Information processing system, information processing method, program, and recording medium
A system tracks software component changes with time stamps to identify past vulnerabilities, enhancing security by enabling timely notifications and updates.
Patent Information
- Application Number
- PCT/JP2024/035074
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-27
- Filing Date
- 2024-10-01
- Publication Date
- 2025-07-03
AI Technical Summary
Existing systems fail to identify when software with vulnerabilities was used in the past, making it difficult to address potential security risks and defects.
A system that generates history information linking software component changes with time stamps, allowing identification of past software usage and vulnerabilities by associating configuration information with time information.
Enables the identification of past software usage and vulnerabilities, facilitating timely notifications and updates to mitigate risks.
Smart Images

Figure JP2024035074_03072025_PF_FP_ABST
Abstract
Description
Information processing system, information processing method, program, and recording medium
[0001] The present disclosure relates to an information processing system, an information processing method, a program, and a recording medium.
[0002] The management device described in Patent Document 1 aims to identify locations in a system where an abnormality may occur. To achieve this aim, the management device stores configuration information indicating the configuration of each component of the system. The management device performs the following operations: identifies a first component in which an abnormality has occurred; and identifies a second component that is common to the identified first component from the stored configuration information.
[0003] In the management device, in relation to the above-mentioned operation, a software bill of materials (SBOM), which is software configuration information, may include vulnerability information, for example.
[0004] International Publication No. 2023-084671
[0005] However, the above-described management device has a problem in that, for example, even if software has had a vulnerability in the past, it is not possible to identify when the software was used.
[0006] The object of the present disclosure is to provide an information processing system, an information processing method, a program, and a recording medium that can identify when software was used, even if the software had vulnerabilities in the past.
[0007] In order to solve the above-mentioned problems, the information processing system according to the present disclosure generates, by a processing unit, history information indicating a change history of the software component information based on software component information (including SBOM) and history timing information relating to one or more software components that constitute a specified piece of software, and the history timing information is information indicating the timing of one or more points in time from the time the software component information is generated to the time the history information is stored.
[0008] According to the information processing system of the present disclosure, even if software has had vulnerabilities in the past, it is possible to identify when the software was used.
[0009] 1 shows the configuration of an information processing system JSS of embodiment 1. FIG. 1 shows the configuration of a terminal TM of embodiment 1. FIG. 1 shows the configuration of a server SV of embodiment 1. FIG. 2 is a flowchart showing the operation of the information processing system JSS of embodiment 1. FIG. 3 is a time chart showing the operation of the information processing system JSS of embodiment 1. FIG. 4 shows configuration information KJ0 (at time t0) of embodiment 1. FIG. 5 shows time information JJ0 (at time t0) of embodiment 1. FIG. 6 shows configuration information KJ1 (at time t1) of embodiment 1. FIG. 7 shows time information JJ1 (at time t1) of embodiment 1. FIG. 8 shows configuration information KJ2 (at time t2) of embodiment 1. FIG. 9 shows time information JJ2 (at time t2) of embodiment 1. FIG. 10 shows configuration information KJ3 (at time t3) of embodiment 1. FIG. 11 shows time information JJ3 (at time t3) of embodiment 1. FIG. 12 shows configuration information KJ4 (at time t4) of embodiment 1. FIG. 13 shows time information JJ4 (at time t4) of embodiment 1. 1 shows configuration information KJ5 (at time t5) of embodiment 1. 2 shows time information JJ5 (at time t5) of embodiment 1. 3 shows history information RJ (at time t0) of embodiment 1. 4 shows history information RJ (at time t1) of embodiment 1. 5 shows history information RJ (at time t2) of embodiment 1. 6 shows history information RJ (at time t3) of embodiment 1. 7 shows history information RJ (at time t4) of embodiment 1. 8 shows history information RJ (at time t5) of embodiment 1. 9 shows history information RJ (at time t5) of embodiment 1. 10 shows history information RJ of embodiment 2. 11 shows configuration information KJ0 and configuration information KJ1 of embodiment 2. 12 shows configuration information (hierarchy) KJ0 (KS) and configuration information (hierarchy) KJ1 (KS) of embodiment 2. 13 shows configuration information (relationship) KJ0 (KK) and configuration information (relationship) KJ1 (KK) of embodiment 2. 14 shows the display mode of configuration information KJ11 of embodiment 3. 1 shows a display form of configuration information KJ12 according to embodiment 3. 2 shows a display form of configuration information KJ13 according to embodiment 3. 3 shows a display form of configuration information KJ14 according to embodiment 3. 4 shows a hardware configuration of the information processing system JSS according to embodiments 1 to 3. 5 shows a hardware configuration based on software realization of the information processing system JSS according to embodiments 1 to 3.
