-
公开(公告)号:US20230018096A1
公开(公告)日:2023-01-19
申请号:US17786191
申请日:2019-12-25
Applicant: NEC Corporation
Inventor: Hirofumi UEDA , Ryo MIZUSHIMA , Tomohiko YAGYU
IPC: H04L9/40
Abstract: An analysis apparatus (10) includes an environment assessment unit (11) for assessing environmental metrics of a Common Vulnerability Scoring System (CVSS) as regards a vulnerability in an information system based on an attack path extracted from the information system to which the vulnerability to be analyzed is applied, a base assessment unit (12) for assessing base metrics of the CVSS as regards the vulnerability in the information system based on obtained CVSS base value information of the vulnerability and a predetermined base value countermeasure determination condition of the information system, and a determination unit (13) for determining whether or not the vulnerability in the information system needs to be addressed based on an assessment result of the environmental metrics and an assessment result of the base metrics.
-
公开(公告)号:US20170142747A1
公开(公告)日:2017-05-18
申请号:US15321877
申请日:2015-06-22
Applicant: NEC Corporation
Inventor: Norio YAMAGAKI , Shunichi KINOSHITA , Hirofumi UEDA , Norihito FUJITA
CPC classification number: H04W72/1242 , H04L12/4625 , H04W72/02 , H04W72/121 , H04W74/02 , H04W74/0816 , H04W84/12
Abstract: A data-storing-terminal counting unit counts the number of communication terminals in which each of a number of data are stored. Based on the results of the counts, a communication terminal count estimation unit estimates the number of communication terminals that will transmit data with the same timing. An adjustment reference value calculation unit computes an adjustment reference value for constraining the number of communication terminals estimated by the communication terminal count estimation unit to be less than or equal to a preset allowable number. On the basis of the adjustment reference value computed by the adjustment reference value calculation unit, a determination unit determines whether or not to permit transmission of data stored by a storing means. If the determination unit permits the transmission of said data, a data transmission unit transmits the data to a communication terminal in which said data is not stored.
-
公开(公告)号:US20160006802A1
公开(公告)日:2016-01-07
申请号:US14769524
申请日:2013-12-04
Applicant: NEC Corporation
Inventor: Bounpadith KANNHAVONG , Norihito FUJITA , Hirofumi UEDA
CPC classification number: H04L67/1076 , H04L67/1004 , H04L67/1059 , H04L67/16 , H04W4/06 , H04W84/12 , H04W84/18 , H04W84/20 , H04W88/04
Abstract: Individual communication terminals are connected to a communication network in which one communication terminal functions as a parent that has a relay function, the other communication terminals function as children, and transmitting and receiving of communication messages between child communication terminals are performed via the parent. Each communication terminal transmits a holding list that lists information about data that the own communication terminal holds, to other communication terminals. Further, each communication terminal temporarily stores holding lists received from other communication terminals. Each communication terminal, while it does not function as a parent, preferentially selects the holding list that does not match that of the own communication terminal and whose transmission source is the parent communication terminal, among the stored holding lists, and, while the own communication terminal functions as a parent, selects any holding list that does not match that of the own communication terminal. Each communication terminal transmits and receives communication messages with another communication terminal that is a transmission source of the selected holding list so that data sharing is performed.
Abstract translation: 单个通信终端连接到通信网络,其中一个通信终端用作具有中继功能的父母,其他通信终端用作儿童,并且通过父母来执行子通信终端之间的通信消息的发送和接收。 各个通信终端向其他通信终端发送列出有关自身通信终端所保持的关于数据的信息的保持列表。 此外,每个通信终端临时存储从其他通信终端接收的保持列表。 每个通信终端虽然不作为父级,但是在存储的保持列表中优先选择与自身的通信终端的不相符的保持列表,其发送源是父通信终端,并且在自己的通信 终端功能作为父级,选择与自己的通信终端不匹配的任何保持列表。 每个通信终端与作为所选保持列表的发送源的另一个通信终端发送和接收通信消息,从而执行数据共享。
-
公开(公告)号:US20240283792A1
公开(公告)日:2024-08-22
申请号:US18025162
申请日:2022-03-23
Applicant: NEC Corporation
Inventor: Shohei MITANI , Hirofumi UEDA , Nakul GHATE
IPC: H04L9/40
CPC classification number: H04L63/10
Abstract: An analysis apparatus according to an example embodiment of the present disclosure includes at least one memory configured to store instructions and at least one processor configured to execute the instructions to: acquire at least a data set in which a plurality of combinations of a first pattern of one or more elements indicating attributes of access and an action of access control corresponding to the first pattern are defined, and a second pattern of one or more elements indicating attributes of access that change over time; evaluate an execution cost when an action corresponding to the second pattern is changed over time by using at least transition information indicating a state transition in the one or more elements indicating attributes of access, and the second pattern; and determine the action corresponding to the second pattern by using at least a result of the evaluation and the data set.
