system
The system addresses the challenge of real-time anomaly detection in communication networks by preprocessing and analyzing communication records with a self-learning model, enhancing detection efficiency and reducing administrative burden through improved analysis and visualization.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- SOFTBANK GROUP CORP
- Filing Date
- 2024-12-10
- Publication Date
- 2026-06-22
AI Technical Summary
In modern high-speed information communication networks, detecting communication anomalies in real time and responding appropriately is difficult due to the complexity of communication logs and the inadequacy of existing security systems in handling unknown threats, leading to increased administrative burden and delayed responses.
A system that includes a data aggregation device for storing and preprocessing communication records, employing anomaly detection algorithms, and utilizing a self-learning function with a learning model to generate warnings and visualize communication records, thereby enhancing detection efficiency and reducing network management burden.
The system efficiently detects communication anomalies in real time, provides quick countermeasures against unknown threats, and reduces the administrative burden by improving analysis accuracy and visualization of network security status.
Smart Images

Figure 2026101327000001_ABST
Abstract
Description
Technical Field
[0001] The technology of the present disclosure relates to a system.
Background Art
[0002] Patent Document 1 discloses a method for controlling a persona chatbot, which is performed by at least one processor, and includes steps of receiving a user utterance, adding the user utterance to a prompt including an instruction sentence related to an explanation of a character of the chatbot, encoding the prompt, and inputting the encoded prompt into a language model to generate a chatbot utterance in response to the user utterance.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] In a modern high-speed information communication network environment, due to the enormity of communication logs and the complexity of their analysis, it is difficult to detect communication anomalies in real time and respond appropriately. In addition, existing security systems are often based on static rules and are insufficient in dealing with unknown threats and patterns. As a result, the burden on network administrators has increased, and a quick and appropriate response is required.
Means for Solving the Problems
[0005] This invention combines a data aggregation device that stores and preprocesses communication records with means for analyzing these communication records to detect anomalies. Furthermore, it includes means for generating and presenting warnings based on detected anomalies, and employs a self-learning function that improves the accuracy of analysis and detection using a learning model. As a result, it provides a system that efficiently detects communication anomalies in real time, enables countermeasures against unknown threats, and also has the function of visualizing communication records and warnings and generating reports, thereby reducing the burden of network management tasks.
[0006] A "data collection device" is a device that has the function of collecting and storing communication records from each device within a network.
[0007] "Communication records" refer to the history of data sent and received within a network, and are log data that are the subject of analysis.
[0008] "Preprocessing" is the process of formatting communication records for analysis, removing unnecessary information, and standardizing the data.
[0009] "Analysis" refers to data processing used to identify anomalies or unique patterns based on collected communication records.
[0010] "Anomaly" refers to the detection of suspicious activity or communication that deviates from normal communication patterns.
[0011] "Detection means" refers to means that have algorithms or functions for analyzing communication records and identifying abnormal patterns.
[0012] A "warning" is a notification generated based on detected anomalies, informing the user of potential threats.
[0013] "Means of presentation" refers to the means by which the generated warning is effectively communicated to the user.
[0014] The "learning model" refers to a statistical model that learns based on past data and has knowledge applicable to future analysis.
[0015] "Self-learning" is a process of continuously learning based on new data to improve the accuracy of the model.
[0016] "Visualization" is a process for presenting complex data and warnings in a form that is easy for users to understand.
[0017] A "report" is a document that summarizes communication records and the results of anomaly detection, providing information useful for evaluating the state and security of a network.
Brief Explanation of Drawings
[0018] [Figure 1] It is a conceptual diagram showing an example of the configuration of a data processing system according to the first embodiment. [Figure 2] It is a conceptual diagram showing an example of the main functions of a data processing device and a smart device according to the first embodiment. [Figure 3] It is a conceptual diagram showing an example of the configuration of a data processing system according to the second embodiment. [Figure 4] It is a conceptual diagram showing an example of the main functions of a data processing device and smart glasses according to the second embodiment. [Figure 5] It is a conceptual diagram showing an example of the configuration of a data processing system according to the third embodiment. [Figure 6] It is a conceptual diagram showing an example of the main functions of a data processing device and a headset-type terminal according to the third embodiment. [Figure 7] It is a conceptual diagram showing an example of the configuration of a data processing system according to the fourth embodiment. [Figure 8] It is a conceptual diagram showing an example of the main functions of a data processing device and a robot according to the fourth embodiment. [Figure 9] It shows an emotion map to which multiple emotions are mapped. [Figure 10] It shows an emotion map to which multiple emotions are mapped. [Figure 11] It is a sequence diagram showing the processing flow of the data processing system in Example 1. [Figure 12] It is a sequence diagram showing the processing flow of the data processing system in Application Example 1. [Figure 13] It is a sequence diagram showing the processing flow of the data processing system in Example 2 when the emotion engine is combined. [Figure 14] It is a sequence diagram showing the processing flow of the data processing system in Application Example 2 when the emotion engine is combined.
Mode for Carrying Out the Invention
[0019] Hereinafter, an example of an embodiment of a system according to the technology of the present disclosure will be described with reference to the accompanying drawings.
[0020] First, the terms used in the following description will be explained.
[0021] In the following embodiments, the numbered processor (hereinafter simply referred to as "processor") may be a single arithmetic unit or a combination of multiple arithmetic units. Also, the processor may be a single type of arithmetic unit or a combination of multiple types of arithmetic units. Examples of arithmetic units include a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), a GPGPU (General-Purpose computing on Graphics Processing Units), an APU (Accelerated Processing Unit), and the like.
[0022] In the following embodiments, the numbered RAM (Random Access Memory) is a memory in which information is temporarily stored and is used as a work memory by the processor.
[0023] In the following embodiments, the signed storage is one or more non-volatile storage devices that store various programs and various parameters. Examples of non-volatile storage devices include flash memory (SSD (Solid State Drive)), magnetic disks (e.g., hard disks), or magnetic tapes.
[0024] In the following embodiments, the signed communication interface (I / F) is an interface that includes a communication processor and an antenna, etc. The communication interface manages communication between multiple computers. Examples of communication standards applicable to the communication interface include wireless communication standards such as 5G (5th Generation Mobile Communication System), Wi-Fi (registered trademark), or Bluetooth (registered trademark).
[0025] In the following embodiments, "A and / or B" is synonymous with "at least one of A and B." That is, "A and / or B" means that it may be A alone, or B alone, or a combination of A and B. Furthermore, in this specification, the same concept as "A and / or B" applies when expressing three or more things linked by "and / or."
[0026] [First Embodiment]
[0027] Figure 1 shows an example of the configuration of the data processing system 10 according to the first embodiment.
[0028] As shown in Figure 1, the data processing system 10 includes a data processing device 12 and a smart device 14. An example of the data processing device 12 is a server.
[0029] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0030] The smart device 14 comprises a computer 36, a reception device 38, an output device 40, a camera 42, and a communication interface 44. The computer 36 comprises a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The reception device 38, output device 40, and camera 42 are also connected to the bus 52.
[0031] The reception device 38 is equipped with a touch panel 38A and a microphone 38B, etc., and receives user input. The touch panel 38A receives user input by detecting contact with an object (e.g., a pen or finger). The microphone 38B receives user input by detecting the user's voice. The control unit 46A transmits data indicating the user input received by the touch panel 38A and microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the data indicating the user input.
[0032] The output device 40 includes a display 40A and a speaker 40B, and presents data to the user 20 by outputting the data in a form perceptible to the user 20 (e.g., audio and / or text). The display 40A displays visible information such as text and images according to instructions from the processor 46. The speaker 40B outputs audio according to instructions from the processor 46. The camera 42 is a small digital camera equipped with an optical system such as a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor.
[0033] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various types of information between processor 46 and processor 28 via network 54.
[0034] Figure 2 shows an example of the main functions of the data processing device 12 and the smart device 14.
[0035] As shown in Figure 2, in the data processing device 12, a specific processing is performed by the processor 28. A specific processing program 56 is stored in the storage 32. The specific processing program 56 is an example of a "program" related to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 according to the specific processing program 56 executed on the RAM 30.
[0036] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[0037] In the smart device 14, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The reception output program 60 is used in conjunction with a specific processing program 56 by the data processing system 10. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.
[0038] Next, the specific processing performed by the specific processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the smart device 14 as the "terminal".
[0039] The system according to the present invention aims to efficiently detect and quickly address abnormal communications within a network. To achieve this, the server continuously collects communication records from each device on the network. This data is stored in a database and serves as the basis for analysis.
[0040] The server preprocesses the collected communication records, formatting them to be suitable as input for anomaly detection algorithms. During this process, unnecessary data and noise are removed, and the data is standardized. Next, the server analyzes this data using a machine learning model. This analysis process detects deviations from normal communication patterns and assigns a score to events considered anomalous.
[0041] When a device detects an anomaly, the AI generates a natural language alert for the user and notifies the device. Through this alert, the user can easily recognize potential cyber threats that require immediate attention. For example, an alert might appear on the device stating, "An attempt was made to access the device from a suspicious IP address at 10:00 AM."
[0042] Furthermore, this system features a function that improves analysis accuracy by allowing the server to self-learn using past incidents as learning material. This enables the system to quickly adapt to new threat patterns and reduce the false positive rate.
[0043] Furthermore, users can monitor the security status of the entire network in real time through a dashboard. The server regularly updates this data, making it easy for users to understand the network's security. Regularly generated reports include detailed summaries of past incidents and current threat levels, which are also useful for long-term analysis.
[0044] Thus, the system of the present invention integrates various means to achieve improved efficiency and accuracy in network security management.
[0045] The following describes the processing flow.
[0046] Step 1:
[0047] The server begins collecting communication logs in real time from all devices on the network. The server continuously receives this data and stores it in a secure database.
[0048] Step 2:
[0049] The server performs data cleansing on the collected communication records. Specifically, the server filters out noisy data and irrelevant information to create a shaped dataset.
[0050] Step 3:
[0051] The server inputs pre-processed data into an anomaly detection algorithm. The server uses a machine learning model to compare the current communication pattern with past normal patterns and scores the anomaly.
[0052] Step 4:
[0053] When an anomaly is detected, the device uses a generative AI to create a warning message in natural language. This warning message is sent to the user as a potential threat requiring immediate attention.
[0054] Step 5:
[0055] The user receives a warning displayed on their device and checks the situation. Based on the warning, the user contacts the network administrator as needed to ensure a prompt response.
[0056] Step 6:
[0057] The server saves detected anomalies and corresponding incidents, and inputs them into a self-learning model. This allows the server to train the model with new insights to improve the accuracy of future anomaly detection.
[0058] Step 7:
[0059] Users can view the network's security status in real time through a dashboard updated by the server. This information includes past incidents and current threat levels.
[0060] (Example 1)
[0061] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server," and the smart device 14 will be referred to as the "terminal."
[0062] Modern communication networks require the rapid detection and appropriate response to abnormal communication activity. However, conventional methods struggle to effectively analyze large amounts of data and identify and notify anomalies in real time, leading to false alarms and delayed responses. Furthermore, self-learning capabilities are necessary to adaptively improve these anomaly detection systems, but achieving this is not easy. Therefore, there is a need to develop a system that can detect and respond to anomalies quickly and accurately while maintaining a high level of network security.
[0063] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.
[0064] In this invention, the server includes means for storing and pre-processing data records acquired from an information collection device, analysis means for analyzing the data records to detect anomalies, and means for generating alarms based on the detected anomalies and notifying users. This makes it possible to effectively detect abnormal communication activity within the network and notify users quickly in a way that allows them to take action.
[0065] An "information gathering device" is a device used to acquire data from a communication network and has the role of storing data records.
[0066] "Data recording" refers to a recording format that includes various types of information about communication activities on a network, and serves as the basis for analysis and anomaly detection.
[0067] "Preprocessing" is the process of removing unnecessary elements from acquired data records and formatting them into a state suitable for analysis.
[0068] "Analysis means" refers to technical methods and processes for detecting anomalies based on pre-processed data records, and includes anomaly detection algorithms.
[0069] An "anomaly" refers to an event that deviates from normal communication patterns and may have an impact on security.
[0070] An "alert" is a notification message generated based on a detected anomaly, intended to alert the user.
[0071] "Self-learning" is the process of improving the accuracy of a system's analysis and detection by continuously improving machine learning algorithms.
[0072] "Visualization" refers to a means of displaying data records and alarms in a format that is easy for users to understand.
[0073] A "report" is a document that includes visualized information and summarizes past events and the current situation.
[0074] "Real-time monitoring" is a monitoring method that allows for immediate understanding of the network's security status and enables rapid response.
[0075] A "machine learning algorithm" is a computational method that allows computers to learn from past data and make predictions based on unknown data.
[0076] "Automated artificial intelligence" refers to machine learning technology that has the ability to solve problems independently with minimal human intervention.
[0077] This invention is a system for improving network security and consists of several key elements. First, a server collects data. The server uses hardware such as packet capture tools to collect communication records from each device in the network. This communication data is stored in a relational database system for efficient management.
[0078] The collected communication records are preprocessed by the server. This preprocessing filters out unnecessary data and noise, and standardizes the data. This preprocessing is performed using TENSORFLOW® or PyTorch, prior to machine learning analysis.
[0079] Next, the server analyzes the data using machine learning algorithms. To detect deviations from normal communication patterns, the server performs predictive analysis using existing models. If an anomaly is detected, the generative AI model generates an alert in natural language.
[0080] The generated alerts are sent to the terminal. The terminal displays these alerts to the user, prompting a quick response. This alert system provides users with important information to understand the current state of the system and take necessary actions.
[0081] This system features self-learning capabilities, with the server continuously updating its machine learning model using past incident data. This improves the accuracy of anomaly detection and enables rapid responses to new threats.
[0082] As a concrete example, if a new suspicious access attempt occurs on a corporate network at 10:00 AM, the AI will generate an alert stating, "An access attempt was made from a suspicious IP address at 10:00 AM," and notify the terminal. Based on this information, the user can immediately take network security measures.
[0083] Furthermore, users can monitor the security status in real time through a dashboard. The server periodically updates the dashboard, providing users with the latest threat intelligence and summaries of past incidents. This allows users to perform analyses to maintain network security over the long term.
[0084] An example of a prompt message could be, "Detect suspicious communication activity on the internal network and generate a report." By inputting this prompt message into the AI generation model, the necessary data is accurately organized, and appropriate alerts and reports are created.
[0085] The flow of the specific processing in Example 1 will be explained using Figure 11.
[0086] Step 1:
[0087] The server collects communication logs from each device on the network. It takes network traffic data as input using a packet capture tool and obtains raw communication log data as output. Specifically, the server monitors a particular network port and records metadata such as source IP, destination IP, and data volume.
[0088] Step 2:
[0089] The server stores the collected communication records in a database. It takes the communication records obtained in step 1 as input and outputs them in a format that allows for organized and efficient management. Specifically, the server uses database software to index the data, making it readily accessible.
[0090] Step 3:
[0091] The server preprocesses the stored communication records. It takes records from the database as input and obtains standardized data suitable for analysis as output. Specifically, the server removes unnecessary noise and unifies all data entries into a standard format.
[0092] Step 4:
[0093] The server analyzes preprocessed data using a machine learning model. It receives standardized data from step 3 as input and generates anomaly detection results as output. The server uses libraries such as TensorFlow and PyTorch to compare the data with normal communication patterns and identify events that have been marked as anomalies.
