Risk information output device, risk information output method, and recording medium
The risk information output device simplifies complex LLM answers by integrating UI processing and visualization to enhance user understanding of security risk diagnoses in information processing systems.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-09-17
- Publication Date
- 2026-03-26
AI Technical Summary
Existing systems using large language models (LLM) to diagnose security risks in information processing systems provide answers that are not easily understandable by ordinary users.
A risk information output device that includes UI processing, parameter acquisition, information collection, attack route calculation, topology display, and LLM explanation units to generate chat and topology display information, making complex LLM answers more understandable through user interface enhancements and visualizations.
Facilitates easier comprehension of security risk diagnoses by providing clear explanations and visual representations of system vulnerabilities and attack routes, enhancing user understanding of security risks.
Smart Images

Figure JP2024033022_26032026_PF_FP_ABST
Abstract
Description
Risk Information Output Device, Risk Information Output Method, and Recording Medium
[0001] The present disclosure relates to a risk information output device, a risk information output method, and a recording medium.
[0002] Patent Document 1 discloses a system that obtains and presents information about vulnerabilities in Web applications on the World Wide Web (WWW) from a large language model (LLM: Large Language Models).
[0003] Japanese Patent No. 7488976
[0004] However, the answers obtained from the LLM are not necessarily easy for ordinary users to understand.
[0005] An object of the present disclosure is to provide a risk information output device or the like that outputs information for more easily understanding an answer obtained from an LLM in the diagnosis of security risks of an information processing system using the LLM.
[0006] A risk information output device in one form of this disclosure includes: UI processing means that acquires user input about an element to be diagnosed for security risk in an information processing system and outputs chat display information and topology display information generated based on the answer obtained from LLM; parameter acquisition means that uses the user input to acquire parameters of the element to be diagnosed from LLM; information acquisition means that uses the parameters of the element to be diagnosed to collect system information of the element to be diagnosed; attack route calculation means that uses the system information of the element to be diagnosed to calculate an attack route for a threat that brings security risk to one or more elements in the information system by utilizing the vulnerability of the element to be diagnosed; topology display means that generates topology display information which is information for displaying the topology of the system related to the security risk including the attack route; and LLM explanation means that uses the user input and the system information of the element to be diagnosed to acquire the answer regarding security risk about the element to be diagnosed and an explanation of the answer from LLM, and generates chat display information which is information for displaying the acquired answer and the explanation of the answer.
[0007] A risk information output method in one form of this disclosure involves obtaining user input about an element to be diagnosed for security risk in an information processing system; using the user input, obtaining parameters of the element to be diagnosed from the LLM; using the parameters of the element to be diagnosed, collecting system information of the element to be diagnosed; using the system information of the element to be diagnosed, calculating an attack route for a threat that would cause a security risk to one or more elements in the information system by exploiting the vulnerability of the element to be diagnosed; generating topology display information, which is information for displaying the system topology related to the security risk including the attack route; using the user input and the system information of the element to be diagnosed, obtaining a security risk answer and an explanation of the answer from the LLM; generating chat display information, which is information for displaying the obtained answer and the explanation of the answer; and outputting the chat display information and topology display information generated based on the answer obtained from the LLM.
[0008] A recording medium in one form of this disclosure records a program to be executed by a computer, which includes: a process for acquiring user input about an element to be diagnosed for security risks in an information processing system, and outputting chat display information and topology display information generated based on the answer obtained from the LLM; a process for acquiring parameters of the element to be diagnosed from the LLM using the user input; a process for collecting system information of the element to be diagnosed using the parameters of the element to be diagnosed; a process for calculating an attack route for a threat that brings security risks to any one or more elements in the information system by utilizing the vulnerability of the element to be diagnosed using the system information of the element to be diagnosed; a process for generating topology display information which is information for displaying the topology of the system related to the security risk including the attack route; a process for acquiring answers about security risks regarding the element to be diagnosed and explanations about those answers from the LLM using the user input and the system information of the element to be diagnosed, and generating chat display information which is information for displaying the acquired answers and explanations about those answers.
[0009] According to this disclosure, in diagnosing the security risks of an information processing system using LLM, the system outputs information that makes it easier to understand the responses obtained from LLM.
[0010] This is a block diagram showing an example of the configuration of a risk information output device. This is a block diagram showing an example of the configuration of a system equipped with a configuration for storing information used by the risk information output device. This is a block diagram showing an example of the configuration of the LLM explanation section. This is a flowchart showing an example of the operation of the risk information output device. This is a diagram showing an example of a chat screen that displays chat display information output by the risk information output device and a topology screen that displays topology display information. This is an example of the first display screen. This is an example of a display screen that displays suggestions in response to user input. This is an example of the second display screen. This is an example of the third display screen. This is an example of the fourth display screen. This is an example of the fifth display screen. This is an example of the sixth display screen. This is an example of the seventh display screen. This is an example of the eighth display screen. This is a diagram showing an example of vulnerability information. This is a diagram showing an example of system information. This is a diagram showing an example of an attack route. This is a diagram showing an example of a countermeasure. This is information showing an example of a countermeasure including a score. This is a block diagram showing an example of hardware configuration.
[0011] Embodiments in this disclosure will be described with reference to the drawings. However, embodiments are not limited to those shown in the drawings. For example, lines connecting components in the drawings are included to facilitate understanding of the description. Therefore, connections between components are not limited to the connecting lines shown in the drawings. Similar components in multiple drawings may be denoted by the same reference numerals, and repeated descriptions may be omitted.
[0012] • Overview: As a method for diagnosing security risks in information systems, diagnostics are often performed using topology diagrams related to security risks, such as the elements included in the system and the routes connecting them. However, for the average system user, diagnosing the security risks of an information system from topology diagrams is often difficult.
[0013] It is assumed that LLM will be used as a reference for diagnosis. However, the answers obtained from LLM may not necessarily be appropriate for the user.
[0014] Therefore, in each embodiment, the risk information output device 10 outputs information that makes it easier to understand the answers obtained from the LLM20 when diagnosing the security risks of an information processing system using the LLM20.
[0015] ・Premise for the description of the embodiment In the following description, for the sake of convenience, the screen on which the user of the risk information output device 10 communicates with the LLM 20 in real time by exchanging text messages, etc., will be referred to as the "chat screen". The information used to display chats, etc., on the chat screen will be referred to as "chat display information". Furthermore, the screen on which diagrams and charts such as topology related to security risks are displayed will be referred to as the "topology screen". The information used to display diagrams and charts, etc., on the topology screen will be referred to as "topology display information".
[0016] As described below, the risk information output device 10 outputs chat display information and topology display information as processing related to the user interface (UI) in the use of LLM 20. However, this does not mean that the information output by the risk information output device 10 is limited to the information displayed on the chat screen and topology screen.
[0017] Furthermore, in the following explanation, the information used by the risk information output device 10 is assumed to be pre-stored. This information will be explained in detail later, but an overview is provided below.
[0018] Figure 2 is a block diagram showing an example of a system configuration that includes a setting for storing information used by the risk information output device 10. In Figure 2, the risk information output device 10 is connected to the LLM 20 and the user-operated terminal device 30. Furthermore, the risk information output device 10 is connected to a vulnerability information storage unit 210, a system information storage unit 220, an attack route storage unit 230, a proposed countermeasure storage unit 240, and a template prompt storage unit 250. However, the configuration in Figure 2 is just one example of a configuration for using the risk information output device 10. The configuration for using the risk information output device 10 is not limited to the configuration in Figure 2. For example, the risk information output device 10 may have some or all of the above-mentioned storage units as internal components.
[0019] The vulnerability information storage unit 210 stores information on vulnerabilities related to the security risks of the information processing system to be diagnosed. The system information storage unit 220 stores system information of the devices and other elements that constitute the information system and the network. The countermeasure proposal storage unit 240 stores at least one of the countermeasure proposals and mitigation measures for vulnerabilities of elements in the information system. The template prompt storage unit 250 stores template prompts used in queries to the LLM 20. The attack route storage unit 230 stores attack routes calculated by the attack route calculation unit 120.
[0020] LLM20 is an LLM used by users to diagnose the security risks of information systems. As will be explained in detail later, the risk information output device 10 outputs information to make it easier to understand the answers obtained from LLM20. In Figure 2, one LLM20 is shown. However, LLM20 is not limited to one LLM, but may consist of multiple LLMs. In other words, the risk information output device 10 may use one LLM as LLM20, or it may use multiple LLMs. The risk information output device 10 may have LLM20 as an internal component, or it may use an external LLM20.
[0021] The LLM used as LLM20 is not particularly limited. For example, the following may be used as LLM20: GPT-3 (Generative Pre-trained Transformer-3), GPT-3.5, GPT-4, or GPT-4.5, T5 (Text-to-Text Transfer Transformer), BERT (Bidirectional Encoder Representations from Transformers), or RoBERTa (Robustly optimized BERT approach), ELECTRA (Efficiently Learning an Encoder that Classifies Token Replacements Accurately), BLOOM (BigScience Large Open-science Open-access Multilingual Language Model), and LLaMA (Large Language Model Meta AI).
