Information processing method, information processing device, and program
The method automates the creation of an allow list for vulnerability attacks, reducing unnecessary alerts and workload by identifying protected devices, thus addressing excessive alert generation in existing systems.
Patent Information
- Application Number
- PCT/JP2025/023995
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-07-26
- Filing Date
- 2025-07-03
- Publication Date
- 2026-01-29
AI Technical Summary
Existing systems generate excessive alerts for vulnerability attacks, leading to increased workload for Security Operation Centers (SOCs) due to overdetection and manual vulnerability investigations, despite some devices having implemented countermeasures.
An information processing method and device that automatically creates an allow list for devices based on vulnerability status, determining whether to output alerts only when a device is vulnerable and not protected, reducing unnecessary alerts.
Reduces the number of alerts for vulnerability attacks, minimizing SOC workload and resource expenditure by automating the process of identifying and managing device vulnerabilities.
Smart Images

Figure JP2025023995_29012026_PF_FP_ABST
Abstract
Description
Information processing method, information processing device, and program
[0001] The present disclosure relates to an information processing method, an information processing device, and a program.
[0002] Conventionally, a system has been disclosed that can reduce the operational costs of updating whitelists while achieving both security against cyber attacks and convenience for users (see, for example, Patent Document 1).
[0003] The system disclosed in Patent Document 1 updates security level information that defines the security level of a predetermined event for each resource that can be the subject or target of access. Specifically, the system disclosed in Patent Document 1 determines whether a predetermined access is permitted or not using a predetermined algorithm based on the security level information of each resource related to the predetermined access, and updates the security level information of the predetermined resource related to the predetermined access using the predetermined algorithm.
[0004] Patent No. 6884652
[0005] Cyber attacks include those that exploit vulnerabilities in devices (vulnerability attacks). When a vulnerability attack is detected by, for example, an IDS (Intrusion Detection System), the IDS outputs an alert to an SOC (Security Operation Center) or the like. Vulnerability attacks are often the initial step in malware infection. Therefore, alerts output in response to vulnerability attacks cannot be ignored by the SOC.
[0006] Here, in the past, when a vulnerability attack was detected, an alert was output regardless of whether the device that was the target of the vulnerability attack had taken measures against the vulnerability attack. Therefore, because an alert was output every time a vulnerability attack was detected, even if measures against the vulnerability attack had been taken, the SOC required a lot of effort to check the output alert, etc.
[0007] The present disclosure provides an information processing method and the like that can reduce the number of times alerts are output in response to vulnerability attacks.
[0008] An information processing method according to one aspect of the present disclosure determines whether a specified device has a first vulnerability based on specified information, and based on the result of the determination of whether the specified device has the first vulnerability, links device information indicating the specified device to first vulnerability information indicating the first vulnerability and registers it in an authorization list, and when the specified device is attacked through an attack exploiting the first vulnerability, determines based on the authorization list whether to output an alert indicating that the specified device has been attacked through an attack exploiting the first vulnerability.
[0009] An information processing device according to one aspect of the present disclosure includes a processor and a memory, and the processor uses the memory to determine whether a specific device has a first vulnerability based on specific information, and based on the determination result of whether the specific device has the first vulnerability, links device information indicating the specific device to first vulnerability information indicating the first vulnerability and registers it in an authorization list, and when the specific device is attacked through an attack exploiting the first vulnerability, determines based on the authorization list whether to output an alert indicating that the specific device has been attacked through the first vulnerability.
[0010] A program according to one aspect of the present disclosure is a program for causing a computer to execute the information processing method described above.
[0011] According to the present disclosure, it is possible to provide an information processing method that can reduce the number of times alerts are output in response to vulnerability attacks.
[0012] FIG. 1 is a diagram illustrating a configuration of a network system according to an embodiment. FIG. 2 is a diagram illustrating a configuration of an intrusion detection device according to an embodiment. FIG. 3 is a sequence diagram illustrating a first example of processing executed in a network system according to an embodiment. FIG. 4 is a diagram illustrating a first example of an allowance list according to an embodiment. FIG. 5 is a diagram illustrating a second example of an allowance list according to an embodiment. FIG. 6 is a sequence diagram illustrating a second example of processing executed in a network system according to an embodiment. FIG. 7 is a diagram illustrating a third example of an allowance list according to an embodiment. FIG. 8 is a flowchart illustrating a processing procedure of an intrusion detection device according to an embodiment. FIG. 9 is a diagram illustrating a fourth example of an allowance list according to an embodiment. FIG. 10 is a diagram illustrating a fifth example of an allowance list according to an embodiment. FIG. 11 is a diagram illustrating a sixth example of an allowance list according to an embodiment. FIG. 12 is a diagram illustrating a seventh example of an allowance list according to an embodiment. FIG. 13 is a sequence diagram illustrating a third example of processing executed in a network system according to an embodiment. FIG. 14 is a diagram illustrating an eighth example of an allowance list according to an embodiment. FIG. 15 is a flowchart illustrating an information processing method according to an embodiment.
[0013] (Findings that form the basis of the present disclosure) IDSs are used to monitor, for example, operational technology (OT) or development networks in factories and the like. The IDS detects unauthorized communication packets in the network, such as communication packets intended for cyber attacks. When the IDS detects unauthorized communication packets, it outputs (notifies) an alert to the SOC.
[0014] The IDS detects, for example, malware, Denial of Service (DoS) attacks, brute force attacks, and vulnerability attacks. If the IDS detects a vulnerability attack, it outputs an alert regardless of whether or not countermeasures against the vulnerability have been implemented in the device targeted by the attack. Because vulnerability attacks are often the initial step in malware infection, the SOC cannot ignore these alerts.
[0015] When an SOC receives an alert issued in response to a vulnerability attack, the SOC, for example, contacts the user of the device that was the target of the attack to confirm whether countermeasures against the vulnerability have been taken. Furthermore, because vulnerability attacks are detected, for example, by simple signature matching, there are many cases of overdetection (false positive detection). Therefore, the number of alerts issued regarding vulnerability attacks tends to increase, and the man-hours required to respond to the alerts are also large, requiring a lot of effort on the SOC's part.
[0016] Furthermore, devices that are targets of attacks include various devices other than PCs (Personal Computers), and there are cases where the OS (Operating System) or applications used by each device are not managed, countermeasures against vulnerabilities in each device are not managed, or each device uses an OS or application that has vulnerabilities.
[0017] Therefore, conventionally, the investigation of device vulnerabilities has been performed manually and requires a lot of time. Therefore, the investigation of device vulnerabilities is performed every time a vulnerability attack is detected, which puts a strain on the work of the SOC. Furthermore, vulnerabilities are discovered every day, and the types of vulnerabilities continue to increase.
[0018] Therefore, the inventors of the present application have discovered a method for automatically creating an allow list specialized for vulnerabilities. For example, even if a vulnerability attack is detected against a device registered on the allow list, an alert is not output. This reduces the number of times alerts are output in response to vulnerability attacks.
[0019] Hereinafter, the embodiments will be specifically described with reference to the drawings.
[0020] The embodiments described below are all comprehensive or specific examples. The numerical values, shapes, materials, components, component placement and connection configurations, steps, and step order shown in the following embodiments are merely examples and are not intended to limit the present disclosure. Furthermore, among the components in the following embodiments, components that are not recited in the independent claims of the present disclosure are described as optional components. Furthermore, the drawings are not necessarily strict illustrations. In the drawings, substantially identical components are denoted by the same reference numerals, and redundant descriptions may be omitted or simplified.
[0021] Furthermore, in this specification, ordinal numbers such as "first" and "second" do not refer to the number or order of components unless otherwise specified, but are used for the purpose of avoiding confusion and distinguishing between components of the same type.
[0022] (Embodiment) [Configuration] FIG. 1 is a diagram showing the configuration of a network system 10 according to an embodiment.
