Risk management support device, risk management support method, and storage medium

The risk management support device visualizes the implementation status of security measures in communication paths by determining and outputting the number of measures per path, enhancing risk assessment and management in communication networks.

WO2025182068A1PCT designated stage Publication Date: 2025-09-04NEC CORP
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2024/007749
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-03-01
Publication Date
2025-09-04

AI Technical Summary

Technical Problem

Existing technologies fail to visualize the implementation status of security measures for each communication path in a communication network, making it difficult to assess and manage risks effectively.

Method used

A risk management support device and method that determines the number of security measures implemented in each communication path and outputs this information in a manner corresponding to a calculated risk value, using a countermeasure number determination unit and an output unit to visualize the security measures.

Benefits of technology

Enables visualization of the implementation status of security measures for each communication path, allowing for better risk assessment and management by representing the number of security measures implemented in devices along the path.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2024007749_04092025_PF_FP_ABST
    Figure JP2024007749_04092025_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure provides a risk management support device and the like capable of visually displaying the implementation status of security measures for each communication route from an intrusion point to an attack target. A risk management support device according to one aspect of the present disclosure comprises: a measure count determination means that uses information on a communication route from an intrusion point device to an attack target device in an information processing system including a plurality of devices and a communication network connecting the plurality of devices; and information on security measures implemented in the plurality of devices to determine the number of measures in the communication route; and an output means that outputs information on the communication route in a manner corresponding to a risk value calculated using the number of measures in the communication route.
Need to check novelty before this filing date? Find Prior Art

Description

Risk management support device, risk management support method, and storage medium

[0001] The present disclosure relates to a risk management support device, a risk management support method, and a storage medium.

[0002] Understanding risk is important in communication networks that connect multiple devices, such as information processing devices, managed by companies and other organizations, for example.

[0003] Patent Document 1 describes an attack route extraction system that extracts attack routes from the system entry point to the attack target in descending order of priority from configuration information of the system to be diagnosed and at least one of threat information, attack content information, and countermeasure possibility information.

[0004] International Publication No. 2023 / 089669

[0005] The technology of Patent Document 1 makes it possible to grasp attack routes from the system entry point to the attack target in order of priority, but the technology of Patent Document 1 does not make it possible to visualize the implementation status of security measures for each communication path that could be an attack route.

[0006] One of the objects of the present disclosure is to provide a risk management support device, a risk management support method, and a storage medium that can visualize the implementation status of security measures for each communication path from an entry point to an attack target.

[0007] A risk management support device according to one embodiment of the present disclosure comprises: a countermeasure number determination means for determining the number of countermeasures in a communication path between an entry device and an attack target device in an information processing system including a plurality of devices and a communication network connecting the plurality of devices, based on information about the communication path between the entry device and the attack target device and information about security measures implemented in the plurality of devices; and an output means for outputting information about the communication path in a manner corresponding to a risk value calculated using the number of countermeasures in the communication path.

[0008] A risk management support method according to one aspect of the present disclosure determines the number of security measures implemented in a communication path between an entry device and an attack target device in an information processing system including a plurality of devices and a communication network connecting the plurality of devices, based on information about the communication path between the entry device and the attack target device and information about the security measures implemented in the plurality of devices, and outputs the information about the communication path in a manner corresponding to a risk value determined using the number of security measures implemented in the communication path.

[0009] A storage medium according to one aspect of the present disclosure stores a program that causes a computer to execute a countermeasure number determination process that determines the number of countermeasures in a communication path between an entry device and an attack target device based on information about the communication path between an entry device and an attack target device and information about security measures implemented in the plurality of devices in an information processing system that includes a plurality of devices and a communication network connecting the plurality of devices, and an output process that outputs information about the communication path in a manner corresponding to a risk value determined using the number of countermeasures in the communication path.

[0010] The present disclosure has the effect of making it possible to visualize the implementation status of security measures for each communication path from the entry point to the target of attack.

[0011] FIG. 1 is a block diagram illustrating an example of the configuration of a risk management support device according to the present disclosure. FIG. 2 is a flowchart illustrating an example of the operation of a risk management support device according to the present disclosure. FIG. 3 is a block diagram illustrating an example of the configuration of a risk management support device according to the present disclosure. FIG. 4 is a diagram illustrating an example of output information according to the present disclosure. FIG. 5 is a diagram illustrating an example of output information according to the present disclosure. FIG. 6 is a diagram illustrating an example of output information according to the present disclosure. FIG. 7 is a flowchart illustrating an example of the operation of a risk management support device according to the present disclosure. FIG. 8 is a flowchart illustrating an example of the operation of a risk management support device according to the present disclosure. FIG. 9 is a block diagram illustrating an example of the configuration of a risk management support device according to the present disclosure. FIG. 10 is a diagram illustrating an example of the hardware configuration of a computer that can realize a risk management support device according to an embodiment of the present disclosure.

[0012] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the drawings.

[0013] First Embodiment First, a first embodiment of the present disclosure will be described in detail with reference to the drawings.

[0014] <Configuration> FIG. 1 is a block diagram showing an example of the configuration of a risk management support device according to the present disclosure.

[0015] The configuration of the risk management support device 10 according to the first embodiment of the present disclosure will be described below with reference to FIG.

[0016] In the example shown in FIG. 1, the risk management support device 10 includes a countermeasure number determination unit 150 and an output unit 180.

[0017] The countermeasure number determination unit 150 determines the number of countermeasures in a communication path from information on the communication path between an intrusion device and an attack target device in an information processing system including multiple devices and information on security countermeasures implemented in the multiple devices. The information processing system includes multiple devices and a communication network connecting the multiple devices. The intrusion device and the attack target device are included in the multiple devices.

[0018] The output unit 180 outputs information about the communication path in a format according to a risk value determined using the number of measures for the communication path.

[0019] <Countermeasure Number Determination Unit 150> The multiple devices include information processing devices including servers and information processing terminals. The multiple devices may also include devices for security measures. The devices for security measures are, for example, a firewall (FW) device that functions as a firewall, a unified threat management (UTM) device, etc. The unified threat management device is, for example, a device that has functions such as a firewall, antivirus, antispam, intrusion prevention, and content filtering. The unified threat management device may also have other functions such as a virtual private network (VPN). Hereinafter, a firewall device will also be simply referred to as a FW. Hereinafter, a unified threat management device will also be simply referred to as a UTM. In the present disclosure, a device for security measures will also be referred to as a countermeasure device.

[0020] The intrusion device is a device (e.g., an information processing device) that is designated in advance as a device that will be an entry point for an attack among a plurality of devices. The attack target device is a device (e.g., an information processing device) that is designated in advance as a device that will be a target of an attack among a plurality of devices. The intrusion device is a device different from the attack target device.

[0021] A communication path is a communication path that can be an attack path in an attack from an entry device to an attack target device. A communication path is expressed as a communication path that connects multiple devices, including an entry device and an attack target device, in series. Multiple communication paths may exist in a communication system. One device may be included in multiple communication paths. In the present disclosure, a communication path between an entry device and an attack target device in which the devices through which the communication path passes do not match is a different communication path. A communication path between an entry device and an attack target device in which the order of the devices through which the communication path passes does not match is a different communication path.

[0022] The number of security measures for a communication path is, for example, the number of information processing devices for which security measures have been taken and devices for security measures (i.e., countermeasure devices) in devices through which the communication path passes. In this embodiment, information processing devices for which security measures have been taken and devices for security measures (i.e., countermeasure devices) are also referred to as devices for which measures have been taken, i.e., countermeasure-completed devices. The number of security measures may be other numbers. Other examples of the number of security measures will be described later. Note that if the intrusion device and the attack target device are known, security measures are implemented in advance for the intrusion device and the attack target device. Therefore, the intrusion device and the attack target device do not need to be included in the devices through which the communication path passes. The intrusion device and the attack target device may be included in the devices through which the communication path passes. In this embodiment, it is described that the intrusion device and the attack target device are not included in the devices through which the communication path passes.