[0022] Terminal device 30 is an example of a device operated by a user. Terminal device 30 receives user input information used for diagnosing the security risks of the information system and outputs it to the risk information output device 10. Hereinafter, the information entered by the user will also be referred to as "user input". Furthermore, terminal device 30 receives and displays chat display information and topology display information generated based on the responses obtained from LLM 20 from the risk information output device 10. Chat display information and topology display information will be explained in detail later. The risk information output device 10 may have terminal device 30 built into it. Alternatively, the risk information output device 10 may have terminal device 30 built into it.
[0023] The configuration of the risk information output device 10 of the first embodiment will be described. Figure 1 is a block diagram showing an example of the configuration of the risk information output device 10. The risk information output device 10 comprises an information collection unit 110, an attack route calculation unit 120, a topology display unit 130, a parameter acquisition unit 140, an LLM explanation unit 150, and a UI processing unit 160.
[0024] The UI processing unit 160 acquires user input regarding the elements to be diagnosed as security risks in the information processing system. The UI processing unit 160 then outputs chat display information and topology display information generated based on the answers obtained from the LLM 20.
[0025] "User input" refers to information such as messages that a user enters into a terminal device 30 to inquire about security risks, etc., to the LLM20. Chat display information and topology display information will be explained in detail later.
[0026] As an example of user input, let's describe the case where the UI processing unit 160 is connected to a terminal device 30 operated by the user in a communicative manner. In this case, the UI processing unit 160 obtains user input from the terminal device 30. For example, the UI processing unit 160 obtains input information such as prompts related to security risk diagnosis entered by the user on the chat screen displayed on the terminal device 30 as user input.
[0027] Security risk refers to the possibility that a potential threat to an information system may materialize and cause damage or loss. For example, security risk includes the possibility and impact of data breaches, system failures, and unauthorized access due to potential threats or vulnerabilities that compromise the confidentiality, integrity, or availability of a system. Vulnerabilities, on the other hand, are weaknesses or flaws that could potentially compromise the security of an information system.
[0028] However, the risks of the information system in each embodiment are not limited to security risks, but may include other risks. For example, the risks of the information system to be diagnosed may include operational risks, technical risks, strategic risks, compliance risks, or disaster risks. However, in the following explanation, security risks will be used as an example of information system risks.
[0029] Furthermore, the UI processing unit 160 outputs topology display information for displaying diagrams of elements to be diagnosed on the topology screen, and chat display information for displaying the answers and explanations obtained from the LLM 20 on the chat screen. The explanations will be explained in detail later.
[0030] For example, the UI processing unit 160 displays a WWW page or the like on a user-operated device such as a terminal device 30, thereby realizing the functions of a user interface as described above. However, the user interface realized by the UI processing unit 160 is not limited to the above, as long as it can realize the functions described in this explanation.
[0031] The parameter acquisition unit 140 uses user input to acquire parameters of the elements to be diagnosed in the user input from the LLM 20. For example, the parameter acquisition unit 140 uses user input and a template prompt to generate a first prompt to query the LLM 20 for parameters in the user input. The parameter acquisition unit 140 then inputs the generated first prompt to the LLM 20 and acquires parameters of the elements to be diagnosed in the user input from the LLM 20. The parameter acquisition unit 140 may use the LLM that is the target of the user input as the LLM 20 from which to acquire parameters, or it may use a different LLM.
[0032] Parameters are pieces of information used in user input to obtain system information for elements that are the subject of security risk assessment in an information processing system. For example, if the user input is "Please collect information on asset 10.0.0.1," the parameters would be information indicating "asset 10.0.0.1," which is the element to be assessed, such as the identifier for "asset 10.0.0.1."
[0033] A template prompt is a standardized phrase that is entered in the same format when entering a query into LLM20. When using a template prompt, LLM20 often provides more accurate answers compared to asking a different question each time.
[0034] Therefore, the parameter acquisition unit 140 obtains, for example, a template prompt from the template prompt storage unit 250 for querying the LLM 20 for the parameters of an element. The parameter acquisition unit 140 then combines the user input and the acquired template prompt to generate a first prompt for querying the LLM 20 for the parameters, and inputs the generated first prompt to the LLM 20. The parameter acquisition unit 140 then obtains the parameters of the element to be diagnosed from the LLM 20 based on the user input.
[0035] The information collection unit 110 uses the acquired parameters to collect system information of the element to be diagnosed. For example, the information collection unit 110 uses the parameters to collect system information of the element to be diagnosed for security risk from the system information storage unit 220. For example, if the parameter of the element to be diagnosed is an identifier, the information collection unit 110 uses that identifier as a parameter to collect system information of the element. The information collection unit 110 may also collect information to be included in the system information from other devices connected via a network (not shown), such as the Internet.
[0036] The attack route calculation unit 120 uses the system information of the element to be diagnosed to calculate attack routes for threats that pose a security risk to one or more elements of the information system by utilizing the vulnerabilities of the element to be diagnosed.
[0037] An attack route describes how a malicious actor exploits vulnerabilities in an information system to reach a target element by traversing elements within that system. For example, an attacker might access their final target by following a multi-step process and exploiting multiple vulnerabilities in a chain reaction. Therefore, attack routes include routes corresponding to various attack methods, such as network intrusion, malware infection, and social engineering. However, attack routes are not limited to those listed above and may be defined according to the security risk being assessed.
[0038] For example, the attack route calculation unit 120 uses the system information of the element to be diagnosed to determine the security risk vulnerability in the element to be diagnosed. Then, using the determined vulnerability of the element, the attack route calculation unit 120 calculates an attack route for a threat that will cause a security risk to one or more elements in the information system.
[0039] The attack route calculation unit 120 may perform, for example, the following actions, although this is not limited to the following.
[0040] First example of operation: The attack route calculation unit 120 generates a graph representing the relationships between elements. Then, the attack route calculation unit 120 uses graph theory algorithms such as the shortest path problem and element vulnerabilities to calculate the most likely or most efficient attack route from the elements to be diagnosed.
[0041] Second example of operation: The attack route calculation unit 120 calculates an attack route using a trained model that was trained using supervised machine learning, which uses known vulnerability information, past attack routes, and system information as training datasets.
[0042] Third example of operation: The attack route calculation unit 120 may use CVSS (Common Vulnerability Scoring System), a framework for quantifying vulnerability characteristics and evaluating them using a common scale. CVSS is an industry-standard method for evaluating the severity of vulnerabilities in information systems, and is a framework for quantifying vulnerability characteristics and evaluating them using a common scale. For example, the attack route calculation unit 120 calculates the probability of an attack success based on the CVSS score of the element's vulnerability. Then, the attack route calculation unit 120 constructs a probabilistic model such as a Bayesian network or Markov chain that uses conditional probabilities based on the dependencies between elements. Then, the attack route calculation unit 120 uses the constructed probabilistic model to calculate the attack route with the highest probability of success.
[0043] The topology display unit 130 generates topology display information, which is information for displaying the topology of a system related to security risks including attack routes. The topology display unit 130 is not limited to all ranges of the attack route, and may generate topology display information including a partial range of the attack route or one element included in the attack route. The topology display unit 130 may generate topology display information including elements related to the attack route. For example, the topology display unit 130 generates topology display information for displaying at least one of the topology related to the attack route in the information system, an element having a vulnerability that becomes a security risk, and an element constituting the attack route.
[0044] The topology display information is information for displaying charts such as topology on a topology screen. The data format of the topology display information is not limited as long as charts or the like can be displayed on the topology screen. For example, the topology display information may be image information to be displayed on the screen. Alternatively, the topology display information may be a set of information indicating elements constituting the topology and information indicating connections between the elements. Furthermore, the topology display information may include information indicating the positional relationship and distance between elements constituting the topology. Furthermore, the topology display information may include information regarding a display method for at least some of the elements included in the topology, such as highlighting.
[0045] The topology indicates the physical or logical arrangement and connection method of a network composed of physical or logical devices (for example, nodes or devices) included in a system and links connecting them. That is, the elements constituting the topology are assumed to be nodes and links, etc., but are not limited thereto. In the following description, a topology particularly related to security risks is used. However, the topology in each embodiment is not limited to the topology related to security risks.
[0046] For example, the topology display unit 130 may generate topology display information for displaying a topology including the following elements on a topology screen.
[0047] (1) System topology diagram: A representation showing the elements of a system such as network devices, servers, endpoints, etc., and the connections between the elements.
[0048] (2) Visualization of attack routes: A display showing potential attack routes with arrows and colored lines, and a display showing the direction of the attack.
[0049] (3) Highlighting of vulnerabilities: Highlighting of components with vulnerabilities that an attacker may exploit, and display of the type or importance of the vulnerabilities.
[0050] (4) Display of attack steps: Displaying each stage of an attack (initial intrusion, privilege escalation, lateral movement, etc.) with numbers, and display of links to detailed information for each step.
[0051] (5) Risk assessment indicators: Representation of the risk levels of each element and attack step, and display of the overall risk score of the information system.
[0052] (6) Display of defense mechanisms: Display of security countermeasure elements (such as firewalls), and display of the parts where the countermeasures are effective.
[0053] (7) Timeline display: A display showing the time progression of an attack, and display of the estimated time taken for each step and the time until detection.
