Information processing method, program, and information processing system
The information processing method and system address the challenge of evaluating cyberattack risks on products by categorizing and calculating security risks based on product fields and phases, facilitating accurate and actionable risk assessments.
Patent Information
- Application Number
- PCT/JP2025/017942
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-07-12
- Filing Date
- 2025-05-19
- Publication Date
- 2026-01-15
AI Technical Summary
Organizations face challenges in efficiently evaluating and managing the security risk of cyberattacks on their products, particularly after delivery, especially when dealing with a variety of products that require prioritization for security measures.
An information processing method and system that acquires security risk-related information, calculates a security risk evaluation value based on evaluation criteria, and classifies evaluation items into categories to facilitate accurate risk assessment, including considerations for product fields, phases, and update frequencies.
Enables quantitative evaluation of security risks before and after product delivery, ensuring accurate assessment and highlighting high-risk categories for targeted countermeasures, thereby enhancing security risk management.
Smart Images

Figure JP2025017942_15012026_PF_FP_ABST
Abstract
Description
Information processing method, program, and information processing system
[0001] The present disclosure relates to an information processing method, a program, and an information processing system.
[0002] Patent Document 1 discloses an evaluation device for evaluating the risk of source code that changes over time.
[0003] Patent No. 7322963
[0004] The present disclosure provides an information processing method and the like that makes it easy to evaluate the security risk of cyber attacks against products.
[0005] In an information processing method according to one aspect of the present disclosure, security risk-related information is acquired, which includes one or more data items for a product related to each of one or more evaluation items for evaluating the security risk of a cyber-attack against the product; a security risk evaluation value is calculated based on whether the one or more data items included in the acquired security risk-related information each satisfy one or more evaluation criteria; and the calculated security risk evaluation value is output; and each of the one or more evaluation items is classified into one or more categories, including a category to which evaluation items related to functions possessed by the product belong, a category to which evaluation items related to programs implemented in the product belong, a category to which evaluation items related to modifications to software possessed by the product belong, and a category to which evaluation items related to responses to cyber-attacks against the product belong.
[0006] A program according to one aspect of the present disclosure causes one or more processors to execute the information processing method.
[0007] An information processing system according to one aspect of the present disclosure comprises an acquisition unit that acquires security risk-related information including one or more data items of a product related to each of one or more evaluation items for evaluating the security risk of a cyber-attack against the product; a calculation unit that calculates a security risk evaluation value that evaluates the security risk based on whether or not the one or more data items included in the security risk-related information acquired by the acquisition unit each satisfy one or more evaluation criteria; and an output unit that outputs the security risk evaluation value calculated by the calculation unit, wherein each of the one or more evaluation items is classified into one or more categories including a category to which evaluation items related to functions possessed by the product belong, a category to which evaluation items related to programs implemented in the product belong, a category to which evaluation items related to modifications to software possessed by the product belong, and a category to which evaluation items related to responses to cyber-attacks against the product belong.
[0008] The present disclosure has the advantage of making it easier to evaluate the security risk of cyber attacks against products.
[0009] FIG. 1 is a block diagram showing an example of an overall configuration including an information processing system according to an embodiment. FIG. 2 is a block diagram showing another example of an overall configuration including an information processing system according to an embodiment. FIG. 3 is a block diagram showing an example of a functional configuration of an information processing system according to an embodiment. FIG. 4 is an explanatory diagram of security risk information. FIG. 5 is a diagram showing an example of a category to which each evaluation item belongs. FIG. 6 is a diagram showing an example of an evaluation item. FIG. 7 is a diagram showing an example of an evaluation standard. FIG. 8 is a diagram showing an example of security risk-related information. FIG. 9 is a diagram showing an example of a calculation of a category-specific evaluation value. FIG. 10 is a diagram showing an example of a calculation of a security risk evaluation value. FIG. 11 is a diagram showing an example of an output result of a security risk evaluation value. FIG. 12 is a sequence diagram showing an example of an operation of an information processing system according to an embodiment. FIG. 13 is a flowchart showing an example of an operation of an information processing system according to an embodiment. FIG. 14 is a flowchart showing an example of a process for extracting evaluation items. FIG. 15 is a flowchart showing an example of a process for acquiring security risk-related information. FIG. 16 is a flowchart showing an example of a process for calculating a security risk evaluation value. FIG. 17 is a flowchart showing an example of a process for calculating a category-specific evaluation value. FIG. 18 is a flowchart showing an example of a process for calculating a security risk evaluation value from a category-specific evaluation value. Fig. 19 is a flowchart showing an example of processing for outputting a security risk assessment value. Fig. 20 is a diagram showing an example of a product application field in the first modified example. Fig. 21 is a diagram showing an example of product application field information in the first modified example. Fig. 22 is a diagram showing an example of security risk-related information in the first modified example. Fig. 23 is a diagram showing an example of an evaluation criterion in the first modified example. Fig. 24 is a flowchart showing an example of processing for acquiring an evaluation criterion in the first modified example. Fig. 25 is a diagram showing an example of a field-specific evaluation value in the first modified example. Fig. 26 is a flowchart showing an example of processing for calculating a security assessment value in the first modified example. Fig. 27 is a diagram showing an example of product phase information in the second modified example. Fig. 28 is a flowchart showing an example of processing for acquiring security risk assessment information in the second modified example.FIG. 29 is a diagram showing an example of evaluation criteria in the third modified example. FIG. 30 is a diagram showing an example of processing for updating evaluation criteria in the third modified example. FIG. 31 is a diagram showing an example of the correspondence between categories and weighting factors in the fourth modified example. FIG. 32 is a diagram showing an example of calculation of a security risk assessment value in the fourth modified example. FIG. 33 is a flowchart showing an example of processing for acquiring a weighting factor in the fourth modified example. FIG. 34 is a flowchart showing an example of processing for calculating a security risk assessment value in the fourth modified example. FIG. 35 is a diagram showing an example of the correspondence between product application fields and weighting factors in the fifth modified example. FIG. 36 is a flowchart showing another example of processing for acquiring a weighting factor in the fifth modified example. FIG. 37 is a diagram showing an example of the correspondence between update frequencies of security risk-related information and weighting factors in the sixth modified example. FIG. 38 is a flowchart showing an example of processing for updating a weighting factor in the sixth modified example. FIG. 39 is a diagram showing an example of calculation of a security risk assessment value in the seventh modified example. FIG. 40 is a flowchart showing an example of processing for acquiring security-related information in the seventh modified example. FIG. 41 is a diagram showing an example of calculation of a trend value in the eighth modified example. FIG. 42 is a flowchart showing an example of processing for calculating a trend value in the eighth modified example. Fig. 43 is a diagram showing an example of output results of a security risk assessment value and a category-specific assessment value in the ninth modified example. Fig. 44 is a flowchart showing an example of processing for outputting a security risk assessment in the ninth modified example. Fig. 45 is a diagram showing an example of output of a security risk assessment value in the tenth modified example. Fig. 46 is a flowchart showing an example of processing for outputting a security risk assessment value in the tenth modified example. Fig. 47 is a diagram showing an example of output of a security risk assessment value in the eleventh modified example. Fig. 48 is a diagram showing another example of output of a security risk assessment value in the eleventh modified example. Fig. 49 is a flowchart showing an example of processing for outputting a security risk assessment value in the eleventh modified example. Fig. 50 is a flowchart showing an example of processing for outputting a security risk assessment value in the eleventh modified example, with the assessment items of each category highlighted.
[0010] (Findings that Form the Basis of the Present Disclosure) Organizations that sell or rent products are required to implement security measures against cyberattacks on the products not only before delivery but also after delivery. Here, if an organization manages a large variety of products, it is essential for the organization to evaluate the security risk of cyberattacks on each product and determine which products to prioritize for security measures. Here, security risk refers to the potential threat or danger that indicates the degree to which a product is likely to be targeted by a cyberattack.
[0011] In view of the above, the present disclosure aims to provide an information processing method etc. that makes it easy to evaluate the security risk of cyber attacks against products.
[0012] More specifically, in an information processing method relating to a first aspect of the present disclosure, security risk-related information including one or more data of a product related to each of one or more evaluation items for evaluating the security risk of a cyber-attack against the product is acquired, a security risk evaluation value that evaluates the security risk is calculated based on whether or not each of the one or more data included in the acquired security risk-related information satisfies one or more evaluation criteria, and the calculated security risk evaluation value is output, and each of the one or more evaluation items is classified into one or more categories including a category to which evaluation items related to functions possessed by the product belong, a category to which evaluation items related to programs implemented in the product belong, a category to which evaluation items related to modifications to software possessed by the product belong, and a category to which evaluation items related to responses to cyber-attacks against the product belong.
[0013] This has the advantage that, as long as one or more pieces of product data are obtained, it is possible to quantitatively evaluate security risks not only before delivery of the product but also after delivery of the product, making it easier to evaluate the security risks of cyber attacks against the product.
[0014] Also, for example, in an information processing method relating to the second aspect of the present disclosure, in the first aspect, one or more evaluation criteria are determined based on the field to which the product belongs, and a security risk assessment value is calculated using the determined one or more evaluation criteria.
[0015] This has the advantage that the security risk assessment value can be calculated taking into account the field to which the product belongs, making it easier to assess the security risk of cyber attacks against the product with greater accuracy.
[0016] Also, for example, in the information processing method according to the third aspect of the present disclosure, in the second aspect, if a product belongs to multiple fields, multiple field-specific evaluation values are calculated that evaluate the security risk for each of the multiple fields, and the field-specific evaluation value with the highest risk among the multiple calculated field-specific evaluation values is determined to be the security risk evaluation value.
[0017] This has the advantage that the security risk assessment value is determined to be the evaluation value for the highest risk category, making it easier to prevent underestimating the security risk of cyber attacks against products.
[0018] Furthermore, for example, in an information processing method relating to the fourth aspect of the present disclosure, in any one of the first to third aspects, one or more evaluation criteria are determined based on the product phase to which the product belongs at the time the information processing method is executed during the process of producing the product, and a security risk assessment value is calculated using the determined one or more evaluation criteria.
[0019] This has the advantage that the security risk assessment value can be calculated taking into account the product phase to which the product belongs at the time the information processing method is executed during the product production process, making it easier to assess the security risk of cyber attacks against the product with greater accuracy.
[0020] Also, for example, in an information processing method according to a fifth aspect of the present disclosure, in any one of the first to fourth aspects, one or more evaluation criteria are updated according to the distribution of the acquired security risk-related information.
[0021] This has the advantage that the evaluation criteria are updated according to the distribution of security risk-related information, making it easier to maintain a constant proportion of products that meet the evaluation criteria among all products that are subject to evaluation.
[0022] Furthermore, for example, in an information processing method relating to a sixth aspect of the present disclosure, in any one of the first to fifth aspects, a security risk assessment value is calculated further using one or more weighting coefficients indicating the importance of each of one or more categories.
[0023] This has the advantage that the security risk assessment value can be calculated taking into account the contribution of each category to the security risk assessment, making it easier to assess the security risk of cyber attacks against products with greater accuracy.