[0023] <Output unit 180> The risk value is, for example, the number of security measures for the communication path (i.e., the number of measures described above). In this case, the smaller the risk value of the communication path, the higher the risk of the communication path. The larger the risk value of the communication path, the lower the risk of the communication path. The risk value may be another value. Other examples of risk values ​​will be described later.

[0024] The information on the communication path is, for example, information on a device through which the communication path passes. The information on the communication path may be information on a device through which the communication path passes, generated as an image. In the present disclosure, information representing information on a device through which the communication path passes is referred to as output information. The output information is, for example, a screen (referred to as output screen) or an image (referred to as output image).

[0025] In the output information, the device information may be represented by, for example, a combination of a character string representing information that identifies the device and a graphic representing the device. The information representing the device is referred to as a device display.

[0026] The output information may include a device display of the intrusion device and a device display of the attack target device. The output information may not include a device display of a device that is not passed through the communication path.

[0027] In the output information, the information representing the communication path may be represented, for example, by a line connecting the device display of the intrusion device and the device display of the attack target device via the device displays of the devices through which the communication path passes, and the device displays of the devices through which the communication path passes. The display representing the communication path is referred to as a path display. Of the path displays, the line connecting the device displays is referred to as a connection display.

[0028] The mode according to the risk value is a mode that differs depending on the magnitude of the risk value. The mode is, for example, at least one of color, line thickness, line type, etc. For example, a mode may be defined in advance for a risk value (or a range of risk values). The output information may include a route display that is displayed in a mode that is defined for the risk value of the route represented by the route display.

[0029] In the path display, the device display of a countermeasure-completed device may be displayed in a different manner from the device display of a device that is not a countermeasure-completed device.

[0030] For example, if the risk value satisfies a predetermined standard (e.g., if the risk indicated by the risk value is lower than a predetermined risk), the device display and connection display mode of the countermeasured device in the route display may be displayed in a mode corresponding to the risk value, and the device display of the device that is not countermeasured may be displayed in a predetermined mode different from the mode corresponding to the risk value.

[0031] For example, if the risk value does not satisfy a predetermined standard (for example, if the risk indicated by the risk value is the same as or higher than the predetermined risk), the device display and connection display mode of the device that is not a countermeasured device may be displayed in a mode corresponding to the risk value. In this case, the device display of the countermeasured device may be displayed in a predetermined mode that is different from the mode corresponding to the risk value.

[0032] The above-mentioned predetermined criteria may be, for example, criteria that are defined as criteria that the risk value of a communication path must satisfy.

[0033] <Operation> Next, the operation of the risk management support device according to the first embodiment of the present disclosure will be described.

[0034] FIG. 2 is a flowchart illustrating an example of the operation of the risk management support device according to the present disclosure.

[0035] An example of the operation of the risk management support device 10 according to the first embodiment of the present disclosure will be described in detail below with reference to FIG.

[0036] 2, the countermeasure number determination unit 150 determines the number of countermeasures for the communication path between the entry device and the attack target device in the information processing system (step S11). Next, the output unit 180 outputs output information indicating information about the communication path in a manner corresponding to the risk value calculated using the number of countermeasures (step S12).

[0037] <Effect> The present disclosure has an effect of making it possible to visualize the implementation status of security measures for each communication path from an entry point to an attack target.

[0038] This is because the output unit 180 outputs information about a communication path in a manner corresponding to a risk value determined using the number of measures for the communication path. The risk value is determined using the number of measures (i.e., security measures) for the communication path. In other words, the implementation status of security measures is represented by, for example, the number of security measures implemented in devices through which the communication path passes.

[0039] <Example of Number of Countermeasures> In the above explanation, the number of countermeasures for a communication path is the number of countermeasure-implemented devices among the devices through which the communication path passes.

[0040] In the above description, the countermeasure-completed devices are countermeasure devices such as FW and UTM, and information processing devices in which security settings have been implemented. The information processing device in which security settings have been implemented is, for example, an information processing device in which a predetermined type of antivirus software is installed. The information processing device in which security settings have been implemented may also be, for example, an information processing device in which a predetermined type of antivirus software is installed and in which a firewall is enabled.

[0041] A countermeasure-completed device, which is a device for which countermeasures have been implemented, may be a device for which all of the security measures that have been predetermined for the type of device have been implemented, including countermeasure devices such as FW and UTM, and devices such as information processing devices.

[0042] Countermeasure-completed devices, which are devices for which countermeasures have been implemented, may be devices for which predetermined settings have been made among countermeasure devices such as FW and UTM, and information processing devices for which security countermeasures have been implemented. In this case, the number of countermeasures for a communication path may be the number of devices for which security countermeasure settings satisfy predetermined setting standards among countermeasure devices such as FW and UTM, and information processing devices for which security settings have been implemented, through which the communication path passes.

[0043] The setting criteria may be predetermined according to the type of device. The type of device may be, for example, an information processing device, a firewall, a UTM, etc. The setting criteria may be determined for each device. The setting criteria may be determined according to a device connected to the attack target side of the device.

[0044] For example, if the device is a FW or UTM, the setting criteria may include a setting that blocks communication of a specific protocol. For example, if the device is a FW or UTM, the setting criteria may include a setting that blocks communication from a specific device to another specific device. For example, if the device is a FW or UTM, the setting criteria may include a setting that blocks communication of a specific protocol from a specific device to another specific device. More specifically, for example, if the device is a FW or UTM, the setting criteria may include a setting that blocks RDP (Remote Desktop Protocol) communication from the intrusion device to the attack target device. For example, if the device is a FW or UTM, the setting criteria may include a setting that blocks RDP communication from the intrusion device to a device located closer to the attack target device than the FW or UTM device.

[0045] For example, if the device is an information processing device, the setting criteria may include, for example, that a predetermined type of antivirus software is installed and that the installed antivirus software and its settings are updated to be up to date. For example, if the device is an information processing device, the setting criteria may include, for example, that the firewall settings of the information processing device are set to predetermined settings.

[0046] The set criteria are not limited to these examples, and the set criteria do not have to include the above examples.

[0047] <Example of Risk Value> In the first embodiment of the present disclosure, the risk value is the number of countermeasures.

[0048] The risk value is not limited to the number of measures, but may be, for example, the ratio of the number of measures to the number of devices through which the communication path passes.

[0049] Second Embodiment Next, a second embodiment of the present disclosure will be described in detail with reference to the drawings.

[0050] FIG. 3 is a block diagram illustrating an example of the configuration of a risk management support device according to the present disclosure.

[0051] Hereinafter, the risk management support device 100 according to the second embodiment of the present disclosure will be described in detail with reference to FIG.

[0052] 3, the risk management support device 100 includes a configuration information receiving unit 110, a countermeasure information receiving unit 120, a path identifying unit 130, a correspondence identifying unit 140, a countermeasure number determining unit 150, a risk value calculating unit 160, an output information generating unit 170, an output unit 180, and a countermeasure identifying unit 190. In the example shown in FIG. 3, the two components connected by a line are examples of components that exchange data. However, the components that exchange data are not limited to components connected by a line.