[0010] An embodiment of an information processing system JSS according to the present disclosure will be described.
[0011] First Embodiment An information processing system JSS according to a first embodiment will be described.
[0012] <Configuration of First Embodiment> <Configuration of Information Processing System JSS> FIG. 1 shows the configuration of an information processing system JSS according to the first embodiment.
[0013] The information processing system JSS of the first embodiment includes terminals TM1 to TMm (m is an integer equal to or greater than 1) and a server SV, as shown in Fig. 1. The terminals TM1 to TMm and the server SV are connected to each other via a network NW (e.g., the Internet).
[0014] The terminals TM1 to TMm are used by users US1 to USm who develop and use software SW to be managed by the server SV. For example, the terminal TM1 is used by the user US1, the terminal TM2 is used by the user US2, and so on, and the terminal TMm is used by the user USm.
[0015] The server SV is used by the administrator KA. As shown in FIG. 1 , the server SV stores software SW and generates and stores configuration information KJ (particularly, component information included in the software SW (hereinafter also referred to as “software component information”)) and history information RJ including history timing information (e.g., time information JJ). The history timing information is timing information stored as history information, and may be timing information (e.g., information including at least a date, hereinafter also referred to as “time information JJ”) at one or more points in time from the time the software component information (e.g., configuration information KJ) was generated to the time the history information RJ was stored. More specifically, the history timing information may be, for example, the time when the software component information was generated by the processing unit SY (SV), the time when the software component information was acquired by the server SV (e.g., if generated outside the server SV), the time when the software component information was stored by the server SV, the time when the history information was generated by the processing unit SY (SV), or the time when the history information was stored by the server SV. In addition, when the server SV is configured logically (for example, a cloud server), the administrator KA may operate the terminal TM to perform operations on the server SV.
[0016] In the following, for ease of explanation and understanding, a plurality of identical devices may be collectively referred to by a single name, for example, terminals TM1 to TMm may be collectively referred to as terminal TM.
[0017] <Configuration of Terminal TM> FIG. 2 shows the configuration of the terminal TM according to the first embodiment.
[0018] As shown in FIG. 2, the terminal TM of the first embodiment has an input / output unit NS(TM), a processing unit SY(TM), a storage unit KI(TM), and a communication unit TU(TM).
[0019] The input / output unit NS(TM) is used by the user US to input data to change, add, delete, etc., components that make up the software SW (e.g., as shown in FIG. 6) in order to update the software SW, and is also used to output the configuration of the software SW obtained from the server SV. The input / output unit NS(TM) is, for example, a touch panel, a keyboard, a mouse, an LCD monitor, or a printer.
[0020] The processing unit SY(TM) performs processing related to, for example, input for updating the software SW and output of the configuration of the software SW. The processing unit SY(TM) also executes the software SW obtained by the user US according to the needs of the user US.
[0021] The storage unit KI(TM) stores, for example, data necessary for processing by the processing unit SY(TM).
[0022] The communication unit TU(TM) communicates via the network NW, for example, transmitting the above-mentioned updated software SW to the server SV, and also receiving the software SW managed by the server SV from the server SV.
[0023] <Configuration of Server SV> FIG. 3 shows the configuration of the server SV according to the first embodiment.
[0024] As shown in FIG. 3, the server SV of the first embodiment includes an input / output unit NS(SV), a processing unit SY(SV), a storage unit KI(SV), and a communication unit TU(SV).
[0025] The input / output unit NS (SV) is used, for example, to output history information RJ (e.g., as shown in FIG. 1 ) of the software SW in connection with an update of the software SW, and is also used to input information to add supplementary information (e.g., bibliographic information) to the history information RJ. The input / output unit NS (TM) is, for example, a touch panel, keyboard, mouse, LCD monitor, or printer. Note that, as described above, if the server SV is logically configured via a network (e.g., a cloud server), it may be replaced by the input / output unit NS provided in the terminal TM of the administrator KA.
[0026] The processing unit SY (SV) performs, for example, processing related to the output of the history information RJ and input to the history information RJ. The processing unit SY (SV) also notifies the user US and manages the license of the software SW as necessary based on the history information RJ.
[0027] The storage unit KI (SV) stores, for example, data necessary for processing by the processing unit SY (SV).
[0028] The communication unit TU (SV) performs communication via the network NW, for example, receives updated software SW from the user US, and transmits software SW managed by the server SV to the terminal TM.
[0029] <Operation of First Embodiment> FIG. 4 is a flowchart showing the operation of the information processing system JSS of the first embodiment.