[0024] Also, for example, in the information processing method relating to the seventh aspect of the present disclosure, in the sixth aspect, one or more weighting factors are determined based on the field to which the product belongs, and a security risk assessment value is calculated using the determined one or more weighting factors.
[0025] This has the advantage that the security risk assessment value can be calculated taking into account the contribution of the product to the security risk assessment of the field to which it belongs, making it easier to assess the security risk of cyber attacks against the product with greater accuracy.
[0026] Also, for example, in the information processing method relating to the eighth aspect of the present disclosure, in the sixth or seventh aspect, one or more weighting factors are determined based on the update frequency of one or more data items over a specified period, and a security risk assessment value is calculated using the determined one or more weighting factors.
[0027] This has the advantage that the security risk assessment value can be calculated taking into account the contribution of each category to the security risk assessment, which can change as data is updated, making it easier to assess the security risk of cyber attacks against products with greater accuracy.
[0028] Furthermore, for example, in an information processing method relating to a ninth aspect of the present disclosure, in any one of the first to eighth aspects, a security risk assessment value is calculated based on whether one or more pieces of data contained in past security risk-related information obtained before the time of execution of the information processing method each satisfy one or more evaluation criteria at the time of execution.
[0029] This has the advantage that the security risk of a product at the time security risk-related information was obtained in the past can be evaluated based on one or more current evaluation criteria, making it easier to compare and consider the security risk of past products with the security risk of current products.
[0030] Furthermore, for example, in an information processing method according to a tenth aspect of the present disclosure, a trend value indicating the trend of the security risk of a product is calculated based on the calculated security risk assessment value in any one of the first to ninth aspects and a past security risk assessment value calculated before the time the information processing method is executed.
[0031] This has the advantage that by referring to the trend value, it becomes easier to grasp trends in product security risks that cannot be captured by the product's current security risks alone.
[0032] Also, for example, in an information processing method relating to an eleventh aspect of the present disclosure, in any one of the first to tenth aspects, one or more category-specific evaluation values that evaluate the security risk for each of one or more categories are calculated, and the calculated one or more category-specific evaluation values are output.
[0033] This has the advantage that not only an assessment of the overall security risk of the product but also an assessment of the security risk for each category is output, making it easier for the user to understand which category of security risk should be given priority.
[0034] Furthermore, for example, in an information processing method relating to the twelfth aspect of the present disclosure, in any one of the first to eleventh aspects, a time series change in the security risk assessment value is output based on the calculated security risk assessment value and a past security risk assessment value calculated before the time the information processing method is executed.
[0035] This has the advantage that the time-series changes in the security risk assessment value are output, making it easier for the user to grasp sudden changes or future fluctuations in the security risk of the product.
[0036] Furthermore, for example, in an information processing method according to a thirteenth aspect of the present disclosure, in any one of the first to twelfth aspects, one or more category-specific evaluation values that evaluate the security risk for each of one or more categories are calculated, and a category-specific evaluation value that exceeds a predetermined risk among the one or more calculated category-specific evaluation values is highlighted and output, and countermeasures for lowering the category-specific evaluation value are output.
[0037] This has the advantage that it highlights the category-specific evaluation values that pose relatively high risks and outputs countermeasures to lower those category-specific evaluation values, making it easier for users to understand which categories pose a high security risk and to implement those countermeasures.
[0038] Furthermore, for example, in an information processing method according to a fourteenth aspect of the present disclosure, in any one of the first to thirteenth aspects, one or more evaluation item-specific evaluation values that evaluate the security risk for each of one or more evaluation items are calculated, and among the calculated one or more evaluation item-specific evaluation values, evaluation item-specific evaluation values that exceed a predetermined risk are highlighted and output, and countermeasures for lowering the evaluation item-specific evaluation values are output.
[0039] This has the advantage that the evaluation values for each evaluation item that pose a relatively high risk are highlighted and countermeasures to lower the evaluation values for each evaluation item are output, making it easier for users to understand which evaluation items pose a high security risk and to implement those countermeasures.
[0040] Also, for example, a program according to a fifteenth aspect of the present disclosure causes one or more processors to execute the information processing method of any one of the first to fourteenth aspects.
[0041] This has the advantage that, as long as one or more pieces of product data are obtained, it is possible to quantitatively evaluate security risks not only before delivery of the product but also after delivery of the product, making it easier to evaluate the security risks of cyber attacks against the product.
[0042] Also, for example, an information processing system according to a sixteenth aspect of the present disclosure includes an acquisition unit, a calculation unit, and an output unit. The acquisition unit acquires security risk-related information including one or more data items of a product related to one or more evaluation items for evaluating the security risk of a cyberattack against the product. The calculation unit calculates a security risk assessment value that evaluates the security risk based on whether or not the one or more data items included in the security risk-related information acquired by the acquisition unit satisfy one or more evaluation criteria. The output unit outputs the security risk assessment value calculated by the calculation unit. Each of the one or more evaluation items is classified into one or more categories including a category to which evaluation items related to functions possessed by the product belong, a category to which evaluation items related to programs implemented in the product belong, a category to which evaluation items related to software modifications possessed by the product belong, and a category to which evaluation items related to responses to cyberattacks against the product belong.
[0043] This has the advantage that, as long as one or more pieces of product data are obtained, it is possible to quantitatively evaluate security risks not only before delivery of the product but also after delivery of the product, making it easier to evaluate the security risks of cyber attacks against the product.
[0044] Furthermore, these comprehensive or specific aspects may be realized in a system, an apparatus, a method, an integrated circuit, a computer program, or a non-transitory recording medium such as a computer-readable CD-ROM, or may be realized in any combination of a system, an apparatus, a method, an integrated circuit, a computer program, and a recording medium.
[0045] Hereinafter, embodiments will be described in detail with reference to the drawings. Note that the embodiments described below are all comprehensive or specific examples. The numerical values, shapes, materials, components, component placement and connection configurations, steps, or step order shown in the following embodiments are merely examples and are not intended to limit the present disclosure. Furthermore, among the components in the following embodiments, components not recited in independent claims will be described as optional components. Note that each figure is a schematic diagram and is not necessarily an exact illustration. Furthermore, in each figure, substantially identical components are assigned the same reference numerals, and duplicated descriptions may be omitted or simplified.
[0046] (Embodiment) [1. Configuration] An information processing system according to an embodiment will be described below. The information processing system is a system for evaluating the security risk of cyber attacks against a product. In the embodiment, the product is assumed to be an ECU (Electronic Control Unit) installed in a vehicle, but may be something other than an ECU.
[0047] Fig. 1 is a block diagram showing an example of an overall configuration including an information processing system according to an embodiment. As shown in Fig. 1, in the embodiment, the information processing system 1 is realized by a client 200. The client 200 is an information processing terminal such as a desktop or laptop personal computer. In the embodiment, it is assumed that the user of the client 200 is a member of an organization that purchases a product, but the user may also be a member of an organization that sells or rents a product.
[0048] The information processing system 1 communicates with the server 100 via a network such as the Internet to acquire security risk-related information stored in a storage unit 101 included in the server 100, and uses the acquired security risk-related information to evaluate the security risk of a cyber-attack against the product. The storage unit 101 is realized by an appropriate storage device such as a hard disk drive (HDD) or a solid state drive (SSD).
[0049] Here, the security risk-related information includes one or more data related to each of one or more evaluation items for evaluating the security risk of cyberattacks against a product. For example, if the one or more evaluation items are a first evaluation item, a second evaluation item, and a third evaluation item, the security risk-related information includes three pieces of data: first data related to the first evaluation item, second data related to the second evaluation item, and third data related to the third evaluation item. As will be described in more detail below, for example, if the evaluation item is "programming language used," the data corresponding to the evaluation item indicates the programming language used in the product, such as C language. The security risk-related information is extracted, for example, from documents describing the product configuration, product specifications, materials created by the product developer, the product itself, etc.
[0050] Note that the information processing system 1 may acquire security risk-related information input by a user at the client 200, instead of acquiring security risk-related information stored in the storage unit 101 from the server 100. The information processing system 1 may also acquire, for example, part of the security risk-related information from the storage unit 101 of the server 100. In this case, the information processing system 1 may acquire the data input by the user at the client 200 as the remaining security risk-related information.
[0051] Furthermore, the information processing system 1 may be realized by a server 100, for example, as shown in Fig. 2. Fig. 2 is a block diagram showing another example of the overall configuration including the information processing system 1 according to the embodiment. In the example shown in Fig. 2, a user can access the server 100 using a client 200 to cause the server 100 to execute a process for evaluating the security risk of a cyber-attack against a product.
[0052] 3 is a block diagram showing an example of the functional configuration of an information processing system 1 according to an embodiment. The information processing system 1 includes a processor and a memory, and realizes its functions by the processor executing a program stored in the memory. As shown in FIG. 3, the information processing system 1 includes an acquisition unit 11, a calculation unit 12, an output unit 13, a storage unit 14, and a communication unit 15.
[0053] The acquisition unit 11 acquires security risk information. FIG. 4 is an explanatory diagram of security risk information. As shown in FIG. 4, the security risk information is classified into security risk assessment information and security risk-related information. The security risk assessment information also includes one or more assessment items and one or more assessment criteria (described later). The security risk assessment information may also include one or more weighting coefficients (described later).
[0054] In the embodiment, the acquisition unit 11 acquires security risk-related information from the security risk information. Specifically, the acquisition unit 11 acquires the security risk-related information stored in the storage unit 101 included in the server 100 by communicating with the server 100 via the communication unit 15. Note that the acquisition unit 11 may also acquire security risk-related information input by the user to the client 200.
[0055] In the embodiment, the security risk assessment information of the security risk information is stored in the storage unit 14. Of course, the security risk assessment information may be acquired by the acquisition unit 11.
[0056] FIG. 5 is a diagram showing an example of categories to which each evaluation item belongs. Each evaluation item is classified into one or more categories including a total of four categories shown in FIG. 5: a "product function specifications" category, a "product implementation specifications" category, a "product modification frequency" category, and a "product attack observation frequency" category. The "product function specifications" category is a category to which evaluation items related to the functions of a product belong. The "product implementation specifications" category is a category to which evaluation items related to programs implemented in a product belong. The "product modification frequency" category is a category to which evaluation items related to modifications to software included in a product belong. The "product attack observation frequency" category is a category to which evaluation items related to responses to cyber attacks against a product belong.
[0057] The evaluation items will be explained below with reference to Fig. 6. Fig. 6 is a diagram showing an example of evaluation items. In Fig. 6, the "Category" column indicates the category to which the evaluation item belongs, the "Item ID (Identifier)" column indicates an ID for identifying the evaluation item, and the "Evaluation Item" column indicates the content of the evaluation item.
[0058] The "product functional specifications" category includes evaluation items such as "number of product functions" and "programming language used." The evaluation item "number of product functions" is an item that evaluates security risk based on the number of functions a product has. For example, if a product has a large number of functions, it is evaluated as having a high security risk. The evaluation item "programming language used" is an item that evaluates security risk based on the programming language used in the product. For example, if a product uses a programming language that does not have high memory safety, it is evaluated as having a high security risk.
