首页> 外国专利> SECURITY RISK ANALYSIS ASSISTANCE DEVICE, METHOD, AND COMPUTER-READABLE MEDIUM

SECURITY RISK ANALYSIS ASSISTANCE DEVICE, METHOD, AND COMPUTER-READABLE MEDIUM

机译:安全风险分析辅助设备,方法和计算机可读介质

摘要

According to the present invention, objective indicators are presented to users in risk evaluation. Attack route information (21) includes information on an attack route including one or more attack steps including an attack source, an attack destination, and an attack method. A vulnerability specifying means (11) specifies the vulnerability used for attacking the attack destination in the attack step with reference to the attack route information (21). A vulnerability information DB (22) stores the vulnerability in association with the presence or absence of an attack verification code for the vulnerability. A diagnostic evaluation generation means (12) examines whether or not the attack verification code exists for the specified vulnerability with reference to the vulnerability information DB (22), and generates, for an attack step, a risk diagnosis evaluation including the number of specified vulnerabilities and the presence or absence of the attack verification code. An output means (13) outputs the attack step and the risk diagnosis evaluation in association with each other.
机译:根据本发明,客观指标呈现给风险评估中的用户。攻击路由信息(21)包括关于攻击路由的信息,包括一个或多个攻击步骤,包括攻击源,攻击目的地和攻击方法。漏洞指定手段(11)指定用于参考攻击路由信息(21)中攻击攻击步骤中攻击攻击目的地的漏洞。漏洞信息DB(22)将漏洞与攻击验证码的存在或不存在相关联,以实现漏洞。诊断评估生成装置(12)检查攻击验证码是否存在于参考漏洞信息DB(22)的指定漏洞,并为攻击步骤生成,其中风险诊断评估包括指定漏洞的数量以及攻击验证码的存在与否。输出装置(13)输出攻击步骤和彼此相关联的风险诊断评估。

著录项

  • 公开/公告号WO2021059471A1

    专利类型

  • 公开/公告日2021-04-01

    原文格式PDF

  • 申请/专利权人 NEC CORPORATION;

    申请/专利号WO2019JP38107

  • 申请日2019-09-27

  • 分类号G06F21/57;

  • 国家 JP

  • 入库时间 2022-08-24 18:03:41

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号