IP Library Granted Patent US 12,013,948
Granted Patent B2
US 12,013,948 · App. 17/535,951 · Granted Jun 18, 2024

Processing device and processing method

Inventor: Yasuhiro Suzuki (Tokyo, JP)
Assignee: Assured, Inc.
G06F21/577G06F21/54G06F21/554G06F21/566
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,013,948
App. No.
17/535,951
Granted
Jun 18, 2024
Kind
B2
Abstract

A processing device that determines a vulnerability of open software in a system, the processing device comprising: a control unit that outputs priority of the vulnerability based on at least one of first information indicating whether the open software is externally accessible, and second information indicating whether an attack code for the vulnerability of the open software is in circulation, wherein the control unit assigns higher priority to the vulnerability of the open software externally accessible compared to the vulnerability of the open software externally inaccessible, or assigns higher priority to the vulnerability where the attack code is in circulation compared to the vulnerability where the attack code is not in circulation.

Claims (22)

1. A processing device comprising:

a memory; and

a processor that, when executing a program stored in the memory;

outputs a user interface to enable a user to input whether the open software is externally accessible when detecting that a system including open software has a vulnerability; and

determines, in response to the input, a priority of the vulnerability of the open software based on first information indicating whether the open software is externally accessible, and second information indicating whether an attack code for the vulnerability of the open software is in circulation, wherein

the processor assigns higher priority to the vulnerability of the open software externally accessible compared to the vulnerability of the open software externally inaccessible, and assigns higher priority to the vulnerability of the open software where the attack code is in circulation compared to the vulnerability of the open software where the attack code is not in circulation.

2. The processing device according to claim 1 , wherein

the processor outputs the priority of the vulnerability of the open software based on both the first information and the second information.

3. The processing device according to claim 2 , wherein

the processor outputs the priority of the vulnerability of the open software based on third information indicating a type of the vulnerability of the open software, in addition to the first information and the second information.

4. The processing device according to claim 3 , wherein

the processor outputs the priority of the vulnerability of the open software based on fourth information indicating a level of the vulnerability of the open software set by a third-party organization, in addition to the first information, the second information, and the third information.

5. The processing device according to claim 4 , wherein

the processor identifies that the vulnerability of the open software having the level meets a level condition based on the fourth information, and

the processor outputs the priority of the vulnerability of the open software for an identified vulnerability, based on the first information, the second information, and the third information.

6. The processing device according to claim 3 , wherein

the processor identifies that the vulnerability of the open software has the attack code in circulation based on the second information, or identifies that the vulnerability of the open software has the type that meets a type condition based on the third information, and

the processor outputs the priority of the vulnerability of the open software for an identified vulnerability, based on the first information.

7. A processing method for determining a vulnerability of open software in a system, the method comprising the steps of:

outputting a user interface used to input whether the open software is externally accessible per system including the open software, and receiving first information indicating whether the open software is externally accessible from the user interface;

in response to the input, determining priority of the vulnerability of the open software based on the first information and based on second information indicating whether an attack code for the vulnerability of the open software is in circulation; and

assigning higher priority to the vulnerability of the open software externally accessible compared to the vulnerability of the open software externally inaccessible, and assigns higher priority to the vulnerability of the open software where the attack code is in circulation compared to the vulnerability of the open software where the attack code is not in circulation.

Assignments (2)
CHANGE OF NAME Recorded Sep 9, 2022
From: VISIONAL INCUBATION, INC.
To: ASSURED, INC.
Reel/Frame 061039/0704 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 30, 2021
From: SUZUKI, YASUHIRO
To: VISIONAL INCUBATION, INC.
Reel/Frame 058243/0550 →
Priority Claims (1)
JP 2019-099506 · May 28, 2019 · national
Continuity (2)
Continuation PCTJP2020018232 · Apr 30, 2020
Related Publication 20220083670A1 · Mar 17, 2022