of the operation of the countermeasure support device according to the present disclosure. Fig. 5 is a flowchart showing an example of the operation of the countermeasure support device according to the present disclosure. Fig. 6 is a diagram showing an example of the hardware configuration of a computer that can realize the countermeasure support device according to the present disclosure.

[0013] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the drawings.

[0014] First Embodiment First, a first embodiment of the present disclosure will be described in detail with reference to the drawings.

[0015] <Configuration> FIG. 1 is a block diagram illustrating an example of the configuration of a countermeasure support device according to the present disclosure.

[0016] Hereinafter, the configuration of the countermeasure support device 10 according to the first embodiment of the present disclosure will be described with reference to FIG.

[0017] In the example shown in Fig. 1, the countermeasure support device 10 according to the first embodiment of the present disclosure includes a risk information acquisition unit 140, a difficulty level information receiving unit 150, an efficiency calculation unit 160, and an output unit 180. In Fig. 1 and other diagrams showing configurations described below, components connected by lines indicate that data is exchanged between those components. However, the components between which data is exchanged are not limited to those connected by lines.

[0018] The risk information acquisition unit 140 acquires risk information representing a change in the attack risk level of a communication path connecting an intrusion device and an attack target device in an information processing system when security measures are taken for information processing devices on the communication path. The information processing system includes a plurality of information processing devices and a communication network connecting the plurality of information processing devices. Note that the information processing devices on the communication path may include the intrusion device and the attack target device.

[0019] The attack risk level is a value indicating the risk determined, for example, from the degree of susceptibility (hereinafter referred to as the threat level) of an information processing system (e.g., an attack from an entry device to a target device via a communication path) and the degree of vulnerability (hereinafter referred to as the vulnerability level). The higher the degree of susceptibility (i.e., more susceptible to attack) and the higher the vulnerability (i.e., more vulnerable), the higher the attack risk level value indicating the risk. In other words, the attack risk level indicates the degree of likelihood that an attack will be carried out when an information processing system is attacked (e.g., an attack from an entry device to a target device via a communication path). For example, the attack risk level of a certain partial path represents the degree of likelihood that an attack will be carried out via that partial path. The attack risk level may be predetermined for a combination of a threat level value and a vulnerability level value.

[0020] In this embodiment, the security measures for an information processing device may include multiple measures. In other words, in this embodiment, one or more security measures for one information processing device are collectively described as the security measures for that information processing device. The security measures include, for example, applying a security program to software such as an operating system and an application (application of a so-called security patch). The security measures may also include changing the settings of the information processing device, such as introducing two-factor authentication or changing firewall settings.

[0021] In this embodiment, the risk information acquisition unit 140 may acquire risk information that has already been derived. As described below, the risk information acquisition unit 140 may derive risk information from information about the configuration of the information processing system (e.g., information about information processing devices on the communication path) and information about measures that have not been implemented by information processing devices on the communication path. In this case, the information about measures includes, for example, information indicating security measures, information about the attack risk level when the measures are not implemented, and information about the attack risk level when the measures are implemented. Note that the derivation of risk information by the risk information acquisition unit 140 will be described in detail later.

[0022] The difficulty level information receiving unit 150 receives difficulty level information indicating the difficulty level of the countermeasure. The difficulty level is, for example, a value that represents the difficulty of implementing the countermeasure from one or more perspectives. The difficulty level may be, for example, a value appropriately determined by an administrator of the information processing system. The difficulty level and difficulty information will be described in detail later.

[0023] The efficiency calculation unit 160 calculates, from the change in the attack risk level and the difficulty level, the value of the difficulty level of the countermeasure per predetermined change in the attack risk level as an efficiency value. For example, the efficiency calculation unit 160 may calculate, as the efficiency value, a value obtained by dividing the value of the difficulty level by a value representing the change in the attack risk level. For example, the efficiency calculation unit 160 may calculate, as the efficiency value, a value obtained by dividing the value of the difficulty level by a value that is a constant multiple of the value representing the change in the attack risk level.

[0024] The output unit 180 outputs the countermeasure information in a manner corresponding to the level of efficiency indicated by the efficiency value. The manner corresponding to the level of efficiency indicated by the efficiency value will be described in detail later. The countermeasure information includes, for example, information indicating the information processing device on which the countermeasure is to be implemented. The countermeasure information may also include, for example, information indicating the content of the countermeasure to be implemented on the information processing device.

[0025] <Operation> FIG. 2 is a flowchart showing an example of the operation of the countermeasure support device according to the present disclosure.

[0026] Hereinafter, the operation of the countermeasure support device 10 according to the first embodiment of the present disclosure will be described in detail with reference to FIG.

[0027] In the example shown in Figure 2, the risk information acquisition unit 140 first acquires risk information representing a change in the attack risk level of a communication path connecting an intrusion device and an attack target device in an information processing system when security measures are implemented for information processing devices on the communication path (step S11). Next, the difficulty information receiving unit 150 receives difficulty information indicating the difficulty level of the countermeasure (step S12). The efficiency calculation unit 160 calculates an efficiency value, which is the difficulty level value of the countermeasure per a predetermined amount of change in the attack risk level, based on the change in the attack risk level and the difficulty level (step S13). Then, the output unit 180 outputs the countermeasure information in a manner corresponding to the level of efficiency indicated by the efficiency value (step S14).

[0028] <Effect> The present disclosure has an effect of being able to support improving the efficiency of reducing risks due to attacks when selecting information processing devices for which security measures are to be taken in an information processing system including multiple information processing devices. The attack is, for example, a cyber attack. The cyber attack is, for example, a cyber attack against the information processing system (specifically, for example, a cyber attack directed at a target device included in the information processing system).

[0029] This is because the efficiency calculation unit 160 calculates the value of the difficulty level of a countermeasure per a predetermined amount of change in the attack risk level from the change in the attack risk level and the difficulty level as the efficiency value.The output unit 180 then outputs information about the countermeasure in a manner corresponding to the level of efficiency indicated by the efficiency value.As a result, it is possible to know which countermeasures have high efficiency indicated by the efficiency value.

[0030] The efficiency value represents the value of the difficulty level of the countermeasure required to obtain the same change in the attack risk level. The reciprocal of the efficiency value represents the change in the attack risk level obtained per unit difficulty level of the countermeasure. These values ​​can be said to represent the efficiency of the countermeasure. In other words, the efficiency value can be said to represent the efficiency of the countermeasure.

[0031] Note that the countermeasures are measures that reduce the risk indicated by the attack risk level. Measures that increase the risk indicated by the attack risk level are not included in the countermeasures. Therefore, the change in the attack risk level indicates the magnitude of the change in the attack risk level, which indicates the amount of reduction in the risk of an attack.

[0032] The output unit 180 outputs information about the countermeasures in a manner corresponding to the level of efficiency indicated by the efficiency value, thereby making it possible to know the degree of efficiency of the countermeasures. Compared to a case where information about the efficiency of the countermeasures is not available, by selecting a countermeasure to be implemented based on the output information about the countermeasures in a manner corresponding to the level of efficiency indicated by the efficiency value, it is possible to improve the efficiency of the selected countermeasure in reducing the risk of attacks.

[0033] Second Embodiment Next, a second embodiment of the present disclosure will be described in detail with reference to the drawings.

[0034] <Configuration> FIG. 3 is a block diagram illustrating an example of the configuration of a countermeasure support device according to the present disclosure.

[0035] The configuration of the countermeasure support device 100 according to the second embodiment of the present disclosure will be described in detail below with reference to FIG.

