Threat analysis support device, threat analysis support system, and computer-readable recording medium
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- FANUC LTD
- Filing Date
- 2025-01-21
- Publication Date
- 2026-07-30
Smart Images

Figure JP2025001762_30072026_PF_FP_ABST
Abstract
Description
Threat analysis support device, threat analysis support system, and computer-readable recording medium
[0001] The present disclosure relates to a threat analysis support device, a threat analysis support system, and a computer-readable recording medium.
[0002] In recent years, with the advancement of the utilization of AI and big data, control devices installed in manufacturing sites such as factories and their management systems have come to be connected to a network and used. Along with this, the security threats of IoT have been increasing. Therefore, in order for users to be able to use the devices installed at the manufacturing site with confidence, it is necessary to conduct a security threat analysis and implement countermeasures that do not lead to serious incidents even if a cyber-attack occurs (for example, Patent Document 1, etc.).
[0003]
[0003] In addition, ISA / IEC 62443 and CRA require the implementation of security threat analysis of control systems and digital devices. Therefore, it is expected that the need to analyze the security risks of control devices and digital devices will increase in the future.
[0004] Japanese Patent Application Laid-Open No. 2019-219898
[0005] The threat analysis of a control device varies depending on the actual usage environment and usage situation. Therefore, when conducting threat analysis, it is necessary for an expert with security knowledge to confirm on-site. However, experts with security knowledge are scarce human resources, and there is a problem that a great deal of cost is required for on-site confirmation work. At the site, a technology that enables easy threat analysis is desired.
[0006] The threat analysis support device according to the present disclosure collects machine information data according to the usage environment and usage situation from a control device or a control system, and requests a series of threat analysis-related operations such as analysis of the collected data, identification of threats, evaluation of cyber security risks, and presentation of recommended countermeasures to the trained generative AI. Then, by presenting the analyzed results to the user, the above problems are solved.
[0007] Furthermore, one aspect of the present disclosure is a threat analysis support device comprising: an information collection unit for collecting usage status data of at least one device related to the object of analysis; a prompt creation unit for creating a prompt for performing threat analysis based on the usage status data; a transmission unit for transmitting the prompt to a generating AI device; a receiving unit for receiving a response containing information related to the threat analysis from the generating AI device; and an output unit for outputting the results of the threat analysis included in the response.
[0008] This is a schematic hardware configuration diagram of a threat analysis support device according to one embodiment of the present disclosure. This is a block diagram showing the schematic functions of a threat analysis support device according to the first embodiment. This is a schematic diagram showing examples of multiple templates stored in the template storage unit. This is a schematic diagram showing an example of a template. This is a schematic diagram showing another example of a template. This is a schematic diagram showing an example of a prompt. This is a schematic diagram showing an example of a response from a generating AI device. This is a block diagram showing the schematic functions of a threat analysis support device according to the second embodiment. This is a schematic diagram showing an example of a template used when creating a prompt that includes threat analysis reference data. This is a block diagram showing the schematic functions of a threat analysis support device according to the third embodiment.
[0009] Embodiments of this disclosure will be described below with reference to the drawings. In the following description, components having the same or similar functions will be denoted by the same reference numerals. Duplication of these components may be omitted.
[0010] In this application, "based on XX" means "based on at least XX," and includes cases where it is based on another element in addition to XX. Furthermore, "based on XX" is not limited to cases where XX is used directly, but also includes cases where it is based on something that has been calculated or processed. "XX" is any element (for example, any information).
[0011] [First Embodiment] Figure 1 is a schematic hardware configuration diagram showing the main parts of a threat analysis support device according to the first embodiment of the present disclosure. The threat analysis support device 1 according to this embodiment can be mounted, for example, on a portable terminal carried by a user working in a manufacturing plant. The threat analysis support device 1 can also be mounted on a computer such as a personal computer attached to a control device, or a personal computer, cell computer, fog computer 6, cloud server 7, etc., connected to the control device via a wired / wireless network. In this embodiment, an example is shown in which the threat analysis support device 1 is mounted on a portable terminal carried by a user working in a manufacturing plant.