[0053] <Configuration Information Receiving Unit 110> The configuration information receiving unit 110 receives information about the configuration of the information processing system, for example, from another information processing device that holds information about the configuration of the information processing system. The information about the configuration of the information processing system includes information about the devices included in the information processing system and information about the connections between the devices. The device information includes, for example, information that identifies the device and information about the type of device.

[0054] The information on the configuration of the information processing system also includes information indicating an entry point device and information indicating an attack target device among the devices included in the information processing system.

[0055] The information about the configuration of the information processing system may include information indicating whether the device is included in a boundary network (in other words, whether the device is connected to the boundary network) or whether the device is included in a business network (in other words, whether the device is connected to the business network). A business network refers to, for example, an internal communication network that is protected by security in an organizational network such as a company. A boundary network refers to, for example, a communication network that exists between the outside of the organizational network and the organization's business network.

[0056] <Countermeasure Information Receiving Unit 120> The countermeasure information receiving unit 120 receives countermeasure information including information on security countermeasures implemented in multiple devices included in the information processing system, for example, from another information processing device that stores the countermeasure information. The countermeasure information includes information on security countermeasures implemented in devices included in the information processing system for which security countermeasures have been implemented. The countermeasure information may include information on the settings of the security countermeasures implemented in multiple devices included in the information processing system. Specifically, the countermeasure information may include information on the settings of the security countermeasures implemented in devices included in the information processing system for which security countermeasures have been implemented. The countermeasure information may include information identifying each device included in the information processing system for which security countermeasures have been implemented (hereinafter referred to as device identification information), information on the security countermeasures being implemented, and information on the settings of the security countermeasures.

[0057] <Path Identification Unit 130> The path identification unit 130 uses information about the configuration of the information processing system to identify a communication path between the intrusion device and the attack target device that could be a path for an attack. Information about the communication path identified by the path identification unit 130 is referred to as path information. The path identification unit 130 may also use countermeasure information (e.g., firewall setting information) to identify the communication path. The method by which the path identification unit 130 identifies the communication path may be one of various existing methods. The path identification unit 130 may identify the communication path between the intrusion device and the attack target device using the method described in Reference 1 or Reference 2 below.

[0058] (Reference 1) International Publication No. 2023 / 175878

[0059] (Reference 2) Ryo Mizushima, Maki Inokuchi, Tomohiko Yagyu, "Countermeasure Planning Method Considering Multi-Layer Defense Against Cyber ​​Attacks," 2023 Symposium on Cryptography and Information Security, Fukuoka, Japan, January 24-27, 2023. <Correspondence Identification Unit 140> The correspondence identification unit 140 associates devices through which the communication path passes with devices whose device identification information is included in the received countermeasure information. Then, the correspondence identification unit 140 associates devices through which the communication path passes with the countermeasure information for those devices included in the received countermeasure information.

[0060] <Countermeasures determination unit 150> The countermeasures number determination unit 150 determines the number of countermeasures for each communication path from the route information, countermeasure information, and information that associates the devices through which the communication path passes with the countermeasure information for those devices contained in the received countermeasure information.

[0061] The countermeasure number determination unit 150, for example, identifies countermeasure devices and information processing devices on which security measures have been implemented, among the devices included in the information processing system, as countermeasure-implemented devices, which are devices on which countermeasures have been implemented. For example, the countermeasure number determination unit 150 may identify, among the countermeasure devices and information processing devices on which security measures have been implemented, included in the information processing system, devices whose security measure settings satisfy the above-mentioned predetermined setting criteria, as countermeasure-implemented devices.

[0062] The countermeasure number determining unit 150 determines, for each communication path, the number of countermeasure-taken devices through which the communication path passes as the number of countermeasures taken for the communication path.

[0063] <Risk value calculation unit 160> The risk value calculation unit 160 calculates (in other words, determines) a risk value for each communication path, which is a value indicating the level of risk that the target device will be attacked via the communication path from the entry device, using the number of countermeasures.

[0064] The risk value calculation unit 160 may use, for example, the number of countermeasures for a communication path as the risk value.

[0065] The risk value calculation unit 160 may determine, for example, the ratio of the number of measures for a communication path to the number of devices through which the communication path passes as the risk value of the communication path.

[0066] <Output Information Generator 170> The output information generator 170 generates output information including a path display showing a communication path in a manner according to the level of risk indicated by the risk value of the communication path. The path display includes device displays showing devices through which the communication path passes. The path display also includes lines showing connections between devices connected by the communication path.

[0067] The device representation may be shown in the same manner as the path representation lines of the communication paths that pass through the device that the device representation represents.

[0068] The device display may be displayed in a manner that corresponds to the level of risk indicated by the risk value of the communication path passing through the device indicated by the device display and whether the device is a countermeasure-completed device, that is, a device for which countermeasures have been taken.

[0069] For example, among the devices through which the communication path passes, countermeasure-completed devices and non-countermeasure-completed devices may be represented in different ways.

[0070] As described above, specifically, for example, when the risk value satisfies a predetermined standard (for example, when the risk indicated by the risk value is lower than a predetermined risk), the device display and connection display mode of the countermeasured device in the route display may be displayed in a mode corresponding to the risk value, and the device display of the device that is not countermeasured may be displayed in a predetermined mode different from the mode corresponding to the risk value.

[0071] For example, if the risk value does not satisfy a predetermined standard (for example, if the risk indicated by the risk value is the same as or higher than the predetermined risk), the device display and connection display mode of the device that is not a countermeasured device may be displayed in a mode corresponding to the risk value. In this case, the device display of the countermeasured device may be displayed in a predetermined mode that is different from the mode corresponding to the risk value.

[0072] Here, among countermeasure devices and information processing devices in which countermeasures have been implemented, devices whose settings for the countermeasures meet predetermined standards are referred to as countermeasure-completed devices. Furthermore, devices (e.g., information processing devices) for which countermeasures have not been implemented are referred to as uncountermeasured devices. Among countermeasure devices and information processing devices in which countermeasures have been implemented, devices whose settings for the countermeasures do not meet predetermined standards are referred to as incompletely configured devices. The output information generation unit 170 may generate output information including device indications in different forms for the incompletely countermeasured devices, incompletely configured devices, and countermeasure-completed devices.

[0073] Furthermore, the output information generation unit 170 may generate output information including a display indicating the range of the business network and a display indicating the range of the boundary network from the business network information and boundary network information included in the information on the configuration of the information processing system. The display indicating the range of the business network may be represented by a line surrounding the device display of the device included in the business network, or a graphic including the device display of the device included in the business network. The display indicating the range of the boundary network may be represented by a line surrounding the device display of the device included in the boundary network, or a graphic including the device display of the device included in the business network. If a device exists that is included in both the boundary network and the business network, the device display of that device may be included in both the display indicating the range of the boundary network and the display indicating the range of the business network. If a device exists that is included in both the boundary network and the business network, a portion of the device display of that device may be included in the display indicating the range of the boundary network, and another portion of the device display may be included in the display indicating the range of the business network.

[0074] 4, 5, and 6 are diagrams showing examples of output information according to the present disclosure.

[0075] In the examples shown in Figures 4, 5, and 5A, the information processing system includes terminal A, terminal B, terminal C, FW, UTM, and server A. In these examples, terminal A is an intrusion device. Server A is an attack target device. Terminals B and C are devices for which countermeasures have not been implemented. FW and UTM are countermeasure devices. It is assumed that the FW has a setting defect in that it is not set to not allow RDP from terminal A to server A to pass (i.e., it is set to allow RDP from terminal A to server A to pass).

