Security Inspection Apparatus Configuration Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security inspection methods struggle to detect flaws in security structures beyond vulnerability assessment, such as security architecture or design issues in systems related to software and hardware.

Innovation Solution

A security inspection apparatus and method that obtain configuration information related to a system, determine if this information is associated with predefined security functions, and generate information on these determinations to identify structural flaws in security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If vulnerability assessment tools and software are used for security inspection, then automation and comprehensive detection of known vulnerabilities are achieved, but detection of flaws in security structure (such as security architecture or design) becomes difficult

Engineering Contradiction:
Improveautomation of security inspectionVSAvoiddetection of security structure flaws
Core Design Contradiction:
Extent of automationVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments the security inspection process into two distinct parts: (1) automated vulnerability assessment using tools and software for detecting known vulnerabilities, and (2) manual or semi-automated security structure assessment for evaluating security architecture and design. This segmentation allows each method to be applied to the type of flaw it is best suited for, resolving the contradiction between automation and detection capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary component that bridges automated vulnerability assessment and manual security structure assessment. This intermediary analyzes configuration information and determines associations with security functions, enabling the transition from automated vulnerability detection to structured security architecture evaluation, thereby maintaining automation benefits while improving security structure flaw detection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If configuration information is obtained and analyzed for security functions, then detection of security structure flaws is improved, but inspection time and processing complexity increase

Engineering Contradiction:
Improvedetection accuracy of security structure flawsVSAvoidinspection time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-defining security functions and their associated configuration information before the actual inspection process. Configuration information is obtained and prepared in advance, and security functions are predetermined, allowing the inspection process to efficiently match configuration information against predefined security functions rather than analyzing everything from scratch, thus reducing inspection time while maintaining detection accuracy.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If comprehensive security inspection including security architecture and design is performed, then detection capability is improved, but device complexity and processing requirements increase

Engineering Contradiction:
Improvecomprehensiveness of security inspectionVSAvoidcomplexity of inspection system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements universality by designing an inspection system that can handle multiple types of security assessments through a unified framework. The system determines associations between configuration information and security functions using a generalizable approach that works for both vulnerability assessment and security structure assessment, reducing the need for separate specialized tools and thereby managing complexity while maintaining comprehensiveness.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12223058B2Security inspection apparatus, security inspection method, and program
Publication Date: 2025.02.11 NEC CORP
  • US12223058B2 patent drawing
  • US12223058B2 patent drawing
  • US12223058B2 patent drawing

AI summary

In order to appropriately detect flaws in a structure related to security of a system related to at least one of software and hardware, a security inspection apparatus includes an obtaining unit that obtains one or more pieces of configuration information related to configuration of a system to be inspected in security inspection, the system being related to at least one of software and hardware, a determining unit that determines whether or not each of the one or more pieces of configuration information is associated with any of one or more types of security functions set as inspection items for the security inspection, and a generating unit that generates information related to the determination.