Risk management support device, risk management support method, and storage medium

WO2025186969A8PCT designated stage Publication Date: 2025-10-02NEC CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2024/008639
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-03-07
Publication Date
2025-10-02

AI Technical Summary

Technical Problem

Existing risk management systems fail to provide information on devices that can be routes for attacks on other devices in an information processing system and prioritize security measures based on the impact of such attacks.

Method used

A risk management support device identifies target devices through which communication paths pass and whose security measures do not meet standards, determining the total impact of potential attacks on these devices and outputs information accordingly.

Benefits of technology

Provides information on devices that can be attack routes and prioritizes security measures based on the extent of business impact, enhancing risk management in information processing systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2024008639_02102025_PF_FP_ABST
    Figure JP2024008639_02102025_PF_FP_ABST
Patent Text Reader

Abstract

Provided are a risk management support device and the like capable of providing information about devices which can form a route for attacks on other devices in an information processing system and for which security measures are to be taken on a priority basis according to the magnitude of impact on business by the attacks on the other devices through the devices. A risk management support device according to one aspect of the present disclosure is provided with: a target device identification means that, from information about a communication path that can be an attack route from an intrusion entry device to attack target devices in an information processing system including a plurality of devices and a communication network connecting the plurality of devices, and information about the security states of the plurality of devices, identifies a target device through which the communication path passes and the security state of which does not satisfy a criterion, among the plurality of devices; an impact level determination means that, from impact level information representing the magnitude of impact on business of the stoppage of the attack target devices due to attacks, determines a total impact level, which is the sum of the impact levels for the attack target devices, which can be targets of attacks via the communication path that passes through the target device; and an output means that outputs information indicating the target device in a manner corresponding to the total impact level.
Need to check novelty before this filing date? Find Prior Art

Description

Risk management support device, risk management support method, and storage medium

[0001] The present disclosure relates to a risk management support device, a risk management support method, and a storage medium.

[0002] For example, in an information processing system managed by an organization such as a company, which includes multiple devices such as information processing devices connected to each other via a communication network, if a device is attacked, the business may be affected.

[0003] Patent Literature 1 describes an estimation device that estimates the risk of a device being attacked on a network based on attribute information of the device and observed events that have occurred on the device. The estimation device also describes an estimation device that estimates the impact of an attack on the device on business related to services provided by the network, based on the estimated risk of the device being attacked.

[0004] International Publication No. 2020 / 100570

[0005] The technology of Patent Document 1 can estimate the impact on business caused by an attack on a device in a network. However, the technology of Patent Document 1 cannot provide information on devices that can be a route for attacks on other devices in an information processing system, and on which devices security measures should be prioritized depending on the impact on business caused by an attack on other devices via that device.

[0006] One of the purposes of the present disclosure is to provide a risk management support device, a risk management support method, and a storage medium that can provide information on devices that can be a route for attacks on other devices in an information processing system, and for which security measures should be given priority depending on the extent of the impact on business of attacks on other devices that pass through the device.

[0007] A risk management support device according to one aspect of the present disclosure comprises: a target device identification means for identifying a target device among the plurality of devices, which is a device through which the communication path passes and for which the implemented security measures do not meet standards, based on information on communication paths that could be a route for an attack from an entry device to an attack target device in an information processing system including a plurality of devices and a communication network connecting the plurality of devices; an impact determination means for determining a total impact, which is the sum of the impacts of the attack target devices that could be the target of an attack via the communication path that passes through the target device, based on information on the impact that indicates the magnitude of the impact that the shutdown of the attack target device due to an attack would have on a business; and an output means for outputting information indicating the target device in a manner corresponding to the total impact.

[0008] A risk management support method according to one aspect of the present disclosure, in an information processing system including a plurality of devices and a communication network connecting the plurality of devices, identifies a target device among the plurality of devices through which the communication path passes and whose security state does not meet a standard, based on information on the communication path that can be a route for an attack from an entry device to a target device and information on the security state of the plurality of devices, determines a total impact, which is the sum of the impacts of the target devices that can be the target of an attack via the communication path that passes through the target device, based on information on the impact that indicates the magnitude of the impact on the business of the shutdown of the target device due to an attack, and outputs information indicating the target device in a manner corresponding to the total impact.

[0009] A storage medium according to one aspect of the present disclosure stores a program that causes a computer to execute the following steps in an information processing system including a plurality of devices and a communication network connecting the plurality of devices: a target device identification process that identifies, from the plurality of devices, a target device through which the communication path passes and whose security state does not meet a standard, based on information on a communication path that can be a path for an attack from the entry device to the target device and information on the security status of the plurality of devices; an impact determination process that determines, from information on impact that indicates the magnitude of the impact that a shutdown of the target device due to an attack would have on a business, a total impact that is the sum of the impacts of the target devices that can be the target of an attack via the communication path that passes through the target device; and an output process that outputs information indicating the target device in a manner corresponding to the total impact. One aspect of the present disclosure can also be realized by the program stored in the storage medium.

[0010] The present disclosure has the effect of being able to provide information on devices that can be a route for attacks on other devices in an information processing system, and for which security measures should be given priority depending on the extent of the impact on business of attacks on other devices that pass through the device.

[0011] FIG. 1 is a block diagram illustrating an example of the configuration of a risk management support device according to the present disclosure. FIG. 2 is a flowchart illustrating an example of the operation of a risk management support device according to the present disclosure. FIG. 3 is a block diagram illustrating an example of the configuration of a risk management support device according to the present disclosure. FIG. 4 is a flowchart illustrating an example of the operation of a risk management support device according to the present disclosure. FIG. 5 is a flowchart illustrating an example of the operation of a risk management support device according to the present disclosure. FIG. 6 is a diagram illustrating an example of output information according to the present disclosure. FIG. 7 is a block diagram illustrating an example of the configuration of a risk management support device according to the present disclosure. FIG. 8 is a flowchart illustrating an example of the operation of a risk management support device according to the present disclosure. FIG. 9 is a diagram illustrating an example of the output information of a risk management support device according to the present disclosure. FIG. 10 is a block diagram illustrating an example of the configuration of a risk management support device according to the present disclosure. FIG. 11 is a flowchart illustrating an example of the operation of a risk management support device according to the present disclosure. FIG. 12 is a flowchart illustrating an example of the operation of a risk management support device according to the present disclosure. FIG. 13 is a diagram illustrating an example of the hardware configuration of a computer that can realize a risk management support device according to the present disclosure.

[0012] Next, embodiments of the present disclosure will be described in detail with reference to the drawings.

[0013] First Embodiment First, a first embodiment of the present disclosure will be described in detail with reference to the drawings.

[0014] <Configuration> First, the configuration of the risk management support device according to the first embodiment of the present disclosure will be described in detail with reference to the drawings.

[0015] FIG. 1 is a block diagram illustrating an example of the configuration of a risk management support device according to the present disclosure.

[0016] The configuration of the risk management support device according to the first embodiment of the present disclosure will be described in detail below with reference to FIG.

[0017] In the example shown in FIG. 1, the risk management support device 10 according to this embodiment includes a target device specifying unit 130 , an influence degree determining unit 140 , and an output unit 160 .

[0018] <Target device identification unit 130> The target device identification unit 130 identifies a target device based on information about communication paths that could be attack routes from an entry device to an attack target device in an information processing system and information about the security status of multiple devices. The information processing system includes multiple devices and a communication network connecting the multiple devices. A target device is one of the multiple devices through which a communication path passes and whose security status does not meet a standard.

[0019] <Impact determination unit 140> The impact determination unit 140 determines a total impact, which is the sum of the impacts of attack target devices that could be targets of attacks via communication paths that pass through the target device, from impact information that indicates the extent to which the shutdown of the attack target device due to an attack will affect the business.

[0020] <Output Unit 160> The output unit 160 outputs information indicating the target device in a format according to the total influence degree.

[0021] In the present disclosure, the multiple devices included in the information processing system include information processing devices such as a server and an information processing terminal. The multiple devices may also include a device for security measures. The device for security measures is, for example, a firewall (FW) device that functions as a firewall, a unified threat management (UTM) device, etc. The unified threat management device is, for example, a device that has functions such as a firewall, antivirus, antispam, intrusion prevention, and content filtering. The unified threat management device may also have other functions such as a virtual private network (VPN). Hereinafter, the firewall device will also be simply referred to as FW. Hereinafter, the unified threat management device will also be simply referred to as UTM. In the present disclosure, the device for security measures will also be referred to as a countermeasure device.

