Evaluation Specification Refinement Through Threat-Vulnerability Linking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing risk evaluation countermeasure planning systems fail to effectively associate threat analysis, vulnerability analysis, and security tests, leading to incomplete evaluations of evaluation target devices.
Innovation Solution
An evaluation support system that performs first and second association processing to concatenate threat and vulnerability analysis information with evaluation specifications, and re-defines these specifications to ensure comprehensive evaluation, including feedback mechanisms for improved accuracy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If threat analysis information and vulnerability analysis information are separately processed without association, then the evaluation process is simpler, but the evaluation completeness deteriorates
Solution Approach 1:
The patent combines threat analysis information and vulnerability analysis information into a unified evaluation framework by performing association processing that links threats, vulnerabilities, and evaluation specifications together, ensuring comprehensive evaluation without excessive complexity
Solution Approach 2:
The patent introduces an association processing mechanism as an intermediary that connects threat analysis results, vulnerability analysis results, and evaluation specifications, enabling integrated evaluation while maintaining modular system architecture
2Measurement precision
If evaluation specifications are not re-defined based on analysis results, then the processing time is shorter, but the evaluation accuracy deteriorates
Solution Approach 1:
The patent performs preliminary association processing to concatenate threat and vulnerability analysis information with evaluation specifications before the actual evaluation, preparing refined evaluation specifications in advance to improve accuracy without significant time loss
Solution Approach 2:
The patent implements a feedback mechanism where evaluation specifications are re-defined based on the results of threat and vulnerability analysis, creating an iterative process that improves evaluation accuracy through systematic refinement
Data Source
AI summary
An evaluation support system includes a threat concatenator that performs first association processing for concatenating at least part of threat analysis information with first evaluation specification information, the threat analysis information indicating a result of analysis of a threat to information security of an evaluation target device, the first evaluation specification information indicating one or more evaluation specifications of the evaluation target device; a vulnerability concatenator that performs second association processing for concatenating at least part of vulnerability analysis information with the first evaluation specification information, the vulnerability analysis information indicating a result of analysis of the vulnerability of the information security of the evaluation target device; and a re-definer that generates and outputs second evaluation specification information by re-defining, based on the first association processing and the second association processing, the one or more evaluation specifications indicated by the first evaluation specification information.