[0059] Other evaluation items in the "product function specifications" category include "encryption," "external connection function," "internet communication function," "product developer," and "function name." The "encryption" evaluation item evaluates security risk based on whether communication data handled by the product is encrypted. For example, if communication data is not encrypted, the security risk is evaluated as high. The "external connection function" evaluation item evaluates security risk based on whether a product has a function for connecting to an external device. For example, if a product has a function for connecting to an external device, the security risk is evaluated as high. The "internet communication function" evaluation item evaluates security risk based on whether a product can connect to the Internet. For example, if a product can connect to the Internet, the security risk is evaluated as high. The "product developer" evaluation item evaluates security risk based on the development experience of the product developer. For example, if the product developer has insufficient development experience, the security risk is evaluated as high. The "function name" evaluation item evaluates security risk based on whether a product's function is important. For example, if a product's function is important, the security risk is evaluated as high.
[0060] As shown in FIG. 6, the "product implementation specifications" category includes evaluation items such as "program size" and "CPU (Central Processing Unit) usage rate." The "program size" evaluation item is an item for evaluating security risk based on the size of the program implemented in the product. For example, if the program size is large, the security risk is evaluated as high. The "CPU usage rate" evaluation item is an item for evaluating security risk based on the usage rate of the CPU of the product. For example, if the CPU usage rate is high, the security risk is evaluated as high.
[0061] Other evaluation items in the "Product Implementation Specifications" category include "Memory Usage," "Error Frequency," "Number of Program Functions," "Number of External Libraries Used," and "Number of Expansion Add-ins." The "Memory Usage" evaluation item evaluates security risk based on the amount of memory used by a product. For example, a high memory usage is evaluated as a high security risk. The "Error Frequency" evaluation item evaluates security risk based on the frequency of errors that occur when a program implemented in the product is executed. For example, a high error frequency is evaluated as a high security risk. The "Number of Program Functions" evaluation item evaluates security risk based on the number of program functions implemented in the product. For example, a large number of program functions is evaluated as a high security risk. The "Number of External Libraries Used" evaluation item evaluates security risk based on the number of external libraries used by a program implemented in the product. For example, a large number of external libraries used is evaluated as a high security risk. The "Number of Expansion Add-ins" evaluation item evaluates security risk based on the number of add-ins that extend the functions of a program implemented in the product. For example, a large number of add-ins is evaluated as a high security risk.
[0062] As shown in FIG. 6 , the "product update frequency" category includes evaluation items such as "number of firmware (FW) updates in the past year" and "number of days since the last FW update date." The evaluation item "number of firmware updates in the past year" is an item for evaluating security risk based on the number of updates in the past year of the FW implemented in the product. For example, if the number of updates is small, the security risk is evaluated as high. The evaluation item "number of days since the last FW update date" is an item for evaluating security risk based on the number of days since the last update date of the FW implemented in the product. For example, if the number of days since the last update date is large, the security risk is evaluated as high.
[0063] Other evaluation items that belong to the "product modification frequency" category include "whether or not there has been a major update," "whether or not there has been experience developing similar products," and "proportion of code changes." The evaluation item "whether or not there has been a major update" is an item that evaluates security risk based on whether or not the most recent update of the FW implemented in the product was a major update. For example, if the most recent update was a major update, the security risk is evaluated as high. The evaluation item "whether or not there has been experience developing similar products" is an item that evaluates security risk based on whether or not the developer of the product has experience developing similar products. For example, if the developer has no experience developing similar products, the security risk is evaluated as high. The "proportion of code changes" is an item that evaluates security risk based on the proportion of changes to the code of the FW implemented in the product. For example, if the proportion of code changes is large, the security risk is evaluated as high.
[0064] As shown in FIG. 6, the "frequency of observed product attacks" category includes evaluation items such as "whether or not a product has been attacked by a cyberattack in the past year." The evaluation item "whether or not a product has been attacked by a cyberattack in the past year" is an item for evaluating security risk based on whether or not a product has been attacked by a cyberattack in the past year. For example, if a product has been attacked by a cyberattack in the past year, the security risk is evaluated as high.
[0065] Other evaluation items that fall under the "frequency of observed product attacks" category include "latest FW application rate among product users" and "average vulnerability response time." The evaluation item "latest FW application rate among product users" is an item that evaluates security risk based on the probability that product users will apply the latest FW. For example, if the probability is low, the security risk is evaluated as high. The evaluation item "average vulnerability response time" is an item that evaluates security risk based on the average time it takes from the discovery of a vulnerability in the FW implemented in the product to the time it is addressed. For example, if the average time is long, the security risk is evaluated as high.
[0066] Next, the evaluation criteria will be described. The evaluation criteria are criteria used to evaluate the security risk of a product. In the embodiment, the information processing system 1 evaluates the security risk of a product for each evaluation item by determining whether the product satisfies the evaluation criteria corresponding to each evaluation item.
[0067] FIG. 7 is a diagram illustrating an example of evaluation criteria. As shown in FIG. 7, each evaluation criterion belongs to one of the categories of "product function specifications," "product implementation specifications," "product modification frequency," and "product attack observation frequency." In the example shown in FIG. 7, only the "product function specifications" and "product implementation specifications" categories are illustrated. In FIG. 7, the "Category" column represents the category to which the evaluation criterion belongs, the "Evaluation Criteria ID" column represents an ID for identifying the evaluation criterion, the "Evaluation Criteria Description" column represents an explanation of what the evaluation criterion evaluates, and the "Evaluation Criteria" column represents an explanation of which evaluation condition it corresponds to. Also, in FIG. 7, the "Evaluation Condition ID" column represents an ID for identifying the evaluation condition, the "Evaluation Item" column in the "Evaluation Condition" column represents the content of the evaluation item to be evaluated, the "Evaluation Item Requirement Criteria" column in the "Evaluation Condition" column represents the criteria required for the evaluation item to be evaluated, and the "Criteria-Specific Evaluation Value" column represents the evaluation value of the product's security risk for each evaluation criterion.
[0068] As shown in Fig. 7, each evaluation criterion is made up of one or more evaluation conditions. In the example shown in Fig. 7, the evaluation criteria "EC-11" and "EC-12" each consist of two evaluation conditions.
[0069] For example, when evaluating security risk for the evaluation item "number of functions," the evaluation criteria for "EC-01" and "EC-02" are referenced. Here, if the "number of functions" is "10 or more" as indicated by the "evaluation item requirement criteria" in the evaluation conditions for "ECD-01-01," the evaluation value for the evaluation item "number of functions" will be "10" in the "criteria-specific evaluation value." On the other hand, if the "number of functions" is "less than 10" as indicated by the "evaluation item requirement criteria" in the evaluation conditions for "ECD-01-02," the evaluation value for the evaluation item "number of functions" will be "5" in the "criteria-specific evaluation value."
[0070] Furthermore, for example, when evaluating security risks for the evaluation items "program size" and "CPU usage," the evaluation criteria of "EC-11" and "EC-12" are referenced. Here, if the "program size" is "10% or more of the memory installed in the product" as indicated by the "evaluation item requirement criteria" in the evaluation conditions of "ECD-11-01," and the "CPU usage" is "5% or more" as indicated by the "evaluation item requirement criteria" in the evaluation conditions of "ECD-11-02," the evaluation values for the evaluation items "program size" and "CPU usage" will be "10" in the "criteria-specific evaluation value." On the other hand, if the "program size" is "less than 10% of the memory installed in the product" as indicated by the "evaluation item requirement criteria" in the evaluation conditions of "ECD-12-01," and the "CPU usage" is "less than 5%" as indicated by the "evaluation item requirement criteria" in the evaluation conditions of "ECD-12-02," the evaluation values for the evaluation items "program size" and "CPU usage" will be "5" in the "criteria-specific evaluation value."
[0071] Next, security risk-related information will be described. Fig. 8 is a diagram showing an example of security risk-related information. In Fig. 8, the "Product ID" column represents an ID for identifying a product, the "Product Functional Specifications" column represents data for each evaluation item belonging to the "Product Functional Specifications" category among all evaluation items for the product, the "Product Implementation Specifications" column represents data for each evaluation item belonging to the "Product Implementation Specifications" category among all evaluation items for the product, the "Product Modification Frequency" column represents data for each evaluation item belonging to the "Product Modification Frequency" category among all evaluation items for the product, and the "Product Attack Observation Frequency" column represents data for each evaluation item belonging to the "Product Attack Observation Frequency" category among all evaluation items for the product.
[0072] For example, for a product with a "Product ID" of "PID-12," data on the evaluation item "Number of External Libraries Used" cannot be obtained. In this way, there may be security risk-related information that cannot be obtained depending on the product.
[0073] Furthermore, even if security risk-related information can be obtained, if an unexpected value is obtained, it may not be possible to evaluate the security risk of the product for the evaluation item corresponding to that value. For example, for a product with a "Product ID" of "PID-13," the evaluation item for "Product Developer" is "Vendor C." If "Vendor C" is a new vendor, there will be insufficient data about the product, and the security risk cannot be evaluated for the missing data.
[0074] The calculation unit 12 calculates a security risk assessment value by assessing security risk based on whether one or more data items included in the security risk-related information acquired by the acquisition unit 11 each satisfy one or more assessment criteria. In the embodiment, the calculation unit 12 classifies each of the one or more data items acquired by the acquisition unit 11 into one of the categories of "product function specifications," "product implementation specifications," "product modification frequency," and "product attack observation frequency," and evaluates the security risk of the product for each category. Hereinafter, the product security risk assessment value calculated for each category will be referred to as a "category-specific assessment value." Then, the calculation unit 12 calculates the product security risk assessment value by adding up the category-specific assessment values for each category.
[0075] FIG. 9 is a diagram showing an example of calculation of a category-specific evaluation value. The example shown in FIG. 9 represents an example of calculation of a category-specific evaluation value in the "product function specifications" category for a product whose "product ID" is "PID-14." In FIG. 9, the "acquisition stage" column indicates whether or not security risk-related information corresponding to the evaluation item has been acquired, and the "evaluation item acquisition value" column indicates the data of security risk-related information corresponding to the evaluation item. Also, in FIG. 9, the "compliance result" indicates whether or not the security-related information corresponding to the evaluation item complies with the evaluation criteria. Note that the other columns are the same as in FIG. 7, and therefore description thereof will be omitted here.
[0076] In the example shown in FIG. 9 , data for the evaluation item "number of functions" is obtained for a product with a "product ID" of "PID-14," and the data is "17." Here, for the data on the evaluation item "number of functions," the "compliance result" for the evaluation condition "ECD-21-01" is "compliance," while for the evaluation condition "ECD-22-01," the "compliance result" is "non-compliance." The "criterion-specific evaluation value" for the evaluation item "number of functions" is the sum of the "criterion-specific evaluation values" for which the "compliance result" is "compliance." In this case, since only the "compliance result" for the evaluation condition "ECD-21-01" is "compliance," the "criterion-specific evaluation value" for that evaluation condition, "10," becomes the "criterion-specific evaluation value" for the evaluation item "number of functions."