[0023] The network system 10 is a system that detects abnormalities in communication packets sent or received by devices 210 to 250. The network system 10 includes an intrusion detection device 100, a plurality of devices, and a switch device 300.
[0024] In this example, five devices are shown as devices 210, 220, 230, 240, and 250 included in the network system 10. The number of devices included in the network system 10 may be any number and is not particularly limited.
[0025] The devices 210 to 250 are, for example, devices capable of communicating with a communication device connected to a network 400 such as the Internet via the switch device 300 (for example, IoT (Internet of Things) devices). Examples of the types of the devices 210 to 250 include repeaters, scanners, printers, smartphones, and PCs. The types of the devices 210 to 250 may be any type and are not particularly limited. Each of the devices 210 to 250 is an example of a predetermined device.
[0026] The switch device 300 is a device that functions as a relay for communication between a communication device connected to the network 400 and the devices 210 to 250. For example, the switch device 300 forwards a communication packet received from the communication device via the network 400 to one of the devices 210 to 250, and forwards a communication packet received from the devices 210 to 250 to the communication device via the network 400.
[0027] The switch device 300 also functions as a network switch that performs mirroring. Specifically, the switch device 300 transmits a copy of a received communication packet to the intrusion detection device 100.
[0028] The intrusion detection device 100 is a computer that detects abnormalities in communication packets. The intrusion detection device 100 is a so-called IDS that monitors and analyzes communication packets sent or received by the devices 210 to 250. The intrusion detection device 100 has, for example, analysis rules for detecting abnormalities in communication packets (specifically, information indicating the analysis rules) and detects abnormalities in communication packets using the analysis rules. When the intrusion detection device 100 detects an abnormality in a communication packet, that is, when it detects an attack, it outputs an alert indicating the detection of the attack to the SOC (specifically, a computer such as a PC used in the SOC). In this embodiment, the intrusion detection device 100 detects cyber attacks that exploit vulnerabilities (also referred to as vulnerability attacks). The intrusion detection device 100 is an example of an information processing device. Note that the devices (in this embodiment, the devices 210 to 250) whose communication packets the intrusion detection device 100 monitors and analyzes are also referred to as monitoring targets.
[0029] The intrusion detection device 100 is realized, for example, by a communication interface, non-volatile memory storing a program, volatile memory serving as a temporary storage area for executing the program, an input / output port for transmitting and receiving signals, and a processor for executing the program. The communication interface may be realized, for example, by an antenna and a wireless communication circuit for wireless communication, or by a connector to which a communication line is connected for wired communication. Note that communication performed in the network system 10 may be wired or wireless. Furthermore, any communication standard may be used for communication performed in the network system 10.
[0030] FIG. 2 is a diagram showing the configuration of the intrusion detection device 100 according to the embodiment.
[0031] The intrusion detection device 100 includes an acquisition unit 110, an abnormality detection unit 120, a notification unit 130, a vulnerability detection execution unit 140, a vulnerability information update unit 150, a vulnerability detection management unit 160, an authorization list management unit 170, an asset information management unit 180, and a memory unit 190.
[0032] The acquisition unit 110 is a processing unit that acquires communication packets and various information. For example, the acquisition unit 110 acquires communication packets from the switch device 300, analyzes the acquired communication packets, acquires asset information indicating software (specifically, the type of software) used by the devices 210 to 250, and acquires vulnerability information indicating the type of vulnerabilities that the software has (in other words, vulnerabilities contained in the software) from server devices connected to the network 400. The types of vulnerabilities indicated by the vulnerability information may be determined arbitrarily and are not particularly limited. The vulnerability information is, for example, information indicating the type of attack that causes the monitored object to perform abnormal behavior.
[0033] The anomaly detection unit 120 is a processing unit that detects communication anomalies. Specifically, the anomaly detection unit 120 detects anomalies in communication packets by analyzing the communication packets. In this embodiment, the anomaly detection unit 120 detects vulnerability attacks. Specifically, the anomaly detection unit 120 determines whether or not a monitoring target (in this embodiment, at least one of the devices 210 to 250) has been subjected to a vulnerability attack. Of course, the anomaly detection unit 120 may detect attacks other than vulnerability attacks.
[0034] The notification unit 130 is a processing unit that notifies of an abnormality, in other words, outputs an alert. Specifically, when the abnormality detection unit 120 detects an abnormality, the notification unit 130 transmits an alert (alert information) indicating the detection of the abnormality to a computer or the like used in the SOC via a communication interface provided in the intrusion detection device 100.
[0035] The alert may include information indicating that an abnormality has been detected, in other words, information indicating that the monitored object has been attacked, or may include information indicating which of multiple monitored objects has been attacked, or may include information indicating the type of attack, or may include any information related to the attack.
[0036] The vulnerability detection execution unit 140 is a processing unit that detects vulnerabilities of the monitored devices (specifically, whether or not the devices 210 to 250 have vulnerabilities). Specifically, the vulnerability detection execution unit 140 determines whether or not the devices 210 to 250 have vulnerabilities based on predetermined information. More specifically, the vulnerability detection execution unit 140 determines whether or not each of the devices 210 to 250 has one or more types of vulnerabilities.
[0037] The predetermined information is information used to detect whether or not the devices 210 to 250 have vulnerabilities. The predetermined information is, for example, information including asset information. The asset information is information related to the devices 210 to 250. The asset information includes, for example, information indicating the type of software (type of software) used by the devices 210 to 250.
[0038] The asset information may include information indicating the type of software, such as the software name, or may include information indicating both the type of software and the version of the software. Examples of software include an OS or an application. The asset information may include only information indicating the type of OS, or may include information indicating the type of OS and the version of the OS. For example, the asset information may include information indicating the name of the OS, such as Windows (registered trademark) or UBUNTU (registered trademark), as the type of OS. The asset information may also include information indicating the version of the same product family (Windows in this example), such as Windows 7 or Windows 10. The asset information may also include information indicating the applications used by the devices 210-250 (e.g., information indicating the names of the applications) and information indicating the versions of the applications.
[0039] For example, the acquisition unit 110 acquires asset information from each of the devices 210 to 250 by transmitting a request signal requesting asset information to the devices 210 to 250. In this case, for example, if the acquisition unit 110 is able to acquire asset information from the devices 210 to 250, the vulnerability detection execution unit 140 determines whether or not the devices 210 to 250 have vulnerabilities based on the asset information. On the other hand, for example, if the acquisition unit 110 is unable to acquire asset information from the devices 210 to 250, the vulnerability detection execution unit 140 executes a vulnerability scan on the devices 210 to 250 to determine whether or not the devices 210 to 250 have vulnerabilities. In other words, the vulnerability detection execution unit 140 determines whether or not the devices 210 to 250 have vulnerabilities based on the asset information for monitoring targets for which asset information was acquired, and determines whether or not the devices 210 to 250 have vulnerabilities by executing a vulnerability scan for monitoring targets for which asset information was not acquired.
[0040] A vulnerability scan (vulnerability diagnosis) is a process for detecting whether or not a monitored target has vulnerabilities. For example, a vulnerability scan detects vulnerabilities in a monitored target by sending a communication packet containing parameters indicating abnormal values to the monitored target and checking the response from the monitored target. Another example of a vulnerability scan involves determining whether or not the monitored target is using the latest security patches. A vulnerability scan requires a large amount of processing because it involves sending various parameters and analyzing the response. Specifically, a vulnerability scan may cause the monitored target to stop operating in some cases. Furthermore, a vulnerability scan requires a large amount of processing compared to a process that simply determines whether or not a monitored target has vulnerabilities based on asset information. Therefore, in this embodiment, the vulnerability detection execution unit 140 does not execute a vulnerability scan on a monitored target whose vulnerability status has already been determined from asset information.
