JP7294441B2 - 評価装置、評価システム、評価方法及びプログラム - Google Patents

評価装置、評価システム、評価方法及びプログラム Download PDF

Info

Publication number
JP7294441B2
JP7294441B2 JP2021553260A JP2021553260A JP7294441B2 JP 7294441 B2 JP7294441 B2 JP 7294441B2 JP 2021553260 A JP2021553260 A JP 2021553260A JP 2021553260 A JP2021553260 A JP 2021553260A JP 7294441 B2 JP7294441 B2 JP 7294441B2
Authority
JP
Japan
Prior art keywords
application
information
vulnerability
library
risk
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
JP2021553260A
Other languages
English (en)
Japanese (ja)
Other versions
JPWO2021079495A1 (https=
JPWO2021079495A5 (https=
Inventor
和彦 磯山
純明 榮
淳 西岡
佑嗣 小林
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
NEC Corp
Original Assignee
NEC Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by NEC Corp filed Critical NEC Corp
Publication of JPWO2021079495A1 publication Critical patent/JPWO2021079495A1/ja
Publication of JPWO2021079495A5 publication Critical patent/JPWO2021079495A5/ja
Application granted granted Critical
Publication of JP7294441B2 publication Critical patent/JP7294441B2/ja
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/52Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems during program execution, e.g. stack integrity ; Preventing unwanted data erasure; Buffer overflow
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/57Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
    • G06F21/577Assessing vulnerabilities and evaluating computer system security
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F2221/00Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/03Indexing scheme relating to G06F21/50, monitoring users, programs or devices to maintain the integrity of platforms
    • G06F2221/033Test or assess software

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Hardware Design (AREA)
  • General Engineering & Computer Science (AREA)
  • Software Systems (AREA)
  • Theoretical Computer Science (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Computing Systems (AREA)
  • Debugging And Monitoring (AREA)
JP2021553260A 2019-10-25 2019-10-25 評価装置、評価システム、評価方法及びプログラム Active JP7294441B2 (ja)

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/JP2019/041928 WO2021079495A1 (ja) 2019-10-25 2019-10-25 評価装置、評価システム、評価方法及びプログラム

Publications (3)

Publication Number Publication Date
JPWO2021079495A1 JPWO2021079495A1 (https=) 2021-04-29
JPWO2021079495A5 JPWO2021079495A5 (https=) 2022-06-27
JP7294441B2 true JP7294441B2 (ja) 2023-06-20

Family

ID=75619725

Family Applications (1)

Application Number Title Priority Date Filing Date
JP2021553260A Active JP7294441B2 (ja) 2019-10-25 2019-10-25 評価装置、評価システム、評価方法及びプログラム

Country Status (3)

Country Link
US (1) US12271483B2 (https=)
JP (1) JP7294441B2 (https=)
WO (1) WO2021079495A1 (https=)

Families Citing this family (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US12149555B2 (en) 2021-12-28 2024-11-19 SecureX.AI, Inc. Systems and methods for vulnerability assessment for cloud assets using imaging methods
US12299133B2 (en) * 2021-12-28 2025-05-13 SecureX.AI, Inc. Systems and methods for prioritizing security findings using machine learning models
US12166785B2 (en) 2021-12-28 2024-12-10 SecureX.AI, Inc. Systems and methods for predictive analysis of potential attack patterns based on contextual security information
US12299135B2 (en) * 2022-09-29 2025-05-13 Red Hat, Inc. K-anonymous vulnerability detection
JP2025040502A (ja) * 2023-09-12 2025-03-25 株式会社東芝 情報処理装置、情報処理方法及びプログラム

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2009217637A (ja) 2008-03-11 2009-09-24 Fujitsu Ltd セキュリティ状況表示装置、セキュリティ状況表示方法、およびコンピュータプログラム
WO2012132125A1 (ja) 2011-03-30 2012-10-04 株式会社日立製作所 脆弱性判定システム、脆弱性判定方法、および、脆弱性判定プログラム
JP2017224053A (ja) 2016-06-13 2017-12-21 株式会社日立製作所 脆弱性リスク評価システムおよび脆弱性リスク評価方法
JP2019525287A (ja) 2016-06-23 2019-09-05 インターナショナル・ビジネス・マシーンズ・コーポレーションInternational Business Machines Corporation 脆弱なアプリケーションの検出

Family Cites Families (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2005114403A1 (en) * 2004-05-21 2005-12-01 Computer Associates Think, Inc. Method and apparatus for reusing a computer software library
JP4751431B2 (ja) 2008-09-12 2011-08-17 株式会社東芝 脆弱性判定装置及びプログラム
JP2010117887A (ja) 2008-11-13 2010-05-27 Nec Corp 脆弱性判定装置、脆弱性判定方法及び脆弱性判定プログラム
US20120137369A1 (en) * 2010-11-29 2012-05-31 Infosec Co., Ltd. Mobile terminal with security functionality and method of implementing the same
US8799647B2 (en) * 2011-08-31 2014-08-05 Sonic Ip, Inc. Systems and methods for application identification
MX349569B (es) * 2013-02-25 2017-08-03 Beyondtrust Software Inc Sistemas y metodos de reglas a base de riesgo para control de aplicaciones.
US9591570B2 (en) * 2014-04-07 2017-03-07 Aruba Networks, Inc. Method and system for tracking devices
JP6415353B2 (ja) 2015-03-02 2018-10-31 キヤノン株式会社 情報処理方装置、情報処理装置の制御方法、およびコンピュータプログラム
US10678513B2 (en) * 2017-09-12 2020-06-09 Devfactory Fz-Llc Library upgrade method, apparatus, and system
WO2020026228A1 (en) * 2018-08-01 2020-02-06 Vdoo Connected Trust Ltd. Firmware verification

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2009217637A (ja) 2008-03-11 2009-09-24 Fujitsu Ltd セキュリティ状況表示装置、セキュリティ状況表示方法、およびコンピュータプログラム
WO2012132125A1 (ja) 2011-03-30 2012-10-04 株式会社日立製作所 脆弱性判定システム、脆弱性判定方法、および、脆弱性判定プログラム
JP2017224053A (ja) 2016-06-13 2017-12-21 株式会社日立製作所 脆弱性リスク評価システムおよび脆弱性リスク評価方法
JP2019525287A (ja) 2016-06-23 2019-09-05 インターナショナル・ビジネス・マシーンズ・コーポレーションInternational Business Machines Corporation 脆弱なアプリケーションの検出

Also Published As

Publication number Publication date
WO2021079495A1 (ja) 2021-04-29
US12271483B2 (en) 2025-04-08
JPWO2021079495A1 (https=) 2021-04-29
US20220374528A1 (en) 2022-11-24

Similar Documents

Publication Publication Date Title
JP7294441B2 (ja) 評価装置、評価システム、評価方法及びプログラム
US9665469B2 (en) System and method of runtime downloading of debug code and diagnostics tools in an already deployed baseboard management controller (BMC) devices
US9317276B2 (en) Updating software
US20200074084A1 (en) Privacy-preserving component vulnerability detection and handling
US9471780B2 (en) System, method, and computer program product for mounting an image of a computer system in a pre-boot environment for validating the computer system
EP3616066B1 (en) Human-readable, language-independent stack trace summary generation
US9229758B2 (en) Passive monitoring of virtual systems using extensible indexing
US9471594B1 (en) Defect remediation within a system
CN121579028A (zh) 即时容器
WO2015178895A1 (en) Point-wise protection of application using runtime agent
CN108292342B (zh) 向固件中的侵入的通知
WO2014013499A1 (en) System and method for operating system agnostic hardware validation
US11435991B2 (en) Automated machine deployment and configuration
US20180225109A1 (en) Techniques of adding security patches to embedded systems
CN114519004A (zh) 应用软件的稳定性测试方法、装置、设备及介质
US8392469B2 (en) Model based distributed application management
US20260106888A1 (en) System and method for software service cybersecurity remediation
JP7355211B2 (ja) シグネチャ生成装置、シグネチャ生成方法およびシグネチャ生成プログラム
WO2024003785A1 (en) Techniques for differential inspection of container layers
US20250335186A1 (en) Configuration validation for container deployments in a computing environment
US20260099340A1 (en) Custom operating system generation for resource-constrained computing systems
US12278835B1 (en) System and method for tracing cloud computing environment deployments to code objects
CN119512714B (zh) 一种对于容器的监测方法和宿主机
US12423426B1 (en) System and method for tracing cloud computing environment deployments to code objects utilizing unique fingerprints
US12462039B2 (en) System and method for evaluating active backups using penetration testing

Legal Events

Date Code Title Description
A521 Request for written amendment filed

Free format text: JAPANESE INTERMEDIATE CODE: A523

Effective date: 20220420

A621 Written request for application examination

Free format text: JAPANESE INTERMEDIATE CODE: A621

Effective date: 20220420

A131 Notification of reasons for refusal

Free format text: JAPANESE INTERMEDIATE CODE: A131

Effective date: 20230328

A521 Request for written amendment filed

Free format text: JAPANESE INTERMEDIATE CODE: A523

Effective date: 20230417

TRDD Decision of grant or rejection written
A01 Written decision to grant a patent or to grant a registration (utility model)

Free format text: JAPANESE INTERMEDIATE CODE: A01

Effective date: 20230509

A61 First payment of annual fees (during grant procedure)

Free format text: JAPANESE INTERMEDIATE CODE: A61

Effective date: 20230522

R151 Written notification of patent or utility model registration

Ref document number: 7294441

Country of ref document: JP

Free format text: JAPANESE INTERMEDIATE CODE: R151