Risk management support device, risk management support method, and storage medium
The risk management support device identifies devices for replacement based on security support expiration dates, enhancing system security by prioritizing devices with expired or nearing support to improve security.
Patent Information
- Application Number
- PCT/JP2024/007751
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-01
- Publication Date
- 2025-09-04
AI Technical Summary
Existing risk management systems fail to identify which devices should be prioritized for replacement to enhance the security of an information processing system, despite being able to minimize the total cost of securing a target path.
A risk management support device and method that calculates a replacement score for devices on communication paths based on security support expiration dates, outputting information on devices that need replacement to improve system security.
Provides prioritized information on devices that should be replaced to enhance the security of an information processing system, improving security by replacing devices with expired support and those nearing expiration.
Smart Images

Figure JP2024007751_04092025_PF_FP_ABST
Abstract
Description
Risk management support device, risk management support method, and storage medium
[0001] The present disclosure relates to a risk management support device, a risk management support method, and a storage medium.
[0002] In information processing systems that include devices such as multiple information processing devices connected to each other by a communication network, for example, managed by companies and other organizations, it is important to mitigate the risk of attack.
[0003] Patent document 1 describes a risk analysis device that identifies target elements that minimize the total cost required to cut off a target path from an entry point to a protected target in a system containing two or more elements by increasing the security level of elements on the target path to above a threshold.
[0004] International Publication No. 2020 / 189669
[0005] The technology of Patent Document 1 can identify target elements whose security is to be improved so that the total cost required to cut off the target path from the entry point to the protected target by improving the security of the elements is minimized. However, the technology of Patent Document 1 cannot identify devices that should be preferentially replaced in order to improve the security of the information processing system.
[0006] One of the objects of the present disclosure is to provide a risk management support device, a risk management support method, a storage medium, etc. that can provide information on devices that should be preferentially replaced in order to increase the security of an information processing system.
[0007] A risk management support device according to one aspect of the present disclosure comprises: a score calculation means for calculating a replacement score representing the degree of necessity of replacing a path device present on the communication path among the plurality of devices, based on information on the communication path between an entry device and an attack target device and information on the expiration date of security support for the plurality of devices, in an information processing system including a plurality of devices and a communication network connecting the plurality of devices; and an output means for outputting information on the path device in a manner corresponding to the replacement score of the path device.
[0008] A risk management support method according to one aspect of the present disclosure calculates a replacement score representing the degree of need to replace a path device among the plurality of devices that exists on the communication path in accordance with the support deadline, based on information on the communication path between an entry device and an attack target device in an information processing system that includes a plurality of devices and a communication network connecting the plurality of devices, and information on the security support deadline of the plurality of devices, and outputs information on the path device in a manner corresponding to the replacement score of the path device.
[0009] A storage medium according to one aspect of the present disclosure stores a program that causes a computer to execute a score calculation process that calculates a replacement score representing the degree of need to replace a path device among the plurality of devices that exists on the communication path based on information about the communication path between an entry device and an attack target device and information about the security support expiration date of the plurality of devices in an information processing system that includes a plurality of devices and a communication network connecting the plurality of devices, and an output process that outputs information about the path device in a manner that corresponds to the replacement score of the path device.
[0010] The present disclosure has an effect of being able to provide information on devices that should be replaced with priority in order to enhance the security of an information processing system.
[0011] FIG. 1 is a block diagram illustrating an example of the configuration of a risk management support device according to the present disclosure. FIG. 2 is a flowchart illustrating an example of the operation of a risk management support device according to the present disclosure. FIG. 3 is a block diagram illustrating an example of the configuration of a risk management support device according to the present disclosure. FIG. 4 is a diagram illustrating an example of output information. FIG. 5 is a diagram illustrating an example of output information. FIG. 6 is a diagram illustrating an example of output information. FIG. 7 is a flowchart illustrating an example of the operation of a risk management support device according to the present disclosure. FIG. 8 is a block diagram illustrating an example of the configuration of a risk management support device according to the present disclosure. FIG. 9 is a flowchart illustrating an example of the operation of a risk management support device according to the present disclosure. FIG. 10 is a block diagram illustrating an example of the configuration of a risk management support device according to the present disclosure. FIG. 11 is a flowchart illustrating an example of the operation of a risk management support device according to the present disclosure. FIG. 12 is a flowchart illustrating an example of the operation of a risk management support device according to the present disclosure. FIG. 13 is a diagram illustrating an example of the hardware configuration of a computer that can realize the risk management support device according to the present disclosure.
[0012] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the drawings.
[0013] First Embodiment First, a first embodiment of the present disclosure will be described.
[0014] <Configuration> FIG. 1 is a block diagram showing an example of the configuration of a risk management support device according to the present disclosure.
[0015] An example of the configuration of a risk management support device according to the present disclosure will be described in detail with reference to FIG.
[0016] In the example shown in FIG. 1 , the risk management support device 10 according to the first embodiment of the present disclosure includes a score calculation unit 130 and an output unit 150 .
[0017] The score calculation unit 130 calculates a replacement score for a path device, among multiple devices, that exists on the communication path from information on the communication path between an intrusion device and an attack target device in an information processing system and information on the security support expiration dates of the multiple devices. The information processing system includes multiple devices and a communication network connecting the multiple devices. The replacement score represents the degree of necessity to replace the path device according to the support expiration date.
[0018] The output unit 150 outputs information about the routing device in a format according to the replacement score of the routing device.
[0019] The multiple devices include information processing devices such as a server and an information processing terminal. The multiple devices may also include a device for security measures. The device for security measures is, for example, a firewall (FW) device that functions as a firewall, a unified threat management (UTM) device, etc. The unified threat management device is, for example, a device that has functions such as a firewall, antivirus, antispam, intrusion prevention, and content filtering. The unified threat management device may also have other functions such as a virtual private network (VPN). Hereinafter, the firewall device will also be simply referred to as FW. Hereinafter, the unified threat management device will also be simply referred to as UTM. In the present disclosure, the device for security measures will also be referred to as a countermeasure device.
[0020] The intrusion device is a device (e.g., an information processing device) that is designated in advance as a device that will be an entry point for an attack among a plurality of devices. The attack target device is a device (e.g., an information processing device) that is designated in advance as a device that will be a target of an attack among a plurality of devices. The intrusion device is a device that is different from the attack target device. In this embodiment, information on the intrusion device and the attack target device is given in advance.
[0021] A communication path is a communication path that can be an attack path in an attack from an intrusion device to an attack target device. A communication path is expressed as a communication path that connects multiple devices, including an intrusion device and an attack target device, in series. Multiple communication paths may exist in an information processing system. One device may be included in multiple communication paths. In the present disclosure, a communication path between an intrusion device and an attack target device, in which the devices through which the communication path passes do not match, is a different communication path. A communication path between an intrusion device and an attack target device, in which the order of the devices through which the communication path passes does not match, is a different communication path. In this embodiment, information about the communication path is given in advance.
[0022] Device support indicates, for example, that security updates for the device will be provided. A device security update is an update to the software that controls the device to fix security flaws in the software that controls the device. The software that controls the device includes, for example, the firmware of the device. The software that controls the device may also include, for example, the operating system of the device. The end of device support is, for example, the time when security updates for the device will end. If the device is controlled by firmware and an operating system, the end of device support may be, for example, the time when security updates for at least one of the firmware and the operating system will no longer be provided.
[0023] The replacement score may be, for example, either a value assigned to a device for which security support has been terminated or another value assigned to a device for which security support has not been terminated. In this case, the security score assigned to a device for which security support has been terminated indicates a higher need for replacement than the security score assigned to a device for which security support has not been terminated. The replacement score is not limited to these examples. The replacement score may be another value. Other examples of the replacement score will be described in detail later.
[0024] The mode according to the replacement score is a mode that is assigned in advance to a value of the replacement score. The mode according to the replacement score may be a mode that is assigned in advance to a range of values of the replacement score.