[0094] Step 5:
[0095] The generating AI creates an alert when an anomaly is detected. It uses the anomaly detection results from step 4 as input and generates an alert message in natural language as output. Specifically, the generating AI understands the nature of the anomaly and constructs a specific message such as, "An attempt was made to access the system from a suspicious IP address."
[0096] Step 6:
[0097] The device notifies the user of the generated alert. It receives the alert message generated in step 5 as input and outputs it directly to the user. Specifically, the device sends an alert via a pop-up notification or email so that the user can quickly understand the situation.
[0098] Step 7:
[0099] The server updates and self-learns machine learning models using historical incident data. It utilizes previously collected incident data as input to train and output new models. Specifically, the server updates the dataset to the latest state through periodic batch processing, improving the model's predictive accuracy.
[0100] Step 8:
[0101] Users monitor the network's security status in real time through a dashboard. They receive the latest security information sent from the server as input and obtain visualized information as output. Specifically, users can view past incident history and real-time threat levels on the dashboard and develop necessary countermeasures.
[0102] (Application Example 1)
[0103] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server," and the smart device 14 will be referred to as the "terminal."
[0104] In today's network environments, there is a need to quickly detect abnormal communications and notify users of appropriate warnings. However, many current systems have low accuracy in anomaly detection, leading to delayed warnings and false alarms. Furthermore, they lack sufficient mechanisms to learn from past incidents and improve analysis accuracy in order to reduce the burden on administrators. To solve this problem, a system is needed that can improve the accuracy of anomaly detection and provide rapid user notifications.
[0105] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.
[0106] In this invention, the server includes means for storing and performing initial processing of communication information obtained from a data collection device, detection means for analyzing the communication information to detect anomalies, and means for generating warnings based on the detected anomalies and notifying mobile terminals. This makes it possible to quickly and accurately detect abnormal communications and immediately notify users. Furthermore, by visualizing the communication information and warnings and creating reports, administrators can easily grasp the security of the network and utilize this information for long-term security analysis.
[0107] A "data collection device" is a device used to acquire communication information from various devices within a network.
[0108] "Communication information" refers to the records and data of all communications that take place within a network.
[0109] "Initial processing" refers to pre-processing to format the collected communication information into a form suitable for analysis.
[0110] "Detection means" refers to methods for analyzing collected communication information and identifying anomalies.
[0111] A "warning" is information or a message used to notify the user of a detected anomaly.
[0112] "Mobile devices" refer to portable communication devices such as smartphones and tablets.
[0113] A "report" is a document that visualizes the security of a network, created based on communication information and anomaly detection results.
[0114] "Visualization" refers to the process of displaying data and information in an easy-to-understand manner using graphs and diagrams.
[0115] "Self-learning methods" refer to techniques that utilize machine learning models to continuously improve analytical accuracy based on past data.
[0116] The system implementing this invention mainly consists of a server and a mobile terminal. The server collects communication information from each device in the network through a data collection device. This communication information is stored in a database and becomes the subject of analysis. Subsequently, the server performs initial processing such as standardization and noise reduction, and uses machine learning models to perform analysis to identify deviations from normal communication patterns.
[0117] If an anomaly is detected, the server uses a generative AI to create a warning in natural language. This warning is then pushed to the mobile device, allowing the user to take immediate action. Specifically, an alert such as "A new device has connected to the network. Please check for potential unauthorized access" is sent.
[0118] The server also handles report generation, which includes anomaly detection results and a visual representation of the overall communication status. Users can use this to periodically assess network security and help develop long-term security strategies.
[0119] To implement this system, the server program will use Python and machine learning libraries such as Scikit-learn and TensorFlow, while the mobile device application will be developed using React Native. Specific processing steps include data collection, preprocessing, policy-based anomaly detection, natural language generation, and user notification. An example of a prompt message might be, "A new anomalous communication has been detected on the network. What action should be taken?"
[0120] The flow of a specific process in Application Example 1 will be explained using Figure 12.
[0121] Step 1:
[0122] The server acquires communication information from each device in the network using data collection devices. The input at this stage is all data transmitted through the network. The server stores this data in a database, making it available as foundational data for subsequent processing. Specifically, it collects packet information and connection logs sent from each device.
[0123] Step 2:
[0124] The server performs initial processing to standardize the collected communication information and remove noise and unnecessary data. The input is the raw communication information obtained in the previous step, and the output is data in a clean format suitable for anomaly detection. This processing reduces data variability and creates a consistent dataset.
[0125] Step 3:
[0126] The server uses machine learning models to analyze the data after initial processing and identify deviations from normal communication patterns. The input is the initially processed communication data, and the output is the data points considered anomalous. Specifically, anomaly detection is performed using support vector machines or neural networks.
[0127] Step 4:
[0128] If an anomaly is detected, the server uses a generative AI to create a warning in natural language. In this step, the AI generates an appropriate warning message using the prompt "Abnormal communication has been detected. How will you respond?". The input is the detected anomaly data, and the output is a warning message in natural language.
[0129] Step 5:
[0130] The server notifies mobile devices of the generated warnings. The input is the warning message created by the generation AI, and the output is the notification displayed on the user's smartphone or tablet. The server uses a push notification system to quickly deliver the information to the user.
[0131] Step 6:
[0132] The server generates and visualizes reports based on communication information and anomaly detection results. Inputs are communication information and anomaly detection results, while outputs are visualized data and reports on a user-accessible dashboard. These reports include graphs and charts illustrating historical trends and network security.
[0133] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.
[0134] The system according to the present invention aims not only to detect anomalies in network communications in real time and respond appropriately, but also to optimize the interface while considering the user's emotional state. By incorporating an emotion engine, this system offers a novel approach to improving the user experience.
[0135] The server collects communication logs in real time from each device on the network. This data is preprocessed for analysis and sent to an anomaly detection algorithm. Any detected anomalies are generated as warning messages in natural language using generative artificial intelligence and notified to the user.
[0136] During this process, the device uses an emotion engine to analyze the user's current emotional state. The emotion engine evaluates the user's stress level and emotional tendencies based on their past response patterns and operation history. Based on this information, the device can dynamically change the content and display method of notifications. Specifically, if high stress levels are detected, the device will display a message in a calmer tone and add detailed support information.
[0137] For example, if the emotion engine determines that a user has received frequent alerts in the past few hours and is under stress, the next alert message sent will be in the form of, "A new threat has been detected, but we are already taking action. Please rest assured." In this way, the emotion engine is designed to make notifications more acceptable and reduce the user's psychological burden.
[0138] Furthermore, through self-learning mechanisms, the system can continuously learn from these emotional feedbacks, improving the accuracy of future anomaly detection and user responses. Users can monitor and manage the network's security status in real time through the dashboard and analyze areas for long-term improvement through regular reports.
[0139] In this way, the system of the present invention enhances the efficiency of security management and provides a user-friendly interface.
[0140] The following describes the processing flow.
[0141] Step 1:
[0142] The server collects communication logs from each device on the network and stores them in a database. This data collection is performed in real time, and the data is continuously updated.
[0143] Step 2:
[0144] The server preprocesses the collected data, removing noise and preparing it for anomaly detection algorithms. Preprocessing includes data standardization and filtering irrelevant information.
[0145] Step 3:
[0146] The server uses pre-processed data to run an anomaly detection algorithm. This algorithm analyzes communication patterns and identifies trends that deviate from the normal range.
[0147] Step 4:
[0148] If an anomaly is detected, the server uses generative artificial intelligence to generate a warning message in natural language. This message briefly explains the nature of the anomaly and its potential impact.
[0149] Step 5:
[0150] Before displaying a warning message to the user, the device uses an emotion engine to assess the user's emotional state. This assessment is based on the user's current actions and past responses.
[0151] Step 6:
[0152] Based on the evaluation results of the emotion engine, the device adjusts the content and tone of warning messages. For example, if the user is stressed, a message with a more polite and calm tone will be selected.
[0153] Step 7:
[0154] Users receive a tailored warning message on their device and review its contents. Based on the message, users can take appropriate action.
[0155] Step 8:
[0156] The server collects user reactions and emotional feedback, and uses its self-learning function to learn from this data and apply it to future anomaly detection. This process allows the system to improve its performance over time.
[0157] Step 9:
[0158] Users can monitor and manage the overall security status of the network and the history of past incidents in real time through the dashboard. Regular reports enable trend analysis and long-term security assessments.
[0159] (Example 2)
[0160] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server" and the smart device 14 as the "terminal".
[0161] In today's network environment, it is crucial to quickly detect anomalies in communication data and appropriately deliver warnings. However, conventional systems do not take into account the user's emotional state, and notifications can potentially cause stress to users. Furthermore, there is room for improvement in the accuracy of anomaly detection and the naturalness of warning generation. To solve this problem, a notification system optimized based on user emotions is necessary.
[0162] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.
[0163] In this invention, the server includes means for storing and pre-processing communication data acquired from an information processing device, means for analyzing the communication data to detect anomalies, means for analyzing user emotional information, and means for generating warnings based on anomalies in natural language using generative artificial intelligence and notifying the user. This enables anomaly notifications that take into account the user's emotional state, thereby reducing psychological burden while ensuring network security.
[0164] An "information processing device" is a digital device that has the function of storing and processing communication data.
[0165] "Communication data" refers to a collection of information transmitted over a network.
[0166] "Preprocessing" is the process of shaping data and extracting necessary information for analysis or detection.
[0167] "Anomaly detection" is the process of identifying and pinpointing deviations from standard communication patterns.
[0168] "User emotional information" refers to data about a user's mental state and emotional tendencies.
[0169] "Generative artificial intelligence" is an AI technology that has the ability to generate natural language based on a given prompt.
[0170] "Notification in natural language" is the process of transmitting information in a language that is easy for humans to understand.
[0171] "Visualization" is the process of representing data and information visually to make them easier to understand.
[0172] A "report" is a document that systematically summarizes the results of data analysis and the details of activities.
[0173] "Self-learning function" is a technology that allows a system to improve its own performance based on past data and experience.
[0174] The system in this invention efficiently monitors communication data within a network and detects anomalies to provide appropriate warnings to the user. The server first collects communication data in real time from the information processing device. In this process, network monitoring software is used to acquire and store a large number of data packets. The collected data is preprocessed using data processing libraries such as Pandas to prepare it for anomaly detection.
[0175] Next, the server leverages machine learning libraries such as Scikit-learn to apply anomaly detection algorithms. This allows it to identify anomalies that deviate from normal communication patterns. If an anomaly is detected, a generative artificial intelligence model, such as GPT, is used to generate a warning message in natural language based on the detected anomaly. This process includes a mechanism that automatically generates specific warning content based on the input of prompts.
[0176] The device further analyzes the user's emotional information using libraries such as Emotion Detection. Based on the user's past operation history and response patterns, it evaluates their emotional state and determines their stress level. Based on this data, the server optimizes the generated warnings to match the user's emotional state. For example, if it is determined that the user is stressed, a message in a calm tone will be presented, such as, "A new threat has been detected, but we are already taking measures to address it. Please rest assured."
[0177] An example of a prompt message might be, "Generate a reassuring warning message when the user is under stress." In this way, the system reduces the user's psychological burden while enhancing real-time network security.
[0178] The flow of the specific processing in Example 2 will be explained using Figure 13.
[0179] Step 1:
[0180] The server collects communication data in real time from the information processing device. It receives packet data from the communication network as input and outputs it in the form of data stored in a database. This operation requires the accurate collection of large amounts of data using a communication packet capture tool.
[0181] Step 2:
[0182] The server preprocesses the collected communication data. Using the raw data stored as input, it removes noise through data cleansing and extracts features necessary for anomaly detection. The output is a structured dataset, and data preprocessing is performed using the Pandas library.
[0183] Step 3:
[0184] The server performs anomaly detection using pre-processed data. The input is a formatted dataset that is analyzed by machine learning algorithms. The output is a list of detected anomaly events. Specifically, algorithms such as Scikit-learn's Isolation Forest are used to identify deviations from standard patterns.
[0185] Step 4:
[0186] The server generates warning messages based on anomalies using a generative AI model. It receives detected anomaly events as input and outputs natural language warning messages via prompts. A model like GPT is used to generate messages that correspond to the nature of the anomaly.
[0187] Step 5:
[0188] The device analyzes the user's emotional information. It receives the user's past operation history and real-time emotional data as input, and uses an Emotion Detection library to evaluate the emotional state. The output is evaluation data regarding stress levels and emotional tendencies, which is used to analyze the user's state.
[0189] Step 6:
[0190] The device optimizes notification content and method based on analyzed emotional information. The input is the previously generated emotional evaluation data, which is combined with the generated warning message to optimize and output notifications in a way that suits the user's psychological state. If the user is stressed, the system will display messages with calmer language.
[0191] (Application Example 2)
[0192] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as a "server" and the smart device 14 as a "terminal".
[0193] In today's network environment, ensuring the security of communications is extremely important. However, it is difficult not only to detect anomalies but also to transmit information appropriately while minimizing the impact on users. In particular, uniform notifications that do not take into account the user's emotional state can cause unnecessary stress. To solve this problem, there is a need for a system that provides customized notification methods that take into account the user's emotional state.
[0194] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means.
[0195] In this invention, the server includes means for storing and preprocessing communication records acquired from data acquisition means, means for detecting anomalies by analyzing the communication records, means for analyzing the user's emotional state, means for dynamically changing the content and display method of warnings based on the results of the emotion analysis means, means for self-learning to improve the accuracy of analysis and detection using a learning algorithm, and means for visualizing the communication records and warnings and generating a report. This makes it possible to detect anomalies and provide accurate and psychologically less burdensome notifications that take into consideration the user's emotions.
[0196] "Data acquisition means" refers to an element that has the function of collecting and storing communication records from devices on a network.
[0197] "Means for pre-processing" refers to an element equipped with processing functions that prepare the collected communication records for analysis.
[0198] An "anomaly detection means" is an element that analyzes communication records and has the function of detecting deviations from normal patterns.
[0199] "Means for generating and presenting warnings" refers to elements that create and display warning messages in natural language to the user based on detected anomalies.
[0200] An "emotion analysis tool" is an element that has the function of evaluating the user's emotional state and reflecting that information in the method of communication notifications.
[0201] A "dynamically changing mechanism" refers to an element that allows for the appropriate adjustment of the notification format and content based on the user's emotional state.
[0202] A "self-learning mechanism" is an element that has the function of continuously improving the accuracy of analysis and anomaly detection based on past data and user emotional feedback.
[0203] "Means for visualization and report generation" refers to elements that have the functionality to organize communication records and generated warnings as graphs and reports, and present them to users in an easy-to-understand manner.
[0204] This invention relates to a system that analyzes communication records collected over a network in real time to detect anomalies and provide notifications to users based on their emotions. The hardware used to implement this system includes a network-enabled server and user terminals (e.g., smartphones and smart glasses).
[0205] The server has data acquisition means to collect communication records from devices on the network. The collected data is preprocessed and then analyzed using anomaly detection means. If an anomaly is detected, the server uses a generative AI model to generate a warning message in natural language. In this case, the generative AI model is given an example prompt: "Consider the user's emotional state and express the security alert in a calm tone."
[0206] The device receives warnings sent from the server and analyzes the user's emotional state using emotion analysis tools. A dedicated emotion engine API is used for this emotion analysis. The content and display method of the warnings are dynamically adjusted according to the user's stress level, allowing the user to receive information with less psychological burden.
[0207] For example, if a user receives a warning about abnormal communication on their work smartphone, and the system determines that the user is experiencing high levels of stress, a calm message will be displayed stating, "A new anomaly has been detected, but we have already taken steps to resolve it, so please rest assured."