[0041] There are no particular limitations on the method by which the acquisition unit 110 acquires the asset information. For example, the acquisition unit 110 may acquire communication packets (e.g., communication packets transmitted during normal communication or communication logs indicating the contents of the communication packets) transmitted from the devices 210 to 250, and acquire the asset information by identifying the types of software used by the devices 210 to 250 based on the acquired communication packets.
[0042] The vulnerability information update unit 150 is a processing unit that updates the vulnerability information stored in the storage unit 190 based on the vulnerability information acquired by the acquisition unit 110. As a result, for example, the latest vulnerability information is stored in the storage unit 190. Furthermore, for example, the vulnerability information update unit 150 updates the logic for acquiring asset information and the logic for detecting vulnerabilities, both of which are stored in the storage unit 190.
[0043] The vulnerability detection management unit 160 is a processing unit that manages information about the presence or absence of vulnerabilities in the devices 210 to 250, which is stored in the storage unit 190, based on the presence or absence of vulnerabilities in the devices 210 to 250 detected by the vulnerability detection execution unit 140. The vulnerability detection management unit 160 also manages plans, such as the timing of the vulnerability detection process executed by the vulnerability detection execution unit 140 and the logic of the detection process. For example, the vulnerability detection management unit 160 stores this information in the storage unit 190 and updates this information stored in the storage unit 190. For example, when the vulnerability detection management unit 160 acquires information indicating such a plan from a computer used by an analyst, such as an SOC, the vulnerability detection management unit 160 stores the acquired information indicating the plan in the storage unit 190. The vulnerability detection execution unit 140 executes a process to detect vulnerabilities, for example, based on the information indicating such a plan stored in the storage unit 190.
[0044] The allowance list management unit 170 is a processing unit that manages the allowance list (allowance list information) stored in the storage unit 190. Specifically, the allowance list management unit 170 associates device information indicating the devices 210 to 250 with vulnerability information indicating vulnerabilities, based on the determination result of the vulnerability detection execution unit 140 as to whether or not the devices 210 to 250 have vulnerabilities, and registers the linked device information indicative of the devices 210 to 250 in the allowance list. As described above, in this embodiment, the allowance list is not updated manually by, for example, an analyst at the SOC, but is automatically updated by the allowance list management unit 170.
[0045] The permission list (automatic permission list) is information indicating whether to output an alert when a vulnerability attack is detected on one of the devices 210 to 250. For example, the notification unit 130 determines whether to output an alert based on the permission list when a vulnerability attack is detected. For example, if the device 210 has a vulnerability, the notification unit 130 outputs an alert when the device 210 is attacked by a vulnerability attack. On the other hand, if the device 210 does not have a vulnerability, the notification unit 130 does not output an alert when the device 210 is attacked by a vulnerability attack. In this way, when the device 210 to 250 is attacked by an attack that exploits a vulnerability (i.e., a vulnerability attack), the notification unit 130 determines, based on the permission list, whether to output an alert indicating that the device 210 to 250 has been attacked by an attack that exploits a vulnerability. The notification unit 130 outputs or does not output an alert based on the determination result.
[0046] For example, the allowance list includes vulnerability information indicating a vulnerability and software information indicating the type of software that is subject to attacks exploiting the vulnerability. There are multiple types of vulnerabilities and multiple types of software. Therefore, the allowance list includes multiple pieces of vulnerability information and, for each of the multiple pieces of vulnerability information, software information indicating the type of software that is subject to attacks exploiting the vulnerability. For example, the allowance list includes first vulnerability information indicating a first vulnerability, first software information indicating the type of software that is subject to attacks exploiting the first vulnerability, second vulnerability information indicating a second vulnerability different from the first vulnerability, and second software information indicating the type of software that is subject to attacks exploiting the second vulnerability. In this embodiment, the allowance list includes information indicating the type of vulnerability, information indicating the OS and version of the OS that has the vulnerability, and information indicating devices that will not output an alert when the device is subjected to an attack exploiting the vulnerability. In this embodiment, the allowance list also includes information indicating devices for which the vulnerability detection execution unit 140 will not perform a vulnerability scan. For example, if the allowance list management unit 170 determines that the devices 210 to 250 are not vulnerable, it links the device information indicating the devices 210 to 250 with the vulnerability information and registers it in the allowance list. On the other hand, if the allowance list management unit 170 determines that the devices 210 to 250 are vulnerable, it does not link the device information indicating the devices 210 to 250 with the vulnerability information and register it in the allowance list. For example, if the allowance list management unit 170 determines that the device 210 is not vulnerable, it links the device information indicating the device 210 with the vulnerability information and registers it in the allowance list. Furthermore, if the allowance list management unit 170 determines that the device 220 is vulnerable, it does not register the device information indicating the device 220 in the allowance list. For example, when determining whether to output the above-mentioned alert, the notification unit 130 determines whether the device information linked to the vulnerability information is registered in the permission list if the anomaly detection unit 120 determines that the devices 210 to 250 have been attacked due to a vulnerability, that is, if the devices 210 to 250 have been attacked by exploiting a vulnerability.When the notification unit 130 determines that device information linked to the vulnerability information is registered in the permission list, the notification unit 130 determines not to output an alert and does not output the alert. When the notification unit 130 determines that device information linked to the vulnerability information is not registered in the permission list, the notification unit 130 determines to output an alert and does not output the alert. Specifically, in determining whether to output the alert, when the anomaly detection unit 120 determines that the device 210 has been subjected to an attack that exploits a vulnerability (vulnerability attack), the notification unit 130 determines whether device information indicating the device 210 linked to the vulnerability information is registered in the permission list. When the notification unit 130 determines that device information indicating the device 210 linked to the vulnerability information is registered in the permission list, the notification unit 130 determines not to output an alert and does not output the alert. When the notification unit 130 determines that device information indicating the device 210 linked to the vulnerability information is not registered in the permission list, the notification unit 130 determines to output an alert and does not output the alert.
[0047] Note that there are multiple types of vulnerabilities. For example, vulnerability information is linked to device information and registered in the allow list for each type of vulnerability. For example, if the allow list management unit 170 determines that the device 210 does not have a first vulnerability, it links the device information indicating the device 210 with the vulnerability information indicating the first vulnerability (first vulnerability information) and registers the device information in the allow list. However, if the allow list management unit 170 determines that the device 210 has a second vulnerability of a different type from the first vulnerability, it does not link the device information indicating the device 210 with the vulnerability information indicating the second vulnerability (second vulnerability information) and register the device information in the allow list.
[0048] The allow list may also be a list of devices that have vulnerabilities. In this case, for example, if the device 210 is attacked by a vulnerability and the device information for the device 210 is registered in the allow list, an alert is output. On the other hand, for example, if the device 210 is attacked by a vulnerability and the device information for the device 210 is not registered in the allow list, no alert is output.
[0049] For example, the allow list management unit 170 may determine whether or not the devices 210-250 have vulnerabilities based on the allow list. That is, the allow list management unit 170 may determine, based on the vulnerability information, software information, and device information already registered in the allow list, whether or not to link the device information with the vulnerability information to be newly added to the allow list and register it, and update the allow list based on the determination result. For example, the allow list management unit 170 may link device information indicating a monitoring target with first vulnerability information and register it in the allow list, and then determine, based on the allow list, whether or not the monitoring target has a second vulnerability, and based on the determination result of the presence or absence of the second vulnerability, register the device information in the allow list linked with the second vulnerability information.
[0050] The asset information management unit 180 is a processing unit that updates (manages) the asset information stored in the storage unit 190 based on the asset information acquired by the acquisition unit 110. The asset information management unit 180 also manages the timing of the asset information acquisition process executed by the acquisition unit 110, as well as the logic of the acquisition process and other plans. For example, the asset information management unit 180 stores this information in the storage unit 190 and updates this information stored in the storage unit 190.