[0054] (8) Recommended countermeasures: Display of recommended countermeasures to block attack routes, and display of high-priority countermeasures.
[0055] The topology display unit 130 may generate topology display information including other information. For example, the topology display unit 130 may generate topology display information including at least one of user input, system information, the answer obtained from the LLM 20, and the explanation of the answer.
[0056] The LLM explanation unit 150 uses user input and system information of the element to be diagnosed to obtain the answer regarding the security risk of the element to be diagnosed and an explanation of that answer from the LLM 20. The LLM explanation unit 150 then generates chat display information, which is information for displaying the obtained answer and the explanation of the answer. The LLM explanation unit 150 may use the same LLM as the parameter acquisition unit 140 as the LLM 20, or it may use a different LLM. Furthermore, the LLM explanation unit 150 may use the same LLM or a different LLM when acquiring the answer and explanation.
[0057] Explanations are information designed to make the answers obtained from LLM20 easier to understand. For example, explanations include, but are not limited to, information that helps users deepen their understanding of security risks, and information that helps users consider countermeasures for security risks. For example, explanations provide clear explanations of the content, importance, impact, and proposed countermeasures of the security risks included in the answers obtained from LLM20, supporting users in making decisions regarding security risks. For example, explanations may also be detailed explanations of at least some of the terms or devices included in the answers obtained from LLM20. Alternatively, explanations may include, for example, at least one of the following pieces of information:
[0058] (1) Risk Overview: A brief description of the detected risk, an assessment of the risk's importance and priority, etc.
[0059] (2) Technical details: specific technical issues related to the risk, potentially affected system components or functions and their scope, etc.
[0060] (3) Contextual information: the relationship between the risk and industry standards or regulatory requirements, examples of problems caused by similar risks in the past,
[0061] (4) Proposal of countermeasures: Proposed measures or mitigation measures to reduce risks, recommended actions in those measures, etc.
[0062] (5) Information on implementation: Estimates of the resources and time required to implement the proposed countermeasures and mitigation measures, potential challenges and considerations associated with implementation, etc.
[0063] (6) Trend analysis: Trends in the frequency and severity of similar risks, external risk trends, etc.
[0064] (7) Monitoring: Indicators and methods for tracking the progression of risks, recommended frequency of continuous evaluation and reporting, etc.
[0065] Chat display information is information used to display chats and other content on the chat screen. The data format of chat display information is not limited as long as it can display chats on the chat screen. For example, chat display information can be text information. Alternatively, chat display information can be information that includes formatting related to the display. For example, chat display information can be information using a markup language that describes the logical structure and formatting information of the text together with the text in a text file.
[0066] The LLM explanation unit 150 will be further described with reference to the drawings. Figure 3 is a block diagram showing an example of the configuration of the LLM explanation unit 150. The LLM explanation unit 150 comprises an answer acquisition unit 151, an explanation acquisition unit 152, and a chat display information generation unit 153. However, the configuration of the LLM explanation unit 150 is not limited to Figure 3. For example, one configuration may realize the functions of multiple configurations, such as the answer acquisition unit 151 and the explanation acquisition unit 152.
[0067] The response acquisition unit 151 uses user input and system information of the element to be diagnosed to obtain a response regarding the security risk of the element to be diagnosed from the LLM 20. For example, the response acquisition unit 151 uses the parameters in the user input and the system information of the element to be diagnosed to obtain a template prompt for querying the security risk from the template prompt storage unit 250. Then, the response acquisition unit 151 combines the user input parameters and the system information of the element to be diagnosed with the template prompt to generate a second prompt for querying the LLM 20 regarding the security risk.
[0068] The response acquisition unit 151 may acquire a template prompt using the non-parameter portion of the user input in addition to the parameters. Alternatively, the response acquisition unit 151 may use the non-parameter portion of the user input to generate the second prompt. The response acquisition unit 151 then inputs the generated second prompt to the LLM 20 and obtains the security risk response from the LLM 20.
[0069] The explanation acquisition unit 152 uses the answer to obtain an explanation about the answer from the LLM 20. For example, when the answer acquisition unit 151 obtains an answer from the LLM 20, the explanation acquisition unit 152 uses the answer obtained from the LLM 20 to obtain a template prompt from the template prompt storage unit 250 for querying the LLM 20 for an explanation about the answer. The explanation acquisition unit 152 may use at least one of user input and system information of the element to be diagnosed to obtain the template prompt. Then, the explanation acquisition unit 152 uses the answer obtained from the LLM 20 and the template prompt to generate a third prompt for querying the LLM 20 for an explanation about the answer.
[0070] The explanation acquisition unit 152 may generate a third prompt to query for an explanation of information related to the answer obtained from the LLM 20. For example, the explanation acquisition unit 152 may generate a third prompt to query for an explanation related to at least one of the vulnerability information, system information, attack routes, countermeasures, and mitigation measures of other elements related to the element being diagnosed.
[0071] Then, the explanation acquisition unit 152 inputs the generated third prompt to the LLM 20 and acquires an explanation of the answer from the LLM 20.
[0072] Alternatively, the explanation acquisition unit 152 may use the LLM 20 to acquire information about a source that stores information that serves as an explanation for the answer, and acquire the explanation from that source. In this case as well, the explanation acquisition unit 152 may use the answer and the template prompt to generate a third prompt for querying the source of the explanation, input the generated third prompt to the LLM 20, and acquire the source of the explanation.
[0073] The chat display information generation unit 153 generates chat display information, which is information for displaying the answers and explanations about the answers obtained from the LLM 20. For example, when the explanation acquisition unit 152 acquires an explanation about an answer from the LLM 20, the chat display information generation unit 153 generates chat display information that displays the answers and explanations about the answers obtained from the LLM 20 in a way that makes them distinguishable on the chat screen.
[0074] Alternatively, the chat display information generation unit 153 may generate chat display information on the chat screen that shows the relationship between the answer and the explanation obtained from the LLM 20. For example, the LLM explanation unit 150 may generate chat display information that includes the answer and explanation, as well as an explanation indicating that the content of the explanation is reference information for the answer. In this way, the chat display information generation unit 153 generates chat display information that adds an explanation about the answer to the answer obtained from the LLM 20.
[0075] The UI processing unit 160 then outputs the generated chat display information. As a result, the user can use the outputted chat display information to refer to the explanation, which is information that makes it easier to understand the answer obtained from the LLM 20.
[0076] The LLM explanation unit 150 may acquire information about the user, such as the user's skill level or area of expertise, input this information into the LLM 20, and generate chat display information from the LLM 20 that includes answers and explanations tailored to the user. For example, if the user is an expert, the LLM explanation unit 150 may generate chat display information that includes a concise explanation or an advanced explanation. On the other hand, if the user is a beginner, the LLM explanation unit 150 may generate chat display information that includes a detailed explanation or a simple explanation.
[0077] The parameter acquisition unit 140 and the LLM explanation unit 150 perform similar operations in that they utilize the LLM 20. Therefore, a single configuration may implement the functions of both the parameter acquisition unit 140 and the LLM explanation unit 150. For example, if the parameter acquisition unit 140 and the LLM explanation unit 150 utilize the same LLM 20, the risk information output device 10 may have a configuration that implements the functions of both the parameter acquisition unit 140 and the LLM explanation unit 150. In this case, the configuration allows for the commonization of functions that operate similarly in the parameter acquisition unit 140 and the LLM explanation unit 150. Therefore, by adopting such a configuration, the developers of the risk information output device 10 can reduce development man-hours.
[0078] Thus, the risk information output device 10 includes an information collection unit 110, an attack route calculation unit 120, a topology display unit 130, a parameter acquisition unit 140, an LLM explanation unit 150, and a UI processing unit 160. The UI processing unit 160 acquires user input about the elements to be diagnosed for security risks in the information processing system. The UI processing unit 160 then outputs chat display information and topology display information generated based on the answers acquired from the LLM 20. The parameter acquisition unit 140 uses the user input to acquire the parameters of the elements to be diagnosed from the LLM 20. The information collection unit 110 uses the parameters of the elements to be diagnosed to collect system information of the elements to be diagnosed. The attack route calculation unit 120 uses the system information of the elements to be diagnosed to calculate attack routes for threats that pose a security risk to one or more elements in the information system by utilizing the vulnerabilities of the elements to be diagnosed. The topology display unit 130 generates topology display information, which is information for displaying the topology of the system related to security risks, including attack routes. The LLM explanation unit 150 uses user input and system information of the elements to be diagnosed to obtain answers regarding security risks for the elements to be diagnosed and explanations of those answers from the LLM 20. The LLM explanation unit 150 then generates chat display information, which is information for displaying the answers and explanations of those answers.
[0079] Topology display information is information for displaying diagrams of elements to be diagnosed. Chat display information, on the other hand, is information that includes not only security risk information such as elements to be diagnosed obtained as answers from LLM20, but also explanations to make the answers easier to understand. In other words, when a user diagnoses security risks using LLM20, the risk information output device 10 outputs chat display information that includes answers obtained from LLM20 for elements, as well as explanations to make the answers easier to understand. Furthermore, the risk information output device 10 outputs topology display information as information for visually confirming diagrams of elements and routes related to security risks.