[0036] 3 , the countermeasure support device 100 includes a configuration information receiving unit 110, an attack path derivation unit 120, a countermeasure information receiving unit 130, a risk information acquisition unit 140, a difficulty level information receiving unit 150, an efficiency calculation unit 160, an output information generation unit 170, an output unit 180, and a designation receiving unit 190. The risk information acquisition unit 140, the difficulty level information receiving unit 150, the efficiency calculation unit 160, and the output unit 180 of this embodiment are similar to the risk information acquisition unit 140, the difficulty level information receiving unit 150, the efficiency calculation unit 160, and the output unit 180.

[0037] <Configuration Information Receiving Unit 110> The configuration information receiving unit 110 receives information about the configuration of the information processing system. The information about the configuration of the information processing system includes information about the vulnerabilities of multiple information processing devices (the above-mentioned vulnerability level values), information about the communication paths connecting those information processing devices, and information indicating an entry point device and an attack target device among the multiple information processing devices. An entry point device is an information processing device that is expected to be an entry point for an attack. An attack target device is an information processing device that is expected to be the final target of an attack in the information processing system.

[0038] <Attack path derivation unit 120> When assuming an attack from an intrusion device to an attack target device based on information about the configuration of the information processing system, the attack path derivation unit 120 derives an intrusion path from an intrusion device to an attack target device, for example, by using an existing algorithm described in the following reference document. In this embodiment, this intrusion path (in other words, attack path) is referred to as a communication path.

[0039] (References) Ryo Mizushima, Maki Inokuchi, Tomohiko Yagyu, "Countermeasure Planning Method Considering Multi-Layer Defense Against Cyber ​​Attacks," 2023 Symposium on Cryptography and Information Security, Fukuoka, Japan, January 24-27, 2023. The attack path deriving unit 120 determines an attack risk level for each attack path (i.e., communication path) from information about the configuration of the information processing system. Specifically, the attack path deriving unit 120 determines a threat level value for each information processing device using the algorithm described in the above reference. The attack path deriving unit 120 determines the attack risk level value from the threat level value and vulnerability level value of the information processing system, for example, using a lookup table indicating attack risk level values ​​associated with combinations of threat level values ​​and vulnerability level values. The attack path derivation unit 120 then uses the algorithm described in the above reference to determine the value of the attack risk level for each partial path connecting information processing devices. The value of the attack risk level for a partial path represents, for example, the degree of likelihood that an attack will occur from an information processing device closer to an entry device of the partial path to an information processing device closer to an attack target device of the partial path.

[0040] <Countermeasure Information Receiving Unit 130> The countermeasure information receiving unit 130 receives information on countermeasures that can be implemented for each information processing device included in the information processing system. The countermeasure information includes information on the value of the vulnerability level when the countermeasure is implemented.

[0041] <Risk information acquisition unit 140> In this embodiment, the risk information acquisition unit 140 derives risk information that represents the change in the attack risk level of the communication path when security measures are taken for the information processing device on the communication path connecting the intrusion device and the attack target device in the information processing system.

[0042] Specifically, the risk information acquisition unit 140 receives the value of the attack risk level for each partial path connecting the information processing devices in the information processing system and information on the implementable countermeasures for each information processing device included in the information processing system. The risk information acquisition unit 140 derives the value of the attack risk level for each partial path connecting the information processing devices in the information processing system when the implementable countermeasures for each information processing device included in the information processing system are implemented. The risk information acquisition unit 140 may derive the value of the attack risk level for each partial path described above using, for example, the lookup table described above. The risk information acquisition unit 140 derives the value of the attack risk level for each partial path described above in a state in which each countermeasure for the information processing devices included in the information processing system has been implemented individually and other countermeasures have not been implemented.

[0043] The risk information acquisition unit 140 may cause the attack path derivation unit 120 to derive the value of the attack risk level for each of the partial paths described above in a state where each of the countermeasures for the information processing devices included in the information processing system has been implemented individually and no other countermeasures have been implemented. In this case, the risk information acquisition unit 140 transmits information on the countermeasures that can be implemented for each of the information processing devices included in the information processing system to the attack path derivation unit 120. Then, the risk information acquisition unit 140 receives from the attack path derivation unit 120 the value of the attack risk level for each of the partial paths described above in a state where each of the countermeasures for the information processing devices included in the information processing system has been implemented individually and no other countermeasures have been implemented.

[0044] The risk information acquisition unit 140 derives risk information that represents a change in the attack risk level of a communication path when security measures are implemented, from the attack risk level values ​​for each partial path when no measures are implemented and the attack risk level values ​​for each partial path when measures are implemented.The risk information acquisition unit 140 calculates the attack risk level value of a communication path connecting an intrusion gateway device and an attack target device from the attack risk level values ​​for each partial path when no measures are implemented.The risk information acquisition unit 140 sets the attack risk level value that represents the smallest risk among the attack risk level values ​​of the partial paths included in the communication path as the value of the attack risk level of that communication path.

[0045] The risk information acquisition unit 140 calculates, for each measure, the value of the attack risk level of the communication path connecting the intrusion gateway device and the attack target device in a state where only the target measure has been taken, from the value of the attack risk level for each partial path in a state where only the target measure has been taken.The risk information acquisition unit 140 sets the attack risk level value that represents the smallest risk among the attack risk level values ​​of the partial paths included in the communication path in a state where only the target measure has been taken as the value of the attack risk level of that communication path in a state where only that measure has been taken.

[0046] The risk information acquisition unit 140 derives risk information representing the change in the attack risk level of the communication path when the measure is implemented from the difference between the value of the attack risk level of the communication path when the measure is not implemented and the value of the attack risk level of the communication path when the target measure is implemented, for each measure.

[0047] The risk information acquisition unit 140 derives risk information for each communication path connecting the intrusion device and the attack target device. The risk information acquisition unit 140 may derive risk information for a pre-specified communication path between the intrusion device and the attack target device.

[0048] <Difficulty level information receiving unit 150> The difficulty level information receiving unit 150 receives difficulty level information indicating the difficulty level of a measure. The difficulty level information is, for example, a value indicating the degree of difficulty, which is set for each measure with respect to each of a plurality of items indicating the difficulty of the measure. The maximum and minimum values ​​of the value indicating the difficulty level of each item may be determined in advance. The value indicating the difficulty level of each item may be determined as appropriate within a range between the minimum value and the maximum value, so that the relationship between the level of difficulty and the magnitude of the value is the same between items.

[0049] The item may be, for example, a device application history indicating whether or not a patch has been applied to an information processing device in the past. In this case, the difficulty levels are, for example, Yes, Unknown, and No, in ascending order of difficulty. Values ​​representing the difficulty levels are appropriately determined for Yes, Unknown, and No, which are the difficulty levels.

[0050] The item may be, for example, a procedure check indicating whether the patch application procedure has been confirmed. In this case, the difficulty levels may be, from lowest to highest, whether the patch has been applied (e.g., on a development machine) or whether it has not been applied. Values ​​representing the difficulty levels are appropriately determined for these difficulty levels.

[0051] The item may be, for example, a device role indicating the role of an information processing device. The device role may be, for example, a terminal, a server, a router, etc. In this case, the difficulty level may be determined appropriately according to the magnitude of the role. For these difficulty levels, a value representing the difficulty level is determined appropriately.

[0052] The item may be, for example, an application method indicating whether the patch is applied automatically or manually. In this case, the difficulty levels are, for example, automatic and manual, from least to most difficult. Values ​​representing the difficulty levels are appropriately determined for these difficulty levels.

