system
The system addresses the challenge of limited resources in SMEs by integrating and preprocessing network and sensor data to detect threats and propose countermeasures, enhancing security response efficiency.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- SOFTBANK GROUP CORP
- Filing Date
- 2024-12-12
- Publication Date
- 2026-06-24
Smart Images

Figure 2026103544000001_ABST
Abstract
Description
Technical Field
[0001] The technology of the present disclosure relates to a system.
Background Art
[0002] Patent Document 1 discloses a method for controlling a persona chatbot, which is performed by at least one processor, the method including steps of receiving a user utterance, adding the user utterance to a prompt including an instruction sentence related to an explanation of a character of the chatbot, encoding the prompt, and inputting the encoded prompt into a language model to generate a chatbot utterance as a response to the user utterance.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] In modern times, many enterprises are exposed to the threat of cyberattacks. In particular, small and medium-sized enterprises have difficulty taking advanced security measures due to budget and personnel constraints. Therefore, it is required to effectively and quickly detect and respond to network and physical security threats. Furthermore, many existing security systems lack the ability to integrate multiple platforms and data types, which reduces the accuracy and efficiency of threat detection.
Means for Solving the Problems
[0005] This invention provides a system for collecting, integrating, and preprocessing network logs and sensor data, and includes a function to detect anomalies using generative models and machine learning algorithms based on that data. When an anomaly is detected, it automatically generates an alert and proposes appropriate countermeasures, enabling effective threat response even in environments with insufficient manpower. Furthermore, it has the function to execute specific countermeasures such as blocking network segments and locking specific user accounts, and it is possible to continuously improve the model based on feedback to improve the accuracy of future responses.
[0006] A "network log" is a record of communication activity within a computer network, containing detailed information including traffic, connections, errors, and security events.
[0007] "Sensor data" refers to information obtained from sensors that detect changes in the physical environment, and includes variables such as temperature, motion, and light.
[0008] "Integration" refers to combining data of different formats and types into a single system or an analyzable format.
[0009] "Preprocessing" is the process of organizing data, removing unnecessary information, and converting it into a format suitable for analysis before performing data analysis.
[0010] A "generative model" is an algorithm that uses artificial intelligence technology to generate new data or patterns from existing data.
[0011] A "machine learning algorithm" is a set of mathematical methods and algorithms that allow a computer to learn from data and perform predictions and classifications.
[0012] Anomaly detection is the process of identifying irregular data or behavior that deviates from normal patterns and evaluating whether it may be a security threat or an error.
[0013] An "alert" is a notification or warning signal issued by a system when it detects an abnormal situation or an event that warrants a warning.
[0014] A "countermeasure" is a plan of action or set of measures to deal with a specific problem or threat.
[0015] "Feedback" is the cycle of information that provides information about the results and effects on a system or process, and uses that information to make further improvements or adjustments. [Brief explanation of the drawing]
[0016] [Figure 1] This is a conceptual diagram showing an example of the configuration of a data processing system according to the first embodiment. [Figure 2] This is a conceptual diagram showing an example of the essential functions of the data processing device and smart device according to the first embodiment. [Figure 3] This is a conceptual diagram showing an example of the configuration of a data processing system according to the second embodiment. [Figure 4] This is a conceptual diagram showing an example of the main functions of a data processing device and smart glasses according to the second embodiment. [Figure 5] This is a conceptual diagram showing an example of the configuration of a data processing system according to the third embodiment. [Figure 6] This is a conceptual diagram showing an example of the main functions of a data processing device and a headset-type terminal according to the third embodiment. [Figure 7] This is a conceptual diagram showing an example of the configuration of a data processing system according to the fourth embodiment. [Figure 8] This is a conceptual diagram showing an example of the main functions of a data processing device and a robot according to the fourth embodiment. [Figure 9] This shows an emotion map where multiple emotions are mapped. [Figure 10] This shows an emotion map where multiple emotions are mapped. [Figure 11] This is a sequence diagram showing the processing flow of the data processing system in Example 1. [Figure 12] It is a sequence diagram showing the processing flow of the data processing system in Application Example 1. [Figure 13] It is a sequence diagram showing the processing flow of the data processing system in Embodiment 2 when the emotion engine is combined. [Figure 14] It is a sequence diagram showing the processing flow of the data processing system in Application Example 2 when the emotion engine is combined.
Mode for Carrying Out the Invention
[0017] Hereinafter, an example of an embodiment of the system according to the technology of the present disclosure will be described with reference to the accompanying drawings.
[0018] First, the language used in the following description will be explained.
[0019] In the following embodiments, the numbered processor (hereinafter simply referred to as "processor") may be a single arithmetic unit or a combination of multiple arithmetic units. Also, the processor may be a single type of arithmetic unit or a combination of multiple types of arithmetic units. Examples of arithmetic units include a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), a GPGPU (General-Purpose computing on Graphics Processing Units), an APU (Accelerated Processing Unit), and the like.
[0020] In the following embodiments, the numbered RAM (Random Access Memory) is a memory in which information is temporarily stored and is used as a work memory by the processor.
[0021] In the following embodiments, the signed storage is one or more non-volatile storage devices that store various programs and various parameters. Examples of non-volatile storage devices include flash memory (SSD (Solid State Drive)), magnetic disks (e.g., hard disks), or magnetic tapes.
[0022] In the following embodiments, the signed communication interface (I / F) is an interface that includes a communication processor and an antenna, etc. The communication interface manages communication between multiple computers. Examples of communication standards applicable to the communication interface include wireless communication standards such as 5G (5th Generation Mobile Communication System), Wi-Fi (registered trademark), or Bluetooth (registered trademark).
[0023] In the following embodiments, "A and / or B" is synonymous with "at least one of A and B." That is, "A and / or B" means that it may be A alone, or B alone, or a combination of A and B. Furthermore, in this specification, the same concept as "A and / or B" applies when expressing three or more things linked by "and / or."
[0024] [First Embodiment]
[0025] Figure 1 shows an example of the configuration of the data processing system 10 according to the first embodiment.
[0026] As shown in Figure 1, the data processing system 10 includes a data processing device 12 and a smart device 14. An example of the data processing device 12 is a server.
[0027] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0028] The smart device 14 comprises a computer 36, a reception device 38, an output device 40, a camera 42, and a communication interface 44. The computer 36 comprises a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The reception device 38, output device 40, and camera 42 are also connected to the bus 52.
[0029] The reception device 38 is equipped with a touch panel 38A and a microphone 38B, etc., and receives user input. The touch panel 38A receives user input by detecting contact with an object (e.g., a pen or finger). The microphone 38B receives user input by detecting the user's voice. The control unit 46A transmits data indicating the user input received by the touch panel 38A and microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the data indicating the user input.
[0030] The output device 40 includes a display 40A and a speaker 40B, and presents data to the user 20 by outputting the data in a form perceptible to the user 20 (e.g., audio and / or text). The display 40A displays visible information such as text and images according to instructions from the processor 46. The speaker 40B outputs audio according to instructions from the processor 46. The camera 42 is a small digital camera equipped with an optical system such as a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor.
[0031] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various types of information between processor 46 and processor 28 via network 54.
[0032] Figure 2 shows an example of the main functions of the data processing device 12 and the smart device 14.
[0033] As shown in Figure 2, in the data processing device 12, a specific processing is performed by the processor 28. A specific processing program 56 is stored in the storage 32. The specific processing program 56 is an example of a "program" related to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 according to the specific processing program 56 executed on the RAM 30.
[0034] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[0035] In the smart device 14, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The reception output program 60 is used in conjunction with a specific processing program 56 by the data processing system 10. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.
[0036] Next, the specific processing performed by the specific processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the smart device 14 as the "terminal".
[0037] The system according to the present invention is designed to detect threats in network and physical environments in real time and to quickly propose countermeasures. An example of this system is shown below.
[0038] The server collects network logs from devices located within the company's network. This includes communication records from routers, firewalls, and various network devices. It also acquires sensor data from sensors installed in the physical environment, such as surveillance cameras and door sensors.
[0039] After the data is collected, the server performs a process to integrate it. Because the data is in different formats depending on the source, it is converted to a unified format. For example, the server processes video frames from surveillance cameras as analyzable image data, and network logs are converted to JSON format.
[0040] Next, the integrated data is preprocessed. Preprocessing includes removing noisy data, imputing missing data, and normalizing the data. This improves the accuracy of anomaly detection.
[0041] During the analysis phase, the server uses generative models and machine learning algorithms to detect anomalies. This includes a mechanism where an AI model, trained on normal operating patterns, is used to detect suspicious behavior or abnormal patterns, and the algorithm reacts accordingly.
[0042] If an anomaly is detected, the server immediately generates an alert and sends a notification to the terminals of users and security personnel. Notifications are sent via email, SMS, and a dedicated management dashboard to enable a swift response in emergencies.
[0043] Finally, the server can automatically generate and present countermeasures for specific threats. For example, if excessive or unauthorized access is detected, it can offer options to block the relevant network segment and temporarily lock the user accounts involved. It can also stream security camera footage to monitors' terminals to quickly assess the situation on-site.
[0044] In this way, the present invention enables effective and automated security measures to be implemented, particularly in small and medium-sized enterprises that have constraints on budget and personnel.
[0045] The following describes the processing flow.
[0046] Step 1:
[0047] The server collects data from various network devices and sensors within the enterprise. This includes network logs from routers and switches, video streams from surveillance cameras, and status information from door sensors. The data is acquired in real time and stored in storage.
[0048] Step 2:
[0049] The server initiates a process to consolidate the collected data into a single format. Network logs are stored in a temporary buffer and then converted to CSV format. Surveillance camera footage is converted to a format usable for image recognition (e.g., JPEG). This ensures consistency across different data sources.
[0050] Step 3:
[0051] The server performs preprocessing. This step involves cleaning the data, filling in missing data, and removing noise. For example, it removes unnecessary frames from surveillance camera footage and dummy data from network logs. This enables highly accurate analysis.
[0052] Step 4:
[0053] The server applies generative models and machine learning algorithms to analyze the integrated and preprocessed data. Anomaly detection algorithms work to identify suspicious activity by identifying behavior that deviates from normal operating patterns. Here, anomalies are identified by comparing them to a baseline based on historical data.
[0054] Step 5:
[0055] When an anomaly is detected, the server generates an alert and sends a notification to the user's or designated person's terminal requesting immediate action. Notifications are delivered through various means (email, SMS, dashboard notifications, etc.), allowing for flexible selection depending on the situation.
[0056] Step 6:
[0057] The server automatically suggests countermeasures based on alerts, prompting a rapid response. Specific measures may include blocking the network segment causing the abnormal traffic or locking specific user accounts. If additional surveillance camera footage needs to be reviewed, the procedure for doing so is also provided.
[0058] These steps enable the system to target threats in real time and respond to security threats efficiently.
[0059] (Example 1)
[0060] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server," and the smart device 14 will be referred to as the "terminal."
[0061] In modern information systems, rapidly and accurately detecting and immediately responding to threats in network and physical environments is an increasingly critical challenge. Integrating information from various data sources, detecting anomalies in real time, and taking countermeasures requires automated, advanced systems.
[0062] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.
[0063] In this invention, the server includes means for obtaining communication logs from an information system and data from physical sensors, means for processing the communication logs and physical sensor data in a unified format, and means for utilizing a learning model and data analysis algorithm for identifying anomalies based on the processed information. This makes it possible to effectively detect threats in the network and physical environment and to take countermeasures autonomously.
[0064] An "information system" is a collection of foundational technologies for collecting, processing, storing, and distributing information.
[0065] A "communication log" is record data related to communication generated by network devices and applications.
[0066] A "physical sensor" is a device that measures changes in the physical environment and acquires that data.
[0067] "Processing in a unified format" refers to a method of standardizing data from different formats and converting it into a consistent format.
[0068] A "learning model" is a data analysis technique that analyzes and learns from data to detect patterns in order to solve a specific problem.
[0069] A "data analysis algorithm" is a set of computational procedures used to extract useful information from data and to make decisions or recommendations based on that information.
[0070] An "alarm" is a notification or warning signal generated when an anomaly is detected within a system.
[0071] "Countermeasures" refer to specific actions or solutions taken in response to an issue or problem that has arisen.
[0072] "Autonomously proposing solutions" refers to a process in which a system independently provides solutions based on pre-defined rules and algorithms.
[0073] This invention primarily relates to a security system for network and physical environments involving servers, terminals, and users. Specific embodiments of this system are described below.
[0074] The server collects communication logs from network devices within the information system and related data from deployed physical sensors. This system utilizes network routers, firewalls, surveillance cameras, door sensors, and other devices to acquire comprehensive and detailed data.
[0075] The server processes the collected data in a standardized format. For example, network logs are converted to JSON format, and video data from surveillance cameras is standardized as analyzable image data. Database systems and data analysis tools are used in the data conversion and processing process.
[0076] Next, the server uses the processed data to detect anomalies using a learning model and data analysis algorithms. The generative AI model has pre-learned normal operating patterns and can quickly identify deviations from them. This anomaly detection utilizes machine learning algorithms built in programming languages such as Python.
[0077] Furthermore, users can evaluate the system based on feedback from the anomaly detection algorithm and adjust parameters to improve accuracy.
[0078] If an anomaly is detected, the server immediately generates an alarm and sends a notification to the terminal. Notifications are sent via email, SMS, and a dedicated management dashboard. In addition, the server autonomously proposes countermeasures based on the detected anomaly. For example, excessive access can be addressed by blocking the network segment, and the related user accounts will be restricted at the same time.
[0079] As a concrete example of a prompt, by inputting the text "Please suggest ways to strengthen office security over the weekend and detect anomalies early" into the AI model, security measures can be generated.
[0080] This invention aims to automate and efficiently implement comprehensive security management, which is difficult for small businesses and individuals to manage manually.
[0081] The flow of the specific processing in Example 1 will be explained using Figure 11.
[0082] Step 1:
[0083] The server acquires data from network devices and physical sensors. Inputs include communication logs from routers and firewalls, as well as data from surveillance cameras and door sensors. The server periodically collects this data and stores it as an initial dataset.
[0084] Step 2:
[0085] The server converts the acquired data into a standardized format. The input consists of data in various formats; the server uses a database system to convert network logs into JSON format and surveillance camera footage into analyzable image data. The output is a standardized dataset.
[0086] Step 3:
[0087] The server preprocesses a unified dataset. The input is a standardized dataset, from which noise data is removed, missing data is inferred and imputed, and the data is normalized. The output is preprocessed data suitable for anomaly detection.