-
公开(公告)号:US20220311786A1
公开(公告)日:2022-09-29
申请号:US17641506
申请日:2019-09-27
Applicant: NEC Corporation
Inventor: Hirofumi UEDA , Yoshinobu OHTA , Tomohiko YAGYU , Norio YAMAGAKI
IPC: H04L9/40
Abstract: Provided is an analysis system that can analyze the degree of impact of vulnerability on individual systems. An analysis unit 6 generates an attack pattern that includes an attack condition, an attack result, an attack means that is vulnerability that is used by an attack, and a segment where the attack can occur in a system to be diagnosed. A calculation unit 12 calculates an evaluation value, for each vulnerability, which indicates degree of impact of the vulnerability on the system to be diagnosed. Specifically, the calculation unit 12 calculates the evaluation value, for each vulnerability, based on the number of the attack patterns that include the vulnerability focused on as the attack means and the number of the segments indicated by each attack pattern that includes the vulnerability focused on as the attack means.
-
公开(公告)号:US20220147659A1
公开(公告)日:2022-05-12
申请号:US17430069
申请日:2019-02-14
Applicant: NEC corporation
Inventor: Taniya SINGH , Masafumi WATANABE , Hirofumi UEDA
Abstract: The present disclosure provides a security assessment apparatus, a method, and a program capable of making an assessment of a security risk simply and appropriately. The security assessment apparatus according to the present disclosure is a security assessment apparatus of a facility to be controlled using a controller, including: an identification unit (15) configured to identify a compromised component which puts the facility into an unsafe situation based on data regarding a plurality of components provided in the facility and control program code of the controller, thereby generating a list of the compromised component; and a compromised behavior generating unit (16) configured to generate a compromised behavior of a selected component selected from the list of the compromised component.
-
公开(公告)号:US20170094582A1
公开(公告)日:2017-03-30
申请号:US15126776
申请日:2014-12-17
Applicant: NEC Corporation
Inventor: Hirofumi UEDA , Norihito FUJITA , Norio YAMAGAKI , Shunichi KINOSHITA
IPC: H04W40/24 , H04L12/935
CPC classification number: H04W40/24 , H04L12/6418 , H04L49/3009 , H04W84/18
Abstract: A communication terminal in an ad hoc network has a wireless communication part, a lower layer protocol part operating on a lower layer of the network, and an upper layer protocol part operating on an upper layer of the network. The lower layer protocol part has a routing table holding route information including a destination IP address and a next hop IP address associated with each other. The upper layer protocol part has: an information sharing management part transmitting and receiving a message including an IP address of the local communication terminal to and from a neighbor communication terminal through the wireless communication part by broadcast communication; and a route information registration part registering, into the routing table, the route information including the IP address included in the message received by broadcast communication as the destination IP address and as the next hop IP address.
-
公开(公告)号:US20240396925A1
公开(公告)日:2024-11-28
申请号:US18694006
申请日:2021-11-08
Applicant: NEC Corporation
Inventor: Hirofumi UEDA , Kazuaki Nakajima
IPC: H04L9/40
Abstract: A setting unit (11) sets a path or a procedure for a cyber attack that is obtained through analysis of a risk to a communication system. A collection unit (12) collects safety information that is associated with safety in terms of information security regarding the constituent apparatuses of a communication system. An evaluation unit (13) evaluates the magnitude of a security risk present in the communication system, in accordance with the path or procedure for the cyber attack, on the basis of the security information, the security risk to a constituent apparatus related to the path or procedure for the cyber attack being evaluated to be lower when inspection for information security has been carried out on the constituent apparatus related to the path or procedure for the cyber attack than when inspection for information security is not carried out.
-
公开(公告)号:US20240297903A1
公开(公告)日:2024-09-05
申请号:US18582972
申请日:2024-02-21
Applicant: NEC Corporation
Inventor: Nakul GHATE , Shohei MITANI , Hirofumi UEDA
IPC: H04L9/40
CPC classification number: H04L63/20 , H04L63/101 , H04L63/1433
Abstract: An access control system includes workload distribution control function that decides an access control granularity by analyzing dynamic risk factors in network system; and policy selection function that selects an access control policy corresponding to the access control granularity, from a core policy and distributes the selected access control policy toward filtering PEP (Policy Enforcement Point) controller and fine-grained PEP (Policy Enforcement Point) controller.
-
10.
公开(公告)号:US20230024824A1
公开(公告)日:2023-01-26
申请号:US17785487
申请日:2019-12-25
Applicant: NEC Corporation
Inventor: Hirofumi UEDA , Ryo Mizushima , Tomohiko Yagyu
IPC: G06F21/57
Abstract: An analysis apparatus (10) includes: a setting unit (11) configured to set virtual vulnerabilities in a plurality of nodes configuring an information system to be analyzed; an extraction unit (12) configured to extract an attack route of the information system based on the virtual vulnerabilities set by the setting unit (11); and a discrimination unit (13) configured to discriminate vulnerabilities to be monitored based on the virtual vulnerabilities in the extracted attack route extracted by the extraction unit (12).
-
-
-
-
-
-
-
-
-