[0030] 5 is a time chart showing the operation of the information processing system JSS of embodiment 1. The operation of the information processing system JSS of embodiment 1 will be described with reference to the flowchart of FIG. 4 and the time chart of FIG.
[0031] In the following, for ease of explanation and understanding, the following is assumed: (1) Users US1 to US3 among users US1 to USm are involved in the development of the software SW (shown in FIG. 4); (2) The initial version of the software SW includes one or more components (e.g., components A, B, C, ..., W) (shown in FIG. 6); and (3) History information RJ (shown in FIG. 18) that links together configuration information KJ0 (shown in FIG. 6) indicating the configuration of the initial version of the software SW and time information JJ0 (shown in FIG. 7) indicating the time t0 (12:34, Feb. 3, 2023) when the software SW (initial version) was saved is stored in the server SV.
[0032] Step ST11 (at time t1): The terminal TM1 transmits the software SW to which the user US1 has added the part Dadd, that is, the configuration information KJ1 (shown in FIG. 8), to the server SV.
[0033] Step ST12: When the server SV receives or acquires the software SW to which "component Dadd has been added," i.e., the configuration information KJ1, it acquires, for example, time information JJ1 (shown in FIG. 9) indicating time t1 "March 4, 2023, 1:45 PM" from the clock in the information processing system JSS. The server SV further updates the history information RJ by linking the configuration information KJ1 and the time information JJ1 to each other (shown in FIG. 19).
[0034] Step ST13 (at time t2): The terminal TM2 transmits the software SW for which the user US2 has "changed the part T to the part Tchg", that is, the configuration information KJ2 (shown in FIG. 10), to the server SV.
[0035] Step ST14: When the server SV receives the software SW in which "part T has been changed to part Tchg," i.e., the configuration information KJ2, it acquires time information JJ2 (shown in FIG. 11) indicating time t2, "April 5, 2023, 14:32." The server SV further updates the history information RJ by linking the configuration information KJ2 and the time information JJ2 to each other (shown in FIG. 20).
[0036] Step ST15 (at time t3): The terminal TM3 transmits the software SW for which the user US3 has "changed the part U to the part Uchg", that is, the configuration information KJ3 (shown in FIG. 12), to the server SV.
[0037] Step ST16: When the server SV receives the software SW in which "part U has been changed to part Uchg", i.e., the configuration information KJ3, it acquires time information JJ3 (shown in FIG. 13) indicating time t3 "15:21, May 6, 2023". The server SV further updates the history information RJ by linking the configuration information KJ3 and the time information JJ3 to each other (shown in FIG. 21).
[0038] Step ST17 (at time t4): The terminal TM2 transmits the software SW for which the user US2 has "changed the part Tchg1 to the part Tchg2", that is, the configuration information KJ4 (shown in FIG. 14), to the server SV.
[0039] Step ST18: When the server SV receives the software SW in which "part Tchg1 has been changed to part Tchg2," i.e., the configuration information KJ4, it acquires time information JJ4 (shown in FIG. 15) indicating time t4, "June 7, 2023, 16:10." The server SV further updates the history information RJ by linking the configuration information KJ4 and the time information JJ4 to each other (shown in FIG. 22).
[0040] Step ST19 (at time t5): The terminal TM1 transmits the software SW for which the user US1 has "changed the part W to the part Wchg", that is, the configuration information KJ5 (shown in FIG. 16), to the server SV.
[0041] Step ST20: When the server SV receives the software SW for which "part W has been changed to part Wchg," i.e., the configuration information KJ5, it acquires time information JJ5 (shown in FIG. 17) indicating time t5, "17:05, July 8, 2023." The server SV further updates the history information RJ by linking the configuration information KJ5 and the time information JJ5 to each other (shown in FIG. 23).
[0042] In the above example, the configuration information KJ is transmitted to the server SV. However, instead, the configuration information KJ (particularly, software component information) of the software SW may be generated by analyzing information about the software SW (e.g., folder hierarchy information, program source hierarchy information, etc.) by the processing unit SY of the server SV, thereby constructing the configuration information KJ including hierarchical component information. Furthermore, the software-related information may be transmitted from the terminal TM, or may be information read from a storage area of another computer (e.g., a cloud server) via a predetermined path. The predetermined path may be, for example, reading the information via a network or a wired cable (e.g., by being granted access to the storage area of the other computer) by the processing unit SY of the server SV or the terminal TM. Alternatively, the information may be temporarily stored in an external storage device such as a memory card, and then connected to a computer accessible to the server SV, such as the terminal TM, and read from the external storage device, thereby storing the information in the storage unit KI of the server SV.