[0077] In the example shown in FIG. 9, data for the evaluation item "Programming Language Used" has not been obtained for the product with a "Product ID" of "PID-14." Therefore, the data for the evaluation item "Programming Language Used" cannot be determined. Therefore, the "criteria-specific evaluation value" for the evaluation item "Programming Language Used" is "0" because the "compliance result" for none of the evaluation conditions is "compliance." Note that, when the data for an evaluation item cannot be determined, it may be considered that there is a high security risk, and the "criteria-specific evaluation value" for that evaluation item may be set to the same "criteria-specific evaluation value" as when the evaluation criteria are met.
[0078] 9, the calculation unit 12 calculates the category-specific evaluation value of the "product function specifications" category of a product whose "product ID" is "PID-14" as "10" by adding up the "criteria-specific evaluation values" of the evaluation items in the "product function specifications" category. In this way, the calculation unit 12 calculates the category-specific evaluation value of each category.
[0079] 10 is a diagram showing an example of how security risk assessment values are calculated. In the example shown in FIG. 10, for a product whose "product ID" is "PID-15," the calculation unit 12 calculates the category-specific assessment value for the "product functional specifications" category as "50," the category-specific assessment value for the "product implementation specifications" category as "100," the category-specific assessment value for the "product modification frequency" category as "50," and the category-specific assessment value for the "product attack observation frequency" category as "100." Therefore, the calculation unit 12 adds up the category-specific assessment values for each category to calculate the security risk assessment value of the product as "300."
[0080] The output unit 13 outputs the security risk assessment value calculated by the calculation unit 12. In the embodiment, the output unit 13 outputs the security risk assessment value by displaying the security risk assessment value on a display provided in the client 200. Note that the output unit 13 may also output the security risk assessment value by transmitting data including the security risk assessment value to an external device via a network such as the Internet.
[0081] Fig. 11 is a diagram showing an example of an output result of a security risk assessment value. In the example shown in Fig. 11, the output unit 13 outputs a security risk assessment value for each product by displaying a table linking "product ID" with "security risk assessment value" on the display. Note that the display format of the security risk assessment value is not limited to the table shown in Fig. 11, and other display formats such as a bar graph may also be used.
[0082] The storage unit 14 is realized by an appropriate storage device such as an HDD or SSD. The storage unit 14 stores the security risk assessment information acquired by the acquisition unit 11 for each product. The storage unit 14 may also store the security risk-related information acquired by the acquisition unit 11 for each product. The storage unit 14 may also store the security risk assessment value calculated by the calculation unit 12 for each product.
[0083] The communication unit 15 is a communication interface that performs wired or wireless communication with the server 100 via a network such as the Internet.
[0084] [2. Operation] An example of operation of the information processing system 1 according to the embodiment will be described below. First, an overview of the processing of the information processing system 1 according to the embodiment will be described using Fig. 12 and Fig. 13. Fig. 12 is a sequence diagram showing an example of operation of the information processing system 1 according to the embodiment. Fig. 13 is a flowchart showing an example of operation of the information processing system 1 according to the embodiment.
[0085] First, the information processing system 1 determines a product to be evaluated (S11), as shown in Fig. 13. Specifically, when the user inputs a product to be evaluated on the client 200, the information processing system 1 determines the product as the product to be evaluated.
[0086] Next, the information processing system 1 acquires security risk assessment information (S12) as shown in Fig. 13. Specifically, the calculation unit 12 of the information processing system 1 acquires security risk assessment information by reading the security risk assessment information from the storage unit 14 as shown in Fig. 12 (S1).
[0087] Next, the information processing system 1 acquires security risk-related information (S13), as shown in Fig. 13. Specifically, the calculation unit 12 determines the security risk-related information to acquire based on the acquired security risk assessment information (S2), as shown in Fig. 12. Then, the calculation unit 12 acquires the determined security risk-related information from the security-related information acquired by the acquisition unit 11 (S3).
[0088] The specific content of step S2 will be described below. Step S2 is executed when one or more evaluation criteria differ for each product. Specifically, the calculation unit 12 extracts evaluation items by executing the process shown in FIG. 14. FIG. 14 is a flowchart showing an example of the process of extracting evaluation items. The calculation unit 12 acquires one or more evaluation criteria for the product to be evaluated from the acquired security risk assessment information (S21). Then, the calculation unit 12 extracts one or more evaluation items included in each of the acquired one or more evaluation criteria (S22).
[0089] Next, the specific content of step S3 will be described. Fig. 15 is a flowchart showing an example of processing for acquiring security risk-related information. The calculation unit 12 reads one or more evaluation items included in the acquired security risk assessment information (S31). Here, if step S2 is being executed, the calculation unit 12 reads one or more evaluation items extracted in step S2.
[0090] Next, the calculation unit 12 determines the security risk-related information to be acquired based on the one or more evaluation items that have been read (S32). Specifically, the calculation unit 12 determines to acquire security risk-related information that includes one or more data corresponding to each of the one or more evaluation items that have been read. For example, if the one or more evaluation items that have been read include an evaluation item for "number of functions," the calculation unit 12 determines to acquire security-related information that includes data corresponding to the evaluation item for "number of functions." On the other hand, if the one or more evaluation items that have been read include an evaluation item for "programming language used," the calculation unit 12 determines not to acquire security-related information that includes data corresponding to the evaluation item for "programming language used."
[0091] Then, the calculation unit 12 acquires security risk-related information belonging to each category (S3, S33). Specifically, the calculation unit 12 acquires security-related information including one or more pieces of data corresponding to one or more evaluation items belonging to the "product functional specifications" category among the one or more evaluation items. The calculation unit 12 also acquires security risk-related information for each of the "product implementation specifications" category, the "product modification frequency" category, and the "product attack observation frequency" category.
[0092] Next, the information processing system 1 calculates a security risk assessment value (S4, S14) as shown in Figures 12 and 13. Specifically, the calculation unit 12 calculates the security risk assessment value by executing the process shown in Figure 16.
[0093] FIG. 16 is a flowchart showing an example of a process for calculating a security risk assessment value. First, the calculation unit 12 evaluates the security risk related to the product function specifications (S41). Specifically, the calculation unit 12 calculates a category-specific assessment value for the "product function specifications" category using the security risk-related information for the "product function specifications" category acquired in step S33. Next, the calculation unit 12 evaluates the security risk related to the product implementation specifications (S42). Specifically, the calculation unit 12 calculates a category-specific assessment value for the "product implementation specifications" category using the security risk-related information for the "product implementation specifications" category acquired in step S33. Next, the calculation unit 12 evaluates the security risk related to the product modification frequency (S43). Specifically, the calculation unit 12 calculates a category-specific assessment value for the "product modification frequency" category using the security risk-related information for the "product modification frequency" category acquired in step S33. Next, the calculation unit 12 evaluates the security risk related to the frequency of observed product attacks (S44). Specifically, the calculation unit 12 calculates the category-specific evaluation value for the "product attack observation frequency" category using the security risk-related information for the "product attack observation frequency" category acquired in step S33. Note that the order in which steps S41 to S44 are performed is not limited to this order and may be other orders. Furthermore, steps S41 to S44 may be performed simultaneously in parallel.
[0094] 17 is a flowchart showing an example of a process for calculating a category-specific evaluation value. The process shown in FIG. 17 is executed in each of steps S41 to S44. First, the calculation unit 12 reads one or more evaluation criteria for the corresponding category (i.e., the category for which the category-specific evaluation value is to be calculated) (S51). Next, the calculation unit 12 determines whether or not there are any unevaluated evaluation criteria (S52). If there are any unevaluated evaluation criteria (S52: YES), the calculation unit 12 acquires one or more evaluation items included in each of the one or more evaluation criteria (S53).
[0095] Next, the calculation unit 12 determines whether security risk-related information corresponding to each of one or more evaluation items has been acquired (S54). If security risk-related information corresponding to the evaluation item has been acquired (S54: YES), the calculation unit 12 then determines whether the security risk-related information conforms to the evaluation criteria corresponding to the evaluation item (S55). If the security risk-related information conforms to the evaluation criteria (S55: YES), the calculation unit 12 sets the "conformance result" to "conformance" (S56). On the other hand, if the security risk-related information does not conform to the evaluation criteria (S55: NO), the calculation unit 12 sets the "conformance result" to "non-conformance" (S57). Furthermore, if security risk-related information corresponding to the evaluation item has not been acquired (S54: NO), the calculation unit 12 sets the "conformance result" to "determined" (S58).
[0096] Thereafter, the calculation unit 12 repeatedly executes the processes of steps S53 to S58 for each unevaluated evaluation criterion. When there are no more unevaluated evaluation criterion (S52: NO), the calculation unit 12 calculates the corresponding category-specific evaluation value (S59). Specifically, the calculation unit 12 calculates the category-specific evaluation value by adding up the "standard evaluation values" for which the "suitability result" is "suitable" in the corresponding category.
[0097] Then, the calculation unit 12 calculates a security risk assessment value (S45), as shown in Fig. 16. Specifically, the calculation unit 12 calculates a security risk assessment value from the calculated category-specific assessment values of each category. Fig. 18 is a flowchart showing an example of a process for calculating a security risk assessment value from category-specific assessment values. The calculation unit 12 calculates a security risk assessment value by adding up the category-specific assessment values of each category (S61) (S62). Here, the calculation unit 12 calculates the security risk assessment value by simply summing up the category-specific assessment values of each category.
[0098] The information processing system 1 then outputs the calculated security risk assessment value (S5, S15, S71) as shown in Figures 12, 13, and 19. Figure 19 is a flowchart showing an example of a process for outputting a security risk assessment value. Here, the output unit 13 of the information processing system 1 outputs the security risk assessment value by displaying the security risk assessment value calculated by the calculation unit 12 on a display provided in the client 200.
[0099] [3. Advantages] The advantages of the information processing system 1 (information processing method) according to the embodiment will be described below. As described above, the information processing system 1 according to the embodiment evaluates security risks based on whether one or more pieces of product data satisfy one or more evaluation criteria for at least one or more evaluation items among the product's functions, programs implemented in the product, software modifications in the product, and responses to cyberattacks against the product. Therefore, the information processing system 1 according to the embodiment has the advantage that, as long as one or more pieces of product data are obtained, security risks can be quantitatively evaluated not only before delivery of the product but also after delivery of the product, making it easy to evaluate the security risk of cyberattacks against the product.
[0100] In particular, the information processing system 1 according to the embodiment has the advantage of being easily versatile, meaning that the security risk of any product can be evaluated, since it can evaluate the security risk of a cyberattack against the product simply by acquiring one or more data sets about the product.Furthermore, the information processing system 1 according to the embodiment can use the latest data for one or more data sets about the product, one or more evaluation criteria, and one or more evaluation items used in the evaluation, so it has the advantage of being easily accurate, meaning that the security risk of a cyberattack against the product can be evaluated with high precision.
[0101] [4. Other Embodiments] Although the embodiments have been described above, the present disclosure is not limited to the above-described embodiments. Modifications of the embodiments are listed below. The first to tenth modifications listed below may be implemented in any suitable combination.