[0208] In this way, users can receive security-related information stress-free, and the system is designed to continuously improve the accuracy of anomaly detection and notification through self-learning mechanisms.
[0209] The flow of a specific process in Application Example 2 will be explained using Figure 14.
[0210] Step 1:
[0211] The server acquires communication logs from each device on the network. The input here is communication data from each device, and the output is the raw communication log collected by the server. This communication log is stored in a database and used in subsequent processing steps as needed.
[0212] Step 2:
[0213] The server performs preprocessing on the collected communication logs. The input is the raw communication log, and the output is the data after noise has been removed and normalized. Specifically, this involves filtering out unnecessary data and standardizing the format.
[0214] Step 3:
[0215] The server performs analysis to detect anomalies based on pre-processed communication records. The input is the pre-processed communication records, and the output is a list of detected anomalies. The server uses an anomaly detection algorithm to evaluate deviations in communication patterns and identify behavior that is different from normal.
[0216] Step 4:
[0217] When an anomaly is detected, the server uses a generative AI model to generate a warning message in natural language. The input here is information about the detected anomaly, and the output is the warning message to be presented to the user. Specifically, based on the anomaly data, the generative AI is instructed to generate a message using the prompt "Consider the user's emotional state and express the security alert in a calm tone."
[0218] Step 5:
[0219] The terminal receives a warning message sent from the server and analyzes the user's emotional state using emotion analysis tools. The input is the user's past response patterns and operation history, and the output is the evaluation result of the current emotional state. Specifically, it uses a dedicated emotion engine API to evaluate the stress level and passes that information to the next step.
[0220] Step 6:
[0221] The device uses the results of sentiment analysis to adjust how warning messages are displayed to the user. The input is the warning message and the results of the sentiment analysis, and the output is an optimized notification for the user. For example, if the device determines that the user is highly stressed, it will soften the tone of the message and add reassuring language.
[0222] The specific processing unit 290 transmits the result of the specific processing to the smart device 14. In the smart device 14, the control unit 46A causes the output device 40 to output the result of the specific processing. The microphone 38B acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.
[0223] Data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of data generation model 58 is ChatGPT (registered trademark) (Internet search).<URL: https: / / openai.com / blog / chatgpt> ), Gemini (registered trademark) (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[0224] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and the specific processing may also be performed by the smart device 14.
[0225] [Second Embodiment]
[0226] Figure 3 shows an example of the configuration of the data processing system 210 according to the second embodiment.
[0227] As shown in Figure 3, the data processing system 210 includes a data processing device 12 and smart glasses 214. An example of the data processing device 12 is a server.
[0228] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0229] The smart glasses 214 include a computer 36, a microphone 238, a speaker 240, a camera 42, and a communication interface 44. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, and camera 42 are also connected to the bus 52.
[0230] The microphone 238 receives voice signals from the user 20 and receives instructions from the user 20. The microphone 238 captures the voice signals from the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.
[0231] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the area around the user 20 (for example, an imaging range defined by a field of view equivalent to the width of a typical healthy person's field of vision).
[0232] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.
[0233] Figure 4 shows an example of the main functions of the data processing device 12 and the smart glasses 214. As shown in Figure 4, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.
[0234] The specific processing program 56 is an example of a "program" relating to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[0235] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[0236] In the smart glasses 214, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.
[0237] Next, the identification processing performed by the identification processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the smart glasses 214 will be referred to as the "terminal".
[0238] The system according to the present invention aims to efficiently detect and quickly address abnormal communications within a network. To achieve this, the server continuously collects communication records from each device on the network. This data is stored in a database and serves as the basis for analysis.
[0239] The server preprocesses the collected communication records, formatting them to be suitable as input for anomaly detection algorithms. During this process, unnecessary data and noise are removed, and the data is standardized. Next, the server analyzes this data using a machine learning model. This analysis process detects deviations from normal communication patterns and assigns a score to events considered anomalous.
[0240] When a device detects an anomaly, the AI generates a natural language alert for the user and notifies the device. Through this alert, the user can easily recognize potential cyber threats that require immediate attention. For example, an alert might appear on the device stating, "An attempt was made to access the device from a suspicious IP address at 10:00 AM."
[0241] Furthermore, this system features a function that improves analysis accuracy by allowing the server to self-learn using past incidents as learning material. This enables the system to quickly adapt to new threat patterns and reduce the false positive rate.
[0242] Furthermore, users can monitor the security status of the entire network in real time through a dashboard. The server regularly updates this data, making it easy for users to understand the network's security. Regularly generated reports include detailed summaries of past incidents and current threat levels, which are also useful for long-term analysis.
[0243] Thus, the system of the present invention integrates various means to achieve improved efficiency and accuracy in network security management.
[0244] The following describes the processing flow.
[0245] Step 1:
[0246] The server begins collecting communication logs in real time from all devices on the network. The server continuously receives this data and stores it in a secure database.
[0247] Step 2:
[0248] The server performs data cleansing on the collected communication records. Specifically, the server filters out noisy data and irrelevant information to create a shaped dataset.
[0249] Step 3:
[0250] The server inputs pre-processed data into an anomaly detection algorithm. The server uses a machine learning model to compare the current communication pattern with past normal patterns and scores the anomaly.
[0251] Step 4:
[0252] When an anomaly is detected, the device uses a generative AI to create a warning message in natural language. This warning message is sent to the user as a potential threat requiring immediate attention.
[0253] Step 5:
[0254] The user receives a warning displayed on their device and checks the situation. Based on the warning, the user contacts the network administrator as needed to ensure a prompt response.
[0255] Step 6:
[0256] The server saves detected anomalies and corresponding incidents, and inputs them into a self-learning model. This allows the server to train the model with new insights to improve the accuracy of future anomaly detection.
[0257] Step 7:
[0258] Users can view the network's security status in real time through a dashboard updated by the server. This information includes past incidents and current threat levels.
[0259] (Example 1)
[0260] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server," and the smart glasses 214 will be referred to as the "terminal."
[0261] Modern communication networks require the rapid detection and appropriate response to abnormal communication activity. However, conventional methods struggle to effectively analyze large amounts of data and identify and notify anomalies in real time, leading to false alarms and delayed responses. Furthermore, self-learning capabilities are necessary to adaptively improve these anomaly detection systems, but achieving this is not easy. Therefore, there is a need to develop a system that can detect and respond to anomalies quickly and accurately while maintaining a high level of network security.
[0262] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.
[0263] In this invention, the server includes means for storing and pre-processing data records acquired from an information collection device, analysis means for analyzing the data records to detect anomalies, and means for generating alarms based on the detected anomalies and notifying users. This makes it possible to effectively detect abnormal communication activity within the network and notify users quickly in a way that allows them to take action.
[0264] An "information gathering device" is a device used to acquire data from a communication network and has the role of storing data records.
[0265] "Data recording" refers to a recording format that includes various types of information about communication activities on a network, and serves as the basis for analysis and anomaly detection.
[0266] "Preprocessing" is the process of removing unnecessary elements from acquired data records and formatting them into a state suitable for analysis.
[0267] "Analysis means" refers to technical methods and processes for detecting anomalies based on pre-processed data records, and includes anomaly detection algorithms.
[0268] An "anomaly" refers to an event that deviates from normal communication patterns and may have an impact on security.
[0269] An "alert" is a notification message generated based on a detected anomaly, intended to alert the user.
[0270] "Self-learning" is the process of improving the accuracy of a system's analysis and detection by continuously improving machine learning algorithms.
[0271] "Visualization" refers to a means of displaying data records and alarms in a format that is easy for users to understand.
[0272] A "report" is a document that includes visualized information and summarizes past events and the current situation.
[0273] "Real-time monitoring" is a monitoring method that allows for immediate understanding of the network's security status and enables rapid response.
[0274] A "machine learning algorithm" is a computational method that allows computers to learn from past data and make predictions based on unknown data.
[0275] "Automated artificial intelligence" refers to machine learning technology that has the ability to solve problems independently with minimal human intervention.
[0276] This invention is a system for improving network security and consists of several key elements. First, a server collects data. The server uses hardware such as packet capture tools to collect communication records from each device in the network. This communication data is stored in a relational database system for efficient management.
[0277] The collected communication records are preprocessed by the server. This preprocessing filters out unnecessary data and noise, and standardizes the data. This preprocessing is performed using TensorFlow or PyTorch, prior to machine learning analysis.
[0278] Next, the server analyzes the data using machine learning algorithms. To detect deviations from normal communication patterns, the server performs predictive analysis using existing models. If an anomaly is detected, the generative AI model generates an alert in natural language.
[0279] The generated alerts are sent to the terminal. The terminal displays these alerts to the user, prompting a quick response. This alert system provides users with important information to understand the current state of the system and take necessary actions.
[0280] This system features self-learning capabilities, with the server continuously updating its machine learning model using past incident data. This improves the accuracy of anomaly detection and enables rapid responses to new threats.
[0281] As a concrete example, if a new suspicious access attempt occurs on a corporate network at 10:00 AM, the AI will generate an alert stating, "An access attempt was made from a suspicious IP address at 10:00 AM," and notify the terminal. Based on this information, the user can immediately take network security measures.
[0282] In addition, users can monitor the security status in real time through the dashboard. The server updates the dashboard regularly to provide users with the latest threat information and summaries of past incidents. This enables users to conduct analyses for maintaining network security over the long term.
[0283] As an example of a prompt sentence, "Detect and report suspicious communication activities in the company network" can be considered. By inputting this prompt sentence into the generative AI model, the necessary data is accurately organized, and appropriate alerts and reports are created.
[0284] The flow of the specific process in Example 1 will be described using FIG. 11.
[0285] Step 1:
[0286] The server collects communication records from each device in the network. As input, network traffic data is obtained using a packet capture tool, and raw communication record data is obtained as its output. As a specific operation, the server monitors specific network ports and records metadata such as source IP, destination IP, and data volume.
[0287] Step 2:
[0288] The server stores the collected communication records in a database. Using the communication records obtained in Step 1 as input, it outputs them in a form that can be organized and efficiently managed. Specifically, the server indexes the data using database software to make it quickly accessible.
[0289] Step 3:
[0290] The server preprocesses the stored communication records. It takes records from the database as input and obtains standardized data suitable for analysis as output. Specifically, the server removes unnecessary noise and unifies all data entries into a standard format.
[0291] Step 4:
[0292] The server analyzes preprocessed data using a machine learning model. It receives standardized data from step 3 as input and generates anomaly detection results as output. The server uses libraries such as TensorFlow and PyTorch to compare the data with normal communication patterns and identify events that have been marked as anomalies.
[0293] Step 5:
[0294] The generating AI creates an alert when an anomaly is detected. It uses the anomaly detection results from step 4 as input and generates an alert message in natural language as output. Specifically, the generating AI understands the nature of the anomaly and constructs a specific message such as, "An attempt was made to access the system from a suspicious IP address."
[0295] Step 6:
[0296] The device notifies the user of the generated alert. It receives the alert message generated in step 5 as input and outputs it directly to the user. Specifically, the device sends an alert via a pop-up notification or email so that the user can quickly understand the situation.
[0297] Step 7:
[0298] The server updates and self-learns machine learning models using historical incident data. It utilizes previously collected incident data as input to train and output new models. Specifically, the server updates the dataset to the latest state through periodic batch processing, improving the model's predictive accuracy.
[0299] Step 8:
[0300] Users monitor the network's security status in real time through a dashboard. They receive the latest security information sent from the server as input and obtain visualized information as output. Specifically, users can view past incident history and real-time threat levels on the dashboard and develop necessary countermeasures.
[0301] (Application Example 1)
[0302] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server," and the smart glasses 214 will be referred to as the "terminal."
[0303] In today's network environments, there is a need to quickly detect abnormal communications and notify users of appropriate warnings. However, many current systems have low accuracy in anomaly detection, leading to delayed warnings and false alarms. Furthermore, they lack sufficient mechanisms to learn from past incidents and improve analysis accuracy in order to reduce the burden on administrators. To solve this problem, a system is needed that can improve the accuracy of anomaly detection and provide rapid user notifications.
[0304] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.
[0305] In this invention, the server includes means for storing and performing initial processing of communication information obtained from a data collection device, detection means for analyzing the communication information to detect anomalies, and means for generating warnings based on the detected anomalies and notifying mobile terminals. This makes it possible to quickly and accurately detect abnormal communications and immediately notify users. Furthermore, by visualizing the communication information and warnings and creating reports, administrators can easily grasp the security of the network and utilize this information for long-term security analysis.
[0306] The "data collection device" is a device for acquiring communication information from each device within a network.
[0307] "Communication information" refers to the records and data of all communications conducted within a network.
[0308] "Initial processing" is preprocessing for shaping the collected communication information into a form suitable for analysis.
[0309] The "detection means" is a means for analyzing the collected communication information to identify abnormalities.
[0310] "Warning" is information or a message for notifying a user of the detected abnormality.
[0311] "Mobile terminal" refers to portable communication devices such as smartphones and tablets.
[0312] "Report" is a document visualizing the security of a network created based on communication information and the results of anomaly detection.
[0313] "Visualization" means presenting data and information clearly using graphs and diagrams.
[0314] "Self-learning means" is a means for continuously improving the analysis accuracy based on past data by utilizing a machine learning model.
[0315] The system for implementing this invention is mainly composed of a server and a mobile terminal. The server collects communication information from each device within the network through the data collection device. This communication information is stored in a database and becomes the object of analysis. Subsequently, the server performs initial processing such as standardization and noise removal, and conducts analysis for identifying deviations from normal communication patterns by utilizing a machine learning model.
[0316] If an anomaly is detected, the server uses a generative AI to create a warning in natural language. This warning is then pushed to the mobile device, allowing the user to take immediate action. Specifically, an alert such as "A new device has connected to the network. Please check for potential unauthorized access" is sent.
[0317] The server also handles report generation, which includes anomaly detection results and a visual representation of the overall communication status. Users can use this to periodically assess network security and help develop long-term security strategies.
[0318] To implement this system, the server program will use Python and machine learning libraries such as Scikit-learn and TensorFlow, while the mobile device application will be developed using React Native. Specific processing steps include data collection, preprocessing, policy-based anomaly detection, natural language generation, and user notification. An example of a prompt message might be, "A new anomalous communication has been detected on the network. What action should be taken?"
[0319] The flow of a specific process in Application Example 1 will be explained using Figure 12.
[0320] Step 1:
[0321] The server acquires communication information from each device in the network using data collection devices. The input at this stage is all data transmitted through the network. The server stores this data in a database, making it available as foundational data for subsequent processing. Specifically, it collects packet information and connection logs sent from each device.
[0322] Step 2:
[0323] The server performs initial processing to standardize the collected communication information and remove noise and unnecessary data. The input is the raw communication information obtained in the previous step, and the output is data in a clean format suitable for anomaly detection. This processing reduces data variability and creates a consistent dataset.
[0324] Step 3:
[0325] The server uses machine learning models to analyze the data after initial processing and identify deviations from normal communication patterns. The input is the initially processed communication data, and the output is the data points considered anomalous. Specifically, anomaly detection is performed using support vector machines or neural networks.
[0326] Step 4:
[0327] If an anomaly is detected, the server uses a generative AI to create a warning in natural language. In this step, the AI generates an appropriate warning message using the prompt "Abnormal communication has been detected. How will you respond?". The input is the detected anomaly data, and the output is a warning message in natural language.