[0043] Effect of First Embodiment As described above, in the information processing system JSS of the first embodiment, each time the users US1 to US3 update the contents of the software SW (adding, changing, deleting, etc.), the server SV generates history information RJ by linking the configuration information KJ and the time information JJ to each other. As a result, even if the software SW has had defects in the past (e.g., vulnerabilities, bugs, crashes, and other problems, as well as license-related defects caused by the licensor of a licensed component (e.g., use outside the scope specified in the license, open-source software no longer being open source, the expiration of a paid license, etc.)), it is possible to check the history information RJ and determine when the software SW was used.
[0044] For example, even if part Tchg1 has a vulnerability, as shown in Figure 5, it is possible to determine that part Tchg1 is being used and the usage period SK is between time t2 and time t4, and more specifically, between "14:32, April 5, 2023" and "16:10, June 7, 2023."
[0045] <Variation 1-1> Information on whether components A to W, etc. included in the software SW have vulnerabilities (hereinafter also referred to as "vulnerability information") may be received as an input from a terminal TM of a user US who develops the software SW and stored in a storage unit KI of the server SV, or the vulnerability information may be generated by an independent analysis by a processing unit SY of the server SV and stored in the storage unit KI of the server SV. Furthermore, if a vulnerability database in which vulnerability information of the software SW is stored is publicly available (especially if it is open source), the processing unit SY of the server SV may access the vulnerability database via a network NW (e.g., the Internet) to collect (crawl) and store the vulnerability information.
[0046] Then, the processing unit SY of the server SV may compare the vulnerability information stored in the memory unit KI of the server SV with the configuration information KJ (particularly, information regarding components A to W) contained in the history information RJ, and perform a process to identify information indicating at least one of the period during which the component corresponding to the vulnerability information was included, software information (including version information), or configuration information KJ (hereinafter also referred to as "vulnerability target information").
[0047] While vulnerability information has been described above for ease of explanation and understanding, the present invention is not limited to this. Information (hereinafter also referred to as "defect information") related to defects in software SW (particularly, components A-W included in the software SW) stored in the storage unit KI of the server SV (e.g., vulnerability information, malfunction information, license-related defect information, etc., as described above) may be used. That is, the processing unit SY of the server SV may compare the defect information stored in the storage unit KI of the server SV with configuration information KJ (particularly, information related to components A-W) included in the history information RJ, and identify (generate) information indicating at least one of the period or version during which the component corresponding to the defect information was included in the history information RJ and the configuration information KJ (hereinafter also referred to as "defect-related information"). Note that "storing" the defect information includes storing the defect information in a primary storage device (main memory), secondary storage device, cache memory, or the like included in the storage unit KI. For example, the defect information may be stored in a registration process in response to a registration operation by the user US or administrator KA, or temporarily stored when retrieved from an external database or the like for reference.
[0048] <Effects of Variation 1-1> With the configuration of Variation 1-1, even if the software SW has had a defect in the past (for example, including vulnerabilities, bugs, crashes, and other problems, and also including license-related defects caused by the licensor of a licensed component (for example, use outside the scope specified in the license, open source software ceasing to be open source, or a paid license expiring)), it is possible to identify the information related to the defect through processing by the processing unit SY of the server SV.
[0049] <Variation 1-2> Furthermore, based on a defect-related specification process in which the administrator KA or the like checks the history information RJ and specifies at least one of the period or version in which the component corresponding to the defect information was included in the history information RJ and the configuration information KJ through a defect-related specification operation, as in the first embodiment, or based on the processing of the processing unit SY as in variation 1-1 above, the processing unit SY of the server SV may transmit to the terminals TM1 to TMm, in response to the identification (generation) of defect-related information, such as a period in which a component corresponding to the defect information was included in the history information RJ. For example, the processing unit SY of the server SV may transmit, to the terminals TM1 to TMm, a notification that "during the usage period SK (shown in FIG. 6 ) the software SW included the defective component Tchg1" (i.e., a notification regarding the usage period SK in which the defective component was used), a notification that "the use of the software SW including the component Tchg1 is prohibited" (i.e., a notification regarding the prohibition of use of software including the defective component), or a notification that "the use of the software SW including the component Tchg2 that does not have the vulnerability is recommended" (i.e., a notification regarding the recommendation to use software including the component that does not have the defect).
[0050] <Effects of Modification 1-2> With the configuration of Modification 1-2, a notification regarding a software component having an identified defect is sent to the terminal TM of the user US, thereby enabling the user US to smoothly recognize the defect.