[0088] Step 4:
[0089] The server detects anomalies using pre-processed data. The input is pre-processed data, and the server uses generative AI models and machine learning algorithms to perform calculations that detect anomalies deviating from normal operation. The output is a list of detected anomalies.
[0090] Step 5:
[0091] When an anomaly is detected, the server generates an alarm and sends a notification to the terminal. The input is a list of anomalies, and the output is an anomaly notification email, SMS, or a warning on a dedicated dashboard. This allows the server to take emergency action.
[0092] Step 6:
[0093] The server generates and presents immediate countermeasures for detected anomalies. The input is the type of anomaly and its severity assessment. The server suggests defensive measures such as blocking specific network segments and temporarily locking suspicious user accounts. The output is the proposed countermeasures.
[0094] (Application Example 1)
[0095] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server," and the smart device 14 will be referred to as the "terminal."
[0096] Recent advancements in information technology have led to an increase in threats to internal corporate networks and physical environments. Small and medium-sized enterprises (SMEs) with limited resources are required to respond quickly and effectively to these threats, but a lack of personnel and budget poses a significant obstacle. Therefore, providing solutions that more efficiently detect threats, propose countermeasures, and enable remote control is crucial.
[0097] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.
[0098] In this invention, the server includes means for collecting network data and environmental data, means for integrating and preprocessing the network data and environmental data, and means for using generative models and machine learning algorithms for detecting anomalies based on the integrated and preprocessed data. This enables companies to automatically and quickly monitor threats, implement appropriate countermeasures, and perform effective security management remotely.
[0099] "Network data" refers to all communication information obtained from devices within a computer network. This includes the movement of data packets on the network and access logs.
[0100] "Environmental data" refers to information obtained from the physical environment. This includes things like video from surveillance cameras and data from door sensors (opening and closing).
[0101] "Means of aggregation" refers to a system for collecting and centralizing data from different sources. Servers fulfill this role.
[0102] "Means of integration and preprocessing" refers to the process of organizing and transforming data collected in different formats so that it can be analyzed.
[0103] A "generative model" refers to an algorithm designed to generate new information or patterns in data analysis.
[0104] A "machine learning algorithm" is a general term for methods that learn patterns from data and perform predictions and classifications based on that learning.
[0105] "Means for detecting abnormalities" refers to a system for automatically identifying behaviors or patterns that differ from normal conditions.
[0106] A "warning" refers to a notification or sign that alerts you when an anomaly is detected.
[0107] "Means of proposing countermeasures" refers to a function that suggests appropriate actions or procedures when an anomaly is detected.
[0108] "Means of remote control" refers to a system for operating and managing devices and systems from a physically distant location.
[0109] In this invention, the server first collects network data and environmental data. Network data includes access logs and packet data from communication devices, while environmental data includes surveillance camera footage and various sensor information. A server application using Django is used to collect this data.
[0110] Next, the server integrates and preprocesses the collected data. Because the data formats vary, the Pandas library is used to format the data and convert it into an analyzable form. This process includes noise reduction and data imputation. The integrated data is then subjected to anomaly detection using generative models and machine learning algorithms based on TENSORFLOW®.
[0111] If the server detects an anomaly, it immediately generates an alert and notifies the user's device. Notifications are sent via SMS or email using the Twilio API. Users can receive these notifications and quickly understand the situation and check necessary countermeasures through applications on their devices.
[0112] Furthermore, the server automatically suggests countermeasures. For example, if abnormal access is detected, it will recommend blocking the network portion or temporarily locking user accounts. In this case, users can remotely control the system through their terminals and actually implement the countermeasures.
[0113] As a concrete example, consider a scenario where an office door is opened or closed illegally at night. Such an anomaly is detected instantly, and a warning notification is sent to the user's smartphone. The user can then use the app to check the door's status and remotely lock it if necessary. This allows for a swift response.
[0114] An example of an input prompt for the generating AI model is the instruction, "Analyze the latest security logs and abnormal behavior patterns in the office, and suggest necessary countermeasures." Using this prompt, the system will generate the most appropriate countermeasures for the situation.
[0115] The flow of a specific process in Application Example 1 will be explained using Figure 12.
[0116] Step 1:
[0117] The server collects network and environmental data from network devices and physical sensors. This process involves inputting logs from routers and firewalls, as well as data from surveillance cameras and door sensors. The collected data is temporarily stored on the server in its raw form.
[0118] Step 2:
[0119] The server integrates the collected data and performs preprocessing using the Pandas library. The input is the raw data saved in step 1, where data format conversion, denoising, and missing data imputation are performed. The output is a normalized dataset.
[0120] Step 3:
[0121] The server analyzes the preprocessed data using TensorFlow's generative AI models and machine learning algorithms. The input for this step is a normalized dataset, which is then processed for anomaly detection. The output is the anomaly detection result.
[0122] Step 4:
[0123] If the server detects an anomaly, it uses the Twilio API to send a warning to the user's device. The input for this step is the anomaly detection result, and the output is a warning message via SMS or email.
[0124] Step 5:
[0125] The user reviews the warning received on their device, launches the application, and checks the suggested course of action. The input in this step is the warning message, and the output is access to an interface for the user to take action.
[0126] Step 6:
[0127] The server, in response to user requests, inputs prompt messages into an AI model that automatically generates appropriate countermeasures. The input is a prompt message such as "Please suggest countermeasures appropriate to the situation," and the output is a recommended countermeasure.
[0128] Step 7:
[0129] The user remotely controls the system via a terminal based on the suggested countermeasures. In this step, the input is the recommended countermeasure, and the output is the actual control action, such as temporarily shutting down the network or locking a door.
[0130] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.
[0131] This invention is a system that detects threats in network and physical environments in real time and proposes effective countermeasures that also take user emotions into consideration.
[0132] This system begins with a server collecting data from network devices and sensors within the enterprise. Once network logs and sensor data are recorded, the server integrates the data and performs preprocessing as needed. After preprocessing, the data is analyzed using generative models and machine learning algorithms for anomaly detection.
[0133] When an anomaly is detected, the server generates an alert and sends that information to the terminal of the relevant person in charge. A key feature of this invention is the involvement of an emotion engine in recognizing the user's emotional state when generating the alert. The emotion engine recognizes emotions from the user's behavior, facial expressions, and voice data, and understands the current situation of the user.
[0134] For example, if the system determines that a user is under stress, it will adjust the content of the alert notification to a calmer and more concise format. The suggested actions will also be flexibly modified based on the user's current emotions. If a significant threat is detected and the user is emotionally distressed, the system will simplify the details of the actions to encourage them to focus on the most important actions first.
[0135] Therefore, by considering the user's psychological state, the system can achieve efficient and effective security measures, going beyond mere technical solutions. This approach allows companies to achieve both automated security and a human-centered interface.
[0136] The following describes the processing flow.
[0137] Step 1:
[0138] The server collects data in real time from network devices and sensors. Network logs are received in a format that details each communication, and video data and event information are obtained from surveillance cameras and door sensors according to the situation.
[0139] Step 2:
[0140] The server integrates the collected data and converts it into a standard format. Network logs are organized into a consistent format, and video data is converted into image fragments suitable for analysis. This makes all data available on a common analysis platform.
[0141] Step 3:
[0142] The server analyzes preprocessed data using generative models and machine learning algorithms. It identifies patterns that deviate from normal behavior and detects suspicious activity. The machine learning algorithms evaluate the degree of anomaly based on learning from past data.
[0143] Step 4:
[0144] The server generates an alert when an anomaly is detected and uses an emotion engine to evaluate the user's emotional state. The emotion engine understands the user's current psychological state by analyzing factors such as voice tone, facial expression data, and input speed.
[0145] Step 5:
[0146] The server adjusts the wording of alerts based on the user's emotional state and sends notifications to the device. For example, if the user is in a state of anxiety, the alert message will be concise and clear, prioritizing and highlighting the necessary steps.
[0147] Step 6:
[0148] The server automatically suggests countermeasures based on detected anomalies. If the emotion engine determines that the user is feeling anxious, it will clearly present the first steps to take and then provide additional information in stages to help the user feel at ease.
[0149] Step 7:
[0150] Users will take appropriate action based on the alerts and suggested countermeasures they receive. Feedback on the progress of the response and the results after implementation will be sent to the server to contribute to system improvement.
[0151] (Example 2)
[0152] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server" and the smart device 14 as the "terminal".
[0153] Traditional security systems can detect network threats and issue warnings, but they lack the ability to suggest countermeasures that take into account the user's psychological state. As a result, warnings may not be taken seriously, leading to a decrease in the system's effectiveness. In particular, when users are emotionally distressed, appropriate countermeasures may not be provided, potentially creating security vulnerabilities.
[0154] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.
[0155] In this invention, the server includes means for collecting network data and sensor information, means for integrating and preprocessing the network data and sensor information, and means for using a generative AI model and machine learning algorithm for detecting anomalies based on the integrated and preprocessed information. This enables the automatic adjustment of warning content and suggestion of countermeasures according to the user's emotional state.
[0156] "Network data" refers to information related to packets and traffic transmitted and received within a communication system.
[0157] "Sensor information" refers to digital data acquired from the physical environment, including information such as temperature, humidity, and motion measured by sensor devices.
[0158] A "generative AI model" refers to an algorithm that uses artificial intelligence technology to generate and predict new data and patterns.
[0159] A "machine learning algorithm" refers to a series of computational methods used to learn rules and patterns from data and perform estimation and classification.
[0160] A "warning" refers to a message or signal that notifies the user of an anomaly or potential problem detected by the system.
[0161] An "emotion engine" refers to a technology that analyzes behavior, facial expressions, and voice data to identify a user's emotional state.
[0162] "User emotional state" refers to the user's psychological state or mood, and the factors that influence their normal actions and behaviors.
[0163] "Countermeasures" refer to specific actions or procedures proposed to address detected problems or anomalies.
[0164] This invention is a system that uses information acquired from corporate networks and sensors to detect threats in real time and provide response measures that take user emotions into consideration. Specifically, a server collects data from network devices and sensors and performs data integration and preprocessing. This is done using general network analysis tools and database software. Various machine learning libraries for anomaly detection are used as the generative AI model to be applied. Specific software includes open-source machine learning frameworks such as TensorFlow and PyTorch.
[0165] The server analyzes pre-processed data using a generative AI model and machine learning algorithms to detect anomalies. If an anomaly is detected, the server uses an emotion engine to recognize the user's emotional state from their facial expressions and voice data. The emotion engine utilizes an open-source emotion analysis library.
[0166] For example, when a server detects a large data transfer during non-business hours, it sends an alert to the terminal. However, if the emotion engine determines that the user is relaxed, it generates an alert in a polite and gentle tone. It then suggests the most appropriate course of action based on the user's emotional state.
[0167] A concrete example of a prompt might be: "Please begin the demonstration of the system that generates alert notifications considering the user's emotional state. Assuming the current emotional state is calm, please propose an action plan based on standard security protocols." By considering the user's emotions and providing the most appropriate security response in real time, the system's effectiveness can be enhanced.
[0168] The flow of the specific processing in Example 2 will be explained using Figure 13.
[0169] Step 1:
[0170] The server collects data from network devices and sensors within the enterprise. Inputs are network logs and sensor data, and output is integrated raw data. Specifically, it uses a data collector module to gather traffic and environmental data in real time.
[0171] Step 2:
[0172] The server integrates and preprocesses the collected raw data. The input is the integrated raw data, and the output is the preprocessed data. It performs noise reduction, format conversion, and missing value imputation to prepare the data for analysis. Specifically, it converts different data formats into a common historical database and sorts them chronologically.
[0173] Step 3:
[0174] The server performs anomaly detection based on pre-processed data. The input is pre-processed data, and the output is anomaly detection information. Generative AI models and machine learning algorithms are applied to analyze and identify abnormal patterns. Specifically, it detects unusual communication patterns and suspicious access from time-series data.
[0175] Step 4:
[0176] The server analyzes the user's emotions using an emotion engine when an anomaly is detected. The input is anomaly detection information and user behavior data, and the output is the user's emotional state. It analyzes voice data and facial expression data to evaluate the user's emotions. Specifically, it captures data in real time from cameras and microphones and performs evaluation using an emotion analysis library.
[0177] Step 5:
[0178] The server generates and sends a warning to the terminal, taking into account the user's emotional state. The input is the user's emotional state and anomaly detection information, while the output is an emotionally sensitive warning message. The server adjusts the content of the warning and notifies the user in the most appropriate format. Specifically, it sends a concise and reassuring warning to users experiencing high stress levels.
[0179] Step 6:
[0180] The user refers to and implements appropriate countermeasures based on the warning received. The input is the warning message, and the output is the countermeasures to be taken. The specific action plan is adjusted according to the user's emotional state. For example, if the user is upset, the action plan is simplified and priority actions are clearly indicated so that they can focus on the most important matters.
[0181] (Application Example 2)
[0182] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server," and the smart device 14 will be referred to as the "terminal."
[0183] In today's business environment, it is crucial to quickly detect and appropriately respond to threats from the network and physical environment. However, while traditional systems are specialized in threat detection, they cannot propose response measures that take into account the psychological state and emotions of users, which can lead to a decrease in the quality and efficiency of responses in emergencies. Furthermore, they may fail to adjust communication appropriately according to the emotional state of users, potentially amplifying stress.
[0184] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means.
[0185] In this invention, the server includes means for collecting network data and sensing device data, means for integrating and preprocessing the network data and sensing device data, and means for using generative models and machine learning techniques to detect anomalies based on the integrated and preprocessed data. This makes it possible to quickly detect threats and automatically propose flexible and effective countermeasures that take into account the user's emotional state.
[0186] "Network data" refers to the records and logs of information exchanged within a communication system, and is used for anomaly detection and communication analysis.
[0187] "Sensing device data" refers to information collected by sensors installed in the physical environment, and includes data used to detect temperature, movement, sound, and other similar phenomena.
[0188] A "generative model" refers to a mathematical framework for data analysis built using artificial intelligence to assist in anomaly detection.
[0189] "Machine learning methods" are algorithms that analyze large amounts of data, learn patterns, and then use them to make predictions and decisions.
[0190] "Emotional analysis methods" refer to technologies that identify emotional states from a user's facial expressions, voice, etc., and utilize artificial intelligence for analysis.
[0191] A "network segment" refers to a segment or part of a communication system that is managed individually and is a separate area designed to improve security and efficiency.
[0192] A "user account" is a record of information used to manage identification information and access rights associated with a specific user within the system.
[0193] An embodiment of this invention consists of a multi-functional server connected to a network and an end-user terminal.
[0194] The server first collects network data and sensor data. Data collection utilizes APIs and sensor technologies to obtain network communication logs and physical sensor outputs. This data is temporarily stored in a database on the server and preprocessed using Python. This preprocessing includes filtering and standardizing abnormal data. Libraries used include Pandas and NumPy for data processing.