[0102] (First Variant) The information processing system 1 of the first variant differs from the information processing system 1 of the embodiment in that it determines one or more evaluation criteria based on the field to which the product belongs (hereinafter also referred to as the "product application field"), and calculates a security risk assessment value using the determined one or more evaluation criteria.
[0103] Fig. 20 is a diagram showing an example of product application fields in the first modified example. In Fig. 20, the column "Product Application Field ID" indicates an ID for identifying the product application field, and the column "Product Application Field" indicates the content of the field to which the product belongs. In the example shown in Fig. 20, the "standard" product application field is a field to which products that do not belong to any of the fields such as automobiles, IoT (Internet of Things), factories, and buildings belong.
[0104] FIG. 21 is a diagram showing an example of product application field information in the first modified example. The product application field information is information indicating which product application field each product belongs to, and is included in the security risk assessment information. In the example shown in FIG. 21, the product application field of a product with a "product ID" of "PID-21" is "factories," and the product application field of a product with a "product ID" of "PID-22" is "automobiles." In addition, in the example shown in FIG. 21, the product application fields of a product with a "product ID" of "PID-23" are "IoT" and "automobiles." In this way, one product may belong to multiple product application fields.
[0105] FIG. 22 is a diagram illustrating an example of security risk-related information in the first modified example. The example illustrated in FIG. 22 is an example of security risk-related information that takes into account the product application field. As illustrated in FIG. 22, this security risk-related information differs from the example of security risk-related information illustrated in FIG. 8 of the embodiment in that it includes an evaluation item, "Whether or Not MAC (Message Authentication Code) Authentication of CAN (Controller Area Network) Signals Is Performed," which is an evaluation item unique to the product application field of "Automobile" in the "Product Functional Specifications" category. The evaluation item, "Whether or Not MAC Authentication of CAN Signals Is Performed," evaluates security risk based on whether MAC authentication is performed in communication using CAN signals handled by the product. For example, if MAC authentication is not performed, the security risk is evaluated as high.
[0106] Fig. 23 is a diagram showing an example of evaluation criteria in the first modified example. The example shown in Fig. 23 is an example of evaluation criteria corresponding to the evaluation item "number of firmware updates in the last year" in the category "product update frequency" taking into account the product application field. As shown in Fig. 23, in this evaluation criteria, "evaluation item requirement criteria" are set for each product application field. Specifically, when the product application field is "standard," the "evaluation item requirement criteria" are set so that the "criteria-specific evaluation value" is high if the "number of firmware updates in the last year" is "less than 12 times."
[0107] On the other hand, when the product application field is "IoT," the "evaluation item requirement criteria" are set so that the "criteria-specific evaluation value" is high if the "number of firmware updates in the past year" is "less than 24 times," and the standard value is larger than when the product application field is "standard." This is because firmware updates are relatively frequent for products in the IoT field. Also, when the product application field is "automobiles," the "evaluation item requirement criteria" are set so that the "criteria-specific evaluation value" is high if the "number of firmware updates in the past year" is "less than 6 times," and the standard value is smaller than when the product application field is "standard." This is because firmware updates are relatively infrequent for products in the automotive field.
[0108] Fig. 24 is a flowchart showing an example of a process for acquiring evaluation criteria in Modification 1. In Modification 1, the information processing system 1 executes the process shown in Fig. 24 instead of step S21 (see Fig. 14) in the embodiment to acquire one or more evaluation criteria for the product to be evaluated from the acquired security risk assessment information.
[0109] Specifically, the calculation unit 12 first obtains the product application field to which the product belongs by referring to the product application field information (S81). Next, the calculation unit 12 determines whether there are multiple product application fields to which the product belongs (S82). If there are multiple product application fields to which the product belongs (S82: YES), the calculation unit 12 selects one of the product application fields (S83). Then, the calculation unit 12 determines whether the selected product application field has its own evaluation criteria (S84). Note that if there is only one product application field to which the product belongs (S82: NO), the calculation unit 12 executes step S84 without executing step S83.
[0110] If a unique evaluation criterion exists (S84: YES), the calculation unit 12 determines the evaluation criterion to be the evaluation criterion for the product application field (S85). On the other hand, if a unique evaluation criterion does not exist (S84: NO), the calculation unit 12 determines the evaluation criterion to be the evaluation criterion for the standard field (S86).
[0111] Specifically, for example, when the product application field is "automobiles," the calculation unit 12 calculates the security risk assessment value by further using an evaluation criterion corresponding to the evaluation item "whether or not MAC authentication of CAN signals is performed" in addition to the one or more evaluation criteria acquired in step S21 of the embodiment. Furthermore, when the product application field is "automobiles," for example, the calculation unit 12 uses the "evaluation item requirement criteria" for "automobiles." On the other hand, when the product application field is "standard" or when the product application field does not have its own evaluation criterion, the calculation unit 12 calculates the security risk assessment value by using the one or more evaluation criteria acquired in step S21 of the embodiment.
[0112] As described above, the first variant has the advantage that the security risk assessment value can be calculated taking into account the field to which the product belongs, making it easier to assess the security risk of cyber attacks against the product with greater accuracy.
[0113] Here, if a product belongs to multiple fields, the calculation unit 12 calculates a security risk assessment value for each product application field. Hereinafter, the security risk assessment value calculated for each product application field will be referred to as a "field-specific assessment value."
[0114] FIG. 25 is a diagram showing an example of a category-specific evaluation value in the first modified example. In the example shown in FIG. 25, a product with a "product ID" of "PID-31" belongs to two product application categories, "automobiles" and "IoT," and a category-specific evaluation value for the product application category of "automobiles" and a category-specific evaluation value for the product application category of "IoT" are calculated. In such a case, the calculation unit 12 may determine the category-specific evaluation value with the highest risk (the highest category-specific evaluation value in this modified example) as the security risk evaluation value. That is, when a product belongs to multiple categories, the calculation unit 12 may calculate multiple category-specific evaluation values by evaluating security risks for each of the multiple categories, and determine the highest category-specific evaluation value of the calculated multiple category-specific evaluation values as the security risk evaluation value. In the example shown in FIG. 25, since the category-specific evaluation value for the product application category of "automobiles" is the highest, the calculation unit 12 determines the category-specific evaluation value for the product application category of "automobiles" as the security risk evaluation value.
[0115] Here, the "evaluation value by category with the highest risk" corresponds to the "highest evaluation value by category" when, as in this modified example, the larger the evaluation value by category, the higher the security risk, i.e., when there is a positive correlation between the evaluation value by category and the security risk. On the other hand, when the smaller the evaluation value by category, the higher the security risk, i.e., when there is a negative correlation between the evaluation value by category and the security risk, the "evaluation value by category with the highest risk" corresponds to the "lowest evaluation value by category."
[0116] 26 is a flowchart showing an example of a process for calculating a security assessment value in the first modification. First, the calculation unit 12 calculates a category-specific assessment value for each product application category (S91). Then, the calculation unit 12 determines the highest category-specific assessment value among the calculated multiple category-specific assessment values as the security risk assessment value (S92).
[0117] Here, the output unit 13 may output the security risk assessment value by displaying a table linking "product IDs" with "security risk assessment values" on a display, similar to the table shown in FIG. 11 in the embodiment, but is not limited to this. For example, the output unit 13 may output the category-specific assessment value for each product application field by displaying a table linking "product IDs" with "category-specific assessment values" for each product application field on a display, similar to the table shown in FIG. 25. In this case, there is an advantage that the user can compare and consider multiple category-specific assessment values, making it easier to take measures such as changing one or more assessment criteria for a product application field whose category-specific assessment value significantly deviates from other category-specific assessment values.
[0118] (Second variant) The information processing system 1 of the second variant differs from the information processing system 1 of the embodiment in that it determines one or more evaluation criteria based on the product phase to which the product belongs at the time of use of the information processing system 1 (i.e., at the time of execution of the information processing method) during the process of producing the product, and calculates a security risk assessment value using the determined one or more evaluation criteria.
[0119] FIG. 27 is a diagram illustrating an example of product phase information in the second modified example. The product phase information indicates which categories are evaluated depending on the phase to which the product to be evaluated belongs, and is included in the security risk assessment information. In the example illustrated in FIG. 27 , when the product phase is in the “design” phase, only the “product function specifications” category is “target,” and the other categories are “not target.” In this case, the calculation unit 12 calculates only the category-specific evaluation value of the “product function specifications” category using one or more evaluation criteria for the “product function specifications” category, and does not calculate the category-specific evaluation values of the other categories. Therefore, in this case, the calculation unit 12 calculates the category-specific evaluation value of the “product function specifications” category as the security risk assessment value. Also, in the example illustrated in FIG. 27 , when the product phase is in the “release” phase, all categories are “target.” In this case, the calculation unit 12 calculates the category-specific evaluation value of each of all categories using one or more evaluation criteria for each of all categories. Therefore, in this case, the calculation unit 12 calculates the security risk assessment value by summing the category-specific evaluation values of all categories.
[0120] Fig. 28 is a flowchart showing an example of processing for acquiring security risk assessment information in Modification 2. In Modification 2, the information processing system 1 executes the processing shown in Fig. 28 instead of step S21 (see Fig. 14) in the embodiment, thereby acquiring one or more evaluation criteria for the product to be evaluated from the acquired security risk assessment information.
[0121] Specifically, the calculation unit 12 first acquires the product phase to which the product belongs by referring to the product phase information (S101), and then determines whether the acquired product phase has its own evaluation criteria (S102).
[0122] If a unique evaluation criterion exists (S102: YES), the calculation unit 12 determines the evaluation criterion as the product phase evaluation criterion (S103). On the other hand, if a unique evaluation criterion does not exist (S102: NO), the calculation unit 12 determines the common evaluation criterion (S104).
[0123] Specifically, for example, when the product phase is in the "design" stage, the calculation unit 12 calculates the security risk assessment value using only one or more evaluation criteria in the "product function specification" category. Also, for example, when the product phase is in the "release" stage, the calculation unit 12 calculates the security risk assessment value using one or more evaluation criteria in each of all categories.
[0124] As described above, the second variant has the advantage that the security risk assessment value can be calculated taking into account the product phase to which the product belongs at the time the information processing method is executed during the process of producing the product, making it easier to assess the security risk of cyber attacks against the product with greater accuracy.
[0125] (Third Variant) The information processing system 1 of the third variant differs from the information processing system 1 of the embodiment in that it updates one or more evaluation criteria according to the distribution of security risk-related information acquired by the acquisition unit 11.
[0126] FIG. 29 is a diagram illustrating an example of evaluation criteria in the third modified example. In the example shown in FIG. 29, the evaluation criteria corresponding to the evaluation item "number of functions" are determined based on the distribution of security risk-related information. Specifically, as shown in FIG. 29, the "evaluation item requirement criteria" in the evaluation conditions for "number of functions" are determined based on the "top 10% values" in the distribution of "number of functions" data for all evaluated products. In FIG. 29, the "evaluation item requirement criteria conversion result" indicates the absolute value obtained by converting the "top 10% values" in the distribution of "number of functions" data for all evaluated products at the time of use of the information processing system 1 (i.e., at the time of execution of the information processing method), which is "10." In addition, in FIG. 29, the "previous evaluation item requirement criteria conversion result" indicates the absolute value obtained by converting the "top 10% values" in the distribution of "number of functions" data for all evaluated products at the time of previous use of the information processing system 1, which is "6." In this way, the evaluation criteria corresponding to the evaluation item "number of functions" are updated based on the distribution of "number of functions" data for all evaluated products.