[0012] The CPU 11 in the threat analysis support device 1 according to this embodiment is a processor that controls the threat analysis support device 1 as a whole. The CPU 11 reads the system program stored in the ROM 12 via the bus 22 and controls the entire threat analysis support device 1 according to the system program. The RAM 13 temporarily stores temporary calculation data, display data, and various data acquired from external sources.
[0013] The non-volatile memory 14 is composed of, for example, a memory or SSD (Solid State Drive) backed up by a battery (not shown), and retains its stored state even when the power to the threat analysis support device 1 is turned off. The non-volatile memory 14 stores programs and data read from external devices 72 via the interface 15, programs and data input via the input device 71, and programs and data acquired from the control device 3 that controls the industrial machine 4 and other devices via the network 5. The programs and data stored in the non-volatile memory 14 may be expanded into the RAM 13 when executed or used. In addition, various system programs, such as known analysis programs, are pre-written in the ROM 12.
[0014] Interface 15 is an interface for connecting the CPU 11 of the threat analysis support device 1 to an external device 72 such as a USB device. System programs, configuration data, etc., can be read from the external device 72. Programs and configuration data created or edited within the threat analysis support device 1 can also be stored in an external storage means via the external device 72.
[0015] Interface 20 is an interface for connecting the CPU 11 of the threat analysis support device 1 to a wired or wireless network 5. The network 5 may communicate using technologies such as serial communication (RS-485, for example), Ethernet® communication, optical communication, wireless LAN, Wi-Fi®, Bluetooth®, etc. The network 5 is connected to a control device 3 that controls at least one industrial machine 4 to be verified, a generation AI device 2 that responds to user inquiries, a fog computer 6, a cloud server 7, etc., and exchanges data with the threat analysis support device 1.
[0016] The display device 70 displays data obtained as a result of the execution of various data, programs, etc., loaded into memory, via the interface 17. The input device 71, which consists of at least one input device such as a keyboard, pointing device, touch panel, voice input device, imaging device, or barcode reader, transmits commands, data, etc., based on user operations to the CPU 11 via the interface 18.
[0017] The Generative AI Device 2 is configured as a device that responds to a predetermined text with data such as response text, images, audio, or programs. The Generative AI Device 2 includes, for example, a known Large Language Model (LLM) that has learned response data such as text, images, audio, or programs to a predetermined text. This model can be a known model such as the Transformer model. Depending on how the documents that respond to a predetermined text are trained in the Large Language Model training, the Generative AI Device 2 can be used for purposes such as dialogue, question and answer, text summarization, text editing, text translation, text transformation, text modification, text optimization, text interpretation, text detection, recognition, prediction, judgment, code generation, image generation, and overall judgment.
[0018] The threat analysis support device 1 described herein is assumed to be connected to the generation AI device 2 via a network 5. The threat analysis support device 1 can constitute a threat analysis support system 300 together with the generation AI device 2. The generation AI device 2 includes a model that has been trained based on various information publicly available on the internet, for example. The information publicly available on the internet includes information on attack patterns and risk assessment algorithms related to security for control devices, industrial machinery, and manufacturing equipment management systems. In addition, if necessary, additional training (fine-tuning) may be performed in advance using threat analysis-related data that includes at least information on attack patterns and risk assessment algorithms related to security for control devices, industrial machinery, and manufacturing equipment management systems as training data. By narrowing down the information used for training, it is possible to prepare a generation AI device 2 that returns responses with a certain degree of accuracy to queries.
[0019] Figure 2 is a schematic block diagram showing the functions of the threat analysis support device 1 according to the first embodiment of this disclosure. Each function of the threat analysis support device 1 according to this embodiment is realized by the CPU 11 of the threat analysis support device 1 shown in Figure 1 executing a system program and controlling the operation of each part of the threat analysis support device 1.
[0020] The threat analysis support device 1 of this embodiment includes an information collection unit 100, a prompt creation unit 120, a transmission unit 140, a reception unit 150, and an output unit 190. In addition, the RAM 13 to non-volatile memory 14 of the threat analysis support device 1 is provided with a template storage unit 200, which is an area that stores templates related to prompts in advance.