[0076] In the example shown in FIG. 4 , the countermeasure-completed devices are the countermeasure device (FW and UTM) and the information processing device for which countermeasures have been implemented (not present in the example shown in FIG. 4 ). In FIG. 4 , route displays are drawn for a communication route via terminal B (denoted as route 1), a communication route via the FW and UTM (denoted as route 2), and a communication route via the FW, terminal C, and UTM (denoted as route 3). If the risk value is the number of measures, the risk value for route 1 is 0, and the risk values ​​for routes 2 and 3 are 2. If the risk value is the number of measures relative to the number of devices the communication route passes through, the risk value for route 1 is 0, the risk value for route 2 is 1 (= 2 / 2), and the risk value for route 3 is 2 / 3. If the risk value criterion is greater than 0, the risk value for route 1 does not meet the criterion. The risk values ​​for routes 2 and 3 meet the criterion. For example, if the aspect according to the risk value is a different color depending on whether the risk value meets the criterion, the route display for route 1 is drawn in a color (e.g., red) different from the color (e.g., green) of the route displays for routes 2 and 3. Furthermore, a device (e.g., terminal C) on which no countermeasures have been implemented and which is passed through a route whose risk value meets the criteria may be depicted in a color (e.g., black) different from the color of the line of route C.

[0077] 5, the risk value-dependent aspects are represented by different types of lines depending on whether the risk value satisfies the criteria. Communication paths whose risk values ​​satisfy the criteria are represented by dashed lines. Communication paths whose risk values ​​do not satisfy the criteria are represented by solid lines.

[0078] 6, the risk value-dependent aspects are represented by lines of different thicknesses depending on whether the risk value satisfies the criteria. A communication path whose risk value satisfies the criteria is represented by a thin line. A communication path whose risk value does not satisfy the criteria is represented by a thick line.

[0079] The manner in which the risk value is determined is not limited to these examples.

[0080] Furthermore, for example, the device display of a device with a setting error (for example, FW) may be drawn in a different manner (for example, a different color) than the device display of a device with no setting error (for example, UTM).

[0081] Furthermore, for example, the path identification unit 130 may identify a communication path caused by a defect in the device settings (i.e., a path that could be a route of attack). In this case, the path identification unit 130 identifies, for example, a communication path that does not exist when there is no defect in the device settings (when a predetermined setting is set) but is identified in the device settings state as a communication path caused by a defect in the device settings. In the example shown in FIG. 4 etc., the communication path identified in the device settings state is, for example, path 2 that passes through the FW and the UTM, which is created when the FW is set to allow RDP from terminal A to server A to pass.

[0082] The output information generation unit 170 may generate output information that includes a route display of a communication route that has occurred due to an incomplete device configuration in a manner different from the route display of a route whose risk value meets the standard, even if the risk value of the communication route meets the standard.

[0083] <Output unit 180> The output unit 180 outputs the generated output information to an output device such as a display device of the risk management support device 100. The output unit 180 may output the generated output information to, for example, another information processing device communicatively connected to the risk management support device 100.

[0084] <Operation> Next, an example of the operation of the risk management support device 100 according to the second embodiment of the present disclosure will be described.

[0085] 7 and 8 are flowcharts showing an example of the operation of the risk management support device according to the present disclosure.

[0086] An example of the operation of the risk management support device 100 according to the second embodiment of the present disclosure will be described in detail below with reference to FIGS. 7 and 8. FIG.

[0087] 7, first, the configuration information receiving unit 110 receives information on the configuration of the information processing system (step S101). The countermeasure information receiving unit 120 receives information on security countermeasures for devices included in the information processing system (step S102). The path identifying unit 130 identifies a communication path from an entry device of the information processing system to an attack target device (step S103). The correspondence identifying unit 140 identifies a correspondence between devices along the communication path and devices of the countermeasure information (step S104).

[0088] Then, the countermeasure number determination unit 150 determines the number of countermeasures for each communication path (step S105).The risk management support device 100 then performs the operation of step S106 in FIG.

[0089] 8, the risk value calculation unit 160 calculates a risk value for each communication path from the number of measures (step S106). The output information generation unit 170 generates output information from the communication path information and the communication path risk value (step S107). The output unit 180 then outputs the output information (step S108).

[0090] <Effects> The present disclosure has the same effects as the first embodiment, for the same reasons as those for the effects of the first embodiment.

[0091] <First Modification of Second Embodiment> Next, a first modification of the second embodiment of the present disclosure will be described.

[0092] FIG. 9 is a block diagram illustrating an example of the configuration of a risk management support device according to the present disclosure.

[0093] Hereinafter, the risk management support device 101 according to the first modified example of the second embodiment of the present disclosure will be described in detail with reference to FIG.

[0094] The risk management support device 101 of this modification includes a measure identification unit 190 in addition to all of the components of the risk management support device 100 of the second embodiment. The risk management support device 101 of this modification has the same functions as the functions of the risk management support device 100 of the second embodiment. The risk management support device 101 of this modification performs the same operations as the risk management support device 100 of the second embodiment. The following mainly describes the differences between this modification and the second embodiment.

[0095] <Countermeasure Identification Unit 190> The countermeasure identification unit 190 may generate countermeasure recommendation information that includes information about devices that are not countermeasured devices (e.g., information that identifies the devices) in descending order of risk indicated by the risk values ​​of the communication paths that pass through the devices. A device that is not a countermeasured device may, for example, be a device among multiple devices that is not a countermeasure device or an information processing device for which countermeasures have been implemented (e.g., an information processing device for which countermeasures have not been implemented). A device that is not a countermeasured device may be a device among countermeasure devices and information processing devices for which countermeasures have been implemented, whose settings for countermeasures do not satisfy a predetermined standard, and an information processing device for which countermeasures have not been implemented.

[0096] <Output Unit 180> The output unit 180 outputs recommended countermeasure information.

[0097] Second Modification of Second Embodiment Next, a second modification of the second embodiment of the present disclosure will be described.

[0098] The configuration of the risk management support device 101 of this modified example is the same as the configuration of the risk management support device 101 of the second modified example of the second embodiment of the present disclosure.

[0099] The risk management support device 101 of this modification includes a measure identification unit 190 in addition to all of the components of the risk management support device 100 of the second embodiment. The risk management support device 101 of this modification has the same functions as the functions of the risk management support device 100 of the second embodiment. The risk management support device 101 of this modification performs the same operations as the risk management support device 100 of the second embodiment. The following mainly describes the differences between this modification and the second embodiment.

[0100] <Countermeasure information receiving unit 120> In this modified example, the countermeasure information receiving unit 120 receives countermeasure information including information on predetermined countermeasures (for example, countermeasures that are requested to be implemented by the administrator of the information processing system) for each type of device.

[0101] The countermeasure information may include information on settings for countermeasures that satisfy predetermined criteria for each type of device. The settings for countermeasures that satisfy the predetermined criteria are settings that are determined in advance (for example, by an administrator of the information processing system) for each type of device. The settings for countermeasures that satisfy the predetermined criteria may also be settings that are determined in advance (for example, by an administrator of the information processing system) for each device.

[0102] <Countermeasure Identification Unit 190> The countermeasure identification unit 190 identifies countermeasures that need to be implemented for devices for which countermeasures have not been implemented, from countermeasure information including information on implementable countermeasures for each device type. The countermeasure identification unit 190 generates countermeasure information including information on countermeasures that need to be implemented for devices for which countermeasures have not been implemented. A device for which countermeasures have not been implemented is a device for which at least some of the countermeasures that have been predetermined for that device type have not been implemented (in other words, a device for which the implementation of countermeasures is incomplete). A countermeasure that needs to be implemented for a device for which countermeasures have not been implemented is a countermeasure that has been predetermined for that device type but has not been implemented for the device for which countermeasures have not been implemented.

