Risk analysis apparatus, virtual model generation apparatus, method, and computer readable medium
Grouping means groups a plurality of hosts included in a system to be analyzed into a plurality of groups each including one or more hosts. The grouping means uses measure-related information including information related to measures planned for the system to be analyzed to group the plurality of hosts into the plurality of groups. Virtual analysis element generation means generates a virtual analysis element for each of the plurality of groups. Virtual model generation means generates a virtual model used for risk analysis that includes the virtual analysis elements generated by the virtual analysis element generation means. Analysis means analyzes the risks included in the system to be analyzed using the virtual model generated by the virtual model generation means.
1 . A risk analysis apparatus comprising:
a memory storing instructions; and
a processor configured to execute the instructions to:
group a plurality of hosts included in a system to be analyzed into a plurality of groups each including one or more hosts using countermeasure-related information including information related to countermeasures planned to address risks included in the system;
generate one or more virtual analysis elements for each of the plurality of groups;
generate a virtual model used for risk analysis, the virtual model including the generated virtual analysis elements; and
analyze the risks included in the system to be analyzed using the virtual model,
wherein the countermeasure-related information includes at least one of time information, management information, operation information, or functional performance information, and
wherein the time information includes at least one of an operating time of the host, a frequency of countermeasures, and a time required for countermeasures, the management information including at least one of information about a vendor, a management department, and a location where the host is installed, the operation information including at least one of information related to whether or not administrator privileges can be disabled and whether or not USB memory devices can be used, the functional performance information including information about an available capacity of storage devices, a memory capacity, a central processing unit (CPU) performance, a maintenance support expiration date for an OS or software, and an availability of rack space.
2 . The risk analysis apparatus according to claim 1 ,
wherein the processor is configured to execute the instructions to group the plurality of hosts into the plurality of groups further using a grouping condition specifying, from among information included in the countermeasure-related information, information to be used for grouping and a value of the information.
3 . The risk analysis apparatus according to claim 1 , wherein the processor is configured to execute the instructions to group the hosts into the plurality of groups further using configuration information about the system.
4 . The risk analysis apparatus according to claim 3 , wherein the processor is configured to execute the instructions to group the hosts into the plurality of groups based on the configuration information in a first stage, and divide at least some of the plurality of groups into the plurality of groups using the countermeasure-related information in a second stage.
5 . The risk analysis apparatus according to claim 1 , wherein the processor is configured to execute the instructions to generate a representative host that is a virtual host representing the hosts belonging to the group as the virtual analysis element.
6 . The risk analysis apparatus according to claim 5 , wherein the processor is configured to execute the instructions to merge attackable elements of the host belonging to the group and use the merged attackable elements as an attackable element of the representative host.
7 . A virtual model generation apparatus comprising:
a memory storing instructions; and
a processor configured to execute the instructions to:
group a plurality of hosts included in a system to be analyzed into a plurality of groups each including one or more hosts using countermeasure-related information including information related to countermeasures planned to address risks included in the system;
generate one or more virtual analysis elements for each of the plurality of groups; and
generate a virtual model used for risk analysis, the virtual model including the generated virtual analysis elements,
wherein the countermeasure-related information includes at least one of time information, management information, operation information, or functional performance information, and
wherein the time information including at least one of an operating time of the host, a frequency of countermeasures, and a time required for countermeasures, the management information including at least one of information about a vendor, a management department, and a location where the host is installed, the operation information including at least one of information related to whether or not administrator privileges can be disabled and whether or not USB memory devices can be used, the functional performance information including information about an available capacity of storage devices, a memory capacity, a central processing unit (CPU) performance, a maintenance support expiration date for an OS or software, and an availability of rack space.
8 . The virtual model generation apparatus according to claim 7 , wherein the processor is configured to execute the instructions to group the hosts into the plurality of groups further using configuration information about the system.
9 . A risk analysis method comprising:
grouping a plurality of hosts included in a system to be analyzed into a plurality of groups each including one or more hosts using countermeasure-related information including information related to countermeasures planned to address risks included in the system;
generating one or more virtual analysis elements for each of the plurality of groups;
generating a virtual model used for risk analysis, the virtual model including the generated virtual analysis elements; and
analyzing the risks included in the system to be analyzed using the virtual model,
wherein the countermeasure-related information includes at least one of time information, management information, operation information, or functional performance information, and
wherein the time information includes at least one of an operating time of the host, a frequency of countermeasures, and a time required for countermeasures, the management information including at least one of information about a vendor, a management department, and a location where the host is installed, the operation information including at least one of information related to whether or not administrator privileges can be disabled and whether or not USB memory devices can be used, the functional performance information including information about an available capacity of storage devices, a memory capacity, a central processing unit (CPU) performance, a maintenance support expiration date for an OS or software, and an availability of rack space.
10 . A virtual model generation method comprising:
grouping a plurality of hosts included in a system to be analyzed into a plurality of groups each including one or more hosts using countermeasure-related information including information related to countermeasures planned to address risks included in the system;
generating one or more virtual analysis elements for each of the plurality of groups; and
generating a virtual model used for risk analysis, the virtual model including the generated virtual analysis elements,
wherein the countermeasure-related information includes at least one of time information, management information, operation information, or functional performance information, and
wherein the time information includes at least one of an operating time of the host, a frequency of countermeasures, and a time required for countermeasures, the management information including at least one of information about a vendor, a management department, and a location where the host is installed, the operation information including at least one of information related to whether or not administrator privileges can be disabled and whether or not USB memory devices can be used, the functional performance information including information about an available capacity of storage devices, a memory capacity, a central processing unit (CPU) performance, a maintenance support expiration date for an OS or software, and an availability of rack space.
11 . A non-transitory computer readable medium storing a program for causing a computer to execute processing comprising:
grouping a plurality of hosts included in a system to be analyzed into a plurality of groups each including one or more hosts using countermeasure-related information including information related to countermeasures planned to address risks included in the system;
generating one or more virtual analysis elements for each of the plurality of groups;
generating a virtual model used for risk analysis, the virtual model including the generated virtual analysis elements; and
analyzing the risks included in the system to be analyzed using the virtual model,
wherein the countermeasure-related information includes at least one of time information, management information, operation information, or functional performance information, and
wherein the time information includes at least one of an operating time of the host, a frequency of countermeasures, and a time required for countermeasures, the management information including at least one of information about a vendor, a management department, and a location where the host is installed, the operation information including at least one of information related to whether or not administrator privileges can be disabled and whether or not USB memory devices can be used, the functional performance information including information about an available capacity of storage devices, a memory capacity, a central processing unit (CPU) performance, a maintenance support expiration date for an OS or software, and an availability of rack space.
12 . A non-transitory computer readable medium storing a program for causing a computer to execute processing comprising:
grouping a plurality of hosts included in a system to be analyzed into a plurality of groups each including one or more hosts using countermeasure-related information including information related to countermeasures planned to address risks included in the system;
generating one or more virtual analysis elements for each of the plurality of groups; and
generating a virtual model used for risk analysis, the virtual model including the generated virtual analysis elements,
wherein the countermeasure-related information includes at least one of time information, management information, operation information, or functional performance information, and
wherein the time information includes at least one of an operating time of the host, a frequency of countermeasures, and a time required for countermeasures, the management information including at least one of information about a vendor, a management department, and a location where the host is installed, the operation information including at least one of information related to whether or not administrator privileges can be disabled and whether or not USB memory devices can be used, the functional performance information including information about an available capacity of storage devices, a memory capacity, a central processing unit (CPU) performance, a maintenance support expiration date for an OS or software, and an availability of rack space.