[0051] <Variation 1-3> Furthermore, the processing unit SY of the server SV may associate importance information indicating the importance of each software component or software SW (which may also be called "impact indicating the impact") and store it in the memory unit KI of the server SV.
[0052] The importance information (impact information) may be, for example, input from at least one of the user US and the administrator KA, and an arbitrary importance may be set for each software component and / or each software SW in the memory unit KI of the server SV, and / or the processing unit SY of the server SV may execute a setting process to set the importance by referring to importance condition information indicating the conditions for setting each importance. Here, the conditions for setting each importance may be, for example, at least one of the following six: (1) Whether or not at least one of the target software SW or software component (hereinafter referred to as software component, etc.) is connected to the Internet (i.e., a condition based on connection relationship information); (2) Whether or not the target software component, etc. is connected to an area where access is restricted (i.e., a condition based on access restriction information); (3) Whether or not the target software component, etc. contains important data information (e.g., confidential information, customer information, personal information, credit card information, etc.) (i.e., a condition based on important data information); (4) Which software environment (test environment, development environment, production environment, etc.) is the target software component, etc. (i.e., a condition based on software environment information); (5) Whether or not the target software component, etc. has access rights to other resources (computers, databases, networks, etc.) (i.e., a condition based on access right information); (6) What is the threat level of the defects (especially vulnerabilities) linked to the software component itself (i.e., a condition based on defect threat level information)
[0053] Then, the processing unit SY performs a determination process in which importance information indicating the importance corresponding to the changed software component, etc. (particularly, software components, etc., for which the difference in change identified in the second embodiment described below is greater than the standard) is compared with the standard information, and determines whether the importance is higher than the standard.Only when it is determined that the importance is higher than the standard, a notification including information regarding the importance of the changed software component, etc. (for example, a notification informing users that a software component, etc., with a high level of importance has been changed) may be sent (i.e., the need for a notification may be determined based on the importance). At this time, one or more pieces of criterion information may be stored in the memory unit KI of the server SV, and if two or more comparison results are obtained (for example, if the importance level is set to four levels, Critical, High, Medium, and Low, according to the conditions, then if there is one criterion, two comparison results, Critical or higher and High or lower, or two comparison results, High or higher and Medium or lower, etc.; if there are three criteria, four comparison results, each with a weight from Critical to Low, may be obtained), notification destination information may be set according to each comparison result. That is, the notification destination information may include destination information (e.g., an email address, etc.). For example, if there is one criterion, if the importance level of the changed software component or the like is Critical, a notification may be sent based on destination information indicating a mailing list for all members of the group, and if the importance level is High or lower, a notification may be sent based on destination information indicating only one specific responsible person. In other words, depending on the comparison results, the notification may be sent to different recipients (e.g., a mailing list or just one responsible person) or to different notification scopes (e.g., a mailing list and one responsible person or just one responsible person).
[0054] Alternatively, or in addition, the processing unit SY may compare importance information indicating the importance of a software component or the like identified as defect-related information with reference information to determine whether the importance is higher than the reference level. The notification described in Modification 1-2 may be sent only if the importance is determined to be higher than the reference level (i.e., the necessity of the notification may be determined based on the importance level). In this case, one or more reference information may be stored in the storage unit KI of the server SV, and when two or more comparison results are obtained, notification destination information may be set according to each comparison result. That is, the notification destination information may include destination information (e.g., email address). For example, if there is only one criterion, if the importance of the changed software component or the like is Critical, the notification may be sent based on destination information indicating a mailing list for all members of the group. If the importance is High or lower, the notification may be sent based on destination information indicating only one specific responsible person. In other words, depending on the comparison results, the notification may be sent to different recipients (e.g., a mailing list or just one responsible person) or to different notification scopes (e.g., a mailing list and one responsible person or just one responsible person).
[0055] <Effects of Modification 1-3> The configuration of Modification 1-3 enables efficient response when software updates are frequent by checking the importance (impact) of changed software components, etc. (or software components, etc. in which defects have been identified). In particular, when issuing notifications, the number of notifications can be reduced by limiting notifications to those with a predetermined importance (importance higher than the standard).
[0056] Second Embodiment An information processing system JSS according to a second embodiment will be described.
[0057] <Configuration of Second Embodiment> The information processing system JSS of the second embodiment has the same configuration as the information processing system JSS of the first embodiment (shown in FIGS. 1, 2, and 3).
[0058] <Operation of Second Embodiment> The information processing system JSS of the second embodiment basically performs the same operations as the information processing system JSS of the first embodiment (shown in FIGS. 4 and 5).