[0328] Step 5:
[0329] The server notifies mobile devices of the generated warnings. The input is the warning message created by the generation AI, and the output is the notification displayed on the user's smartphone or tablet. The server uses a push notification system to quickly deliver the information to the user.
[0330] Step 6:
[0331] The server generates and visualizes reports based on communication information and anomaly detection results. Inputs are communication information and anomaly detection results, while outputs are visualized data and reports on a user-accessible dashboard. These reports include graphs and charts illustrating historical trends and network security.
[0332] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.
[0333] The system according to the present invention aims not only to detect anomalies in network communications in real time and respond appropriately, but also to optimize the interface while considering the user's emotional state. By incorporating an emotion engine, this system offers a novel approach to improving the user experience.
[0334] The server collects communication logs in real time from each device on the network. This data is preprocessed for analysis and sent to an anomaly detection algorithm. Any detected anomalies are generated as warning messages in natural language using generative artificial intelligence and notified to the user.
[0335] During this process, the device uses an emotion engine to analyze the user's current emotional state. The emotion engine evaluates the user's stress level and emotional tendencies based on their past response patterns and operation history. Based on this information, the device can dynamically change the content and display method of notifications. Specifically, if high stress levels are detected, the device will display a message in a calmer tone and add detailed support information.
[0336] For example, if the emotion engine determines that a user has received frequent alerts in the past few hours and is under stress, the next alert message sent will be in the form of, "A new threat has been detected, but we are already taking action. Please rest assured." In this way, the emotion engine is designed to make notifications more acceptable and reduce the user's psychological burden.
[0337] Furthermore, through self-learning mechanisms, the system can continuously learn from these emotional feedbacks, improving the accuracy of future anomaly detection and user responses. Users can monitor and manage the network's security status in real time through the dashboard and analyze areas for long-term improvement through regular reports.
[0338] In this way, the system of the present invention enhances the efficiency of security management and provides a user-friendly interface.
[0339] The following describes the processing flow.
[0340] Step 1:
[0341] The server collects communication logs from each device on the network and stores them in a database. This data collection is performed in real time, and the data is continuously updated.
[0342] Step 2:
[0343] The server preprocesses the collected data, removing noise and preparing it for anomaly detection algorithms. Preprocessing includes data standardization and filtering irrelevant information.
[0344] Step 3:
[0345] The server uses pre-processed data to run an anomaly detection algorithm. This algorithm analyzes communication patterns and identifies trends that deviate from the normal range.
[0346] Step 4:
[0347] If an anomaly is detected, the server uses generative artificial intelligence to generate a warning message in natural language. This message briefly explains the nature of the anomaly and its potential impact.
[0348] Step 5:
[0349] Before displaying a warning message to the user, the device uses an emotion engine to assess the user's emotional state. This assessment is based on the user's current actions and past responses.
[0350] Step 6:
[0351] Based on the evaluation results of the emotion engine, the device adjusts the content and tone of warning messages. For example, if the user is stressed, a message with a more polite and calm tone will be selected.
[0352] Step 7:
[0353] Users receive a tailored warning message on their device and review its contents. Based on the message, users can take appropriate action.
[0354] Step 8:
[0355] The server collects user reactions and emotional feedback, and uses its self-learning function to learn from this data and apply it to future anomaly detection. This process allows the system to improve its performance over time.
[0356] Step 9:
[0357] Users can monitor and manage the overall security status of the network and the history of past incidents in real time through the dashboard. Regular reports enable trend analysis and long-term security assessments.
[0358] (Example 2)
[0359] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server" and the smart glasses 214 will be referred to as the "terminal".
[0360] In today's network environment, it is crucial to quickly detect anomalies in communication data and appropriately deliver warnings. However, conventional systems do not take into account the user's emotional state, and notifications can potentially cause stress to users. Furthermore, there is room for improvement in the accuracy of anomaly detection and the naturalness of warning generation. To solve this problem, a notification system optimized based on user emotions is necessary.
[0361] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.
[0362] In this invention, the server includes means for storing and pre-processing communication data acquired from an information processing device, means for analyzing the communication data to detect anomalies, means for analyzing user emotional information, and means for generating warnings based on anomalies in natural language using generative artificial intelligence and notifying the user. This enables anomaly notifications that take into account the user's emotional state, thereby reducing psychological burden while ensuring network security.
[0363] An "information processing device" is a digital device that has the function of storing and processing communication data.
[0364] "Communication data" refers to a collection of information transmitted over a network.
[0365] "Preprocessing" is the process of shaping data and extracting necessary information for analysis or detection.
[0366] "Anomaly detection" is the process of identifying and pinpointing deviations from standard communication patterns.
[0367] "User emotional information" refers to data about a user's mental state and emotional tendencies.
[0368] "Generative artificial intelligence" is an AI technology that has the ability to generate natural language based on a given prompt.
[0369] "Notification in natural language" is the process of transmitting information in a language that is easy for humans to understand.
[0370] "Visualization" is the process of representing data and information visually to make them easier to understand.
[0371] A "report" is a document that systematically summarizes the results of data analysis and the details of activities.
[0372] "Self-learning function" is a technology that allows a system to improve its own performance based on past data and experience.
[0373] The system in this invention efficiently monitors communication data within a network and detects anomalies to provide appropriate warnings to the user. The server first collects communication data in real time from the information processing device. In this process, network monitoring software is used to acquire and store a large number of data packets. The collected data is preprocessed using data processing libraries such as Pandas to prepare it for anomaly detection.
[0374] Next, the server leverages machine learning libraries such as Scikit-learn to apply anomaly detection algorithms. This allows it to identify anomalies that deviate from normal communication patterns. If an anomaly is detected, a generative artificial intelligence model, such as GPT, is used to generate a warning message in natural language based on the detected anomaly. This process includes a mechanism that automatically generates specific warning content based on the input of prompts.
[0375] The device further analyzes the user's emotional information using libraries such as Emotion Detection. Based on the user's past operation history and response patterns, it evaluates their emotional state and determines their stress level. Based on this data, the server optimizes the generated warnings to match the user's emotional state. For example, if it is determined that the user is stressed, a message in a calm tone will be presented, such as, "A new threat has been detected, but we are already taking measures to address it. Please rest assured."
[0376] An example of a prompt message might be, "Generate a reassuring warning message when the user is under stress." In this way, the system reduces the user's psychological burden while enhancing real-time network security.
[0377] The flow of the specific processing in Example 2 will be explained using Figure 13.
[0378] Step 1:
[0379] The server collects communication data in real time from the information processing device. It receives packet data from the communication network as input and outputs it in the form of data stored in a database. This operation requires the accurate collection of large amounts of data using a communication packet capture tool.
[0380] Step 2:
[0381] The server preprocesses the collected communication data. Using the raw data stored as input, it removes noise through data cleansing and extracts features necessary for anomaly detection. The output is a structured dataset, and data preprocessing is performed using the Pandas library.
[0382] Step 3:
[0383] The server performs anomaly detection using pre-processed data. The input is a formatted dataset that is analyzed by machine learning algorithms. The output is a list of detected anomaly events. Specifically, algorithms such as Scikit-learn's Isolation Forest are used to identify deviations from standard patterns.
[0384] Step 4:
[0385] The server generates warning messages based on anomalies using a generative AI model. It receives detected anomaly events as input and outputs natural language warning messages via prompts. A model like GPT is used to generate messages that correspond to the nature of the anomaly.
[0386] Step 5:
[0387] The device analyzes the user's emotional information. It receives the user's past operation history and real-time emotional data as input, and uses an Emotion Detection library to evaluate the emotional state. The output is evaluation data regarding stress levels and emotional tendencies, which is used to analyze the user's state.
[0388] Step 6:
[0389] The device optimizes notification content and method based on analyzed emotional information. The input is the previously generated emotional evaluation data, which is combined with the generated warning message to optimize and output notifications in a way that suits the user's psychological state. If the user is stressed, the system will display messages with calmer language.
[0390] (Application Example 2)
[0391] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server," and the smart glasses 214 will be referred to as the "terminal."
[0392] In today's network environment, ensuring the security of communications is extremely important. However, it is difficult not only to detect anomalies but also to transmit information appropriately while minimizing the impact on users. In particular, uniform notifications that do not take into account the user's emotional state can cause unnecessary stress. To solve this problem, there is a need for a system that provides customized notification methods that take into account the user's emotional state.
[0393] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means.
[0394] In this invention, the server includes means for storing and preprocessing communication records acquired from data acquisition means, means for detecting anomalies by analyzing the communication records, means for analyzing the user's emotional state, means for dynamically changing the content and display method of warnings based on the results of the emotion analysis means, means for self-learning to improve the accuracy of analysis and detection using a learning algorithm, and means for visualizing the communication records and warnings and generating a report. This makes it possible to detect anomalies and provide accurate and psychologically less burdensome notifications that take into consideration the user's emotions.
[0395] "Data acquisition means" refers to an element that has the function of collecting and storing communication records from devices on a network.
[0396] "Means for pre-processing" refers to an element equipped with processing functions that prepare the collected communication records for analysis.
[0397] An "anomaly detection means" is an element that analyzes communication records and has the function of detecting deviations from normal patterns.
[0398] "Means for generating and presenting warnings" refers to elements that create and display warning messages in natural language to the user based on detected anomalies.
[0399] An "emotion analysis tool" is an element that has the function of evaluating the user's emotional state and reflecting that information in the method of communication notifications.
[0400] A "dynamically changing mechanism" refers to an element that allows for the appropriate adjustment of the notification format and content based on the user's emotional state.
[0401] A "self-learning mechanism" is an element that has the function of continuously improving the accuracy of analysis and anomaly detection based on past data and user emotional feedback.
[0402] "Means for visualization and report generation" refers to elements that have the functionality to organize communication records and generated warnings as graphs and reports, and present them to users in an easy-to-understand manner.
[0403] This invention relates to a system that analyzes communication records collected over a network in real time to detect anomalies and provide notifications to users based on their emotions. The hardware used to implement this system includes a network-enabled server and user terminals (e.g., smartphones and smart glasses).
[0404] The server has data acquisition means to collect communication records from devices on the network. The collected data is preprocessed and then analyzed using anomaly detection means. If an anomaly is detected, the server uses a generative AI model to generate a warning message in natural language. In this case, the generative AI model is given an example prompt: "Consider the user's emotional state and express the security alert in a calm tone."
[0405] The device receives warnings sent from the server and analyzes the user's emotional state using emotion analysis tools. A dedicated emotion engine API is used for this emotion analysis. The content and display method of the warnings are dynamically adjusted according to the user's stress level, allowing the user to receive information with less psychological burden.
[0406] For example, if a user receives a warning about abnormal communication on their work smartphone, and the system determines that the user is experiencing high levels of stress, a calm message will be displayed stating, "A new anomaly has been detected, but we have already taken steps to resolve it, so please rest assured."
[0407] In this way, users can receive security-related information stress-free, and the system is designed to continuously improve the accuracy of anomaly detection and notification through self-learning mechanisms.
[0408] The flow of a specific process in Application Example 2 will be explained using Figure 14.
[0409] Step 1:
[0410] The server acquires communication logs from each device on the network. The input here is communication data from each device, and the output is the raw communication log collected by the server. This communication log is stored in a database and used in subsequent processing steps as needed.
[0411] Step 2:
[0412] The server performs preprocessing on the collected communication logs. The input is the raw communication log, and the output is the data after noise has been removed and normalized. Specifically, this involves filtering out unnecessary data and standardizing the format.
[0413] Step 3:
[0414] The server performs analysis to detect anomalies based on pre-processed communication records. The input is the pre-processed communication records, and the output is a list of detected anomalies. The server uses an anomaly detection algorithm to evaluate deviations in communication patterns and identify behavior that is different from normal.
[0415] Step 4:
[0416] When an anomaly is detected, the server uses a generative AI model to generate a warning message in natural language. The input here is information about the detected anomaly, and the output is the warning message to be presented to the user. Specifically, based on the anomaly data, the generative AI is instructed to generate a message using the prompt "Consider the user's emotional state and express the security alert in a calm tone."
[0417] Step 5:
[0418] The terminal receives a warning message sent from the server and analyzes the user's emotional state using emotion analysis tools. The input is the user's past response patterns and operation history, and the output is the evaluation result of the current emotional state. Specifically, it uses a dedicated emotion engine API to evaluate the stress level and passes that information to the next step.
[0419] Step 6:
[0420] The device uses the results of sentiment analysis to adjust how warning messages are displayed to the user. The input is the warning message and the results of the sentiment analysis, and the output is an optimized notification for the user. For example, if the device determines that the user is highly stressed, it will soften the tone of the message and add reassuring language.
[0421] The specific processing unit 290 transmits the result of the specific processing to the smart glasses 214. In the smart glasses 214, the control unit 46A causes the speaker 240 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.
[0422] Data generation model 58 is a type of so-called generative AI (Artificial Intelligence). One example of data generation model 58 is ChatGPT (Internet search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[0423] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and the specific processing may also be performed by the smart glasses 214.
[0424] [Third Embodiment]
[0425] Figure 5 shows an example of the configuration of the data processing system 310 according to the third embodiment.
[0426] As shown in Figure 5, the data processing system 310 includes a data processing device 12 and a headset terminal 314. An example of the data processing device 12 is a server.
[0427] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0428] The headset terminal 314 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication interface 44, and a display 343. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, camera 42, and display 343 are also connected to the bus 52.
[0429] The microphone 238 receives voice signals from the user 20 and receives instructions from the user 20. The microphone 238 captures the voice signals from the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.
[0430] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the area around the user 20 (for example, an imaging range defined by a field of view equivalent to the width of a typical healthy person's field of vision).
[0431] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.
[0432] Figure 6 shows an example of the main functions of the data processing device 12 and the headset terminal 314. As shown in Figure 6, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.
[0433] The specific processing program 56 is an example of a "program" relating to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[0434] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[0435] In the headset terminal 314, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.
[0436] Next, the specific processing performed by the specific processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the headset terminal 314 will be referred to as the "terminal".
[0437] The system according to the present invention aims to efficiently detect and quickly address abnormal communications within a network. To achieve this, the server continuously collects communication records from each device on the network. This data is stored in a database and serves as the basis for analysis.
[0438] The server preprocesses the collected communication records, formatting them to be suitable as input for anomaly detection algorithms. During this process, unnecessary data and noise are removed, and the data is standardized. Next, the server analyzes this data using a machine learning model. This analysis process detects deviations from normal communication patterns and assigns a score to events considered anomalous.
[0439] When a device detects an anomaly, the AI generates a natural language alert for the user and notifies the device. Through this alert, the user can easily recognize potential cyber threats that require immediate attention. For example, an alert might appear on the device stating, "An attempt was made to access the device from a suspicious IP address at 10:00 AM."
[0440] Furthermore, this system features a function that improves analysis accuracy by allowing the server to self-learn using past incidents as learning material. This enables the system to quickly adapt to new threat patterns and reduce the false positive rate.
[0441] Furthermore, users can monitor the security status of the entire network in real time through a dashboard. The server regularly updates this data, making it easy for users to understand the network's security. Regularly generated reports include detailed summaries of past incidents and current threat levels, which are also useful for long-term analysis.
[0442] Thus, the system of the present invention integrates various means to achieve improved efficiency and accuracy in network security management.
[0443] The following describes the processing flow.
[0444] Step 1:
[0445] The server begins collecting communication logs in real time from all devices on the network. The server continuously receives this data and stores it in a secure database.
[0446] Step 2:
[0447] The server performs data cleansing on the collected communication records. Specifically, the server filters out noisy data and irrelevant information to create a shaped dataset.
