Risk evaluation device, risk evaluation method, and program product

US12554858B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12554858-B2
Application numberUS-202318173870-A
CountryUS
Kind codeB2
Filing dateFeb 24, 2023
Priority dateJul 6, 2022
Publication dateFeb 17, 2026
Grant dateFeb 17, 2026

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

According to one embodiment, a risk evaluation device includes a vulnerability information input unit, an individual countermeasure acquisition unit, a parameter acquisition unit, a determination unit, and a calculation unit. The vulnerability information input unit receives an input of vulnerability information to be subjected to risk evaluation. The individual countermeasure acquisition unit acquires at least one security countermeasure introduced into a system to be evaluated. The parameter acquisition unit acquires a candidate parameter value to be used for calculation of the risk of vulnerability for each security countermeasure based on the security countermeasure and the vulnerability information. The determination unit determines a parameter to be used for the calculation of the risk of vulnerability from the candidate parameter values. The calculation unit calculates a risk value indicating the risk of vulnerability by using the parameters determined by the determination unit.

First claim

Opening claim text (preview).

What is claimed is: 1 . A risk evaluation device, comprising: one or more hardware processors configured to function as: a vulnerability information input unit configured to receive an input of vulnerability information to be subjected to risk evaluation; an individual countermeasure acquisition unit configured to acquire at least one security countermeasure introduced into a system to be evaluated; a parameter acquisition unit configured to acquire a candidate parameter value to be used for calculation of a risk of vulnerability for each of security countermeasures based on the security countermeasure and the vulnerability information; a determination unit configured to determine a parameter to be used for the calculation of the risk of vulnerability from candidate parameter values; and a calculation unit configured to calculate a risk value indicating the risk of vulnerability by using the parameter determined by the determination unit. 2 . The risk evaluation device according to claim 1 , wherein the vulnerability information is common vulnerabilities and exposures (CVE). 3 . The risk evaluation device according to claim 1 , wherein the one or more hardware processors are configured to further function as: a target risk value input unit configured to receive an input of a target risk value and determine a risk value higher than the target risk value as a risk value to be output; and an output unit configured to output the risk value to be output. 4 . The risk evaluation device according to claim 1 , wherein the parameter acquisition unit acquires, for each security product introduced into the system to be evaluated, the c parameter value further based on the type of vulnerability when the type of vulnerability that is handleable by the security product can be acquired. 5 . The risk evaluation device according to claim 1 , wherein the one or more hardware processors are configured to further function as: an evaluation unit configured to specify an assumed attack source, evaluate whether the security countermeasure is effective based on whether there is a device that performs the security countermeasure on a path from the attack source to the system to be evaluated, and change the candidate parameter value acquired for each of the security countermeasures when the security countermeasure is not effective. 6 . The risk evaluation device according to claim 5 , wherein, when there is a device that performs the security countermeasure on the path, the evaluation unit further evaluates whether the security countermeasure is effective from a setting of the device and changes the candidate parameter value acquired for each of the security countermeasures when the security countermeasure is not effective. 7 . The risk evaluation device according to claim 1 , wherein the calculation unit further receives an input of a security requirement degree of the system to be evaluated and calculates the risk value based on the security requirement degree. 8 . The risk evaluation device according to claim 7 , wherein the one or more hardware processors are configured to further function as: an adjustment unit configured to adjust the security requirement degree from program information of a program operating in the system to be evaluated and a predetermined adjustment rule. 9 . The risk evaluation device according to claim 8 , wherein the program information includes an operation time of the program, and the adjustment rule is a rule for adjusting the security requirement degree according to the operation time. 10 . The risk evaluation device according to claim 8 , wherein the program information includes a usage status of a library linked to the program, and the adjustment rule is a rule for adjusting the security requirement degree according to the usage status. 11 . The risk evaluation device according to claim 8 , wherein the program information includes information indicating whether the program performs network communication, and the adjustment rule is a rule for adjusting the security requirement degree according to presence or absence of the network communication. 12 . The risk evaluation device according to claim 1 , wherein the one or more hardware processors are configured to further function as: a generation unit configured to generate a combination of unintroduced security countermeasures into the system to be evaluated, wherein the calculation unit further calculates a risk value when the combination of the unintroduced security countermeasures is introduced. 13 . The risk evaluation device according to claim 12 , wherein the one or more hardware processors are configured to further function as: a constraint consideration unit configured to give a priority to a combination of the unintroduced security countermeasures from a constraint condition when the combination of the unintroduced security countermeasures is introduced; and an output unit configured to output the combination of the unintroduced security countermeasures and the priority. 14 . A risk evaluation method implemented by a computer, the method comprising: receiving, by the risk evaluation device, an input of vulnerability information to be subjected to risk evaluation; acquiring, by the risk evaluation device, at least one security countermeasure introduced into a system to be evaluated; acquiring, by the risk evaluation device, a candidate parameter value to be used for calculation of a risk of vulnerability for each of security countermeasures based on the security countermeasure and the vulnerability information; determining, by the risk evaluation device, a parameter to be used for the calculation of the risk of vulnerability from candidate parameter values; and calculating, by the risk evaluation device, a risk value indicating the risk of vulnerability by using the determined parameter. 15 . A computer program product having a non-transitory computer readable medium including programmed instructions stored thereon, wherein the instructions, when executed by a computer, cause the computer to function as: a vulnerability information input unit configured to receive an input of vulnerability information to be subjected to risk evaluation; an individual countermeasure acquisition unit configured to acquire at least one security countermeasure introduced into a system to be evaluated; a parameter acquisition unit configured to acquire a candidate parameter value to be used for calculation of a risk of vulnerability for each of security countermeasures based on the security countermeasure and the vulnerability information; a determination unit configured to determine a parameter to be used for the calculation of the risk of vulnerability from candidate parameter values; and a calculation unit configured to calculate a risk value indicating the risk of vulnerability by using the parameter determined by the determination unit.

Assignees

Inventors

Classifications

  • Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities · CPC title

  • G06F21/577Primary

    Assessing vulnerabilities and evaluating computer system security · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12554858B2 cover?
According to one embodiment, a risk evaluation device includes a vulnerability information input unit, an individual countermeasure acquisition unit, a parameter acquisition unit, a determination unit, and a calculation unit. The vulnerability information input unit receives an input of vulnerability information to be subjected to risk evaluation. The individual countermeasure acquisition unit …
Who is the assignee on this patent?
Toshiba Kk
What technology area does this patent fall under?
Primary CPC classification G06F21/577. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Feb 17 2026 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 11 related publications on this page (citations in our corpus or others sharing the same primary CPC).