[0051] Each processing unit, such as the acquisition unit 110, the anomaly detection unit 120, the notification unit 130, the vulnerability detection execution unit 140, the vulnerability information update unit 150, the vulnerability detection management unit 160, the permission list management unit 170, and the asset information management unit 180, is realized, for example, by a memory and a processor, such as a CPU (Central Processing Unit), that executes a control program stored in the memory. The memory included in these processing units may be realized by a shared memory, or by one or more independent memories. Furthermore, the processor included in these processing units may be realized by a processor shared by each processing unit, or by one or more independent processors.
[0052] The storage unit 190 is a storage device that stores various types of information, such as an authorization list, asset information, vulnerability information, and analysis rules.
[0053] The storage unit 190 is realized by a storage device such as a semiconductor memory or a hard disc drive (HDD), for example.
[0054] The intrusion detection device 100 may also collectively register device information for multiple monitoring targets in an allow list. For example, devices performing particularly important processing in a factory, unlike other devices, may be prevented from using vulnerable software or may be specially monitored daily by a manager working in the factory, and thus may already have vulnerability countermeasures in place. Therefore, the intrusion detection device 100 may collectively register multiple such monitoring targets in an allow list. For example, the specified information may be information (group information) indicating a group to which the monitoring targets for which vulnerability countermeasures have been implemented belong. For example, the vulnerability detection execution unit 140 may determine whether multiple monitoring targets belonging to a specified group have vulnerabilities based on specified information (specifically, group information). Furthermore, the allow list management unit 170 may collectively register multiple device information indicating multiple monitoring targets, each associated with vulnerability information, in an allow list based on the determination results. In addition, when any of these multiple monitored targets is attacked by a vulnerability, the notification unit 130 determines, based on the permission list, whether or not to output an alert indicating that any of the multiple monitored targets (i.e., the monitored target that has been attacked by a vulnerability) has been attacked by a vulnerability, and outputs the alert based on the determination result.
[0055] The groups to which each of the multiple monitoring targets belongs may be determined arbitrarily and are not particularly limited. The multiple monitoring targets are classified into one of multiple groups based on, for example, the network segment (for example, one of a group that outputs an alert and a group that does not output an alert when a vulnerability attack is detected). For example, among the multiple monitoring targets, monitoring targets that belong to the same network segment are classified into the same group, and monitoring targets that belong to different network segments are classified into different groups.
[0056] Furthermore, after a monitoring target (e.g., a first device) has been registered on the allow list, the group information may be used to determine whether a different monitoring target (e.g., a second device) should be registered on the allow list. For example, the group information may include information indicating groups categorized by devices using the same software. For example, the intrusion detection device 100 may use this information to determine whether a second device, different from the first device, belongs to the same group as the first device. If the intrusion detection device 100 determines that the second device belongs to the same group as the first device, the intrusion detection device 100 may determine that the second device has the same vulnerability as the first device, and may register the second device on the allow list, linking the vulnerability information to the second device.
[0057] [Processing Procedure] Next, the processing in the network system 10 will be described.
[0058] 3 is a sequence diagram showing a first example of processing executed in network system 10 according to an embodiment. Specifically, FIG. 3 is a diagram showing a specific example of a processing procedure in which intrusion detection device 100 updates the permission list based on asset information. Note that FIG. 3 shows intrusion detection device 100, device 210, and device 220, which are components included in network system 10 shown in FIG. 1.
[0059] First, the intrusion detection device 100 executes an asset information acquisition process (S110). The asset information acquisition process is a process for acquiring asset information from the devices 210 and 220. Specifically, the asset information acquisition process involves the following steps S111 to S113.
[0060] The intrusion detection device 100 requests asset information from each of the devices 210 and 220 by transmitting a request signal requesting asset information to the devices 210 and 220 (S111).
[0061] Next, upon receiving the request signal, the devices 210 and 220 transmit, for example, asset information stored therein to the intrusion detection device 100. For example, the device 210 transmits asset information indicating that the OS type is YYY10 and the version is 22H1 to the intrusion detection device 100 (S112). Meanwhile, if the type of OS used by the device 220 is unknown, the device 210 transmits information indicating that the OS type is unknown to the intrusion detection device 100 (S113). For example, the intrusion detection device 100 may determine that the OS type used by the device is unknown if there is no response to the request information within a predetermined period of time. Alternatively, for example, the intrusion detection device 100 may determine that the OS type is unknown if the OS type indicated in the asset information acquired from the device 220 is not a predetermined type. The predetermined type may be determined arbitrarily in advance and is not particularly limited.
[0062] Next, the intrusion detection device 100 updates the permission list based on the responses from the devices 210 and 220 (S120).
[0063] FIG. 4 is a diagram illustrating a first example of a permission list according to the embodiment.
[0064] The permission list includes, for example, information indicating the type of vulnerability ("Vulnerability" shown in Figure 4), information indicating the OS and version of the OS that has the vulnerability ("Target OS" and "Target Version" shown in Figure 4), information indicating monitored targets for which the vulnerability detection execution unit 140 will not perform a vulnerability scan ("Devices not subject to scan" shown in Figure 4), and information indicating monitored targets for which an alert will not be issued if the monitored target is attacked using the vulnerability ("Devices not subject to alert" shown in Figure 4).
[0065] For example, if the OS type is XXX and the version is 18.04.1 LTS, the OS has V1 (hereinafter also referred to as vulnerability V1), which is an example of a vulnerability type. In other words, a monitoring target using XXX, whose version is 18.04.1 LTS, as its OS has vulnerability V1. Therefore, if a monitoring target with vulnerability V1 is subjected to an attack that exploits vulnerability V1 (hereinafter also referred to as a vulnerability V1 attack), there is a risk that the monitoring target will malfunction due to the vulnerability V1 attack. On the other hand, a monitoring target using YYY10, whose version is 22H1, as its OS does not have vulnerability V1. Therefore, even if a monitoring target that does not have vulnerability V1 is subjected to a vulnerability V1 attack, it is considered that there will be no particular impact from the vulnerability V1 attack.
[0066] For example, the items “Vulnerability,” “Target OS,” and “Target Version” in the permission list are registered in advance by a user or the like, or updated (registered) by the vulnerability information update unit 150 .
[0067] The information registered in the "Target Version" field may be used, for example, to determine whether the OS version used by the monitoring target matches the version indicated in the information. In other words, the "Target Version" may indicate, for example, the version itself. The "Target Version" may also indicate a version lower than the version indicated, or a range of versions. In other words, the information registered in the "Target Version" field may be used, for example, to determine whether the OS version used by the monitoring target is lower than the version indicated in the information, or whether it is included in the range of versions indicated in the information.
[0068] The intrusion detection device 100 (specifically, the permission list management unit 170) registers device information in the "devices not subject to scanning" and "devices not subject to alerts" fields based on the asset information.
[0069] In the example shown in FIG. 3 , the device 210 uses OS version YYY10, 22H1. Therefore, in the example shown in FIG. 4 , the device 210 has vulnerability V2 but does not have vulnerability V1, V3, or VN. In this case, the allowance list management unit 170 registers device information indicating the device 210 (in the example shown in FIG. 4 , “first device”) in the columns corresponding to vulnerability V1, V3, and VN in the “non-alert target device” section of the allowance list. Meanwhile, the allowance list management unit 170 does not register device information indicating the device 210 in the column corresponding to vulnerability V2 in the “non-alert target device” section of the allowance list. As a result, for example, the intrusion detection device 100 (specifically, the notification unit 130) does not output an alert if the device 210 is attacked with vulnerability V1, V3, or VN. Meanwhile, the intrusion detection device 100 outputs an alert if the device 210 is attacked with vulnerability V2.
[0070] Furthermore, since the intrusion detection device 100 (specifically, the allow list management unit 170) determines whether or not the device 210 has a vulnerability based on the asset information, the intrusion detection device 100 (specifically, the vulnerability detection execution unit 140) registers device information indicating the device 210 in the "devices not subject to scanning" list. As a result, the intrusion detection device 100 (specifically, the vulnerability detection execution unit 140) does not execute a vulnerability scan on the device 210.