[0059] On the other hand, the information processing system JSS of the second embodiment differs from the information processing system JSS of the first embodiment, which stores history information RJ (shown in FIGS. 18 to 23) consisting of time information JJ and configuration information KJ, in that, or in addition, the information processing system JSS of the second embodiment stores history information RJ consisting of time information JJ and difference information SJ, as shown in Fig. 24. That is, the information processing system JSS generates comparison result information (hereinafter also referred to as "difference information") that indicates the results (differences) of comparing software component information stored at two different points in time. In addition, the difference information SJ may be stored in the memory unit KI of the server SV, for example, by accepting input from the terminal TM, and / or the processing unit SY of the server SV may perform a comparison process (for example, character comparison by character-based search, or image comparison by image-based image analysis, etc.) between any form of configuration information KJ, including tree-diagram-like configuration information KJ (i.e., configuration information KJ showing the relationships between software components), matrix-like configuration information KJ, and interrelationship configuration information KJ, and the results of the comparison may be stored in the memory unit KI of the server SV as difference information.
[0060] In the history information RJ, as shown in FIG. 24, the time information JJ and the difference information SJ are linked to each other; for example, the time information JJ1 at time t1 and the difference information SJ1 at time t1 are linked to each other.
[0061] The difference information SJ of the second embodiment, which replaces the configuration information KJ of the first embodiment, indicates the difference between the software SW before and after the software SW is updated, that is, the difference between the configuration information KJ.
[0062] For example, difference information SJ1 is the result of comparing configuration information KJ0 (shown in the top of Figure 25), which is a tree diagram, at time t0 indicated by time information JJ0, with configuration information KJ1 (shown in the bottom of Figure 25), which is a tree diagram, at time t1 indicated by time information JJ1, i.e., it indicates the difference, ``addition of part Dadd'' (shown in Figures 24 and 25).
[0063] The difference information SJ1 also indicates the difference "addition of part Dadd" (shown in Figures 24 and 26) between the matrix-shaped configuration information (hierarchy) KJ0 (KS) (shown in the top of Figure 26) at time t0 indicated by the time information JJ0 and the matrix-shaped configuration information (hierarchy) KJ1 (KS) (shown in the bottom of Figure 26) at time t1 indicated by the time information JJ1.
[0064] The difference information SJ1 further indicates the difference "addition of part Dadd" (shown in Figures 24 and 27) between the configuration information (relationship) KJ0(KK) (shown in the top of Figure 27) indicating the interrelationship between parts (e.g., parent-child relationship) at time t0 indicated by the time information JJ0 and the configuration information (relationship) KJ1(KK) (shown in the bottom of Figure 27) indicating the interrelationship between parts at time t1 indicated by the time information JJ1.
[0065] As described above, in the information processing system JSS of the second embodiment, history information RJ in which difference information SJ and time information JJ are linked to each other is generated, instead of history information RJ in which configuration information KJ and time information JJ are linked to each other as in the first embodiment. As a result, similar to the first embodiment, it is possible to identify when software SW was used, even if the software SW had vulnerabilities in the past.
[0066] <Variation 2-1> The difference information described above includes the component name, but instead of or in addition to this, a difference value corresponding to the amount of difference may be linked. The difference value may be, for example, a value based on the number of differences. Alternatively, the difference value may be a value obtained by multiplying the number of differences by a weighting coefficient set for each component.
[0067] Effect of Modification 2-1 With the configuration of Modification 2-1, by linking a difference value according to the amount of difference instead of or in addition to the component name as difference information, it becomes possible to recognize not only differences in the software configuration but also changes more quantitatively. This makes it possible to perform operations such as "checking whether the difference amount after a change exceeds a reference value, and if so, checking whether a malfunction has occurred."
[0068] <Variation 2-2> Furthermore, result condition information indicating conditions related to the comparison result may be set, and a notification indicating that the conditions are met may be transmitted to the terminal TM based on the comparison result information (difference value) and the result condition information (for example, a reference value is set and the difference value exceeds the reference difference value).
[0069] <Effects of Variation 2-2> The configuration of Variation 2-2 enables the user US to smoothly recognize changes to the software SW (especially changes with large differences) by sending notifications about software components that have differences greater than a predetermined standard to the user US's terminal TM.
[0070] Third Embodiment An information processing system JSS according to a third embodiment will be described.
[0071] <Configuration of Third Embodiment> The information processing system JSS of the third embodiment has the same configuration as the information processing system JSS of the first embodiment (shown in FIGS. 1, 2, and 3).
[0072] <Operation of embodiment 3> In the information processing system JSS of embodiment 3, the input / output units NS (TM) (shown in Figure 2) of terminals TM1 to TMm display, for example, the configuration of the software SW in the form of configuration information KJ11 to KJ4 (shown in Figures 28 to 31) instead of or in addition to the configuration information KJ of embodiment 1 (for example, configuration information KJ0 (shown in Figure 6)).