[0103] The countermeasure identification unit 190, for example, identifies the type of device for which countermeasures have not been implemented (i.e., device for which countermeasures have not been fully implemented) among the devices included in the information processing system. The countermeasure identification unit 190 identifies, from the countermeasure information, countermeasures that have been determined in advance for the identified type of device (e.g., countermeasures that are required to be implemented). The countermeasure identification unit 190 identifies, from the identified countermeasures, countermeasures that have not been implemented in the device for which countermeasures have not been implemented as countermeasures that are required to be implemented in that device. The countermeasure identification unit 190 identifies countermeasures that are required to be implemented for each of the devices for which countermeasures have not been implemented.

[0104] The countermeasure identification unit 190 generates countermeasure recommendation information that includes information identifying a device for which countermeasures have not been implemented, information associated with the information identifying the device that indicates the countermeasures that are required to be implemented in the device, and information indicating the risk indicated by the risk value of the communication path through the device in order of increasing risk.

[0105] The countermeasure identification unit 190 may identify, for each device type, from countermeasure information including information on countermeasure settings that satisfy a predetermined standard, a setting change to change the settings of a device whose countermeasure settings do not satisfy the predetermined standard so that the settings satisfy the predetermined standard. A device whose countermeasure settings do not satisfy the predetermined standard is a device in which at least a portion of the countermeasure settings that are predetermined for that device type are not set. A device whose countermeasure settings do not satisfy the predetermined standard may also be a device in which at least a portion of the countermeasure settings that are predetermined for that device are not set.

[0106] Specifically, the countermeasure identification unit 190 identifies, as the above-mentioned change in countermeasure, a setting that has not been set among the countermeasure settings that are predetermined for the type of device of a device whose countermeasure settings do not satisfy a predetermined standard. The countermeasure identification unit 190 may also identify, as the above-mentioned change in countermeasure, a setting that has not been set among the countermeasure settings that are predetermined for the device of a device whose countermeasure settings do not satisfy a predetermined standard. The countermeasure identification unit 190 generates countermeasure recommendation information that includes information on the identified change in countermeasures for the devices in order of the level of risk indicated by the risk value of the communication path through the device.

[0107] The countermeasure identification unit 190 may generate countermeasure recommendation information including information indicating identified countermeasures that need to be implemented for devices through which the communication paths pass, and information on identified setting changes, in descending order of the risk value of the communication paths.The countermeasure identification unit 190 may generate countermeasure recommendation information including information indicating identified countermeasures that need to be implemented for devices through which the communication paths pass, and information on identified setting changes, in descending order of the risk value of the communication paths, for communication paths whose risk values ​​do not satisfy a predetermined standard.

[0108] <Output Unit 180> The output unit 180 outputs recommended countermeasure information.

[0109] <Third Modification of Second Embodiment> For each countermeasure implemented in a device, an element risk value may be set according to the magnitude of the threat if the countermeasure is not implemented. The risk value calculation unit 160 may determine, for example, a statistical value such as the sum or maximum value of the element risk values ​​of countermeasures that have not been implemented among the countermeasures previously defined for the device (measures that are requested to be implemented, for example, by the administrator of the information processing system), as the device countermeasure risk value, which is the risk value due to the countermeasures for the device. The risk value calculation unit 160 may further determine, as the risk value of the communication path, a statistical value such as the sum, maximum value, or minimum value of the device countermeasure risk values ​​of the devices through which the communication path passes.

[0110] For settings configured in a device, an element risk value may be set according to the magnitude of the threat if the settings are not configured. The risk value calculation unit 160 may determine, for example, a statistical value such as the sum or maximum value of element risk values ​​of settings that are not configured among measures predefined for the device (settings that are requested to be configured, for example, by an administrator of the information processing system), as the device setting risk value, which is a risk value due to the device settings. The risk value calculation unit 160 may determine, as the device risk value representing the degree of attack risk of the device, the sum of the device countermeasure risk value and the device setting risk value of the device. The risk value calculation unit 160 may determine, as the risk value of the communication path, a statistical value such as the sum, maximum value, or minimum value of the device risk values ​​of devices through which the communication path passes.

[0111] <Fourth Modification of Second Embodiment> The configuration information receiving unit 110 may receive information on communication paths of the information processing system that has been generated in advance. In this case, the path identifying unit 130 may not be present.

[0112] <Other Embodiments> A risk management support device according to an embodiment of the present disclosure can be realized by a computer including a memory into which a program read from a storage medium is loaded and a processor that executes the program. A risk management support device according to an embodiment of the present disclosure can be realized by dedicated hardware. A risk management support device according to an embodiment of the present disclosure can be realized by a combination of the above-mentioned computer and dedicated hardware.

[0113] FIG. 10 is a diagram illustrating an example of the hardware configuration of a computer 1000 capable of implementing a risk management support device according to an embodiment of the present disclosure. In the example illustrated in FIG. 10 , the computer 1000 includes a processor 1001, a memory 1002, a storage device 1003, and an I / O (Input / Output) interface 1004. The computer 1000 can also access a storage medium 1005. The memory 1002 and the storage device 1003 are, for example, storage devices such as RAM (Random Access Memory) and a hard disk. The storage medium 1005 is, for example, a storage device such as RAM or a hard disk, a ROM (Read Only Memory), or a portable storage medium. The storage device 1003 may also be the storage medium 1005. The processor 1001 can read and write data and programs from and to the memory 1002 and the storage device 1003. The processor 1001 can access, for example, other information devices via the I / O interface 1004. The processor 1001 can access a storage medium 1005. The storage medium 1005 stores a program that causes the computer 1000 to operate as a risk management support device according to an embodiment of the present disclosure.

[0114] The processor 1001 loads a program stored in the storage medium 1005, which causes the computer 1000 to operate as a risk management support device according to an embodiment of the present disclosure, into the memory 1002. Then, the processor 1001 executes the program loaded into the memory 1002, causing the computer 1000 to operate as the risk management support device according to an embodiment of the present disclosure.

[0115] The configuration information receiving unit 110, the countermeasure information receiving unit 120, the path identifying unit 130, the correspondence identifying unit 140, the number of countermeasures determining unit 150, the risk value calculating unit 160, the output information generating unit 170, the output unit 180, and the countermeasure identifying unit 190 can be realized, for example, by a processor 1001 that executes a program loaded into memory 1002. Some or all of the configuration information receiving unit 110, the countermeasure information receiving unit 120, the path identifying unit 130, the correspondence identifying unit 140, the number of countermeasures determining unit 150, the risk value calculating unit 160, the output information generating unit 170, the output unit 180, and the countermeasure identifying unit 190 can be realized by dedicated circuits.

[0116] Furthermore, some or all of the above-described embodiments can be described as, but are not limited to, the following supplementary notes.

[0117] (Supplementary Note 1) A risk management support device comprising: a countermeasure number determination means for determining the number of countermeasures in a communication path between an entry device and an attack target device from information on the communication path between an entry device and an attack target device and information on security countermeasures implemented in the plurality of devices in an information processing system including a plurality of devices and a communication network connecting the plurality of devices; and an output means for outputting information on the communication path in a manner according to a risk value determined using the number of countermeasures in the communication path.

[0118] (Supplementary Note 2) The risk management support device according to Supplementary Note 1, further comprising a risk value calculation means for calculating the ratio of the number of measures for the communication path to the number of devices through which the communication path passes as the risk value of the communication path.