[0195] After the data is preprocessed, the server analyzes the data using generative AI models and machine learning techniques for anomaly detection. Machine learning libraries such as TensorFlow and Scikit-learn are used to detect data anomalies in real time. Furthermore, OpenCV and SpeechRecognition are used to analyze image and audio data acquired from user terminals and perform sentiment analysis.
[0196] When a warning is issued from the server on the device, a notification tailored to the user's sentiment analysis results is sent. This reduces user stress while providing important threat information and countermeasures. This notification is displayed in a user-friendly format and can be monitored via a GUI developed in Python or a mobile application.
[0197] For example, if a minor threat is detected while the user is relaxed, the application will notify the user with calm language such as, "Please review and report if there are no issues." An example of a related prompt from a generative AI model would be, "A minor threat has been detected on the corporate network. If the user is currently relaxed, please create a notification in a calm tone."
[0198] This system aims to provide flexible and effective security measures that take into account the emotional state of the user.
[0199] The flow of a specific process in Application Example 2 will be explained using Figure 14.
[0200] Step 1:
[0201] The server collects communication logs from the network and acquires various sensor data from sensing devices. This data is stored as raw data in the server's database. The inputs are network logs and sensor data, and the output is storage in the server's database.
[0202] Step 2:
[0203] The server preprocesses the collected raw data. During this process, it uses the Pandas library to clean and standardize the data. Specifically, it performs operations such as imputing incomplete data, detecting and removing outliers, and scaling the data. The input is the raw data saved in step 1, and the output is the preprocessed structured data.
[0204] Step 3:
[0205] The server performs anomaly detection using a generated AI model based on pre-processed structured data. TensorFlow is used to identify anomaly patterns. The data is input to the model, and if an anomaly is detected, an alert is generated. The input is pre-processed data, and the output consists of the detected anomaly pattern and alert information.
[0206] Step 4:
[0207] The server receives user image and audio data acquired from the terminal and performs sentiment analysis. This analysis uses OpenCV and SpeechRecognition to identify the user's emotional state from their facial expressions and voice. The input is the user's real-time image and audio, and the output is the evaluation result of the user's emotional state.
[0208] Step 5:
[0209] The server integrates the results of anomaly detection and sentiment analysis to adjust the content of the alert notification sent to the user. Based on the sentiment analysis results, it changes the wording and level of detail of the alert. Specifically, if the user is stressed, the notification content is made concise and a gentle tone is used to alleviate tension. The input is the results of anomaly detection and sentiment analysis, and the output is the adjusted alert notification sent to the user.
[0210] Step 6:
[0211] The user's device displays alert notifications received from the server. This allows the user to understand the nature of the threat and recommended countermeasures. The display is done through a dedicated mobile or desktop app. The input is a pre-configured alert notification from the server, and the output is a user-friendly screen display.
[0212] The specific processing unit 290 transmits the result of the specific processing to the smart device 14. In the smart device 14, the control unit 46A causes the output device 40 to output the result of the specific processing. The microphone 38B acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.
[0213] Data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of data generation model 58 is ChatGPT (registered trademark) (Internet search).<URL: https: / / openai.com / blog / chatgpt> ), Gemini (registered trademark) (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[0214] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and the specific processing may also be performed by the smart device 14.
[0215] [Second Embodiment]
[0216] Figure 3 shows an example of the configuration of the data processing system 210 according to the second embodiment.
[0217] As shown in Figure 3, the data processing system 210 includes a data processing device 12 and smart glasses 214. An example of the data processing device 12 is a server.
[0218] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0219] The smart glasses 214 include a computer 36, a microphone 238, a speaker 240, a camera 42, and a communication interface 44. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, and camera 42 are also connected to the bus 52.
[0220] The microphone 238 receives voice signals from the user 20 and receives instructions from the user 20. The microphone 238 captures the voice signals from the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.
[0221] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the area around the user 20 (for example, an imaging range defined by a field of view equivalent to the width of a typical healthy person's field of vision).
[0222] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.
[0223] Figure 4 shows an example of the main functions of the data processing device 12 and the smart glasses 214. As shown in Figure 4, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.
[0224] The specific processing program 56 is an example of a "program" relating to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[0225] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[0226] In the smart glasses 214, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.
[0227] Next, the identification processing performed by the identification processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the smart glasses 214 will be referred to as the "terminal".
[0228] The system according to the present invention is designed to detect threats in network and physical environments in real time and to quickly propose countermeasures. An example of this system is shown below.
[0229] The server collects network logs from devices located within the company's network. This includes communication records from routers, firewalls, and various network devices. It also acquires sensor data from sensors installed in the physical environment, such as surveillance cameras and door sensors.
[0230] After the data is collected, the server performs a process to integrate it. Because the data is in different formats depending on the source, it is converted to a unified format. For example, the server processes video frames from surveillance cameras as analyzable image data, and network logs are converted to JSON format.
[0231] Next, the integrated data is preprocessed. Preprocessing includes removing noisy data, imputing missing data, and normalizing the data. This improves the accuracy of anomaly detection.
[0232] During the analysis phase, the server uses generative models and machine learning algorithms to detect anomalies. This includes a mechanism where an AI model, trained on normal operating patterns, is used to detect suspicious behavior or abnormal patterns, and the algorithm reacts accordingly.
[0233] If an anomaly is detected, the server immediately generates an alert and sends a notification to the terminals of users and security personnel. Notifications are sent via email, SMS, and a dedicated management dashboard to enable a swift response in emergencies.
[0234] Finally, the server can automatically generate and present countermeasures for specific threats. For example, if excessive or unauthorized access is detected, it can offer options to block the relevant network segment and temporarily lock the user accounts involved. It can also stream security camera footage to monitors' terminals to quickly assess the situation on-site.
[0235] In this way, the present invention enables effective and automated security measures to be implemented, particularly in small and medium-sized enterprises that have constraints on budget and personnel.
[0236] The following describes the processing flow.
[0237] Step 1:
[0238] The server collects data from various network devices and sensors within the enterprise. This includes network logs from routers and switches, video streams from surveillance cameras, and status information from door sensors. The data is acquired in real time and stored in storage.
[0239] Step 2:
[0240] The server initiates a process to consolidate the collected data into a single format. Network logs are stored in a temporary buffer and then converted to CSV format. Surveillance camera footage is converted to a format usable for image recognition (e.g., JPEG). This ensures consistency across different data sources.
[0241] Step 3:
[0242] The server performs preprocessing. This step involves cleaning the data, filling in missing data, and removing noise. For example, it removes unnecessary frames from surveillance camera footage and dummy data from network logs. This enables highly accurate analysis.
[0243] Step 4:
[0244] The server applies generative models and machine learning algorithms to analyze the integrated and preprocessed data. Anomaly detection algorithms work to identify suspicious activity by identifying behavior that deviates from normal operating patterns. Here, anomalies are identified by comparing them to a baseline based on historical data.
[0245] Step 5:
[0246] When an anomaly is detected, the server generates an alert and sends a notification to the user's or designated person's terminal requesting immediate action. Notifications are delivered through various means (email, SMS, dashboard notifications, etc.), allowing for flexible selection depending on the situation.
[0247] Step 6:
[0248] The server automatically suggests countermeasures based on alerts, prompting a rapid response. Specific measures may include blocking the network segment causing the abnormal traffic or locking specific user accounts. If additional surveillance camera footage needs to be reviewed, the procedure for doing so is also provided.
[0249] These steps enable the system to target threats in real time and respond to security threats efficiently.
[0250] (Example 1)
[0251] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server," and the smart glasses 214 will be referred to as the "terminal."
[0252] In modern information systems, rapidly and accurately detecting and immediately responding to threats in network and physical environments is an increasingly critical challenge. Integrating information from various data sources, detecting anomalies in real time, and taking countermeasures requires automated, advanced systems.
[0253] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.
[0254] In this invention, the server includes means for obtaining communication logs from an information system and data from physical sensors, means for processing the communication logs and physical sensor data in a unified format, and means for utilizing a learning model and data analysis algorithm for identifying anomalies based on the processed information. This makes it possible to effectively detect threats in the network and physical environment and to take countermeasures autonomously.
[0255] An "information system" is a collection of foundational technologies for collecting, processing, storing, and distributing information.
[0256] A "communication log" is record data related to communication generated by network devices and applications.
[0257] A "physical sensor" is a device that measures changes in the physical environment and acquires that data.
[0258] "Processing in a unified format" refers to a method of standardizing data from different formats and converting it into a consistent format.
[0259] A "learning model" is a data analysis technique that analyzes and learns from data to detect patterns in order to solve a specific problem.
[0260] A "data analysis algorithm" is a set of computational procedures used to extract useful information from data and to make decisions or recommendations based on that information.
[0261] An "alarm" is a notification or warning signal generated when an anomaly is detected within a system.
[0262] "Countermeasures" refer to specific actions or solutions taken in response to an issue or problem that has arisen.
[0263] "Autonomously proposing solutions" refers to a process in which a system independently provides solutions based on pre-defined rules and algorithms.
[0264] This invention primarily relates to a security system for network and physical environments involving servers, terminals, and users. Specific embodiments of this system are described below.
[0265] The server collects communication logs from network devices within the information system and related data from deployed physical sensors. This system utilizes network routers, firewalls, surveillance cameras, door sensors, and other devices to acquire comprehensive and detailed data.
[0266] The server processes the collected data in a standardized format. For example, network logs are converted to JSON format, and video data from surveillance cameras is standardized as analyzable image data. Database systems and data analysis tools are used in the data conversion and processing process.
[0267] Next, the server uses the processed data to detect anomalies using a learning model and data analysis algorithms. The generative AI model has pre-learned normal operating patterns and can quickly identify deviations from them. This anomaly detection utilizes machine learning algorithms built in programming languages such as Python.
[0268] Furthermore, users can evaluate the system based on feedback from the anomaly detection algorithm and adjust parameters to improve accuracy.
[0269] If an anomaly is detected, the server immediately generates an alarm and sends a notification to the terminal. Notifications are sent via email, SMS, and a dedicated management dashboard. In addition, the server autonomously proposes countermeasures based on the detected anomaly. For example, excessive access can be addressed by blocking the network segment, and the related user accounts will be restricted at the same time.
[0270] As a concrete example of a prompt, by inputting the text "Please suggest ways to strengthen office security over the weekend and detect anomalies early" into the AI model, security measures can be generated.
[0271] This invention aims to automate and efficiently implement comprehensive security management, which is difficult for small businesses and individuals to manage manually.
[0272] The flow of the specific processing in Example 1 will be explained using Figure 11.
[0273] Step 1:
[0274] The server acquires data from network devices and physical sensors. Inputs include communication logs from routers and firewalls, as well as data from surveillance cameras and door sensors. The server periodically collects this data and stores it as an initial dataset.
[0275] Step 2:
[0276] The server converts the acquired data into a standardized format. The input consists of data in various formats; the server uses a database system to convert network logs into JSON format and surveillance camera footage into analyzable image data. The output is a standardized dataset.
[0277] Step 3:
[0278] The server preprocesses a unified dataset. The input is a standardized dataset, from which noise data is removed, missing data is inferred and imputed, and the data is normalized. The output is preprocessed data suitable for anomaly detection.
[0279] Step 4:
[0280] The server detects anomalies using pre-processed data. The input is pre-processed data, and the server uses generative AI models and machine learning algorithms to perform calculations that detect anomalies deviating from normal operation. The output is a list of detected anomalies.
[0281] Step 5:
[0282] When an anomaly is detected, the server generates an alarm and sends a notification to the terminal. The input is a list of anomalies, and the outputs are anomaly notification emails, SMS messages, and warnings on a dedicated dashboard. This enables the server to take immediate action.
[0283] Step 6:
[0284] The server generates an immediate countermeasure for the detected anomaly and presents it to the user. The input is the type of anomaly and the evaluation result of its severity. The server presents defensive measures such as blocking a specific network segment and temporarily locking a suspicious user account. The output is the presented countermeasure.
[0285] (Application Example 1)
[0286] Next, Application Example 1 will be described. In the following description, the data processing device 12 is referred to as the "server", and the smart glasses 214 are referred to as the "terminal".
[0287] Due to the recent development of information technology, threats to the internal networks and physical environments of enterprises have been increasing. In small and medium-sized enterprises with limited resources, a quick and effective response to such threats is required, but a shortage of personnel and budget is a major obstacle. Therefore, the challenge is to provide a solution that can more efficiently detect threats, present countermeasures, and even enable remote control.
[0288] The specific processing by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.
[0289] In this invention, the server includes means for collecting network data and environmental data, means for integrating and preprocessing the network data and environmental data, and means for using generative models and machine learning algorithms for detecting anomalies based on the integrated and preprocessed data. This enables companies to automatically and quickly monitor threats, implement appropriate countermeasures, and perform effective security management remotely.
[0290] "Network data" refers to all communication information obtained from devices within a computer network. This includes the movement of data packets on the network and access logs.
[0291] "Environmental data" refers to information obtained from the physical environment. This includes things like video from surveillance cameras and data from door sensors (opening and closing).
[0292] "Means of aggregation" refers to a system for collecting and centralizing data from different sources. Servers fulfill this role.
[0293] "Means of integration and preprocessing" refers to the process of organizing and transforming data collected in different formats so that it can be analyzed.
[0294] A "generative model" refers to an algorithm designed to generate new information or patterns in data analysis.
[0295] A "machine learning algorithm" is a general term for methods that learn patterns from data and perform predictions and classifications based on that learning.
[0296] "Means for detecting abnormalities" refers to a system for automatically identifying behaviors or patterns that differ from normal conditions.
[0297] A "warning" refers to a notification or sign that alerts you when an anomaly is detected.
[0298] "Means of proposing countermeasures" refers to a function that suggests appropriate actions or procedures when an anomaly is detected.
[0299] "Means of remote control" refers to a system for operating and managing devices and systems from a physically distant location.
[0300] In this invention, the server first collects network data and environmental data. Network data includes access logs and packet data from communication devices, while environmental data includes surveillance camera footage and various sensor information. A server application using Django is used to collect this data.
[0301] Next, the server integrates and preprocesses the collected data. Because the data formats vary, the Pandas library is used to format the data and convert it into an analyzable form. This process includes noise reduction and data imputation. The integrated data is then subjected to anomaly detection using generative models and machine learning algorithms based on TensorFlow.
[0302] If the server detects an anomaly, it immediately generates an alert and notifies the user's device. Notifications are sent via SMS or email using the Twilio API. Users can receive these notifications and quickly understand the situation and check necessary countermeasures through applications on their devices.