[0448] Step 3:
[0449] The server inputs pre-processed data into an anomaly detection algorithm. The server uses a machine learning model to compare the current communication pattern with past normal patterns and scores the anomaly.
[0450] Step 4:
[0451] When an anomaly is detected, the device uses a generative AI to create a warning message in natural language. This warning message is sent to the user as a potential threat requiring immediate attention.
[0452] Step 5:
[0453] The user receives a warning displayed on their device and checks the situation. Based on the warning, the user contacts the network administrator as needed to ensure a prompt response.
[0454] Step 6:
[0455] The server saves detected anomalies and corresponding incidents, and inputs them into a self-learning model. This allows the server to train the model with new insights to improve the accuracy of future anomaly detection.
[0456] Step 7:
[0457] Users can view the network's security status in real time through a dashboard updated by the server. This information includes past incidents and current threat levels.
[0458] (Example 1)
[0459] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."
[0460] Modern communication networks require the rapid detection and appropriate response to abnormal communication activity. However, conventional methods struggle to effectively analyze large amounts of data and identify and notify anomalies in real time, leading to false alarms and delayed responses. Furthermore, self-learning capabilities are necessary to adaptively improve these anomaly detection systems, but achieving this is not easy. Therefore, there is a need to develop a system that can detect and respond to anomalies quickly and accurately while maintaining a high level of network security.
[0461] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.
[0462] In this invention, the server includes means for storing and pre-processing data records acquired from an information collection device, analysis means for analyzing the data records to detect anomalies, and means for generating alarms based on the detected anomalies and notifying users. This makes it possible to effectively detect abnormal communication activity within the network and notify users quickly in a way that allows them to take action.
[0463] An "information gathering device" is a device used to acquire data from a communication network and has the role of storing data records.
[0464] "Data recording" refers to a recording format that includes various types of information about communication activities on a network, and serves as the basis for analysis and anomaly detection.
[0465] "Preprocessing" is the process of removing unnecessary elements from acquired data records and formatting them into a state suitable for analysis.
[0466] "Analysis means" refers to technical methods and processes for detecting anomalies based on pre-processed data records, and includes anomaly detection algorithms.
[0467] An "anomaly" refers to an event that deviates from normal communication patterns and may have an impact on security.
[0468] An "alert" is a notification message generated based on a detected anomaly, intended to alert the user.
[0469] "Self-learning" is the process of improving the accuracy of a system's analysis and detection by continuously improving machine learning algorithms.
[0470] "Visualization" refers to a means of displaying data records and alarms in a format that is easy for users to understand.
[0471] A "report" is a document that includes visualized information and summarizes past events and the current situation.
[0472] "Real-time monitoring" is a monitoring method that allows for immediate understanding of the network's security status and enables rapid response.
[0473] A "machine learning algorithm" is a computational method that allows computers to learn from past data and make predictions based on unknown data.
[0474] "Automated artificial intelligence" refers to machine learning technology that has the ability to solve problems independently with minimal human intervention.
[0475] This invention is a system for improving network security and consists of several key elements. First, a server collects data. The server uses hardware such as packet capture tools to collect communication records from each device in the network. This communication data is stored in a relational database system for efficient management.
[0476] The collected communication records are preprocessed by the server. This preprocessing filters out unnecessary data and noise, and standardizes the data. This preprocessing is performed using TensorFlow or PyTorch, prior to machine learning analysis.
[0477] Next, the server analyzes the data using machine learning algorithms. To detect deviations from normal communication patterns, the server performs predictive analysis using existing models. If an anomaly is detected, the generative AI model generates an alert in natural language.
[0478] The generated alerts are sent to the terminal. The terminal displays these alerts to the user, prompting a quick response. This alert system provides users with important information to understand the current state of the system and take necessary actions.
[0479] This system features self-learning capabilities, with the server continuously updating its machine learning model using past incident data. This improves the accuracy of anomaly detection and enables rapid responses to new threats.
[0480] As a concrete example, if a new suspicious access attempt occurs on a corporate network at 10:00 AM, the AI will generate an alert stating, "An access attempt was made from a suspicious IP address at 10:00 AM," and notify the terminal. Based on this information, the user can immediately take network security measures.
[0481] Furthermore, users can monitor the security status in real time through a dashboard. The server periodically updates the dashboard, providing users with the latest threat intelligence and summaries of past incidents. This allows users to perform analyses to maintain network security over the long term.
[0482] An example of a prompt message could be, "Detect suspicious communication activity on the internal network and generate a report." By inputting this prompt message into the AI generation model, the necessary data is accurately organized, and appropriate alerts and reports are created.
[0483] The flow of the specific processing in Example 1 will be explained using Figure 11.
[0484] Step 1:
[0485] The server collects communication logs from each device on the network. It takes network traffic data as input using a packet capture tool and obtains raw communication log data as output. Specifically, the server monitors a particular network port and records metadata such as source IP, destination IP, and data volume.
[0486] Step 2:
[0487] The server stores the collected communication records in a database. It takes the communication records obtained in step 1 as input and outputs them in a format that allows for organized and efficient management. Specifically, the server uses database software to index the data, making it readily accessible.
[0488] Step 3:
[0489] The server preprocesses the stored communication records. It takes records from the database as input and obtains standardized data suitable for analysis as output. Specifically, the server removes unnecessary noise and unifies all data entries into a standard format.
[0490] Step 4:
[0491] The server analyzes preprocessed data using a machine learning model. It receives standardized data from step 3 as input and generates anomaly detection results as output. The server uses libraries such as TensorFlow and PyTorch to compare the data with normal communication patterns and identify events that have been marked as anomalies.
[0492] Step 5:
[0493] The generating AI creates an alert when an anomaly is detected. It uses the anomaly detection results from step 4 as input and generates an alert message in natural language as output. Specifically, the generating AI understands the nature of the anomaly and constructs a specific message such as, "An attempt was made to access the system from a suspicious IP address."
[0494] Step 6:
[0495] The device notifies the user of the generated alert. It receives the alert message generated in step 5 as input and outputs it directly to the user. Specifically, the device sends an alert via a pop-up notification or email so that the user can quickly understand the situation.
[0496] Step 7:
[0497] The server updates and self-learns machine learning models using historical incident data. It utilizes previously collected incident data as input to train and output new models. Specifically, the server updates the dataset to the latest state through periodic batch processing, improving the model's predictive accuracy.
[0498] Step 8:
[0499] Users monitor the network's security status in real time through a dashboard. They receive the latest security information sent from the server as input and obtain visualized information as output. Specifically, users can view past incident history and real-time threat levels on the dashboard and develop necessary countermeasures.
[0500] (Application Example 1)
[0501] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."
[0502] In today's network environments, there is a need to quickly detect abnormal communications and notify users of appropriate warnings. However, many current systems have low accuracy in anomaly detection, leading to delayed warnings and false alarms. Furthermore, they lack sufficient mechanisms to learn from past incidents and improve analysis accuracy in order to reduce the burden on administrators. To solve this problem, a system is needed that can improve the accuracy of anomaly detection and provide rapid user notifications.
[0503] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.
[0504] In this invention, the server includes means for storing and performing initial processing of communication information obtained from a data collection device, detection means for analyzing the communication information to detect anomalies, and means for generating warnings based on the detected anomalies and notifying mobile terminals. This makes it possible to quickly and accurately detect abnormal communications and immediately notify users. Furthermore, by visualizing the communication information and warnings and creating reports, administrators can easily grasp the security of the network and utilize this information for long-term security analysis.
[0505] A "data collection device" is a device used to acquire communication information from various devices within a network.
[0506] "Communication information" refers to the records and data of all communications that take place within a network.
[0507] "Initial processing" refers to pre-processing to format the collected communication information into a form suitable for analysis.
[0508] "Detection means" refers to methods for analyzing collected communication information and identifying anomalies.
[0509] A "warning" is information or a message used to notify the user of a detected anomaly.
[0510] "Mobile devices" refer to portable communication devices such as smartphones and tablets.
[0511] A "report" is a document that visualizes the security of a network, created based on communication information and anomaly detection results.
[0512] "Visualization" refers to the process of displaying data and information in an easy-to-understand manner using graphs and diagrams.
[0513] "Self-learning methods" refer to techniques that utilize machine learning models to continuously improve analytical accuracy based on past data.
[0514] The system implementing this invention mainly consists of a server and a mobile terminal. The server collects communication information from each device in the network through a data collection device. This communication information is stored in a database and becomes the subject of analysis. Subsequently, the server performs initial processing such as standardization and noise reduction, and uses machine learning models to perform analysis to identify deviations from normal communication patterns.
[0515] If an anomaly is detected, the server uses a generative AI to create a warning in natural language. This warning is then pushed to the mobile device, allowing the user to take immediate action. Specifically, an alert such as "A new device has connected to the network. Please check for potential unauthorized access" is sent.
[0516] The server also handles report generation, which includes anomaly detection results and a visual representation of the overall communication status. Users can use this to periodically assess network security and help develop long-term security strategies.
[0517] To implement this system, the server program will use Python and machine learning libraries such as Scikit-learn and TensorFlow, while the mobile device application will be developed using React Native. Specific processing steps include data collection, preprocessing, policy-based anomaly detection, natural language generation, and user notification. An example of a prompt message might be, "A new anomalous communication has been detected on the network. What action should be taken?"
[0518] The flow of a specific process in Application Example 1 will be explained using Figure 12.
[0519] Step 1:
[0520] The server acquires communication information from each device in the network using data collection devices. The input at this stage is all data transmitted through the network. The server stores this data in a database, making it available as foundational data for subsequent processing. Specifically, it collects packet information and connection logs sent from each device.
[0521] Step 2:
[0522] The server performs initial processing to standardize the collected communication information and remove noise and unnecessary data. The input is the raw communication information obtained in the previous step, and the output is data in a clean format suitable for anomaly detection. This processing reduces data variability and creates a consistent dataset.
[0523] Step 3:
[0524] The server uses machine learning models to analyze the data after initial processing and identify deviations from normal communication patterns. The input is the initially processed communication data, and the output is the data points considered anomalous. Specifically, anomaly detection is performed using support vector machines or neural networks.
[0525] Step 4:
[0526] If an anomaly is detected, the server uses a generative AI to create a warning in natural language. In this step, the AI generates an appropriate warning message using the prompt "Abnormal communication has been detected. How will you respond?". The input is the detected anomaly data, and the output is a warning message in natural language.
[0527] Step 5:
[0528] The server notifies mobile devices of the generated warnings. The input is the warning message created by the generation AI, and the output is the notification displayed on the user's smartphone or tablet. The server uses a push notification system to quickly deliver the information to the user.
[0529] Step 6:
[0530] The server generates and visualizes reports based on communication information and anomaly detection results. Inputs are communication information and anomaly detection results, while outputs are visualized data and reports on a user-accessible dashboard. These reports include graphs and charts illustrating historical trends and network security.
[0531] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.
[0532] The system according to the present invention aims not only to detect anomalies in network communications in real time and respond appropriately, but also to optimize the interface while considering the user's emotional state. By incorporating an emotion engine, this system offers a novel approach to improving the user experience.
[0533] The server collects communication logs in real time from each device on the network. This data is preprocessed for analysis and sent to an anomaly detection algorithm. Any detected anomalies are generated as warning messages in natural language using generative artificial intelligence and notified to the user.
[0534] During this process, the device uses an emotion engine to analyze the user's current emotional state. The emotion engine evaluates the user's stress level and emotional tendencies based on their past response patterns and operation history. Based on this information, the device can dynamically change the content and display method of notifications. Specifically, if high stress levels are detected, the device will display a message in a calmer tone and add detailed support information.
[0535] For example, if the emotion engine determines that a user has received frequent alerts in the past few hours and is under stress, the next alert message sent will be in the form of, "A new threat has been detected, but we are already taking action. Please rest assured." In this way, the emotion engine is designed to make notifications more acceptable and reduce the user's psychological burden.
[0536] Furthermore, through self-learning mechanisms, the system can continuously learn from these emotional feedbacks, improving the accuracy of future anomaly detection and user responses. Users can monitor and manage the network's security status in real time through the dashboard and analyze areas for long-term improvement through regular reports.
[0537] In this way, the system of the present invention enhances the efficiency of security management and provides a user-friendly interface.
[0538] The following describes the processing flow.
[0539] Step 1:
[0540] The server collects communication logs from each device on the network and stores them in a database. This data collection is performed in real time, and the data is continuously updated.
[0541] Step 2:
[0542] The server preprocesses the collected data, removing noise and preparing it for anomaly detection algorithms. Preprocessing includes data standardization and filtering irrelevant information.
[0543] Step 3:
[0544] The server uses pre-processed data to run an anomaly detection algorithm. This algorithm analyzes communication patterns and identifies trends that deviate from the normal range.
[0545] Step 4:
[0546] If an anomaly is detected, the server uses generative artificial intelligence to generate a warning message in natural language. This message briefly explains the nature of the anomaly and its potential impact.
[0547] Step 5:
[0548] Before displaying a warning message to the user, the device uses an emotion engine to assess the user's emotional state. This assessment is based on the user's current actions and past responses.
[0549] Step 6:
[0550] Based on the evaluation results of the emotion engine, the device adjusts the content and tone of warning messages. For example, if the user is stressed, a message with a more polite and calm tone will be selected.
[0551] Step 7:
[0552] Users receive a tailored warning message on their device and review its contents. Based on the message, users can take appropriate action.
[0553] Step 8:
[0554] The server collects user reactions and emotional feedback, and uses its self-learning function to learn from this data and apply it to future anomaly detection. This process allows the system to improve its performance over time.
[0555] Step 9:
[0556] Users can monitor and manage the overall security status of the network and the history of past incidents in real time through the dashboard. Regular reports enable trend analysis and long-term security assessments.
[0557] (Example 2)
[0558] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."
[0559] In today's network environment, it is crucial to quickly detect anomalies in communication data and appropriately deliver warnings. However, conventional systems do not take into account the user's emotional state, and notifications can potentially cause stress to users. Furthermore, there is room for improvement in the accuracy of anomaly detection and the naturalness of warning generation. To solve this problem, a notification system optimized based on user emotions is necessary.
[0560] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.
[0561] In this invention, the server includes means for storing and pre-processing communication data acquired from an information processing device, means for analyzing the communication data to detect anomalies, means for analyzing user emotional information, and means for generating warnings based on anomalies in natural language using generative artificial intelligence and notifying the user. This enables anomaly notifications that take into account the user's emotional state, thereby reducing psychological burden while ensuring network security.
[0562] An "information processing device" is a digital device that has the function of storing and processing communication data.
[0563] "Communication data" refers to a collection of information transmitted over a network.
[0564] "Preprocessing" is the process of shaping data and extracting necessary information for analysis or detection.
[0565] "Anomaly detection" is the process of identifying and pinpointing deviations from standard communication patterns.
[0566] "User emotional information" refers to data about a user's mental state and emotional tendencies.
[0567] "Generative artificial intelligence" is an AI technology that has the ability to generate natural language based on a given prompt.
[0568] "Notification in natural language" is the process of transmitting information in a language that is easy for humans to understand.
[0569] "Visualization" is the process of representing data and information visually to make them easier to understand.
[0570] A "report" is a document that systematically summarizes the results of data analysis and the details of activities.
[0571] "Self-learning function" is a technology that allows a system to improve its own performance based on past data and experience.
[0572] The system in this invention efficiently monitors communication data within a network and detects anomalies to provide appropriate warnings to the user. The server first collects communication data in real time from the information processing device. In this process, network monitoring software is used to acquire and store a large number of data packets. The collected data is preprocessed using data processing libraries such as Pandas to prepare it for anomaly detection.