[0127] Fig. 30 is a diagram showing an example of a process for updating evaluation criteria in Modification 3. In Modification 3, the information processing system 1 executes the process of Fig. 30 when acquiring one or more evaluation criteria for a product to be evaluated from acquired security evaluation information.
[0128] Specifically, the calculation unit 12 first reads one or more evaluation criteria included in the acquired security risk assessment information (S111). Next, the calculation unit 12 determines whether each of the one or more evaluation criteria read is determined according to the security risk-related information (S112). If none of the evaluation criteria is determined according to the security risk-related information (S112: NO), none of the evaluation criteria are updated. On the other hand, if any of the evaluation criteria is determined according to the security risk-related information (S112: YES), the calculation unit 12 acquires security risk-related information including data on the evaluation items corresponding to the evaluation criteria for all products that were evaluated (S113). Then, the calculation unit 12 updates the evaluation criteria according to the distribution of the security risk-related information for all acquired products (S114).
[0129] As described above, the third variant updates the evaluation criteria according to the distribution of security risk-related information, which has the advantage of making it easier to maintain a constant proportion of products that meet the evaluation criteria among all products that are evaluated.
[0130] (Fourth Modification) The information processing system 1 of the fourth modification differs from the information processing system 1 according to the embodiment in that the security risk assessment value is calculated by further using one or more weighting factors each indicating the importance of one or more categories. The one or more weighting factors can also be referred to as the contribution to the security risk assessment. As already mentioned, the one or more weighting factors are included in the security risk assessment information (see FIG. 4).
[0131] 31 is a diagram showing an example of the correspondence between categories and weighting factors in the fourth modified example. As shown in FIG. 31, a weighting factor is set for each of the categories of "product function specifications," "product implementation specifications," "product modification frequency," and "product attack observation frequency." The larger the weighting factor, the greater the impact on security risk assessment. For example, evaluation items belonging to the "product implementation specifications" category have a larger impact on security risk due to specification changes than other categories, so a larger weighting factor is set for them than for other categories.
[0132] FIG. 32 is a diagram showing an example of calculation of security risk assessment values in the fourth modified example. In the example shown in FIG. 32 , for a product whose "product ID" is "PID-60," the calculation unit 12 calculates the category-specific assessment value for the "product functional specifications" category as "50," the category-specific assessment value for the "product implementation specifications" category as "100," the category-specific assessment value for the "product modification frequency" category as "50," and the category-specific assessment value for the "product attack observation frequency" category as "100." In addition, in the example shown in FIG. 32 , the weighting coefficients for the "product functional specifications" category are set to "0.2," "0.4," "0.3," and "0.1." The calculation unit 12 then multiplies the category-specific assessment value by the weighting coefficient for each category to calculate a weighted assessment value, and adds up the calculated weighted assessment values for each category to calculate a security risk assessment value of "75" for the product.
[0133] Fig. 33 is a flowchart showing an example of a process for acquiring weighting factors in the fourth modified example. In the fourth modified example, the information processing system 1 extracts evaluation items and acquires weighting factors by executing the process shown in Fig. 33 instead of steps S21 and S22 (see Fig. 14 ) in the embodiment. The calculation unit 12 acquires one or more evaluation criteria for the product to be evaluated from the acquired security risk assessment information (S121). Next, the calculation unit 12 extracts one or more evaluation items included in each of the acquired one or more evaluation criteria (S122). Next, the calculation unit 12 acquires one or more weighting factors set for one or more categories from the acquired security risk assessment information (S123).
[0134] FIG. 34 is a flowchart showing an example of a process for calculating a security risk assessment value in the fourth modified example. In the fourth modified example, the security risk assessment value is calculated by executing the process shown in FIG. 34 instead of steps S61 and S62 in the embodiment. The calculation unit 12 calculates the security risk assessment value by multiplying the category-specific assessment value by a weighting coefficient for each category and adding up the results (S131) (S132). Specifically, the calculation unit 12 calculates a weighted assessment value for each category by multiplying the category-specific assessment value by a weighting coefficient for each category. The calculation unit 12 then calculates the security risk assessment value by simply summing up the calculated weighted assessment values for each category.
[0135] As described above, the fourth variant has the advantage that the security risk assessment value can be calculated taking into account the contribution of each category to the security risk assessment, making it easier to assess the security risk of cyber attacks against products with greater accuracy.
[0136] (Fifth Variant) The information processing system 1 of the fifth variant differs from the information processing system 1 of the fourth variant in that it determines one or more weighting coefficients based on the field to which the product belongs, and calculates a security risk assessment value using the determined one or more weighting coefficients.
[0137] 35 is a diagram showing an example of the correspondence between product application fields and weighting factors in the fifth modified example. As shown in FIG. 35 , in the fifth modified example, weighting factors are set not only for the categories of “product function specifications,” “product implementation specifications,” “product modification frequency,” and “product attack observation frequency,” but also for each product application field, such as “standard,” “automotive,” “IoT,” and “factory.” For example, in the “IoT” product application field, the functions of the product and the programs implemented in the product are not significantly changed, and the impact on the security risk assessment is considered to be small, so the weighting factors for the “product function specifications” and “product implementation specifications” categories are set to be small. On the other hand, the impact on the security risk assessment is considered to be large due to the modifications of the software installed in the product and the frequency of cyberattacks against the product, so the weighting factors for the “product modification frequency” and “product attack observation frequency” categories are set to be large.
[0138] Fig. 36 is a flowchart showing another example of the process for acquiring weighting factors in Modification 5. In Modification 5, the information processing system 1 acquires weighting factors by executing the process shown in Fig. 36 instead of step S123 (see Fig. 33) in Modification 4.
[0139] Specifically, the calculation unit 12 first obtains the product application field to which the product belongs by referring to the product application field information (S141). Next, the calculation unit 12 determines whether there are multiple product application fields to which the product belongs (S142). If there are multiple product application fields to which the product belongs (S142: YES), the calculation unit 12 selects one of the product application fields (S143). Then, the calculation unit 12 determines whether the selected product application field has its own weight coefficient (S144). Note that if there is only one product application field to which the product belongs (S144: NO), the calculation unit 12 skips step S143 and executes step S144.
[0140] If a unique weighting factor exists (S144: YES), the calculation unit 12 acquires a weighting factor for the product application field (S145). On the other hand, if a unique weighting factor does not exist (S144: NO), the calculation unit 12 acquires a weighting factor for the standard field (S146).
[0141] As described above, the fifth variant has the advantage that the security risk assessment value can be calculated taking into account the contribution of the product to the security risk assessment of the field to which it belongs, making it easier to assess the security risk of cyber attacks against the product with even greater accuracy.
[0142] In the fifth modified example, a weighting factor is set for each category and each product application field, but a weighting factor may be set only for each product application field.
[0143] (Sixth Modification) The information processing system 1 of the sixth modification differs from the information processing system 1 of the fourth modification in that it determines one or more weighting factors based on the update frequency of one or more data items in a predetermined period, and calculates a security risk assessment value using the determined one or more weighting factors. Specifically, in the sixth modification, the weighting factor is set to a large value when one or more data items included in the security risk-related information frequently change due to changes in product specifications or the like in a predetermined period (for example, one year), and the weighting factor is set to a small value when one or more data items hardly change.
[0144] 37 is a diagram showing an example of the correspondence between the update frequency of security risk-related information and the weighting coefficient in the sixth modified example. In FIG. 37, the column "Average Annual Updates" indicates the average number of times data included in the acquired security risk-related information was updated in a year. For example, in the example shown in FIG. 37, the weighting coefficient for the "Product Implementation Specifications" category is set to be larger than that for other categories because data corresponding to the evaluation items belonging to that category fluctuates frequently. On the other hand, the weighting coefficient for the "Product Attack Observation Frequency" category is set to be smaller than that for other categories because data corresponding to the evaluation items belonging to that category hardly fluctuates at all.
[0145] FIG. 38 is a flowchart showing an example of a process for updating weighting factors in the sixth modified example. In the sixth modified example, the information processing system 1 executes the process shown in FIG. 38 , for example, at the timing when a weighting factor is acquired in step S123 (see FIG. 33 ) of the fourth modified example. First, the calculation unit 12 acquires a history of security risk-related information stored in, for example, the storage unit 14 (S151). Next, the calculation unit 12 calculates the update frequency (here, the average annual update count) of one or more pieces of data for each category based on the acquired history of security risk-related information (S152). Then, the calculation unit 12 updates the weighting factor for each category based on the calculated update frequency for each category (S153).
[0146] As described above, in the sixth variant, the security risk assessment value can be calculated taking into account the contribution of each category to the security risk assessment, which can change as data is updated, which has the advantage of making it easier to assess the security risk of cyber attacks against products with even greater accuracy.
[0147] (Seventh Modification) The information processing system 1 of the seventh modification differs from the information processing system 1 of the embodiment in that the information processing system 1 calculates a security risk assessment value based on whether one or more pieces of data included in past security risk-related information acquired before the time of use of the information processing system 1 (i.e., the time of execution of the information processing method) each satisfy one or more assessment criteria at the time of execution. In other words, in the seventh modification, the information processing system 1 assesses the security risk of a product at the time when the security risk-related information was acquired in the past based on one or more current assessment criteria.
[0148] 39 is a diagram showing an example of calculation of security risk assessment values in the seventh modified example. In FIG. 39, the column "category-specific assessment value" represents category-specific assessment values calculated using the previously acquired security risk-related information and one or more currently acquired assessment criteria. On the other hand, the column "previous category-specific assessment value" represents category-specific assessment values calculated using the previously acquired security risk-related information and one or more previously acquired assessment criteria. In the example shown in FIG. 39, the assessment criteria corresponding to the assessment items belonging to the "product functional specifications" and "product update frequency" categories are different between the previous and current cases, and therefore the category-specific assessment values have also changed.
[0149] Fig. 40 is a flowchart showing an example of a process for acquiring security-related information in the seventh modification. In the seventh modification, the information processing system 1 executes the process of Fig. 40 instead of step S13 (see Fig. 13 ) in the embodiment, thereby evaluating the security risk of a product at the time when security risk-related information was previously acquired based on one or more current evaluation criteria. The calculation unit 12 acquires past security-related information by reading out past security-related information stored in the storage unit 14 (S161).
[0150] As described above, the seventh variant has the advantage that the security risk of a product at the time when security risk-related information was obtained in the past can be evaluated based on one or more current evaluation criteria, making it easier to compare and consider the security risk of past products with the security risk of current products.
[0151] (Eighth Variant) The information processing system 1 of the eighth variant differs from the information processing system 1 of the embodiment in that it calculates a trend value indicating the trend of the security risk of the product based on the calculated security risk assessment value and a past security risk assessment value calculated before the time of use of the information processing system 1 (i.e., the time of execution of the information processing method).