[0053] The item may be, for example, a "restart required" item indicating whether or not the information processing device needs to be restarted after applying a patch. In this case, the difficulty levels may be, for example, "no," "unknown," and "required," in order of increasing difficulty. Values ​​representing the difficulty levels are appropriately determined for these difficulty levels.

[0054] The item may be, for example, an inaccessible range, which indicates the size of the area that will be inaccessible during the restart of the information processing devices. In this case, the difficulty level is determined so that, for example, the difficulty level increases as the number of information processing devices that will be inaccessible during the restart of the information processing devices increases. Values ​​representing the difficulty level are appropriately determined for these difficulty levels.

[0055] The item may be, for example, maintenance restart availability, which indicates whether a restart can be performed during maintenance time. In this case, the difficulty levels are, for example, available, unknown, and unavailable, in order of increasing difficulty. Values ​​representing the difficulty levels are appropriately determined for these difficulty levels.

[0056] The item may be, for example, a restart time that indicates the length of time required to restart the information processing device. In this case, the difficulty level is determined so that, for example, the longer the time required to restart the information processing device, the higher the difficulty level. For these difficulty levels, values ​​that indicate the difficulty level are appropriately determined.

[0057] The item may be, for example, a patch application history indicating whether or not the patch has been applied to other information processing devices. In this case, the difficulty levels may be, for example, Yes, Unknown, and No, from lowest to highest. Values ​​representing the difficulty levels are appropriately determined for these difficulty levels.

[0058] In the following description, the value of the difficulty level for each item will also be referred to as the element difficulty level.

[0059] <Efficiency Calculation Unit 160> The efficiency calculation unit 160 calculates the difficulty level value for each measure from the difficulty level information.

[0060] Specifically, the efficiency calculation unit 160 calculates the difficulty level value of each measure from the element difficulty level value of each item of the measure.

[0061] When multiple countermeasures exist for one information processing device, the efficiency calculation unit 160 determines the element difficulty level value for each item of the countermeasures for that information processing device based on the element difficulty level value for each item that would result from implementing all of the multiple countermeasures.The efficiency calculation unit 160 then calculates the difficulty level value of the countermeasures for that information processing device using the determined element difficulty level value for each item.

[0062] The efficiency calculation section 160 may calculate the average of the element difficulty level values ​​for each item of a measure as the difficulty level value of that measure.

[0063] The efficiency calculation unit 160 may calculate a weighted average of the element difficulty level values ​​for each item of the measure as the difficulty level value of the measure. In this case, the efficiency calculation unit 160 calculates, for each item of the measure, the product of the element difficulty level value of the item and a weight predetermined for that item. The efficiency calculation unit 160 calculates the product of the element difficulty level values ​​and the weights for all items of the measure. The efficiency calculation unit 160 calculates the sum of the products of the element difficulty level values ​​and the weights for all items of the measure. The efficiency calculation unit 160 determines the difficulty level value of the measure to be the value obtained by dividing the sum of the products of the element difficulty level values ​​and the weights for all items of the measure by the sum of the weights of all items (i.e., the weighted average of the element difficulty level values ​​for each item of the measure).

[0064] The efficiency calculation unit 160 calculates, for each countermeasure, the value of the difficulty level per predetermined amount of change in the attack risk level as the efficiency value. For example, for each countermeasure, the efficiency calculation unit 160 calculates the efficiency value by dividing the value of the difficulty level of the countermeasure by a value indicating the magnitude of the change in the attack risk level of the communication path due to that countermeasure.

[0065] An example of calculating the efficiency value will be described below.

[0066] An example will be described in which the communication path is from an intrusion device A to an attack target device D via information processing device B and information processing device C. For example, assume that in a state in which no countermeasures are implemented, the attack risk level of all partial paths from the intrusion device A to the attack target device is 5. The maximum attack risk level (the value indicating the highest risk) is 5, and the minimum attack risk level (the value indicating the lowest risk) is 1. As described above, the attack risk level of a communication path is the minimum attack risk level of the partial paths included in the communication path. In this case, the attack risk level of the communication path is 5.

[0067] For example, suppose that the security measures that can be implemented are measures in information processing device B and measures in information processing device C. The difficulty level of the measures in information processing device B is 2. The difficulty level of the measures in information processing device C is 4. The maximum value of the difficulty level (i.e., the value representing the highest difficulty) is 5, and the minimum value of the difficulty level (i.e., the value representing the lowest difficulty) is 1.

[0068] Then, when a countermeasure is implemented in information processing device B, the attack risk level of the partial path between information processing device B and information processing device C will change from 5 to 4. In this case, the attack risk level of the communication path will also change from 5 to 4. The change in the attack risk level will be 1. The efficiency value of the countermeasure in information processing device B is 2, which is the value obtained by dividing 2, which is the difficulty level, by 1, which is the change in the attack risk level.

[0069] Furthermore, when a countermeasure is implemented in the information processing device C, the attack risk level of the partial path between the information processing device C and the attack target device D will change from 5 to 2. In this case, the attack risk level of the communication path will also change from 5 to 2. The change in the attack risk level will be 3. The efficiency value of the countermeasure in the information processing device C is 4 / 3 (approximately 1.3), which is obtained by dividing the difficulty level of 4 by the change in the attack risk level of 3.

[0070] In the above example, the measure for the information processing device C has a smaller value of the difficulty level of the measure per reduction in the attack risk level, compared to the measure for the information processing device B. In other words, it can be said that the measure for the information processing device C is more efficient than the measure for the information processing device B.

[0071] <Output Information Generating Unit 170> The output information generating unit 170 generates, as output information, information on measures in a form corresponding to the level of efficiency indicated by the efficiency value.

[0072] The information on countermeasures in a manner corresponding to the degree of efficiency indicated by the efficiency value may be, for example, a list of countermeasures sorted in order of the degree of efficiency indicated by the efficiency value. The list of countermeasures may be, for example, a list of combinations of identifiers of information processing devices that are the target of the countermeasures and information such as text representing the countermeasures. The combinations may include the efficiency values ​​of the countermeasures. The combinations may include information on the difficulty level of the countermeasures. The combinations may include information representing a change in the attack risk level. The information representing the change in the attack risk level may be the amount of change in the attack risk level. The information representing the change in the attack risk level may be a combination of the value of the attack risk level of a communication path in a state where no countermeasures are implemented and the value of the attack risk level of a communication path in a state where the countermeasures are implemented.

[0073] The information on the countermeasures in a manner corresponding to the level of efficiency indicated by the efficiency value may be, for example, an image (hereinafter referred to as output image) representing the configuration of the information processing system, in which the information processing devices on which the countermeasures are implemented are depicted in a manner corresponding to the level of efficiency indicated by the efficiency value. The image representing the configuration of the information processing system is, for example, an image including figures representing multiple information processing devices including an entry device and an attack target device, and figures such as arrows representing partial paths. The output information generation unit 170 generates an output image in which figures representing the information processing devices are depicted in a manner corresponding to the level of efficiency indicated by the efficiency value, for example.

[0074] The figure drawn in a manner corresponding to the level of efficiency indicated by the efficiency value is, for example, a figure whose size corresponds to the efficiency value. The output information generation unit 170 generates an output image, for example, so that the size of the figure representing an information processing device is smaller than the size of the figure representing an information processing device that is the target of a measure having an efficiency value higher than the efficiency indicated by the efficiency value of the measure for which the information processing device is the target. The rule for determining the size according to the efficiency value, i.e., the rule for determining the size of the figure from the efficiency value, may be determined as appropriate in advance. For example, the rule may be determined so that the size of the figure of the information processing device is proportional to the level of efficiency. For example, the size of the figure may be determined for each of multiple ranges into which the efficiency value range is divided. The rule may be determined so that the size of the figure of the information processing device is the size of the figure associated with the range containing the efficiency value of the measure for that information processing device.