[0071] Furthermore, since the type of OS used by the device 220 is unknown, the device information indicating the device 220 is not registered in the permission list.
[0072] 3, after step S120, a vulnerability V1 scan process is performed on, for example, the device 220 for which the presence or absence of a vulnerability has not been determined (S130). The vulnerability V1 scan process is a process for detecting the presence or absence of vulnerability V1 in the monitored device. Specifically, the vulnerability V1 scan process involves the following steps S131 to S132.
[0073] The intrusion detection device 100 executes a vulnerability V1 scan on the device 220 (S131). For example, the intrusion detection device 100 transmits to the device 220 a communication packet including an abnormal parameter that causes a specific response if the device 220 has vulnerability V1.
[0074] Next, the device 220 responds to the vulnerability V1 scan. Here, for example, it is assumed that the device 220 responds normally to a communication packet containing abnormal parameters that would cause an abnormal response if the device 220 had vulnerability V1 (S132). In this case, it is determined that the device 220 does not have vulnerability V1.
[0075] Next, the intrusion detection device 100 updates the permission list based on the execution result of step S130 (S140).
[0076] 5 is a diagram showing a second example of an allow list according to an embodiment of the present invention, in which only the information related to vulnerability V1 is shown among the information included in the allow list.
[0077] Assume that the intrusion detection device 100 determines that the device 220 does not have vulnerability V1 by executing step S130. In this case, the intrusion detection device 100 updates the permission list shown in FIG. 4 by registering device information indicating the device 220 (the "second device" shown in FIG. 5) in the "device not subject to scanning" and "device not subject to alerts" fields corresponding to vulnerability V1.
[0078] The intrusion detection device 100 determines (detects) whether or not the device 220 has each type of vulnerability by, for example, executing a vulnerability scan on the device 220 according to each type of vulnerability.
[0079] 6 is a sequence diagram illustrating a second example of processing executed in the network system 10 according to the embodiment. Specifically, FIG. 6 illustrates a specific example of an alert output process when a vulnerability attack is detected. Of the components included in the network system 10 shown in FIG. 1, FIG. 6 illustrates the intrusion detection device 100, the device 210, and the device 220.
[0080] 7 is a diagram illustrating a third example of an allowance list according to an embodiment of the present invention. The processing procedure illustrated in FIG. 6 is a processing procedure performed, for example, when the intrusion detection device 100 stores the allowance list illustrated in FIG. 7.
[0081] As shown in FIG. 6, first, it is assumed that the device 210 is performing communication that is suspected to be a vulnerability V2 attack (S210).
[0082] In this case, for example, it is assumed that the intrusion detection device 100 (specifically, the anomaly detection unit 120) detects that the device 210 is being attacked using vulnerability V2 (S220).
[0083] When the intrusion detection device 100 detects that the device 210 is under attack due to vulnerability V2, the intrusion detection device 100 checks the permission list (S230). Specifically, the intrusion detection device 100 determines whether device information indicating the device 210 is registered in the "Devices Not Subject to Alerts" field corresponding to vulnerability V2. In the example shown in Fig. 7, device information indicating the device 210 (first device) is not registered in the "Devices Not Subject to Alerts" field corresponding to vulnerability V2.
[0084] Therefore, the intrusion detection device 100 (specifically, the notification unit 130) outputs (notifies) an alert indicating that the device 210 has been attacked using the vulnerability V2 (S240).
[0085] Next, it is assumed that the device 220 is performing communication that is suspected of being an attack against vulnerability V1 (S250).
[0086] In this case, for example, it is assumed that the intrusion detection device 100 (specifically, the anomaly detection unit 120) detects that the device 220 is being attacked using vulnerability V1 (S260).
[0087] When the intrusion detection device 100 detects that the device 220 is under attack due to vulnerability V1, the intrusion detection device 100 checks the permission list (S270). Specifically, the intrusion detection device 100 determines whether device information indicating the device 220 is registered in the "Devices Not Subject to Alerts" field corresponding to vulnerability V1. In the example shown in Fig. 7, device information indicating the device 220 (second device) is registered in the "Devices Not Subject to Alerts" field corresponding to vulnerability V1.
[0088] Therefore, the intrusion detection device 100 (specifically, the notification unit 130) does not output an alert indicating that the device 220 has been attacked using vulnerability V1.
[0089] FIG. 8 is a flowchart illustrating a processing procedure of the intrusion detection device 100 according to an embodiment. Specifically, FIG. 8 illustrates a specific example of a process in which the intrusion detection device 100 updates the allow list based on asset information. In FIG. 8 , the network system 10 includes D devices (monitoring targets), and each device is identified by d. For example, in FIG. 8 , each device is designated as the "dth device." D and d are arbitrary natural numbers. Each vulnerability type is designated as vulnerability Vn. n is also a natural number. The identifiers of each device (e.g., dth device) and the identifiers indicating each vulnerability type (e.g., vulnerability Vn) may be arbitrarily determined in advance. For example, each time a device that transmits or receives communication packets monitored and analyzed by the intrusion detection device 100 is added, an identifier starting from 1 is assigned to the added device. Furthermore, for example, each time a type of vulnerability to be detected by the intrusion detection device 100 is added, an identifier starting from 1 (specifically, V1) is assigned to the added vulnerability type.
[0090] First, the intrusion detection device 100 selects a device (first device) corresponding to d=1 (S310).
[0091] Next, the intrusion detection device 100 determines whether d≦D (S320).
[0092] If the intrusion detection device 100 determines that d≦D (Yes in S320), it performs the following process in order starting from the device with d=1.
[0093] The intrusion detection device 100 acquires asset information of the d-th device (the first device in the case of the process following steps S310 and S320) (S330). For example, the intrusion detection device 100 acquires asset information by sending request information to the first device.
[0094] Next, the intrusion detection device 100 determines whether the acquired asset information includes information indicating the version of the OS (OS version information) (S340).
[0095] If the intrusion detection device 100 determines that OS version information is included (Yes in S340), it selects the vulnerability type corresponding to n=1 (that is, vulnerability V1) (S350).
[0096] Next, the intrusion detection device 100 determines whether n≦N (S360). That is, the intrusion detection device 100 determines whether the value of n obtained before the determination made in step S360 is equal to or less than N.
[0097] If the intrusion detection device 100 determines that n≦N holds (Yes in S360), it performs the following process for each type of vulnerability to be detected, starting with the vulnerability type n=1.
[0098] The intrusion detection device 100 registers device information indicating the d-th device (for example, the first device when d=1) in the "device not targeted for scanning" field corresponding to vulnerability Vn (S370).
[0099] Next, the intrusion detection device 100 determines whether the type and version of the OS used by the d-th device match the type and version of the OS corresponding to the vulnerability Vn (S380). For example, the intrusion detection device 100 determines whether the permission list and the asset information of the d-th device match. That is, the intrusion detection device 100 determines whether the d-th device, more specifically, the type and version of the OS used by the d-th device, has the vulnerability Vn.
[0100] If the intrusion detection device 100 determines that the type and version of the OS used by the d-th device do not match the type and version of the OS corresponding to vulnerability Vn (No in S380), it registers device information indicating the d-th device in the "Devices not subject to alerts" field in the permission list that corresponds to vulnerability Vn (S390). On the other hand, if the intrusion detection device 100 determines that the type and version of the OS used by the d-th device match the type and version of the OS corresponding to vulnerability Vn (Yes in S380), it does not register device information indicating the d-th device in the "Devices not subject to alerts" field in the permission list that corresponds to vulnerability Vn.
