Threat-Type Risk Evaluation for Vulnerable Security Countermeasure Software
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Evaluating the risk to a target system due to vulnerabilities in security countermeasure software has been difficult in existing systems.
Innovation Solution
An information processing system that identifies threat types countered by installed security countermeasure software, calculates risk values with and without countermeasures, and outputs damage potential information based on vulnerability information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security countermeasure software is installed to protect the target system, then the security protection capability is improved, but the risk evaluation capability for the target system deteriorates due to vulnerabilities in the security software itself
Solution Approach 1:
The system segments the risk evaluation process into distinct components: vulnerability detection module, risk calculation module, and countermeasure effectiveness analysis module. This segmentation allows the system to handle the complexity of evaluating security software vulnerabilities separately from evaluating target system risks, making the overall evaluation process more manageable and systematic.
Solution Approach 2:
The patent introduces an intermediary information processing system that acts as a mediator between the security countermeasure software and the target system. This intermediary system detects vulnerabilities in the security software and calculates their impact on the target system, enabling risk evaluation without requiring direct access to the target system's internal security mechanisms.
2Measurement precision
If comprehensive vulnerability detection is performed on security countermeasure software, then the accuracy of risk evaluation is improved, but the processing time and computational resources increase
Solution Approach 1:
The system performs preliminary actions by maintaining a database of known vulnerabilities and their associated risk profiles before actual risk evaluation is needed. When evaluating the target system, the system queries this pre-prepared vulnerability information rather than conducting full vulnerability scans, significantly reducing processing time while maintaining evaluation accuracy.
Solution Approach 2:
The patent changes the evaluation parameters by focusing on specific vulnerability metrics that have the greatest impact on target system risk. Instead of analyzing all possible vulnerability attributes, the system identifies and evaluates only the critical parameters (such as exploitability, impact scope, and countermeasure dependency), reducing computational complexity while preserving accuracy.
3Device complexity
If the system evaluates risks without considering countermeasure effectiveness, then the evaluation process is simplified, but the usefulness of the risk information for decision-making deteriorates
Solution Approach 1:
The system implements feedback by calculating and comparing risk values with and without countermeasures. This feedback mechanism provides decision-makers with actionable information about the effectiveness of installed security software, enabling them to understand whether countermeasures are actually reducing risk or if additional actions are needed.
Solution Approach 2:
The patent applies partial action by focusing the countermeasure effectiveness analysis only on the specific vulnerabilities detected in the security countermeasure software, rather than evaluating all possible security controls. This selective approach provides sufficient information for decision-making without requiring a complete analysis of every security mechanism in the system.
Data Source
AI summary
According to an embodiment, an information processing system includes one or more hardware processors. The one or more hardware processors are configured to: identify a threat type capable of being countered by installed software being security countermeasure software installed in a target system, from among security countermeasure software with a reported vulnerability; calculate a first risk value when a countermeasure is taken by the installed software for a threat of the identified threat type; calculate a second risk value when no countermeasure is taken by the installed software for the threat of the identified threat type; and output damage potential information including risk value change information representing a change in the second risk value with respect to the first risk value.