[0021] The information gathering unit 100 collects usage status data for at least one device related to the device under analysis. The usage status data is information related to the usage environment and usage status of the device under analysis. The usage status data includes at least information related to the hardware configuration of the device under analysis, information related to the software configuration, and information related to the connection status with other devices. The hardware configuration information included in the usage status data includes, for example, the model name of the device under analysis, the names and connection types of peripheral devices attached to the device under analysis, and information on installed hardware security devices. The software configuration information included in the usage status data includes the name and version of the device's firmware, the name and version of the OS installed on the device, the name and version of the drivers installed on the device, the name and version of the software installed on the device, information related to security patches applied to the OS and software, information related to the settings of the OS and software, and information on installed security software. The connection status with other devices includes information related to the interface used for connection, information related to other devices that can communicate, and traffic data on each interface.
[0022] The information collection unit 100 may collect usage status data for at least one designated device based on user operation via the input device 71. The device may be designated, for example, by reading a two-dimensional code containing information that uniquely identifies the control device 3, which is attached to the device such as the control device 3 using an imaging device, which is one of the input devices 71. Alternatively, the user may be prompted to input information that uniquely identifies the device by operating a touch panel or keyboard, which is another input device 71. The information collection unit 100 may also collect usage status data for the control device 3 or other devices designated by the user via the network 5. Alternatively, the usage status data of the device may be coded into a two-dimensional code and attached to the device so that the usage status data can be collected directly from there. The object of analysis may be, for example, a single control device 3, or a control system including multiple control devices 3, a fog computer, a cloud server, etc. In this case, the information relating to the connection status with other devices may include information relating to the network configuration in which multiple devices are connected. The information collection unit 100 outputs the acquired usage status data to the prompt creation unit 120.
[0023] The prompt creation unit 120 creates prompts that can be input to the generating AI device 2 based on the usage status data acquired by the information collection unit 100. The prompts created by the prompt creation unit 120 are for performing threat analysis on at least one device related to the analysis target. The prompt creation unit 120 may assign prompt identification information to the created prompt so that the prompt can be uniquely identified. The prompt creation unit 120 may, for example, create prompts by applying the respective information contained in the usage status data to a prompt template.
[0024] Figure 3 is a schematic diagram showing an example of multiple templates stored in the template storage unit 200. In the example in Figure 3, the template storage unit 200 stores multiple templates 1, 2, ... Each template corresponds to the target of the threat analysis. The prompt creation unit 120 selects a template stored in the template storage unit 200 according to the analysis target for which the information gathering unit 100 has collected usage status data. Then, it creates a prompt using the selected template.
[0025] Figure 4 is a schematic diagram showing an example of a template. In the example in Figure 4, the template includes information keys for embedding predetermined information at predetermined positions in the prompt text. The prompt creation unit 120 creates the prompt by embedding the corresponding information at the positions of each information key. In the example in Figure 4, the usage status data collected by the information collection unit 100 is embedded at the position of the information key "MACHINE_STATUS_DATA".
[0026] Figure 5 is a schematic diagram showing another example of a template. The example in Figure 5 is a template used when requesting a threat analysis for a system consisting of multiple devices. The prompt creation unit 120 embeds usage status data for each device collected by the information collection unit 100 at the information key locations "MACHINE_STATUS_DATA1", "MACHINE_STATUS_DATA2", ... and also embeds information related to the network configuration in which the multiple devices are connected at the information key location "NETWORK_STATUS_DATA".
[0027] Figure 6 is a schematic diagram showing an example of a prompt created based on a template. The prompt in Figure 6 is used when requesting a threat analysis for a control device with the model name "A02B-0353-B502". This prompt is created by embedding usage status data collected by the information collection unit 100 into the template exemplified in Figure 4.