[0119] (Supplementary Note 3) A risk management support device as described in Supplementary Note 1 or 2, comprising: an output information generation means for generating output information including a route display showing the communication route, the route display including a device display showing the device through which the communication route passes and a line showing the connection by the communication route between the devices to which the communication route connects, the route display being expressed in a manner corresponding to the level of risk indicated by the risk value of the communication route; wherein the output means outputs the output information as information about the communication route.

[0120] (Appendix 4) The risk management support device described in Appendix 3, wherein the output information generation means generates the output information including the device display expressed in a manner depending on the level of risk indicated by the risk value of the communication path passing through the device indicated by the device display and whether the device is a countermeasure-completed device, that is, a device for which the countermeasure has been completed.

[0121] (Supplementary Note 5) The risk management support device described in Supplementary Note 4, wherein the countermeasure number determination means determines that, among the plurality of devices, a countermeasure device that is the device for the countermeasure and an information processing device on which the countermeasure is implemented are the countermeasured devices, and the output information generation means generates the output information that includes, among the plurality of devices through which the communication path passes, the countermeasured devices and the devices that are not the countermeasured devices in different forms.

[0122] (Supplementary Note 6) The risk management support device according to Supplementary Note 4, wherein the countermeasure number determination means identifies, among the plurality of devices, information processing devices on which the countermeasure has not been implemented, countermeasure devices that are the devices for the countermeasure, and information processing devices on which the countermeasure has been implemented, and identifies, among the countermeasure devices that are the devices for the countermeasure and the information processing devices on which the countermeasure has been implemented, devices whose settings for the countermeasure satisfy a predetermined standard and devices whose settings for the countermeasure do not satisfy the predetermined standard; and the output information generation means generates the output information including the device display that shows, in different modes, the information processing devices on which the countermeasure has not been implemented, the devices among the countermeasure devices and the information processing devices on which the countermeasure has been implemented, whose settings for the countermeasure satisfy the predetermined standard, and the devices among the countermeasure devices and the information processing devices on which the countermeasure has been implemented, whose settings for the countermeasure satisfy the predetermined standard.

[0123] (Supplementary Note 7) The risk management support device described in Supplementary Note 1 or 2, wherein the countermeasure number determination means identifies, from the plurality of devices, devices for which the countermeasures have not been implemented and devices for which the settings for the countermeasures do not meet a predetermined standard, and the output means outputs information about the devices for which the countermeasures have not been implemented and information about the devices for which the settings for the countermeasures do not meet a predetermined standard, in descending order of risk indicated by the risk value of the communication path passing through the devices.

[0124] (Supplementary Note 8) The risk management support device according to Supplementary Note 7 further comprises a countermeasure identification means for identifying, for each type of device, the countermeasure that needs to be implemented for the device on which the countermeasure has not been implemented, from countermeasure information including information on the countermeasure that can be implemented, and the output means outputs the information on the countermeasure that needs to be implemented for the device on which the countermeasure has not been implemented.

[0125] (Supplementary Note 9) The risk management support device described in Supplementary Note 8, wherein the countermeasure identification means identifies, for each type of device, from countermeasure information including information on the settings for the countermeasures that satisfy the specified criteria, the setting change for the device where the setting for the countermeasure does not satisfy the specified criteria, to change the setting so that the setting satisfies the specified criteria, and the output means outputs the setting change for the device where the setting for the countermeasure does not satisfy the specified criteria.

[0126] (Supplementary Note 10) The risk management support device according to Supplementary Note 1 or 2, wherein the aspect is at least one of line thickness, line color, and line shape.

[0127] (Appendix 11) The risk management support device described in Appendix 1 or 2, wherein the countermeasure number determination means determines, from the information of the plurality of devices, the number of countermeasure-completed devices, which are devices through which the communication path passes and for which the countermeasure has been completed, as the number of countermeasures.

[0128] (Appendix 12) The risk management support device described in Appendix 11, wherein the countermeasure number determination means determines, from the information of the plurality of devices, the number of countermeasure devices that are the devices for the countermeasure and the information processing devices in which the countermeasure is implemented, among the devices through which the communication path passes, as the number of countermeasure-implemented devices.

[0129] (Appendix 13) The risk management support device described in Appendix 11, wherein the countermeasure number determination means determines, from the information of the plurality of devices, the number of devices through which the communication path passes, including countermeasure devices that are devices for the countermeasure and information processing devices in which the countermeasure is implemented, and the number of devices whose settings for the countermeasure meet a predetermined standard, as the number of countermeasure-implemented devices.

[0130] (Supplementary Note 14) A risk management support method in an information processing system including a plurality of devices and a communication network connecting the plurality of devices, comprising: determining the number of security measures implemented in the communication path from information on the communication path between an entry device and an attack target device and information on the security measures implemented in the plurality of devices; and outputting the information on the communication path in a manner according to a risk value determined using the number of security measures implemented in the communication path.

[0131] (Supplementary Note 15) The risk management support method according to Supplementary Note 14, wherein a ratio of the number of measures for the communication path to the number of devices through which the communication path passes is calculated as the risk value of the communication path.

[0132] (Appendix 16) A risk management support method as described in Appendix 14 or 15, which generates output information including a route display showing the communication route, the route display including a device display showing the devices through which the communication route passes and a line showing the connection by the communication route between the devices to which the communication route connects, the route display being expressed in a manner corresponding to the level of risk indicated by the risk value of the communication route, and outputs the output information as information about the communication route.

[0133] (Appendix 17) A risk management support method as described in Appendix 16, which generates output information including a device display expressed in a manner depending on the level of risk indicated by the risk value of the communication path passing through the device indicated by the device display and whether the device is a countermeasure-completed device, that is, a device for which the countermeasure has been completed.

[0134] (Supplementary Note 18) A risk management support method as described in Supplementary Note 17, which determines, among the plurality of devices, a countermeasure device that is the device for the countermeasure and an information processing device on which the countermeasure is implemented as the countermeasured device, and generates the output information that includes, among the plurality of devices through which the communication path passes, the countermeasured device and the device that is not the countermeasured device in different forms.

[0135] (Supplementary Note 19) A risk management support method according to Supplementary Note 17, comprising: identifying, among the plurality of devices, an information processing device on which the countermeasure has not been implemented, a countermeasure device that is the device for the countermeasure, and an information processing device on which the countermeasure has been implemented; identifying, among the countermeasure device that is the device for the countermeasure and the information processing device on which the countermeasure has been implemented, a device whose setting for the countermeasure satisfies a predetermined standard and a device whose setting for the countermeasure does not satisfy the predetermined standard; and generating the output information including the device display that shows, in different modes, the information processing device on which the countermeasure has not been implemented, the device among the countermeasure device and the information processing device on which the countermeasure has been implemented, whose setting for the countermeasure does not satisfy the predetermined standard, and the device among the countermeasure device and the information processing device on which the countermeasure has been implemented, whose setting for the countermeasure satisfies the predetermined standard.

[0136] (Supplementary Note 20) A risk management support method according to Supplementary Note 14 or 15, which identifies from the plurality of devices devices for which the countermeasures have not been implemented and devices for which the settings for the countermeasures do not meet a predetermined standard, and outputs information on the devices for which the countermeasures have not been implemented and information on the devices for which the settings for the countermeasures do not meet a predetermined standard in descending order of risk indicated by the risk value of the communication path passing through the devices.

[0137] (Supplementary Note 21) A risk management support method as described in Supplementary Note 20, which identifies, for each type of device, measures that need to be implemented for devices for which the measures have not been implemented from measures information including information on measures that can be implemented, and outputs information on the measures that need to be implemented for devices for which the measures have not been implemented.