[0573] Next, the server leverages machine learning libraries such as Scikit-learn to apply anomaly detection algorithms. This allows it to identify anomalies that deviate from normal communication patterns. If an anomaly is detected, a generative artificial intelligence model, such as GPT, is used to generate a warning message in natural language based on the detected anomaly. This process includes a mechanism that automatically generates specific warning content based on the input of prompts.
[0574] The device further analyzes the user's emotional information using libraries such as Emotion Detection. Based on the user's past operation history and response patterns, it evaluates their emotional state and determines their stress level. Based on this data, the server optimizes the generated warnings to match the user's emotional state. For example, if it is determined that the user is stressed, a message in a calm tone will be presented, such as, "A new threat has been detected, but we are already taking measures to address it. Please rest assured."
[0575] An example of a prompt message might be, "Generate a reassuring warning message when the user is under stress." In this way, the system reduces the user's psychological burden while enhancing real-time network security.
[0576] The flow of the specific processing in Example 2 will be explained using Figure 13.
[0577] Step 1:
[0578] The server collects communication data in real time from the information processing device. It receives packet data from the communication network as input and outputs it in the form of data stored in a database. This operation requires the accurate collection of large amounts of data using a communication packet capture tool.
[0579] Step 2:
[0580] The server preprocesses the collected communication data. Using the raw data stored as input, it removes noise through data cleansing and extracts features necessary for anomaly detection. The output is a structured dataset, and data preprocessing is performed using the Pandas library.
[0581] Step 3:
[0582] The server performs anomaly detection using pre-processed data. The input is a formatted dataset that is analyzed by machine learning algorithms. The output is a list of detected anomaly events. Specifically, algorithms such as Scikit-learn's Isolation Forest are used to identify deviations from standard patterns.
[0583] Step 4:
[0584] The server generates warning messages based on anomalies using a generative AI model. It receives detected anomaly events as input and outputs natural language warning messages via prompts. A model like GPT is used to generate messages that correspond to the nature of the anomaly.
[0585] Step 5:
[0586] The device analyzes the user's emotional information. It receives the user's past operation history and real-time emotional data as input, and uses an Emotion Detection library to evaluate the emotional state. The output is evaluation data regarding stress levels and emotional tendencies, which is used to analyze the user's state.
[0587] Step 6:
[0588] The device optimizes notification content and method based on analyzed emotional information. The input is the previously generated emotional evaluation data, which is combined with the generated warning message to optimize and output notifications in a way that suits the user's psychological state. If the user is stressed, the system will display messages with calmer language.
[0589] (Application Example 2)
[0590] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."
[0591] In today's network environment, ensuring the security of communications is extremely important. However, it is difficult not only to detect anomalies but also to transmit information appropriately while minimizing the impact on users. In particular, uniform notifications that do not take into account the user's emotional state can cause unnecessary stress. To solve this problem, there is a need for a system that provides customized notification methods that take into account the user's emotional state.
[0592] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means.
[0593] In this invention, the server includes means for storing and preprocessing communication records acquired from data acquisition means, means for detecting anomalies by analyzing the communication records, means for analyzing the user's emotional state, means for dynamically changing the content and display method of warnings based on the results of the emotion analysis means, means for self-learning to improve the accuracy of analysis and detection using a learning algorithm, and means for visualizing the communication records and warnings and generating a report. This makes it possible to detect anomalies and provide accurate and psychologically less burdensome notifications that take into consideration the user's emotions.
[0594] "Data acquisition means" refers to an element that has the function of collecting and storing communication records from devices on a network.
[0595] "Means for pre-processing" refers to an element equipped with processing functions that prepare the collected communication records for analysis.
[0596] An "anomaly detection means" is an element that analyzes communication records and has the function of detecting deviations from normal patterns.
[0597] "Means for generating and presenting warnings" refers to elements that create and display warning messages in natural language to the user based on detected anomalies.
[0598] An "emotion analysis tool" is an element that has the function of evaluating the user's emotional state and reflecting that information in the method of communication notifications.
[0599] A "dynamically changing mechanism" refers to an element that allows for the appropriate adjustment of the notification format and content based on the user's emotional state.
[0600] A "self-learning mechanism" is an element that has the function of continuously improving the accuracy of analysis and anomaly detection based on past data and user emotional feedback.
[0601] "Means for visualization and report generation" refers to elements that have the functionality to organize communication records and generated warnings as graphs and reports, and present them to users in an easy-to-understand manner.
[0602] This invention relates to a system that analyzes communication records collected over a network in real time to detect anomalies and provide notifications to users based on their emotions. The hardware used to implement this system includes a network-enabled server and user terminals (e.g., smartphones and smart glasses).
[0603] The server has data acquisition means to collect communication records from devices on the network. The collected data is preprocessed and then analyzed using anomaly detection means. If an anomaly is detected, the server uses a generative AI model to generate a warning message in natural language. In this case, the generative AI model is given an example prompt: "Consider the user's emotional state and express the security alert in a calm tone."
[0604] The device receives warnings sent from the server and analyzes the user's emotional state using emotion analysis tools. A dedicated emotion engine API is used for this emotion analysis. The content and display method of the warnings are dynamically adjusted according to the user's stress level, allowing the user to receive information with less psychological burden.
[0605] For example, if a user receives a warning about abnormal communication on their work smartphone, and the system determines that the user is experiencing high levels of stress, a calm message will be displayed stating, "A new anomaly has been detected, but we have already taken steps to resolve it, so please rest assured."
[0606] In this way, users can receive security-related information stress-free, and the system is designed to continuously improve the accuracy of anomaly detection and notification through self-learning mechanisms.
[0607] The flow of a specific process in Application Example 2 will be explained using Figure 14.
[0608] Step 1:
[0609] The server acquires communication logs from each device on the network. The input here is communication data from each device, and the output is the raw communication log collected by the server. This communication log is stored in a database and used in subsequent processing steps as needed.
[0610] Step 2:
[0611] The server performs preprocessing on the collected communication logs. The input is the raw communication log, and the output is the data after noise has been removed and normalized. Specifically, this involves filtering out unnecessary data and standardizing the format.
[0612] Step 3:
[0613] The server performs analysis to detect anomalies based on pre-processed communication records. The input is the pre-processed communication records, and the output is a list of detected anomalies. The server uses an anomaly detection algorithm to evaluate deviations in communication patterns and identify behavior that is different from normal.
[0614] Step 4:
[0615] When an anomaly is detected, the server uses a generative AI model to generate a warning message in natural language. The input here is information about the detected anomaly, and the output is the warning message to be presented to the user. Specifically, based on the anomaly data, the generative AI is instructed to generate a message using the prompt "Consider the user's emotional state and express the security alert in a calm tone."
[0616] Step 5:
[0617] The terminal receives a warning message sent from the server and analyzes the user's emotional state using emotion analysis tools. The input is the user's past response patterns and operation history, and the output is the evaluation result of the current emotional state. Specifically, it uses a dedicated emotion engine API to evaluate the stress level and passes that information to the next step.
[0618] Step 6:
[0619] The device uses the results of sentiment analysis to adjust how warning messages are displayed to the user. The input is the warning message and the results of the sentiment analysis, and the output is an optimized notification for the user. For example, if the device determines that the user is highly stressed, it will soften the tone of the message and add reassuring language.
[0620] The specific processing unit 290 transmits the result of the specific processing to the headset terminal 314. In the headset terminal 314, the control unit 46A causes the speaker 240 and display 343 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.
[0621] Data generation model 58 is a type of so-called generative AI (Artificial Intelligence). One example of data generation model 58 is ChatGPT (Internet search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[0622] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and specific processing may also be performed by the headset terminal 314.
[0623] [Fourth Embodiment]
[0624] Figure 7 shows an example of the configuration of the data processing system 410 according to the fourth embodiment.
[0625] As shown in Figure 7, the data processing system 410 includes a data processing device 12 and a robot 414. An example of the data processing device 12 is a server.
[0626] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0627] The robot 414 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication interface 44, and a controlled object 443. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, camera 42, and controlled object 443 are also connected to the bus 52.
[0628] The microphone 238 receives voice signals from the user 20 and receives instructions from the user 20. The microphone 238 captures the voice signals from the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.
[0629] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the area around the user 20 (for example, an imaging range defined by a field of view equivalent to the width of a typical healthy person's field of vision).
[0630] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.
[0631] The controlled object 443 includes a display device, LEDs in the eyes, and motors that drive the arms, hands, and feet. The posture and gestures of the robot 414 are controlled by controlling the motors of the arms, hands, and feet. Some of the robot 414's emotions can be expressed by controlling these motors. Furthermore, the robot 414's facial expressions can also be expressed by controlling the illumination state of the LEDs in its eyes.
[0632] Figure 8 shows an example of the main functions of the data processing device 12 and the robot 414. As shown in Figure 8, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.
[0633] The specific processing program 56 is an example of a "program" relating to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[0634] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[0635] In robot 414, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.
[0636] Next, the specific processing performed by the specific processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".
[0637] The system according to the present invention aims to efficiently detect and quickly address abnormal communications within a network. To achieve this, the server continuously collects communication records from each device on the network. This data is stored in a database and serves as the basis for analysis.
[0638] The server preprocesses the collected communication records, formatting them to be suitable as input for anomaly detection algorithms. During this process, unnecessary data and noise are removed, and the data is standardized. Next, the server analyzes this data using a machine learning model. This analysis process detects deviations from normal communication patterns and assigns a score to events considered anomalous.
[0639] When a device detects an anomaly, the AI generates a natural language alert for the user and notifies the device. Through this alert, the user can easily recognize potential cyber threats that require immediate attention. For example, an alert might appear on the device stating, "An attempt was made to access the device from a suspicious IP address at 10:00 AM."
[0640] Furthermore, this system features a function that improves analysis accuracy by allowing the server to self-learn using past incidents as learning material. This enables the system to quickly adapt to new threat patterns and reduce the false positive rate.
[0641] Furthermore, users can monitor the security status of the entire network in real time through a dashboard. The server regularly updates this data, making it easy for users to understand the network's security. Regularly generated reports include detailed summaries of past incidents and current threat levels, which are also useful for long-term analysis.
[0642] Thus, the system of the present invention integrates various means to achieve improved efficiency and accuracy in network security management.
[0643] The following describes the processing flow.
[0644] Step 1:
[0645] The server begins collecting communication logs in real time from all devices on the network. The server continuously receives this data and stores it in a secure database.
[0646] Step 2:
[0647] The server performs data cleansing on the collected communication records. Specifically, the server filters out noisy data and irrelevant information to create a shaped dataset.
[0648] Step 3:
[0649] The server inputs pre-processed data into an anomaly detection algorithm. The server uses a machine learning model to compare the current communication pattern with past normal patterns and scores the anomaly.
[0650] Step 4:
[0651] When an anomaly is detected, the device uses a generative AI to create a warning message in natural language. This warning message is sent to the user as a potential threat requiring immediate attention.
[0652] Step 5:
[0653] The user receives a warning displayed on their device and checks the situation. Based on the warning, the user contacts the network administrator as needed to ensure a prompt response.
[0654] Step 6:
[0655] The server saves detected anomalies and corresponding incidents, and inputs them into a self-learning model. This allows the server to train the model with new insights to improve the accuracy of future anomaly detection.
[0656] Step 7:
[0657] Users can view the network's security status in real time through a dashboard updated by the server. This information includes past incidents and current threat levels.
[0658] (Example 1)
[0659] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".
[0660] Modern communication networks require the rapid detection and appropriate response to abnormal communication activity. However, conventional methods struggle to effectively analyze large amounts of data and identify and notify anomalies in real time, leading to false alarms and delayed responses. Furthermore, self-learning capabilities are necessary to adaptively improve these anomaly detection systems, but achieving this is not easy. Therefore, there is a need to develop a system that can detect and respond to anomalies quickly and accurately while maintaining a high level of network security.
[0661] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.
[0662] In this invention, the server includes means for storing and pre-processing data records acquired from an information collection device, analysis means for analyzing the data records to detect anomalies, and means for generating alarms based on the detected anomalies and notifying users. This makes it possible to effectively detect abnormal communication activity within the network and notify users quickly in a way that allows them to take action.
[0663] An "information gathering device" is a device used to acquire data from a communication network and has the role of storing data records.
[0664] "Data recording" refers to a recording format that includes various types of information about communication activities on a network, and serves as the basis for analysis and anomaly detection.
[0665] "Preprocessing" is the process of removing unnecessary elements from acquired data records and formatting them into a state suitable for analysis.
[0666] "Analysis means" refers to technical methods and processes for detecting anomalies based on pre-processed data records, and includes anomaly detection algorithms.
[0667] An "anomaly" refers to an event that deviates from normal communication patterns and may have an impact on security.
[0668] An "alert" is a notification message generated based on a detected anomaly, intended to alert the user.
[0669] "Self-learning" is the process of improving the accuracy of a system's analysis and detection by continuously improving machine learning algorithms.
[0670] "Visualization" refers to a means of displaying data records and alarms in a format that is easy for users to understand.
[0671] A "report" is a document that includes visualized information and summarizes past events and the current situation.
[0672] "Real-time monitoring" is a monitoring method that allows for immediate understanding of the network's security status and enables rapid response.
[0673] A "machine learning algorithm" is a computational method that allows computers to learn from past data and make predictions based on unknown data.
[0674] "Automated artificial intelligence" refers to machine learning technology that has the ability to solve problems independently with minimal human intervention.
[0675] This invention is a system for improving network security and consists of several key elements. First, a server collects data. The server uses hardware such as packet capture tools to collect communication records from each device in the network. This communication data is stored in a relational database system for efficient management.
[0676] The collected communication records are preprocessed by the server. This preprocessing filters out unnecessary data and noise, and standardizes the data. This preprocessing is performed using TensorFlow or PyTorch, prior to machine learning analysis.
[0677] Next, the server analyzes the data using machine learning algorithms. To detect deviations from normal communication patterns, the server performs predictive analysis using existing models. If an anomaly is detected, the generative AI model generates an alert in natural language.
[0678] The generated alerts are sent to the terminal. The terminal displays these alerts to the user, prompting a quick response. This alert system provides users with important information to understand the current state of the system and take necessary actions.
[0679] This system features self-learning capabilities, with the server continuously updating its machine learning model using past incident data. This improves the accuracy of anomaly detection and enables rapid responses to new threats.
[0680] As a concrete example, if a new suspicious access attempt occurs on a corporate network at 10:00 AM, the AI will generate an alert stating, "An access attempt was made from a suspicious IP address at 10:00 AM," and notify the terminal. Based on this information, the user can immediately take network security measures.
[0681] Furthermore, users can monitor the security status in real time through a dashboard. The server periodically updates the dashboard, providing users with the latest threat intelligence and summaries of past incidents. This allows users to perform analyses to maintain network security over the long term.
[0682] An example of a prompt message could be, "Detect suspicious communication activity on the internal network and generate a report." By inputting this prompt message into the AI generation model, the necessary data is accurately organized, and appropriate alerts and reports are created.
[0683] The flow of the specific processing in Example 1 will be explained using Figure 11.
[0684] Step 1:
[0685] The server collects communication logs from each device on the network. It takes network traffic data as input using a packet capture tool and obtains raw communication log data as output. Specifically, the server monitors a particular network port and records metadata such as source IP, destination IP, and data volume.
