CPE Configuration Converter for Automated Vulnerability Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The complexity of the Common Platform Enumeration (CPE) format makes it difficult and costly to manually create and manage vulnerability information for products, hindering effective vulnerability monitoring systems that compare product configurations with publicly disclosed vulnerabilities.
Innovation Solution
An information processing apparatus that includes a configuration information converter to transform first configuration information into a standardized CPE format, utilizing vulnerability information from specific and versatile servers to identify and convert software identifiers, enabling efficient detection of vulnerabilities across diverse devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual creation of CPE configuration information is performed, then vulnerability monitoring accuracy is improved, but time consumption and costs increase
Solution Approach 1:
The system automatically retrieves configuration information from the target device and converts it to CPE format without requiring manual intervention. The converter autonomously performs the transformation process by obtaining device configuration, extracting software identifiers, and generating standardized CPE strings, thereby eliminating the need for manual CPE creation while maintaining high accuracy in vulnerability monitoring.
Solution Approach 2:
The patent replaces the manual mechanical process of creating CPE configuration information with an automated information processing system. The converter uses automated tools and algorithms to transform device configuration data into standardized CPE format, substituting human labor with computational processes that are both faster and more consistent.
2Measurement precision
If manual creation of CPE configuration information is performed, then vulnerability monitoring accuracy is improved, but costs increase
Solution Approach 1:
The system performs self-service by automatically obtaining device configuration information and converting it to CPE format without requiring manual expertise or labor. This automation eliminates the need for specialized personnel to manually create CPE strings, thereby reducing both time consumption and operational costs while maintaining high accuracy in vulnerability identification.
Solution Approach 2:
The patent substitutes the manual mechanical process of CPE creation with an automated information processing system. The converter uses computational algorithms to transform raw device configuration data into standardized CPE format, replacing human labor with cost-effective automated processing that maintains or improves accuracy while significantly reducing creation costs.
3Adaptability or versatility
If CPE format is used for configuration information, then vulnerability comparison capability is improved, but device complexity increases
Solution Approach 1:
The converter acts as an intermediary between the target device and the vulnerability monitoring system. It automatically retrieves configuration information from the device, transforms it into standardized CPE format, and provides it to the vulnerability monitoring system. This intermediary process handles the complexity of CPE format conversion, allowing the vulnerability comparison capability to be enhanced without requiring the target device itself to become more complex.
Solution Approach 2:
The converter extracts the necessary configuration information from the target device and separates it from the device's operational complexity. By pulling out only the relevant configuration data and transforming it into standardized CPE format, the system enables comprehensive vulnerability comparison capability while keeping the target device's complexity unchanged.
Data Source
AI summary
An information processing apparatus according to one embodiment, comprising: a first vulnerability information obtainer configured to obtain, from a first server, first vulnerability information; a second vulnerability information obtainer configured to obtain, from a second server, second vulnerability information; a first configuration information obtainer configured to obtain first configuration information included in the target device; a scanner configured to detect a first identifier, from the first vulnerability information, based on the first configuration information, and identify the vulnerability identifier associated with the detected first identifier; a searcher configured to identify a second identifier that is associated with the vulnerability identifier identified, and includes a name of software identical to the name of the target software, based on the second vulnerability information; and an output processor configured to generate a third identifier by replacing the version included in the second identifier identified with the version of the target software.