[0152] Fig. 41 is a diagram showing an example of calculating a trend value in the eighth modified example. In Fig. 41, the "trend value" column shows values that indicate the trend of the security risk of a product, calculated based on the security risk assessment value calculated this time and the security risk assessment value calculated last time. Here, the trend value is the difference between the security risk assessment value calculated this time and the security risk assessment value calculated last time. Note that the trend value is not limited to the difference, and may be, for example, a value obtained by dividing the security risk assessment value calculated this time by the security risk assessment value calculated last time.
[0153] In the example shown in FIG. 41, the product with "Product ID" "PID-100" has a smaller current security risk assessment value than the product with "Product ID" "PID-101". Therefore, the former product appears to have a lower security risk than the latter product. On the other hand, the product with "Product ID" "PID-100" has a higher trend value than the product with "Product ID" "PID-101". Therefore, it can be seen that the security risk of the former product is on an increasing trend compared to the latter product.
[0154] FIG. 42 is a flowchart showing an example of a process for calculating a trend value in the eighth modification. In the eighth modification, the information processing system 1 calculates a trend value by executing the process shown in FIG. 42 instead of steps S61 and S62 (see FIG. 18 ) in the embodiment. First, the calculation unit 12 adds up the category-specific evaluation values of each category (S171) to calculate a current security risk evaluation value (S172). Next, the calculation unit 12 determines whether or not past security risk evaluation values exist in the storage unit 14 (S173). If past security risk evaluation values do not exist (NO in S173), the calculation unit 12 terminates the process without calculating a trend value. On the other hand, if past security risk evaluation values exist (YES in S173), the calculation unit 12 reads the past security risk evaluation values from the storage unit 14 to obtain the past security risk evaluation values (S174). Then, the calculation unit 12 calculates a trend value based on the current security risk evaluation value and the past security risk evaluation values (S175).
[0155] As described above, the eighth variant has the advantage that by referring to the trend value, it becomes easier to grasp trends in the security risks of a product that cannot be captured by the product's current security risks alone.
[0156] (Ninth Modification) The information processing system 1 of the ninth modification differs from the information processing system 1 of the first modification in that the information processing system 1 calculates one or more category-specific evaluation values that evaluate the security risk for each of one or more categories and outputs the calculated one or more category-specific evaluation values. That is, in the ninth modification, the output unit 13 outputs not only the security risk evaluation value but also the category-specific evaluation value for each category.
[0157] FIG. 43 is a diagram showing an example of the output results of the security risk assessment value and the category-specific assessment value in the ninth modification. In the example shown in FIG. 43, the output unit 13 outputs the security risk assessment value for each product and the category-specific assessment value for each category by displaying on the display a table linking the "product ID," "product application field," "security risk assessment value," and the "category-specific assessment value" of each category. In the example shown in FIG. 43, a product with a "product ID" of "PID-110" and a product with a "product ID" of "PID-111" both have the same security risk assessment value, but the former has a higher category-specific assessment value in the "product update frequency" category, and the latter has a higher category-specific assessment value in the "product function specifications" category. Therefore, the user can understand that for the former, priority should be given to addressing the security risk of software updates in the product, and for the latter, priority should be given to addressing the security risk of the product's functions.
[0158] The display format of the security risk assessment value and the category-specific assessment value of each category is not limited to the table shown in FIG. 43, and other display formats such as bar graphs may also be used.
[0159] 44 is a flowchart showing an example of a process for outputting a security risk assessment in the ninth modification. First, the output unit 13 outputs the security risk assessment value calculated by the calculation unit 12 (S181). Then, the output unit 13 further outputs the category-specific assessment value of each category calculated by the calculation unit 12 (S182). Here, the output unit 13 outputs the security risk assessment value and the category-specific assessment value of each category by displaying the security risk assessment value and the category-specific assessment value of each category on a display provided in the client 200.
[0160] As described above, the ninth variant not only outputs an assessment of the overall security risk of the product, but also an assessment of the security risk for each category, which has the advantage that the user can easily understand which category of security risk should be given priority.
[0161] (Tenth Variant) The information processing system 1 of the tenth variant differs from the information processing system 1 of the first variant in that it outputs the time series changes in the security risk assessment value based on the calculated security risk assessment value and a past security risk assessment value calculated before the time when the information processing system 1 is used (i.e., the time when the information processing method is executed).
[0162] Figure 45 is a diagram showing an example of output of security risk assessment values in the tenth modified example. In the example shown in Figure 45(a), the output unit 13 outputs a security risk assessment value for each product by displaying on the display a table linking "product ID," "product application field," and "security risk assessment value." Also, in the example shown in Figure 45(a), the output unit 13 outputs security risk assessment values for "January 2024," "February 2024," "March 2024," and "April 2024." Note that the security risk assessment value for "April 2024" is the security risk assessment value calculated this time.
[0163] In the example shown in Figure 45(b), the output unit 13 outputs the time-series changes in the security risk assessment value by displaying a line graph on the display showing the time-series changes in the security risk assessment value. In the example shown in Figure 45(b), by looking at the line graph, the user can easily visually understand that the current security risk assessment value of each product is the same, but that the security risk assessment value of the product with "Product ID" "PID-120" is rising rapidly. Note that the table shown in Figure 45(a) and the line graph shown in Figure 45(b) may be displayed on the display simultaneously.
[0164] The display format of the security risk assessment value is not limited to a table as shown in Fig. 45(a) but may be other display formats such as a bar graph, etc. Furthermore, the display format of the time-series changes in the security risk assessment value is not limited to a line graph as shown in Fig. 45(b) but may be other display formats such as a bar graph, etc.
[0165] 46 is a flowchart showing an example of a process for outputting a security risk assessment value in the tenth modification. First, the output unit 13 outputs the security risk assessment value calculated by the calculation unit 12 (S191). Then, the output unit 13 reads past security risk assessment values from the storage unit 14 and outputs the time-series changes in the security risk assessment value (S192). Here, the output unit 13 outputs the time-series changes in the security risk assessment value by displaying the time-series changes in the security risk assessment value on a display provided in the client 200.
[0166] As described above, the tenth variant outputs the time-series changes in the security risk assessment value, which has the advantage that the user can easily grasp sudden changes or future fluctuations in the security risk of the product.
[0167] (Eleventh Modification) The information processing system 1 of the eleventh modification differs from the information processing system 1 of the first modification in that it calculates one or more category-specific evaluation values that evaluate the security risk for each of one or more categories, highlights and outputs any category-specific evaluation value that exceeds a predetermined risk among the one or more calculated category-specific evaluation values, and outputs a countermeasure for lowering the category-specific evaluation value. The information processing system 1 of the eleventh modification also differs from the information processing system 1 of the first modification in that it calculates one or more evaluation item-specific evaluation values that evaluate the security risk for each of one or more evaluation items, highlights and outputs any evaluation item-specific evaluation value that exceeds a predetermined risk (exceeds a threshold in this modification) among the calculated one or more evaluation item-specific evaluation values, and outputs a countermeasure for lowering the evaluation item-specific evaluation value.
[0168] Here, exceeding a "predetermined risk" corresponds to "exceeding a threshold" when, as in this modified example, the larger the category-specific evaluation value (or the evaluation value for each evaluation item), the higher the security risk, i.e., when there is a positive correlation between the category-specific evaluation value (or the evaluation value for each evaluation item) and the security risk. On the other hand, when the smaller the category-specific evaluation value (or the evaluation value for each evaluation item), the higher the security risk, i.e., when there is a negative correlation between the category-specific evaluation value (or the evaluation value for each evaluation item) and the security risk, "exceeding a predetermined risk" corresponds to "falling below a threshold." Note that the threshold used for comparison with the category-specific evaluation value and the threshold used for comparison with the evaluation value for each evaluation item are different values, but they may also be the same value.
[0169] Examples of countermeasures for each evaluation item are listed below. First, countermeasures in the "product function specifications" category are listed. For example, a countermeasure for the evaluation item "programming language used" is to change to a programming language with high memory security. For example, a countermeasure for the evaluation item "whether encryption is used" is to encrypt communication data. For example, a countermeasure for the evaluation item "whether external connection function is used" is to remove or suspend unnecessary functions for connecting to external devices. For example, a countermeasure for the evaluation item "whether Internet communication function is used" is to remove or suspend unnecessary communication functions. For example, a countermeasure for the evaluation item "number of product functions" is to reduce unnecessary functions. For example, a countermeasure for the evaluation item "product developer" is to provide supervision or training by an experienced developer. For example, a countermeasure for the evaluation item "function name" is to strengthen the security of important functions.
[0170] Next, we will list countermeasures in the "Product Implementation Specifications" category. For example, a countermeasure for the evaluation item "Program Size" is to optimize the code to reduce the program size. For example, a countermeasure for the evaluation item "CPU Usage" is to reduce the CPU load through efficient processing. For example, a countermeasure for the evaluation item "Memory Usage" is to optimize processing to improve memory efficiency. For example, a countermeasure for the evaluation item "Error Frequency" is to identify and correct the cause of the error. For example, a countermeasure for the evaluation item "Number of Program Functions" is to reduce unnecessary functions. For example, a countermeasure for the evaluation item "Number of Expansion Add-ins" is to reduce unnecessary add-ins.
[0171] Next, countermeasures in the "product update frequency" category are listed. For example, a countermeasure for the evaluation item "presence or absence of major updates" is to recheck for vulnerabilities and implement minor updates as necessary. For example, a countermeasure for the evaluation item "number of days since last FW update" is to implement regular updates. For example, a countermeasure for the evaluation item "number of FW updates in the past year" is to update the FW frequently. For example, a countermeasure for the evaluation item "presence or absence of experience developing similar products" is to gain development experience or seek advice from an experienced developer. For example, a countermeasure for the evaluation item "percentage of code changes" is to aim to maintain a stable code base.
[0172] Next, we will list countermeasures in the "Frequency of Observed Product Attacks" category. For example, a countermeasure for the evaluation item "Whether or not there have been any cyberattacks on products in the past year" is to strengthen security measures and prevent cyberattacks before they occur. For example, a countermeasure for the evaluation item "Latest FW application rate among product users" is to encourage users to update to the latest version. For example, a countermeasure for the evaluation item "Average vulnerability response time" is to implement a prompt response to vulnerabilities.
[0173] 47 is a diagram showing an example of output of security risk assessment values in the eleventh modified example. In the example shown in (a) of FIG. 47, the output unit 13 displays on the display a table linking "product ID," "product application field," "security risk assessment value," and "category-specific assessment value" of each category, thereby outputting the security risk assessment value for each product and the category-specific assessment value for each category. Also, in the example shown in (a) of FIG. 47, the output unit 13 outputs category-specific assessment values that exceed a threshold value (e.g., 25) in bold, thereby emphasizing the category-specific assessment value. In this example, since the category-specific assessment value for the "product implementation specifications" category exceeds the threshold value, the category-specific assessment value is highlighted on the display.