[0022] In the present disclosure, among multiple devices included in an information processing system, a device for which security measures have been implemented is referred to as a countermeasure-completed device. In the present disclosure, the countermeasure-completed device includes an information processing device for which security measures have been implemented, a device for security measures (hereinafter also referred to as a countermeasure-specific device), etc. The countermeasure-completed device may be, among devices such as an information processing device for which security measures have been implemented and a device for security measures (hereinafter also referred to as a countermeasure-specific device), a device whose security settings meet standards. A device for which support has ended (i.e., a device for which the support period has expired) may be excluded from the countermeasure-completed devices. A device for which the length of time until support ends is less than a predetermined length may be excluded from the countermeasure-completed devices.

[0023] In the present disclosure, an intrusion device is a device (e.g., an information processing device) that is designated in advance as a device that will be an intrusion point for an attack among a plurality of devices. An attack target device is a device (e.g., an information processing device) that is designated in advance as a device that will be the target of an attack among a plurality of devices. An intrusion device is a device separate from the attack target device. In this embodiment, information on the intrusion device and the attack target device is given in advance. The number of intrusion devices does not have to be one. The number of attack target devices does not have to be one. The number of combinations of intrusion devices and attack target devices does not have to be one.

[0024] In the present disclosure, a communication path is a communication path that can be an attack path in an attack from an intrusion device to an attack target device. A communication path is expressed as a communication path that connects multiple devices, including an intrusion device and an attack target device, in series. Multiple communication paths may exist in an information processing system. One device may be included in multiple communication paths. In the present disclosure, a communication path between an intrusion device and an attack target device, in which the devices through which the communication path passes do not match, is a different communication path. A communication path between an intrusion device and an attack target device, in which the order of the devices through which the communication path passes does not match, is a different communication path. In this embodiment, information about the communication path is given in advance.

[0025] In the present disclosure, the security status criterion may be expressed by, for example, one or more conditions. The target device identification unit 130 may determine that the security status criterion is satisfied when the security status of the device satisfies all of the conditions that represent the security status criterion. The security status criterion may be expressed by a logical expression of one or more conditions. The target device identification unit 130 may determine that the security status of the device satisfies the logical expression that represents the security status criterion.

[0026] The condition may include, for example, that the length of time until the support expiration date of the device is equal to or greater than a predetermined non-zero period. The condition may include, for example, that all security updates for software controlling the device have been performed. The condition may include, for example, that the device is a countermeasure device or an information processing device on which security countermeasure software is running. The condition may include, for example, that predetermined settings for security countermeasures have been performed. The predetermined settings for security countermeasures may be determined for each type of device. The predetermined settings for security countermeasures may be determined according to the type of other device communicatively connected to the device. The predetermined settings for security countermeasures may be determined according to the arrangement of the device in the information processing system. The predetermined settings for security countermeasures may be determined for each device.

[0027] In the present disclosure, the impact level, which indicates the magnitude of the impact on business caused by the shutdown of the target device due to an attack, is also simply referred to as the impact level of the target device.

[0028] The impact of the target device, i.e., the impact indicating the magnitude of the impact on business of the shutdown of the target device due to an attack, may be expressed, for example, by the sales amount of a product whose production is affected by the shutdown of the target device due to an attack. The impact may be expressed, for example, by the total sales amount of a product whose production is affected by the shutdown of the target device due to an attack and other products into which that product is incorporated. The impact is not limited to these examples. Other examples of impact will be described in detail later.

[0029] The information of a device (including a target device) output by the output unit 160 is information such as a character string that identifies the device, such as a name, identification information, or a combination thereof. The device information may be a combination of information that identifies the device and a graphic such as a rectangle. The device information is also referred to as information indicating the device and a device display.

[0030] In the present disclosure, an aspect refers to, for example, a combination of information indicating a device, such as a graphic color, a graphic pattern (in other words, a texture), a line color, a line type, a line thickness, a character color, a character type, and a character thickness.

[0031] The information of the target device output by the output unit 160 may be information of the target device generated as an image. In the present disclosure, information output by the output unit 160 (e.g., information representing information of a path device through which a communication path passes) is referred to as output information. The output information is, for example, a screen (referred to as output screen) or an image (referred to as output image).

[0032] <Operation> Next, the operation of the risk management support device 10 according to the first embodiment of the present disclosure will be described in detail with reference to the drawings.

[0033] FIG. 2 is a flowchart illustrating an example of the operation of the risk management support device according to the present disclosure.

[0034] Hereinafter, the operation of the risk management support device 10 according to the first embodiment of the present disclosure will be described in detail with reference to FIG.

[0035] 2, first, the target device identification unit 130 identifies a target device based on information on communication paths that can be attack paths from an entry device in the information processing system to an attack target device and information on security measures implemented in multiple devices (step S11). The target device is a device through which a communication path passes and for which the implemented security measures do not meet the criteria.

[0036] Next, the impact determination unit 140 determines a total impact, which is the sum of the impacts of the target devices that could be the target of an attack via a communication path passing through the target device, from the impact information that indicates the extent to which the shutdown of the target device due to an attack will affect the business (step S12).

[0037] Then, the output unit 160 outputs information indicating the target device in a format according to the total influence degree (step S12).

[0038] <Effect> This embodiment has the effect of being able to provide information on devices that can be a route for attacks on other devices in an information processing system, and for which security measures should be given priority depending on the extent of the impact on business of attacks on other devices that pass through the device.

[0039] This is because the target device identification unit 130 identifies target devices that are devices through which communication paths pass and for which implemented security measures do not meet standards. The impact determination unit 140 then determines a total impact, which is the sum of the impacts of attack target devices that could be targets of attacks via communication paths that pass through the target device. The impact of the attack target device represents the magnitude of the impact on business that the shutdown of the attack target device due to an attack would have. The output unit 160 then outputs information indicating the target device in a manner corresponding to the total impact.

[0040] Second Embodiment Next, a second embodiment of the present disclosure will be described in detail with reference to the drawings.

[0041] <Configuration> First, the configuration of a risk management support device according to a second embodiment of the present disclosure will be described in detail with reference to the drawings.

[0042] FIG. 3 is a block diagram illustrating an example of the configuration of a risk management support device according to the present disclosure.

[0043] The configuration of the risk management support device according to the second embodiment of the present disclosure will be described in detail below with reference to FIG.

[0044] In the example shown in Figure 3, the risk management support device 100 includes a configuration information receiving unit 110, a device information receiving unit 120, a target device identification unit 130, an impact determination unit 140, an output information generation unit 150, an output unit 160, and a sales information storage unit 180.

[0045] <Configuration Information Receiving Unit 110> The configuration information receiving unit 110 receives information about the configuration of the information processing system.

[0046] The configuration information receiving unit 110 receives information about the configuration of the information processing system, for example, from another information processing device that holds information about the configuration of the information processing system. The information about the configuration of the information processing system includes information about the devices included in the information processing system and information about the connections between the devices and other devices. The device information includes, for example, information that identifies the device and information about the type of device.

[0047] The information on the configuration of the information processing system also includes information indicating an entry point device and information indicating an attack target device among the devices included in the information processing system.

[0048] The information on the configuration of the information processing system further includes information on the above-mentioned communication paths that can be the attack paths from the entry device to the target device.

[0049] The information about the configuration of the information processing system may include information indicating whether the device is included in a boundary network (in other words, whether the device is connected to the boundary network) or whether the device is included in a business network (in other words, whether the device is connected to the business network). A business network refers to, for example, an internal communication network that is protected by security in an organizational network such as a company. A boundary network refers to, for example, a communication network that exists between the outside of the organizational network and the organization's business network.

[0050] <Device Information Receiving Unit 120> The device information receiving unit 120 receives device information, including security status information, for each of a plurality of devices included in the information processing system. The device information receiving unit 120 receives device information from another information processing device that holds the device information.

[0051] <Target Device Identification Unit 130> As described above, the target device identification unit 130 identifies a target device based on information about communication paths that could be attack routes from an entry device to an attack target device in an information processing system and information about the security status of multiple devices. The information processing system includes multiple devices and a communication network connecting the multiple devices. A target device is one of the multiple devices through which a communication path passes and whose security status does not meet a standard.

[0052] That is, the target device identifying unit 130 of this embodiment has the same functions as the target device identifying unit 130 of the first embodiment. The target device identifying unit 130 of this embodiment performs the same operations as the target device identifying unit 130 of the first embodiment.

[0053] Specifically, the target device identification unit 130 may first identify path devices that are devices on a communication path from an entry device of the information processing system to an attack target device. Among the identified path devices, the target device identification unit 130 may identify a path device whose security status does not satisfy a standard as a target device.