[0138] (Supplementary Note 22) A risk management support method according to Supplementary Note 21, which identifies, for each type of device, a setting change for changing the settings of the device for which the settings for the countermeasures do not satisfy the specified criteria from countermeasure information including information on the settings for the countermeasures that satisfy the specified criteria, so that the settings satisfy the specified criteria; and outputs the setting change for the device for which the settings for the countermeasures do not satisfy the specified criteria.

[0139] (Supplementary Note 23) The risk management support method according to Supplementary Note 14 or 15, wherein the aspect is at least one of line thickness, line color, and line shape.

[0140] (Appendix 24) A risk management support method as described in Appendix 14 or 15, in which the number of countermeasures is determined as the number of countermeasure-completed devices, which are devices through which the communication path passes among the plurality of devices and for which the countermeasures have been completed, from the information of the plurality of devices.

[0141] (Appendix 25) A risk management support method as described in Appendix 24, in which, from the information of the plurality of devices, the number of countermeasure devices that are the devices for the countermeasure and the information processing devices on which the countermeasure is implemented are determined as the number of countermeasure-implemented devices among the plurality of devices through which the communication path passes,

[0142] (Appendix 26) A risk management support method as described in Appendix 24, in which, from the information of the plurality of devices, among the devices through which the communication path passes, the number of devices whose settings for the countermeasures meet a predetermined standard, including countermeasure devices that are the devices for the countermeasures and information processing devices in which the countermeasures are implemented, is defined as the number of countermeasure-implemented devices.

[0143] (Supplementary Note 27) A storage medium storing a program that causes a computer to execute the following steps: a countermeasure number determination process that determines the number of countermeasures in a communication path between an entry device and an attack target device based on information about the communication path between an entry device and an attack target device and information about security countermeasures implemented in the plurality of devices in an information processing system including a plurality of devices and a communication network connecting the plurality of devices; and an output process that outputs information about the communication path in a manner according to a risk value determined using the number of countermeasures in the communication path.

[0144] (Supplementary Note 28) The storage medium according to Supplementary Note 27, wherein the program further causes a computer to execute a risk value calculation process that calculates the ratio of the number of measures for the communication path to the number of devices through which the communication path passes as the risk value of the communication path.

[0145] (Appendix 29) The program causes a computer to execute an output information generation process to generate output information including a route display showing the communication route, the route display including a device display showing devices through which the communication route passes and a line showing a connection by the communication route between the devices to which the communication route connects, the route display being expressed in a manner corresponding to the level of risk indicated by the risk value of the communication route, and the output process outputs the output information as information about the communication route.

[0146] (Appendix 30) The storage medium described in Appendix 29, wherein the output information generation process generates the output information including the device display expressed in a manner depending on the level of risk indicated by the risk value of the communication path passing through the device indicated by the device display and whether the device is a countermeasure-completed device, that is, a device for which the countermeasure has been completed.

[0147] (Supplementary Note 31) The storage medium described in Supplementary Note 30, wherein the countermeasure number determination process determines, among the plurality of devices, a countermeasure device that is the device for the countermeasure and an information processing device on which the countermeasure is implemented, as the countermeasured devices, and the output information generation process generates the output information that includes, among the plurality of devices through which the communication path passes, the countermeasured devices and the devices that are not the countermeasured devices in different forms.

[0148] (Supplementary Note 32) The storage medium according to Supplementary Note 30, wherein the countermeasure number determination process identifies, among the plurality of devices, an information processing device on which the countermeasure has not been implemented, a countermeasure device that is the device for the countermeasure, and an information processing device on which the countermeasure has been implemented, and identifies, among the countermeasure device that is the device for the countermeasure and the information processing device on which the countermeasure has been implemented, a device whose setting for the countermeasure satisfies a predetermined standard and a device whose setting for the countermeasure does not satisfy the predetermined standard; and the output information generation process generates the output information including the device display that shows, in different modes, the information processing device on which the countermeasure has not been implemented, the device among the countermeasure device and the information processing device on which the countermeasure has been implemented, whose setting for the countermeasure does not satisfy the predetermined standard, and the device among the countermeasure device and the information processing device on which the countermeasure has been implemented, whose setting for the countermeasure satisfies the predetermined standard. (Supplementary Note 32) The storage medium according to Supplementary Note 30, wherein the countermeasure number determination process identifies, among the plurality of devices, an information processing device on which the countermeasure has not been implemented, a countermeasure device that is the device for the countermeasure, and an information processing device on which the countermeasure has been implemented,

[0149] (Supplementary Note 33) The storage medium described in Supplementary Note 27 or 28, wherein the countermeasure number determination process identifies, from the plurality of devices, devices for which the countermeasures have not been implemented and devices for which the settings for the countermeasures do not meet a predetermined standard, and the output process outputs information about the devices for which the countermeasures have not been implemented and information about the devices for which the settings for the countermeasures do not meet a predetermined standard, in descending order of risk indicated by the risk value of the communication path passing through the devices.

[0150] (Supplementary Note 34) The program further causes the computer to execute a countermeasure identification process for identifying, for each type of device, the countermeasure that needs to be implemented for the device on which the countermeasure has not been implemented, from countermeasure information including information on the countermeasure that can be implemented, and the output process outputs the information on the countermeasure that needs to be implemented for the device on which the countermeasure has not been implemented. The storage medium described in Supplementary Note 33.

[0151] (Supplementary Note 35) The storage medium described in Supplementary Note 34, wherein the countermeasure identification process identifies, for each type of device, from countermeasure information including information on the settings for the countermeasures that satisfy the predetermined criteria, a setting change for changing the settings of the device where the settings for the countermeasures do not satisfy the predetermined criteria so that the settings satisfy the predetermined criteria; and the output process outputs the setting change for the device where the settings for the countermeasures do not satisfy the predetermined criteria.

[0152] (Supplementary Note 36) The storage medium according to Supplementary Note 27 or 28, wherein the aspect is at least one of line thickness, line color, and line shape.

[0153] (Appendix 37) The storage medium described in Appendix 27 or 28, wherein the countermeasure number determination process determines, from information on the plurality of devices, the number of countermeasure-completed devices, which are devices through which the communication path passes and for which the countermeasure has been completed, as the number of countermeasures.

[0154] (Appendix 38) The storage medium described in Appendix 37, wherein the countermeasure number determination process determines, from the information of the plurality of devices, the number of countermeasure devices that are the devices for the countermeasure and the information processing devices in which the countermeasure is implemented, among the devices through which the communication path passes, as the number of countermeasure-implemented devices.

[0155] (Appendix 39) The storage medium described in Appendix 37, in which the process of determining the number of countermeasures determines, from the information of the plurality of devices, the number of devices among the devices through which the communication path passes, including countermeasure devices that are devices for the countermeasures and information processing devices in which the countermeasures are implemented, and the number of devices whose settings for the countermeasures meet a predetermined standard, as the number of countermeasure-implemented devices.

[0156] Although the present disclosure has been described above with reference to the embodiments, the present disclosure is not limited to the above embodiments. Various modifications that can be understood by those skilled in the art can be made to the configuration and details of the present disclosure within the scope of the present disclosure.

[0157] 10 Risk management support device 100 Risk management support device 101 Risk management support device 110 Configuration information receiving unit 120 Countermeasure information receiving unit 130 Path identification unit 140 Response identification unit 150 Number of countermeasures determination unit 160 Risk value calculation unit 170 Output information generation unit 180 Output unit 190 Countermeasure identification unit 1000 Computer 1001 Processor 1002 Memory 1003 Storage device 1004 I / O interface 1005 Storage medium

Claims

1. A risk management support device comprising: a countermeasure number determination means for determining the number of security measures implemented in a communication path between an entry device and an attack target device in an information processing system including a plurality of devices and a communication network connecting the plurality of devices, based on information about the communication path between the entry device and the attack target device and information about the security measures implemented in the plurality of devices; and an output means for outputting information about the communication path in a manner according to a risk value determined using the number of security measures implemented in the communication path.