[0080] In this way, the risk information output device 10 outputs an explanation, which is information that makes it easier to understand the answers obtained from the LLM 20 when diagnosing the security risks of an information processing system using the LLM 20. As a result, users can understand the security risks more easily or more accurately by referring to the explanation. For example, even if it is difficult to diagnose the security risks of an information system using the display of answers and topology screens, users can understand the security risks more easily by referring to the explanation displayed using chat display information.
[0081] However, the display of answers and explanations using chat display information is a display using text information. Text information can sometimes be difficult to visualize. For example, understanding an attack route is easier if images are used in addition to text information. Therefore, the risk information output device 10 outputs topology display information in addition to chat display information. As a result, users can refer to the topology screen displayed using topology display information and understand security risks visually as well.
[0082] The operation of the risk information output device 10 will be explained with reference to the operation diagram. Figure 4 is a flowchart showing an example of the operation of the risk information output device 10.
[0083] The UI processing unit 160 acquires user input to be entered into the LLM 20 (step S310). The parameter acquisition unit 140 uses the user input to acquire parameters of the elements to be diagnosed in the user input from the LLM 20 (step S320). For example, the parameter acquisition unit 140 generates a first prompt using the user input and a template prompt, and acquires parameters from the LLM 20 using the first prompt.
[0084] The information gathering unit 110 uses the acquired parameters to collect system information of the elements in the information processing system that are subject to security risk diagnosis (step S330). The attack route calculation unit 120 uses the system information of the elements to be diagnosed to calculate attack routes for threats that will cause security risk to one or more elements in the information system by utilizing the vulnerabilities of the elements to be diagnosed (step S340). The topology display unit 130 generates topology display information, which is information for displaying the topology of the system related to the security risk, including the attack routes (step S350).
[0085] The LLM explanation unit 150 obtains a response regarding the security risk of the element to be diagnosed from the LLM 20 using user input and system information of the element to be diagnosed (step S360). For example, the LLM explanation unit 150 generates a second prompt using the element's system information, user input parameters, and template prompts, and obtains a response regarding the security risk from the LLM 20 using the second prompt.
[0086] Furthermore, the LLM explanation unit 150 uses the answer to obtain an explanation about the answer from the LLM 20 (step S370). For example, the LLM explanation unit 150 generates a third prompt using the answer obtained from the LLM 20 and a template prompt, and uses the third prompt to obtain an explanation from the LLM 20. Then, the LLM explanation unit 150 generates chat display information, which is information for displaying the answer and the explanation about that answer (step S380).
[0087] Then, the UI processing unit 160 outputs chat display information and topology display information generated based on the response obtained from the LLM 20 (step S390).
[0088] The above operation is just one example. The operation of the risk information output device 10 is not limited to that described above. For example, the risk information output device 10 may perform at least part of the generation of topology display information and the generation of chat display information in parallel, or it may generate the chat display information first and then generate the topology display information.
[0089] The risk information output device 10 performs the operations described above and outputs an explanation, which is information that makes it easier to understand the answers obtained from the LLM20 when diagnosing the security risks of an information processing system using the LLM20.
[0090] - Variations The UI processing unit 160 may also perform the following operations:
[0091] The UI processing unit 160 may output chat display information for displaying system information of the element selected in the topology displayed using topology display information. Hereinafter, the element selected in this way will be referred to as the "second element". The second element is, for example, a node or a link, but is not limited to these, and may be an element that includes multiple configurations, such as a route that includes a node and a link.
[0092] For example, the UI processing unit 160 obtains information from the terminal device 30 to identify the second element, such as the identifier or device name of the second element selected on the topology screen displayed using topology display information. The UI processing unit 160 then outputs the information to identify the second element to the information collection unit 110. The information collection unit 110 collects system information of the second element. The LLM explanation unit 150 then generates chat display information including the system information of the second element. The UI processing unit 160 then outputs the chat display information generated by the LLM explanation unit 150.
[0093] The LLM explanation unit 150 may use the system information of the second element to obtain additional information or other answers regarding the second element from the LLM 20 and generate chat display information including the obtained answers. Furthermore, the LLM explanation unit 150 may obtain explanations about the answers of the second element from the LLM 20 and generate chat display information including the explanations.
[0094] However, the UI processing unit 160 may generate information for displaying the system information of the second element. For example, the UI processing unit 160 may output information for identifying the second element to the information collection unit 110, obtain the system information of the second element from the information collection unit 110, and output the obtained system information of the second element. In this case, the device that obtained the system information of the second element, such as the terminal device 30, may display the system information of the second element in any location, not limited to the chat screen.
[0095] The LLM explanation unit 150 may generate chat display information that includes other information about the second element, not just system information about the second element. For example, the LLM explanation unit 150 may generate chat display information to display vulnerability information or proposed countermeasures for the second element. Furthermore, the LLM explanation unit 150 may generate chat display information that includes an explanation of the vulnerability or proposed countermeasures for the second element. In this case as well, the UI processing unit 160 only needs to output the chat display information generated by the LLM explanation unit 150.
[0096] However, the UI processing unit 160 may acquire vulnerability information or proposed countermeasures for the second element and output such information. In this case, the device that acquired the vulnerability information or proposed countermeasures for the second element, such as the terminal device 30, may display the information not only on the chat screen but also in any location of its choice.
[0097] The UI processing unit 160 may output information for changing the display on at least one of the chat screen and the topology screen. For example, the UI processing unit 160 may output information for zooming in / out on at least one of the chat display information and the topology display information. Alternatively, the UI processing unit 160 may output information for performing displays related to filtering security risks, such as displays according to the importance of a specific attack type or countermeasure.
[0098] ・The following describes an example of operation related to the chat display information and topology display information output by the risk information output device 10, referring to the example operation diagram.In the following description, "Asset 10.0.0.1" will be used as an example of an element that is subject to security risk diagnosis.
[0099] Figure 5 is a diagram showing an example of a chat screen that displays chat display information output by the risk information output device 10 and a topology screen that displays topology display information, as used in the explanation of Figures 6-14. For example, terminal device 30 displays the chat screen and topology screen shown in Figure 5. The chat screen shown in Figure 5 includes a message input field at the bottom for entering user input and a send button for sending the entered user input to the risk information output device 10. However, the display of the chat screen and topology screen is not limited to the example shown in Figure 5. For example, the chat display information and topology display information may be displayed in the same frame. Alternatively, the chat display information and topology display information may be displayed in opposite positions. For example, the chat display information may be displayed on the right and the topology display information on the left. Alternatively, the chat display information and topology display information may be displayed vertically. Alternatively, the chat display information and topology display information may be displayed in separate positions. Alternatively, the chat display information and topology display information may be displayed on different display devices.
[0100] Figures 6-14 show examples of display screens that show chat display information and topology display information output in conjunction with the operation of the risk information output device 10. In Figures 6-11 and 13-14, user input is displayed after "You" on the chat screen. The chat display information, including answers and explanations obtained from the LLM 20 output by the risk information output device 10, is displayed after "LLM". In Figure 12, user input is displayed after each "Question". Answers and explanations are displayed after each "Answer". The topology display information output by the risk information output device 10 is displayed on the topology screen.
[0101] Figure 6 is an example of the first display screen. Specifically, Figure 6 is an example of the display of chat display information and topology display information for the system information of asset 10.0.0.1 output by the risk information output device 10. The details of the display in Figure 6 are as follows.
[0102] Following "YOU," the following user input is displayed: "Starting risk assessment for asset 10.0.0.1. Please collect information for asset 10.0.0.1."
[0103] Following "LLM," the system information for asset 10.0.0.1 is displayed based on the chat display information. Information for asset 10.0.0.1 has been collected. Asset 10.0.0.1 is the following device: Model: Asset_A Purchase date: October 2021 Firmware version: OS_A 3.1.2 IP address: 10.0.0.1 Open ports 443 https 8443 https-alt Furthermore, based on the chat display information, the following explanation is displayed: You may be able to access the management interface on port 443. You may be providing SSL-VPN on port 8443.
[0104] The topology screen then displays an image representing asset 10.0.0.1, based on the topology display information.
[0105] To realize this first display screen, the configuration of the risk information output device 10 operates as follows, for example. The UI processing unit 160 acquires user input displayed after "You" on the chat screen as user input to be input to the LLM 20. Specifically, the UI processing unit 160 acquires user input that queries for information on asset 10.0.0.1, which is an example of an element, as user input.
[0106] The parameter acquisition unit 140 inputs a first prompt to the LLM 20 to query it for the parameters in the user input, and acquires the parameters of the element to be diagnosed from the LLM 20 based on the user input. The information collection unit 110 uses the acquired parameters to collect system information of the element to be diagnosed. The topology display unit 130 generates topology display information, which is information for displaying the elements of the element to be diagnosed on the topology screen.
[0107] The LLM explanation unit 150 uses the user input parameters and system information of the element to be diagnosed to input a second prompt to the LLM 20 to query the LLM 20 for information related to the security risk of the element to be diagnosed. The LLM explanation unit 150 then obtains a response from the LLM 20. Furthermore, once the LLM explanation unit 150 obtains a response from the LLM 20, it inputs a third prompt to the LLM 20 to query the LLM 20 for an explanation of the response obtained from the LLM 20. The LLM explanation unit 150 then obtains an explanation of the response from the LLM 20.