[0054] The target device identification unit 130 may identify a device whose security state does not satisfy a standard among a plurality of devices in the information processing system. The target device identification unit 130 may identify, as a target device, a path device that is a device on a communication path from an intrusion device of the information processing system to an attack target device among the devices whose security state does not satisfy a standard.

[0055] <Impact determination unit 140> As described above, the impact determination unit 140 determines a total impact, which is the sum of the impacts of the attack target devices that could be the target of an attack via a communication path that passes through the target device, from impact information that indicates the extent to which the shutdown of the attack target device due to an attack will have an impact on the business.

[0056] The impact determination unit 140 of this embodiment has the same functions as the impact determination unit 140 of the first embodiment. The impact determination unit 140 of this embodiment performs the same operations as the impact determination unit 140 of the first embodiment. The impact of this embodiment is the same as the impact of the first embodiment. As described above, the impact is not limited to the example described in the first embodiment. Other examples of the impact will be described in detail later.

[0057] <Output Information Generating Unit 150> The output information generating unit 150 generates output information including information on route devices in a format according to the total influence degree of the route devices.

[0058] The output information generating unit 150 may generate, as output information, an output display showing a path display indicating a communication path. This path display includes a device display indicating a target device through which the communication path passes, in a manner corresponding to the total influence of the target device. This path display may include a device display indicating a path device that is not a target device, in a manner different from the device display indicating the target device. Furthermore, this path display further includes a connection display indicating a connection by the communication path between devices connected by the communication path. The device display of a device (including the target device and other path devices) includes information such as a character string identifying the device, such as the device's name, identification information, or a combination thereof. The device display may be represented by a combination of information identifying the device and a shape such as a rectangle. The path display of a path may be represented by a line connecting two device displays connected by the path.

[0059] The output information generating unit 150 may generate output information including a device display of the target device to which the total impact value of the target device has been added. The device display to which the total impact value has been added is, for example, output information in which a character string indicating the total impact value is displayed within a predetermined distance from the device display. If the output information is an image, the predetermined distance may be expressed, for example, by the number of pixels. If the output information is expressed by text, the predetermined distance may be expressed, for example, by the number of characters.

[0060] The output information generation unit 150 may generate output information including a device display of the target device, to which a combination of information identifying the target device and an impact value has been added for each of the target devices that may be attacked via a communication path passing through the target device.

[0061] The relationship between the total impact and the aspect may be predetermined. The output information generating unit 150 may use the relationship between the total impact and the aspect to determine the aspect of the device display representing the path device from the total impact of the path device. The above relationship may be defined such that the greater the impact indicated by the total impact of the target device, the higher the priority of taking security measures for the target device (i.e., the higher the priority of implementing security measures for the target device). The aspect indicating the higher priority of taking security measures for the target device is, for example, a more prominent aspect.

[0062] The output information generating unit 150 may generate output information that does not include a device indication of a non-path device. When the total impact degree of the non-path devices has been determined, the output information generating unit 150 may generate output information that includes a device indication indicating the non-path device in a manner corresponding to the total impact degree of the non-path devices (i.e., a manner indicating that the implementation of security measures has the lowest priority).

[0063] The output information generation unit 150 may also generate output information including a display indicating the range of the business network and a display indicating the range of the boundary network from the business network information and the boundary network information included in the information on the configuration of the information processing system. The display indicating the range of the business network may be represented by a line surrounding the device display of the device included in the business network, or a graphic including the device display of the device included in the business network. The display indicating the range of the boundary network may be represented by a line surrounding the device display of the device included in the boundary network, or a graphic including the device display of the device included in the business network. If a device exists that is included in both the boundary network and the business network, the device display of that device may be included in both the display indicating the range of the boundary network and the display indicating the range of the business network. If a device exists that is included in both the boundary network and the business network, a portion of the device display of that device may be included in the display indicating the range of the boundary network, and another portion of the device display may be included in the display indicating the range of the business network.

[0064] The output information generating section 150 may generate, as output information, a list of target devices sorted in descending order of the total impact degree.

[0065] <Output unit 160> The output unit 160 outputs information of the target device in a manner according to the total impact of the target device. Specifically, the output unit 160 outputs the above-mentioned output information to a display device of the risk management support device 100 or the like. The output unit 160 may output to another information processing device. The output unit 160 may output to a storage device.

[0066] <Business Information Storage Unit 180> The business information storage unit 180 stores impact information, which is information on the degree of impact that the shutdown of an attack target device due to an attack will have on a business.

[0067] The business information storage unit 180 may store, for example, impact information including impact information indicating the extent to which a shutdown due to an attack will have an impact on the business of each of multiple devices included in the information processing system.

[0068] The impact determination unit 140 may read, from the sales information storage unit 180 , information on the impact of the attack target device, out of the impact information stored in the sales information storage unit 180 .

[0069] As described above, the output information generation unit 150 may be configured to generate output information including a device display of each target device that may be attacked via a communication path via the target device, to which a combination of information identifying the target device and an impact value has been added. In this case, the output information generation unit 150 reads the impact information of the target device from, for example, the sales information storage unit 180.

[0070] <Operation> Next, the operation of the risk management support device according to the second embodiment of the present disclosure will be described in detail with reference to the drawings.

[0071] 4 and 5 are flowcharts showing an example of the operation of the risk management support device according to the present disclosure.

[0072] Hereinafter, the operation of the risk management support device 100 according to the second embodiment of the present disclosure will be described in detail with reference to FIGS. 4 and 5. FIG.

[0073] In the example shown in FIG. 4, the configuration information receiving unit 110 receives information on the configuration of the information processing system (step S101). The device information receiving unit 120 receives information on security measures for multiple devices included in the information processing system (step S102). The target device identifying unit 130 identifies path devices, which are devices on a communication path from an entry device of the information processing system to an attack target device (step S103). The target device identifying unit 130 further identifies target devices among the path devices whose security status does not meet the criteria (step S104). The impact determining unit 140 identifies target attack target devices, which are attack target devices that may be the target of attacks via a communication path that passes through the target device (step S105). The risk management support device 100 then performs the operation of step S106 of FIG. 5.

[0074] 5, the impact determination unit 140 then identifies the impact, which is the magnitude of the impact that the shutdown of the identified attack target device will have on the business (step S106). The impact determination unit 140 then determines a total impact, which is the sum of the impacts of the shutdown of the target attack target devices (step S107). The output information generation unit 150 generates output information including a device display indicating the target device in a format corresponding to the total impact (step S108). The output unit 160 then outputs the output information including a device display indicating the target device in a format corresponding to the total impact (step S109).

[0075] <Example of Output Information> Fig. 6 is a diagram showing an example of output information according to the present disclosure. In the example shown in Fig. 6, for example, terminal A is an intrusion entrance device, server A is an attack target device, and terminal B is a target device.

[0076] <Effects> This embodiment has the same effects as the first embodiment, for the same reasons as those for the effects of the first embodiment.

[0077] <Other Examples of Impact Degree> The impact degree may be expressed by one or more indexes (specifically, index values) indicating the magnitude of the impact caused by the shutdown of the attack target device. Specifically, the index is an index that indicates the magnitude of the impact on the business of the shutdown of the attack target device, for example, due to the shutdown of the attack target device.

[0078] The impact determination unit 140 may determine the impact of the target device using one or more indicators indicating the magnitude of the impact of the shutdown of the target device. Specifically, the impact determination unit 140 may calculate a weighted sum of one or more indicators indicating the magnitude of the impact of the shutdown of the target device (specifically, a weighted sum of the values ​​of the indicators). The impact determination unit 140 may determine the calculated weighted sum as the impact of the target device. The weighted sum may be, for example, a sum, for one or more indicators, of the products of the values ​​of the indicators and predetermined weights for those indicators. The weighted sum may be, for example, a value obtained by dividing, for one or more indicators, the sum of the products of the values ​​of the indicators and predetermined weights for those indicators by the sum of the weights.

[0079] The indicators may include, for example, an indicator (referred to as a manufacturer impact indicator) that represents the magnitude of the impact on the product's manufacturer (e.g., the company that produces the product) and an indicator (referred to as a destination impact indicator) that represents the magnitude of the impact on the product's shipping destination.

[0080] The indicators may include economic impact indicators, which are indicators that represent the magnitude of impact that can be converted into a monetary value, and indicators that represent the magnitude of impact that cannot necessarily be converted into a monetary value (referred to as, for example, social impact indicators, non-economic impact indicators, etc. in this disclosure). In the example below, the social impact indicators are indicators that represent, for example, the decline in brand value, the impact on employee morale, and the magnitude of the environmental burden. Another indicator that can be expressed in monetary terms is the economic impact indicator.