2. The risk management support device according to claim 1, further comprising a risk value calculation means for calculating the ratio of the number of measures for the communication path to the number of devices through which the communication path passes as the risk value of the communication path.

3. A risk management support device as described in claim 1 or 2, comprising an output information generation means for generating output information including a route display showing the communication route, the route display including a device display showing the device through which the communication route passes and a line showing the connection by the communication route between the devices to which the communication route connects, the route display being expressed in a manner corresponding to the level of risk indicated by the risk value of the communication route, wherein the output means outputs the output information as information about the communication route.

4. The risk management support device of claim 3, wherein the output information generation means generates the output information including the device display expressed in a manner corresponding to the level of risk indicated by the risk value of the communication path passing through the device indicated by the device display and whether the device is a countermeasure-completed device, i.e., a device for which the countermeasure has been completed.

5. The risk management support device according to claim 4, wherein the countermeasure number determination means determines that, among the plurality of devices, a countermeasure device that is the device for the countermeasure and an information processing device on which the countermeasure is implemented are the countermeasured devices, and the output information generation means generates the output information that includes, among the plurality of devices through which the communication path passes, the countermeasured devices and the devices that are not the countermeasured devices in different forms.

6. The risk management support device according to claim 4, wherein the countermeasure number determination means identifies, among the plurality of devices, information processing devices on which the countermeasure has not been implemented, countermeasure devices that are the devices for the countermeasure, and information processing devices on which the countermeasure has been implemented, and identifies, among the countermeasure devices that are the devices for the countermeasure and the information processing devices on which the countermeasure has been implemented, devices whose settings for the countermeasure satisfy a predetermined standard and devices whose settings for the countermeasure do not satisfy the predetermined standard; and the output information generation means generates the output information including the device display that shows, in different forms, the information processing devices on which the countermeasure has not been implemented, the devices among the countermeasure devices and the information processing devices on which the countermeasure has been implemented, whose settings for the countermeasure satisfy the predetermined standard, and the devices among the countermeasure devices and the information processing devices on which the countermeasure has been implemented, whose settings for the countermeasure satisfy the predetermined standard.

7. A risk management support device as described in claim 1 or 2, wherein the countermeasure number determination means identifies, from the plurality of devices, devices for which the countermeasures have not been implemented and devices for which the settings for the countermeasures do not meet a predetermined standard, and the output means outputs information about the devices for which the countermeasures have not been implemented and information about the devices for which the settings for the countermeasures do not meet a predetermined standard, in descending order of risk indicated by the risk value of the communication path passing through the devices.

8. A risk management support device as described in claim 7, further comprising a countermeasure identification means for identifying, for each type of device, the countermeasure that is required to be implemented for the device on which the countermeasure has not been implemented, from countermeasure information including information on the countermeasure that can be implemented, and wherein the output means outputs information on the countermeasure that is required to be implemented for the device on which the countermeasure has not been implemented.

9. The risk management support device according to claim 8, wherein the countermeasure identification means identifies, for each type of device, from countermeasure information including information on the settings for the countermeasures that satisfy the specified criteria, the setting change for the device in which the setting for the countermeasure does not satisfy the specified criteria, so as to satisfy the specified criteria; and the output means outputs the setting change for the device in which the setting for the countermeasure does not satisfy the specified criteria.

10. The risk management support device according to claim 1 or 2, wherein the aspect is at least one of line thickness, line color, and line shape.

11. A risk management support device as described in claim 1 or 2, wherein the countermeasure number determination means determines, from information on the plurality of devices, the number of countermeasure-completed devices, which are devices through which the communication path passes and for which the countermeasure has been completed, as the number of countermeasures.

12. The risk management support device described in claim 11, wherein the countermeasure number determination means determines, from the information of the plurality of devices, the number of countermeasure devices that are the devices for the countermeasure and the number of information processing devices in which the countermeasure is implemented, among the devices through which the communication path passes, as the number of countermeasure-implemented devices.

13. The risk management support device described in claim 11, wherein the countermeasure number determination means determines, from the information on the plurality of devices, the number of devices through which the communication path passes, including countermeasure devices that are devices for the countermeasure and information processing devices in which the countermeasure is implemented, and determines the number of devices whose settings for the countermeasure meet a predetermined standard as the number of countermeasure-implemented devices.

14. A risk management support method in an information processing system including a plurality of devices and a communication network connecting the plurality of devices, which determines the number of security measures implemented in the communication path from information about the communication path between an entry device and an attack target device and information about the security measures implemented in the plurality of devices, and outputs the information about the communication path in a manner corresponding to a risk value determined using the number of security measures implemented in the communication path.

15. The risk management support method according to claim 14, wherein the risk value of the communication path is calculated as a ratio of the number of measures for the communication path to the number of devices through which the communication path passes.

16. A risk management support method as described in claim 14 or 15, which generates output information including a route display showing the communication route, the route display including a device display showing the devices through which the communication route passes and a line showing the connection by the communication route between the devices to which the communication route connects, the route display being expressed in a manner corresponding to the level of risk indicated by the risk value of the communication route, and outputs the output information as information on the communication route.

17. A risk management support method as described in claim 16, wherein the output information is generated including the device display expressed in a manner according to the level of risk indicated by the risk value of the communication path passing through the device indicated by the device display and whether the device is a countermeasure-completed device, that is, a device for which the countermeasure has been completed.

18. A risk management support method as described in claim 17, wherein, among the plurality of devices, a countermeasure device that is the device for the countermeasure and an information processing device on which the countermeasure is implemented are determined to be the countermeasured devices, and the output information is generated that includes, in different forms, the countermeasured devices and the devices that are not the countermeasured devices among the plurality of devices through which the communication path passes.

19. A risk management support method as described in claim 17, wherein, from among the plurality of devices, an information processing device on which the countermeasure has not been implemented, a countermeasure device that is the device for the countermeasure, and an information processing device on which the countermeasure has been implemented are identified; from among the countermeasure device that is the device for the countermeasure and the information processing device on which the countermeasure has been implemented, devices whose settings for the countermeasure satisfy a predetermined standard and devices whose settings for the countermeasure do not satisfy the predetermined standard are identified; and the output information is generated including the device display that shows, in different forms, the information processing device on which the countermeasure has not been implemented, the device among the countermeasure device and the information processing device on which the countermeasure has been implemented whose settings for the countermeasure do not satisfy the predetermined standard, and the device among the countermeasure device and the information processing device on which the countermeasure has been implemented whose settings for the countermeasure satisfy the predetermined standard.

20. A storage medium storing a program that causes a computer to execute the following steps: a countermeasure number determination process that determines the number of countermeasures for a communication path between an entry device and an attack target device based on information about the communication path between the entry device and the attack target device and information about security measures implemented in the multiple devices in an information processing system that includes multiple devices and a communication network connecting the multiple devices; and an output process that outputs information about the communication path in a manner according to a risk value determined using the number of countermeasures for the communication path.

Citation Information

Patent Citations

  • Method and device for evaluating security and method and device for aiding preparation of security measure

    JP2001101135A

  • Introduction support device, introduction support method, and introduction support program

    JP2023012617A

  • Analysis device, analysis method, and non-transitory computer-readable medium in which analysis program is stored

    WO2021130933A1

  • Attack route extraction system, attack route extraction method, and program

    WO2023089669A1