Security determination device, secure system design device, security determination method, and non-transitory storage medium
A security determination device comprehensively generates an attack path, which is a chained route of a threat showing execution steps of an attack to be prevented from being established; determines the validity of the attack path; and determines whether a system configuration is secure or insecure, depending on the validity of the attack path.
1 . A security determination device comprising:
at least one memory configured to store instructions; and
at least one processor configured to execute the instructions to:
comprehensively generate an attack path, which is a chained route of a threat showing execution steps of an attack to be prevented from being established;
determine the validity of the attack path; and
determine whether a system configuration is secure or insecure, depending on the validity of the attack path, wherein
a validity of the threat and the validity of the attack path are expressed as continuous values, and
a product of the validities of threats making up the attack path is regarded as the validity of the attack path.
2 . The security determination device according to claim 1 , wherein
the validity of the threat is expressed as a discrete value; and the at least one processor is further configured to execute the instructions to determine the attack path as being valid if the values indicating the validity of the threats making up the attack path are all valid.
3 . The security determination device according to claim 1 , wherein the at least one processor is further configured to execute the instructions to:
express the validity of the attack path in a continuous value, and regard a sum of the validities of threats making up the attack path as the validity of the attack path.
4 . The security determination device according to claim 1 ,
wherein the at least one processor is further configured to execute the instructions to, based on an element of a countermeasure in a system configuration and an implementation status of the countermeasure in the system configuration, remove the threat, determine the validity of the threat based on a discrete value, or determine the validity of the threat based on a continuous value, and
wherein the at least one processor is configured to execute the instructions to determine the validity of the attack path, based on the validities of the threats making up the attack path.
5 . A secure system design device comprising:
the security determination device according to claim 1 ,
wherein the at least one processor is further configured to execute the instructions to:
accept a request to a system; and
concretize the threat based on the request,
wherein the at least one processor is configured to execute the instructions to:
comprehensively generate the attack path based on the threat that is concretized.
6 . A security determination method comprising:
comprehensively generating an attack path, which is a chained route of a threat showing execution steps of an attack to be prevented from being established;
determining the validity of the attack path; and
determining whether a system configuration is secure or insecure, depending on the validity of the attack path, wherein
a validity of the threat and the validity of the attack path are expressed as continuous values, and
a product of the validities of threats making up the attack path is regarded as the validity of the attack path.
7 . A non-transitory storage medium that stores a program that causes a computer to execute processes, the processes comprising:
comprehensively generating an attack path, which is a chained route of a threat showing execution steps of an attack to be prevented from being established;
determining the validity of the attack path; and
determining whether a system configuration is secure or insecure, depending on the validity of the attack path, wherein
a validity of the threat and the validity of the attack path are expressed as continuous values, and
a product of the validities of threats making up the attack path is regarded as the validity of the attack path.