[0025] The device information (including information about route devices) output by the output unit 150 is information such as a character string that identifies the device, such as a name, identification information, or a combination thereof. The device information may be a combination of information that identifies the device and a graphic such as a rectangle. The device information is also referred to as information indicating the device and a device display.
[0026] The aspect indicates, for example, a combination of the information indicating the device, such as the color of the figure, the pattern of the figure (in other words, the texture), the color of the line, the type of the line, the thickness of the line, the color of the character, the type of the character, and the thickness of the character.
[0027] The information on the path device may be information on the path device generated as an image. In the present disclosure, information representing information on the path device through which the communication path passes is referred to as output information. The output information is, for example, a screen (referred to as output screen) or an image (referred to as output image).
[0028] <Operation> Next, the operation of the risk management support device 10 according to the first embodiment of the present disclosure will be described.
[0029] FIG. 2 is a flowchart illustrating an example of the operation of the risk management support device according to the present disclosure.
[0030] Hereinafter, the operation of the risk management support device 10 according to the first embodiment of the present disclosure will be described in detail with reference to FIG.
[0031] 2, in an information processing system including a plurality of devices and a communication network connecting the plurality of devices, the score calculation unit 130 calculates a replacement score of a path device present on the communication path from information on the communication path between an entry device and an attack target device and information on security support of the plurality of devices (step S11). Next, the output unit 150 outputs information on the path device in a manner corresponding to the replacement score of the path device (step S12).
[0032] <Effect> This embodiment has the effect of being able to provide information on devices that should be replaced with priority in order to increase the security of the information processing system.
[0033] This is because the score calculation unit 130 calculates the replacement score of a path device on a communication path from information about the communication path between an intrusion device and an attack target device in an information processing system and information about the security support of multiple devices. As described above, the replacement score represents the degree of necessity for replacing a path device according to the support deadline. Then, the output unit 150 outputs information about the path device in a manner according to the replacement score of the path device.
[0034] When the expiration date of security support expires, the security of the device can no longer be guaranteed. For example, by replacing a path device whose support expiration date has expired with, for example, another device whose support expiration date has not expired, the security of the information processing system against attacks via a communication path between an intrusion device and an attack target device can be improved. Also, by replacing a path device whose support expiration date is approaching with, for example, another device whose support expiration date is longer than the support expiration date of the path device, the security of the information processing system against the above-mentioned attacks can be improved.
[0035] By outputting information about route devices in a manner corresponding to a replacement score that indicates the degree of need for replacing route devices according to the support deadline, it is possible to identify devices that should be replaced as a priority in order to increase the security of the information processing system.
[0036] Second Embodiment Next, a second embodiment of the present disclosure will be described in detail with reference to the drawings.
[0037] <Configuration> FIG. 3 is a block diagram showing an example of the configuration of a risk management support device according to the present disclosure.
[0038] The configuration of the risk management support device according to the second embodiment of the present disclosure will be described in detail below with reference to FIG.
[0039] In the example shown in Figure 3, the risk management support device 100 of this embodiment includes a configuration information receiving unit 110, a device information receiving unit 120, a score calculation unit 130, an output information generation unit 140, and an output unit 150.
[0040] <Configuration Information Receiving Unit 110> The configuration information receiving unit 110 receives information about the configuration of the information processing system.
[0041] The configuration information receiving unit 110 receives information about the configuration of the information processing system, for example, from another information processing device that holds information about the configuration of the information processing system. The information about the configuration of the information processing system includes information about the devices included in the information processing system and information about the connections between the devices and other devices. The device information includes, for example, information that identifies the device and information about the type of device.
[0042] The information on the configuration of the information processing system also includes information indicating an entry point device and information indicating an attack target device among the devices included in the information processing system.
[0043] The information on the configuration of the information processing system further includes information on the above-mentioned communication paths that can be the attack paths from the entry device to the target device.
[0044] The information about the configuration of the information processing system may include information indicating whether the device is included in a boundary network (in other words, whether the device is connected to the boundary network) or whether the device is included in a business network (in other words, whether the device is connected to the business network). A business network refers to, for example, an internal communication network that is protected by security in an organizational network such as a company. A boundary network refers to, for example, a communication network that exists between the outside of the organizational network and the organization's business network.
[0045] <Device Information Receiving Unit 120> The device information receiving unit 120 receives device information, including information on the expiration date of device support, from another information processing device that holds the device information.
[0046] <Score Calculation Unit 130> As described above, the score calculation unit 130 calculates a replacement score for a path device, among multiple devices, that exists on the communication path from information about the communication path between the intrusion device and the attack target device in the information processing system and information about the security support expiration dates of the multiple devices. As described above, the information processing system includes multiple devices and a communication network connecting the multiple devices. The replacement score represents the degree of necessity to replace the path device according to the support expiration date.
[0047] In the present disclosure, a device on a communication path for which support has ended is also referred to as an end-of-path device, and a device on a communication path for which support has not ended is also referred to as a continuation-path device.
[0048] Note that the score calculation unit 130 does not need to determine the replacement score for a device that is not a path device. In other words, a device that is not a path device is a device that does not pass through a communication path that could be a path for an attack from an entry device to an attack target device, i.e., a device that does not exist on a communication path. In the present disclosure, a device that is not a path device is referred to as a non-path device. A non-path device does not exist on a path that could be a path for an attack from an entry device to an attack target device. Therefore, it is assumed that a non-path device is not related to the security of an information processing system against attacks from an entry device to an attack target device. The score calculation unit 130 may determine a score that indicates the lowest need for replacement as the replacement score for a non-path device.
[0049] <First Example of Replacement Score> As described above, the score calculation unit 130 calculates the replacement score so that, for example, the necessity indicated by the replacement score of the continuing path device is lower than the necessity indicated by the replacement score of the ending path device.
[0050] The score calculation unit 130 may determine, for example, a predetermined score as the replacement score of the end path device. The score calculation unit 130 may determine, as the replacement score of the continuing path device, another predetermined score that indicates a lower necessity than the necessity indicated by the above-mentioned predetermined score, which is the replacement score of the end path device.
[0051] As mentioned above, replacement scores are not limited to these examples, and other examples of replacement scores are described in more detail below.
[0052] <Second Example of Replacement Score> The score calculation unit 130 may set the replacement score of a continuing path device to a score according to the length of the deadline until support for the continuing path device ends (hereinafter referred to as the remaining support period). In this case, for example, the relationship between the remaining support period and the replacement score may be determined in advance. The score calculation unit 130 may determine the replacement score of the continuing path device from the remaining support period of the continuing path device using the relationship between the remaining support period and the replacement score.
[0053] In this case, for example, if the period until support of the continuing path device ends is longer than the period until support of the other continuing path devices ends, the score calculation unit 130 determines the replacement score of the continuing path device as follows: That is, in this case, the score calculation unit 130 determines the replacement score so that the necessity of replacement indicated by the replacement score of support of the continuing path device is not higher than the necessity of replacement indicated by the replacement scores of the other continuing path devices.
[0054] For example, if the period until support of the continuing path device ends is shorter than the period until support of the other continuing path devices ends, the score calculation unit 130 determines the replacement score of the continuing path device as follows: That is, in this case, the score calculation unit 130 determines the replacement score so that the necessity of replacement indicated by the replacement score of support of the continuing path device is not lower than the necessity of replacement indicated by the replacement scores of the other continuing path devices.
[0055] In this case, the score calculation unit 130 also determines the replacement score so that the replacement score of the continuing path device indicates a lower necessity than the replacement score of the ending path device, for example.
[0056] <Third Example of Replacement Score> The score calculation unit 130 uses the length of time until support of a route device ends to calculate the replacement score of the route device.
[0057] The score calculation unit 130 may further calculate the replacement score of a route device using any of the period from ordering the other device that replaces the route device to delivery, the cost of the other device that replaces the route device, and the period until depreciation of the route device is completed.
[0058] In this case, the score calculation unit 130 determines the element score according to the length of the period until the end of support. The score calculation unit 130 determines the element score such that the longer the period until the end of support, the lower the necessity for replacement indicated by the element score. In this case, the score calculation unit 130 determines the element score from the period until the end of support, for example, by using a predetermined relationship between the period until the end of support and the element score.