[0101] After step S390, or if step S380 returns Yes, the intrusion detection device 100 executes n++ (S400), that is, adds 1 to the value of n, and executes the processing for the next type of vulnerability, starting from step S360. For example, if the intrusion detection device 100 has executed the processing for vulnerability V1 in steps S360 to S390, then in step S400 it selects vulnerability V2 and executes the processing of step S360.
[0102] If the intrusion detection device 100 determines that n≦N is not satisfied (No in S360) after repeatedly executing steps S360 to S400, that is, if it determines that steps S370 to S400 have been executed for all vulnerabilities to be detected, it executes d++ (S410), that is, it adds 1 to the value of d, and executes the process for the next device from step S320. For example, if the intrusion detection device 100 has executed the process for the first device in the previous processes, it selects a second device in step S410 and executes the process of step S320.
[0103] If the intrusion detection device 100 determines that d is not less than D (No in S320) by repeatedly executing the processing from step S320 onwards, that is, if it determines that the processing from step S330 onwards has been executed for all devices to be monitored, it terminates the processing.
[0104] 9 and 10 are diagrams illustrating a fourth and fifth example of the permission list according to the embodiment.
[0105] 9 and 10 are diagrams illustrating a specific example of the processing performed by the intrusion detection device 100 when a new type of vulnerability Vx is added after device information has been registered in the "Devices not subject to scanning" and "Devices not subject to alerts" fields in the permission list based on, for example, asset information.
[0106] For example, the intrusion detection device 100 creates (updates) an allow list as shown in FIG. 7 by executing the process and vulnerability scan shown in FIG. 8 . Thereafter, for example, the intrusion detection device 100 obtains information indicating a new type of vulnerability, the type of OS containing the vulnerability, and the version of the OS from an external server. Specifically, the intrusion detection device 100 obtains information indicating vulnerability Vx and information indicating that the type of OS containing vulnerability Vx is "XXX" and that the version of the OS is "18.04.1LTS." In this case, the intrusion detection device 100 creates (updates) an allow list as shown in FIG. 9 .
[0107] Next, the intrusion detection device 100 determines, based on the permission list, whether device information can be registered in the "Devices Not Subject to Scanning" and "Devices Not Subject to Alerts" fields corresponding to the vulnerability Vx. Specifically, the intrusion detection device 100 determines whether device information can be registered in the "Devices Not Subject to Scanning" and "Devices Not Subject to Alerts" fields corresponding to the vulnerability Vx based on the device information already registered in the permission list, information indicating the type of vulnerability corresponding to (linked to) the device information, information indicating the type of OS corresponding to the vulnerability, and information indicating the OS version corresponding to the vulnerability. For example, the intrusion detection device 100 determines whether device information is registered in the "Devices Not Subject to Scanning" and "Devices Not Subject to Alerts" fields in association with a vulnerability type for which the same information is registered as the "Target OS" and "Target Version" fields corresponding to the vulnerability Vx (in this example, "XXX" and "18.04.1LTS"). In this example, the information registered for vulnerability V1 in the "Target OS" and "Target Version" fields is the same as that for vulnerability Vx. In this example, the first and second devices are registered as device information in the "Devices not subject to scanning" and "Devices not subject to alerts" fields corresponding to vulnerability V1. In such a case, the intrusion detection device 100 registers the first and second devices, which are the same device information as the device information corresponding to vulnerability V1, in the "Devices not subject to scanning" and "Devices not subject to alerts" fields corresponding to vulnerability Vx, as shown in FIG.
[0108] In this way, the intrusion detection device 100 may register new device information corresponding to the newly added vulnerability type based on device information already registered in the allow list.
[0109] The intrusion detection device 100 may also collectively register device information indicating multiple devices that belong to the same group, such as multiple devices that belong to the same network segment, in the allowance list.
[0110] For example, in a factory or the like, devices that perform particularly important processing may already have vulnerability countermeasures in place, such as disabling the use of vulnerable operating systems and applications, or being specially monitored daily by managers working in the factory. Even if such devices are subject to a vulnerability attack, there may be no need to issue an alert. Therefore, the intrusion detection device 100 may register device information in the allow list based on information indicating such a group (group information).
[0111] The group information may be stored in the storage unit 190, or may be acquired by the acquisition unit 110 from an external server or the like.
[0112] Fig. 11 is a diagram illustrating a sixth example of the permission list according to the embodiment. Fig. 12 is a diagram illustrating a seventh example of the permission list according to the embodiment. Specifically, Figs. 11 and 12 are diagrams illustrating a specific example of the process in which the intrusion detection device 100 registers device information in the permission list based on group information.
[0113] Assume that the intrusion detection device 100 obtains group information indicating the group to which the first and second devices belong. In this case, for example, the intrusion detection device 100 registers device information indicating the first and second devices in all of the "Devices Not Subject to Scanning" and "Devices Not Subject to Alerts" fields in the allow list. After this, for example, the intrusion detection device 100 obtains information regarding vulnerability Vy. At this time, the intrusion detection device 100 registers the information regarding vulnerability Vy in the allow list, thereby creating (updating) the allow list shown in FIG. 11 , for example, and further creates (updating) the allow list shown in FIG. 12 based on the group information.
[0114] In this way, if the intrusion detection device 100 has information, such as group information, that indicates devices for which countermeasures against vulnerabilities have already been implemented, the intrusion detection device 100 may update the permission list based on that information.
[0115] Furthermore, in the above description, the intrusion detection device 100 obtains asset information from the monitored object by sending request information to the monitored object, but the method by which the intrusion detection device 100 obtains asset information is not limited to this, and the asset information may be obtained by any method.
[0116] Fig. 13 is a sequence diagram showing a third example of processing executed in network system 10 according to the embodiment. Specifically, Fig. 13 is a sequence diagram showing a specific example of processing in which intrusion detection device 100 acquires asset information related to device 210. Note that Fig. 13 shows intrusion detection device 100, device 210, and device 220, which are components included in network system 10 shown in Fig. 1.
[0117] First, the intrusion detection device 100 executes a communication packet acquisition process (S510). In the communication packet acquisition process, the intrusion detection device 100 acquires a communication packet transmitted by the device 210. Specifically, in the communication packet acquisition process, the intrusion detection device 100 performs the following step S511.
[0118] The intrusion detection device 100 acquires communication packets from the device 210 by communicating with the device 210 using HTTP (Hyper Text Transfer Protocol) (S511).
[0119] Next, the intrusion detection device 100 identifies the type of OS used by the device 210 based on the acquired communication packet (S520). In this manner, the intrusion detection device 100 may acquire asset information that includes information indicating the type of OS used by the device 210.
[0120] Depending on the communication standard, communication packets may contain information indicating the type of OS used by the monitoring target. Therefore, for example, when communication is performed using such a communication standard, the intrusion detection device 100 acquires communication packets from the communication performed during normal operation of the monitoring target without performing communication to acquire asset information, and identifies the type of OS used by the monitoring target based on the acquired communication packets. Note that HTTP is just one example. When communication is performed using a specified communication standard such as SMB (Server Message Block), the intrusion detection device 100 may also acquire information indicating the type of OS used by the monitoring target from the communication packets. The specified communication standard is not particularly limited as long as asset information, such as information indicating the OS type, is included in the communication packets.
[0121] FIG. 14 is a diagram illustrating an eighth example of the permission list according to the embodiment.
[0122] For example, suppose that the intrusion detection device 100 identifies that the type of OS used by the device 210 is YYY10 by executing the process shown in Fig. 13. Also, suppose that the intrusion detection device 100 is unable to identify the version of the OS used by the device 210 even after executing the process shown in Fig. 13.