[0686] Step 2:
[0687] The server stores the collected communication records in a database. It takes the communication records obtained in step 1 as input and outputs them in a format that allows for organized and efficient management. Specifically, the server uses database software to index the data, making it readily accessible.
[0688] Step 3:
[0689] The server preprocesses the stored communication records. It takes records from the database as input and obtains standardized data suitable for analysis as output. Specifically, the server removes unnecessary noise and unifies all data entries into a standard format.
[0690] Step 4:
[0691] The server analyzes preprocessed data using a machine learning model. It receives standardized data from step 3 as input and generates anomaly detection results as output. The server uses libraries such as TensorFlow and PyTorch to compare the data with normal communication patterns and identify events that have been marked as anomalies.
[0692] Step 5:
[0693] The generating AI creates an alert when an anomaly is detected. It uses the anomaly detection results from step 4 as input and generates an alert message in natural language as output. Specifically, the generating AI understands the nature of the anomaly and constructs a specific message such as, "An attempt was made to access the system from a suspicious IP address."
[0694] Step 6:
[0695] The device notifies the user of the generated alert. It receives the alert message generated in step 5 as input and outputs it directly to the user. Specifically, the device sends an alert via a pop-up notification or email so that the user can quickly understand the situation.
[0696] Step 7:
[0697] The server updates and self-learns machine learning models using historical incident data. It utilizes previously collected incident data as input to train and output new models. Specifically, the server updates the dataset to the latest state through periodic batch processing, improving the model's predictive accuracy.
[0698] Step 8:
[0699] Users monitor the network's security status in real time through a dashboard. They receive the latest security information sent from the server as input and obtain visualized information as output. Specifically, users can view past incident history and real-time threat levels on the dashboard and develop necessary countermeasures.
[0700] (Application Example 1)
[0701] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".
[0702] In today's network environments, there is a need to quickly detect abnormal communications and notify users of appropriate warnings. However, many current systems have low accuracy in anomaly detection, leading to delayed warnings and false alarms. Furthermore, they lack sufficient mechanisms to learn from past incidents and improve analysis accuracy in order to reduce the burden on administrators. To solve this problem, a system is needed that can improve the accuracy of anomaly detection and provide rapid user notifications.
[0703] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.
[0704] In this invention, the server includes means for storing and performing initial processing of communication information obtained from a data collection device, detection means for analyzing the communication information to detect anomalies, and means for generating warnings based on the detected anomalies and notifying mobile terminals. This makes it possible to quickly and accurately detect abnormal communications and immediately notify users. Furthermore, by visualizing the communication information and warnings and creating reports, administrators can easily grasp the security of the network and utilize this information for long-term security analysis.
[0705] A "data collection device" is a device used to acquire communication information from various devices within a network.
[0706] "Communication information" refers to the records and data of all communications that take place within a network.
[0707] "Initial processing" refers to pre-processing to format the collected communication information into a form suitable for analysis.
[0708] "Detection means" refers to methods for analyzing collected communication information and identifying anomalies.
[0709] A "warning" is information or a message used to notify the user of a detected anomaly.
[0710] "Mobile devices" refer to portable communication devices such as smartphones and tablets.
[0711] A "report" is a document that visualizes the security of a network, created based on communication information and anomaly detection results.
[0712] "Visualization" refers to the process of displaying data and information in an easy-to-understand manner using graphs and diagrams.
[0713] "Self-learning methods" refer to techniques that utilize machine learning models to continuously improve analytical accuracy based on past data.
[0714] The system implementing this invention mainly consists of a server and a mobile terminal. The server collects communication information from each device in the network through a data collection device. This communication information is stored in a database and becomes the subject of analysis. Subsequently, the server performs initial processing such as standardization and noise reduction, and uses machine learning models to perform analysis to identify deviations from normal communication patterns.
[0715] If an anomaly is detected, the server uses a generative AI to create a warning in natural language. This warning is then pushed to the mobile device, allowing the user to take immediate action. Specifically, an alert such as "A new device has connected to the network. Please check for potential unauthorized access" is sent.
[0716] The server also handles report generation, which includes anomaly detection results and a visual representation of the overall communication status. Users can use this to periodically assess network security and help develop long-term security strategies.
[0717] To implement this system, the server program will use Python and machine learning libraries such as Scikit-learn and TensorFlow, while the mobile device application will be developed using React Native. Specific processing steps include data collection, preprocessing, policy-based anomaly detection, natural language generation, and user notification. An example of a prompt message might be, "A new anomalous communication has been detected on the network. What action should be taken?"
[0718] The flow of a specific process in Application Example 1 will be explained using Figure 12.
[0719] Step 1:
[0720] The server acquires communication information from each device in the network using data collection devices. The input at this stage is all data transmitted through the network. The server stores this data in a database, making it available as foundational data for subsequent processing. Specifically, it collects packet information and connection logs sent from each device.
[0721] Step 2:
[0722] The server performs initial processing to standardize the collected communication information and remove noise and unnecessary data. The input is the raw communication information obtained in the previous step, and the output is data in a clean format suitable for anomaly detection. This processing reduces data variability and creates a consistent dataset.
[0723] Step 3:
[0724] The server uses machine learning models to analyze the data after initial processing and identify deviations from normal communication patterns. The input is the initially processed communication data, and the output is the data points considered anomalous. Specifically, anomaly detection is performed using support vector machines or neural networks.
[0725] Step 4:
[0726] If an anomaly is detected, the server uses a generative AI to create a warning in natural language. In this step, the AI generates an appropriate warning message using the prompt "Abnormal communication has been detected. How will you respond?". The input is the detected anomaly data, and the output is a warning message in natural language.
[0727] Step 5:
[0728] The server notifies mobile devices of the generated warnings. The input is the warning message created by the generation AI, and the output is the notification displayed on the user's smartphone or tablet. The server uses a push notification system to quickly deliver the information to the user.
[0729] Step 6:
[0730] The server generates and visualizes reports based on communication information and anomaly detection results. Inputs are communication information and anomaly detection results, while outputs are visualized data and reports on a user-accessible dashboard. These reports include graphs and charts illustrating historical trends and network security.
[0731] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.
[0732] The system according to the present invention aims not only to detect anomalies in network communications in real time and respond appropriately, but also to optimize the interface while considering the user's emotional state. By incorporating an emotion engine, this system offers a novel approach to improving the user experience.
[0733] The server collects communication logs in real time from each device on the network. This data is preprocessed for analysis and sent to an anomaly detection algorithm. Any detected anomalies are generated as warning messages in natural language using generative artificial intelligence and notified to the user.
[0734] During this process, the device uses an emotion engine to analyze the user's current emotional state. The emotion engine evaluates the user's stress level and emotional tendencies based on their past response patterns and operation history. Based on this information, the device can dynamically change the content and display method of notifications. Specifically, if high stress levels are detected, the device will display a message in a calmer tone and add detailed support information.
[0735] For example, if the emotion engine determines that a user has received frequent alerts in the past few hours and is under stress, the next alert message sent will be in the form of, "A new threat has been detected, but we are already taking action. Please rest assured." In this way, the emotion engine is designed to make notifications more acceptable and reduce the user's psychological burden.
[0736] Furthermore, through self-learning mechanisms, the system can continuously learn from these emotional feedbacks, improving the accuracy of future anomaly detection and user responses. Users can monitor and manage the network's security status in real time through the dashboard and analyze areas for long-term improvement through regular reports.
[0737] In this way, the system of the present invention enhances the efficiency of security management and provides a user-friendly interface.
[0738] The following describes the processing flow.
[0739] Step 1:
[0740] The server collects communication logs from each device on the network and stores them in a database. This data collection is performed in real time, and the data is continuously updated.
[0741] Step 2:
[0742] The server preprocesses the collected data, removing noise and preparing it for anomaly detection algorithms. Preprocessing includes data standardization and filtering irrelevant information.
[0743] Step 3:
[0744] The server uses pre-processed data to run an anomaly detection algorithm. This algorithm analyzes communication patterns and identifies trends that deviate from the normal range.
[0745] Step 4:
[0746] If an anomaly is detected, the server uses generative artificial intelligence to generate a warning message in natural language. This message briefly explains the nature of the anomaly and its potential impact.
[0747] Step 5:
[0748] Before displaying a warning message to the user, the device uses an emotion engine to assess the user's emotional state. This assessment is based on the user's current actions and past responses.
[0749] Step 6:
[0750] Based on the evaluation results of the emotion engine, the device adjusts the content and tone of warning messages. For example, if the user is stressed, a message with a more polite and calm tone will be selected.
[0751] Step 7:
[0752] Users receive a tailored warning message on their device and review its contents. Based on the message, users can take appropriate action.
[0753] Step 8:
[0754] The server collects user reactions and emotional feedback, and uses its self-learning function to learn from this data and apply it to future anomaly detection. This process allows the system to improve its performance over time.
[0755] Step 9:
[0756] Users can monitor and manage the overall security status of the network and the history of past incidents in real time through the dashboard. Regular reports enable trend analysis and long-term security assessments.
[0757] (Example 2)
[0758] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".
[0759] In today's network environment, it is crucial to quickly detect anomalies in communication data and appropriately deliver warnings. However, conventional systems do not take into account the user's emotional state, and notifications can potentially cause stress to users. Furthermore, there is room for improvement in the accuracy of anomaly detection and the naturalness of warning generation. To solve this problem, a notification system optimized based on user emotions is necessary.
[0760] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.
[0761] In this invention, the server includes means for storing and pre-processing communication data acquired from an information processing device, means for analyzing the communication data to detect anomalies, means for analyzing user emotional information, and means for generating warnings based on anomalies in natural language using generative artificial intelligence and notifying the user. This enables anomaly notifications that take into account the user's emotional state, thereby reducing psychological burden while ensuring network security.
[0762] An "information processing device" is a digital device that has the function of storing and processing communication data.
[0763] "Communication data" refers to a collection of information transmitted over a network.
[0764] "Preprocessing" is the process of shaping data and extracting necessary information for analysis or detection.
[0765] "Anomaly detection" is the process of identifying and pinpointing deviations from standard communication patterns.
[0766] "User emotional information" refers to data about a user's mental state and emotional tendencies.
[0767] "Generative artificial intelligence" is an AI technology that has the ability to generate natural language based on a given prompt.
[0768] "Notification in natural language" is the process of transmitting information in a language that is easy for humans to understand.
[0769] "Visualization" is the process of representing data and information visually to make them easier to understand.
[0770] A "report" is a document that systematically summarizes the results of data analysis and the details of activities.
[0771] "Self-learning function" is a technology that allows a system to improve its own performance based on past data and experience.
[0772] The system in this invention efficiently monitors communication data within a network and detects anomalies to provide appropriate warnings to the user. The server first collects communication data in real time from the information processing device. In this process, network monitoring software is used to acquire and store a large number of data packets. The collected data is preprocessed using data processing libraries such as Pandas to prepare it for anomaly detection.
[0773] Next, the server leverages machine learning libraries such as Scikit-learn to apply anomaly detection algorithms. This allows it to identify anomalies that deviate from normal communication patterns. If an anomaly is detected, a generative artificial intelligence model, such as GPT, is used to generate a warning message in natural language based on the detected anomaly. This process includes a mechanism that automatically generates specific warning content based on the input of prompts.
[0774] The device further analyzes the user's emotional information using libraries such as Emotion Detection. Based on the user's past operation history and response patterns, it evaluates their emotional state and determines their stress level. Based on this data, the server optimizes the generated warnings to match the user's emotional state. For example, if it is determined that the user is stressed, a message in a calm tone will be presented, such as, "A new threat has been detected, but we are already taking measures to address it. Please rest assured."
[0775] An example of a prompt message might be, "Generate a reassuring warning message when the user is under stress." In this way, the system reduces the user's psychological burden while enhancing real-time network security.
[0776] The flow of the specific processing in Example 2 will be explained using Figure 13.
[0777] Step 1:
[0778] The server collects communication data in real time from the information processing device. It receives packet data from the communication network as input and outputs it in the form of data stored in a database. This operation requires the accurate collection of large amounts of data using a communication packet capture tool.
[0779] Step 2:
[0780] The server preprocesses the collected communication data. Using the raw data stored as input, it removes noise through data cleansing and extracts features necessary for anomaly detection. The output is a structured dataset, and data preprocessing is performed using the Pandas library.
[0781] Step 3:
[0782] The server performs anomaly detection using pre-processed data. The input is a formatted dataset that is analyzed by machine learning algorithms. The output is a list of detected anomaly events. Specifically, algorithms such as Scikit-learn's Isolation Forest are used to identify deviations from standard patterns.
[0783] Step 4:
[0784] The server generates warning messages based on anomalies using a generative AI model. It receives detected anomaly events as input and outputs natural language warning messages via prompts. A model like GPT is used to generate messages that correspond to the nature of the anomaly.
[0785] Step 5:
[0786] The device analyzes the user's emotional information. It receives the user's past operation history and real-time emotional data as input, and uses an Emotion Detection library to evaluate the emotional state. The output is evaluation data regarding stress levels and emotional tendencies, which is used to analyze the user's state.
[0787] Step 6:
[0788] The device optimizes notification content and method based on analyzed emotional information. The input is the previously generated emotional evaluation data, which is combined with the generated warning message to optimize and output notifications in a way that suits the user's psychological state. If the user is stressed, the system will display messages with calmer language.
[0789] (Application Example 2)
[0790] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".
[0791] In today's network environment, ensuring the security of communications is extremely important. However, it is difficult not only to detect anomalies but also to transmit information appropriately while minimizing the impact on users. In particular, uniform notifications that do not take into account the user's emotional state can cause unnecessary stress. To solve this problem, there is a need for a system that provides customized notification methods that take into account the user's emotional state.
[0792] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means.
[0793] In this invention, the server includes means for storing and preprocessing communication records acquired from data acquisition means, means for detecting anomalies by analyzing the communication records, means for analyzing the user's emotional state, means for dynamically changing the content and display method of warnings based on the results of the emotion analysis means, means for self-learning to improve the accuracy of analysis and detection using a learning algorithm, and means for visualizing the communication records and warnings and generating a report. This makes it possible to detect anomalies and provide accurate and psychologically less burdensome notifications that take into consideration the user's emotions.
[0794] "Data acquisition means" refers to an element that has the function of collecting and storing communication records from devices on a network.
[0795] "Means for pre-processing" refers to an element equipped with processing functions that prepare the collected communication records for analysis.
[0796] An "anomaly detection means" is an element that analyzes communication records and has the function of detecting deviations from normal patterns.
[0797] "Means for generating and presenting warnings" refers to elements that create and display warning messages in natural language to the user based on detected anomalies.
[0798] An "emotion analysis tool" is an element that has the function of evaluating the user's emotional state and reflecting that information in the method of communication notifications.
[0799] A "dynamically changing mechanism" refers to an element that allows for the appropriate adjustment of the notification format and content based on the user's emotional state.
[0800] A "self-learning mechanism" is an element that has the function of continuously improving the accuracy of analysis and anomaly detection based on past data and user emotional feedback.
[0801] "Means for visualization and report generation" refers to elements that have the functionality to organize communication records and generated warnings as graphs and reports, and present them to users in an easy-to-understand manner.
[0802] This invention relates to a system that analyzes communication records collected over a network in real time to detect anomalies and provide notifications to users based on their emotions. The hardware used to implement this system includes a network-enabled server and user terminals (e.g., smartphones and smart glasses).