[0059] In addition, the score calculation unit 130 determines an element score that represents at least one of the length of time from ordering the other device that replaces the route device to delivery, the cost of the other device that replaces the route device, and the time until depreciation of the route device is completed.
[0060] When determining the element score representing the length of the period from the order placement of the other device to be replaced with the routing device until its delivery, the score calculation unit 130 may determine the element score such that the longer the period from the order placement of the other device to be replaced with the routing device until its delivery, the greater the necessity of replacement indicated by the element score. In this case, the score calculation unit 130 determines the element score from the period from the order placement of the other device to be replaced with the routing device until its delivery, for example, by using a predetermined relationship between the period from the order placement of the other device to be replaced with the routing device until its delivery.
[0061] The policy for replacing a path device may be such that the higher the cost of the other device replacing the path device, the earlier preparation for replacement (e.g., preparation for securing a budget for replacement) begins. In this case, when determining the element score representing the cost of the other device replacing the path device, the score calculation unit 130 is configured to determine the element score such that the higher the cost of the other device replacing the path device, the greater the necessity of replacement indicated by the element score. The policy for replacing a path device may be to proceed with replacement of the path devices in order of lowest cost. In this case, when determining the element score representing the cost of the other device replacing the path device, the score calculation unit 130 is configured to determine the element score such that the lower the cost of the other device replacing the path device, the greater the necessity of replacement indicated by the element score. In these cases, the score calculation unit 130 determines the element score from the cost of the other device replacing the path device, for example, using a predetermined relationship between the cost of the other device replacing the path device and the element score. The relationship between the cost of the other device replacing the path device and the element score may be determined according to the policy for replacing a path device. That is, the relationship between replacement cost and element score may be determined depending on whether the replacement policy of the route device is to start preparing for replacement from those with high replacement costs or to replace those with low replacement costs first.
[0062] When determining the element score representing the period until depreciation of the route device is completed, the score calculation unit 130 may determine the element score such that the shorter the period until depreciation of the route device is completed, the greater the necessity of replacement indicated by the element score. In this case, the score calculation unit 130 determines the element score from the period until depreciation of the route device is completed, for example, by using a predetermined relationship between the period until depreciation of the route device is completed and the element score.
[0063] The score calculation unit 130 calculates the weighted sum of the element scores as the replacement score. The weighted sum is, for example, the sum of the products of the element score and a weight predetermined for each type of element score, for multiple types of element scores. The weighted sum may be, for example, the sum of the products of the element score and a weight predetermined for each type of element score, for multiple types of element scores, divided by the sum of the weights.
[0064] <Output Information Generating Unit 140> The output information generating unit 140 generates output information including information about the route device in a format according to the replacement score of the route device.
[0065] The output information generating unit 140 may generate, as output information, an output display showing a route display indicating a communication route. This route display includes device displays showing route devices through which the communication route passes in a manner according to the replacement scores of the route devices. In addition, this route display further includes connection displays showing connections by the communication route between devices connected by the communication route. The device display of a device (including a route device) includes information such as a character string that identifies the device, such as the name, identification information, or a combination thereof, of the device. The device display may be represented by a combination of information that identifies the device and a graphic such as a rectangle. The route display of a route may be represented by a line connecting two device displays connected by the route.
[0066] The relationship between the replacement score and the aspect may be determined in advance. The output information generating unit 140 may use the relationship between the replacement score and the aspect to determine the aspect of the device display representing the path device based on the replacement score of the path device.
[0067] The output information generating unit 140 may generate output information that does not include a device indication of a non-path device. When the replacement score of a non-path device has been determined, the output information generating unit 140 may generate output information that includes a device indication indicating the non-path device in a manner corresponding to the replacement score of the non-path device (i.e., a manner indicating that the need for replacement is lowest).
[0068] Furthermore, the output information generation unit 140 may generate output information including a display indicating the range of the business network and a display indicating the range of the boundary network from the business network information and the boundary network information included in the information on the configuration of the information processing system. The display indicating the range of the business network may be represented by a line surrounding the device display of the device included in the business network, or a graphic including the device display of the device included in the business network. The display indicating the range of the boundary network may be represented by a line surrounding the device display of the device included in the boundary network, or a graphic including the device display of the device included in the business network. If a device exists that is included in both the boundary network and the business network, the device display of that device may be included in both the display indicating the range of the boundary network and the display indicating the range of the business network. If a device exists that is included in both the boundary network and the business network, a portion of the device display of that device may be included in the display indicating the range of the boundary network, and another portion of the device display may be included in the display indicating the range of the business network.
[0069] <Output unit 150> The output unit 150 outputs information about the route device in a manner according to the replacement score of the route device. Specifically, the output unit 150 outputs the above-mentioned output information to a display device or the like of the risk management support device 100. The output unit 150 may output to another information processing device. The output unit 150 may output to a storage device.
[0070] <Display Examples> Figures 4, 5, and 6 are diagrams showing examples of output information. In Figures 4, 5, and 6, terminal A is an intrusion gateway device. Server A is an attack target device. Terminal device X is a non-path device. In Figures 4, 5, and 6, the device display showing terminal device X is shown in a manner (e.g., blue) that indicates that replacement is least necessary. The device display showing terminal device X does not have to be displayed.
[0071] In the example shown in Figure 4, terminals B and FW are continuation path devices that are devices for which support has not been discontinued among devices present on a communication path that could be an attack path from an intrusion device to an attack target device. Terminals C and UTM are end path devices that are devices for which support has been discontinued among devices present on a communication path that could be an attack path from an intrusion device to an attack target device. In the example of Figure 4, the replacement score of a path device is either a replacement score assigned to a continuation path device or a replacement score assigned to an end path device. In this example, the device display of a continuation path device is displayed in a different manner (e.g., yellow) from the manner (e.g., red) of the device display of an end path device.
[0072] In the example shown in FIG. 5 , terminals B and FW are continuing path devices. Terminals C and UTM are ending path devices. In the example shown in FIG. 5 , the replacement score of a path device is a replacement score corresponding to the length of time until support for the path device ends. The device display of an ending path device is displayed in a manner (e.g., red) corresponding to the time until support for the path device ends (i.e., zero days). The device display of a continuing path device is displayed in a manner (e.g., color) different from the manner (e.g., red) of the device display of an ending path device corresponding to the time until support for the continuing path device ends. In the example shown in FIG. 5 , the device display of a device (e.g., terminal B in the example of FIG. 5 ) whose support will end in less than one year is displayed in yellow. Furthermore, the device display of a device (e.g., FW in the example of FIG. 5 ) whose support will end in one year or more is displayed in blue. In this example, the device display of a device whose support will end in one year or more is displayed in the same manner as the device display of a non-path device (e.g., a manner indicating that the need for replacement is lowest).
[0073] In the example of FIG. 5 , the device display of the continuing path device has two modes corresponding to the period until support for the path device ends: a mode when the period until support ends is less than one year, and a mode when the period until support ends is one year or more. The period until support ends may be divided into three or more ranges. Different modes may be assigned to each range. The output information generation unit 140 may generate output information including the device display of the continuing path device in a mode assigned to a range that includes the length of the period until support for the path device ends. At least a portion of the modes (e.g., color, line thickness, etc.) may be represented, for example, by a function of the length of the period until support ends. The output information generation unit 140 may generate output information including the device display of the continuing path device in a mode determined by the function of the length of the period until support for the path device ends.
[0074] 6, the device display of a path device is displayed in a manner corresponding to a replacement score calculated by a weighted sum of the element scores of the path device. If the replacement score of a path device indicates a lower need for replacement than a predetermined score indicates, the device display of the path device may be displayed in the same manner as the device display of a non-path device (e.g., a manner indicating the lowest need for replacement).
[0075] The element score may include, for example, an element score that indicates the length of time until support ends. The element score may also include an element score that indicates any of the time from ordering another device that replaces the path device until delivery, the cost of the other device that replaces the path device, and the time until depreciation of the path device ends. The element score is not limited to these examples. The element score may also include the element scores described below.