[0081] The indicators may include, for example, an indicator (referred to as a product impact indicator in this disclosure) that indicates the magnitude of the impact of a change (e.g., a stoppage) in product production due to an attack on the target device, and an indicator (referred to as a countermeasure impact indicator) that indicates the magnitude of the impact of countermeasures to eliminate the impact of countermeasures due to an attack on the target device. In the example below, the countermeasure impact indicator is, for example, the cost of restarting the production line and the cost of countermeasures for security measures for the target device. The other indicators are product impact indicators.

[0082] Manufacturer impact indicators include, for example, product market share, product sales, product supply volume, excess product inventory, availability of alternative products, impact on employees, decline in brand value, impact on quality control, and impact on the environment (impact of disposing of defective products as waste). Manufacturer impact indicators may also include, for example, the cost of restarting the product's production line and the cost of security measures for the target device.

[0083] The product sales amount is, for example, the sales amount of the product during the period in which the target device is expected to be shut down by the attack. The product sales amount may include the sales amount of the product itself and the sales amount of other products of the manufacturer into which the product is incorporated. The value of the product sales index is determined so that the larger the sales amount, the greater the importance indicated by the index value.

[0084] The number of products supplied is, for example, the number of products supplied during the period in which the target device is expected to be shut down due to an attack. If the product is an embedded product that is incorporated into other products from the manufacturer, the sales revenue of the product itself may not be calculated. Even in such cases, the impact on the production of the product due to the target device being shut down due to an attack can be expressed by the number of products supplied. The value of the index for the number of products supplied is determined so that the greater the number of products supplied, the greater the importance indicated by the value of the index.

[0085] If the target device is attacked, the quality of the products produced may be reduced. The impact on quality control may be expressed, for example, by the amount of increase in costs for quality control of the products if the target device is attacked. The value of the index of the impact on quality control is determined such that, for example, the greater the amount of increase in costs for quality control of the products, the greater the importance represented by the index value.

[0086] Excess product inventory reduces the impact of product production being stopped when the production of the product is stopped due to an attack on the target device. Excess product inventory is an index that represents the degree to which the impact on business caused by the stoppage of product production is reduced. The value of the index for excess product inventory is determined so that the smaller the amount of excess inventory, the greater the importance indicated by the value of the index.

[0087] The presence or absence of a substitute product indicates the presence or absence of a substitute product that can be used in place of a product that is affected by an attack on the target device (for example, a product whose production will be halted). The value of the presence or absence of a substitute product may be determined so that the value of the index for the presence or absence of a substitute product when there is no substitute product indicates a greater impact than the value of the index for the presence or absence of a substitute product when there is a substitute product.

[0088] The manufacturer impact index may include an index indicating the cost of using a substitute product. The cost of using a substitute product is, for example, the amount of increase in cost when the substitute product is used instead of the product during the period in which the target device is expected to be shut down due to the attack. The use of a substitute product is, for example, using a substitute product instead of the product in a product into which the product is incorporated. The use of a substitute product may include, for example, shipping a substitute product instead of the product. The value of the index for the cost of using a substitute product is determined so that the greater the amount of increase in cost, the greater the importance indicated by the value of the index.

[0089] The impact on employees may be represented, for example, by the total amount of loss of income of employees involved in the production of products whose production is halted due to the shutdown of the attack target device during the period in which the attack target device is expected to be shut down. The impact on employees may be represented, for example, by the magnitude of the psychological impact that the shutdown of product production due to the shutdown of the attack target device has on employees. The magnitude of the psychological impact may be determined as appropriate in advance. The value of the index of impact on employees is determined so that the greater the magnitude of the impact on employees (e.g., the total amount of loss of income and the magnitude of the psychological impact), the greater the importance indicated by the index value.

[0090] The manufacturer impact index may include, for example, an index representing employment costs, which are the costs of employing employees involved in the production of products whose production will be halted due to the shutdown of the target device during the period in which the target device is expected to be shut down due to the attack. The value of the employment cost index is determined so that the greater the employment cost, the greater the importance indicated by the value of the index.

[0091] The manufacturer impact indicator may include, for example, an indicator of a loss in profits, which is the amount of loss in profits of the manufacturer caused by the suspension of product shipments due to the shutdown of the target device caused by the attack. The amount of loss in profits is predicted in advance. The value of the indicator of loss in profits is determined so that the greater the amount of loss in profits, the greater the importance indicated by the value of the indicator.

[0092] The decline in brand value represents the degree of decline in the brand value of the manufacturer when it becomes clear that the target device has been attacked. The value representing the decline in brand value may be determined in advance as appropriate using past records (e.g., records obtained through questionnaires, etc.) of the degree of decline in brand value due to attacks. The decline in brand value may represent the degree of decline in the brand value of a product when it becomes clear that the target device has been attacked. The decline in brand value may represent the degree of decline in the brand value of other products into which the product is incorporated when it becomes clear that the target device has been attacked. The value of the index for decline in brand value is determined so that the greater the degree of decline in brand value, the greater the importance indicated by the value of the index.

[0093] The environmental impact represents the magnitude of the impact on the environment when a product becomes defective due to an attack on the target device and the defective product is disposed of as waste. The magnitude of the environmental impact may be represented, for example, by an index representing the environmental load caused by waste resulting from an attack on the target device. The magnitude of the environmental impact may be represented, for example, by the cost of reducing (or eliminating) the environmental impact caused by waste resulting from an attack on the target device to below a standard. The value of the environmental impact index is determined such that the greater the magnitude of the impact (the magnitude of the environmental load and the cost of reducing the environmental impact), the higher the impact indicated by the index value.

[0094] The countermeasure cost for the security measures of the target device is, for example, the cost required to implement security measures that meet the standards for the target device. The countermeasure cost for the security measures of the target device may be expressed, for example, by the cost of replacing the target device with another device that is capable of implementing security measures that meet the standards. The countermeasure cost for the security measures of the target device may be expressed, for example, by the delivery time (in other words, the period from order to delivery) of the other device that replaces the target device and is capable of implementing security measures that meet the standards. In this case, for example, the value of the index may be determined so that the longer the delivery time, the greater the impact indicated by the countermeasure cost index for the security measures of the target device.

[0095] The destination impact index may be, for example, the importance of the destination, the delivery date of the product, the compensation due to the suspension of product shipments, the decline in the destination's brand value, or the shift in customer share.

[0096] The importance of the shipping destination indicates the degree of importance of the shipping destination as a customer of the manufacturer. The value indicating the degree of importance may be determined in advance as appropriate.

[0097] The product delivery time represents the length of time until the product is delivered to the shipping destination. The value of the product delivery time index is determined so that the shorter the time until the product is delivered to the shipping destination, the higher the value of the product delivery time index indicates.

[0098] The damages due to product shipment suspension are the amount of damages that a product manufacturer pays to a product recipient when product shipments are suspended due to the suspension of the target device caused by an attack. The value of the index for damages due to product shipment suspension is determined so that the higher the amount of damages, the greater the importance indicated by the value of the index for damages due to product shipment suspension.

[0099] The decline in the brand value of the shipping destination represents the degree of decline in the brand value of the shipping destination caused by the inability to ship products to the shipping destination due to the shutdown of the attack target device caused by the attack. In other words, the decline in the brand value of the shipping destination represents the degree of decline in the brand value of the shipping destination caused by the shipping destination using products whose shipments have been stopped due to the shutdown of the attack target device caused by the attack. The value represented by the index of the decline in the brand value of the shipping destination is determined so that the greater the degree of decline in brand value, the greater the impact represented by the value represented by the index of the decline in the brand value of the shipping destination.

[0100] The shift in customer share represents, for example, the magnitude of the change in share due to the suspension of shipments of a product whose shipments are suspended due to the shutdown of the target device due to an attack. The magnitude of the change (i.e., decrease) in share due to the suspension of shipments may be predicted in advance. The magnitude of the change in share due to the suspension of shipments may be the magnitude of the change in share predicted within a predetermined period of time that includes the period during which product shipments are suspended due to the shutdown of the target device due to an attack. The magnitude of the change in share due to the suspension of shipments may be the magnitude of the change in share predicted after shipments of a product whose shipments have been suspended due to the shutdown of the target device due to an attack are resumed. The magnitude of the change in share may represent the magnitude of the change in share of the product in the overall market. The magnitude of the change in share may represent the magnitude of the change in share of the product among products of the same type delivered to the product's shipping destination. The value of the index of the shift in customer share is determined such that the greater the magnitude of the change in share, the greater the magnitude of the impact indicated by the value of the index of the shift in customer share.

[0101] The value of each index may be determined so that when the quantified value of the event represented by the index is a predetermined value determined in advance for each index, the value of the index becomes a predetermined reference value.

