Cross-Operator Vulnerability Analysis via Standardized Identifier Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing vulnerability management systems are difficult to apply to the Operational Technology (OT) field due to differences in software management methods among business operators, making it challenging to integrate and analyze vulnerabilities across a supply chain.

Innovation Solution

A vulnerability analysis method and system that acquire component parts identifiers and proprietary software identifiers from multiple business operators, create correspondence data, and use a vulnerability database to identify and analyze vulnerabilities in target products, enabling cross-operator vulnerability analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If vulnerability management systems are applied to OT field, then vulnerability analysis capability is improved, but system complexity increases due to differences in software management methods among business operators

Engineering Contradiction:
Improvevulnerability analysis capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a standardized correspondence data structure as an intermediary between different business operators' software management systems. This correspondence data includes standardized fields such as product identifiers, component parts identifiers, and proprietary software identifiers that map different operators' proprietary identifier systems to a common framework, enabling vulnerability analysis without requiring direct integration of complex proprietary systems

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transforms the problem by changing the parameters from direct proprietary software identifier comparison to standardized identifier mapping. By introducing correspondence relationships between different identifier systems (component parts identifiers, proprietary software identifiers, and standardized product identifiers), the system enables vulnerability analysis across different business operators while maintaining their existing management methods

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If software information is integrated across multiple business operators, then vulnerability identification accuracy is improved, but information integration difficulty increases

Engineering Contradiction:
Improvevulnerability identification accuracyVSAvoidinformation integration difficulty
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the information integration problem into manageable components by processing data in three distinct stages: first collecting component parts identifiers and proprietary software identifiers separately from each business operator, then creating correspondence relationships between these identifiers and standardized product identifiers, and finally performing vulnerability analysis on the structured correspondence data. This segmentation avoids the need for complete pre-integration of proprietary information systems

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal correspondence data structure that can accommodate different business operators' proprietary identifier systems. The standardized data model with product identifiers, component parts identifiers, and proprietary software identifiers serves multiple functions: it preserves each operator's proprietary system, enables cross-operator vulnerability analysis, and provides a common framework for future expansions

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20240354418A1Vulnerability analysis method and vulnerability analysis system
Publication Date: 2024.10.24 HITACHI LTD
  • US20240354418A1 patent drawing
  • US20240354418A1 patent drawing
  • US20240354418A1 patent drawing

AI summary

A vulnerability analysis method including: acquisition processing of acquiring a component parts identifier, which is an identifier of component parts as parts configuring a product for each identifier of the product from each of a plurality of business operators, and business operator inherent data including an identifier of proprietary software but not included in the component parts from each of a plurality of business operators; correspondence identification processing of identifying a correspondence of an identifier of the product and the component parts identifier between different business operators based on previously created correspondence data; target product identification processing of identifying a target product as a product to be investigated; and vulnerability identification processing of identifying all of the proprietary software included in the target product based on the correspondence identification processing, and identifying vulnerability of software included in the target product by referring to a vulnerability DB storing data.