[0303] Furthermore, the server automatically suggests countermeasures. For example, if abnormal access is detected, it will recommend blocking the network portion or temporarily locking user accounts. In this case, users can remotely control the system through their terminals and actually implement the countermeasures.
[0304] As a specific example, consider the case where the office door is illegally opened or closed at night. Such an abnormality is detected instantaneously, and a warning notification is sent to the user's smartphone. The user can use the app to check the door status and execute a remote lock if necessary. This enables a prompt response.
[0305] As an example of an input prompt sentence for the generative AI model, an instruction such as "Analyze the latest security logs and abnormal operation patterns in the office and propose the necessary countermeasures." can be given. By using this prompt sentence, the system generates optimal countermeasures according to the situation.
[0306] The flow of the specific process in Application Example 1 will be described using FIG. 12.
[0307] Step 1:
[0308] The server collects network data and environmental data from network devices and physical sensors. In this process, data such as router and firewall logs, and data from surveillance cameras and door sensors are input. The collected data is temporarily stored on the server in its raw format.
[0309] Step 2:
[0310] The server integrates the collected data and performs preprocessing using the Pandas library. The input is the raw data saved in Step 1, where data format conversion, noise removal, and missing value imputation are performed. The output is a normalized dataset.
[0311] Step 3:
[0312] The server analyzes the preprocessed data using the generative AI model and machine learning algorithms of TensorFlow. The input for this step is the normalized dataset, where data processing for anomaly detection is performed. The output is the anomaly detection result.
[0313] Step 4:
[0314] If the server detects an anomaly, it uses the Twilio API to send a warning to the user's device. The input for this step is the anomaly detection result, and the output is a warning message via SMS or email.
[0315] Step 5:
[0316] The user reviews the warning received on their device, launches the application, and checks the suggested course of action. The input in this step is the warning message, and the output is access to an interface for the user to take action.
[0317] Step 6:
[0318] The server, in response to user requests, inputs prompt messages into an AI model that automatically generates appropriate countermeasures. The input is a prompt message such as "Please suggest countermeasures appropriate to the situation," and the output is a recommended countermeasure.
[0319] Step 7:
[0320] The user remotely controls the system via a terminal based on the suggested countermeasures. In this step, the input is the recommended countermeasure, and the output is the actual control action, such as temporarily shutting down the network or locking a door.
[0321] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.
[0322] This invention is a system that detects threats in network and physical environments in real time and proposes effective countermeasures that also take user emotions into consideration.
[0323] This system begins with a server collecting data from network devices and sensors within the enterprise. Once network logs and sensor data are recorded, the server integrates the data and performs preprocessing as needed. After preprocessing, the data is analyzed using generative models and machine learning algorithms for anomaly detection.
[0324] When an anomaly is detected, the server generates an alert and sends that information to the terminal of the relevant person in charge. A key feature of this invention is the involvement of an emotion engine in recognizing the user's emotional state when generating the alert. The emotion engine recognizes emotions from the user's behavior, facial expressions, and voice data, and understands the current situation of the user.
[0325] For example, if the system determines that a user is under stress, it will adjust the content of the alert notification to a calmer and more concise format. The suggested actions will also be flexibly modified based on the user's current emotions. If a significant threat is detected and the user is emotionally distressed, the system will simplify the details of the actions to encourage them to focus on the most important actions first.
[0326] Therefore, by considering the user's psychological state, the system can achieve efficient and effective security measures, going beyond mere technical solutions. This approach allows companies to achieve both automated security and a human-centered interface.
[0327] The following describes the processing flow.
[0328] Step 1:
[0329] The server collects data in real time from network devices and sensors. Network logs are received in a format that details each communication, and video data and event information are obtained from surveillance cameras and door sensors according to the situation.
[0330] Step 2:
[0331] The server integrates the collected data and converts it into a standard format. Network logs are organized into a consistent format, and video data is converted into image fragments suitable for analysis. This makes all data available on a common analysis platform.
[0332] Step 3:
[0333] The server analyzes preprocessed data using generative models and machine learning algorithms. It identifies patterns that deviate from normal behavior and detects suspicious activity. The machine learning algorithms evaluate the degree of anomaly based on learning from past data.
[0334] Step 4:
[0335] The server generates an alert when an anomaly is detected and uses an emotion engine to evaluate the user's emotional state. The emotion engine understands the user's current psychological state by analyzing factors such as voice tone, facial expression data, and input speed.
[0336] Step 5:
[0337] The server adjusts the wording of alerts based on the user's emotional state and sends notifications to the device. For example, if the user is in a state of anxiety, the alert message will be concise and clear, prioritizing and highlighting the necessary steps.
[0338] Step 6:
[0339] The server automatically suggests countermeasures based on detected anomalies. If the emotion engine determines that the user is feeling anxious, it will clearly present the first steps to take and then provide additional information in stages to help the user feel at ease.
[0340] Step 7:
[0341] Users will take appropriate action based on the alerts and suggested countermeasures they receive. Feedback on the progress of the response and the results after implementation will be sent to the server to contribute to system improvement.
[0342] (Example 2)
[0343] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server" and the smart glasses 214 will be referred to as the "terminal".
[0344] Traditional security systems can detect network threats and issue warnings, but they lack the ability to suggest countermeasures that take into account the user's psychological state. As a result, warnings may not be taken seriously, leading to a decrease in the system's effectiveness. In particular, when users are emotionally distressed, appropriate countermeasures may not be provided, potentially creating security vulnerabilities.
[0345] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.
[0346] In this invention, the server includes means for collecting network data and sensor information, means for integrating and preprocessing the network data and sensor information, and means for using a generative AI model and machine learning algorithm for detecting anomalies based on the integrated and preprocessed information. This enables the automatic adjustment of warning content and suggestion of countermeasures according to the user's emotional state.
[0347] "Network data" refers to information related to packets and traffic transmitted and received within a communication system.
[0348] "Sensor information" refers to digital data acquired from the physical environment, including information such as temperature, humidity, and motion measured by sensor devices.
[0349] A "generative AI model" refers to an algorithm that uses artificial intelligence technology to generate and predict new data and patterns.
[0350] A "machine learning algorithm" refers to a series of computational methods used to learn rules and patterns from data and perform estimation and classification.
[0351] A "warning" refers to a message or signal that notifies the user of an anomaly or potential problem detected by the system.
[0352] An "emotion engine" refers to a technology that analyzes behavior, facial expressions, and voice data to identify a user's emotional state.
[0353] "User emotional state" refers to the user's psychological state or mood, and the factors that influence their normal actions and behaviors.
[0354] "Countermeasures" refer to specific actions or procedures proposed to address detected problems or anomalies.
[0355] This invention is a system that uses information acquired from corporate networks and sensors to detect threats in real time and provide response measures that take user emotions into consideration. Specifically, a server collects data from network devices and sensors and performs data integration and preprocessing. This is done using general network analysis tools and database software. Various machine learning libraries for anomaly detection are used as the generative AI model to be applied. Specific software includes open-source machine learning frameworks such as TensorFlow and PyTorch.
[0356] The server analyzes pre-processed data using a generative AI model and machine learning algorithms to detect anomalies. If an anomaly is detected, the server uses an emotion engine to recognize the user's emotional state from their facial expressions and voice data. The emotion engine utilizes an open-source emotion analysis library.
[0357] For example, when a server detects a large data transfer during non-business hours, it sends an alert to the terminal. However, if the emotion engine determines that the user is relaxed, it generates an alert in a polite and gentle tone. It then suggests the most appropriate course of action based on the user's emotional state.
[0358] A concrete example of a prompt might be: "Please begin the demonstration of the system that generates alert notifications considering the user's emotional state. Assuming the current emotional state is calm, please propose an action plan based on standard security protocols." By considering the user's emotions and providing optimal security responses in real time, the system's effectiveness can be enhanced.
[0359] The flow of the specific processing in Example 2 will be explained using Figure 13.
[0360] Step 1:
[0361] The server collects data from network devices and sensors within the enterprise. Inputs are network logs and sensor data, and output is integrated raw data. Specifically, it uses a data collector module to gather traffic and environmental data in real time.
[0362] Step 2:
[0363] The server integrates and preprocesses the collected raw data. The input is the integrated raw data, and the output is the preprocessed data. It performs noise reduction, format conversion, and missing value imputation to prepare the data for analysis. Specifically, it converts different data formats into a common historical database and sorts them chronologically.
[0364] Step 3:
[0365] The server performs anomaly detection based on pre-processed data. The input is pre-processed data, and the output is anomaly detection information. Generative AI models and machine learning algorithms are applied to analyze and identify abnormal patterns. Specifically, it detects unusual communication patterns and suspicious access from time-series data.
[0366] Step 4:
[0367] The server analyzes the user's emotions using an emotion engine when an anomaly is detected. The input is anomaly detection information and user behavior data, and the output is the user's emotional state. It analyzes voice data and facial expression data to evaluate the user's emotions. Specifically, it captures data in real time from cameras and microphones and performs evaluation using an emotion analysis library.
[0368] Step 5:
[0369] The server generates and sends a warning to the terminal, taking into account the user's emotional state. The input is the user's emotional state and anomaly detection information, while the output is an emotionally sensitive warning message. The server adjusts the content of the warning and notifies the user in the most appropriate format. Specifically, it sends a concise and reassuring warning to users experiencing high stress levels.
[0370] Step 6:
[0371] The user refers to and implements appropriate countermeasures based on the warning received. The input is the warning message, and the output is the countermeasures to be taken. The specific action plan is adjusted according to the user's emotional state. For example, if the user is upset, the action plan is simplified and priority actions are clearly indicated so that they can focus on the most important matters.
[0372] (Application Example 2)
[0373] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server," and the smart glasses 214 will be referred to as the "terminal."
[0374] In today's business environment, it is crucial to quickly detect and appropriately respond to threats from the network and physical environment. However, while traditional systems are specialized in threat detection, they cannot propose response measures that take into account the psychological state and emotions of users, which can lead to a decrease in the quality and efficiency of responses in emergencies. Furthermore, they may fail to adjust communication appropriately according to the emotional state of users, potentially amplifying stress.
[0375] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means.
[0376] In this invention, the server includes means for collecting network data and sensing device data, means for integrating and preprocessing the network data and sensing device data, and means for using generative models and machine learning techniques to detect anomalies based on the integrated and preprocessed data. This makes it possible to quickly detect threats and automatically propose flexible and effective countermeasures that take into account the user's emotional state.
[0377] "Network data" refers to the records and logs of information exchanged within a communication system, and is used for anomaly detection and communication analysis.
[0378] "Sensing device data" refers to information collected by sensors installed in the physical environment, and includes data used to detect temperature, movement, sound, and other similar phenomena.
[0379] A "generative model" refers to a mathematical framework for data analysis built using artificial intelligence to assist in anomaly detection.
[0380] "Machine learning methods" are algorithms that analyze large amounts of data, learn patterns, and then use them to make predictions and decisions.
[0381] "Emotional analysis methods" refer to technologies that identify emotional states from a user's facial expressions, voice, etc., and utilize artificial intelligence for analysis.
[0382] A "network segment" refers to a segment or part of a communication system that is managed individually and is a separate area designed to improve security and efficiency.
[0383] A "user account" is a record of information used to manage identification information and access rights associated with a specific user within the system.
[0384] An embodiment of this invention consists of a multi-functional server connected to a network and an end-user terminal.
[0385] The server first collects network data and sensor data. Data collection utilizes APIs and sensor technologies to obtain network communication logs and physical sensor outputs. This data is temporarily stored in a database on the server and preprocessed using Python. This preprocessing includes filtering and standardizing abnormal data. Libraries used include Pandas and NumPy for data processing.
[0386] After the data is preprocessed, the server analyzes the data using generative AI models and machine learning techniques for anomaly detection. Machine learning libraries such as TensorFlow and Scikit-learn are used to detect data anomalies in real time. Furthermore, OpenCV and SpeechRecognition are used to analyze image and audio data acquired from user terminals and perform sentiment analysis.
[0387] When a warning is issued from the server on the device, a notification tailored to the user's sentiment analysis results is sent. This reduces user stress while providing important threat information and countermeasures. This notification is displayed in a user-friendly format and can be monitored via a GUI developed in Python or a mobile application.
[0388] For example, if a minor threat is detected while the user is relaxed, the application will notify the user with calm language such as, "Please review and report if there are no issues." An example of a related prompt from a generative AI model would be, "A minor threat has been detected on the corporate network. If the user is currently relaxed, please create a notification in a calm tone."
[0389] This system aims to provide flexible and effective security responses that take into account the emotional state of the user.
[0390] The flow of a specific process in Application Example 2 will be explained using Figure 14.
[0391] Step 1:
[0392] The server collects communication logs from the network and acquires various sensor data from sensing devices. This data is stored as raw data in the server's database. The inputs are network logs and sensor data, and the output is storage in the server's database.
[0393] Step 2:
[0394] The server preprocesses the collected raw data. During this process, it uses the Pandas library to clean and standardize the data. Specifically, it performs operations such as imputing incomplete data, detecting and removing outliers, and scaling the data. The input is the raw data saved in step 1, and the output is the preprocessed structured data.
[0395] Step 3:
[0396] The server performs anomaly detection using a generated AI model based on pre-processed structured data. TensorFlow is used to identify anomaly patterns. The data is input to the model, and if an anomaly is detected, an alert is generated. The input is pre-processed data, and the output consists of the detected anomaly pattern and alert information.
[0397] Step 4:
[0398] The server receives user image and audio data acquired from the terminal and performs sentiment analysis. This analysis uses OpenCV and SpeechRecognition to identify the user's emotional state from their facial expressions and voice. The input is the user's real-time image and audio, and the output is the evaluation result of the user's emotional state.
[0399] Step 5:
[0400] The server integrates the results of anomaly detection and sentiment analysis to adjust the content of the alert notification sent to the user. Based on the sentiment analysis results, it changes the wording and level of detail of the alert. Specifically, if the user is stressed, the notification content is made concise and a gentle tone is used to alleviate tension. The input is the results of anomaly detection and sentiment analysis, and the output is the adjusted alert notification sent to the user.
[0401] Step 6:
[0402] The user's device displays alert notifications received from the server. This allows the user to understand the nature of the threat and recommended countermeasures. The display is done through a dedicated mobile or desktop app. The input is a pre-configured alert notification from the server, and the output is a user-friendly screen display.
[0403] The specific processing unit 290 transmits the result of the specific processing to the smart glasses 214. In the smart glasses 214, the control unit 46A causes the speaker 240 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.