[0075] The graphic drawn in a manner corresponding to the level of efficiency indicated by the efficiency value may be, for example, a graphic drawn using lines of a thickness corresponding to the efficiency value. In this case, the relationship between the efficiency value and the line thickness is predetermined. The output information generation unit 170 determines the line thickness corresponding to the efficiency value of the countermeasure for the information processing device using the predetermined relationship. Then, the output information generation unit 170 generates an output image in which the graphic representing the information processing device is drawn using lines of the determined thickness.

[0076] The graphic drawn in a manner corresponding to the level of efficiency indicated by the efficiency value may be, for example, a graphic with a color corresponding to the efficiency value. In this case, the relationship between the efficiency value and the color is predetermined. The output information generation unit 170 determines the line thickness corresponding to the efficiency value of the countermeasure for the information processing device using the predetermined relationship. Then, the output information generation unit 170 generates an output image in which the graphic representing the information processing device is drawn in the determined color.

[0077] The aspect according to the level of efficiency indicated by the efficiency value may be at least one of size, line thickness, and color according to the level of efficiency indicated by the efficiency value. The output information generation unit 170 may generate an output image showing a character string representing the information processing device in addition to a graphic representing the information processing device.

[0078] When the designation receiving unit 190 described below receives information indicating that one of the information processing devices has been designated (hereinafter referred to as designation of an information processing device), the output information generating unit 170 generates detailed information on measures for the designated information processing device (in other words, the information processing device indicated by the designation).

[0079] The detailed information about measures is detailed information about measures that includes more information than the information about the measures described above. The detailed information about measures may include the content of the measures. The detailed information about measures may include information representing a change in the attack risk level of the communication path due to the measures. The information representing a change in the attack risk level may include a combination of information representing the attack risk level in a state where the measures are not implemented and information representing the attack risk level in a state where the measures are implemented. The detailed information about measures may include information about the difficulty level of the measures. The detailed information about measures may include information about the element difficulty level for each item of the measures. The detailed information about measures may include information indicating the efficiency value of the measures.

[0080] The output information generating unit 170 may generate detailed information about the countermeasure in text format.

[0081] The output information generating unit 170 may superimpose the detailed information of the measures on the output image that shows the information of the measures in a form that corresponds to the level of efficiency indicated by the efficiency value. The output information generating unit 170 may generate the output image on which the detailed information of the measures is superimposed as detailed information of the measures to be output.

[0082] <Output unit 180> The output unit 180 outputs output information that is information about measures in a form corresponding to the level of efficiency indicated by the efficiency value. The output information is, for example, the above-mentioned output image that shows information about measures in a form corresponding to the level of efficiency indicated by the efficiency value. The output information may be, for example, a list of measures sorted by the level of efficiency indicated by the efficiency value.

[0083] When the output information generating unit 170 generates the detailed information on the countermeasures, the output unit 180 outputs the generated detailed information on the countermeasures. The detailed information on the countermeasures is, for example, the above-mentioned output image on which the detailed information on the countermeasures is superimposed. The information on the countermeasures may be, for example, the detailed information on the countermeasures in text format.

[0084] The information output by the output unit 180 may be output to a display device of the countermeasure support device 100. In this case, the display device displays the information output by the output unit 180. The information output by the output unit 180 may be output to another information processing device (hereinafter referred to as an output destination device). In this case, the output destination device that receives the information output by the output unit 180 displays the information output by the output unit 180 on the display device of the output destination device.

[0085] <Designation Accepting Unit 190> The designation accepting unit 190 accepts information designating an information processing device included in the information processing system (i.e., designation of an information processing device). The designation accepting unit 190 accepts the designation of an information processing device input using, for example, an input device that is at least one of a keyboard, a mouse, and a touch panel of the countermeasure support device 100. The designation accepting unit 190 may accept the designation of an information processing device input using the input device of the above-mentioned output destination device and transmitted from the output destination device. The designation accepting unit 190 sends the accepted designation of an information processing device to, for example, the output information generating unit 170.

[0086] For example, if the output unit 180 is configured to output the above-mentioned output image as countermeasure information, the designation accepting unit 190 may accept information specifying an information processing device in the displayed output image. In this case, for example, the designation accepting unit 190 may accept information indicating a position in the displayed output image as information specifying an information processing device. Then, the designation accepting unit 190 identifies the information processing device represented by a figure or the like displayed at the position in the output image indicated by the accepted information indicating the position. The designation accepting unit 190 sends information indicating the identified information processing device to, for example, the output information generating unit 170, as the designation of the accepted information processing device.

[0087] <Operation> Next, the operation of the countermeasure support device 100 according to the second embodiment of the present disclosure will be described in detail with reference to the drawings.

[0088] 4 and 5 are flowcharts illustrating an example of the operation of the countermeasure support device 100 according to the present disclosure.

[0089] Hereinafter, the operation of the countermeasure support device 100 according to the second embodiment of the present disclosure will be described in detail with reference to FIGS. 4 and 5. FIG.

[0090] 4, first, the configuration information receiving unit 110 receives information about the configuration of the information processing system (step S101). Next, the attack path deriving unit 120 derives an attack path (communication path) of the information processing system (step S102). The attack path deriving unit 120 further derives an attack risk level for each partial path of the communication path of the information processing system (step S103).

[0091] The countermeasure information receiving unit 130 receives information on countermeasures that can be applied to each information processing device in the information processing system (step S104). Next, the risk information acquiring unit 140 derives a change in the attack risk level of the communication path for each countermeasure (step S105).

[0092] The difficulty level information receiving unit 150 receives information indicating the difficulty level of the countermeasure (step S106).

[0093] 5, the efficiency calculation unit 160 calculates an efficiency value based on the change in the attack risk level of the communication path due to the countermeasure and the difficulty level of the countermeasure (step S107). The output information generation unit 170 generates countermeasure information in a format corresponding to the level of efficiency indicated by the efficiency value (step S108). The output unit 180 then outputs the countermeasure information in a format corresponding to the level of efficiency indicated by the efficiency value (step S109).

[0094] 5, the designation receiving unit 190 receives a designation of an information processing device (step S110). In response to the designation of the information processing device by the designation receiving unit 190, the output information generating unit 170 generates detailed information on measures to be taken for the designated information processing device (step S111). The output unit 180 outputs the detailed information on measures to be taken for the designated information processing device (step S112).

[0095] <Effects> The present embodiment described above has the same effects as the first embodiment, for the same reasons as those for the effects of the first embodiment.

[0096] <First Modification of Second Embodiment> Instead of deriving risk information, the risk information acquisition unit 140 may acquire risk information from another device (hereinafter also referred to as a risk information derivation device). In this case, the risk information derivation device derives the risk information. In this case, the countermeasure support device 100 may not include the configuration information receiving unit 110, the attack path derivation unit 120, and the countermeasure information receiving unit 130.

[0097] The risk information derivation device may also derive information about the communication paths of the information processing system and the attack risk level in a state where no countermeasures are taken. In this case, the risk information acquisition unit 104 receives information about the configuration of the information processing system, information about the communication paths of the information processing system, and the attack risk level in a state where no countermeasures are taken from the risk information derivation device. In this case, the countermeasure support device 100 may not include the configuration information receiving unit 110 and the attack path derivation unit 120.

[0098] The countermeasure support device 100 does not need to output detailed information about the countermeasures. In this case, the countermeasure support device 100 does not need to include the designation receiving unit 190.