[0803] The server has data acquisition means to collect communication records from devices on the network. The collected data is preprocessed and then analyzed using anomaly detection means. If an anomaly is detected, the server uses a generative AI model to generate a warning message in natural language. In this case, the generative AI model is given an example prompt: "Consider the user's emotional state and express the security alert in a calm tone."
[0804] The device receives warnings sent from the server and analyzes the user's emotional state using emotion analysis tools. A dedicated emotion engine API is used for this emotion analysis. The content and display method of the warnings are dynamically adjusted according to the user's stress level, allowing the user to receive information with less psychological burden.
[0805] For example, if a user receives a warning about abnormal communication on their work smartphone, and the system determines that the user is experiencing high levels of stress, a calm message will be displayed stating, "A new anomaly has been detected, but we have already taken steps to resolve it, so please rest assured."
[0806] In this way, users can receive security-related information stress-free, and the system is designed to continuously improve the accuracy of anomaly detection and notification through self-learning mechanisms.
[0807] The flow of a specific process in Application Example 2 will be explained using Figure 14.
[0808] Step 1:
[0809] The server acquires communication logs from each device on the network. The input here is communication data from each device, and the output is the raw communication log collected by the server. This communication log is stored in a database and used in subsequent processing steps as needed.
[0810] Step 2:
[0811] The server performs preprocessing on the collected communication logs. The input is the raw communication log, and the output is the data after noise has been removed and normalized. Specifically, this involves filtering out unnecessary data and standardizing the format.
[0812] Step 3:
[0813] The server performs analysis to detect anomalies based on pre-processed communication records. The input is the pre-processed communication records, and the output is a list of detected anomalies. The server uses an anomaly detection algorithm to evaluate deviations in communication patterns and identify behavior that is different from normal.
[0814] Step 4:
[0815] When an anomaly is detected, the server uses a generative AI model to generate a warning message in natural language. The input here is information about the detected anomaly, and the output is the warning message to be presented to the user. Specifically, based on the anomaly data, the generative AI is instructed to generate a message using the prompt "Consider the user's emotional state and express the security alert in a calm tone."
[0816] Step 5:
[0817] The terminal receives a warning message sent from the server and analyzes the user's emotional state using emotion analysis tools. The input is the user's past response patterns and operation history, and the output is the evaluation result of the current emotional state. Specifically, it uses a dedicated emotion engine API to evaluate the stress level and passes that information to the next step.
[0818] Step 6:
[0819] The device uses the results of sentiment analysis to adjust how warning messages are displayed to the user. The input is the warning message and the results of the sentiment analysis, and the output is an optimized notification for the user. For example, if the device determines that the user is highly stressed, it will soften the tone of the message and add reassuring language.
[0820] The specific processing unit 290 transmits the result of the specific processing to the robot 414. In the robot 414, the control unit 46A causes the speaker 240 and the controlled object 443 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.
[0821] Data generation model 58 is a type of so-called generative AI (Artificial Intelligence). One example of data generation model 58 is ChatGPT (Internet search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[0822] In the above embodiment, an example was given in which the specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and the specific processing may also be performed by the robot 414.
[0823] Furthermore, the emotion identification model 59, acting as an emotion engine, may determine the user's emotion according to a specific mapping. Specifically, the emotion identification model 59 may determine the user's emotion according to a specific mapping, which is an emotion map (see Figure 9). Similarly, the emotion identification model 59 may also determine the robot's emotion, and the identification processing unit 290 may perform identification processing using the robot's emotion.
[0824] Figure 9 shows an emotion map 400 in which multiple emotions are mapped. In the emotion map 400, emotions are arranged in concentric circles radiating from the center. The closer to the center of the concentric circles, the more primitive the emotions are located. Further out of the concentric circles, emotions representing states and actions arising from mental states are located. Emotion is a concept that includes feelings and mental states. On the left side of the concentric circles, emotions that are generally generated from reactions occurring in the brain are located. On the right side of the concentric circles, emotions that are generally induced by situational judgment are located. Above and below the concentric circles, emotions that are generally generated from reactions occurring in the brain and induced by situational judgment are located. In addition, the emotion of "pleasure" is located on the upper side of the concentric circles, and the emotion of "displeasure" is located on the lower side. Thus, in the emotion map 400, multiple emotions are mapped based on the structure in which emotions arise, and emotions that are likely to occur simultaneously are mapped close together.
[0825] These emotions are distributed at the 3 o'clock position on the Emotion Map 400, and usually fluctuate between feelings of security and anxiety. In the right half of the Emotion Map 400, situational awareness takes precedence over internal feelings, resulting in a calm impression.
[0826] The inside of the Emotion Map 400 represents inner thoughts, while the outside represents actions. Therefore, the further you go from the outside of the Emotion Map 400, the more visible (expressed in actions) your emotions become.
[0827] Here, human emotions are based on various balances, such as posture and blood sugar levels. When these balances deviate from the ideal, it results in discomfort, and when they approach the ideal, it results in pleasure. Similarly, in robots, cars, motorcycles, etc., emotions can be created based on various balances, such as posture and battery level. When these balances deviate from the ideal, it results in discomfort, and when they approach the ideal, it results in pleasure. The emotion map can be generated, for example, based on Dr. Mitsuyoshi's emotion map (Research on a system for analyzing brain physiological signals of speech emotion recognition and emotion, Tokushima University, doctoral dissertation: https: / / ci.nii.ac.jp / naid / 500000375379). The left half of the emotion map contains emotions belonging to a region called "response," where sensation is dominant. The right half of the emotion map contains emotions belonging to a region called "situation," where situational awareness is dominant.
[0828] The emotion map defines two emotions that promote learning. One is the emotion around the middle of the negative "repentance" and "reflection" on the situation side. In other words, it is when the robot experiences negative emotions such as "I never want to feel this way again" or "I don't want to be scolded again." The other is the emotion around the positive "desire" on the reaction side. In other words, it is when the robot has positive feelings such as "I want more" or "I want to know more."
[0829] The emotion identification model 59 inputs user input into a pre-trained neural network, obtains emotion values representing each emotion shown in the emotion map 400, and determines the user's emotion. This neural network is pre-trained based on multiple training data sets, which are combinations of user input and emotion values representing each emotion shown in the emotion map 400. Furthermore, this neural network is trained so that emotions located close together have similar values, as shown in the emotion map 900 in Figure 10. Figure 10 shows an example where multiple emotions such as "reassured," "calm," and "confident" have similar emotion values.
[0830] The above description primarily focuses on the functions of the data processing device 12 in relation to this disclosure. However, the system related to this disclosure is not necessarily implemented on a server. The system related to this disclosure may be implemented as a general information processing system. This disclosure may be implemented, for example, as a software program that runs on a personal computer or as an application that runs on a smartphone. The method related to this disclosure may be provided to users in SaaS (Software as a Service) format.
[0831] In the above embodiment, an example was given in which a specific process is performed by a single computer 22. However, the technology of this disclosure is not limited thereto, and a distributed processing of the specific process may be performed by multiple computers, including computer 22. For example, a data generation model 58 may be provided in an external device of the data processing device 12, and the external device may generate data according to the input data.
[0832] In the above embodiment, an example was given in which the specific processing program 56 is stored in the storage 32, but the technology of this disclosure is not limited thereto. For example, the specific processing program 56 may be stored in a portable, computer-readable, non-temporary storage medium such as a USB (Universal Serial Bus) memory. The specific processing program 56 stored in the non-temporary storage medium is installed in the computer 22 of the data processing device 12. The processor 28 executes specific processing according to the specific processing program 56.
[0833] Alternatively, the specific processing program 56 may be stored in a storage device such as a server connected to the data processing device 12 via the network 54, and the specific processing program 56 may be downloaded and installed on the computer 22 in response to a request from the data processing device 12.
[0834] Furthermore, it is not necessary to store the entirety of the specific processing program 56 in a storage device such as a server connected to the data processing device 12 via the network 54, or to store the entirety of the specific processing program 56 in the storage 32; it is acceptable to store only a portion of the specific processing program 56.
[0835] The following types of processors can be used as hardware resources to perform specific processing. Examples of processors include a CPU, a general-purpose processor that functions as a hardware resource to perform specific processing by executing software, i.e., a program. Other examples of processors include dedicated electrical circuits, such as FPGAs (Field-Programmable Gate Arrays), PLDs (Programmable Logic Devices), or ASICs (Application Specific Integrated Circuits), which have circuit configurations specifically designed to perform specific processing. All of these processors have built-in or connected memory, and all of them perform specific processing by using memory.
[0836] The hardware resource that performs a specific process may consist of one of these various processors, or it may consist of a combination of two or more processors of the same or different types (for example, a combination of multiple FPGAs, or a combination of a CPU and an FPGA). Alternatively, the hardware resource that performs a specific process may consist of a single processor.
[0837] Examples of configurations using a single processor include, firstly, a configuration in which one or more CPUs and software are combined to form a single processor, and this processor functions as a hardware resource that performs a specific process. Secondly, there is a configuration using a processor that realizes the functions of the entire system, including multiple hardware resources that perform a specific process, on a single IC chip, as exemplified by SoCs (System-on-a-chip). In this way, a specific process is realized using one or more of the above types of processors as hardware resources.
[0838] Furthermore, the hardware structure of these various processors can more specifically utilize electrical circuits that combine circuit elements such as semiconductor devices. Also, the specific processing described above is merely an example. Therefore, it goes without saying that unnecessary steps can be deleted, new steps added, or the processing order rearranged, as long as it does not deviate from the main purpose.
[0839] The descriptions and illustrations presented above are detailed explanations of the technical aspects of this disclosure and are merely examples of the technical aspects. For example, the above descriptions of the structure, function, operation, and effect are examples of the structure, function, operation, and effect of the technical aspects of this disclosure. Therefore, it goes without saying that you may delete unnecessary parts, add new elements, or replace elements in the descriptions and illustrations presented above, as long as you do not deviate from the essence of the technical aspects of this disclosure. Furthermore, in order to avoid confusion and facilitate understanding of the technical aspects of this disclosure, explanations of common technical knowledge and the like that do not require special explanation to enable the implementation of the technical aspects of this disclosure have been omitted from the descriptions and illustrations presented above.
[0840] All documents, patent applications, and technical standards described herein are incorporated by reference to the same extent as if each individual document, patent application, and technical standard were specifically and individually noted to be incorporated by reference.
[0841] The following is further disclosed regarding the embodiments described above.
[0842] (Claim 1)
[0843] A means for storing and pre-processing communication records acquired from a data collection device,
[0844] A detection means for analyzing the communication record to detect anomalies,
[0845] A means for generating and presenting a warning based on the detected anomaly,
[0846] A self-learning method that improves the accuracy of analysis and detection using a learning model,
[0847] A means for visualizing the aforementioned communication records and warnings and generating a report,
[0848] A system that includes this.
[0849] (Claim 2)
[0850] The system according to claim 1, characterized in that it identifies a deviation from the normal communication pattern when detecting an anomaly.
[0851] (Claim 3)
[0852] The system according to claim 1, characterized in that it uses generative artificial intelligence to provide notifications in natural language when generating warnings.
[0853] "Example 1"
[0854] (Claim 1)
[0855] A means for storing and pre-processing data records acquired from an information collection device,
[0856] An analysis means for analyzing the data record to detect anomalies,
[0857] A means of generating an alarm based on detected anomalies and notifying the user,
[0858] A self-learning method that improves the accuracy of analysis and detection using machine learning algorithms,
[0859] A means for visualizing the aforementioned data records and alarms and generating a report,
[0860] A visualization method that enables real-time monitoring,
[0861] A system that includes this.
[0862] (Claim 2)
[0863] The system according to claim 1, characterized in that it identifies deviations from normal data patterns when detecting an anomaly.
[0864] (Claim 3)
[0865] The system according to claim 1, characterized in that it uses automated artificial intelligence to provide notifications in natural language when generating alarms.
[0866] "Application Example 1"
[0867] (Claim 1)
[0868] A means for storing and performing initial processing on communication information obtained from a data acquisition device,
[0869] A detection means for analyzing the communication information and detecting anomalies,
[0870] A means for generating and presenting a warning based on the detected anomaly,
[0871] A self-learning method that improves the accuracy of analysis and detection using machine learning models,
[0872] A means for visualizing the aforementioned communication information and warnings and for creating a report,
[0873] A means of notifying mobile terminals when an anomaly is detected in the communication network,
[0874] A system that includes this.
[0875] (Claim 2)
[0876] The system according to claim 1, characterized in that, when detecting an anomaly, it identifies a deviation from the normal communication pattern and transmits the detected anomaly to a mobile terminal.
[0877] (Claim 3)
[0878] The system according to claim 1, characterized in that when generating a warning, it uses generative artificial intelligence to create a notification in natural language and sends it to a mobile terminal.
[0879] "Example 2 of combining an emotion engine"
[0880] (Claim 1)
[0881] A means for storing and pre-processing communication data acquired from an information processing device,
[0882] A means for analyzing the communication data to detect anomalies,
[0883] Methods for analyzing user sentiment information,
[0884] A means of generating anomaly-based warnings in natural language using generative artificial intelligence and notifying the user,
[0885] A means for dynamically optimizing notification content and methods based on user sentiment information,
[0886] A means to improve the accuracy of analysis and detection through self-learning function,
[0887] A means for visualizing the aforementioned communication data and warnings and generating a report,
[0888] A system that includes this.
[0889] (Claim 2)
[0890] The system according to claim 1, characterized in that it identifies a deviation from a standard communication pattern when detecting an anomaly.
[0891] (Claim 3)
[0892] The system according to claim 1, characterized in that when generating a warning, it uses generative artificial intelligence to provide a natural language notification based on a prompt sentence.
[0893] "Application example 2 when combining with an emotional engine"
[0894] (Claim 1)
[0895] A means for storing and pre-processing communication records obtained from a data acquisition means,
[0896] An anomaly detection means for analyzing the communication record to detect anomalies,
[0897] A means for generating and presenting a warning based on the detected anomaly,
[0898] A means of analyzing the emotional state of a user,
[0899] A means for dynamically changing the content and display method of a warning based on the results of an emotion analysis method,
[0900] A self-learning method that improves the accuracy of analysis and detection using a learning algorithm,
[0901] A means for visualizing the aforementioned communication records and warnings and generating a report,
[0902] A system that includes this.
[0903] (Claim 2)
[0904] The system according to claim 1, characterized in that it identifies a deviation from the normal communication pattern when detecting an anomaly.
[0905] (Claim 3)
[0906] The system according to claim 1, characterized in that when generating a warning, it uses a generation AI model to provide notification in natural language and uses a prompt sentence. [Explanation of Symbols]
[0907] 10, 210, 310, 410 Data Processing Systems 12 Data Processing Devices 14 Smart Devices 214 Smart Glasses 314 Headset-type terminal 414 Robots< / url:> < / url:> < / url:> < / url:>
Claims
1. A means for storing and performing initial processing on communication information obtained from a data acquisition device, A detection means for analyzing the communication information and detecting anomalies, A means for generating and presenting a warning based on the detected anomaly, A self-learning method that improves the accuracy of analysis and detection using machine learning models, A means for visualizing the aforementioned communication information and warnings and for creating a report, A means of notifying mobile terminals when an anomaly is detected in the communication network, A system that includes this.
2. The system according to claim 1, characterized in that, when detecting an anomaly, it identifies a deviation from the normal communication pattern and transmits the detected anomaly to a mobile terminal.
3. The system according to claim 1, characterized in that when generating a warning, it uses generative artificial intelligence to create a notification in natural language and sends it to a mobile terminal.
Citation Information
Patent Citations
Persona chatbot control method and system
JP2022180282A