[0404] Data generation model 58 is a type of so-called generative AI (Artificial Intelligence). One example of data generation model 58 is ChatGPT (Internet search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[0405] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and the specific processing may also be performed by the smart glasses 214.
[0406] [Third Embodiment]
[0407] Figure 5 shows an example of the configuration of the data processing system 310 according to the third embodiment.
[0408] As shown in Figure 5, the data processing system 310 includes a data processing device 12 and a headset terminal 314. An example of the data processing device 12 is a server.
[0409] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0410] The headset terminal 314 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication interface 44, and a display 343. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, camera 42, and display 343 are also connected to the bus 52.
[0411] The microphone 238 receives voice signals from the user 20 and receives instructions from the user 20. The microphone 238 captures the voice signals from the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.
[0412] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the area around the user 20 (for example, an imaging range defined by a field of view equivalent to the width of a typical healthy person's field of vision).
[0413] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.
[0414] Figure 6 shows an example of the main functions of the data processing device 12 and the headset terminal 314. As shown in Figure 6, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.
[0415] The specific processing program 56 is an example of a "program" relating to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[0416] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[0417] In the headset terminal 314, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.
[0418] Next, the specific processing performed by the specific processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the headset terminal 314 will be referred to as the "terminal".
[0419] The system according to the present invention is designed to detect threats in network and physical environments in real time and to quickly propose countermeasures. An example of this system is shown below.
[0420] The server collects network logs from devices located within the company's network. This includes communication records from routers, firewalls, and various network devices. It also acquires sensor data from sensors installed in the physical environment, such as surveillance cameras and door sensors.
[0421] After the data is collected, the server performs a process to integrate it. Because the data is in different formats depending on the source, it is converted to a unified format. For example, the server processes video frames from surveillance cameras as analyzable image data, and network logs are converted to JSON format.
[0422] Next, the integrated data is preprocessed. Preprocessing includes removing noisy data, imputing missing data, and normalizing the data. This improves the accuracy of anomaly detection.
[0423] During the analysis phase, the server uses generative models and machine learning algorithms to detect anomalies. This includes a mechanism where an AI model, trained on normal operating patterns, is used to detect suspicious behavior or abnormal patterns, and the algorithm reacts accordingly.
[0424] If an anomaly is detected, the server immediately generates an alert and sends a notification to the terminals of users and security personnel. Notifications are sent via email, SMS, and a dedicated management dashboard to enable a swift response in emergencies.
[0425] Finally, the server can automatically generate and present countermeasures for specific threats. For example, if excessive or unauthorized access is detected, it can offer options to block the relevant network segment and temporarily lock the user accounts involved. It can also stream security camera footage to monitors' terminals to quickly assess the situation on-site.
[0426] In this way, the present invention enables effective and automated security measures to be implemented, particularly in small and medium-sized enterprises that have constraints on budget and personnel.
[0427] The following describes the processing flow.
[0428] Step 1:
[0429] The server collects data from various network devices and sensors within the enterprise. This includes network logs from routers and switches, video streams from surveillance cameras, and status information from door sensors. The data is acquired in real time and stored in storage.
[0430] Step 2:
[0431] The server initiates a process to consolidate the collected data into a single format. Network logs are stored in a temporary buffer and then converted to CSV format. Surveillance camera footage is converted to a format usable for image recognition (e.g., JPEG). This ensures consistency across different data sources.
[0432] Step 3:
[0433] The server performs preprocessing. This step involves cleaning the data, filling in missing data, and removing noise. For example, it removes unnecessary frames from surveillance camera footage and dummy data from network logs. This enables highly accurate analysis.
[0434] Step 4:
[0435] The server applies generative models and machine learning algorithms to analyze the integrated and preprocessed data. Anomaly detection algorithms work to identify suspicious activity by identifying behavior that deviates from normal operating patterns. Here, anomalies are identified by comparing them to a baseline based on historical data.
[0436] Step 5:
[0437] When an anomaly is detected, the server generates an alert and sends a notification to the user's or designated person's terminal requesting immediate action. Notifications are delivered through various means (email, SMS, dashboard notifications, etc.), allowing for flexible selection depending on the situation.
[0438] Step 6:
[0439] The server automatically suggests countermeasures based on alerts, prompting a rapid response. Specific measures may include blocking the network segment causing the abnormal traffic or locking specific user accounts. If additional surveillance camera footage needs to be reviewed, the procedure for doing so is also provided.
[0440] These steps enable the system to target threats in real time and respond to security threats efficiently.
[0441] (Example 1)
[0442] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."
[0443] In modern information systems, rapidly and accurately detecting and immediately responding to threats in network and physical environments is an increasingly critical challenge. Integrating information from various data sources, detecting anomalies in real time, and taking countermeasures requires automated, advanced systems.
[0444] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.
[0445] In this invention, the server includes means for obtaining communication logs from an information system and data from physical sensors, means for processing the communication logs and physical sensor data in a unified format, and means for utilizing a learning model and data analysis algorithm for identifying anomalies based on the processed information. This makes it possible to effectively detect threats in the network and physical environment and to take countermeasures autonomously.
[0446] An "information system" is a collection of foundational technologies for collecting, processing, storing, and distributing information.
[0447] A "communication log" is record data related to communication generated by network devices and applications.
[0448] A "physical sensor" is a device that measures changes in the physical environment and acquires that data.
[0449] "Processing in a unified format" refers to a method of standardizing data from different formats and converting it into a consistent format.
[0450] A "learning model" is a data analysis technique that analyzes and learns from data to detect patterns in order to solve a specific problem.
[0451] A "data analysis algorithm" is a set of computational procedures used to extract useful information from data and to make decisions or recommendations based on that information.
[0452] An "alarm" is a notification or warning signal generated when an anomaly is detected within a system.
[0453] "Countermeasures" refer to specific actions or solutions taken in response to an issue or problem that has arisen.
[0454] "Autonomously proposing solutions" refers to a process in which a system independently provides solutions based on pre-defined rules and algorithms.
[0455] This invention primarily relates to a security system for network and physical environments involving servers, terminals, and users. Specific embodiments of this system are described below.
[0456] The server collects communication logs from network devices within the information system and related data from deployed physical sensors. This system utilizes network routers, firewalls, surveillance cameras, door sensors, and other devices to acquire comprehensive and detailed data.
[0457] The server processes the collected data in a standardized format. For example, network logs are converted to JSON format, and video data from surveillance cameras is standardized as analyzable image data. Database systems and data analysis tools are used in the data conversion and processing process.
[0458] Next, the server uses the processed data to detect anomalies using a learning model and data analysis algorithms. The generative AI model has pre-learned normal operating patterns and can quickly identify deviations from them. This anomaly detection utilizes machine learning algorithms built in programming languages such as Python.
[0459] Furthermore, users can evaluate the system based on feedback from the anomaly detection algorithm and adjust parameters to improve accuracy.
[0460] If an anomaly is detected, the server immediately generates an alarm and sends a notification to the terminal. Notifications are sent via email, SMS, and a dedicated management dashboard. In addition, the server autonomously proposes countermeasures based on the detected anomaly. For example, excessive access can be addressed by blocking the network segment, and the related user accounts will be restricted at the same time.
[0461] As a concrete example of a prompt, by inputting the text "Please suggest ways to strengthen office security over the weekend and detect anomalies early" into the AI model, security measures can be generated.
[0462] This invention aims to automate and efficiently implement comprehensive security management, which is difficult for small businesses and individuals to manage manually.
[0463] The flow of the specific processing in Example 1 will be explained using Figure 11.
[0464] Step 1:
[0465] The server acquires data from network devices and physical sensors. Inputs include communication logs from routers and firewalls, as well as data from surveillance cameras and door sensors. The server periodically collects this data and stores it as an initial dataset.
[0466] Step 2:
[0467] The server converts the acquired data into a standardized format. The input consists of data in various formats; the server uses a database system to convert network logs into JSON format and surveillance camera footage into analyzable image data. The output is a standardized dataset.
[0468] Step 3:
[0469] The server preprocesses a unified dataset. The input is a standardized dataset, from which noise data is removed, missing data is inferred and imputed, and the data is normalized. The output is preprocessed data suitable for anomaly detection.
[0470] Step 4:
[0471] The server detects anomalies using pre-processed data. The input is pre-processed data, and the server uses generative AI models and machine learning algorithms to perform calculations that detect anomalies deviating from normal operation. The output is a list of detected anomalies.
[0472] Step 5:
[0473] When an anomaly is detected, the server generates an alarm and sends a notification to the terminal. The input is a list of anomalies, and the output is an anomaly notification email, SMS, or a warning on a dedicated dashboard. This allows the server to take emergency action.
[0474] Step 6:
[0475] The server generates and presents immediate countermeasures for detected anomalies. The input is the type of anomaly and its severity assessment. The server suggests defensive measures such as blocking specific network segments and temporarily locking suspicious user accounts. The output is the proposed countermeasures.
[0476] (Application Example 1)
[0477] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."
[0478] Recent advancements in information technology have led to an increase in threats to internal corporate networks and physical environments. Small and medium-sized enterprises (SMEs) with limited resources are required to respond quickly and effectively to these threats, but a lack of personnel and budget poses a significant obstacle. Therefore, providing solutions that more efficiently detect threats, propose countermeasures, and enable remote control is crucial.
[0479] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.
[0480] In this invention, the server includes means for collecting network data and environmental data, means for integrating and preprocessing the network data and environmental data, and means for using generative models and machine learning algorithms for detecting anomalies based on the integrated and preprocessed data. This enables companies to automatically and quickly monitor threats, implement appropriate countermeasures, and perform effective security management remotely.
[0481] "Network data" refers to all communication information obtained from devices within a computer network. This includes the movement of data packets on the network and access logs.
[0482] "Environmental data" refers to information obtained from the physical environment. This includes things like video from surveillance cameras and data from door sensors (opening and closing).
[0483] "Means of aggregation" refers to a system for collecting and centralizing data from different sources. Servers fulfill this role.
[0484] "Means of integration and preprocessing" refers to the process of organizing and transforming data collected in different formats so that it can be analyzed.
[0485] A "generative model" refers to an algorithm designed to generate new information or patterns in data analysis.
[0486] A "machine learning algorithm" is a general term for methods that learn patterns from data and perform predictions and classifications based on that learning.
[0487] "Means for detecting abnormalities" refers to a system for automatically identifying behaviors or patterns that differ from normal conditions.
[0488] A "warning" refers to a notification or sign that alerts you when an anomaly is detected.
[0489] "Means of proposing countermeasures" refers to a function that suggests appropriate actions or procedures when an anomaly is detected.
[0490] "Means of remote control" refers to a system for operating and managing devices and systems from a physically distant location.
[0491] In this invention, the server first collects network data and environmental data. Network data includes access logs and packet data from communication devices, while environmental data includes surveillance camera footage and various sensor information. A server application using Django is used to collect this data.
[0492] Next, the server integrates and preprocesses the collected data. Because the data formats vary, the Pandas library is used to format the data and convert it into an analyzable form. This process includes noise reduction and data imputation. The integrated data is then subjected to anomaly detection using generative models and machine learning algorithms based on TensorFlow.
[0493] If the server detects an anomaly, it immediately generates an alert and notifies the user's device. Notifications are sent via SMS or email using the Twilio API. Users can receive these notifications and quickly understand the situation and check necessary countermeasures through applications on their devices.
[0494] Furthermore, the server automatically suggests countermeasures. For example, if abnormal access is detected, it will recommend blocking the network portion or temporarily locking user accounts. In this case, users can remotely control the system through their terminals and actually implement the countermeasures.
[0495] As a concrete example, consider a scenario where an office door is opened or closed illegally at night. Such an anomaly is detected instantly, and a warning notification is sent to the user's smartphone. The user can then use the app to check the door's status and remotely lock it if necessary. This allows for a swift response.
[0496] An example of an input prompt for the generating AI model is the instruction, "Analyze the latest security logs and abnormal behavior patterns in the office, and suggest necessary countermeasures." Using this prompt, the system will generate the most appropriate countermeasures for the situation.
[0497] The flow of a specific process in Application Example 1 will be explained using Figure 12.
[0498] Step 1:
[0499] The server collects network and environmental data from network devices and physical sensors. This process involves inputting logs from routers and firewalls, as well as data from surveillance cameras and door sensors. The collected data is temporarily stored on the server in its raw form.
[0500] Step 2:
[0501] The server integrates the collected data and performs preprocessing using the Pandas library. The input is the raw data saved in step 1, where data format conversion, denoising, and missing data imputation are performed. The output is a normalized dataset.
[0502] Step 3:
[0503] The server analyzes the preprocessed data using TensorFlow's generative AI models and machine learning algorithms. The input for this step is a normalized dataset, which is then processed for anomaly detection. The output is the anomaly detection result.
[0504] Step 4:
[0505] If the server detects an anomaly, it uses the Twilio API to send a warning to the user's device. The input for this step is the anomaly detection result, and the output is a warning message via SMS or email.
[0506] Step 5:
[0507] The user reviews the warning received on their device, launches the application, and checks the suggested course of action. The input in this step is the warning message, and the output is access to an interface for the user to take action.
[0508] Step 6:
[0509] The server, in response to user requests, inputs prompt messages into an AI model that automatically generates appropriate countermeasures. The input is a prompt message such as "Please suggest countermeasures appropriate to the situation," and the output is a recommended countermeasure.
[0510] Step 7:
[0511] The user remotely controls the system via a terminal based on the suggested countermeasures. In this step, the input is the recommended countermeasure, and the output is the actual control action, such as temporarily shutting down the network or locking a door.
[0512] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.
[0513] This invention is a system that detects threats in network and physical environments in real time and proposes effective countermeasures that also take user emotions into consideration.
[0514] This system begins with a server collecting data from network devices and sensors within the enterprise. Once network logs and sensor data are recorded, the server integrates the data and performs preprocessing as needed. After preprocessing, the data is analyzed using generative models and machine learning algorithms for anomaly detection.
[0515] When an anomaly is detected, the server generates an alert and sends that information to the terminal of the relevant person in charge. A key feature of this invention is the involvement of an emotion engine in recognizing the user's emotional state when generating the alert. The emotion engine recognizes emotions from the user's behavior, facial expressions, and voice data, and understands the current situation of the user.
[0516] For example, if the system determines that a user is under stress, it will adjust the content of the alert notification to a calmer and more concise format. The suggested actions will also be flexibly modified based on the user's current emotions. If a significant threat is detected and the user is emotionally distressed, the system will simplify the details of the actions to encourage them to focus on the most important actions first.
[0517] Therefore, by considering the user's psychological state, the system can achieve efficient and effective security measures, going beyond mere technical solutions. This approach allows companies to achieve both automated security and a human-centered interface.