[0073] In the configuration information KJ11, as shown in FIG. 28, the components A to W that make up the software SW may be displayed separately as main routines and subroutines.
[0074] In the configuration information KJ12, as shown in FIG. 29, the number of times that components A to W that make up the software SW are used in the software SW may be displayed together with the number of times that they are used in the software SW.
[0075] In the configuration information KJ13, as shown in FIG. 30, the components A to W that make up the software SW may be displayed divided into components that have subroutines and components that do not have subroutines.
[0076] In the configuration information KJ14, as shown in FIG. 31, the required times T(A), T(B), T(C), and T(D) of the main routines of the components A, B, C, and D that make up the software SW, and the components that make up the components A, B, C, and D (for example, the components S and T that make up the component A) may be displayed in chronological order.
[0077] Effect of the Third Embodiment As described above, the information processing system JSS of the third embodiment displays the configuration information KJ11 to KJ14 in a display format instead of or in addition to the display format used by the information processing system JSS of the first embodiment. As a result, as in the first embodiment, it is possible to identify when the software SW was used, even if the software SW had a defect in the past. Furthermore, the information processing system JSS of the first embodiment has a display format for the configuration information KJ11 to KJ14 that is more easily visible, making it possible to perform the above identification more easily.
[0078] <Hardware Configuration of the First to Third Embodiments> FIG. 32 shows the hardware configuration of the information processing system JSS of the first to third embodiments.
[0079] To perform the above-described functions, the information processing systems JSS according to the first to third embodiments include a processing circuit SYO, as shown in FIG. 32, and may further include an input circuit NYU and an output circuit SYU as necessary.
[0080] The processing circuit SYO is dedicated hardware and mainly realizes the functions of the processing unit SY(TM) of the terminal TM and the processing unit SY(SV) of the server SV (shown in FIGS. 2 and 3).
[0081] The processing circuit SYO is, for example, a single circuit, a complex circuit, a programmed processor, a parallel programmed processor, an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or a combination thereof.
[0082] The input circuit NYU and the output circuit SYU exchange inputs and outputs related to the operation of the processing circuit SYO with, for example, a terminal TM or an external device outside the server SV.
[0083] <Hardware Configuration Based on Software Realization of the First to Third Embodiments> FIG. 33 shows a hardware configuration based on software realization of the information processing system JSS of the first to third embodiments.
[0084] As shown in FIG. 32, the information processing system JSS according to the first to third embodiments includes a processor PRO and a memory circuit KIO, and may further include an input circuit NYU and an output circuit SYU as necessary.
[0085] The processor PRO is a CPU (also called a central processing unit, processing device, arithmetic unit, microprocessor, microcomputer, or DSP (Digital Signal Processing)) that executes programs. The processor PRO mainly realizes the functions of the processing unit SY (TM) of the terminal TM and the processing unit SY (SV) of the server SV.
[0086] The processor PRO realizes the above-mentioned functions by software, firmware, or a combination of software and firmware. The software and firmware are written as a program PRG and stored in the memory circuit KIO.
[0087] The processor PRO realizes the above-mentioned functions by reading and executing the above-mentioned program PRG from the memory circuit KIO. The above-mentioned program PRG can be said to mainly cause the computer to execute the procedures and methods of the processing unit SY(TM) of the terminal TM and the processing unit SY(SV) of the server SV.
[0088] Here, the memory circuit KIO is, for example, a non-volatile or volatile semiconductor memory such as RAM (Random Access Memory), ROM (Read Only Memory), flash memory, EPROM (Erasable Programmable Read Only Memory), EEPROM (Electrically Erasable Programmable Read-Only Memory), etc., as well as a magnetic disk, a flexible disk, an optical disk, a compact disk, a mini disk, a DVD (Digital Versatile Disc), etc.
[0089] Of the functions of the input / output unit NS(TM) to the communication unit TU(TM) of the terminal TM and the input / output unit NS(SV) to the communication unit TU(SV) of the server SV, some of the functions may be realized by a processing circuit SYO (shown in Figure 32), while other functions may be realized by a processor PRO (shown in Figure 33).
[0090] As described above, the functions of the input / output unit NS(TM) to the communication unit TU(TM) of the terminal TM and the input / output unit NS(SV) to the communication unit TU(SV) of the server SV can be realized by hardware, software, firmware, or a combination of these.
[0091] The input circuit NYU and the output circuit SYU exchange inputs and outputs related to the operation of the processor PRO with, for example, the terminal TM and the outside of the server SV.