[0108] Then, after obtaining an explanation from LLM20, the LLM explanation unit 150 generates chat display information, which is information to be displayed on the chat screen, including the answer obtained from LLM20 and the explanation for that answer.
[0109] The UI processing unit 160 then outputs chat display information and topology display information, which include explanations generated based on the answers obtained from the LLM 20.
[0110] The UI processing unit 160 may output suggestions in response to user input. Suggestions are information that provides information and recommendations related to user input in order to support the user's decision-making and work efficiency.
[0111] The information sources used by the UI processing unit 160 in outputting suggestions are not limited. For example, the UI processing unit 160 may obtain suggestions from the LLM explanation unit 150. For example, the LLM explanation unit 150 may input user input to the LLM 20 and obtain suggestions from the LLM 20 corresponding to the user input. The LLM explanation unit 150 may then generate chat display information including the obtained suggestions. In this case as well, the LLM explanation unit 150 may use a template prompt to query the LLM 20 for suggestions corresponding to the user input. The UI processing unit 160 then outputs the generated chat display information.
[0112] For example, the suggestions may be information to refer to in order to carry out the work described in a manual or handbook. In this case, the LLM explanation unit 150 may obtain the information from a database that stores the manual or handbook. Alternatively, for example, if a workflow is determined, the LLM explanation unit 150 may obtain the workflow from a database that stores the workflow and use that workflow to obtain suggestions from the LLM 20. For example, if the LLM 20 has learned the workflow of an expert, the suggestions that the LLM explanation unit 150 obtains from the LLM 20 will be suggestions that are in line with the expert's workflow. Therefore, when the LLM explanation unit 150 obtains suggestions from such an LLM 20, even if the user is a beginner, the user can refer to the suggestions and proceed with the work to a certain extent in the same way as an expert. The LLM explanation unit 150 may also use user input to obtain suggestions based on the workflow of an expert who has performed the work related to the user input.
[0113] The UI processing unit 160 then outputs chat display information including suggestions. However, the UI processing unit 160 may output suggestion information as information different from the chat display information. For example, the UI processing unit 160 may output suggestions obtained from the LLM 20 by the LLM explanation unit 150. In this case, the device that obtained the suggestion, such as the terminal device 30, may display the suggestion in any location, not limited to the topology screen and the chat screen.
[0114] Figure 7 shows an example of a display screen that shows suggestions in response to user input. The lower left of Figure 7 shows "Please collect information on asset 10.0.01," which is an example of user input. "Please display a list of external servers," is an example of a suggestion. As shown in the upper left of Figure 7, the user uses this suggestion as user input. "Information on asset 10.0.0.1 has been collected from the application information server, asset information server, and scan information server," is an example of a response to the suggestion.
[0115] However, suggestions are not limited to those described above. Suggestions may also specify elements, the scope of the target system, the time range, and the format of the response. Furthermore, suggestions are not limited to system information. For example, in Figures 8-14 used in the following explanation, the UI processing unit 160 may output chat display information that includes suggestions corresponding to user input.
[0116] In this way, when the UI processing unit 160 outputs chat display information containing suggestions, the user can proceed with the security risk assessment without using manuals or other resources. Furthermore, if the LLM 20 has learned the workflow of an expert, even if the user is a beginner, they can refer to the suggestions and proceed with the security risk assessment to a certain extent in the same way as an expert.
[0117] Figure 8 shows an example of the second display screen. Specifically, Figure 8 shows an example of displaying chat display information and topology display information, including vulnerability information for asset 10.0.0.1, output by the risk information output device 10.
[0118] As shown in Figure 8, the UI processing unit 160 obtains user input to inquire about vulnerability information about an element. The LLM explanation unit 150 inputs a second prompt to the LLM 20 in response to the user input. The LLM explanation unit 150 then obtains a response from the LLM 20 regarding the vulnerability information of the element. The LLM explanation unit 150 then generates a third prompt to inquire about an explanation using the response obtained from the LLM 20 regarding the vulnerability information of the element and inputs it to the LLM 20. The LLM explanation unit 150 then obtains an explanation about the response from the LLM 20. The LLM explanation unit 150 then generates chat display information that includes the response obtained from the LLM 20 regarding the vulnerability information of the element and the explanation about that response.
[0119] The UI processing unit 160 then outputs chat display information, including the answer to the vulnerability information for the element and its explanation. Since Figure 8 does not include any elements other than asset 10.0.0.1, the topology display information is the same as in Figure 6. Therefore, the topology screen display is the same as in Figure 6.
[0120] Figure 9 is an example of the third display screen. Specifically, Figure 9 is an example of the display of chat display information and topology display information, which include information related to the impact of the vulnerability of asset 10.0.0.1 output by the risk information output device 10.
[0121] As shown in Figure 9, the UI processing unit 160 obtains user input inquiring about information related to the impact of the element's vulnerability. The LLM explanation unit 150 inputs a second prompt to the LLM 20 in response to the user input inquiring about information related to the impact of the element's vulnerability. The LLM explanation unit 150 then obtains the answer regarding the impact of the element's vulnerability from the LLM 20. Furthermore, the LLM explanation unit 150 generates a third prompt to the LLM 20 to inquire about an explanation using the answer obtained from the LLM 20 regarding the impact of the element's vulnerability, and inputs it to the LLM 20. The LLM explanation unit 150 then obtains an explanation about the answer from the LLM 20.
[0122] The LLM explanation unit 150 then generates chat display information that includes the answer obtained from the LLM 20, which contains information related to the impact of the element's vulnerability, and an explanation of that answer.
[0123] Furthermore, the parameter acquisition unit 140 uses user input to acquire the parameters of the element to be diagnosed from the LLM 20 based on the user input. Then, the information collection unit 110 uses the element parameters to collect system information regarding the scope of impact on the information system if the element to be diagnosed is compromised, as system information related to the impact of the vulnerability of the element to be diagnosed.
[0124] The topology display unit 130 then generates topology display information to display an image on the topology screen showing the scope of impact on the system if asset 10.0.0.1 is compromised, as an image showing the impact of the vulnerability of the element to be diagnosed. Specifically, the topology display unit 130 generates topology display information to show the assets that may be affected. The UI processing unit 160 then outputs chat display information including information and explanations related to the impact of the vulnerability of the element, and topology display information.
[0125] Figure 10 shows an example of the fourth display screen. Specifically, Figure 10 shows an example of the display of chat display information and topology display information output by the risk information output device 10 regarding the attack route.
[0126] As shown in Figure 10, the UI processing unit 160 obtains user input to query the attack route. The parameter acquisition unit 140 uses the user input to obtain the parameters of the element to be diagnosed from the LLM 20. The information collection unit 110 uses the element parameters to collect system information regarding the scope of impact on the information system if the element to be diagnosed is compromised, as system information regarding the impact of the vulnerability of the element to be diagnosed.
[0127] The attack route calculation unit 120 uses the system information of the elements to calculate attack routes for threats that exploit the vulnerabilities of the elements to bring security risks to one or more elements in the information system. The topology display unit 130 then generates topology display information to display an image on the topology screen showing the attack routes if asset 10.0.0.1 is compromised.
[0128] Furthermore, the LLM explanation unit 150 inputs a second prompt to the LLM 20 in response to user input, including an inquiry about the attack route. The LLM explanation unit 150 then obtains the answer about the attack route from the LLM 20. The LLM explanation unit 150 then generates a third prompt to the LLM 20 to inquire about the explanation using the answer obtained from the LLM 20 regarding the attack route, and inputs it. The LLM explanation unit 150 then obtains the explanation about the answer from the LLM 20.
[0129] The LLM explanation unit 150 then generates chat display information that includes the response obtained from the LLM 20, which contains information related to the attack route, and its explanation. The UI processing unit 160 then outputs chat display information including the attack route and topology display information.
[0130] Figure 11 is an example of the fifth display screen. Specifically, Figure 11 is an example of the display of chat display information and topology display information output by the risk information output device 10 for at least one of the countermeasures and mitigation measures regarding the attack route.
[0131] As shown in Figure 11, the UI processing unit 160 obtains user input inquiring about at least one of the proposed countermeasures and mitigation measures for the attack route. The LLM explanation unit 150 then inputs a second prompt to the LLM 20 in response to the user input, which includes an inquiry about at least one of the proposed countermeasures and mitigation measures for the attack route. The LLM explanation unit 150 then obtains the response from the LLM 20, which includes at least one of the proposed countermeasures and mitigation measures.
[0132] The LLM explanation unit 150 then generates a third prompt to inquire about the explanation using the response obtained from the LLM 20, which includes at least one of the countermeasures and mitigation measures, and inputs it to the LLM 20. The LLM explanation unit 150 then obtains an explanation about the response obtained from the LLM 20. The LLM explanation unit 150 then generates chat display information including the response obtained from the LLM 20, which includes at least one of the countermeasures and mitigation measures regarding the attack route, and its explanation. The UI processing unit 160 then outputs chat display information including at least one of the countermeasures and mitigation measures regarding the attack route and its explanation.