[0099] Second Modification of Second Embodiment The countermeasure support device 100 may output countermeasure information for each communication path from an entry device to an attack target device in an information processing system.

[0100] The countermeasure support device 100 may output information on countermeasures for a specified communication path from all communication paths from an intrusion device to an attack target device in an information processing system. In this case, for example, the output information generation unit 170 may generate a screen (e.g., an image) representing all communication paths from an intrusion device to an attack target device in an information processing system. Then, the output unit 180 may output the generated screen. The designation receiving unit 190 receives information specifying a communication path (hereinafter also referred to as a communication path designation). The designation receiving unit 190 may receive information on the communication path specified on the output screen. The information on the communication path specified on the output screen may be, for example, information representing a specified position on the output screen. In this case, the designation receiving unit 190 identifies the communication path indicated by the specified position on the output screen. The designation receiving unit 190 sets the identified communication path as the specified communication path.

[0101] As described above, the output information generating unit 170 may generate the output image that represents the configuration of the information system and shows a graphic indicating the information processing device that is the target of the countermeasure in a manner corresponding to the level of efficiency indicated by the efficiency value of the countermeasure. This output image may be a moving image instead of a still image.

[0102] The output information generation unit 170 may generate an output image in which the designated information processing device is displayed in a manner different from that of the non-designated information processing device. Specifically, the output information generation unit 170 may generate an output image in which the figure representing the designated information processing device blinks, while the figure representing the non-designated information processing device does not blink.

[0103] The output information generation unit 170 may also generate an output image (referred to as an uncountermeasured state output image) depicting a graphic (e.g., an arrow) indicating a partial path in a manner corresponding to the attack risk level of a state in which no countermeasures have been taken in the specified information processing device. The manner corresponding to the attack risk level may, for example, be a manner in which at least one of the color, thickness, and type of line varies depending on the attack risk level. The output information generation unit 170 may further generate an output image (referred to as a countermeasured state output image) depicting a graphic (e.g., an arrow) indicating a partial path in a manner corresponding to the attack risk level of a state in which countermeasures have been taken in the specified information processing device. The output unit 180 may alternately output the uncountermeasured state output image and the countermeasured state output image. The time period during which the uncountermeasured state output image is continuously output (in other words, the time period during which the uncountermeasured state output image is displayed) may be the same as the time period during which the countermeasured state output image is continuously output (in other words, the time period during which the countermeasured state output image is displayed). The time for which the unmeasured state output image is continuously output (in other words, the time for which the unmeasured state output image is displayed) may be different from the time for which the countermeasured state output image is continuously output (in other words, the time for which the countermeasured state output image is displayed).

[0104] The number of information processing devices to be specified is not limited to one, and multiple information processing devices may be selected.

[0105] The risk information acquisition unit 140 may derive an attack risk level for the entire information processing system. Specifically, the risk information acquisition unit 140 determines, for example, the attack risk level indicating the highest risk among the attack risk levels of all communication paths from the intrusion device to the attack target device as the attack risk level for the entire information processing system. Note that the risk information acquisition unit 140 determines, as the attack risk level for that communication path, the attack risk level indicating the lowest risk among the attack risk levels of the partial paths included in the communication path. The risk information acquisition unit 140 derives the attack risk level for the entire information processing system in a state where no countermeasures have been implemented. The risk information acquisition unit 140 further derives the attack risk level for the entire information processing system in a state where countermeasures have been implemented for a specified information processing device.

[0106] In this case, the output information generation unit 170 generates an uncountermeasured state output image in a manner corresponding to the attack risk level of the entire information processing system in a state where no countermeasures have been taken. The output information generation unit 170 may generate an uncountermeasured state output image in which, for example, the background color is a color corresponding to the attack risk level of the entire information processing system in a state where no countermeasures have been taken. The output information generation unit 170 may also generate a countermeasured state output image in which, for example, the background color is a color corresponding to the attack risk level of the entire information processing system in a state where countermeasures have been taken for the specified information processing device. The output information generation unit 170 may generate a countermeasured state output image in which, for example, the background color is a color corresponding to the attack risk level of the entire information processing system in a state where countermeasures have been taken for the specified information processing device.

[0107] In the present disclosure, taking countermeasures does not increase the risk indicated by the attack risk level. Therefore, when an output image in an uncountered state and an output image in an accounted state are alternately displayed, it is possible to distinguish between the output image in an uncountered state and the output image in an accounted state by comparing the appearance of the figures indicating the partial paths included in the output images.

[0108] Furthermore, the output information generating unit 170 may generate the uncountermeasured state output image and the countermeasured state output image so that the appearance of a graphic indicating a partial path whose attack risk level changes depending on the countermeasure taken for the specified information processing device differs between the uncountermeasured state output image and the countermeasured state output image. Specifically, the output information generating unit 170 may generate the uncountermeasured state output image so that, for example, a graphic indicating a partial path whose attack risk level changes depending on the countermeasure taken for the specified information processing device flashes in the uncountermeasured state output image. Furthermore, the output information generating unit 170 may generate the countermeasured state output image so that a graphic indicating a partial path whose attack risk level changes depending on the countermeasure taken for the specified information processing device does not flash in the countermeasured state output image.

[0109] The output information generation unit 170 may generate an output image such that the appearance of a graphic representing a partial path whose attack risk level changes as a result of taking a countermeasure on a specified information processing device is different from the appearance of a graphic representing a partial path whose attack risk level does not change as a result of taking that countermeasure. In this case, specifically, the output information generation unit 170 generates the uncountermeasured state output image and the countermeasured state output image, for example, so that the graphic representing a partial path whose attack risk level changes as a result of taking a countermeasure on a specified information processing device flashes in the uncountermeasured state output image and the countermeasured state output image. Then, the output information generation unit 170 generates the uncountermeasured state output image and the countermeasured state output image, for example, so that the graphic representing a partial path whose attack risk level does not change as a result of taking a countermeasure on a specified information processing device does not flash in the uncountermeasured state output image and the countermeasured state output image.

[0110] <Fourth Modification of Second Embodiment> The output information generation unit 170 may select measures to satisfy specified conditions. Then, the output information generation unit 170 may generate information on the selected measures. In this case, the output unit 180 outputs the information on the selected measures. The conditions may be specified in advance. The conditions may be specified by the user of the measure support device 100. In this case, the specification receiving unit 190 receives information indicating the specified conditions.

[0111] The condition is, for example, that the efficiency indicated by the efficiency value of the measure is higher than the efficiency indicated by the predetermined value. In this case, the output information generating unit 170 selects a measure whose efficiency indicated by the efficiency value is higher than the efficiency indicated by the predetermined value.

[0112] The condition is, for example, that the efficiency indicated by the efficiency value of the measure is within a predetermined number from the most efficient. In this case, the output information generation unit 170 sorts the measures in descending order of efficiency indicated by the efficiency value. Then, the output information generation unit 170 selects a predetermined number of measures from the most efficient indicated by the efficiency value.

[0113] The condition is that the countermeasure is the most efficient countermeasure that reduces the risk indicated by the attack risk level of the entire information processing system to less than or equal to the risk indicated by a predetermined attack risk level (hereinafter referred to as the target risk). In this case, the output information generation unit 170 selects, for each communication path from the intrusion device to the attack target device, the countermeasure with the highest efficiency indicated by the efficiency value among the countermeasures for the information processing device on the communication path that, when applied, reduces the risk indicated by the attack risk level of the communication path to less than or equal to the target risk. Note that if there is no countermeasure that reduces the risk indicated by the attack risk level of the communication path to less than or equal to the target risk, the output information generation unit 170 may select, from the countermeasures for the information processing device on the communication path, the countermeasure that, when applied, reduces the risk indicated by the attack risk level of the communication path to the lowest.