[0102] When the shutdown of a certain target device affects the production of two or more products, the impact determination unit 140 calculates a weighted sum of the index values ​​for each of the two or more products whose production is affected by the shutdown of the target device.The impact determination unit 140 may then determine the sum of the calculated weighted sums of the two or more products whose production is affected by the shutdown of the target device as the impact of the target device.

[0103] <First Modification> Hereinafter, the first modification will be described as a first modification of the second embodiment.

[0104] In this modification, the impact determination unit 140 determines the total impact as the sum of the impacts of attack target devices that may be targets of attacks via communication paths that do not pass through countermeasure-implemented devices among the communication paths that pass through the target device. The impact determination unit 140 of this modification does not add the impacts of attack target devices that may be targets of attacks via communication paths that pass through countermeasure-implemented devices among the communication paths that pass through the target device to the total impact of the target device.

[0105] This modification can be applied to other embodiments of the present disclosure.

[0106] Third Embodiment Next, a third embodiment of the present disclosure will be described in detail with reference to the drawings.

[0107] <Configuration> First, the configuration of a risk management support device according to a third embodiment of the present disclosure will be described in detail with reference to the drawings.

[0108] FIG. 7 is a block diagram illustrating an example of the configuration of a risk management support device according to the present disclosure.

[0109] The configuration of the risk management support device 101 according to the third embodiment of the present disclosure will be described in detail below with reference to FIG.

[0110] The risk management support device 101 according to this embodiment includes a configuration information receiving unit 110, a device information receiving unit 120, a target device identification unit 130, an impact determination unit 140, an output information generation unit 150, an output unit 160, a selection receiving unit 170, and a sales information storage unit 180. The configuration information receiving unit 110, the device information receiving unit 120, the target device identification unit 130, the impact determination unit 140, the output information generation unit 150, the output unit 160, and the sales information storage unit 180 according to this embodiment are the same as the units in the second embodiment that are given the same names and the same reference numerals, except for the differences described below.

[0111] In the following description, it is assumed that the risk management support device 101 performs the same operations as the risk management support device 100 of the second embodiment, causing the output unit 160 to output output information to a display device such as a display of the risk management support device 101. In this case, the display device of the risk management support device 101 displays the output information. Note that the output unit 160 may also output the output information to an information processing device that is communicatively connected to the risk management support device 101. In this case, the information processing device displays the output information on a display device such as a display of the information processing device.

[0112] <Selection Receiving Unit 170> The selection receiving unit 170 receives information on a selected device display, which is a device display selected from the device displays of target devices included in the output information.

[0113] When the output unit 160 outputs output information to the display device of the risk management support device 101, for example, a user of the risk management support device 101 selects a selected device display using an input device such as a mouse or touch panel of the risk management support device 101. The selection receiving unit 170 receives information on the selected device display from an input device such as a mouse or touch panel of the risk management support device 101.

[0114] When the output unit 160 outputs output information to an information processing device, for example, a user of the information processing device selects a selected device display using an input device such as a mouse or a touch panel of the information processing device. The selection receiving unit 170 receives information on the selected device display from, for example, the information processing device.

[0115] <Influence Degree Determining Unit 140> The influence degree determining unit 140 identifies the attack target device that can be attacked via a communication path that passes through the selected device, which is the device indicated by the selected device display.

[0116] <Output Information Generation Unit 150> The output information generation unit 150 identifies impact information indicating the impact of the identified attack target device being stopped when the identified attack target device is stopped. Then, the output information generation unit 150 generates output information including impact information indicating the impact of the identified attack target device being stopped when the identified attack target device is stopped. In other words, the output information generation unit 150 updates the output information so that the output information includes impact information indicating the impact of the identified attack target device being stopped when the identified attack target device is stopped.

[0117] The impact information is information including, for example, information on products affected by the shutdown of the identified attack target device. The impact information may include, for example, information on sales of products affected by the shutdown of the identified attack target device. The impact information may include, for example, information representing the impact on business performance due to the suspension of shipments of products affected by the shutdown of the identified attack target device. The information representing the impact on business performance may include information on the amount of decrease in sales. The information representing the impact on business performance may include information on the amount of loss per unit of time (for example, one day, one week, one month, etc.).

[0118] The impact information may include, for example, information about the delivery destinations of products affected by the shutdown of the identified target device of attack. The impact information may include, for example, contact information for the person in charge at the delivery destinations of products affected by the shutdown of the identified target device of attack.

[0119] The output information generation unit 150 may generate output information including impact information including information about the delivery destinations of products affected by the shutdown of the identified attack target device, and an interface (e.g., a button image) for displaying contact information for the delivery destination person in charge. Hereinafter, the interface for displaying contact information for the delivery destination person in charge will be referred to as a person in charge display interface.

[0120] In this case, when the user selects the agent display interface using the input device, the selection receiving unit 170 receives information indicating that the agent display interface has been selected.

[0121] When the selection receiving unit 170 receives information indicating that the person in charge display interface has been selected, the output information generating unit 150 generates output information including contact information for the person in charge at the delivery destination of the product affected by the shutdown of the identified attack target device. In other words, the output information generating unit 150 updates the output information so that the output information includes contact information for the person in charge at the delivery destination of the product affected by the shutdown of the identified attack target device. Then, the output unit 160 outputs the updated output information.

[0122] <Sales Information Storage Unit 180> The sales information storage unit 180 stores the above-mentioned impact information in advance.

[0123] <Output Unit 160> The output unit 160 displays the output information generated by the output information generation unit 150 (in other words, updated by the output information generation unit 150).

[0124] <Operation> Next, the operation of the risk management support device 101 according to the third embodiment of the present disclosure will be described in detail with reference to the drawings.

[0125] The risk management support device 101 of this embodiment performs the operations shown in FIGS. 4 and 5, similarly to the risk management support device 100 of the second embodiment.

[0126] FIG. 8 is a flowchart illustrating an example of the operation of the risk management support device according to the present disclosure.

[0127] An example of the operation of the risk management support device 101 according to the third embodiment of the present disclosure will be described in detail below with reference to Fig. 8. The risk management support device 101 of this embodiment performs the operation shown in Fig. 8 after the operations shown in Fig. 4 and Fig. 5.

[0128] In the example shown in FIG. 8, the selection receiving unit 170 receives information on the designated device display, which is the designated device display (step S201).

[0129] The impact determination unit 140 identifies an attack target device from the information in the designated device display (step S202). As described above, if the device indicated by the designated device display is a target device, the impact determination unit 140 identifies an attack target device that could be the target of an attack via a communication path that passes through the target device.

[0130] Next, the output information generation unit 150 identifies impact information indicating the impact of the shutdown of the identified attack target device (step S203). The output information generation unit 150 generates output information including the identified impact information (step S204).

[0131] Then, the output unit 160 outputs the output information including the identified impact information (step S205).

[0132] <Example of Output Information> Fig. 9 is a diagram showing an example of output information of the risk management support device according to the present disclosure. The output information of the risk management support device according to this embodiment is, for example, the output information shown in Fig. 9.

[0133] In the example shown in Figure 9, a device display is depicted in the lower left portion of the figure. Impact information is shown in the lower right portion of the figure. This impact information is, for example, impact information when the device display of terminal B is selected.

[0134] <Effects> This embodiment has the same effects as the first embodiment, for the same reasons as those for the effects of the first embodiment.

[0135] <Modification of the Third Embodiment> The selection receiving unit 170 may receive information on the selected device display selected from the device displays of the target device and the attack target device included in the output information.

[0136] When the selected device indicated by the selected device display is a target device, the impact determination unit 140 identifies the attack target device that may be attacked via the communication path passing through the target device. When the selected device is an attack target device, the impact determination unit 140 identifies the attack target device.

[0137] The output information generating unit 150 generates output information including impact information indicating the impact when the identified attack target device is stopped.

[0138] Fourth Embodiment Next, a fourth embodiment of the present disclosure will be described in detail with reference to the drawings.

[0139] <Configuration> First, the configuration of a risk management support device according to the fourth embodiment of the present disclosure will be described in detail with reference to the drawings.

[0140] FIG. 10 is a block diagram illustrating an example of the configuration of a risk management support device according to the present disclosure.

[0141] The configuration of the risk management support device 102 according to the fourth embodiment of the present disclosure will be described in detail below with reference to FIG.

[0142] In the example shown in Figure 10, the risk management support device 102 of this embodiment includes a configuration information receiving unit 110, an apparatus information receiving unit 120, a target apparatus identification unit 130, an impact determination unit 140, an output information generation unit 150, an output unit 160, a selection receiving unit 170, a sales information storage unit 180, and a path estimation unit 190.