[0518] The following describes the processing flow.
[0519] Step 1:
[0520] The server collects data in real time from network devices and sensors. Network logs are received in a format that details each communication, and video data and event information are obtained from surveillance cameras and door sensors according to the situation.
[0521] Step 2:
[0522] The server integrates the collected data and converts it into a standard format. Network logs are organized into a consistent format, and video data is converted into image fragments suitable for analysis. This makes all data available on a common analysis platform.
[0523] Step 3:
[0524] The server analyzes preprocessed data using generative models and machine learning algorithms. It identifies patterns that deviate from normal behavior and detects suspicious activity. The machine learning algorithms evaluate the degree of anomaly based on learning from past data.
[0525] Step 4:
[0526] The server generates an alert when an anomaly is detected and uses an emotion engine to evaluate the user's emotional state. The emotion engine understands the user's current psychological state by analyzing factors such as voice tone, facial expression data, and input speed.
[0527] Step 5:
[0528] The server adjusts the wording of alerts based on the user's emotional state and sends notifications to the device. For example, if the user is in a state of anxiety, the alert message will be concise and clear, prioritizing and highlighting the necessary steps.
[0529] Step 6:
[0530] The server automatically suggests countermeasures based on detected anomalies. If the emotion engine determines that the user is feeling anxious, it will clearly present the first steps to take and then provide additional information in stages to help the user feel at ease.
[0531] Step 7:
[0532] Users will take appropriate action based on the alerts and suggested countermeasures they receive. Feedback on the progress of the response and the results after implementation will be sent to the server to contribute to system improvement.
[0533] (Example 2)
[0534] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."
[0535] Traditional security systems can detect network threats and issue warnings, but they lack the ability to suggest countermeasures that take into account the user's psychological state. As a result, warnings may not be taken seriously, leading to a decrease in the system's effectiveness. In particular, when users are emotionally distressed, appropriate countermeasures may not be provided, potentially creating security vulnerabilities.
[0536] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.
[0537] In this invention, the server includes means for collecting network data and sensor information, means for integrating and preprocessing the network data and sensor information, and means for using a generative AI model and machine learning algorithm for detecting anomalies based on the integrated and preprocessed information. This enables the automatic adjustment of warning content and suggestion of countermeasures according to the user's emotional state.
[0538] "Network data" refers to information related to packets and traffic transmitted and received within a communication system.
[0539] "Sensor information" refers to digital data acquired from the physical environment, including information such as temperature, humidity, and motion measured by sensor devices.
[0540] A "generative AI model" refers to an algorithm that uses artificial intelligence technology to generate and predict new data and patterns.
[0541] A "machine learning algorithm" refers to a series of computational methods used to learn rules and patterns from data and perform estimation and classification.
[0542] A "warning" refers to a message or signal that notifies the user of an anomaly or potential problem detected by the system.
[0543] An "emotion engine" refers to a technology that analyzes behavior, facial expressions, and voice data to identify a user's emotional state.
[0544] "User emotional state" refers to the user's psychological state or mood, and the factors that influence their normal actions and behaviors.
[0545] "Countermeasures" refer to specific actions or procedures proposed to address detected problems or anomalies.
[0546] This invention is a system that uses information acquired from corporate networks and sensors to detect threats in real time and provide response measures that take user emotions into consideration. Specifically, a server collects data from network devices and sensors and performs data integration and preprocessing. This is done using general network analysis tools and database software. Various machine learning libraries for anomaly detection are used as the generative AI model to be applied. Specific software includes open-source machine learning frameworks such as TensorFlow and PyTorch.
[0547] The server analyzes pre-processed data using a generative AI model and machine learning algorithms to detect anomalies. If an anomaly is detected, the server uses an emotion engine to recognize the user's emotional state from their facial expressions and voice data. The emotion engine utilizes an open-source emotion analysis library.
[0548] For example, when a server detects a large data transfer during non-business hours, it sends an alert to the terminal. However, if the emotion engine determines that the user is relaxed, it generates an alert in a polite and gentle tone. It then suggests the most appropriate course of action based on the user's emotional state.
[0549] A concrete example of a prompt might be: "Please begin the demonstration of the system that generates alert notifications considering the user's emotional state. Assuming the current emotional state is calm, please propose an action plan based on standard security protocols." By considering the user's emotions and providing the most appropriate security response in real time, the system's effectiveness can be enhanced.
[0550] The flow of the specific processing in Example 2 will be explained using Figure 13.
[0551] Step 1:
[0552] The server collects data from network devices and sensors within the enterprise. Inputs are network logs and sensor data, and output is integrated raw data. Specifically, it uses a data collector module to gather traffic and environmental data in real time.
[0553] Step 2:
[0554] The server integrates and preprocesses the collected raw data. The input is the integrated raw data, and the output is the preprocessed data. It performs noise reduction, format conversion, and missing value imputation to prepare the data for analysis. Specifically, it converts different data formats into a common historical database and sorts them chronologically.
[0555] Step 3:
[0556] The server performs anomaly detection based on pre-processed data. The input is pre-processed data, and the output is anomaly detection information. Generative AI models and machine learning algorithms are applied to analyze and identify abnormal patterns. Specifically, it detects unusual communication patterns and suspicious access from time-series data.
[0557] Step 4:
[0558] The server analyzes the user's emotions using an emotion engine when an anomaly is detected. The input is anomaly detection information and user behavior data, and the output is the user's emotional state. It analyzes voice data and facial expression data to evaluate the user's emotions. Specifically, it captures data in real time from cameras and microphones and performs evaluation using an emotion analysis library.
[0559] Step 5:
[0560] The server generates and sends a warning to the terminal, taking into account the user's emotional state. The input is the user's emotional state and anomaly detection information, while the output is an emotionally sensitive warning message. The server adjusts the content of the warning and notifies the user in the most appropriate format. Specifically, it sends a concise and reassuring warning to users experiencing high stress levels.
[0561] Step 6:
[0562] The user refers to and implements appropriate countermeasures based on the warning received. The input is the warning message, and the output is the countermeasures to be taken. The specific action plan is adjusted according to the user's emotional state. For example, if the user is upset, the action plan is simplified and priority actions are clearly indicated so that they can focus on the most important matters.
[0563] (Application Example 2)
[0564] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."
[0565] In today's business environment, it is crucial to quickly detect and appropriately respond to threats from the network and physical environment. However, while traditional systems are specialized in threat detection, they cannot propose response measures that take into account the psychological state and emotions of users, which can lead to a decrease in the quality and efficiency of responses in emergencies. Furthermore, they may fail to adjust communication appropriately according to the emotional state of users, potentially amplifying stress.
[0566] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means.
[0567] In this invention, the server includes means for collecting network data and sensing device data, means for integrating and preprocessing the network data and sensing device data, and means for using generative models and machine learning techniques to detect anomalies based on the integrated and preprocessed data. This makes it possible to quickly detect threats and automatically propose flexible and effective countermeasures that take into account the user's emotional state.
[0568] "Network data" refers to the records and logs of information exchanged within a communication system, and is used for anomaly detection and communication analysis.
[0569] "Sensing device data" refers to information collected by sensors installed in the physical environment, and includes data used to detect temperature, movement, sound, and other similar phenomena.
[0570] A "generative model" refers to a mathematical framework for data analysis built using artificial intelligence to assist in anomaly detection.
[0571] "Machine learning methods" are algorithms that analyze large amounts of data, learn patterns, and then use them to make predictions and decisions.
[0572] "Emotional analysis methods" refer to technologies that identify emotional states from a user's facial expressions, voice, etc., and utilize artificial intelligence for analysis.
[0573] A "network segment" refers to a segment or part of a communication system that is managed individually and is a separate area designed to improve security and efficiency.
[0574] A "user account" is a record of information used to manage identification information and access rights associated with a specific user within the system.
[0575] An embodiment of this invention consists of a multi-functional server connected to a network and an end-user terminal.
[0576] The server first collects network data and sensor data. Data collection utilizes APIs and sensor technologies to obtain network communication logs and physical sensor outputs. This data is temporarily stored in a database on the server and preprocessed using Python. This preprocessing includes filtering and standardizing abnormal data. Libraries used include Pandas and NumPy for data processing.
[0577] After the data is preprocessed, the server analyzes the data using generative AI models and machine learning techniques for anomaly detection. Machine learning libraries such as TensorFlow and Scikit-learn are used to detect data anomalies in real time. Furthermore, OpenCV and SpeechRecognition are used to analyze image and audio data acquired from user terminals and perform sentiment analysis.
[0578] When a warning is issued from the server on the device, a notification tailored to the user's sentiment analysis results is sent. This reduces user stress while providing important threat information and countermeasures. This notification is displayed in a user-friendly format and can be monitored via a GUI developed in Python or a mobile application.
[0579] For example, if a minor threat is detected while the user is relaxed, the application will notify the user with calm language such as, "Please review and report if there are no issues." An example of a related prompt from a generative AI model would be, "A minor threat has been detected on the corporate network. If the user is currently relaxed, please create a notification in a calm tone."
[0580] This system aims to provide flexible and effective security measures that take into account the emotional state of the user.
[0581] The flow of a specific process in Application Example 2 will be explained using Figure 14.
[0582] Step 1:
[0583] The server collects communication logs from the network and acquires various sensor data from sensing devices. This data is stored as raw data in the server's database. The inputs are network logs and sensor data, and the output is storage in the server's database.
[0584] Step 2:
[0585] The server preprocesses the collected raw data. During this process, it uses the Pandas library to clean and standardize the data. Specifically, it performs operations such as imputing incomplete data, detecting and removing outliers, and scaling the data. The input is the raw data saved in step 1, and the output is the preprocessed structured data.
[0586] Step 3:
[0587] The server performs anomaly detection using a generated AI model based on pre-processed structured data. TensorFlow is used to identify anomaly patterns. The data is input to the model, and if an anomaly is detected, an alert is generated. The input is pre-processed data, and the output consists of the detected anomaly pattern and alert information.
[0588] Step 4:
[0589] The server receives user image and audio data acquired from the terminal and performs sentiment analysis. This analysis uses OpenCV and SpeechRecognition to identify the user's emotional state from their facial expressions and voice. The input is the user's real-time image and audio, and the output is the evaluation result of the user's emotional state.
[0590] Step 5:
[0591] The server integrates the results of anomaly detection and sentiment analysis to adjust the content of the alert notification sent to the user. Based on the sentiment analysis results, it changes the wording and level of detail of the alert. Specifically, if the user is stressed, the notification content is made concise and a gentle tone is used to alleviate tension. The input is the results of anomaly detection and sentiment analysis, and the output is the adjusted alert notification sent to the user.
[0592] Step 6:
[0593] The user's device displays alert notifications received from the server. This allows the user to understand the nature of the threat and recommended countermeasures. The display is done through a dedicated mobile or desktop app. The input is a pre-configured alert notification from the server, and the output is a user-friendly screen display.
[0594] The specific processing unit 290 transmits the result of the specific processing to the headset terminal 314. In the headset terminal 314, the control unit 46A causes the speaker 240 and display 343 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.
[0595] Data generation model 58 is a type of so-called generative AI (Artificial Intelligence). An example of data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[0596] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and specific processing may also be performed by the headset terminal 314.
[0597] [Fourth Embodiment]
[0598] Figure 7 shows an example of the configuration of the data processing system 410 according to the fourth embodiment.
[0599] As shown in Figure 7, the data processing system 410 includes a data processing device 12 and a robot 414. An example of the data processing device 12 is a server.
[0600] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0601] The robot 414 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication interface 44, and a controlled object 443. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, camera 42, and controlled object 443 are also connected to the bus 52.
[0602] The microphone 238 receives voice signals from the user 20 and receives instructions from the user 20. The microphone 238 captures the voice signals from the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.
[0603] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the area around the user 20 (for example, an imaging range defined by a field of view equivalent to the width of a typical healthy person's field of vision).
[0604] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.
[0605] The controlled object 443 includes a display device, LEDs in the eyes, and motors that drive the arms, hands, and feet. The posture and gestures of the robot 414 are controlled by controlling the motors of the arms, hands, and feet. Some of the robot 414's emotions can be expressed by controlling these motors. Furthermore, the robot 414's facial expressions can also be expressed by controlling the illumination state of the LEDs in its eyes.
[0606] Figure 8 shows an example of the main functions of the data processing device 12 and the robot 414. As shown in Figure 8, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.
[0607] The specific processing program 56 is an example of a "program" relating to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[0608] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[0609] In robot 414, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.
[0610] Next, the specific processing performed by the specific processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".
[0611] The system according to the present invention is designed to detect threats in network and physical environments in real time and to quickly propose countermeasures. An example of this system is shown below.
[0612] The server collects network logs from devices located within the company's network. This includes communication records from routers, firewalls, and various network devices. It also acquires sensor data from sensors installed in the physical environment, such as surveillance cameras and door sensors.
[0613] After the data is collected, the server performs a process to integrate it. Because the data is in different formats depending on the source, it is converted to a unified format. For example, the server processes video frames from surveillance cameras as analyzable image data, and network logs are converted to JSON format.
[0614] Next, the integrated data is preprocessed. Preprocessing includes removing noisy data, imputing missing data, and normalizing the data. This improves the accuracy of anomaly detection.
[0615] During the analysis phase, the server uses generative models and machine learning algorithms to detect anomalies. This includes a mechanism where an AI model, trained on normal operating patterns, is used to detect suspicious behavior or abnormal patterns, and the algorithm reacts accordingly.
[0616] If an anomaly is detected, the server immediately generates an alert and sends a notification to the terminals of users and security personnel. Notifications are sent via email, SMS, and a dedicated management dashboard to enable a swift response in emergencies.
[0617] Finally, the server can automatically generate and present countermeasures for specific threats. For example, if excessive or unauthorized access is detected, it can offer options to block the relevant network segment and temporarily lock the user accounts involved. It can also stream security camera footage to monitors' terminals to quickly assess the situation on-site.
[0618] In this way, the present invention enables effective and automated security measures to be implemented, particularly in small and medium-sized enterprises that have constraints on budget and personnel.
[0619] The following describes the processing flow.
[0620] Step 1:
[0621] The server collects data from various network devices and sensors within the enterprise. This includes network logs from routers and switches, video streams from surveillance cameras, and status information from door sensors. The data is acquired in real time and stored in storage.
[0622] Step 2:
[0623] The server initiates a process to consolidate the collected data into a single format. Network logs are stored in a temporary buffer and then converted to CSV format. Surveillance camera footage is converted to a format usable for image recognition (e.g., JPEG). This ensures consistency across different data sources.
