发明名称 VULNERABILITY COUNTERMEASURE DEVICE AND VULNERABILITY COUNTERMEASURE METHOD
摘要 A vulnerability countermeasure device stores configuration information associating multiple computers connected via a network and software possessed by each computer, vulnerability information associating the software with information related to the vulnerability of the software, and countermeasure policy information associating the software with a countermeasure policy to be executed if there is a vulnerability in the software; calculates the computer that data will reach based on information related to a route of the data included in the data received from a used terminal; acquires software existing in the computer based on the calculated computer and configuration information; assesses whether or not there is a vulnerability in the acquired software based on the acquired software and the vulnerability information; and is provided with countermeasure unit for executing a countermeasure to a vulnerability in accordance with a countermeasure policy with respect to the software assessed to have the vulnerability.
申请公布号 US2014373160(A1) 申请公布日期 2014.12.18
申请号 US201114237152 申请日期 2011.09.08
申请人 Hitachi, Ltd. 发明人 Shigemoto Tomohiro;Nakakoji Hirofumi;Kito Tetsuro;Umeki Hisashi;Takemoto Satoshi;Kaji Tadashi;Kai Satoshi
分类号 G06F21/57 主分类号 G06F21/57
代理机构 代理人
主权项 1. A vulnerability countermeasure device for taking countermeasures against the vulnerability of a system configured of a plurality of computers connected via a network, the vulnerability countermeasure device comprising: a storage unit which stores configuration information associating each of the computers with a piece of software possessed thereby, vulnerability information associating the software with information related to the vulnerability of the software, and countermeasure policy information associating the software with a countermeasure policy to be executed if there is a vulnerability in the software; an assessment unit which receives data transmitted by a used terminal on the system, calculates the computer that the data will reach on the basis of information related to a route of the data included in the received data, acquires the software residing in the computer based on the calculated computer and on the configuration information, and assesses whether there is a vulnerability in the acquired software, and a countermeasure unit which, if the assessment unit assesses that there is a vulnerability in the software, executes countermeasures on the software assessed to be vulnerable against the vulnerability in accordance with the countermeasure policy stored in the countermeasure policy information.
地址 Tokyo JP