Cross-Operator Vulnerability Analysis via Standardized Identifier Mapping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing vulnerability management systems are difficult to apply to the Operational Technology (OT) field due to differences in software management methods among business operators, making it challenging to integrate and analyze vulnerabilities across a supply chain.
Innovation Solution
A vulnerability analysis method and system that acquire component parts identifiers and proprietary software identifiers from multiple business operators, create correspondence data, and use a vulnerability database to identify and analyze vulnerabilities in target products, enabling cross-operator vulnerability analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If vulnerability management systems are applied to OT field, then vulnerability analysis capability is improved, but system complexity increases due to differences in software management methods among business operators
Solution Approach 1:
The patent introduces a standardized correspondence data structure as an intermediary between different business operators' software management systems. This correspondence data includes standardized fields such as product identifiers, component parts identifiers, and proprietary software identifiers that map different operators' proprietary identifier systems to a common framework, enabling vulnerability analysis without requiring direct integration of complex proprietary systems
Solution Approach 2:
The patent transforms the problem by changing the parameters from direct proprietary software identifier comparison to standardized identifier mapping. By introducing correspondence relationships between different identifier systems (component parts identifiers, proprietary software identifiers, and standardized product identifiers), the system enables vulnerability analysis across different business operators while maintaining their existing management methods
2Measurement precision
If software information is integrated across multiple business operators, then vulnerability identification accuracy is improved, but information integration difficulty increases
Solution Approach 1:
The patent segments the information integration problem into manageable components by processing data in three distinct stages: first collecting component parts identifiers and proprietary software identifiers separately from each business operator, then creating correspondence relationships between these identifiers and standardized product identifiers, and finally performing vulnerability analysis on the structured correspondence data. This segmentation avoids the need for complete pre-integration of proprietary information systems
Solution Approach 2:
The patent creates a universal correspondence data structure that can accommodate different business operators' proprietary identifier systems. The standardized data model with product identifiers, component parts identifiers, and proprietary software identifiers serves multiple functions: it preserves each operator's proprietary system, enables cross-operator vulnerability analysis, and provides a common framework for future expansions
Data Source
AI summary
A vulnerability analysis method including: acquisition processing of acquiring a component parts identifier, which is an identifier of component parts as parts configuring a product for each identifier of the product from each of a plurality of business operators, and business operator inherent data including an identifier of proprietary software but not included in the component parts from each of a plurality of business operators; correspondence identification processing of identifying a correspondence of an identifier of the product and the component parts identifier between different business operators based on previously created correspondence data; target product identification processing of identifying a target product as a product to be investigated; and vulnerability identification processing of identifying all of the proprietary software included in the target product based on the correspondence identification processing, and identifying vulnerability of software included in the target product by referring to a vulnerability DB storing data.