[0624] Step 3:
[0625] The server performs preprocessing. This step involves cleaning the data, filling in missing data, and removing noise. For example, it removes unnecessary frames from surveillance camera footage and dummy data from network logs. This enables highly accurate analysis.
[0626] Step 4:
[0627] The server applies generative models and machine learning algorithms to analyze the integrated and preprocessed data. Anomaly detection algorithms work to identify suspicious activity by identifying behavior that deviates from normal operating patterns. Here, anomalies are identified by comparing them to a baseline based on historical data.
[0628] Step 5:
[0629] When an anomaly is detected, the server generates an alert and sends a notification to the user's or designated person's terminal requesting immediate action. Notifications are delivered through various means (email, SMS, dashboard notifications, etc.), allowing for flexible selection depending on the situation.
[0630] Step 6:
[0631] The server automatically suggests countermeasures based on alerts, prompting a rapid response. Specific measures may include blocking the network segment causing the abnormal traffic or locking specific user accounts. If additional surveillance camera footage needs to be reviewed, the procedure for doing so is also provided.
[0632] These steps enable the system to target threats in real time and respond to security threats efficiently.
[0633] (Example 1)
[0634] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".
[0635] In modern information systems, rapidly and accurately detecting and immediately responding to threats in network and physical environments is an increasingly critical challenge. Integrating information from various data sources, detecting anomalies in real time, and taking countermeasures requires automated, advanced systems.
[0636] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.
[0637] In this invention, the server includes means for obtaining communication logs from an information system and data from physical sensors, means for processing the communication logs and physical sensor data in a unified format, and means for utilizing a learning model and data analysis algorithm for identifying anomalies based on the processed information. This makes it possible to effectively detect threats in the network and physical environment and to take countermeasures autonomously.
[0638] An "information system" is a collection of foundational technologies for collecting, processing, storing, and distributing information.
[0639] A "communication log" is record data related to communication generated by network devices and applications.
[0640] A "physical sensor" is a device that measures changes in the physical environment and acquires that data.
[0641] "Processing in a unified format" refers to a method of standardizing data from different formats and converting it into a consistent format.
[0642] A "learning model" is a data analysis technique that analyzes and learns from data to detect patterns in order to solve a specific problem.
[0643] A "data analysis algorithm" is a set of computational procedures used to extract useful information from data and to make decisions or recommendations based on that information.
[0644] An "alarm" is a notification or warning signal generated when an anomaly is detected within a system.
[0645] "Countermeasures" refer to specific actions or solutions taken in response to an issue or problem that has arisen.
[0646] "Autonomously proposing solutions" refers to a process in which a system independently provides solutions based on pre-defined rules and algorithms.
[0647] This invention primarily relates to a security system for network and physical environments involving servers, terminals, and users. Specific embodiments of this system are described below.
[0648] The server collects communication logs from network devices within the information system and related data from deployed physical sensors. This system utilizes network routers, firewalls, surveillance cameras, door sensors, and other devices to acquire comprehensive and detailed data.
[0649] The server processes the collected data in a standardized format. For example, network logs are converted to JSON format, and video data from surveillance cameras is standardized as analyzable image data. Database systems and data analysis tools are used in the data conversion and processing process.
[0650] Next, the server uses the processed data to detect anomalies using a learning model and data analysis algorithms. The generative AI model has pre-learned normal operating patterns and can quickly identify deviations from them. This anomaly detection utilizes machine learning algorithms built in programming languages such as Python.
[0651] Furthermore, users can evaluate the system based on feedback from the anomaly detection algorithm and adjust parameters to improve accuracy.
[0652] If an anomaly is detected, the server immediately generates an alarm and sends a notification to the terminal. Notifications are sent via email, SMS, and a dedicated management dashboard. In addition, the server autonomously proposes countermeasures based on the detected anomaly. For example, excessive access can be addressed by blocking the network segment, and the related user accounts will be restricted at the same time.
[0653] As a concrete example of a prompt, by inputting the text "Please suggest ways to strengthen office security over the weekend and detect anomalies early" into the AI model, security measures can be generated.
[0654] This invention aims to automate and efficiently implement comprehensive security management, which is difficult for small businesses and individuals to manage manually.
[0655] The flow of the specific processing in Example 1 will be explained using Figure 11.
[0656] Step 1:
[0657] The server acquires data from network devices and physical sensors. Inputs include communication logs from routers and firewalls, as well as data from surveillance cameras and door sensors. The server periodically collects this data and stores it as an initial dataset.
[0658] Step 2:
[0659] The server converts the acquired data into a standardized format. The input consists of data in various formats; the server uses a database system to convert network logs into JSON format and surveillance camera footage into analyzable image data. The output is a standardized dataset.
[0660] Step 3:
[0661] The server preprocesses a unified dataset. The input is a standardized dataset, from which noise data is removed, missing data is inferred and imputed, and the data is normalized. The output is preprocessed data suitable for anomaly detection.
[0662] Step 4:
[0663] The server detects anomalies using pre-processed data. The input is pre-processed data, and the server uses generative AI models and machine learning algorithms to perform calculations that detect anomalies deviating from normal operation. The output is a list of detected anomalies.
[0664] Step 5:
[0665] When an anomaly is detected, the server generates an alarm and sends a notification to the terminal. The input is a list of anomalies, and the output is an anomaly notification email, SMS, or a warning on a dedicated dashboard. This allows the server to take emergency action.
[0666] Step 6:
[0667] The server generates and presents immediate countermeasures for detected anomalies. The input is the type of anomaly and its severity assessment. The server suggests defensive measures such as blocking specific network segments and temporarily locking suspicious user accounts. The output is the proposed countermeasures.
[0668] (Application Example 1)
[0669] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".
[0670] Recent advancements in information technology have led to an increase in threats to internal corporate networks and physical environments. Small and medium-sized enterprises (SMEs) with limited resources are required to respond quickly and effectively to these threats, but a lack of personnel and budget poses a significant obstacle. Therefore, providing solutions that more efficiently detect threats, propose countermeasures, and enable remote control is crucial.
[0671] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.
[0672] In this invention, the server includes means for collecting network data and environmental data, means for integrating and preprocessing the network data and environmental data, and means for using generative models and machine learning algorithms for detecting anomalies based on the integrated and preprocessed data. This enables companies to automatically and quickly monitor threats, implement appropriate countermeasures, and perform effective security management remotely.
[0673] "Network data" refers to all communication information obtained from devices within a computer network. This includes the movement of data packets on the network and access logs.
[0674] "Environmental data" refers to information obtained from the physical environment. This includes things like video from surveillance cameras and data from door sensors (opening and closing).
[0675] "Means of aggregation" refers to a system for collecting and centralizing data from different sources. Servers fulfill this role.
[0676] "Means of integration and preprocessing" refers to the process of organizing and transforming data collected in different formats so that it can be analyzed.
[0677] A "generative model" refers to an algorithm designed to generate new information or patterns in data analysis.
[0678] A "machine learning algorithm" is a general term for methods that learn patterns from data and perform predictions and classifications based on that learning.
[0679] "Means for detecting abnormalities" refers to a system for automatically identifying behaviors or patterns that differ from normal conditions.
[0680] A "warning" refers to a notification or sign that alerts you when an anomaly is detected.
[0681] "Means of proposing countermeasures" refers to a function that suggests appropriate actions or procedures when an anomaly is detected.
[0682] "Means of remote control" refers to a system for operating and managing devices and systems from a physically distant location.
[0683] In this invention, the server first collects network data and environmental data. Network data includes access logs and packet data from communication devices, while environmental data includes surveillance camera footage and various sensor information. A server application using Django is used to collect this data.
[0684] Next, the server integrates and preprocesses the collected data. Because the data formats vary, the Pandas library is used to format the data and convert it into an analyzable form. This process includes noise reduction and data imputation. The integrated data is then subjected to anomaly detection using generative models and machine learning algorithms based on TensorFlow.
[0685] If the server detects an anomaly, it immediately generates an alert and notifies the user's device. Notifications are sent via SMS or email using the Twilio API. Users can receive these notifications and quickly understand the situation and check necessary countermeasures through applications on their devices.
[0686] Furthermore, the server automatically suggests countermeasures. For example, if abnormal access is detected, it will recommend blocking the network portion or temporarily locking user accounts. In this case, users can remotely control the system through their terminals and actually implement the countermeasures.
[0687] As a concrete example, consider a scenario where an office door is opened or closed illegally at night. Such an anomaly is detected instantly, and a warning notification is sent to the user's smartphone. The user can then use the app to check the door's status and remotely lock it if necessary. This allows for a swift response.
[0688] An example of an input prompt for the generating AI model is the instruction, "Analyze the latest security logs and abnormal behavior patterns in the office, and suggest necessary countermeasures." Using this prompt, the system will generate the most appropriate countermeasures for the situation.
[0689] The flow of a specific process in Application Example 1 will be explained using Figure 12.
[0690] Step 1:
[0691] The server collects network and environmental data from network devices and physical sensors. This process involves inputting logs from routers and firewalls, as well as data from surveillance cameras and door sensors. The collected data is temporarily stored on the server in its raw form.
[0692] Step 2:
[0693] The server integrates the collected data and performs preprocessing using the Pandas library. The input is the raw data saved in step 1, where data format conversion, denoising, and missing data imputation are performed. The output is a normalized dataset.
[0694] Step 3:
[0695] The server analyzes the preprocessed data using TensorFlow's generative AI models and machine learning algorithms. The input for this step is a normalized dataset, which is then processed for anomaly detection. The output is the anomaly detection result.
[0696] Step 4:
[0697] If the server detects an anomaly, it uses the Twilio API to send a warning to the user's device. The input for this step is the anomaly detection result, and the output is a warning message via SMS or email.
[0698] Step 5:
[0699] The user reviews the warning received on their device, launches the application, and checks the suggested course of action. The input in this step is the warning message, and the output is access to an interface for the user to take action.
[0700] Step 6:
[0701] The server, in response to user requests, inputs prompt messages into an AI model that automatically generates appropriate countermeasures. The input is a prompt message such as "Please suggest countermeasures appropriate to the situation," and the output is a recommended countermeasure.
[0702] Step 7:
[0703] The user remotely controls the system via a terminal based on the suggested countermeasures. In this step, the input is the recommended countermeasure, and the output is the actual control action, such as temporarily shutting down the network or locking a door.
[0704] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.
[0705] This invention is a system that detects threats in network and physical environments in real time and proposes effective countermeasures that also take user emotions into consideration.
[0706] This system begins with a server collecting data from network devices and sensors within the enterprise. Once network logs and sensor data are recorded, the server integrates the data and performs preprocessing as needed. After preprocessing, the data is analyzed using generative models and machine learning algorithms for anomaly detection.
[0707] When an anomaly is detected, the server generates an alert and sends that information to the terminal of the relevant person in charge. A key feature of this invention is the involvement of an emotion engine in recognizing the user's emotional state when generating the alert. The emotion engine recognizes emotions from the user's behavior, facial expressions, and voice data, and understands the current situation of the user.
[0708] For example, if the system determines that a user is under stress, it will adjust the content of the alert notification to a calmer and more concise format. The suggested actions will also be flexibly modified based on the user's current emotions. If a significant threat is detected and the user is emotionally distressed, the system will simplify the details of the actions to encourage them to focus on the most important actions first.
[0709] Therefore, by considering the user's psychological state, the system can achieve efficient and effective security measures, going beyond mere technical solutions. This approach allows companies to achieve both automated security and a human-centered interface.
[0710] The following describes the processing flow.
[0711] Step 1:
[0712] The server collects data in real time from network devices and sensors. Network logs are received in a format that details each communication, and video data and event information are obtained from surveillance cameras and door sensors according to the situation.
[0713] Step 2:
[0714] The server integrates the collected data and converts it into a standard format. Network logs are organized into a consistent format, and video data is converted into image fragments suitable for analysis. This makes all data available on a common analysis platform.
[0715] Step 3:
[0716] The server analyzes preprocessed data using generative models and machine learning algorithms. It identifies patterns that deviate from normal behavior and detects suspicious activity. The machine learning algorithms evaluate the degree of anomaly based on learning from past data.
[0717] Step 4:
[0718] The server generates an alert when an anomaly is detected and uses an emotion engine to evaluate the user's emotional state. The emotion engine understands the user's current psychological state by analyzing factors such as voice tone, facial expression data, and input speed.
[0719] Step 5:
[0720] The server adjusts the wording of alerts based on the user's emotional state and sends notifications to the device. For example, if the user is in a state of anxiety, the alert message will be concise and clear, prioritizing and highlighting the necessary steps.
[0721] Step 6:
[0722] The server automatically suggests countermeasures based on detected anomalies. If the emotion engine determines that the user is feeling anxious, it will clearly present the first steps to take and then provide additional information in stages to help the user feel at ease.
[0723] Step 7:
[0724] Users will take appropriate action based on the alerts and suggested countermeasures they receive. Feedback on the progress of the response and the results after implementation will be sent to the server to contribute to system improvement.
[0725] (Example 2)
[0726] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".
[0727] Traditional security systems can detect network threats and issue warnings, but they lack the ability to suggest countermeasures that take into account the user's psychological state. As a result, warnings may not be taken seriously, leading to a decrease in the system's effectiveness. In particular, when users are emotionally distressed, appropriate countermeasures may not be provided, potentially creating security vulnerabilities.
[0728] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.
[0729] In this invention, the server includes means for collecting network data and sensor information, means for integrating and preprocessing the network data and sensor information, and means for using a generative AI model and machine learning algorithm for detecting anomalies based on the integrated and preprocessed information. This enables the automatic adjustment of warning content and suggestion of countermeasures according to the user's emotional state.
[0730] "Network data" refers to information related to packets and traffic transmitted and received within a communication system.
[0731] "Sensor information" refers to digital data acquired from the physical environment, including information such as temperature, humidity, and motion measured by sensor devices.
[0732] A "generative AI model" refers to an algorithm that uses artificial intelligence technology to generate and predict new data and patterns.
[0733] A "machine learning algorithm" refers to a series of computational methods used to learn rules and patterns from data and perform estimation and classification.
[0734] A "warning" refers to a message or signal that notifies the user of an anomaly or potential problem detected by the system.
[0735] An "emotion engine" refers to a technology that analyzes behavior, facial expressions, and voice data to identify a user's emotional state.
[0736] "User emotional state" refers to the user's psychological state or mood, and the factors that influence their normal actions and behaviors.
[0737] "Countermeasures" refer to specific actions or procedures proposed to address detected problems or anomalies.