[0076] <Operation> Next, the operation of the risk management support device 100 according to the second embodiment of the present disclosure will be described in detail with reference to the drawings.
[0077] FIG. 7 is a flowchart illustrating an example of the operation of the risk management support device according to the present disclosure.
[0078] Hereinafter, the operation of the risk management support device 100 according to the second embodiment of the present disclosure will be described in detail with reference to FIG.
[0079] 7, the configuration information receiving unit 110 receives information about the configuration of the information processing system (step S101), and the device information receiving unit 120 receives support information for multiple devices included in the information processing system (step S102).
[0080] Next, the score calculation unit 130 identifies a path device, which is a device on a communication path from the intrusion device to the attack target device of the information processing system, among the multiple devices included in the information processing system (step S103).The score calculation unit 130 calculates the replacement score of the path device using support information of the path device (step S104).
[0081] Next, the output information generating unit 140 generates output information including a route display showing the route device in a form according to the replacement score of the route device (step S105).
[0082] Then, the output unit 150 outputs the output information (step S106).
[0083] <Effects> This embodiment has the same effects as the first embodiment, for the same reasons as those for the effects of the first embodiment.
[0084] Third Embodiment Next, a third embodiment of the present disclosure will be described in detail with reference to the drawings.
[0085] FIG. 8 is a block diagram illustrating an example of the configuration of a risk management support device according to the present disclosure.
[0086] The configuration of the risk management support device according to the third embodiment of the present disclosure will be described in detail below with reference to FIG.
[0087] 8 , a risk management support device 101 according to the third embodiment of the present disclosure includes a configuration information receiving unit 110, a device information receiving unit 120, a score calculation unit 130, an output information generation unit 140, an output unit 150, and a risk value determination unit 160. The risk management support device 101 of this embodiment is the same as the risk management support device 100 of the second embodiment, except for the differences described below. The configuration information receiving unit 110, the device information receiving unit 120, the score calculation unit 130, the output information generation unit 140, and the output unit 150 of this embodiment are the same as the components in the second embodiment that are given the same names and the same reference numerals, except for the differences described below.
[0088] <Device Information Receiving Unit 120> The device information receiving unit 120 of this embodiment operates in the same manner as the device information receiving unit 120 of the second embodiment.
[0089] The device information receiving unit 120 of this embodiment further receives information indicating devices that are countermeasured devices, which are devices for which security measures have been implemented, among multiple devices included in the information processing system. In the present disclosure, the countermeasured devices include information processing devices for which security measures have been implemented and devices for security measures (hereinafter also referred to as countermeasure devices). The countermeasured devices may be devices, such as information processing devices for which security measures have been implemented and devices for security measures (hereinafter also referred to as countermeasure devices), that are designated as devices whose security settings meet standards.
[0090] Note that devices for which support has ended (i.e., devices for which the support deadline has passed) may be excluded from the countermeasured devices. The risk value determiner 160, which will be described later, may exclude devices for which support has ended from the countermeasured devices. Devices for which the length of time until support ends is less than a predetermined length may be excluded from the countermeasured devices. The risk value determiner 160, which will be described later, may exclude devices for which the length of time until support ends is less than a predetermined length from the countermeasured devices.
[0091] <Risk Value Determining Unit 160> The risk value determining unit 160 determines a risk value that represents the degree of risk of an attack from the number of countermeasure-enabled devices through which a communication path that could be an attack path from an intrusion device of the information processing system to an attack target device passes. The risk value of a communication path may be, for example, the number of countermeasure-enabled devices through which the communication path passes. The risk value of a communication path may be, for example, the ratio of the number of countermeasure-enabled devices through which the communication path passes to the number of devices through which the communication path passes.
[0092] Specifically, the risk value determiner 160 first identifies countermeasured devices through which a communication path that could be a route for an attack from an intrusion device of the information processing system to an attack target device passes.The risk value determiner 160 then identifies the number of countermeasured devices through which the communication path passes.If multiple communication paths exist, the risk value determiner 160 identifies, for each of the multiple communication paths, the countermeasured devices through which the communication path passes.The risk value determiner 160 then identifies, for each of the multiple communication paths, the number of countermeasured devices through which the communication path passes.
[0093] When the risk value is the number of devices through which a communication path passes, the risk value determining unit 160 determines the identified number of countermeasure-completed devices through which the communication path passes as the risk value of that communication path.
[0094] If the risk value is the ratio of the number of countermeasure-completed devices through which the communication path passes to the number of devices through which the communication path passes, the risk value determiner 160 further identifies the number of devices through which the communication path passes. If there are multiple communication paths, the risk value determiner 160 identifies, for each of the multiple communication paths, the number of countermeasure-completed devices through which the communication path passes.
[0095] The risk value determining unit 160 determines the ratio of the number of countermeasure-completed devices through which a communication path passes to the number of countermeasure-completed devices through which the communication path passes as the risk value of that communication path.
[0096] <Score Calculation Unit 130> The score calculation unit 130 of this embodiment may operate in the same manner as the score calculation unit 130 of the second embodiment. The replacement score of this embodiment may be one of the replacement scores described in the description of the second embodiment.
[0097] The score calculation unit 130 of this embodiment may calculate the replacement score for the following fourth or fifth example.
[0098] <Fourth Example of Replacement Score> The score calculation unit 130 calculates the replacement score of a route device using the length of time until support of the route device ends and the risk value of the communication route that passes through the route device.
[0099] The score calculation unit 130 may further calculate the replacement score of a route device using any of the period from ordering the other device that replaces the route device to delivery, the cost of the other device that replaces the route device, and the period until depreciation of the route device is completed.
[0100] In this case, the score calculation unit 130 determines the element score according to the length of the period until the end of support. The score calculation unit 130 determines the element score such that the longer the period until the end of support, the lower the necessity for replacement indicated by the element score. In this case, the score calculation unit 130 determines the element score from the period until the end of support, for example, by using a predetermined relationship between the period until the end of support and the element score.
[0101] Furthermore, the score calculation unit 130 determines an element score according to the risk value of the communication path that passes through the path device. The score calculation unit 130 determines the element score according to the risk value of the communication path that passes through the path device such that the higher the risk indicated by the risk value of the communication path that passes through the path device, the higher the necessity for replacement indicated by the element score. In this case, the score calculation unit 130 determines the element score from the risk value, for example, using a predetermined relationship between the risk value and the element score.
[0102] In addition, the score calculation unit 130 determines an element score that represents at least one of the length of time from ordering the other device that replaces the route device to delivery, the cost of the other device that replaces the route device, and the time until depreciation of the route device is completed.
[0103] When determining the element score representing the length of the period from the order placement of the other device to be replaced with the routing device until its delivery, the score calculation unit 130 may determine the element score such that the longer the period from the order placement of the other device to be replaced with the routing device until its delivery, the greater the necessity of replacement indicated by the element score. In this case, the score calculation unit 130 determines the element score from the period from the order placement of the other device to be replaced with the routing device until its delivery, for example, by using a predetermined relationship between the period from the order placement of the other device to be replaced with the routing device until its delivery.
[0104] When determining the element score representing the cost of another device that replaces the path device, the score calculation unit 130 may determine the element score such that the higher the cost of the other device that replaces the path device, the greater the necessity of replacement indicated by the element score. In this case, the score calculation unit 130 determines the element score from the cost of the other device that replaces the path device, for example, by using a predetermined relationship between the cost of the other device that replaces the path device and the element score.
[0105] When determining the element score representing the period until depreciation of the route device is completed, the score calculation unit 130 may determine the element score such that the shorter the period until depreciation of the route device is completed, the greater the necessity of replacement indicated by the element score. In this case, the score calculation unit 130 determines the element score from the period until depreciation of the route device is completed, for example, by using a predetermined relationship between the period until depreciation of the route device is completed and the element score.
[0106] The score calculation unit 130 calculates the weighted sum of the element scores as the replacement score. The weighted sum is, for example, the sum of the products of the element score and a weight predetermined for each type of element score, for multiple types of element scores. The weighted sum may be, for example, the sum of the products of the element score and a weight predetermined for each type of element score, for multiple types of element scores, divided by the sum of the weights.
