Login| Sign Up| Help| Contact|

Patent Searching and Data


Title:
SCORING DEVICE AND METHOD FOR SCORING SECURITY THREAT
Document Type and Number:
WIPO Patent Application WO/2015/025694
Kind Code:
A1
Abstract:
Provided are a threat risk scoring assistance device and method whereby it is possible, without depending on the skill of an analyst, to compute a threat risk value. A model definition assistance unit carries out an input assistance according to a selected risk scoring technique and stores, obtained from a design specification, a number of externally connected devices, path information, a number of authentications among subsystems, a protected asset confidentiality impact, and an ASIL which is set in the subsystems, in subsystem detail information, externally connected device information, internally connected device information, and protected asset information, of a risk scoring dependent information storage unit. A threat extraction unit and a threat risk value calculation unit carry out a threat extraction and a threat risk value computation using the selected risk scoring technique, on the basis of information stored in a risk scoring independent information storage unit and the risk scoring dependent information storage unit which this threat risk scoring assistance device retains in advance.

Inventors:
MORITA NOBUYOSHI (JP)
KAYASHIMA MAKOTO (JP)
ANDOU ERIKO (JP)
Application Number:
PCT/JP2014/070298
Publication Date:
February 26, 2015
Filing Date:
August 01, 2014
Export Citation:
Click for automatic bibliography generation   Help
Assignee:
HITACHI AUTOMOTIVE SYSTEMS LTD (JP)
International Classes:
G06F21/57; G06Q50/04
Foreign References:
JP2002352062A2002-12-06
US20130074188A12013-03-21
JP2009015570A2009-01-22
JP2006331383A2006-12-07
JP2001101135A2001-04-13
JP2011022903A2011-02-03
Other References:
PETER MELL ET AL.: "A Complete Guide to the Common Vulnerability Scoring System Version 2.0", FORUM OF INCIDENT RESPONSE AND SECURITY TEAMS, June 2007 (2007-06-01), pages 7 - 9,17-22, Retrieved from the Internet [retrieved on 20141022]
Attorney, Agent or Firm:
INOUE Manabu et al. (JP)
Manabu Inoue (JP)
Download PDF: