IP Library Granted Patent US 12688647
Granted Patent B2
US 12688647 · App. 18/568,907 · Granted Jul 21, 2026

Risk analysis apparatus, virtual model generation apparatus, method, and computer readable medium

Inventors: Ryo Mizushima (Tokyo, JP); Tomohiko Yagyu (Tokyo, JP)
Assignee: NEC CORPORATION
G06T17/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12688647
App. No.
18/568,907
Granted
Jul 21, 2026
Kind
B2
Abstract

Grouping means groups a plurality of hosts included in a system to be analyzed into a plurality of groups each including one or more hosts. The grouping means uses measure-related information including information related to measures planned for the system to be analyzed to group the plurality of hosts into the plurality of groups. Virtual analysis element generation means generates a virtual analysis element for each of the plurality of groups. Virtual model generation means generates a virtual model used for risk analysis that includes the virtual analysis elements generated by the virtual analysis element generation means. Analysis means analyzes the risks included in the system to be analyzed using the virtual model generated by the virtual model generation means.

Claims (50)

1 . A risk analysis apparatus comprising:

a memory storing instructions; and

a processor configured to execute the instructions to:

group a plurality of hosts included in a system to be analyzed into a plurality of groups each including one or more hosts using countermeasure-related information including information related to countermeasures planned to address risks included in the system;

generate one or more virtual analysis elements for each of the plurality of groups;

generate a virtual model used for risk analysis, the virtual model including the generated virtual analysis elements; and

analyze the risks included in the system to be analyzed using the virtual model,

wherein the countermeasure-related information includes at least one of time information, management information, operation information, or functional performance information, and

wherein the time information includes at least one of an operating time of the host, a frequency of countermeasures, and a time required for countermeasures, the management information including at least one of information about a vendor, a management department, and a location where the host is installed, the operation information including at least one of information related to whether or not administrator privileges can be disabled and whether or not USB memory devices can be used, the functional performance information including information about an available capacity of storage devices, a memory capacity, a central processing unit (CPU) performance, a maintenance support expiration date for an OS or software, and an availability of rack space.

2 . The risk analysis apparatus according to claim 1 ,

wherein the processor is configured to execute the instructions to group the plurality of hosts into the plurality of groups further using a grouping condition specifying, from among information included in the countermeasure-related information, information to be used for grouping and a value of the information.

3 . The risk analysis apparatus according to claim 1 , wherein the processor is configured to execute the instructions to group the hosts into the plurality of groups further using configuration information about the system.

4 . The risk analysis apparatus according to claim 3 , wherein the processor is configured to execute the instructions to group the hosts into the plurality of groups based on the configuration information in a first stage, and divide at least some of the plurality of groups into the plurality of groups using the countermeasure-related information in a second stage.

5 . The risk analysis apparatus according to claim 1 , wherein the processor is configured to execute the instructions to generate a representative host that is a virtual host representing the hosts belonging to the group as the virtual analysis element.

6 . The risk analysis apparatus according to claim 5 , wherein the processor is configured to execute the instructions to merge attackable elements of the host belonging to the group and use the merged attackable elements as an attackable element of the representative host.

7 . A virtual model generation apparatus comprising:

a memory storing instructions; and

a processor configured to execute the instructions to:

group a plurality of hosts included in a system to be analyzed into a plurality of groups each including one or more hosts using countermeasure-related information including information related to countermeasures planned to address risks included in the system;

generate one or more virtual analysis elements for each of the plurality of groups; and

generate a virtual model used for risk analysis, the virtual model including the generated virtual analysis elements,

wherein the countermeasure-related information includes at least one of time information, management information, operation information, or functional performance information, and

wherein the time information including at least one of an operating time of the host, a frequency of countermeasures, and a time required for countermeasures, the management information including at least one of information about a vendor, a management department, and a location where the host is installed, the operation information including at least one of information related to whether or not administrator privileges can be disabled and whether or not USB memory devices can be used, the functional performance information including information about an available capacity of storage devices, a memory capacity, a central processing unit (CPU) performance, a maintenance support expiration date for an OS or software, and an availability of rack space.

8 . The virtual model generation apparatus according to claim 7 , wherein the processor is configured to execute the instructions to group the hosts into the plurality of groups further using configuration information about the system.

9 . A risk analysis method comprising:

grouping a plurality of hosts included in a system to be analyzed into a plurality of groups each including one or more hosts using countermeasure-related information including information related to countermeasures planned to address risks included in the system;

generating one or more virtual analysis elements for each of the plurality of groups;

generating a virtual model used for risk analysis, the virtual model including the generated virtual analysis elements; and

analyzing the risks included in the system to be analyzed using the virtual model,

wherein the countermeasure-related information includes at least one of time information, management information, operation information, or functional performance information, and

wherein the time information includes at least one of an operating time of the host, a frequency of countermeasures, and a time required for countermeasures, the management information including at least one of information about a vendor, a management department, and a location where the host is installed, the operation information including at least one of information related to whether or not administrator privileges can be disabled and whether or not USB memory devices can be used, the functional performance information including information about an available capacity of storage devices, a memory capacity, a central processing unit (CPU) performance, a maintenance support expiration date for an OS or software, and an availability of rack space.

10 . A virtual model generation method comprising:

grouping a plurality of hosts included in a system to be analyzed into a plurality of groups each including one or more hosts using countermeasure-related information including information related to countermeasures planned to address risks included in the system;

generating one or more virtual analysis elements for each of the plurality of groups; and

generating a virtual model used for risk analysis, the virtual model including the generated virtual analysis elements,

wherein the countermeasure-related information includes at least one of time information, management information, operation information, or functional performance information, and

wherein the time information includes at least one of an operating time of the host, a frequency of countermeasures, and a time required for countermeasures, the management information including at least one of information about a vendor, a management department, and a location where the host is installed, the operation information including at least one of information related to whether or not administrator privileges can be disabled and whether or not USB memory devices can be used, the functional performance information including information about an available capacity of storage devices, a memory capacity, a central processing unit (CPU) performance, a maintenance support expiration date for an OS or software, and an availability of rack space.

11 . A non-transitory computer readable medium storing a program for causing a computer to execute processing comprising:

grouping a plurality of hosts included in a system to be analyzed into a plurality of groups each including one or more hosts using countermeasure-related information including information related to countermeasures planned to address risks included in the system;

generating one or more virtual analysis elements for each of the plurality of groups;

generating a virtual model used for risk analysis, the virtual model including the generated virtual analysis elements; and

analyzing the risks included in the system to be analyzed using the virtual model,

wherein the countermeasure-related information includes at least one of time information, management information, operation information, or functional performance information, and

wherein the time information includes at least one of an operating time of the host, a frequency of countermeasures, and a time required for countermeasures, the management information including at least one of information about a vendor, a management department, and a location where the host is installed, the operation information including at least one of information related to whether or not administrator privileges can be disabled and whether or not USB memory devices can be used, the functional performance information including information about an available capacity of storage devices, a memory capacity, a central processing unit (CPU) performance, a maintenance support expiration date for an OS or software, and an availability of rack space.

12 . A non-transitory computer readable medium storing a program for causing a computer to execute processing comprising:

grouping a plurality of hosts included in a system to be analyzed into a plurality of groups each including one or more hosts using countermeasure-related information including information related to countermeasures planned to address risks included in the system;

generating one or more virtual analysis elements for each of the plurality of groups; and

generating a virtual model used for risk analysis, the virtual model including the generated virtual analysis elements,

wherein the countermeasure-related information includes at least one of time information, management information, operation information, or functional performance information, and

wherein the time information includes at least one of an operating time of the host, a frequency of countermeasures, and a time required for countermeasures, the management information including at least one of information about a vendor, a management department, and a location where the host is installed, the operation information including at least one of information related to whether or not administrator privileges can be disabled and whether or not USB memory devices can be used, the functional performance information including information about an available capacity of storage devices, a memory capacity, a central processing unit (CPU) performance, a maintenance support expiration date for an OS or software, and an availability of rack space.