[0028] Such templates should be created in advance to match the format of the queries to the generation AI device 2. For example, if the generation AI device 2 handles queries that list items, it is desirable to have a template for creating prompts that list each item. Similarly, if it handles queries in natural language, it is desirable to have a template for creating prompts in the form of natural sentences. It is desirable that each template is created to include information that will be helpful in creating answers to the expected service queries.
[0029] The transmission unit 140 transmits the prompt created by the prompt creation unit 120 to the generation AI device 2. Upon receiving the prompt from the transmission unit 140, the generation AI device 2 generates a response to the received prompt. It then transmits the generated response to the threat analysis support device 1.
[0030] The receiving unit 150 receives the response transmitted from the generating AI device 2. This response includes information generated by the generating AI device 2 regarding the threat analysis of at least one device related to the analysis target. Figure 7 is a schematic diagram illustrating the response from the generating AI device 2. The information regarding the threat analysis of at least one device related to the analysis target may include, for example, the detected threat, the risk assessment of the detected threat, and recommended countermeasures against the detected threat. The receiving unit 150 outputs the received response to the output unit 190.
[0031] The output unit 190 outputs information related to the threat analysis of at least one device related to the analysis target received by the receiving unit 150. The output unit 190 may also output to the display device 70. Alternatively, it may output to a display device (not shown) provided by the control device 3 via the network 5. Furthermore, it may transmit output to other computers such as the fog computer 6 or the cloud server 7 via the network 5.
[0032] The threat analysis support device 1 according to this embodiment, equipped with the above configuration, can perform threat analysis easily and quickly, even without security experts being on-site, in accordance with changes in the actual usage environment and conditions. Therefore, it can reduce the inconvenience and significant costs associated with on-site verification work.
[0033] [Second Embodiment] The following describes a threat analysis support device according to a second embodiment of the present disclosure. The threat analysis support device 1 according to this embodiment has the same hardware configuration as the threat analysis support device 1 according to the first embodiment.
[0034] Figure 8 is a schematic block diagram showing the functions of the threat analysis support device 1 according to the second embodiment of this disclosure. Each function of the threat analysis support device 1 according to this embodiment is realized by the CPU 11 of the threat analysis support device 1 shown in Figure 1 executing a system program and controlling the operation of each part of the threat analysis support device 1.
[0035] The threat analysis support device 1 of this embodiment includes a search unit 110 in addition to an information collection unit 100, a prompt creation unit 120, a transmission unit 140, a reception unit 150, and an output unit 190. Furthermore, the RAM 13 to non-volatile memory 14 of the threat analysis support device 1 is provided with a template storage unit 200, which is an area that stores templates related to prompts in advance, as well as a threat analysis related data storage unit 210, which is an area that stores threat analysis related data, including at least information related to attack patterns and risk assessment algorithms for at least one device related to the analysis target.
[0036] The information collection unit 100, transmission unit 140, receiving unit 150, and output unit 190 of the threat analysis support device 1 according to this embodiment have the same functions as the information collection unit 100, transmission unit 140, receiving unit 150, and output unit 190 according to the first embodiment.
[0037] The search unit 110 extracts data related to at least one device subject to analysis from the threat analysis-related data storage unit 210 based on the usage status data collected by the information collection unit 100. Then, it generates threat analysis reference data from the extracted data, including information on at least attack patterns and risk assessment algorithms. The threat analysis-related data storage unit 210 stores information such as manuals and specifications for each device, recommended security settings (network segmentation), technical documents related to security functions (security guidelines, etc.), patterns of external attacks against the device, past attack methods, past cyberattack cases, incident reports, cybersecurity threat scenarios against control devices such as "scenarios of device malfunction due to malware infection" and "scenarios of data leakage due to unauthorized access," algorithms for risk assessment, evaluation values of the impact of each threat, evaluation values of the probability of occurrence, and security measures against each threat. The search unit 110 obtains information on the device subject to analysis from the usage status data collected by the information collection unit 100 and searches the inside of the threat analysis-related data storage unit 210 using the obtained information. Then, threat analysis-related data related to the equipment being analyzed is extracted from the threat analysis-related data storage unit 210 and used as threat analysis reference data. The search unit 110 outputs the threat analysis reference data to the prompt creation unit 120.