[0174] In the example shown in FIG. 47(b), the output unit 13 displays a table linking "categories" and "category-specific evaluation values" on the display, thereby outputting the category-specific evaluation values for each category. In the example shown in FIG. 47(b), the output unit 13 outputs category-specific evaluation values that exceed a threshold (e.g., 25) in bold, thereby emphasizing the category-specific evaluation values. Furthermore, the output unit 13 outputs the countermeasures for the category in bold, thereby emphasizing the countermeasures for the category. In this example, since the category-specific evaluation value for the "product implementation specifications" category exceeds the threshold, the category-specific evaluation value and the countermeasures for the category are displayed on the display with emphasis. The table shown in FIG. 47(a) and the table shown in FIG. 47(b) may be displayed on the display simultaneously.
[0175] FIG. 48 is a diagram showing another example of output of security risk assessment values in the eleventh modification. In the example shown in FIG. 48 , the output unit 13 displays a table linking "category," "assessment item," and "assessment value per evaluation item" on the display for a category whose category-specific assessment value exceeds a threshold, thereby outputting the assessment value per evaluation item for each assessment item belonging to the category. Also, in the example shown in FIG. 48 , the output unit 13 outputs assessment value per evaluation item that exceeds a threshold (e.g., 10) in bold, thereby emphasizing the assessment value per evaluation item. Furthermore, the output unit 13 outputs the countermeasure for the assessment item in bold, thereby emphasizing the countermeasure for the assessment item. In this example, since the assessment value per evaluation item for the "number of program functions" assessment item in the "product implementation specifications" category exceeds the threshold, the assessment value per evaluation item and the countermeasure for the assessment item are highlighted on the display. The table shown in FIG. 48 may be displayed on the display simultaneously with at least one of the table shown in FIG. 47(a) and the table shown in FIG. 47(b).
[0176] 49 is a flowchart showing an example of a process for outputting a security risk assessment value in the eleventh modification. First, the output unit 13 outputs the security risk assessment value calculated by the calculation unit 12 (S201). Next, the output unit 13 determines the highest category-specific assessment value among the category-specific assessment values calculated by the calculation unit 12 (S202). Note that in step S202, the output unit 13 may determine a category-specific assessment value that exceeds a threshold value among the category-specific assessment values of each category. Next, the output unit 13 outputs the category-specific assessment value of the relevant category determined in step S202 while emphasizing it (S203).
[0177] Next, the output unit 13 determines whether or not there is a category with a high category-specific evaluation value, i.e., whether or not there is a category whose category-specific evaluation value exceeds a threshold (S204). If a corresponding category is present (S204: YES), the output unit 13 outputs a countermeasure for the corresponding category (S205). Here, the output unit 13 may output the countermeasure for the corresponding category while emphasizing it. On the other hand, if a corresponding category is not present (S204: NO), the output unit 13 executes step S206 without executing step S205. Then, the output unit 13 executes a process of outputting the evaluation items for each category while emphasizing them (S206).
[0178] 50 is a flowchart showing an example of the process of highlighting and outputting evaluation items for each category in the eleventh modified example (step S206 in FIG. 49 ). First, the output unit 13 determines the highest evaluation value for each evaluation item among the evaluation values for each evaluation item calculated by the calculation unit 12 (S211). Note that in step S211, the output unit 13 may determine an evaluation value for each evaluation item that exceeds a threshold value among the evaluation values for each evaluation item. Next, the output unit 13 highlights and outputs the evaluation value for the corresponding evaluation item determined in step S211 (S212).
[0179] Next, the output unit 13 determines whether there is an evaluation item with a high evaluation value for each evaluation item, i.e., whether there is an evaluation item whose evaluation value for each evaluation item exceeds a threshold (S213). If there is a corresponding evaluation item (S213: YES), the output unit 13 outputs a countermeasure for the corresponding evaluation item (S214). Here, the output unit 13 may output the countermeasure for the corresponding evaluation item while emphasizing it. On the other hand, if there is no corresponding evaluation item (S213: NO), the output unit 13 ends the process without executing step S214.
[0180] As described above, the eleventh variant emphasizes relatively high category-specific evaluation values and outputs countermeasures to lower those category-specific evaluation values, which has the advantage that the user can easily understand which categories have high security risks and can easily implement those countermeasures.
[0181] Furthermore, in the eleventh variant, relatively high evaluation values for each evaluation item are emphasized and countermeasures for lowering the evaluation value for each evaluation item are output, which has the advantage that the user can easily understand which evaluation items have a high security risk and can easily implement those countermeasures.
[0182] In the eleventh modification, the output unit 13 highlights the corresponding category-specific evaluation value, evaluation item-specific evaluation value, and countermeasure by making them bold, but this is not limiting. For example, the output unit 13 may highlight the corresponding category-specific evaluation value, evaluation item-specific evaluation value, and countermeasure by making the font larger, changing the line type, changing the color, or surrounding them with a frame.
[0183] (Other Modifications) In the above-described embodiment, the processing performed by a specific processing unit may be performed by another processing unit. The order of multiple processing operations may be changed, or multiple processing operations may be performed in parallel.
[0184] In the above-described embodiments, each component may be realized by executing a software program suitable for that component, or by a program execution unit such as a CPU or processor reading and executing a software program recorded on a recording medium such as a hard disk or semiconductor memory.
[0185] Furthermore, each component may be realized by hardware. For example, each component may be a circuit (or integrated circuit). These circuits may form a single circuit as a whole, or each may be a separate circuit. Furthermore, each of these circuits may be a general-purpose circuit or a dedicated circuit.
[0186] Furthermore, the general or specific aspects of the present disclosure may be realized as an apparatus, a method, an integrated circuit, a computer program, or a computer-readable recording medium such as a CD-ROM, etc. Furthermore, the general or specific aspects of the present disclosure may be realized as any combination of an apparatus, a method, an integrated circuit, a computer program, and a recording medium.
[0187] For example, the present disclosure may be realized as an information processing method executed by a computer, or as a program for causing a computer to execute the information processing method. The present disclosure may also be realized as a computer-readable non-transitory recording medium on which such a program is recorded.
[0188] In addition, this disclosure also includes forms obtained by applying various modifications to the embodiments that a person skilled in the art would think of, or forms realized by arbitrarily combining the components and functions of the embodiments within the scope that does not deviate from the intent of this disclosure.
[0189] The present disclosure is useful in assessing the security risks of a product.
[0190] REFERENCE SIGNS LIST 1 Information processing system 11 Acquisition unit 12 Calculation unit 13 Output unit 14 Storage unit 15 Communication unit 100 Server 101 Storage unit 200 Client
Claims
1. An information processing method comprising: acquiring security risk-related information including one or more data for a product related to each of one or more evaluation items for assessing the security risk of cyber-attacks against the product; calculating a security risk assessment value that evaluates the security risk based on whether the one or more data included in the acquired security risk-related information each meets one or more evaluation criteria; and outputting the calculated security risk assessment value, wherein each of the one or more evaluation items is classified into one or more categories including a category to which evaluation items related to functions possessed by the product belong, a category to which evaluation items related to programs implemented in the product belong, a category to which evaluation items related to modifications to software possessed by the product belong, and a category to which evaluation items related to responses to cyber-attacks against the product belong.
2. The information processing method according to claim 1, further comprising determining the one or more evaluation criteria based on the field to which the product belongs, and calculating the security risk evaluation value using the determined one or more evaluation criteria.
3. The information processing method according to claim 2, wherein, if the product belongs to multiple categories, multiple category-specific evaluation values are calculated by evaluating the security risk for each of the multiple categories, and the category-specific evaluation value with the highest risk among the multiple calculated category-specific evaluation values is determined to be the security risk evaluation value.
4. An information processing method according to any one of claims 1 to 3, wherein the one or more evaluation criteria are determined based on the product phase to which the product belongs at the time when the information processing method is executed during the process of producing the product, and the security risk assessment value is calculated using the determined one or more evaluation criteria.
5. An information processing method according to any one of claims 1 to 4, wherein the one or more evaluation criteria are updated according to the distribution of the acquired security risk-related information.
6. An information processing method according to any one of claims 1 to 5, further comprising calculating the security risk assessment value using one or more weighting factors indicating the importance of each of the one or more categories.
7. The information processing method according to claim 6, further comprising determining the one or more weighting factors based on the field to which the product belongs, and calculating the security risk assessment value using the determined one or more weighting factors.
8. An information processing method according to claim 6 or 7, wherein the one or more weighting factors are determined based on the update frequency of the one or more data items over a predetermined period, and the security risk assessment value is calculated using the determined one or more weighting factors.
9. An information processing method according to any one of claims 1 to 8, wherein the security risk assessment value is calculated based on whether or not the one or more pieces of data contained in past security risk-related information obtained before the time of execution of the information processing method each satisfy the one or more evaluation criteria at the time of execution.
10. An information processing method according to any one of claims 1 to 9, wherein a trend value indicating the trend of the security risk of the product is calculated based on the calculated security risk assessment value and a past security risk assessment value calculated before the time the information processing method is executed.
11. An information processing method according to any one of claims 1 to 10, further comprising: calculating one or more category-specific evaluation values that evaluate the security risk for each of the one or more categories; and outputting the calculated one or more category-specific evaluation values.
12. An information processing method according to any one of claims 1 to 11, wherein the time series change in the security risk assessment value is output based on the calculated security risk assessment value and a past security risk assessment value calculated before the time the information processing method is executed.
13. An information processing method according to any one of claims 1 to 12, further comprising: calculating one or more category-specific evaluation values that evaluate the security risk for each of the one or more categories; highlighting and outputting, among the one or more calculated category-specific evaluation values, those that exceed a predetermined risk; and outputting countermeasures for lowering the category-specific evaluation values.
14. An information processing method according to any one of claims 1 to 13, which calculates one or more evaluation item-specific evaluation values that evaluate the security risk for each of the one or more evaluation items, highlights and outputs evaluation item-specific evaluation values that exceed a predetermined risk from among the calculated one or more evaluation item-specific evaluation values, and outputs countermeasures for lowering the evaluation item-specific evaluation value.
15. A program causing one or more processors to execute the information processing method according to any one of claims 1 to 14.
16. An information processing system comprising: an acquisition unit that acquires security risk-related information including one or more data of the product related to each of one or more evaluation items for evaluating the security risk of cyber-attacks against the product; a calculation unit that calculates a security risk evaluation value that evaluates the security risk based on whether the one or more data included in the security risk-related information acquired by the acquisition unit each satisfy one or more evaluation criteria; and an output unit that outputs the security risk evaluation value calculated by the calculation unit, wherein each of the one or more evaluation items is classified into one or more categories including a category to which evaluation items related to functions possessed by the product belong, a category to which evaluation items related to programs implemented in the product belong, a category to which evaluation items related to modifications to software possessed by the product belong, and a category to which evaluation items related to responses to cyber-attacks against the product belong.
Citation Information
Patent Citations
Risk assessment method and device for Internet of Things equipment
CN117155593A
System, method, and program for automated health check and risk assessment of computing assets
JP2023546842A
Product risk profile
US20170200006A1
Device-Based Security Scoring
US20210279337A1
Systems and methods for proactively monitoring the inherent cyber-tech risk of software and hardware components
US20240187439A1