[0107] <Fifth Example of Replacement Score> The score calculation unit 130 calculates the replacement score of a route device using the length of time until support of the route device ends and the risk value of the communication route that passes through the route device.
[0108] The score calculation unit 130 may further calculate the replacement score of a route device using any of the period from ordering the other device that replaces the route device to delivery, the cost of the other device that replaces the route device, and the period until depreciation of the route device is completed.
[0109] In this example, the score calculation unit 130 calculates the element scores in the same manner as in the third example of the replacement score. Then, the score calculation unit 130 calculates the weighted sum of the element scores in the same manner as in the third example of the replacement score.
[0110] Furthermore, the score calculation unit 130 determines a coefficient according to the risk value of the communication path passing through the path device. The score calculation unit 130 determines the coefficient so that the higher the risk indicated by the risk value of the communication path passing through the path device, the greater the degree of improvement in the necessity of replacement indicated by the score obtained by multiplying the weighted sum of the element scores by the coefficient, relative to the necessity of replacement indicated by the weighted sum of the element scores. In this case, the score calculation unit 130 determines the coefficient from the risk value, for example, using a predetermined relationship between the risk value and the coefficient.
[0111] The score calculation unit 130 determines the product of the coefficient and the weighted sum of the element scores as the replacement score.
[0112] <Output Information Generating Unit 140> The output information generating unit 140 generates output information including a device display in a manner corresponding to the replacement score and a path display in a manner corresponding to the risk value. Specifically, the output information generating unit 140 generates output information including the same device display as in the second embodiment and a connection display showing the connection between devices on the communication path in a manner corresponding to the risk value of the communication path.
[0113] As described above, the connection display is represented by a line (specifically, a line segment) connecting the device displays representing the devices. The line may be an arrow. The line appearance (including the connection display appearance) is, for example, the color, thickness, and type of the line. The type of line may be, for example, a straight line, a dashed line, a dashed-dotted line, a wavy line, etc.
[0114] <Operation> Next, the operation of the risk management support device 101 according to the third embodiment of the present disclosure will be described in detail with reference to the drawings.
[0115] FIG. 9 is a flowchart illustrating an example of the operation of the risk management support device according to the present disclosure.
[0116] Hereinafter, the operation of the risk management support device 101 according to the third embodiment of the present disclosure will be described in detail with reference to FIG.
[0117] Comparing Fig. 9 with Fig. 7, the operations of steps S101, S102, S103, S104, and S106 in Fig. 9 are the same as the operations of steps S101, S102, S103, S104, and S106 in Fig. 7, respectively. In the example shown in Fig. 9, the operation of step S203 is performed between the operation of step S102 and the operation of step S103. Also, the operation of step S205 is performed instead of the operation of step S105.
[0118] In step S203, the risk value determining unit 160 determines a risk value of the communication path from the information of the information processing system.
[0119] In step S205, the output information generating unit 140 generates output information including a device display in a manner corresponding to the replacement score and a connection display in a manner corresponding to the risk value.
[0120] <Effects> This embodiment has the same effects as the first embodiment, for the same reasons as those for the effects of the first embodiment.
[0121] <Modification of the Second Embodiment> The modification of the second embodiment is the same as the second embodiment except for the differences described below.
[0122] The risk value determining unit 160 may set a predetermined threat level representing the risk of an attack or the degree of threat of the communication path as the risk value of the communication path.
[0123] In this case, for example, the configuration information receiving unit 110 receives information on the threat level of the communication path from an information processing device such as a server that provides information on the threat level of the communication path.
[0124] Fourth Embodiment Next, a fourth embodiment of the present disclosure will be described in detail with reference to the drawings.
[0125] FIG. 10 is a block diagram illustrating an example of the configuration of a risk management support device according to the present disclosure.
[0126] The configuration of the risk management support device according to the fourth embodiment of the present disclosure will be described in detail below with reference to FIG.
[0127] 10 , a risk management support device 102 according to a third embodiment of the present disclosure includes a configuration information receiving unit 110, a device information receiving unit 120, a score calculation unit 130, an output information generation unit 140, an output unit 150, a risk value determination unit 160, a path estimation unit 170, and a virtual vulnerability determination unit 180. The risk management support device 102 according to this embodiment is the same as the risk management support device 101 according to the third embodiment, except for the differences described below. The configuration information receiving unit 110, the device information receiving unit 120, the score calculation unit 130, the output information generation unit 140, the output unit 150, and the risk value determination unit 160 according to this embodiment are the same as the components in the third embodiment that are assigned the same names and the same reference numerals, except for the differences described below.
[0128] <Configuration Information Receiving Unit 110> The configuration information receiving unit 110 of this embodiment receives information indicating the physical connection status of multiple devices included in the information processing device and information indicating an intrusion device and an attack target device among the multiple devices. In this embodiment, the configuration information receiving unit 110 does not need to receive information about communication paths that could be a route for an attack from the intrusion device to the attack target device.
[0129] <Device Information Receiving Unit 120> The device information receiving unit 120 of this embodiment has the same functions as the device information receiving unit 120 of the third embodiment.
[0130] The device information receiving unit 120 of this embodiment receives vulnerability information for each of multiple devices included in the information processing system from an information processing device such as a server that stores vulnerability information for multiple devices. The vulnerability information includes, for example, the type of vulnerability, the severity, and the time when the vulnerability was discovered.
[0131] The device information receiving unit 120 of this embodiment may further receive information on vulnerabilities discovered within a predetermined period of time in the past for each of the devices included in the information processing system from a server or the like that provides vulnerability information.
[0132] <Virtual Vulnerability Determination Unit 180> The virtual vulnerability determination unit 180 determines virtual vulnerabilities (hereinafter referred to as virtual vulnerabilities) that are assumed to occur after support ends for an end-of-support device, which is a piece of equipment whose support period has ended.
[0133] The type of virtual vulnerability that is assumed to occur after support ends, the severity of the virtual vulnerability, and the length of time from the time support ends to the time when the virtual vulnerability will hypothetically occur may be determined in advance. Two or more virtual vulnerabilities may be determined. A different virtual vulnerability may be determined for each device model (e.g., device type distinguished by device model number). A different virtual vulnerability may be determined for each device type (e.g., type of information processing device, FW, UTM, etc.). The same virtual vulnerability may be determined regardless of device. Information on the type of virtual vulnerability that is assumed to occur after support ends, the severity of the virtual vulnerability, and the length of time from the time support ends to the time when the virtual vulnerability will hypothetically occur is referred to as virtual vulnerability occurrence information.
[0134] The virtual vulnerability determination unit 180 determines the virtual vulnerabilities of the discontinued device, for example, by using the virtual vulnerability occurrence information. Note that, when the virtual vulnerability determination unit 180 is configured to determine the virtual vulnerabilities of the discontinued device by using the virtual vulnerability occurrence information, the device information receiving unit 120 does not need to be configured to receive information on vulnerabilities discovered within a predetermined period in the past for each of the devices included in the information processing system.
[0135] The virtual vulnerability determining unit 180 may determine the virtual vulnerability of an end-of-support device by using information about vulnerabilities discovered in the end-of-support device within a predetermined period of time in the past.
[0136] In this case, the virtual vulnerability determination unit 180 determines parameters of a function with time as a variable, which represents the number of vulnerabilities that occurred for each combination of vulnerability type and severity, using information on vulnerabilities discovered within a predetermined period of time in the end-of-support device. The function may be, for example, a linear function. The virtual vulnerability determination unit 180 generates information on trends in the cumulative number of discovered vulnerabilities for each combination of vulnerability type and severity from information on vulnerabilities discovered within a predetermined period of time in the end-of-support device. The virtual vulnerability determination unit 180 determines parameters of the function that best represents trends in the cumulative number of discovered vulnerabilities, for example, using the least squares method. Note that if the value of the variable representing time is zero, the function may be applied to trends in the cumulative number of discovered vulnerabilities so that the variable indicates the start of the predetermined period of time in the past. The function does not have to be a linear function. A method for determining the parameters may be a method other than the least squares method.