[0114] The condition may be that the difficulty level of the countermeasure is equal to or easier than the specified difficulty level (i.e., equal to or lower than the specified difficulty level). In this case, the output information generating unit 170 selects the countermeasure whose difficulty level is equal to or lower than the specified difficulty level.

[0115] The condition may be that the countermeasure is not a countermeasure for the specified information processing device. In this case, the countermeasure is a countermeasure other than the countermeasure for the specified information processing device. In this case, the output information generation unit 170 selects a countermeasure other than the countermeasure for the specified information processing device.

[0116] The condition may be the number of measures at a difficulty level equal to or higher than the specified difficulty level (hereinafter referred to as the "specified number"). In this case, the output information generating unit 170 selects the specified number of measures from the measures at a difficulty level equal to or higher than the specified difficulty level in order of the efficiency indicated by the efficiency value. The output information generating unit 170 further selects measures at a difficulty level lower than the specified difficulty level.

[0117] The output information generating unit 170 may sort the selected measures in descending order of efficiency indicated by the efficiency values. The output information generating unit 170 may generate information on the selected measures sorted in descending order of efficiency indicated by the efficiency values.

[0118] <Fifth Modification of Second Embodiment> The fourth modification of the second embodiment can be applied to the third modification of the second embodiment.

[0119] In this modification, similarly to the fourth modification of the second embodiment, the output information generation unit 170 selects measures so as to satisfy specified conditions. Then, the output information generation unit 170 generates information on measures excluding information on measures that were not selected. When generating the above-described output image as information on measures, the output information generation unit 170 generates an output image in which figures indicating information processing devices that are targets of measures that were not selected are drawn in a manner that is predetermined to indicate that no measures exist.

[0120] The designation receiving unit 190 receives a designated information processing device from the information processing devices that are targets of the selected measures. The designation receiving unit 190 does not accept an information processing device that is a target of a non-selected measure as a designated information processing device.

[0121] This modification is similar to the third modification of the second embodiment except for the points described above.

[0122] <Other Embodiments> The countermeasure support device according to the present disclosure can be realized by a computer including a memory into which a program read from a storage medium is loaded and a processor that executes the program. The countermeasure support device according to the present disclosure can also be realized by dedicated hardware. The countermeasure support device according to the present disclosure can also be realized by a combination of the above-mentioned computer and dedicated hardware.

[0123] FIG. 6 is a diagram illustrating an example of the hardware configuration of a computer 1000 capable of implementing the countermeasure support device according to the present disclosure. In the example illustrated in FIG. 6, the computer 1000 includes a processor 1001, a memory 1002, a storage device 1003, and an I / O (Input / Output) interface 1004. The computer 1000 can also access a storage medium 1005. The memory 1002 and the storage device 1003 are, for example, storage devices such as RAM (Random Access Memory) and a hard disk. The storage medium 1005 is, for example, a storage device such as RAM or a hard disk, a ROM (Read Only Memory), or a portable storage medium. The storage device 1003 may also be the storage medium 1005. The processor 1001 can read and write data and programs from and to the memory 1002 and the storage device 1003. The processor 1001 can access other devices via the I / O interface 1004. The processor 1001 can access a storage medium 1005. The storage medium 1005 stores a program that causes the computer 1000 to operate as a countermeasure support device according to the present disclosure.

[0124] The processor 1001 loads a program stored in the storage medium 1005, which causes the computer 1000 to operate as a countermeasure support device according to the present disclosure, into the memory 1002. Then, the processor 1001 executes the program loaded into the memory 1002, causing the computer 1000 to operate as the countermeasure support device according to the present disclosure.

[0125] The configuration information receiving unit 110, the attack path derivation unit 120, the countermeasure information receiving unit 130, the risk information acquisition unit 140, the difficulty level information receiving unit 150, the efficiency calculation unit 160, the output information generation unit 170, the output unit 180, and the designation reception unit 190 can be realized, for example, by a processor 1001 that executes a program loaded into the memory 1002. Some or all of the configuration information receiving unit 110, the attack path derivation unit 120, the countermeasure information receiving unit 130, the risk information acquisition unit 140, the difficulty level information receiving unit 150, the efficiency calculation unit 160, the output information generation unit 170, the output unit 180, and the designation reception unit 190 can also be realized by dedicated circuits that realize the functions of each unit.

[0126] Furthermore, some or all of the above-described embodiments can be described as, but are not limited to, the following supplementary notes.

[0127] (Supplementary Note 1) A countermeasure support device in an information processing system including a plurality of information processing devices and a communication network connecting the plurality of information processing devices, comprising: a risk information acquisition means for acquiring risk information representing a change in the attack risk level of a communication path connecting an intrusion device and an attack target device when security measures are taken for an information processing device on the communication path connecting the intrusion device and the attack target device; a difficulty information receiving means for receiving difficulty information representing a difficulty level of the countermeasure; an efficiency calculation means for calculating, from the change in the attack risk level and the difficulty level, the value of the difficulty level of the countermeasure per predetermined amount of change in the attack risk level as an efficiency value; and an output means for outputting information about the countermeasure in a manner corresponding to the level of efficiency indicated by the efficiency value.

[0128] (Supplementary Note 2) The countermeasure support device according to Supplementary Note 1 includes an output information generation means for generating an output image including a device display showing the information processing device and a path display showing the communication path, wherein the device display is displayed in a manner corresponding to the degree of efficiency indicated by the efficiency value of the countermeasure of the information processing device shown by the device display, and the path display is represented by a line passing through the information processing device on the communication path, and the output means outputs the output image as information of the countermeasure.

[0129] (Supplementary Note 3) The countermeasure support device according to Supplementary Note 2, further comprising: a designation receiving means for receiving a device designation that designates the information processing device; and the output information generating means for generating the output image that further indicates the risk information of the countermeasure for the information processing device designated by the device designation.

[0130] (Appendix 4) The countermeasure support device described in Appendix 2, wherein the output information generation means generates the output image showing, as the risk information, pre-countermeasure risk information indicating the attack risk level when the countermeasure is not taken on the information processing device, and post-countermeasure risk information indicating the attack risk level when the countermeasure is taken on the information processing device.

[0131] (Supplementary Note 5) The measure support device according to Supplementary Note 1 or 2 further comprises: the difficulty information receiving means receives, as the difficulty information, information representing an element difficulty level indicating the difficulty of each of a plurality of items of the measure; and a difficulty calculation means calculating, as the difficulty level, an average value of the element difficulty levels.

[0132] (Supplementary Note 6) The countermeasure support device according to Supplementary Note 5, wherein the difficulty level calculation means calculates a weighted average of the element difficulty levels as the difficulty level.

[0133] (Supplementary Note 7) The risk information acquisition means of the countermeasure support device described in Supplementary Note 1 or 2 derives the change in the attack risk level of the communication path from the attack risk level of the communication path that passes through the information processing device on which the countermeasure is implemented and the attack risk level of the communication path in a state in which the countermeasure that is not implemented in the information processing device is implemented.

[0134] (Supplementary Note 8) The countermeasure support device described in Supplementary Note 7, wherein the plurality of information processing devices include the intrusion device and the attack target device, the communication path includes the information processing devices on the communication path and partial paths connecting the information processing devices, and the risk information acquisition means acquires, as the attack risk level of the communication path, the smallest attack risk level among the attack risk levels of the partial paths included in the communication path.