[0123] In such a case, for example, intrusion detection device 100 registers device information (first device) identifying device 210 in the "Devices not subject to scanning" and "Devices not subject to alerts" fields corresponding to vulnerabilities V1 and VN in the allowance list shown in Figure 14. On the other hand, for example, intrusion detection device 100 does not register device information identifying device 210 in the "Devices not subject to alerts" field corresponding to vulnerabilities V2 and V3 in the allowance list. Furthermore, in this example, because the version of the OS used by device 210 is unknown, intrusion detection device 100 does not register device information identifying device 210 in the "Devices not subject to alerts" field corresponding to vulnerabilities V2 and V3 in the allowance list.
[0124] [Representative Example] FIG. 15 is a flowchart showing an information processing method according to an embodiment.
[0125] For example, the information processing device includes a processor and a memory, and the processor uses the memory to perform the following processes: The information processing device is, for example, the intrusion detection device 100 described above.
[0126] First, the information processing device determines whether or not a predetermined device has a first vulnerability based on predetermined information (S10). The predetermined information is, for example, information including at least one of the above-mentioned asset information and the above-mentioned group information. The predetermined device is, for example, the above-mentioned monitoring target. The predetermined device is, for example, any of the above-mentioned devices 210 to 250. Furthermore, the first vulnerability is, for example, any of the above-mentioned vulnerabilities V1 to VN, vulnerability Vx, and vulnerability Vy.
[0127] Next, based on the determination result of whether the specific device has the first vulnerability, the information processing device links device information indicating the specific device with first vulnerability information indicating the first vulnerability and registers the device information in the allow list (S20). For example, if the information processing device determines that the software used by the device 210 (e.g., the OS and the version of the OS) does not have vulnerability V1, the information processing device links the device information indicating the device 210 with vulnerability V1 and registers the device information in the allow list. On the other hand, if the information processing device determines that the software used by the device 210 has vulnerability V1, the information processing device does not register the device information indicating the device 210 in the item corresponding to vulnerability V1 in the allow list.
[0128] Next, when a specific device is attacked using the first vulnerability, the information processing device determines, based on the permission list, whether to output an alert indicating that the specific device has been attacked using the first vulnerability (S30). For example, in step S20, if the device information indicating the device 210 is associated with vulnerability V1 and registered in the permission list, the information processing device determines not to output an alert when the device 210 is attacked using vulnerability V1. On the other hand, for example, in step S20, if the device information indicating the device 210 is not registered in the item corresponding to vulnerability V1 in the permission list, the information processing device determines to output an alert when the device 210 is attacked using vulnerability V1, and outputs an alert (alert information) indicating that the device 210 has been attacked using vulnerability V1 to, for example, a terminal used in an SOC.
[0129] [Effects, etc.] Hereinafter, examples of techniques that can be obtained from the disclosure of this specification will be given, and effects, etc. that can be obtained from the exemplified techniques will be described.
[0130] Technique 1 is an information processing method that determines whether a specific device has a first vulnerability based on specific information (S10), and based on the determination result of whether the specific device has the first vulnerability, links device information indicating the specific device with first vulnerability information indicating the first vulnerability and registers the linked information in an authorization list (S20), and when the specific device is attacked through an attack exploiting the first vulnerability, determines based on the authorization list whether to output an alert indicating that the specific device has been attacked through an attack exploiting the first vulnerability (S30).
[0131] According to this, whether to output an alert is determined based on the allow list. Therefore, for example, if the allow list includes device information indicating devices without vulnerabilities, no alert is output when a device indicated by device information included in the allow list is subject to a vulnerability attack. On the other hand, for example, if the allow list does not include device information indicating a device subject to a vulnerability attack, an alert is output. As a result, no alert is output even if a device that is not considered to be affected by a vulnerability attack is subject to the vulnerability attack. Therefore, according to the present disclosure, the number of times alerts are output in response to vulnerability attacks can be effectively reduced.
[0132] The allow list may be a list of vulnerable devices. In this case, for example, if a device indicated by device information included in the allow list is subject to a vulnerability attack, an alert is output. On the other hand, if device information indicating a device subject to a vulnerability attack is not included in the allow list, no alert is output.
[0133] Technique 2 is the information processing method according to Technique 1, in which the predetermined information includes asset information indicating the type of software used by the predetermined device.
[0134] The software is, for example, an OS. The asset information includes, for example, information indicating the type of OS and the version of the OS. Depending on the type of software, the presence or absence of vulnerabilities may be known in advance. Therefore, the presence or absence of vulnerabilities in a device can be accurately determined based on the type of software used by the device.
[0135] Technique 3 is an information processing method according to Technique 2, which transmits a request signal requesting asset information to a specified device, and if the asset information can be acquired from the specified device, determines whether or not the specified device has a first vulnerability based on the asset information, and if the asset information cannot be acquired from the specified device, determines whether or not the specified device has a first vulnerability by executing a vulnerability scan on the specified device.
[0136] It is anticipated that vulnerability scans may cause devices to stop operating in some cases. This reduces the number of devices on which vulnerability scans are performed, thereby reducing the occurrence of malfunctions that cause devices to stop operating. Furthermore, although vulnerability scans can detect device vulnerabilities, they require more processing power than determining whether a device is vulnerable based on asset information. Therefore, if asset information can be acquired from a device, the asset information is used to determine whether the device is vulnerable, and if asset information cannot be acquired from the device, a vulnerability scan is performed to determine whether the device is vulnerable. This reduces the likelihood of having to perform vulnerability scans on all devices when determining whether multiple devices are vulnerable, thereby increasing the possibility of shortening the total time required for the determination.
[0137] Technique 4 is an information processing method described in Technique 2, in which a communication packet transmitted from a specified device is acquired, and asset information is acquired by identifying the type of software used by the specified device based on the acquired communication packet.
[0138] This makes it possible to determine whether a device has vulnerabilities based on communication packets that the device normally carries out.
[0139] Technique 5 is an information processing method according to any one of techniques 1 to 4, wherein in registering device information (S20), if it is determined that a specific device does not have a first vulnerability, the device information is linked to the first vulnerability information and registered in an allow list; and in determining whether to output an alert (S30), if the specific device has been attacked exploiting the first vulnerability, it is determined whether the device information linked to the first vulnerability information is registered in the allow list; if it is determined that the device information linked to the first vulnerability information is registered in the allow list, it is determined not to output an alert; and if it is determined that the device information linked to the first vulnerability information is not registered in the allow list, it is determined to output an alert.
[0140] This allows the use of an authorization list to appropriately output an alert when a device has a vulnerability and is subjected to a vulnerability attack that exploits that vulnerability, that is, when an alert needs to be output.
[0141] Technique 6 is an information processing method according to any one of techniques 1 to 5, wherein the permission list includes first vulnerability information, first software information indicating a type of software that is the target of an attack exploiting the first vulnerability, second vulnerability information indicating a second vulnerability, and OS software information indicating a type of software that is the target of an attack exploiting the second vulnerability; after linking device information to the first vulnerability information and registering it in the permission list, it is determined whether a specific device has the second vulnerability based on the permission list, and based on the determination result of whether the specific device has the second vulnerability, it is registered in the permission list linked to the device information with the second vulnerability information.
[0142] Depending on the type of vulnerability, attacks exploiting the vulnerability may target the same type of software. Therefore, for example, if the allow list already includes device information linked to the first vulnerability information and the first vulnerability and the second vulnerability are targeted at the same type of software, it is possible to determine whether the device indicated by the device information has the second vulnerability based on the first vulnerability information and device information included in the allow list. This makes it easy to determine the vulnerability of the device.
[0143] Technique 7 is an information processing method according to any one of techniques 1 to 6, wherein the predetermined information includes information indicating whether a predetermined group to which a predetermined device belongs is a group to which devices that have been implemented with measures against vulnerabilities belong.