[0137] The virtual vulnerability determination unit 180 determines virtual vulnerabilities of the discontinued device using the function for which the parameters have been determined. Specifically, the virtual vulnerability determination unit 180 calculates the value of the function when the variable indicates the time elapsed since support for the discontinued device ended. The virtual vulnerability determination unit 180 rounds the calculated value and sets the result as the number of virtual vulnerabilities. The rounding method is a predetermined method from among rounding up, rounding down, and rounding off. The virtual vulnerability determination unit 180 determines the number of virtual vulnerabilities for each combination of vulnerability type and severity. The virtual vulnerability determination unit 180 sets the number determined for a combination of vulnerability type and severity as the number of virtual vulnerabilities of that type and severity.
[0138] <Path estimation unit 170> The path estimation unit 170 estimates a communication path from information representing the configuration of the information processing system, information on vulnerabilities of multiple devices included in the information processing system, information on virtual vulnerabilities of devices for which support has ended, and information indicating an entry point device and an attack target device.
[0139] The route estimation unit 170 estimates the communication route using, for example, the method described in at least one of the following reference documents 1 and 2.
[0140] (Reference 1) International Publication No. 2023 / 175878
[0141] (Reference 2) Ryo Mizushima, Maki Inokuchi, Tomohiko Yagyu, "Countermeasure Planning Method Considering Multi-Layer Defense Against Cyber Attacks," 2023 Symposium on Cryptography and Information Security, Fukuoka, Japan, January 24-27, 2023. The path estimation unit 170 may further determine the threat level of the communication path using the method described in at least one of References 1 and 2.
[0142] <Risk Value Determining Unit 160> The risk value determining unit 160 determines the threat level of a communication path determined by the path estimating unit 170 as the risk value of that communication path.
[0143] Similar to the risk value determiner 160 of the third embodiment, the risk value determiner 160 may set a value determined using the number of countermeasured devices through which the communication path passes as the risk value. The value determined using the number of countermeasured devices through which the communication path passes may be the number of countermeasured devices through which the communication path passes. The value determined using the number of countermeasured devices through which the communication path passes may be the ratio of the number of countermeasured devices through which the communication path passes to the number of devices through which the communication path passes. In this case, the risk value determiner 160 of this embodiment excludes from the countermeasured devices any end-of-support device for which a hypothetical vulnerability has been determined for the period since support ended.
[0144] <Operation> Next, an example of the operation of the risk management support device 102 according to the fourth embodiment of the present disclosure will be described in detail with reference to the drawings.
[0145] 11 and 12 are flowcharts showing an example of the operation of the risk management support device according to the present disclosure.
[0146] An example of the operation of the risk management support device 102 according to the fourth embodiment of the present disclosure will be described in detail below with reference to FIGS. 11 and 12. FIG.
[0147] 11 and 12 are compared with Fig. 9 in that the operations of steps S301 and S302 are performed between the operations of steps S103 and S203. The operations of the other steps in Fig. 11 and 12 are the same as the operations of the steps with the same reference numerals in Fig. 9.
[0148] In step S301, the hypothetical vulnerability determination unit 180 determines hypothetical vulnerabilities of the end-of-support device.
[0149] In step S302, the path estimation unit 170 estimates a communication path using information on the discovered vulnerability and information on the hypothetical vulnerability.
[0150] <Effects> This embodiment has the same effects as the first embodiment, for the same reasons as those for the effects of the first embodiment.
[0151] <Other Embodiments> The risk management support device according to the present disclosure can be realized by a computer including a memory into which a program read from a storage medium is loaded and a processor that executes the program. The risk management support device according to the present disclosure can also be realized by dedicated hardware. The risk management support device according to the present disclosure can also be realized by a combination of the above-mentioned computer and dedicated hardware. Examples of the risk management support device according to the present disclosure include the risk management support device 10, the risk management support device 100, the risk management support device 101, and the risk management support device 102.
[0152] FIG. 13 is a diagram illustrating an example of the hardware configuration of a computer 1000 capable of realizing the risk management support device according to the present disclosure. In the example illustrated in FIG. 13, the computer 1000 includes a processor 1001, a memory 1002, a storage device 1003, and an I / O (Input / Output) interface 1004. The computer 1000 can also access a storage medium 1005. The memory 1002 and the storage device 1003 are, for example, storage devices such as RAM (Random Access Memory) and a hard disk. The storage medium 1005 is, for example, a storage device such as RAM or a hard disk, a ROM (Read Only Memory), or a portable storage medium. The storage device 1003 may also be the storage medium 1005. The processor 1001 can read and write data and programs from and to the memory 1002 and the storage device 1003. The processor 1001 can access, for example, other information processing devices via the I / O interface 1004. The processor 1001 can access a storage medium 1005. The storage medium 1005 stores a program that causes the computer 1000 to operate as a risk management support device according to the present disclosure.
[0153] The processor 1001 loads a program stored in the storage medium 1005, which causes the computer 1000 to operate as the risk management support device according to the present disclosure, into the memory 1002. Then, the processor 1001 executes the program loaded into the memory 1002, causing the computer 1000 to operate as the risk management support device according to the present disclosure.
[0154] The configuration information receiving unit 110, the device information receiving unit 120, the score calculation unit 130, the output information generation unit 140, the output unit 150, the risk value determination unit 160, the path estimation unit 170, and the virtual vulnerability determination unit 180 can be realized, for example, by a processor 1001 that executes a program loaded into memory 1002. Some or all of the configuration information receiving unit 110, the device information receiving unit 120, the score calculation unit 130, the output information generation unit 140, the output unit 150, the risk value determination unit 160, the path estimation unit 170, and the virtual vulnerability determination unit 180 can be realized by dedicated circuits.
[0155] Furthermore, some or all of the above-described embodiments can be described as, but are not limited to, the following supplementary notes.
[0156] (Supplementary Note 1) A risk management support device comprising: a score calculation means for calculating a replacement score representing the degree of need to replace a path device among the plurality of devices that exists on the communication path based on information on the communication path between an intrusion device and an attack target device and information on the security support expiration date of the plurality of devices in an information processing system including a plurality of devices and a communication network connecting the plurality of devices; and an output means for outputting information on the path device in a manner corresponding to the replacement score of the path device.
[0157] (Supplementary Note 2) A risk management support device as described in Supplementary Note 1, comprising: an output information generation means for generating output information including a route display showing the communication route, the route display including a device display showing the route devices through which the communication route passes in a manner corresponding to the replacement score of the route devices, and a connection display showing the connection by the communication route between the devices to which the communication route connects, wherein the output means outputs the output information as information of the route devices.
[0158] (Supplementary Note 3) The risk management support device described in Supplementary Note 2, wherein the output information generation means generates the output information that shows, in different forms, the device display of an end route device, which is the route device for which support has ended, and the device display of a continuing route device, which is the route device for which support has not ended.
[0159] (Supplementary Note 4) The risk management support device described in Supplementary Note 2 or 3, wherein the output information generation means generates the output information including the device display of the route device in a manner according to the length of the period until the support for the route device ends.
[0160] (Appendix 5) The risk management support device described in Appendix 3, wherein the output information generation means generates the output information that shows the end path device, the continuation path device, and a non-path device, which is a device among the plurality of devices that is not on the communication path, in different forms.
[0161] (Supplementary Note 6) The risk management support device according to Supplementary Note 3, wherein the score calculation means calculates the replacement score so that the replacement score of the end path device is different from the replacement score of the continuing path device.
[0162] (Supplementary Note 7) The risk management support device according to Supplementary Note 4, wherein the score calculation means calculates the replacement score according to the length of time until the support of the route device ends.
[0163] (Appendix 8) The score calculation means calculates the replacement score so that the necessity indicated by the replacement score of a continuing path device that is a device on the communication path for which support has not ended is lower than the necessity indicated by the replacement score of an ending path device that is a device on the communication path for which support has ended. This is a risk management support device described in Appendix 1 or 2.