[0133] Furthermore, the topology display unit 130 may generate topology display information for display on a topology screen that shows elements related to at least one of the proposed countermeasures and mitigation measures. The UI processing unit 160 may then output the generated topology display information.
[0134] In the operation shown in Figures 6 to 11, the UI processing unit 160 may acquire multiple user inputs, not just one, and output chat display information containing multiple answers corresponding to each of the multiple user inputs. Figure 12 shows an example of a sixth display screen. Specifically, Figure 12 is an example of a display when the risk information output device 10 outputs multiple chat display information. In Figure 12, the UI processing unit 160 acquires two user inputs, Question1 and Question2, followed by the UI processing unit 160. Then, as shown following Answer1 and Answer2, the UI processing unit 160 outputs chat display information containing two answers to each user input.
[0135] In this case, the topology display unit 130 may generate two topology display pieces corresponding to each of the two chat display pieces. The UI processing unit 160 may then output two topology display pieces corresponding to each of the two chat display pieces.
[0136] The UI processing unit 160 may accept three or more user inputs and output chat display information that includes three or more responses to those user inputs. In this case as well, the topology display unit 130 may generate three or more topology display information corresponding to each of the three or more chat display information. The UI processing unit 160 may then output three or more topology display information corresponding to each of the three or more chat display information.
[0137] Furthermore, as shown in Figure 12, the LLM explanation unit 150 may generate chat display information in which each response does not contain a line break, as multiple responses in the chat display information. In Figure 12, as an example of a response that does not contain a line break, the LLM explanation unit 150 uses HTML (Hyper-Text Markup Language) as the newline character in the middle of the response. It generates chat display information that includes the tag "".
[0138] However, it is conceivable that there may be cases where it is necessary to insert a delimiter at the end of each of the multiple answers in order to distinguish between them. In such cases, the LLM explanation unit 150 may use a newline character as the delimiter for the answers. However, even in this case, the LLM explanation unit 150 may generate chat display information that includes answers without newlines in the middle of each of the multiple answers.
[0139] In other words, the LLM explanation unit 150 may generate chat display information that does not include line breaks in the middle of each of the multiple answers. In this case, the UI processing unit 160 outputs multiple chat display information that does not include line breaks in the middle of each of the multiple answers.
[0140] In this way, when displaying multiple chat display information on the chat screen, each response containing no line breaks, the amount of whitespace after line breaks can be reduced in the display of responses on such a chat screen. In other words, by outputting such chat display information, the UI processing unit 160 can reduce the amount of whitespace displayed on the chat screen and increase the amount of information displayed on the screen.
[0141] Figure 13 shows an example of the seventh display screen. Specifically, Figure 13 is an example of the display when the UI processing unit 160 outputs topology display information including system information for asset 10.0.0.1, which is an example of a selected second element.
[0142] In Figure 13, asset 10.0.0.1 is clicked on the topology screen as the second element to be selected. The UI processing unit 160 then obtains information identifying the second element selected on the topology screen. In the case of Figure 13, the UI processing unit 160 obtains the identifier of asset 10.0.0.1. The information gathering unit 110 then collects system information of the second element using the information identifying the second element. The topology display unit 130 then generates topology display information to display the system information of the second element. The UI processing unit 160 then outputs the generated topology display information.
[0143] As shown in Figure 13, the system information of the second element included in the topology display information may be information for displaying structured information, compared to the system information of the second element included in the chat display information. For example, if the user is an expert, it may be easier to grasp the system information from the display of easily viewable system information, such as structured system information, than from the display of system information including explanations on the chat screen. Therefore, the topology display unit 130 may generate topology display information that includes structured system information as a display of easily viewable information, as shown in Figure 13.
[0144] However, the topology display unit 130 may generate topology display information that includes the same information as the system information displayed in the chat display information as the system information of the second element included in the topology display information.
[0145] The system information of the second element may be displayed on the chat screen. In this case, the LLM explanation unit 150 generates chat display information using the system information of the second element collected by the information collection unit 110. In this case as well, the LLM explanation unit 150 may generate chat display information that includes an explanation of the system information of the second element. The UI processing unit 160 then outputs the generated chat display information.
[0146] The UI processing unit 160 may output system information of the second element as information different from topology display information and chat display information. In this case, a device that has acquired the system information of the second element, such as the terminal device 30, may display the system information of the second element on other screens, not limited to the topology screen and the chat screen.
[0147] The UI processing unit 160 may output chat display information or topology display information that includes other information about the second element, such as vulnerability information about the second element. For example, the topology display unit 130 may generate topology display information that includes other information about the second element, such as vulnerability information about the second element. Alternatively, the LLM explanation unit 150 may generate chat display information that includes other information about the second element, such as vulnerability information about the second element.
[0148] Figure 13 shows an example where the second element is selected in Figure 11. However, this is not intended to limit the display of the system information of the second element to the case of Figure 13. The UI processing unit 160 may operate similarly for the second element selected in any topology screen, including Figures 6-10 and 12, not just Figure 11. In other words, the UI processing unit 160 may output the system information for the second element selected in any topology screen.
[0149] For example, the UI processing unit 160 may output system information of the attack route. Figure 14 shows an example of the eighth display screen. Specifically, Figure 14 is an example of displaying topology display information including system information of the attack route output by the UI processing unit 160.
[0150] In Figure 14, an attack route is clicked as the selection on the topology screen. The UI processing unit 160 then obtains information identifying the selected attack route on the topology screen. The topology display unit 130 then uses the information identifying the attack route to obtain system information for the attack route from the information collection unit 110 or the topology display unit 130. The topology display unit 130 then generates topology display information for displaying the system information of the attack route. The UI processing unit 160 then outputs the generated topology display information. The system information for the attack route includes system information for a route that contains multiple elements. In other words, the UI processing unit 160 may output topology display information that includes system information for multiple elements.
[0151] The system information of the attack route may be displayed on the chat screen. In this case, the LLM explanation unit 150 obtains the system information of the attack route from the information gathering unit 110 or the attack route calculation unit 120 and generates chat display information. In this case as well, the LLM explanation unit 150 may generate chat display information that includes an explanation of the system information of the attack route. The UI processing unit 160 then outputs the generated chat display information.
[0152] Alternatively, the UI processing unit 160 may output system information of the attack route as information different from the topology display information and the chat display information. In this case, a device that has acquired the system information of the attack route, such as the terminal device 30, may display the system information of the attack route on a screen different from the topology screen and the chat screen.
[0153] • Explanation of information related to operation Next, as an explanation of the information used by the risk information output device 10, we will explain the information stored by each storage unit shown in Figure 2. The information stored by each storage unit may be entered in advance by the user or by an information system tool, or it may be saved automatically.
[0154] The vulnerability information storage unit 210 stores vulnerability information related to the security risks of the information processing system to be diagnosed. Figure 15 shows an example of vulnerability information. In Figure 15, the vulnerability information is a combination of Common Vulnerabilities and Exposures (CVEs), the target OS, and port information. CVEs are a standardized list provided by MITRE Corporation, a non-profit organization supported by the U.S. government, that provides common identifiers for information security vulnerabilities and exposures targeting vulnerabilities in individual products. In CVEs, each vulnerability is assigned a unique identifier in the format "CVE-YYYY-NNNNN".
[0155] However, vulnerability information is not limited to the information shown in Figure 15. For example, vulnerability information may include the following:
[0156] (1) Software defects: such as bugs in the program or security vulnerabilities,
[0157] (2) Configuration errors: such as using default settings or setting inappropriate access permissions,
[0158] (3) Password vulnerabilities: passwords that can be easily guessed, passwords that have not been changed for a long time, etc.
[0159] (4) Unapplied security patches: The latest security updates have not been applied.
[0160] (5) Use of outdated software: such as using older versions whose support has ended,
[0161] (6) Running unnecessary services: such as leaving unused functions or ports open,
[0162] (7) Lack of physical security: such as improper access control to the server room,
[0163] (8) Socio-engineering vulnerabilities: such as employees' lack of awareness regarding phishing attacks.
[0164] The system information storage unit 220 stores system information for the devices and networks that constitute the system. Figure 16 shows an example of system information. In Figure 16, the system information is a combination of the notebook name, asset type, purchase date, OS version, IP address, and port information. However, the system information is not limited to the information shown in Figure 16. For example, the system information may be the following:
[0165] (1) Software information: Operating system (OS) and application type and version, etc.
[0166] (2) Network configuration: IP (Internet Protocol) address scheme, network topology, virtual LAN (VLAN: Virtual Local Area Network) settings, etc.
[0167] (3) Access control information: User accounts, access rights, password policies, etc.
[0168] (4) Security settings: Firewall rules, Intrusion Detection System (IDS) and Intrusion Prevention System (IPS) settings, log collection and monitoring settings, etc.
[0169] (5) Patch application status: Status of application of the latest security patches and patch management policy, etc.
[0170] The attack route storage unit 230 stores the attack routes calculated by the attack route calculation unit 120. Figure 17 shows an example of an attack route. The attack route in Figure 17 is a combination of an attack route identifier, path elements, and attack method. However, the attack route is not limited to the information shown in Figure 17. The attack route may be in a different format than that shown in Figure 17.