[0038] The prompt creation unit 120 in this embodiment creates a prompt for threat analysis based on the usage status data collected by the information collection unit 100 and the threat analysis reference data extracted by the search unit 110 from the threat analysis related data storage unit 210. Figure 9 is a schematic diagram showing an example of a template used when creating a prompt that includes threat analysis reference data. The template illustrated in Figure 9 includes an information key called "THREAT_ASSMNT_REFERENCE" as an information key for embedding threat analysis related data, in addition to an information key for embedding usage status data. The prompt creation unit 120 embeds the usage status data collected by the information collection unit 100 at the location of the information key called "MACHINE_STATUS_DATA". It also embeds the threat analysis reference data extracted by the search unit 110 at the location of the information key called "THREAT_ASSMNT_REFERENCE". Based on the prompts created in this way, the generating AI device 2 performs a threat analysis on the equipment related to the analysis target, referring to the threat analysis reference data, and creates threat analysis information as a response.
[0039] The threat analysis support device 1 according to this embodiment, with the above configuration, can perform threat analysis easily and quickly, even without a security expert on-site, in accordance with changes in the actual usage environment and conditions. In particular, by providing the data used as reference during threat analysis to the generating AI device 2, it is possible to improve the accuracy of the threat analysis.
[0040] [Third Embodiment] The following describes a threat analysis support device according to the third embodiment of this disclosure. The threat analysis support device 1 according to this embodiment has the same hardware configuration as the threat analysis support device 1 according to the first embodiment.
[0041] Figure 10 is a schematic block diagram showing the functions of the threat analysis support device 1 according to the third embodiment of this disclosure. Each function of the threat analysis support device 1 according to this embodiment is realized by the CPU 11 of the threat analysis support device 1 shown in Figure 1 executing a system program and controlling the operation of each part of the threat analysis support device 1.
[0042] In addition to the information collection unit 100, prompt creation unit 120, transmission unit 140, reception unit 150, and output unit 190, the threat analysis support device 1 of this embodiment further includes a verification unit 170. In the RAM 13 to non-volatile memory 14 of the threat analysis support device 1, a template storage unit 200, which is an area for pre-storing templates related to prompts, is prepared.
[0043] The information collection unit 100, transmission unit 140, reception unit 150, and output unit 190 included in the threat analysis support device 1 according to this embodiment have the same functions as the information collection unit 100, transmission unit 140, reception unit 150, and output unit 190 according to the first embodiment.
[0044] The verification unit 170 analyzes the response received by the reception unit 150 and verifies the threats detected by the generation AI device 2, the risk assessment of the detected threats, and the presence or absence of recommended countermeasures for the detected threats. The verification unit 170 verifies whether information related to the detected threats is included in the information related to the threat analysis of at least one device related to the analysis target created by the generation AI device 2. This can be verified, for example, by searching whether keywords such as "insufficient information required to detect threats" are included in the response using techniques such as known fuzzy search. It can also be verified by confirming whether similar words are not included using known natural language analysis techniques. Further, the verification unit 170 uses a similar technique to verify whether the risk assessment of the detected threats or the recommended countermeasures for the detected threats are included in the information related to the threat analysis of at least one device related to the analysis target created by the generation AI device 2. Then, the verification result is output to the output unit 190 together with the response received by the reception unit.
[0045] If the verification unit 170 finds that at least one of the detected threat, the risk assessment of the detected threat, or the recommended countermeasures for the detected threat is not included in the response from the generating AI device 2, for example, if the response contains a keyword such as "Insufficient information to detect the threat," the verification unit 170 may request the prompt creation unit 120 to create a prompt that includes the additional information necessary to obtain this information. For the additional information, a screen may be displayed to the user requesting additional information, allowing them to add further usage data or other information. At this time, the response from the generating AI device 2 may contain hints regarding the missing information. If such hints are included in the response, the content of the response may be displayed to help the user select the additional information. In this embodiment, the prompt creation unit 120 creates a prompt with the additional information added in response to the request from the verification unit 170. Then, it outputs the created prompt to the transmission unit 140.