[0164] (Appendix 9) The risk management support device described in Appendix 8, wherein the score calculation means calculates the replacement score so that the necessity indicated by the replacement score of the continuation path device is not lower than the necessity indicated by the replacement score of another continuation path device whose period until support ends is longer than the period until support ends of the continuation path device.
[0165] (Supplementary Note 10) The risk management support device described in Supplementary Note 1 or 2, wherein the score calculation means calculates the replacement score of the route device by further using any of the period from ordering the other device to replacing the route device until delivery, the cost of the other device, and the period until depreciation of the route device is completed.
[0166] (Supplementary Note 11) A risk management support device as described in Supplementary Note 1 or 2, further comprising a risk value determination means that uses information about the communication path to determine a risk value that indicates the level of risk that the communication path will be used to attack the target device, wherein the score calculation means calculates the replacement score of the path device using any of the period from ordering to delivery of another device that replaces the path device, the cost of the other device, the period until depreciation of the path device is completed, and the risk value of the communication path that passes through the path device.
[0167] (Appendix 12) A risk management support device as described in Appendix 11, further comprising a virtual vulnerability determination means for determining virtual vulnerabilities, which are hypothetical vulnerabilities that will occur in the end path device after support for the end path device has ended, using information on vulnerabilities previously discovered in the end path device, which is the path device for which support has ended, and the risk value determination means further uses the virtual vulnerabilities to determine the risk value.
[0168] (Supplementary Note 13) The risk management support device described in Supplementary Note 1 or 2 further comprises: a virtual vulnerability determination means for determining virtual vulnerabilities, which are hypothetical vulnerabilities that will occur in an end-of-support device after support for the end-of-support device has ended, using information on vulnerabilities previously discovered in the end-of-support device, which is a device for which support has ended, among the plurality of devices; and a path estimation means for estimating the communication path using information on vulnerabilities discovered in the plurality of devices and information on the virtual vulnerabilities of the end-of-support device.
[0169] (Supplementary Note 14) A risk management support method, in an information processing system including a plurality of devices and a communication network connecting the plurality of devices, which calculates a replacement score representing the degree of need to replace a path device among the plurality of devices that exists on the communication path based on information about the communication path between an intrusion device and an attack target device and information about the expiration date of security support for the plurality of devices, the replacement score representing the degree of need to replace the path device in accordance with the expiration date of support, and outputs information about the path device in a manner corresponding to the replacement score of the path device.
[0170] (Appendix 15) A risk management support method as described in Appendix 14, which generates output information including a route display showing the communication route, the route display including a device display showing the route device through which the communication route passes in a manner corresponding to the replacement score of the route device, and a connection display showing the connection by the communication route between the devices to which the communication route connects, and outputs the output information as information about the route device.
[0171] (Supplementary Note 16) A risk management support method according to Supplementary Note 15, wherein the output information is generated to show, in different forms, the device display of an end route device, which is the route device for which support has ended, and the device display of a continuing route device, which is the route device for which support has not ended.
[0172] (Supplementary Note 17) The risk management support method according to Supplementary Note 15 or 16, wherein the output information including the device display of the route device is generated in a manner according to the length of the period until the support of the route device ends.
[0173] (Supplementary Note 18) The risk management support method described in Supplementary Note 16, wherein the output information is generated to show the end path device, the continuation path device, and non-path devices among the plurality of devices that are not on the communication path in different forms.
[0174] (Supplementary Note 19) The risk management support method according to Supplementary Note 16, wherein the replacement score is calculated such that the replacement score of the end path device and the replacement score of the continuing path device are different.
[0175] (Supplementary Note 20) The risk management support method according to Supplementary Note 17, wherein the replacement score is calculated according to the length of time until the support of the route device ends.
[0176] (Appendix 21) A risk management support method described in Appendix 14 or 15, in which the replacement score is calculated so that the necessity indicated by the replacement score of a continuing path device that is a device on the communication path for which support has not ended is lower than the necessity indicated by the replacement score of an ending path device that is a device on the communication path for which support has ended.
[0177] (Appendix 22) A risk management support method as described in Appendix 21, in which the replacement score of the continuation path device is calculated so that the necessity indicated by the replacement score is not lower than the necessity indicated by the replacement score of another continuation path device whose period until support ends is longer than the period until support ends of the continuation path device.
[0178] (Supplementary Note 23) The risk management support method described in Supplementary Note 14 or 15, wherein the replacement score of the route device is calculated using any one of the period from ordering to delivery of another device that replaces the route device, the cost of the other device, and the period until depreciation of the route device is completed.
[0179] (Supplementary Note 24) A risk management support method as described in Supplementary Note 14 or 15, which uses information about the communication path to determine a risk value representing the level of risk that the communication path will be used to attack the target device, and calculates the replacement score of the path device using any of the period from ordering to delivery of another device that replaces the path device, the cost of the other device, the period until depreciation of the path device is completed, and the risk value of the communication path that passes through the path device.
[0180] (Appendix 25) A risk management support method as described in Appendix 24, which uses information on vulnerabilities previously discovered in an end path device, which is the path device for which support has ended, to determine virtual vulnerabilities, which are hypothetical vulnerabilities that will occur in the end path device after support for the end path device has ended, and further uses the virtual vulnerabilities to determine the risk value.
[0181] (Supplementary Note 26) A risk management support method as described in Supplementary Note 14 or 15, comprising: determining virtual vulnerabilities, which are hypothetical vulnerabilities that will occur in an end-of-support device after support for the end-of-support device has ended, using information on vulnerabilities previously discovered in the plurality of devices, which are devices for which support has ended; and estimating the communication path using information on vulnerabilities discovered in the plurality of devices and information on the virtual vulnerabilities of the end-of-support device.
[0182] (Supplementary Note 27) A storage medium storing a program that causes a computer to execute the following steps: a score calculation process that calculates a replacement score representing the degree of need to replace a path device among the plurality of devices that exists on the communication path based on information on the communication path between an intrusion device and an attack target device and information on the expiration date of security support for the plurality of devices in an information processing system including a plurality of devices and a communication network connecting the plurality of devices; and an output process that outputs information on the path device in a manner corresponding to the replacement score of the path device.
[0183] (Appendix 28) The program causes a computer to execute an output information generation process to generate output information including a route display showing the communication route, the route display including a device display showing the route devices through which the communication route passes in a manner corresponding to the replacement score of the route device, and a connection display showing the connection by the communication route between the devices to which the communication route connects, and the output process outputs the output information as information of the route devices.
[0184] (Supplementary Note 29) The storage medium described in Supplementary Note 28, wherein the output information generation process generates the output information that shows, in different forms, the device display of an end path device, which is the path device for which support has ended, and the device display of a continuing path device, which is the path device for which support has not ended.
[0185] (Supplementary Note 30) The storage medium according to Supplementary Note 28 or 29, wherein the output information generation process generates the output information including the device display of the route device in a manner according to the length of time until the support of the route device ends.
[0186] (Supplementary Note 31) The storage medium described in Supplementary Note 29, wherein the output information generation process generates the output information that indicates the end path device, the continuation path device, and a non-path device that is one of the plurality of devices and is not present on the communication path in different forms.
[0187] (Supplementary Note 32) The storage medium according to Supplementary Note 29, wherein the score calculation process calculates the replacement score such that the replacement score of the end path device is different from the replacement score of the continuing path device.
[0188] (Supplementary Note 33) The storage medium according to Supplementary Note 30, wherein the score calculation process calculates the replacement score according to a length of time until the support of the route device ends.
[0189] (Appendix 34) The score calculation process calculates the replacement score so that the necessity indicated by the replacement score of a continuing path device that is a device on the communication path and whose support has not ended is lower than the necessity indicated by the replacement score of an ending path device that is a device on the communication path and whose support has not ended. A storage medium as described in Appendix 27 or 28.
[0190] (Appendix 35) The score calculation process calculates the replacement score so that the necessity indicated by the replacement score of the continuing path device is not lower than the necessity indicated by the replacement score of another continuing path device whose support period is longer than the support period of the continuing path device. (Appendix 35) The storage medium described in Appendix 34.