[0144] The predetermined group is, for example, a group classified based on a network segment. For example, devices belonging to the same network segment are classified into the same group, and devices belonging to different network segments are classified into different groups. In other words, multiple devices belonging to a predetermined group are, for example, devices belonging to the same network segment. For example, devices performing particularly important processing in a factory, unlike other devices, may already have countermeasures in place against vulnerabilities, such as making vulnerable operating systems and applications unavailable or being specially monitored daily by managers working in the factory. Even if such devices are subject to a vulnerability attack, there may be no need to output an alert. Therefore, by determining whether to output an alert based on information indicating such a group, unnecessary output of alerts can be prevented.
[0145] Technology 8 is an information processing method according to Technology 7, in which determining whether a predetermined device has a first vulnerability includes determining whether a plurality of devices belonging to a predetermined group have the first vulnerability based on predetermined information, and registering the device information by linking a plurality of pieces of device information indicating each of the plurality of devices with the first vulnerability information in an allow list based on a result of determining whether the plurality of devices have the first vulnerability, and determining whether to output an alert by determining whether or not an alert is to be output based on the allow list when one of the plurality of devices has been attacked that exploits the first vulnerability. For example, when a second device of the plurality of devices has been attacked that exploits the first vulnerability, determining whether or not to output an alert by determining whether or not the second device has been attacked that exploits the first vulnerability.
[0146] This can prevent unnecessary alerts from being output.
[0147] Technique 9 is an information processing device that includes a processor and a memory, and the processor uses the memory to determine whether a specific device has a first vulnerability based on specific information, and based on the determination result of whether the specific device has the first vulnerability, links device information indicating the specific device with first vulnerability information indicating the first vulnerability and registers the linked information in an allow list, and when the specific device is attacked that exploits the first vulnerability, determines based on the allow list whether to output an alert indicating that the specific device has been attacked that exploits the first vulnerability.
[0148] For example, the vulnerability detection execution unit 140 determines whether a specific device has a first vulnerability, the permission list management unit 170 links the device information to the first vulnerability information and registers it in the permission list, and the notification unit 130 determines whether to output an alert.
[0149] This provides the same effect as the information processing method described in Technology 1.
[0150] Technique 10 is a program for causing a computer to execute the information processing method according to any one of techniques 1 to 8.
[0151] This provides the same effect as the information processing method described in any one of Techniques 1 to 8.
[0152] (Other Embodiments) Although the embodiments have been described above, the present disclosure is not limited to the above-described embodiments.
[0153] For example, the intrusion detection device 100 detects vulnerability attacks, but may also detect any attacks such as malware, DoS attacks, and brute force attacks.
[0154] Furthermore, for example, the number of devices included in the network system 10 may be any number, and may be one, or two or more.
[0155] Furthermore, for example, the information processing device described in the above embodiments may be realized as a single device that has all of the components, or may be realized by allocating each function to multiple devices and having these multiple devices work together.
[0156] In the above-described embodiment, the processing performed by a specific processing unit may be performed by another processing unit. The order of multiple processing operations may be changed, or multiple processing operations may be performed in parallel.
[0157] In the above-described embodiments, each component may be realized by executing a software program suitable for that component, or by a program execution unit such as a CPU or processor reading and executing a software program recorded on a recording medium such as a hard disk or semiconductor memory.
[0158] Furthermore, each component may be realized by hardware. For example, each component may be a circuit (or integrated circuit). These circuits may form a single circuit as a whole, or each may be a separate circuit. Furthermore, each of these circuits may be a general-purpose circuit or a dedicated circuit.
[0159] Furthermore, the general or specific aspects of the present disclosure may be realized as an apparatus, a system, a method, an integrated circuit, a computer program, or a non-transitory recording medium such as a computer-readable CD-ROM, etc. Furthermore, the general or specific aspects of the present disclosure may be realized as any combination of an apparatus, a system, a method, an integrated circuit, a computer program, and a recording medium.
[0160] In addition, this disclosure also includes forms obtained by applying various modifications to each embodiment that a person skilled in the art would think of, or forms realized by arbitrarily combining the components and functions of each embodiment within the scope of this disclosure.
[0161] The present disclosure is useful for a computer that detects packet anomalies.
[0162] REFERENCE SIGNS LIST 10 Network system 100 Intrusion detection device 110 Acquisition unit 120 Abnormality detection unit 130 Notification unit 140 Vulnerability detection execution unit 150 Vulnerability information update unit 160 Vulnerability detection management unit 170 Permission list management unit 180 Asset information management unit 190 Storage unit 210, 220, 230, 240, 250 Device 300 Switch device 400 Network
Claims
1. An information processing method comprising: determining whether a specified device has a first vulnerability based on specified information; linking device information indicating the specified device with first vulnerability information indicating the first vulnerability and registering the linked information in an authorization list based on the determination result of whether the specified device has the first vulnerability; and, when the specified device is attacked through the first vulnerability, determining, based on the authorization list, whether to output an alert indicating that the specified device has been attacked through the first vulnerability.
2. The information processing method according to claim 1, wherein the predetermined information includes asset information indicating the type of software used by the predetermined device.
3. The information processing method of claim 2, further comprising: transmitting a request signal to the specified device requesting the asset information; if the asset information can be acquired from the specified device, determining whether or not the specified device has the first vulnerability based on the asset information; and if the asset information cannot be acquired from the specified device, determining whether or not the specified device has the first vulnerability by performing a vulnerability scan on the specified device.
4. The information processing method according to claim 2, further comprising: acquiring a communication packet transmitted from the specified device; and identifying the type of software used by the specified device based on the acquired communication packet, thereby acquiring the asset information.
5. The information processing method of claim 1, wherein, in registering the device information, if it is determined that the specified device does not have the first vulnerability, the device information is linked to the first vulnerability information and registered in the permission list; and, in determining whether to output the alert, if the specified device has been attacked exploiting the first vulnerability, it is determined whether the device information linked to the first vulnerability information is registered in the permission list; if it is determined that the device information linked to the first vulnerability information is registered in the permission list, it is determined not to output the alert; and if it is determined that the device information linked to the first vulnerability information is not registered in the permission list, it is determined to output the alert.
6. The information processing method of claim 1, wherein the permission list includes the first vulnerability information, first software information indicating a type of software that is the target of an attack exploiting the first vulnerability, second vulnerability information indicating a second vulnerability, and second software information indicating a type of software that is the target of an attack exploiting the second vulnerability; after linking the device information to the first vulnerability information and registering it in the permission list, determining whether or not the specified device has the second vulnerability based on the permission list; and based on the determination result of whether or not the specified device has the second vulnerability, linking the device information to the second vulnerability information and registering it in the permission list.
7. The information processing method according to claim 1, wherein the predetermined information includes information indicating whether the predetermined group to which the predetermined device belongs is a group to which devices that have been implemented with measures against vulnerabilities belong.
8. The information processing method according to claim 7, wherein, in determining whether the specified device has the first vulnerability, it is determined whether multiple devices belonging to the specified group have the first vulnerability based on the specified information; in registering the device information, based on the determination results of whether the multiple devices have the first vulnerability, multiple pieces of device information indicating the multiple devices are linked together with the first vulnerability information and registered in the permission list; and in determining whether to output an alert, if any of the multiple devices has been attacked that exploits the first vulnerability, it is determined based on the permission list whether to output an alert indicating that any of the multiple devices has been attacked that exploits the first vulnerability.
9. An information processing device comprising: a processor; and a memory, wherein the processor uses the memory to determine whether a specified device has a first vulnerability based on specified information; based on the determination result of whether the specified device has the first vulnerability, link device information indicating the specified device with first vulnerability information indicating the first vulnerability and register it in an authorization list; and when the specified device is attacked that exploits the first vulnerability, determine based on the authorization list whether to output an alert indicating that the specified device has been attacked that exploits the first vulnerability.
10. A program for causing a computer to execute the information processing method according to any one of claims 1 to 8.
Citation Information
Patent Citations
Intrusion detection / prevention system, client computer, intrusion detection / prevention apparatus and method, and program
JP2011188071A
Systems and methods for automated intrusion detection
JP2020201940A