[0046] Furthermore, the verification unit 170 may request the prompt creation unit 120 to create a prompt to check the effectiveness of the recommended countermeasures based on the response from the generating AI device 2 received by the receiving unit 150. In this configuration, the prompt creation unit 120 according to this embodiment creates a prompt requesting threat analysis by adding the recommended countermeasures to the usage status data. The created prompt is then output to the transmission unit 140. This allows the generating AI device 2 to create the results of the threat analysis when the recommended countermeasures are implemented.
[0047] The threat analysis support device 1 according to this embodiment, which has the above configuration, is capable of performing more flexible threat analysis based on the response from the generating AI device 2.
[0048] [Other Embodiments] In the above-described embodiment, the threat analysis support apparatus 1 is shown to have a template storage unit 200 and a threat analysis-related data storage unit 210. However, the template storage unit 200 and the threat analysis-related data storage unit 210 may be provided on other apparatuses such as the fog computer 6 or the cloud server 7, for example. In this case, the threat analysis support apparatus 1 refers to the template storage unit 200 and the threat analysis-related data storage unit 210 via the network 5. By adopting such a configuration, it becomes possible to collectively manage templates and threat analysis-related data at a manufacturing site where many industrial machines 4 and control devices 3 are installed.
[0049] Although the embodiments of the present disclosure have been described in detail above, the present disclosure is not limited to the individual embodiments described above. These embodiments can be variously added, replaced, changed, partially deleted, etc., without departing from the gist of the invention or without departing from the idea and spirit of the present disclosure derived from the content described in the claims and its equivalents. For example, in the above-described embodiment, the order of each operation and the order of each process are shown as an example and are not limited thereto. The same applies when numerical values or mathematical formulas are used in the description of the above-described embodiment.
[0050] The following shows an appendix according to an embodiment of the present disclosure. (Appendix 1) A threat analysis support apparatus (1) according to one aspect of the present disclosure includes an information collection unit (100) that collects usage state data of at least one device related to an analysis target, a prompt creation unit (120) that creates a prompt for performing threat analysis based on the usage state data, a transmission unit (140) that transmits the prompt to a generation AI device (2), a reception unit (150) that receives a response including information related to the threat analysis from the generation AI device (2), and an output unit (190) that outputs the result of the threat analysis included in the response.
[0051] (Note 2) A threat analysis support device (1) in another aspect of the present disclosure further comprises: a threat analysis related data storage unit (210) that stores threat analysis related data including at least information relating to attack patterns and risk assessment algorithms for at least one device related to the analysis target; a search unit (110) that extracts relevant data from the threat analysis related data storage unit based on the usage status data to generate threat analysis reference data including at least information relating to attack patterns and risk assessment algorithms; and a prompt creation unit (120) that creates a prompt for performing threat analysis based on the usage status data and the threat analysis reference data.
[0052] (Note 3) The threat analysis-related data used by the threat analysis support device (1) in other embodiments of the present disclosure includes security measures. (Note 4) The threat analysis support device (1) in other embodiments of the present disclosure further comprises a verification unit (170) that verifies the detected threat, the risk assessment of the detected threat, and whether or not there are recommended countermeasures for the detected threat, based on the response received by the receiving unit (150).
[0053] (Note 5) The verification unit (170) of the threat analysis support device (1) according to another aspect of the present disclosure requests the prompt creation unit (120) to create a prompt that adds the information necessary to obtain the detected threat, the risk assessment of the detected threat, and the recommended countermeasures for the detected threat if the response received by the receiving unit (150) does not include at least one of these. (Note 6) The verification unit (160) of the threat analysis support device (1) according to another aspect of the present disclosure requests the prompt creation unit (120) to create a prompt that adds the recommended countermeasures included in the response to the usage status data based on the response received by the receiving unit (150).
[0054] (Note 7) The usage status data collected by the threat analysis support device (1) in other aspects of this disclosure includes one or more of the following: machine configuration, connection information with external devices, traffic data for each interface, implemented security functions, and configuration data. (Note 8) The usage status data collected by the threat analysis support device (1) in other aspects of this disclosure includes input data.