[0143] The configuration information receiving unit 110, device information receiving unit 120, target device identification unit 130, impact determination unit 140, output information generation unit 150, output unit 160, selection receiving unit 170, and sales information storage unit 180 of this embodiment are the same as the units with the same names and the same reference numerals in the third embodiment, except for the differences described below. This embodiment differs from the third embodiment in that the path estimation unit 190 estimates a communication path that may be a route of an attack from an intrusion device to an attack target device. This embodiment can also be applied to the second embodiment. In other words, it is also possible to incorporate the path estimation unit 190, which estimates a communication path that may be a route of an attack from an intrusion device to an attack target device, into the second embodiment.

[0144] <Path estimation unit 190> The path estimation unit 190 estimates a communication path that could be a route of an attack from an entry device to an attack target device based on information on the configuration of the information processing system, information on the security status of multiple devices included in the information processing system, and information indicating the entry device and the attack target device.

[0145] The route estimation unit 190 estimates the communication route using, for example, the method described in at least one of the following reference documents 1 and 2.

[0146] (Reference 1) International Publication No. 2023 / 175878

[0147] (Reference 2) Ryo Mizushima, Maki Inokuchi, Tomohiko Yagyu, "Countermeasure Planning Method Considering Multi-Layer Defense Against Cyber ​​Attacks," 2023 Symposium on Cryptography and Information Security, Fukuoka, Japan, January 24-27, 2023. The path estimation unit 190 may further determine the threat level of the communication path using the method described in at least one of References 1 and 2. The threat level of the communication path indicates, for example, the degree of possibility that an attack will be carried out from an entry device to an attack target device via that communication path.

[0148] The path estimation unit 190 may determine the threat level of a communication path using the number of countermeasured devices through which the communication path passes. In this case, the threat level of a communication path may be represented, for example, by the ratio of the number of countermeasured devices through which the communication path passes to the number of devices through which the communication path passes. In this case, the threat level of a communication path may be represented, for example, by the number of countermeasured devices through which the communication path passes. In this case, the smaller the threat level value, the greater the above-mentioned possibility indicated by the threat level value.

[0149] <Output Information Generating Unit 150> The output information generating unit 150 may generate output information that includes a connection indication that indicates a connection between devices through which a communication path passes, in a format that corresponds to the threat level of the communication path.

[0150] <Operation> Next, the operation of the risk management support device 102 according to the fourth embodiment of the present disclosure will be described in detail with reference to the drawings.

[0151] 11 and 12 are flowcharts showing an example of the operation of the risk management support device according to the present disclosure.

[0152] The operation of the risk management support device 102 according to the fourth embodiment of the present disclosure will be described in detail below with reference to Figures 11 and 12. The risk management support device 102 according to the fourth embodiment of the present disclosure performs the operations shown in Figures 11 and 12.

[0153] The operation shown in FIG. 11 is the same as the operation shown in FIG. 4, except that the operation of step S301 is performed between the operation of step S102 and the operation of step S103.

[0154] In step S301, the path estimation unit 190 estimates a communication path that can be a path of an attack from the entry device to the attack target device (step S301). As described above, the path estimation unit 190 estimates the communication path from, for example, information on the configuration of the information processing system, information on the security status of multiple devices included in the information processing system, and information indicating the entry device and the attack target device.

[0155] The operations shown in FIG. 12 are the same as those shown in FIG. 5, except that they are performed after the operations shown in FIG.

[0156] Furthermore, the risk management support device 102 of this embodiment performs the operation shown in FIG. 8, similarly to the risk management support device 101 of the third embodiment.

[0157] <Effects> This embodiment has the same effects as the first embodiment, for the same reasons as those for the effects of the first embodiment.

[0158] <Other Embodiments> The risk management support device according to the present disclosure can be realized by a computer including a memory into which a program read from a storage medium is loaded and a processor that executes the program. The risk management support device according to the present disclosure can also be realized by dedicated hardware. The risk management support device according to the present disclosure can also be realized by a combination of the above-mentioned computer and dedicated hardware.

[0159] FIG. 13 is a diagram illustrating an example of the hardware configuration of a computer 1000 capable of realizing the risk management support device according to the present disclosure. In the example illustrated in FIG. 13, the computer 1000 includes a processor 1001, a memory 1002, a storage device 1003, and an I / O (Input / Output) interface 1004. The computer 1000 can also access a storage medium 1005. The memory 1002 and the storage device 1003 are, for example, storage devices such as RAM (Random Access Memory) and a hard disk. The storage medium 1005 is, for example, a storage device such as RAM or a hard disk, a ROM (Read Only Memory), or a portable storage medium. The storage device 1003 may also be the storage medium 1005. The processor 1001 can read and write data and programs from and to the memory 1002 and the storage device 1003. The processor 1001 can access, for example, other information processing devices via the I / O interface 1004. The processor 1001 can access a storage medium 1005. The storage medium 1005 stores a program that causes the computer 1000 to operate as a risk management support device according to the present disclosure.

[0160] The processor 1001 loads a program stored in the storage medium 1005, which causes the computer 1000 to operate as the risk management support device according to the present disclosure, into the memory 1002. Then, the processor 1001 executes the program loaded into the memory 1002, causing the computer 1000 to operate as the risk management support device according to the present disclosure.

[0161] The configuration information receiving unit 110, the device information receiving unit 120, the target device identifying unit 130, the impact determination unit 140, the output information generation unit 150, the output unit 160, the selection receiving unit 170, and the path estimation unit 190 can be realized, for example, by a processor 1001 that executes a program loaded into memory 1002. The sales information storage unit 180 can be realized by the memory 1002 or a storage device 1003 such as a hard disk drive included in the computer 1000. Some or all of the configuration information receiving unit 110, the device information receiving unit 120, the target device identifying unit 130, the impact determination unit 140, the output information generation unit 150, the output unit 160, the selection receiving unit 170, the sales information storage unit 180, and the path estimation unit 190 can be realized by dedicated circuits.

[0162] Furthermore, some or all of the above-described embodiments can be described as, but are not limited to, the following supplementary notes.

[0163] (Supplementary Note 1) A risk management support device comprising: a target device identification means for identifying, from information on communication paths that can be routes of attacks from an entry device to an attack target device and information on the security status of the plurality of devices, a target device among the plurality of devices that is a device through which the communication path passes and whose security status does not meet a standard; an impact determination means for determining, from information on the degree of impact that indicates the magnitude of the impact on business of the shutdown of the attack target device due to an attack, a total impact that is the sum of the impacts of the attack target devices that can be targets of attacks via the communication paths that pass through the target devices; and an output means for outputting information indicating the target device in a manner corresponding to the total impact.

[0164] (Supplementary Note 2) A risk management support device as described in Supplementary Note 1, comprising: an output information generation means for generating output information including a device display representing the target device in a manner according to the total impact degree, wherein the output means outputs the output information as information indicating the target device.

[0165] (Appendix 3) The risk management support device described in Appendix 2, wherein the output information generation means generates the output information including a device display indicating the intrusion device, a device display indicating the attack target device, a device display indicating the device through which the communication path passes, and a connection display indicating the connection between the devices through which the communication path passes.

[0166] (Supplementary Note 4) A risk management support device as described in Supplementary Note 2 or 3, comprising: a selection receiving means for receiving information on a selected device display which is the device display selected from the device displays of the target devices included in the output information; wherein the impact determination means identifies the target device that can be attacked via the communication path that passes through the selected device which is the device indicated by the selected device display; and the output information generation means generates the output information including impact information indicating the impact if the identified target device is stopped.

[0167] (Supplementary Note 5) The risk management support device described in Supplementary Note 4, wherein the output information generation means generates the output information including, as the impact information, information on the impact on business performance due to the suspension of shipments of products affected by the suspension of the identified attack target device.

[0168] (Supplementary Note 6) The risk management support device according to Supplementary Note 4, wherein the output information generation means generates the output information including, as the impact information, information on delivery destinations of products that will be affected by the shutdown of the identified attack target device.

[0169] (Supplementary Note 7) The risk management support device described in Supplementary Note 6, wherein the output information generation means generates the output information including, as the impact information, contact information of a person in charge at a delivery destination of a product that will be affected by the shutdown of the identified attack target device.

[0170] (Supplementary Note 8) The risk management support device described in Supplementary Note 4, wherein the selection receiving means receives information on the selected device display selected from the device displays of the target device and the attack target device included in the output information, the impact determination means, if the selected device indicated by the selected device display is the target device, identifies the attack target device that can be attacked via the communication path via the target device, and if the selected device is the attack target device, identifies the attack target device, and the output information generation means generates the output information including impact information indicating the impact if the identified attack target device is stopped.