[0092] <Configuration Example> The information processing system, information processing system method, program, and recording medium according to the present disclosure have, for example, the following configuration.
[0093] [Item 1] An information processing system in which a processing unit generates history information indicating a change history of the software component information based on software component information and history timing information for one or more software components that make up specified software, wherein the history timing information indicates one or more timing points from the time the software component information is generated to the time the history information is stored. [Item 2] The information processing system according to Item 1, in which the processing unit further identifies information indicating at least one of the software component information or the period during which the component corresponding to the defect information was included, based on the defect information stored in the storage unit and the history information. [Item 3] The information processing system according to Item 2, in which the processing unit further transmits to a specified terminal at least one of a notification regarding the period during which the defective component was used, a notification regarding the prohibition of use of software including the defective component, or a notification regarding the recommendation to use software including the defective component. [Item 4] The information processing system according to Item 3, in which the processing unit further determines whether to send the notification based on importance information set at least either on a component-by-component basis or on a software component information-by-software basis. [Item 5] The information processing system according to any one of items 1 to 4, which generates comparison result information indicating the results of comparing software component information stored at two points in time. [Item 6] The information processing system according to item 5, which transmits a notification to a predetermined terminal indicating that a condition related to the comparison result information is met, based on the comparison result information and result condition information indicating a condition related to the result. [Item 7] The information processing system according to item 6, wherein the comparison result is difference value information based on a difference between the software component information, and the condition includes that the difference value indicated by the difference value information exceeds a reference difference value. [Item 8] The information processing system according to any one of items 1 to 7, wherein the software component information is acquired by analyzing hierarchical information included in information related to software. [Item 9] The information processing system according to item 8, wherein the information related to software is information read from a storage area of another computer.[Item 10] An information processing method, in which a processing unit generates, based on software component information and history timing information for one or more software components that constitute specified software, history information indicating a change history of the software component information, wherein the history timing information is information indicating the timing of one or more points in time from the time the software component information is generated to the time the history information is stored. [Item 10] A program, in which a processing unit generates, based on software component information and history timing information for one or more software components that constitute specified software, history information indicating a change history of the software component information, wherein the history timing information is information indicating the timing of one or more points in time from the time the software component information is generated to the time the history information is stored.
[0094] JSS Information processing system TM Terminal SV Server US User KA Administrator NW Network SW Software RJ History information KJ Configuration information JJ Time information
Claims
1. An information processing system, wherein a processing unit generates history information indicating a change history of software component information based on the software component information and history timing information regarding one or more software components constituting predetermined software, and the history timing information is information indicating the timing of one or more points in time from the generation time point of the software component information to the storage time point of the history information.
2. The information processing system according to claim 1, wherein the processing unit further identifies information indicating at least one of a period during which a component corresponding to defect information was included or software component information, based on the defect information stored in a storage unit and the history information.
3. The information processing system according to claim 2, wherein the processing unit further transmits at least one of a notification regarding a usage period during which a component including the defect was used, a notification regarding prohibition of use of software including the component including the defect, or a notification regarding recommendation of use of software including a component not including the defect, to a predetermined terminal.
4. The information processing system according to claim 3, wherein the processing unit further determines whether to transmit the notification based on importance information set in at least one of a component unit or a software component information unit.
5. The information processing system according to claim 1, which generates comparison result information indicating a result of comparing software component information stored at two points in time with each other.
6. The information processing system according to claim 5, which transmits a notification indicating that the condition is met to a predetermined terminal based on the comparison result information and result condition information indicating a condition related to the result.
7. The information processing system according to claim 6, wherein the comparison result is difference value information based on the difference between software component information, and the condition includes that the difference value indicated by the difference value information exceeds a reference difference value.
8. The software component information is obtained by analyzing hierarchical information included in information regarding software, according to any one of claims 1 to 7.
9. The information regarding software is information read from a storage area of another computer, according to claim 8.
10. An information processing method, wherein a processing unit generates history information indicating a change history of software component information based on the software component information and history timing information regarding one or more software components constituting predetermined software, and the history timing information is information indicating the timing of one or more points in time from the generation time of the software component information to the storage time of the history information.
11. A program, wherein a processing unit generates history information indicating a change history of software component information based on the software component information and history timing information regarding one or more software components constituting predetermined software, and the history timing information is information indicating the timing of one or more points in time from the generation time of the software component information to the storage time of the history information.
Citation Information
Patent Citations
Component version recommendation method and device, equipment and medium
CN116991469A
Software Bill of Materials Validation Systems and Methods
US20200201620A1
Automating trust in software upgrades
US20230208880A1