[0191] (Appendix 36) The storage medium described in Appendix 27 or 28, wherein the score calculation process calculates the replacement score of the route device by further using any one of the period from ordering another device to replacing the route device until delivery, the cost of the other device, and the period until depreciation of the route device is completed.
[0192] (Appendix 37) The program further causes the computer to execute a risk value determination process that uses information about the communication path to determine a risk value that indicates the level of risk that the communication path will be used to attack the target device, and the score calculation process calculates the replacement score of the path device using any of the period from ordering to delivery of another device that replaces the path device, the cost of the other device, the period until depreciation of the path device is completed, and the risk value of the communication path that passes through the path device. (Appendix 37) The storage medium described in Appendices 27 or 28.
[0193] (Appendix 38) The program further causes the computer to execute a virtual vulnerability determination process that determines virtual vulnerabilities, which are hypothetical vulnerabilities that will occur in the end path device after support for the end path device has ended, using information on vulnerabilities previously discovered in the end path device, which is the path device for which support has ended; and the risk value determination process further uses the virtual vulnerabilities to determine the risk value.
[0194] (Supplementary Note 39) The storage medium described in Supplementary Note 27 or 28, wherein the program further causes a computer to execute: a virtual vulnerability determination process that determines virtual vulnerabilities, which are hypothetical vulnerabilities that will occur in an end-of-support device after support for the end-of-support device has ended, using information on vulnerabilities that have been discovered in the plurality of devices and information on the virtual vulnerabilities of the end-of-support device, among the plurality of devices; and a path estimation process that estimates the communication path using information on vulnerabilities that have been discovered in the plurality of devices and information on the virtual vulnerabilities of the end-of-support device.
[0195] Although the present disclosure has been described above with reference to the embodiments, the present disclosure is not limited to the above embodiments. Various modifications that can be understood by those skilled in the art can be made to the configuration and details of the present disclosure within the scope of the present disclosure.
[0196] 10 Risk management support device 100 Risk management support device 101 Risk management support device 102 Risk management support device 110 Configuration information receiving unit 120 Device information receiving unit 130 Score calculation unit 140 Output information generating unit 150 Output unit 160 Risk value determining unit 170 Path estimating unit 180 Virtual vulnerability determining unit 1000 Computer 1001 Processor 1002 Memory 1003 Storage device 1004 I / O interface 1005 Storage medium
Claims
1. A risk management support device comprising: a score calculation means for calculating a replacement score representing the degree of need to replace a path device among the plurality of devices that exists on the communication path based on information on the communication path between an intrusion device and an attack target device and information on the expiration date of security support for the plurality of devices in an information processing system including a plurality of devices and a communication network connecting the plurality of devices; and an output means for outputting information on the path device in a manner corresponding to the replacement score of the path device.
2. A risk management support device as described in claim 1, comprising an output information generation means for generating output information including a route display showing the communication route, the route display including a device display showing the route devices through which the communication route passes in a manner corresponding to the replacement score of the route devices, and a connection display showing the connection by the communication route between the devices to which the communication route connects, wherein the output means outputs the output information as information on the route devices.
3. The risk management support device according to claim 2, wherein the output information generation means generates output information that shows, in different forms, the device display of an end route device, which is the route device for which support has ended, and the device display of a continuing route device, which is the route device for which support has not ended.
4. A risk management support device as described in claim 2 or 3, wherein the output information generation means generates the output information including the device display of the route device in a manner corresponding to the length of the period until the support of the route device ends.
5. The risk management support device described in claim 3, wherein the output information generation means generates the output information in a manner that indicates the end path device, the continuation path device, and non-path devices, which are devices among the plurality of devices that are not present on the communication path, in different forms.
6. A risk management support device as described in claim 3, wherein the score calculation means calculates the replacement score so that the replacement score of the end path device is different from the replacement score of the continuing path device.
7. The risk management support device according to claim 4, wherein the score calculation means calculates the replacement score according to the length of time until the support for the route device ends.
8. The risk management support device of claim 1 or 2, wherein the score calculation means calculates the replacement score so that the necessity indicated by the replacement score of a continuing path device, which is a device on the communication path for which support has not ended, is lower than the necessity indicated by the replacement score of an ending path device, which is a device on the communication path for which support has ended.
9. The risk management support device of claim 8, wherein the score calculation means calculates the replacement score so that the necessity indicated by the replacement score of the continuation path device is not lower than the necessity indicated by the replacement score of another continuation path device whose period until support ends is longer than the period until support ends of the continuation path device.
10. The risk management support device according to claim 1 or 2, wherein the score calculation means calculates the replacement score of the route device by further using any one of the period from ordering the other device to delivery to replace the route device, the cost of the other device, and the period until depreciation of the route device is completed.
11. A risk management support device as described in claim 1 or 2, further comprising a risk value determination means for using information on the communication path to determine a risk value representing the level of risk that the communication path will be used to attack the target device, wherein the score calculation means calculates the replacement score of the path device using any of the period from ordering to delivery of another device that replaces the path device, the cost of the other device, the period until depreciation of the path device is completed, and the risk value of the communication path that passes through the path device.
12. A risk management support device as described in claim 11, further comprising a virtual vulnerability determination means for determining virtual vulnerabilities, which are hypothetical vulnerabilities that will occur in the end path device after support for the end path device has ended, using information on vulnerabilities previously discovered in the end path device, which is the path device for which support has ended, and wherein the risk value determination means further uses the virtual vulnerabilities to determine the risk value.
13. A risk management support device as described in claim 1 or 2, further comprising: a virtual vulnerability determination means for determining virtual vulnerabilities, which are hypothetical vulnerabilities that will occur in an end-of-support device after support for the end-of-support device has ended, using information on vulnerabilities previously discovered in the end-of-support device, among the plurality of devices; and a route estimation means for estimating the communication route using information on vulnerabilities discovered in the plurality of devices and information on the virtual vulnerabilities of the end-of-support device.
14. A risk management support method in an information processing system including a plurality of devices and a communication network connecting the plurality of devices, which calculates a replacement score representing the degree of need to replace a path device among the plurality of devices that exists on the communication path based on information about the communication path between an entry device and an attack target device and information about the expiration date of security support for the plurality of devices, in accordance with the expiration date of the support, and outputs information about the path device in a manner corresponding to the replacement score of the path device.
15. A risk management support method as described in claim 14, wherein output information including a route display showing the communication route, the route display including a device display showing the route device through which the communication route passes in a manner corresponding to the replacement score of the route device, and a connection display showing the connection by the communication route between the devices to which the communication route connects, is generated, and the output information is output as information on the route device.
16. The risk management support method according to claim 15, wherein the output information is generated to show, in different ways, the device display of an end route device, which is the route device for which support has ended, and the device display of a continuing route device, which is the route device for which support has not ended.
17. A risk management support method according to claim 15 or 16, wherein the output information including the device display of the route device is generated in a manner according to the length of the period until the support of the route device ends.
18. The risk management support method according to claim 16, wherein the output information is generated to indicate, in different ways, the end path device, the continuation path device, and non-path devices, which are devices among the plurality of devices that are not present on the communication path.
19. The risk management support method according to claim 16, wherein the replacement score is calculated so that the replacement score of the end path device is different from the replacement score of the continuing path device.
20. A storage medium storing a program that causes a computer to execute the following steps in an information processing system including a plurality of devices and a communication network connecting the plurality of devices: a score calculation process that calculates a replacement score representing the degree of need to replace a path device present on the communication path among the plurality of devices, based on information on the communication path between an intrusion device and an attack target device and information on the expiration date of security support for the plurality of devices, in accordance with the expiration date of the support; and an output process that outputs information on the path device in a manner according to the replacement score of the path device.
Citation Information
Patent Citations
Importance acquisition device, security-design support system, relevance acquisition device, and program
JP2006350399A
Replacement decision support system and replacement decision support method
JP2008242792A
Security measure planning support system and method
JP2018077597A