[0171] (Supplementary Note 9) The risk management support device according to Supplementary Note 1 or 2, wherein the output means outputs information indicating the target devices in descending order of the impact indicated by the total impact degree.

[0172] (Supplementary Note 10) The risk management support device according to Supplementary Note 1 or 2, wherein the impact determination means determines the impact of the attack target device using one or more indicators indicating the magnitude of the impact of the stop of the attack target device.

[0173] (Supplementary Note 11) The risk management support device described in Supplementary Note 10, wherein the impact determination means determines the impact of the attack target device using either a product impact index, which is one or more indexes that represent the impact of the suspension of production of an affected product, the product whose production is affected by the suspension of the attack target device, or a countermeasure impact index, which is one or more indexes that represent the impact of countermeasures to eliminate the impact of an attack on the attack target device.

[0174] (Supplementary Note 12) The impact determination means determines the impact of the attack target device using at least one of: a manufacturer impact index, which is one or more indexes indicating the magnitude of the impact of the stoppage of the attack target device on the manufacturer of the affected product, the product whose production is affected by the stoppage of the attack target device; and a shipping destination impact index, which is one or more indexes indicating the magnitude of the impact of the stoppage of the attack target device on the shipping destination of the affected product. (Supplementary Note 12) The risk management support device described in Supplementary Note 10.

[0175] (Appendix 13) The impact determination means determines the impact of the target device using at least one of an economic impact index, which is an index that represents the magnitude of the economic impact caused by the suspension of production of an affected product, the production of which is affected by the suspension of the target device, and a social impact index, which is an index that represents the magnitude of the social impact caused by the suspension of production of the affected product. (Appendix 13) The risk management support device described in Appendix 10.

[0176] (Supplementary Note 14) The risk management support device according to Supplementary Note 10, wherein the influence determining means determines the weighted sum of the one or more indicators as the influence of the attack target device.

[0177] (Supplementary Note 15) A risk management support method in an information processing system including a plurality of devices and a communication network connecting the plurality of devices, comprising: identifying a target device among the plurality of devices through which the communication path passes and whose security state does not meet a standard, based on information on communication paths that can be a route for an attack from an entry device to a target device and information on the security state of the plurality of devices; determining a total impact, which is the sum of the impacts of the target devices that can be a target of an attack via the communication path that passes through the target device, based on information on impact that indicates the magnitude of the impact on a business of the shutdown of the target device due to an attack; and outputting information indicating the target device in a manner corresponding to the total impact.

[0178] (Supplementary Note 16) A risk management support method according to Supplementary Note 15, further comprising generating output information including a device display representing the target device in a manner according to the total impact degree, and outputting the output information as information indicating the target device.

[0179] (Appendix 17) A risk management support method as described in Appendix 16, wherein the output information is generated to include a device display indicating the intrusion device, a device display indicating the attack target device, a device display indicating the devices through which the communication path passes, and a connection display indicating the connection between the devices through which the communication path passes.

[0180] (Appendix 18) A risk management support method as described in Appendix 16 or 17, which receives information on a selected device display, which is the device display selected from the device display of the target device included in the output information, identifies the target device that can be attacked via the communication path that passes through the selected device, which is the device indicated by the selected device display, and generates the output information including impact information that indicates the impact if the identified target device is stopped.

[0181] (Supplementary Note 19) The risk management support method according to Supplementary Note 18, wherein the output information is generated including, as the impact information, information on the impact on business performance due to the suspension of shipments of products affected by the suspension of the identified attack target device.

[0182] (Supplementary Note 20) The risk management support method according to Supplementary Note 18, wherein the output information is generated including, as the impact information, information on delivery destinations of products that will be affected by a stop of the identified attack target device.

[0183] (Supplementary Note 21) The risk management support method according to Supplementary Note 20, wherein the output information is generated including, as the impact information, contact information of a person in charge at a delivery destination of a product that will be affected by a stop of the identified attack target device.

[0184] (Supplementary Note 22) A risk management support method as described in Supplementary Note 18, which receives information on the selected device display selected from the device displays of the target device and the attack target device included in the output information, identifies the attack target device that can be attacked via the communication path passing through the target device if the selected device indicated by the selected device display is the target device, and identifies the attack target device if the selected device is the attack target device, and generates the output information including impact information indicating the impact if the identified attack target device is stopped.

[0185] (Supplementary Note 23) The risk management support method according to Supplementary Note 15 or 16, wherein information indicating the target devices is output in descending order of the impact indicated by the total impact degree.

[0186] (Supplementary Note 24) The risk management support method according to Supplementary Note 15 or 16, wherein the degree of impact on the attack target device is determined using one or more indicators indicating the magnitude of the impact caused by the stoppage of the attack target device.

[0187] (Supplementary Note 25) A risk management support method as described in Supplementary Note 24, in which the impact level of the attack target device is determined using either a product impact index, which is one or more indexes that represent the impact of the suspension of production of an affected product, which is a product whose production is affected by the suspension of the attack target device, or a countermeasure impact index, which is one or more indexes that represent the impact of measures to eliminate the impact of an attack on the attack target device.

[0188] (Supplementary Note 26) A risk management support method as described in Supplementary Note 24, in which the degree of impact of the attack target device is determined using at least one of: a manufacturer impact index, which is one or more indexes indicating the magnitude of the impact of the stoppage of the attack target device on the manufacturer of an affected product, the production of which is affected by the stoppage of the attack target device; and a shipping destination impact index, which is one or more indexes indicating the magnitude of the impact of the stoppage of the attack target device on the shipping destination of the affected product.

[0189] (Appendix 27) A risk management support method as described in Appendix 24, in which the impact of the target device is determined using at least one of an economic impact index, which is an index that indicates the magnitude of the economic impact caused by the suspension of production of an affected product, the production of which is affected by the suspension of production of the target device, and a social impact index, which is an index that indicates the magnitude of the social impact caused by the suspension of production of the affected product.

[0190] (Supplementary Note 28) The risk management support method according to Supplementary Note 24, wherein a weighted sum of the one or more indicators is determined as the degree of influence of the attack target device.

[0191] (Supplementary Note 29) A storage medium storing a program that causes a computer to execute the following steps in an information processing system including a plurality of devices and a communication network connecting the plurality of devices: a target device identification process that identifies, from information on communication paths that can be routes of attacks from an entry device to a target device of attack and information on the security status of the plurality of devices, a target device that is a device through which the communication path passes and whose security status does not meet a standard; an impact determination process that determines, from information on impact that indicates the magnitude of the impact on business of the shutdown of the target device of attack due to an attack, a total impact that is the sum of the impacts of the target devices of attack that can be targets of attacks via the communication paths that pass through the target devices; and an output process that outputs information indicating the target device in a manner according to the total impact.

[0192] (Supplementary Note 30) The storage medium according to Supplementary Note 29, wherein the program causes a computer to execute an output information generation process that generates output information including a device display representing the target device in a manner according to the total impact degree, and the output process outputs the output information as information indicating the target device.

[0193] (Appendix 31) The storage medium described in Appendix 30, wherein the output information generation process generates the output information including the device display indicating the intrusion device, the device display indicating the attack target device, the device display indicating the devices through which the communication path passes, and a connection display indicating the connection between the devices through which the communication path passes.

[0194] (Appendix 32) The program causes a computer to execute a selection receiving process that receives information on a selected device display, which is the device display selected from the device display of the target device included in the output information; the impact determination process identifies the target device that can be attacked via the communication path that passes through the selected device, which is the device indicated by the selected device display; and the output information generation process generates the output information including impact information that indicates the impact if the identified target device is stopped.

[0195] (Supplementary Note 33) The storage medium according to Supplementary Note 32, wherein the output information generation process generates the output information including, as the impact information, information on the impact on business performance due to the suspension of shipments of products affected by the suspension of the identified attack target device.

[0196] (Supplementary Note 34) The storage medium according to Supplementary Note 32, wherein the output information generation process generates the output information including, as the impact information, information on delivery destinations of products that will be affected by a stop of the identified attack target device.

[0197] (Supplementary Note 35) The storage medium according to Supplementary Note 34, wherein the output information generation process generates the output information including, as the impact information, contact information of a person in charge at a delivery destination of a product that will be affected by the shutdown of the identified attack target device.

[0198] (Appendix 36) The storage medium described in Appendix 32, wherein the selection receiving process receives information on the selected device display selected from the device displays of the target device and the attack target device included in the output information; the impact determination process, if the selected device indicated by the selected device display is the target device, identifies the attack target device that can be attacked via the communication path via the target device, and if the selected device is the attack target device, identifies the attack target device; and the output information generation process generates the output information including impact information indicating the impact if the identified attack target device is stopped.