[0171] The proposed countermeasure storage unit 240 stores at least one of proposed countermeasures and mitigation measures for system vulnerabilities. Figure 18 shows an example of a proposed countermeasure. The proposed countermeasure in Figure 18 is a combination of the element to be countered, the operation of the countermeasure, and other information. The proposed countermeasures and mitigation measures may be assigned priorities. Furthermore, the proposed countermeasures and mitigation measures may each be assigned a score or degree of effectiveness. Figure 19 shows information that illustrates an example of a proposed countermeasure including scores.
[0172] However, proposed countermeasures and mitigation measures are not limited to the information shown in Figures 18 and 19. For example, proposed countermeasures and mitigation measures may include the following information:
[0173] (1) Introduction of Multi-Factor Authentication (MFA): In addition to username and password, additional authentication factors such as smartphone apps or biometric authentication will be used for authentication.
[0174] (2) Regular security updates and patch management: Keep the operating system, applications, firmware, etc., up to date.
[0175] (3) Network segmentation: Logically divide the network to isolate critical systems and confidential data.
[0176] (4) Enhance endpoint protection: Install the latest antivirus software on all devices and implement endpoint detection and response (EDR) tools.
[0177] (5) Security awareness training: Regular security training will be provided to all employees.
[0178] The template prompt storage unit 250 stores template prompts used by the risk information output device 10. For example, the template prompts may be, but are not limited to, the following prompts.
[0179] (1) Prompt for identifying security vulnerabilities: List three major security vulnerabilities in [System Name] and explain the potential impact and mitigation measures for each.
[0180] (2) Prompt for data privacy risk assessment: Identify data privacy risks related to personal information processed in [System Name] and list the current safeguards and additional measures required for each risk.
[0181] (3) System Availability Analysis Prompt: Analyze the impact of [System Name] downtime on business operations and provide three recommendations to improve system availability.
[0182] (4) Prompt for compliance risk assessment: Identify the risks that may arise if [System Name] does not comply with [Specific Regulations or Standards], and propose specific steps to ensure compliance.
[0183] (5) Prompt for third-party dependency risk assessment: List the main third-party vendors and service providers involved in the operation of [System Name], and describe the risks associated with each dependency and the management strategies for each.
[0184] Hardware Configuration Next, the hardware configuration of the risk information output device 10 will be described. Each component of the risk information output device 10 may be made up of hardware circuits. Alternatively, each component of the risk information output device 10 may be made up of multiple devices connected via a network. For example, the risk information output device 10 may be made up using cloud computing. Alternatively, multiple components of the risk information output device 10 may be made up of a single piece of hardware. Alternatively, the risk information output device 10 may be implemented as a computer including a processor and memory.
[0185] The processor is, for example, a Central Processing Unit (CPU), but is not limited thereto. The memory is, for example, read-only memory (ROM) and random access memory (RAM), but is not limited thereto. The risk information output device 10 is not limited to the above configuration and may include other configurations such as buses, storage devices, and network interfaces for connecting each configuration. The risk information output device 10 is not limited to a physical computer, but may be configured using a virtual machine implemented by a software program.
[0186] Figure 20 is a block diagram showing the configuration of a computer 600, which is an example of the hardware configuration of the risk information output device 10. The computer 600 includes a CPU 610, a ROM 620, a RAM 630, a storage device 640, and a network interface 650.
[0187] The CPU 610 reads a program from at least one of the ROM 620 and the storage device 640. Then, based on the read program, the CPU 610 controls the RAM 630, the storage device 640, and the network interface 650. The CPU 610 then controls these configurations to realize the functions of the information gathering unit 110, the attack route calculation unit 120, the topology display unit 130, the parameter acquisition unit 140, the LLM explanation unit 150, and the UI processing unit 160. In this way, the computer 600 may realize its functions as a combination of hardware and software.
[0188] The CPU 610 may read the program contained in the recording medium 690, which stores the program in a computer-readable format, using a recording medium reading device (not shown). Alternatively, the CPU 610 may receive a program from an external device (not shown) via the network interface 650, store it in the RAM 630 or storage device 640, and operate based on the stored program.
[0189] ROM 620 stores programs executed by the CPU 610 and static data. ROM 620 is, for example, a programmable ROM (P-ROM) or flash ROM. RAM 630 temporarily stores programs executed by the CPU 610 and data. RAM 630 is, for example, dynamic RAM (D-RAM). Storage device 640 stores data and programs that the computer 600 will save long-term. Storage device 640 may also function as a temporary storage device for the CPU 610. Storage device 640 is, for example, a hard disk drive, a solid-state drive (SSD), or a disk array.
[0190] ROM 620 and storage device 640 are non-transitory recording media. On the other hand, RAM 630 is a transient recording media. The CPU 610 can operate based on the programs stored in ROM 620, storage device 640, and RAM 630. In other words, the CPU 610 can operate using programs stored on either non-volatile or transient recording media.
[0191] The network interface 650 relays data exchange with external devices (not shown) via the network. For example, the network interface 650 relays data exchange between the LLM 20 and the terminal device 30. The network interface 650 is, for example, a local area network (LAN) card. The network interface 650 may use wireless technology, not just wired connections.
[0192] The computer 600 configured in this way performs the operation of each component in the risk information output device 10, thereby realizing the function of the risk information output device 10.
[0193] Some or all of the above embodiments may also be described as follows, but are not limited to the following:
[0194] (Note 1) Risk information output device comprising: UI processing means for acquiring user input about elements to be diagnosed for security risks in an information processing system and outputting chat display information and topology display information generated based on the answers acquired from LLM; parameter acquisition means for acquiring parameters of the elements to be diagnosed in the user input from LLM using the user input; information acquisition means for collecting system information of the elements to be diagnosed using the parameters of the elements to be diagnosed; attack route calculation means for calculating attack routes for threats that bring security risks to any one or more elements in the information system by utilizing the vulnerabilities of the elements to be diagnosed using the system information of the elements to be diagnosed; topology display means for generating topology display information which is information for displaying the topology of the system related to the security risk including the attack routes; LLM explanation means for acquiring answers about security risks regarding the elements to be diagnosed and explanations about the answers from LLM using the user input and system information of the elements to be diagnosed, and generating chat display information which is information for displaying the acquired answers and explanations about the answers.
[0195] (Note 2) The risk information output device according to Note 1, comprising: an answer acquisition means for obtaining the answer to security risk from LLM using the parameters in the user input and system information of the element to be diagnosed; an explanation acquisition means for obtaining an explanation of the answer from LLM using the answer; and a chat display information generation means for generating chat display information which is information for displaying the answer and the explanation of the answer.
[0196] (Note 3) The risk information output device as described in Note 2, wherein the response acquisition means generates a second prompt for querying the security risk of the element to be diagnosed using the parameters in the user input, the system information of the element to be diagnosed, and the template prompt, inputs the generated second prompt to the LLM, and obtains the response from the LLM; and the explanation acquisition means generates a third prompt for querying the LLM for an explanation of the response using the response and the template prompt, inputs the generated third prompt to the LLM, and obtains an explanation of the response from the LLM.
[0197] (Note 4) The risk information output device according to any one of Notes 1 to 3, wherein the parameter acquisition means generates a first prompt for querying the LLM for the parameters in the user input using the user input and a template prompt, inputs the generated first prompt to the LLM, and acquires the parameters of the elements to be diagnosed in the user input from the LLM.
[0198] (Note 5) The risk information output device according to any one of Notes 1 to 4, wherein the LLM explanation means inputs the user input to the LLM, obtains suggestions from the LLM corresponding to the user input, generates chat display information including the obtained suggestions, and the UI processing means outputs the chat display information including the suggestions.
[0199] (Note 6) The risk information output device described in Note 5, wherein the LLM explanation means obtains suggestions corresponding to the user input from an LLM that has learned the work flow of an expert.
[0200] (Note 7) The risk information output device according to any one of Notes 1 to 6, wherein the UI processing means obtains the user input inquiring about vulnerability information regarding the element to be diagnosed, and outputs the chat display information including vulnerability information and an explanation of the element to be diagnosed.
[0201] (Note 8) The risk information output device according to any one of Notes 1 to 7, wherein the UI processing means obtains the user input inquiring about information related to the impact of the vulnerability of the element to be diagnosed, and outputs the chat display information and topology display information including information related to the impact of the vulnerability of the element to be diagnosed.
[0202] (Note 9) The risk information output device according to any one of Notes 1 to 8, wherein the UI processing means obtains the user input inquiring about the attack route and outputs the chat display information and topology display information including the attack route.
[0203] (Note 10) The risk information output device according to any one of Notes 1 to 9, wherein the UI processing means obtains the user input inquiring about at least one of the proposed countermeasures and mitigation measures for the attack route, and outputs the chat display information including at least one of the proposed countermeasures and mitigation measures for the attack route.
[0204] (Note 11) The risk information output device according to any one of Notes 1 to 10, wherein the UI processing means outputs the topology display information or the chat display information for displaying the system information of the second element selected on the topology screen that displays the topology display information.
[0205] (Note 12) The risk information output device according to any one of Notes 1 to 11, wherein the UI processing means outputs the topology display information or the chat display information for displaying the system information of the selected attack route on the topology screen that displays the topology display information.