[0135] (Supplementary Note 9) The countermeasure support device according to Supplementary Note 7 further comprises an attack path derivation means for deriving the communication path from the intrusion device to the attack target device and the attack risk level of the communication path according to a predetermined algorithm from information processing system information including information on the configuration of the information processing system, information indicating the intrusion device, information indicating the attack target device, and information on the information processing devices included in the information processing system.

[0136] (Supplementary Note 10) The countermeasure support device according to Supplementary Note 1, wherein the output means outputs a combination of information indicating the information processing device that is a target of the countermeasure and information indicating the countermeasure in order of efficiency indicated by the efficiency value.

[0137] (Supplementary Note 11) The countermeasure support device according to Supplementary Note 1 or 2, further comprising: an output information generating means for selecting the countermeasure so as to satisfy a specified condition, and generating information on the selected countermeasure.

[0138] (Supplementary Note 12) A countermeasure support method for an information processing system including a plurality of information processing devices and a communication network connecting the plurality of information processing devices, comprising: acquiring risk information representing a change in the attack risk level of a communication path connecting an intrusion device and an attack target device when security measures are taken for an information processing device on the communication path connecting the intrusion device and the attack target device; receiving difficulty information indicating a difficulty level of the countermeasure; calculating an efficiency value of the difficulty level of the countermeasure per a predetermined amount of change in the attack risk level from the change in the attack risk level and the difficulty level; and outputting information about the countermeasure in a manner corresponding to the level of efficiency indicated by the efficiency value.

[0139] (Supplementary Note 13) A countermeasure support method as described in Supplementary Note 12, which generates an output image including a device display showing the information processing device and a path display showing the communication path, wherein the device display is displayed in a manner corresponding to the degree of efficiency indicated by the efficiency value of the countermeasure of the information processing device shown by the device display, and the path display is represented by a line passing through the information processing device on the communication path, and outputs the output image as information on the countermeasure.

[0140] (Supplementary Note 14) The countermeasure support method according to Supplementary Note 13, further comprising: receiving a device designation that designates the information processing device; and generating the output image that further indicates the risk information of the countermeasure for the information processing device designated by the device designation.

[0141] (Appendix 15) A countermeasure support method as described in Appendix 13, in which the output image is generated to show, as the risk information, pre-countermeasure risk information indicating the attack risk level when the countermeasure is not taken on the information processing device, and post-countermeasure risk information indicating the attack risk level when the countermeasure is taken on the information processing device.

[0142] (Supplementary Note 16) The countermeasure support method according to Supplementary Note 12 or 13, further comprising: receiving, as the difficulty information, information representing an element difficulty level indicating the difficulty of each of a plurality of items of the countermeasure; and calculating, as the difficulty level, an average value of the element difficulty levels.

[0143] (Supplementary Note 17) The countermeasure support method according to Supplementary Note 16, wherein a weighted average of the element difficulty levels is calculated as the difficulty level.

[0144] (Supplementary Note 18) The countermeasure support method described in Supplementary Note 12 or 13, wherein the change in the attack risk level of the communication path is derived from the attack risk level of the communication path that passes through the information processing device on which the countermeasure is implemented and the attack risk level of the communication path in a state in which the countermeasure that is not implemented in the information processing device is implemented.

[0145] (Supplementary Note 19) The countermeasure support method described in Supplementary Note 18, wherein the plurality of information processing devices include the intrusion device and the attack target device, the communication path includes the information processing devices on the communication path and partial paths connecting the information processing devices, and the attack risk level of the communication path is obtained as the smallest attack risk level among the attack risk levels of the partial paths included in the communication path.

[0146] (Supplementary Note 20) A countermeasure support method according to Supplementary Note 18, in which the communication path from the entry point device to the attack target device and the attack risk level of the communication path are derived from information processing system information including information on the configuration of the information processing system, information indicating the entry point device, information indicating the attack target device, and information on the information processing devices included in the information processing system, according to a predetermined algorithm.

[0147] (Supplementary Note 21) The countermeasure support method according to Supplementary Note 12, wherein combinations of information indicating the information processing device that is a target of the countermeasure and information indicating the countermeasure are output in order of increasing efficiency indicated by the efficiency value.

[0148] (Supplementary Note 22) The countermeasure support method according to Supplementary Note 12 or 13, further comprising: selecting the countermeasure so as to satisfy a specified condition; and generating information on the selected countermeasure.

[0149] (Supplementary Note 23) A storage medium storing a program that causes a computer to execute the following steps: a risk information acquisition process that acquires risk information representing a change in the attack risk level of a communication path connecting an intrusion device and an attack target device when security measures are taken on information processing devices on the communication path connecting an intrusion device and an attack target device in an information processing system including a plurality of information processing devices and a communication network connecting the plurality of information processing devices; a difficulty information receiving process that receives difficulty information indicating the difficulty level of the measure; an efficiency calculation process that calculates, from the change in the attack risk level and the difficulty level, the value of the difficulty level of the measure per predetermined amount of change in the attack risk level as an efficiency value; and an output process that outputs information about the measure in a manner corresponding to the level of efficiency indicated by the efficiency value.

[0150] (Appendix 24) The program causes a computer to execute an output information generation process to generate an output image including a device display indicating the information processing device and a path display indicating the communication path, wherein the device display is displayed in a manner corresponding to the degree of efficiency indicated by the efficiency value of the measure of the information processing device indicated by the device display, and the path display is represented by a line passing through the information processing device on the communication path, and the output process outputs the output image as information of the measure. ...

[0151] (Appendix 25) The program causes a computer to execute a designation receiving process that receives a device designation that designates the information processing device, and the output information generation process generates the output image that further indicates the risk information of the measures for the information processing device designated by the device designation.

[0152] (Appendix 26) The output information generation process generates the output image showing, as the risk information, pre-countermeasure risk information indicating the attack risk level when the countermeasure is not taken on the information processing device, and post-countermeasure risk information indicating the attack risk level when the countermeasure is taken on the information processing device. A storage medium as described in Appendix 24.

[0153] (Appendix 27) The storage medium described in Appendix 23 or 24 causes a computer to execute the following program: the difficulty information receiving process receives information representing element difficulty levels indicating the difficulty of each of multiple items of the countermeasure as the difficulty information; and the program causes a computer to execute a difficulty calculation process that calculates the average value of the element difficulty levels as the difficulty level.

[0154] (Supplementary Note 28) The storage medium according to Supplementary Note 27, wherein the difficulty level calculation process calculates a weighted average of the element difficulty levels as the difficulty level.

[0155] (Appendix 29) The risk information acquisition process derives the change in the attack risk level of the communication path from the attack risk level of the communication path that passes through the information processing device on which the countermeasure is implemented and the attack risk level of the communication path in a state in which the countermeasure that is not implemented in the information processing device is implemented. A storage medium described in Appendix 23 or 24.

[0156] (Appendix 30) The storage medium described in Appendix 29, wherein the plurality of information processing devices include the intrusion device and the attack target device, the communication path includes the information processing devices on the communication path and partial paths connecting the information processing devices, and the risk information acquisition process acquires, as the attack risk level of the communication path, the smallest attack risk level among the attack risk levels of the partial paths included in the communication path.

[0157] (Appendix 31) The program is a storage medium described in Appendix 29 that causes a computer to execute an attack path derivation process that derives the communication path from the entry device to the attack target device and the attack risk level of the communication path according to a predetermined algorithm from information processing system information that includes information on the configuration of the information processing system, information indicating the entry device, information indicating the attack target device, and information on the information processing devices included in the information processing system.