[0199] (Supplementary Note 37) The storage medium according to Supplementary Note 29 or 30, wherein the output process outputs information indicating the target devices in descending order of the impact indicated by the total impact degree.

[0200] (Supplementary Note 38) The storage medium according to Supplementary Note 29 or 30, wherein the impact determination process determines the impact of the attack target device using one or more indicators indicating the magnitude of the impact of the stop of the attack target device.

[0201] (Appendix 39) The impact determination process determines the impact of the attack target device using either a product impact index, which is one or more indices that represent the impact of the suspension of production of an affected product, the product whose production is affected by the suspension of the attack target device, or a countermeasure impact index, which is one or more indices that represent the impact of countermeasures to eliminate the impact of an attack on the attack target device. (Appendix 39) The storage medium described in Appendix 38.

[0202] (Appendix 40) The impact determination process determines the impact of the attack target device using at least one of: a manufacturer impact index, which is one or more indexes indicating the magnitude of the impact of the stoppage of the attack target device on the manufacturer of an affected product, the production of which is affected by the stoppage of the attack target device; and a shipping destination impact index, which is one or more indexes indicating the magnitude of the impact of the stoppage of the attack target device on the shipping destination of the affected product. (Appendix 40) The storage medium described in Appendix 38.

[0203] (Appendix 41) The impact determination process determines the impact of the target device by using at least one of an economic impact index, which is an index that represents the magnitude of the economic impact caused by the suspension of production of an affected product, the production of which is affected by the suspension of the target device, and a social impact index, which is an index that represents the magnitude of the social impact caused by the suspension of production of the affected product. (Appendix 38) A storage medium as described in Appendices 38.

[0204] (Supplementary Note 42) The storage medium according to Supplementary Note 38, wherein the influence determination process determines the weighted sum of the one or more indicators as the influence of the attack target device.

[0205] Although the present disclosure has been described above with reference to the embodiments, the present disclosure is not limited to the above embodiments. Various modifications that can be understood by those skilled in the art can be made to the configuration and details of the present disclosure within the scope of the present disclosure.

[0206] 10 Risk management support device 100 Risk management support device 101 Risk management support device 102 Risk management support device 110 Configuration information receiving unit 120 Device information receiving unit 130 Target device identification unit 140 Impact determination unit 150 Output information generation unit 160 Output unit 170 Selection receiving unit 180 Sales information storage unit 190 Path estimation unit 1000 Computer 1001 Processor 1002 Memory 1003 Storage device 1004 I / O interface 1005 Storage medium

Claims

1. A risk management support device comprising: a target device identification means for identifying, from information on communication paths that could be routes of attacks from an entry device to a target device and information on the security status of the multiple devices, a target device among the multiple devices that is a device through which the communication path passes and whose security status does not meet a standard; an impact determination means for determining, from information on the degree of impact that indicates the magnitude of the impact on business of the shutdown of the target device due to an attack, a total impact that is the sum of the impacts of the target devices that could be targets of attacks via the communication paths that pass through the target devices; and an output means for outputting information indicating the target device in a manner corresponding to the total impact.

2. A risk management support device as described in claim 1, comprising an output information generation means for generating output information including a device display representing the target device in a manner corresponding to the total impact degree, wherein the output means outputs the output information as information indicating the target device.

3. The risk management support device of claim 2, wherein the output information generating means generates the output information including a device display indicating the entry point device, a device display indicating the attack target device, a device display indicating the device through which the communication path passes, and a connection display indicating the connection between the devices through which the communication path passes.

4. A risk management support device as described in claim 2 or 3, comprising: a selection receiving means for receiving information on a selected device display, which is the device display selected from the device displays of the target devices included in the output information; wherein the impact determination means identifies the target device that can be attacked via the communication path that passes through the selected device, which is the device indicated by the selected device display; and the output information generation means generates the output information including impact information indicating the impact if the identified target device is stopped.

5. The risk management support device according to claim 4, wherein the output information generation means generates the output information including, as the impact information, information on the impact on business performance due to the suspension of shipments of products affected by the suspension of the identified attack target device.

6. The risk management support device according to claim 4, wherein the output information generation means generates the output information including, as the impact information, information on the delivery destinations of products that will be affected by the shutdown of the identified attack target device.

7. The risk management support device according to claim 6, wherein the output information generation means generates the output information including, as the impact information, contact information for the person in charge at the delivery destination of the product that will be affected by the shutdown of the identified attack target device.

8. The risk management support device according to claim 4, wherein the selection receiving means receives information on the selected device display selected from the device displays of the target device and the attack target device included in the output information, the impact determination means, if the selected device indicated by the selected device display is the target device, identifies the attack target device that can be attacked via the communication path passing through the target device, and if the selected device is the attack target device, identifies the attack target device, and the output information generation means generates the output information including impact information indicating the impact if the identified attack target device is stopped.

9. A risk management support device according to claim 1 or 2, wherein the output means outputs information indicating the target devices in descending order of the impact indicated by the total impact degree.

10. A risk management support device as described in claim 1 or 2, wherein the impact determination means determines the impact of the target device using one or more indicators indicating the magnitude of the impact caused by the shutdown of the target device.

11. The risk management support device described in claim 10, wherein the impact determination means determines the impact of the attack target device using either a product impact index, which is one or more indexes that represent the impact of the suspension of production of an affected product, the production of which is affected by the suspension of the attack target device, or a countermeasure impact index, which is one or more indexes that represent the impact of measures taken to eliminate the impact of an attack on the attack target device.

12. The risk management support device described in claim 10, wherein the impact determination means determines the impact of the attack target device using at least one of the following: a manufacturer impact index, which is one or more indexes indicating the magnitude of the impact of the shutdown of the attack target device on the manufacturer of the affected product, the product whose production is affected by the shutdown of the attack target device; and a shipping destination impact index, which is one or more indexes indicating the magnitude of the impact of the shutdown of the attack target device on the shipping destination of the affected product.

13. The risk management support device described in claim 10, wherein the impact determination means determines the impact of the target device using at least one of an economic impact index, which is an index that represents the magnitude of the economic impact caused by the suspension of production of an affected product, the production of which is affected by the suspension of the target device, and a social impact index, which is an index that represents the magnitude of the social impact caused by the suspension of production of the affected product.

14. The risk management support device according to claim 10, wherein the impact determination means determines the weighted sum of the one or more indicators as the impact of the attack target device.

15. A risk management support method in an information processing system including a plurality of devices and a communication network connecting the plurality of devices, comprising: identifying a target device among the plurality of devices that is a device through which the communication path passes and whose security state does not meet a standard, based on information on communication paths that could be a route for an attack from an entry device to a target device and information on the security status of the plurality of devices; determining a total impact, which is the sum of the impacts of the target devices that could be the target of an attack via the communication path that passes through the target device, based on information on the impact that indicates the magnitude of the impact on business of the shutdown of the target device due to an attack; and outputting information indicating the target device in a manner corresponding to the total impact.

16. A risk management support method as described in claim 15, wherein output information including a device display representing the target device is generated in a manner corresponding to the total impact degree, and the output information is output as information indicating the target device.

17. A risk management support method as described in claim 16, wherein the output information is generated to include a device display indicating the entry point device, a device display indicating the attack target device, a device display indicating the devices through which the communication path passes, and a connection display indicating the connections between the devices through which the communication path passes.

18. A risk management support method as described in claim 16 or 17, which receives information on a selected device display, which is a device display selected from the device displays of the target devices included in the output information, identifies the target device that can be attacked via the communication path that passes through the selected device, which is the device indicated by the selected device display, and generates the output information including impact information that indicates the impact if the identified target device is stopped.

19. A risk management support method as described in claim 18, wherein the output information is generated to include, as the impact information, information on the impact on business performance due to the suspension of shipments of products affected by the suspension of the identified attack target device.

20. A storage medium storing a program that causes a computer to execute the following steps in an information processing system including a plurality of devices and a communication network connecting the plurality of devices: a target device identification process that identifies, from among the plurality of devices, a target device that is a device through which the communication path passes and whose security status does not meet a standard, based on information on communication paths that could be a route for an attack from an entry device to a target device and information on the security status of the plurality of devices; an impact determination process that determines, from information on the impact that indicates the magnitude of the impact on a business of the shutdown of the target device due to an attack, a total impact that is the sum of the impacts of the target devices that could be the target of an attack via the communication paths that pass through the target devices; and an output process that outputs information indicating the target device in a manner corresponding to the total impact.