[0206] (Note 13) The risk information output device according to any one of Notes 1 to 12, wherein the UI processing means acquires a plurality of user inputs and outputs chat display information including a plurality of responses corresponding to each of the plurality of user inputs.
[0207] (Note 14) The risk information output device according to Note 13, wherein the LLM explanation means generates chat display information that does not include line breaks in the middle of each of the multiple answers, and the UI processing means outputs multiple chat display information that does not include line breaks in the middle of each of the multiple answers.
[0208] (Note 15) A risk information output method comprising: obtaining user input about elements to be diagnosed for security risks in an information processing system; obtaining parameters of the elements to be diagnosed from LLM using the user input; collecting system information of the elements to be diagnosed using the parameters of the elements to be diagnosed; calculating attack routes for threats that bring security risks to one or more elements in the information system by utilizing the vulnerabilities of the elements to be diagnosed using the system information of the elements to be diagnosed; generating topology display information, which is information for displaying the topology of the system related to the security risk including the attack routes; obtaining answers about security risks for the elements to be diagnosed and explanations about those answers from LLM using the user input and system information of the elements to be diagnosed; generating chat display information, which is information for displaying the obtained answers and explanations about those answers; and outputting the chat display information and topology display information generated based on the answers obtained from LLM.
[0209] (Note 16) A recording medium for recording a program that causes a computer to execute: a process that obtains user input about an element to be diagnosed as a security risk in an information processing system and outputs chat display information and topology display information generated based on the answer obtained from LLM; a process that uses the user input to obtain the parameters of the element to be diagnosed from LLM; a process that uses the parameters of the element to be diagnosed to collect system information of the element to be diagnosed; a process that uses the system information of the element to be diagnosed to calculate an attack route for a threat that will cause a security risk to one or more elements in the information system by utilizing the vulnerability of the element to be diagnosed; a process that generates topology display information which is information for displaying the topology of the system related to the security risk including the attack route; and a process that uses the user input and the system information of the element to be diagnosed to obtain the answer to the security risk about the element to be diagnosed and an explanation of the answer from LLM, and generates chat display information which is information for displaying the obtained answer and the explanation of the answer.
[0210] Furthermore, some or all of the configurations described in Appendices 2 to 14, which are subordinate to Appendice 1 above, may also be subordinate to Appendices 15 and 16 in the same way as those described in Appendices 2 to 14. Moreover, not limited to Appendices 1, 15, and 16, some or all of the configurations described as appendices may also be subordinate to various hardware, software, various recording means for recording software, or systems, without departing from the embodiments described above.
[0211] The present invention has been described above using the embodiments described above as exemplary examples. However, the present invention is not limited to the embodiments described above. That is, the present invention can be applied in various forms that can be understood by those skilled in the art within the scope of the present invention.
[0212] 10 Risk information output device 20 LLM 30 Terminal device 110 Information collection unit 120 Attack route calculation unit 130 Topology display unit 140 Parameter acquisition unit 150 LLM explanation unit 151 Answer acquisition unit 152 Explanation acquisition unit 153 Chat display information generation unit 160 UI processing unit 210 Vulnerability information storage unit 220 System information storage unit 230 Attack route storage unit 240 Countermeasure proposal storage unit 250 Template prompt storage unit 600 Computer 610 CPU 620 ROM 630 RAM 640 Storage device 650 Network interface 690 Recording medium
Claims
1. Risk information output device comprising: UI processing means for acquiring user input about elements to be diagnosed for security risks in an information processing system and outputting chat display information and topology display information generated based on the answers obtained from LLM; parameter acquisition means for acquiring parameters of the elements to be diagnosed in the user input from LLM using the user input; information acquisition means for collecting system information of the elements to be diagnosed using the parameters of the elements to be diagnosed; attack route calculation means for calculating attack routes for threats that bring security risks to any one or more elements in the information system by utilizing the vulnerabilities of the elements to be diagnosed using the system information of the elements to be diagnosed; topology display means for generating topology display information, which is information for displaying the topology of the system related to the security risk including the attack routes; and LLM explanation means for acquiring answers about security risks regarding the elements to be diagnosed and explanations about those answers from LLM using the user input and system information of the elements to be diagnosed, and generating chat display information, which is information for displaying the acquired answers and explanations about those answers.
2. The risk information output device according to claim 1, comprising: an answer acquisition means for obtaining the answer to security risk from LLM using the parameters in the user input and system information of the element to be diagnosed; an explanation acquisition means for obtaining an explanation of the answer from LLM using the answer; and a chat display information generation means for generating chat display information which is information for displaying the answer and the explanation of the answer.
3. The risk information output device according to claim 2, wherein the response acquisition means generates a second prompt for querying the LLM for security risks regarding the element to be diagnosed using the parameters in the user input, system information of the element to be diagnosed, and a template prompt, inputs the generated second prompt to the LLM, and obtains the response from the LLM; and the explanation acquisition means generates a third prompt for querying the LLM for an explanation of the response using the response and a template prompt, inputs the generated third prompt to the LLM, and obtains an explanation of the response from the LLM.
4. The risk information output device according to any one of claims 1 to 3, wherein the parameter acquisition means generates a first prompt for querying the LLM for the parameters in the user input using the user input and a template prompt, inputs the generated first prompt to the LLM, and acquires the parameters of the element to be diagnosed in the user input from the LLM.
5. The risk information output device according to any one of claims 1 to 4, wherein the LLM explanation means inputs the user input to the LLM, obtains suggestions from the LLM corresponding to the user input, generates chat display information including the obtained suggestions, and the UI processing means outputs the chat display information including the suggestions.
6. The risk information output device according to claim 5, wherein the LLM explanation means obtains suggestions corresponding to the user input from an LLM that has learned the work flow of an expert.
7. The risk information output device according to any one of claims 1 to 6, wherein the UI processing means obtains the user input inquiring about vulnerability information regarding the element to be diagnosed, and outputs the chat display information including vulnerability information and an explanation of the element to be diagnosed.
8. The risk information output device according to any one of claims 1 to 7, wherein the UI processing means obtains user input inquiring about information related to the impact of the vulnerability of the element to be diagnosed, and outputs the chat display information and topology display information including information related to the impact of the vulnerability of the element to be diagnosed.
9. The risk information output device according to any one of claims 1 to 8, wherein the UI processing means obtains the user input inquiring about the attack route and outputs the chat display information and topology display information including the attack route.
10. The risk information output device according to any one of claims 1 to 9, wherein the UI processing means obtains user input inquiring about at least one of the proposed countermeasures and mitigation measures for the attack route, and outputs the chat display information including at least one of the proposed countermeasures and mitigation measures for the attack route.
11. The risk information output device according to any one of claims 1 to 10, wherein the UI processing means outputs the topology display information or the chat display information for displaying system information of a second element selected on a topology screen that displays the topology display information.
12. The risk information output device according to any one of claims 1 to 11, wherein the UI processing means outputs the topology display information or the chat display information for displaying the system information of the selected attack route on the topology screen that displays the topology display information.
13. The risk information output device according to any one of claims 1 to 12, wherein the UI processing means acquires a plurality of user inputs and outputs chat display information including a plurality of responses corresponding to each of the plurality of user inputs.
14. The risk information output device according to claim 13, wherein the LLM explanation means generates chat display information that does not include line breaks in the middle of each of the multiple answers, and the UI processing means outputs the multiple chat display information that does not include line breaks in the middle of each of the multiple answers.
15. Risk information output method comprising: obtaining user input about elements to be diagnosed for security risks in an information processing system; obtaining parameters of the elements to be diagnosed from LLM using the user input; collecting system information of the elements to be diagnosed using the parameters of the elements to be diagnosed; calculating attack routes for threats that bring security risks to one or more elements in the information system by utilizing the vulnerabilities of the elements to be diagnosed using the system information of the elements to be diagnosed; generating topology display information, which is information for displaying the topology of the system related to the security risk including the attack routes; obtaining answers regarding security risks for the elements to be diagnosed and explanations for those answers from LLM using the user input and system information of the elements to be diagnosed; generating chat display information, which is information for displaying the obtained answers and explanations for those answers; and outputting the chat display information and topology display information generated based on the answers obtained from LLM.
16. A recording medium for recording a program that causes a computer to execute:
16. A process that obtains user input about an element to be diagnosed as a security risk in an information processing system, and outputs chat display information and topology display information generated based on the answer obtained from LLM; a process that uses the user input to obtain the parameters of the element to be diagnosed from LLM; a process that uses the parameters of the element to be diagnosed to collect system information of the element to be diagnosed; a process that uses the system information of the element to be diagnosed to calculate an attack route for a threat that brings a security risk to one or more elements in the information system by utilizing the vulnerability of the element to be diagnosed; a process that generates topology display information, which is information for displaying the topology of the system related to the security risk including the attack route; and a process that uses the user input and the system information of the element to be diagnosed to obtain the answer regarding the security risk of the element to be diagnosed and an explanation of the answer from LLM, and generates chat display information, which is information for displaying the obtained answer and the explanation of the answer.
Citation Information
Patent Citations
Security Test System
JP7488976B1