[0055] (Note 9) A threat analysis support system (300) according to one aspect of the present disclosure comprises a threat analysis support device (1) and a generation AI device (2), wherein the generation AI device (2) has undergone additional learning using threat analysis-related data that includes at least information relating to attack patterns and risk assessment algorithms against at least one device related to the analysis target.
[0056] (Note 10) A computer-readable recording medium according to one aspect of the present disclosure records a program that causes a computer to operate as an information collection unit (100) that collects usage status data of at least one device related to the object of analysis, a prompt creation unit (120) that creates a prompt for performing threat analysis based on the usage status data, a transmission unit (140) that transmits the prompt to a generating AI device (2), a receiving unit (150) that receives a response containing information related to the threat analysis from the generating AI device (2), and an output unit (190) that outputs the results of the threat analysis included in the response.
[0057] 1 Threat analysis support device 2 Generation AI device 3 Control device 4 Industrial machine 5 Network 6 Fog computer 7 Cloud server 11 CPU 12 ROM 13 RAM 14 Non-volatile memory 15, 17, 18, 20 Interface 22 Bus 70 Display device 71 Input device 72 External device 100 Information gathering unit 110 Search unit 120 Prompt creation unit 140 Transmission unit 150 Receiving unit 170 Verification unit 190 Output unit 200 Template storage unit 210 Threat analysis related data storage unit 300 Threat analysis support system
Claims
1. A threat analysis support device comprising: an information collection unit that collects usage status data of at least one device related to the target of analysis; a prompt creation unit that creates a prompt for performing threat analysis based on the usage status data; a transmission unit that transmits the prompt to a generating AI device; a receiving unit that receives a response containing information related to the threat analysis from the generating AI device; and an output unit that outputs the results of the threat analysis included in the response.
2. The threat analysis support device according to claim 1, further comprising: a threat analysis related data storage unit that stores threat analysis related data including at least information relating to attack patterns and risk assessment algorithms against at least one device related to the subject of analysis; and a search unit that extracts relevant data from the threat analysis related data storage unit based on the usage status data to generate threat analysis reference data including at least information relating to attack patterns and risk assessment algorithms, wherein the prompt creation unit creates a prompt for performing threat analysis based on the usage status data and the threat analysis reference data.
3. The threat analysis support device according to claim 2, wherein the threat analysis-related data includes security measures.
4. The threat analysis support device according to claim 3, further comprising a verification unit that verifies the detected threat, the risk assessment of the detected threat, and whether or not there are recommended countermeasures for the detected threat, based on the response received by the receiving unit.
5. The threat analysis support device according to claim 4, wherein if the verification unit does not include at least one of the detected threat, the risk assessment of the detected threat, and the recommended countermeasures for the detected threat in the response received by the receiving unit, the verification unit requests the prompt creation unit to create a prompt that adds the information necessary to obtain this information.
6. The threat analysis support device according to claim 4, wherein the verification unit requests the prompt creation unit to create a prompt that adds the recommended countermeasures included in the response to the usage status data, based on the response received by the receiving unit.
7. The threat analysis support device according to claim 1, wherein the usage status data includes one or more of the following: machine configuration, connection information with external devices, traffic data for each interface, implemented security functions, and configuration data.
8. The threat analysis support device according to claim 1, wherein the usage status data includes input data.
9. A threat analysis support system comprising a threat analysis support device according to any one of claims 1 to 8 and a generating AI device, wherein the generating AI device has undergone additional learning using threat analysis-related data that includes at least information relating to attack patterns and risk assessment algorithms against at least one device related to the analysis target.
10. A computer-readable recording medium that records a program causing a computer to operate as: an information collection unit that collects usage status data of at least one device related to the object of analysis; a prompt creation unit that creates a prompt for performing threat analysis based on the usage status data; a transmission unit that transmits the prompt to a generating AI device; a receiving unit that receives a response containing information related to the threat analysis from the generating AI device; and an output unit that outputs the results of the threat analysis included in the response.