[0158] (Supplementary Note 32) The storage medium according to Supplementary Note 23, wherein the output process outputs a combination of information indicating the information processing device that is a target of the countermeasure and information indicating the countermeasure in order of efficiency indicated by the efficiency value.

[0159] (Supplementary Note 33) The storage medium according to Supplementary Note 23 or 24, wherein the program causes a computer to execute an output information generation process for selecting the measures so as to satisfy a specified condition and generating information on the selected measures.

[0160] Although the present disclosure has been described above with reference to the embodiments, the present disclosure is not limited to the above embodiments. Various modifications that can be understood by those skilled in the art can be made to the configuration and details of the present disclosure within the scope of the present disclosure.

[0161] 10 Countermeasure support device 100 Countermeasure support device 104 Risk information acquisition unit 110 Configuration information reception unit 120 Attack path derivation unit 130 Countermeasure information reception unit 140 Risk information acquisition unit 150 Difficulty level information reception unit 160 Efficiency calculation unit 170 Output information generation unit 180 Output unit 190 Designation reception unit 1000 Computer 1001 Processor 1002 Memory 1003 Storage device 1004 I / O interface 1005 Storage medium

Claims

1. A risk information acquisition means for acquiring risk information representing a change in the attack risk level of a communication path for an information processing device on a communication path connecting an intrusion device and an attack target device in an information processing system including a plurality of information processing devices and a communication network connecting the plurality of information processing devices, when security measures are taken against the information processing device; a difficulty information receiving means for receiving difficulty information indicating the difficulty level of the measure; an efficiency calculation means for calculating, from the change in the attack risk level and the difficulty level, a value of the difficulty level per a predetermined change amount of the change in the attack risk level of the measure as an efficiency value; and an output means for outputting information on the measure in a manner corresponding to the level of efficiency indicated by the efficiency value. A countermeasure support device comprising:

2. Output information generation means for generating an output image including a device display indicating the information processing device and a path display indicating the communication path, wherein the device display is represented in a manner corresponding to the level of efficiency indicated by the efficiency value of the measure for the information processing device indicated by the device display, and the path display is represented by a line passing through the information processing device on the communication path; and the output means outputs the output image as information on the measure. The countermeasure support device according to claim 1.

3. Designation reception means for receiving a device designation for designating the information processing device; and the output information generation means generates the output image further indicating the risk information of the measure for the information processing device designated by the device designation. The countermeasure support device according to claim 2.

4. The output information generation means generates the output image indicating, as the risk information, pre-countermeasure risk information indicating the attack risk level when the measure is not taken for the information processing device and post-countermeasure risk information indicating the attack risk level when the measure is taken for the information processing device. The countermeasure support device according to claim 2.

5. The difficulty information receiving means receives, as the difficulty information, information representing an element difficulty level indicating the difficulty of the measure for each of a plurality of items, and further includes difficulty calculation means for calculating an average value of the element difficulty levels as the difficulty level. The countermeasure support device according to claim 1 or 2.

6. The countermeasure support device according to claim 5, wherein the difficulty calculation means calculates the weighted average value of the element difficulty levels as the difficulty level.

7. The countermeasure support device according to claim 1 or 2, wherein the risk information acquisition means derives the change in the attack risk level of the communication path from the attack risk level of the communication path via the information processing device on which the countermeasure is to be implemented and the attack risk level of the communication path in a state where the countermeasure not implemented in the information processing device has been implemented.

8. The plurality of information processing devices include the intrusion device and the attack target device, the communication path includes the information processing device on the communication path and a partial path connecting between the information processing devices, and the risk information acquisition means acquires, as the attack risk level of the communication path, the smallest attack risk level among the attack risk levels of the partial paths included in the communication path. The countermeasure support device according to claim 7.

9. The countermeasure support device according to claim 7, further comprising attack path derivation means for deriving the communication path from the intrusion device to the attack target device and the attack risk level of the communication path from information processing system information including information on the configuration of the information processing system, information indicating the intrusion device, information indicating the attack target device, and information on the information processing devices included in the information processing system according to a predetermined algorithm.

10. The countermeasure support device according to claim 1, wherein the output means outputs a combination of information indicating the information processing device targeted by the countermeasure and information indicating the countermeasure in descending order of the efficiency indicated by the efficiency value.

11. The countermeasure support device according to claim 1 or 2, comprising output information generation means for selecting the countermeasure so as to satisfy a specified condition and generating information on the selected countermeasure.

12. A countermeasure support method for obtaining risk information representing a change in the attack risk level of a communication path for an information processing device on a communication path connecting an intrusion device and an attack target device in an information processing system including a plurality of information processing devices and a communication network connecting the plurality of information processing devices, receiving difficulty information indicating the difficulty level of the countermeasure, calculating, from the change in the attack risk level and the difficulty level, a value of the difficulty level per a predetermined change amount of the change in the attack risk level of the countermeasure as an efficiency value, and outputting information on the countermeasure in a manner corresponding to the level of efficiency indicated by the efficiency value.

13. An output image including a device display indicating the information processing device and a path display indicating the communication path, wherein the device display is represented in a manner corresponding to the level of efficiency indicated by the efficiency value of the countermeasure for the information processing device indicated by the device display, the path display is represented by a line passing through the information processing device on the communication path, generating the output image, and outputting the output image as information on the countermeasure. The countermeasure support method according to claim 12.

14. Receiving a device designation for designating the information processing device, and generating the output image further indicating the risk information of the countermeasure for the information processing device designated by the device designation. The countermeasure support method according to claim 13.

15. Generating the output image indicating, as the risk information, pre-countermeasure risk information indicating the attack risk level when the countermeasure is not performed on the information processing device and post-countermeasure risk information indicating the attack risk level when the countermeasure is performed on the information processing device. The countermeasure support method according to claim 13.

16. Receiving, as the difficulty information, information representing an element difficulty level indicating the difficulty of each of a plurality of items of the countermeasure, and calculating an average value of the element difficulty levels as the difficulty level. The countermeasure support method according to claim 12 or 13.

17. Calculating a weighted average value of the element difficulty levels as the difficulty level. The countermeasure support method according to claim 16.

18. The method for supporting countermeasures according to claim 12 or 13, wherein the change in the attack risk level of the communication path is derived from the attack risk level of the communication path via the information processing apparatus where the countermeasure is implemented and the attack risk level of the communication path in a state where the countermeasure not implemented in the information processing apparatus is implemented.

19. The plurality of information processing apparatuses include the intrusion device and the attack target device, the communication path includes the information processing apparatus on the communication path and a partial path connecting between the information processing apparatuses, and as the attack risk level of the communication path, the smallest attack risk level among the attack risk levels of the partial paths included in the communication path is obtained. The method for supporting countermeasures according to claim 18.

20. A storage medium storing a program for causing a computer to execute: a risk information acquisition process for acquiring risk information representing a change in the attack risk level of a communication path when a security countermeasure is taken against an information processing apparatus on a communication path connecting an intrusion device and an attack target device in an information processing system including a plurality of information processing apparatuses and a communication network connecting the plurality of information processing apparatuses; a difficulty information reception process for receiving difficulty information indicating the difficulty level of the countermeasure; an efficiency calculation process for calculating, as an efficiency value, a value of the difficulty level per a predetermined change amount of the change in the attack risk level of the countermeasure from the change in the attack risk level and the difficulty level; and an output process for outputting information on the countermeasure in a manner corresponding to the level of efficiency indicated by the efficiency value.

Citation Information

Patent Citations

  • Security measure planning support system and method

    JP2018077597A

  • Analysis system, method, and program

    WO2021192587A1