[0738] This invention is a system that uses information acquired from corporate networks and sensors to detect threats in real time and provide response measures that take user emotions into consideration. Specifically, a server collects data from network devices and sensors and performs data integration and preprocessing. This is done using general network analysis tools and database software. Various machine learning libraries for anomaly detection are used as the generative AI model to be applied. Specific software includes open-source machine learning frameworks such as TensorFlow and PyTorch.
[0739] The server analyzes pre-processed data using a generative AI model and machine learning algorithms to detect anomalies. If an anomaly is detected, the server uses an emotion engine to recognize the user's emotional state from their facial expressions and voice data. The emotion engine utilizes an open-source emotion analysis library.
[0740] For example, when a server detects a large data transfer during non-business hours, it sends an alert to the terminal. However, if the emotion engine determines that the user is relaxed, it generates an alert in a polite and gentle tone. It then suggests the most appropriate course of action based on the user's emotional state.
[0741] A concrete example of a prompt might be: "Please begin the demonstration of the system that generates alert notifications considering the user's emotional state. Assuming the current emotional state is calm, please propose an action plan based on standard security protocols." By considering the user's emotions and providing the most appropriate security response in real time, the system's effectiveness can be enhanced.
[0742] The flow of the specific processing in Example 2 will be explained using Figure 13.
[0743] Step 1:
[0744] The server collects data from network devices and sensors within the enterprise. Inputs are network logs and sensor data, and output is integrated raw data. Specifically, it uses a data collector module to gather traffic and environmental data in real time.
[0745] Step 2:
[0746] The server integrates and preprocesses the collected raw data. The input is the integrated raw data, and the output is the preprocessed data. It performs noise reduction, format conversion, and missing value imputation to prepare the data for analysis. Specifically, it converts different data formats into a common historical database and sorts them chronologically.
[0747] Step 3:
[0748] The server performs anomaly detection based on pre-processed data. The input is pre-processed data, and the output is anomaly detection information. Generative AI models and machine learning algorithms are applied to analyze and identify abnormal patterns. Specifically, it detects unusual communication patterns and suspicious access from time-series data.
[0749] Step 4:
[0750] The server analyzes the user's emotions using an emotion engine when an anomaly is detected. The input is anomaly detection information and user behavior data, and the output is the user's emotional state. It analyzes voice data and facial expression data to evaluate the user's emotions. Specifically, it captures data in real time from cameras and microphones and performs evaluation using an emotion analysis library.
[0751] Step 5:
[0752] The server generates and sends a warning to the terminal, taking into account the user's emotional state. The input is the user's emotional state and anomaly detection information, while the output is an emotionally sensitive warning message. The server adjusts the content of the warning and notifies the user in the most appropriate format. Specifically, it sends a concise and reassuring warning to users experiencing high stress levels.
[0753] Step 6:
[0754] The user refers to and implements appropriate countermeasures based on the warning received. The input is the warning message, and the output is the countermeasures to be taken. The specific action plan is adjusted according to the user's emotional state. For example, if the user is upset, the action plan is simplified and priority actions are clearly indicated so that they can focus on the most important matters.
[0755] (Application Example 2)
[0756] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".
[0757] In today's business environment, it is crucial to quickly detect and appropriately respond to threats from the network and physical environment. However, while traditional systems are specialized in threat detection, they cannot propose response measures that take into account the psychological state and emotions of users, which can lead to a decrease in the quality and efficiency of responses in emergencies. Furthermore, they may fail to adjust communication appropriately according to the emotional state of users, potentially amplifying stress.
[0758] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means.
[0759] In this invention, the server includes means for collecting network data and sensing device data, means for integrating and preprocessing the network data and sensing device data, and means for using generative models and machine learning techniques to detect anomalies based on the integrated and preprocessed data. This makes it possible to quickly detect threats and automatically propose flexible and effective countermeasures that take into account the user's emotional state.
[0760] "Network data" refers to the records and logs of information exchanged within a communication system, and is used for anomaly detection and communication analysis.
[0761] "Sensing device data" refers to information collected by sensors installed in the physical environment, and includes data used to detect temperature, movement, sound, and other similar phenomena.
[0762] A "generative model" refers to a mathematical framework for data analysis built using artificial intelligence to assist in anomaly detection.
[0763] "Machine learning methods" are algorithms that analyze large amounts of data, learn patterns, and then use them to make predictions and decisions.
[0764] "Emotional analysis methods" refer to technologies that identify emotional states from a user's facial expressions, voice, etc., and utilize artificial intelligence for analysis.
[0765] A "network segment" refers to a segment or part of a communication system that is managed individually and is a separate area designed to improve security and efficiency.
[0766] A "user account" is a record of information used to manage identification information and access rights associated with a specific user within the system.
[0767] An embodiment of this invention consists of a multi-functional server connected to a network and an end-user terminal.
[0768] The server first collects network data and sensor data. Data collection utilizes APIs and sensor technologies to obtain network communication logs and physical sensor outputs. This data is temporarily stored in a database on the server and preprocessed using Python. This preprocessing includes filtering and standardizing abnormal data. Libraries used include Pandas and NumPy for data processing.
[0769] After the data is preprocessed, the server analyzes the data using generative AI models and machine learning techniques for anomaly detection. Machine learning libraries such as TensorFlow and Scikit-learn are used to detect data anomalies in real time. Furthermore, OpenCV and SpeechRecognition are used to analyze image and audio data acquired from user terminals and perform sentiment analysis.
[0770] When a warning is issued from the server on the device, a notification tailored to the user's sentiment analysis results is sent. This reduces user stress while providing important threat information and countermeasures. This notification is displayed in a user-friendly format and can be monitored via a GUI developed in Python or a mobile application.
[0771] For example, if a minor threat is detected while the user is relaxed, the application will notify the user with calm language such as, "Please review and report if there are no issues." An example of a related prompt from a generative AI model would be, "A minor threat has been detected on the corporate network. If the user is currently relaxed, please create a notification in a calm tone."
[0772] This system aims to provide flexible and effective security measures that take into account the emotional state of the user.
[0773] The flow of a specific process in Application Example 2 will be explained using Figure 14.
[0774] Step 1:
[0775] The server collects communication logs from the network and acquires various sensor data from sensing devices. This data is stored as raw data in the server's database. The inputs are network logs and sensor data, and the output is storage in the server's database.
[0776] Step 2:
[0777] The server preprocesses the collected raw data. During this process, it uses the Pandas library to clean and standardize the data. Specifically, it performs operations such as imputing incomplete data, detecting and removing outliers, and scaling the data. The input is the raw data saved in step 1, and the output is the preprocessed structured data.
[0778] Step 3:
[0779] The server performs anomaly detection using a generated AI model based on pre-processed structured data. TensorFlow is used to identify anomaly patterns. The data is input to the model, and if an anomaly is detected, an alert is generated. The input is pre-processed data, and the output consists of the detected anomaly pattern and alert information.
[0780] Step 4:
[0781] The server receives user image and audio data acquired from the terminal and performs sentiment analysis. This analysis uses OpenCV and SpeechRecognition to identify the user's emotional state from their facial expressions and voice. The input is the user's real-time image and audio, and the output is the evaluation result of the user's emotional state.
[0782] Step 5:
[0783] The server integrates the results of anomaly detection and sentiment analysis to adjust the content of the alert notification sent to the user. Based on the sentiment analysis results, it changes the wording and level of detail of the alert. Specifically, if the user is stressed, the notification content is made concise and a gentle tone is used to alleviate tension. The input is the results of anomaly detection and sentiment analysis, and the output is the adjusted alert notification sent to the user.
[0784] Step 6:
[0785] The user's device displays alert notifications received from the server. This allows the user to understand the nature of the threat and recommended countermeasures. The display is done through a dedicated mobile or desktop app. The input is a pre-configured alert notification from the server, and the output is a user-friendly screen display.
[0786] The specific processing unit 290 transmits the result of the specific processing to the robot 414. In the robot 414, the control unit 46A causes the speaker 240 and the controlled object 443 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.
[0787] Data generation model 58 is a type of so-called generative AI (Artificial Intelligence). An example of data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[0788] In the above embodiment, an example was given in which the specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and the specific processing may also be performed by the robot 414.
[0789] Furthermore, the emotion identification model 59, acting as an emotion engine, may determine the user's emotion according to a specific mapping. Specifically, the emotion identification model 59 may determine the user's emotion according to a specific mapping, which is an emotion map (see Figure 9). Similarly, the emotion identification model 59 may also determine the robot's emotion, and the identification processing unit 290 may perform identification processing using the robot's emotion.
[0790] Figure 9 shows an emotion map 400 in which multiple emotions are mapped. In the emotion map 400, emotions are arranged in concentric circles radiating from the center. The closer to the center of the concentric circles, the more primitive the emotions are located. Further out of the concentric circles, emotions representing states and actions arising from mental states are located. Emotion is a concept that includes feelings and mental states. On the left side of the concentric circles, emotions that are generally generated from reactions occurring in the brain are located. On the right side of the concentric circles, emotions that are generally induced by situational judgment are located. Above and below the concentric circles, emotions that are generally generated from reactions occurring in the brain and induced by situational judgment are located. In addition, the emotion of "pleasure" is located on the upper side of the concentric circles, and the emotion of "displeasure" is located on the lower side. Thus, in the emotion map 400, multiple emotions are mapped based on the structure in which emotions arise, and emotions that are likely to occur simultaneously are mapped close together.
[0791] These emotions are distributed at the 3 o'clock position on the Emotion Map 400, and usually fluctuate between feelings of security and anxiety. In the right half of the Emotion Map 400, situational awareness takes precedence over internal feelings, resulting in a calm impression.
[0792] The inside of the Emotion Map 400 represents inner thoughts, while the outside represents actions. Therefore, the further you go from the outside of the Emotion Map 400, the more visible (expressed in actions) your emotions become.
[0793] Here, human emotions are based on various balances, such as posture and blood sugar levels. When these balances deviate from the ideal, it results in discomfort, and when they approach the ideal, it results in pleasure. Similarly, in robots, cars, motorcycles, etc., emotions can be created based on various balances, such as posture and battery level. When these balances deviate from the ideal, it results in discomfort, and when they approach the ideal, it results in pleasure. The emotion map can be generated, for example, based on Dr. Mitsuyoshi's emotion map (Research on a system for analyzing brain physiological signals of speech emotion recognition and emotion, Tokushima University, doctoral dissertation: https: / / ci.nii.ac.jp / naid / 500000375379). The left half of the emotion map contains emotions belonging to a region called "response," where sensation is dominant. The right half of the emotion map contains emotions belonging to a region called "situation," where situational awareness is dominant.
[0794] The emotion map defines two emotions that promote learning. One is the emotion around the middle of the negative "repentance" and "reflection" on the situation side. In other words, it is when the robot experiences negative emotions such as "I never want to feel this way again" or "I don't want to be scolded again." The other is the emotion around the positive "desire" on the reaction side. In other words, it is when the robot has positive feelings such as "I want more" or "I want to know more."
[0795] The emotion identification model 59 inputs user input into a pre-trained neural network, obtains emotion values representing each emotion shown in the emotion map 400, and determines the user's emotion. This neural network is pre-trained based on multiple training data sets, which are combinations of user input and emotion values representing each emotion shown in the emotion map 400. Furthermore, this neural network is trained so that emotions located close together have similar values, as shown in the emotion map 900 in Figure 10. Figure 10 shows an example where multiple emotions such as "reassured," "calm," and "confident" have similar emotion values.
[0796] The above description primarily focuses on the functions of the data processing device 12 in relation to this disclosure. However, the system related to this disclosure is not necessarily implemented on a server. The system related to this disclosure may be implemented as a general information processing system. This disclosure may be implemented, for example, as a software program that runs on a personal computer or as an application that runs on a smartphone. The method related to this disclosure may be provided to users in SaaS (Software as a Service) format.
[0797] In the above embodiment, an example was given in which a specific process is performed by a single computer 22. However, the technology of this disclosure is not limited thereto, and a distributed processing of the specific process may be performed by multiple computers, including computer 22. For example, a data generation model 58 may be provided in an external device of the data processing device 12, and the external device may generate data according to the input data.
[0798] In the above embodiment, an example was given in which the specific processing program 56 is stored in the storage 32, but the technology of this disclosure is not limited thereto. For example, the specific processing program 56 may be stored in a portable, computer-readable, non-temporary storage medium such as a USB (Universal Serial Bus) memory. The specific processing program 56 stored in the non-temporary storage medium is installed in the computer 22 of the data processing device 12. The processor 28 executes specific processing according to the specific processing program 56.
[0799] Alternatively, the specific processing program 56 may be stored in a storage device such as a server connected to the data processing device 12 via the network 54, and the specific processing program 56 may be downloaded and installed on the computer 22 in response to a request from the data processing device 12.
[0800] Furthermore, it is not necessary to store the entirety of the specific processing program 56 in a storage device such as a server connected to the data processing device 12 via the network 54, or to store the entirety of the specific processing program 56 in the storage 32; it is acceptable to store only a portion of the specific processing program 56.
[0801] The following types of processors can be used as hardware resources to perform specific processing. Examples of processors include a CPU, a general-purpose processor that functions as a hardware resource to perform specific processing by executing software, i.e., a program. Other examples of processors include dedicated electrical circuits, such as FPGAs (Field-Programmable Gate Arrays), PLDs (Programmable Logic Devices), or ASICs (Application Specific Integrated Circuits), which have circuit configurations specifically designed to perform specific processing. All of these processors have built-in or connected memory, and all of them perform specific processing by using memory.
[0802] The hardware resource that performs a specific process may consist of one of these various processors, or it may consist of a combination of two or more processors of the same or different types (for example, a combination of multiple FPGAs, or a combination of a CPU and an FPGA). Alternatively, the hardware resource that performs a specific process may consist of a single processor.
[0803] Examples of configurations using a single processor include, firstly, a configuration in which one or more CPUs and software are combined to form a single processor, and this processor functions as a hardware resource that performs a specific process. Secondly, there is a configuration using a processor that realizes the functions of the entire system, including multiple hardware resources that perform a specific process, on a single IC chip, as exemplified by SoCs (System-on-a-chip). In this way, a specific process is realized using one or more of the above types of processors as hardware resources.
[0804] Furthermore, the hardware structure of these various processors can more specifically utilize electrical circuits that combine circuit elements such as semiconductor devices. Also, the specific processing described above is merely an example. Therefore, it goes without saying that unnecessary steps can be deleted, new steps added, or the processing order rearranged, as long as it does not deviate from the main purpose.
[0805] The descriptions and illustrations presented above are detailed explanations of the technical aspects of this disclosure and are merely examples of the technical aspects. For example, the above descriptions of the structure, function, operation, and effect are examples of the structure, function, operation, and effect of the technical aspects of this disclosure. Therefore, it goes without saying that you may delete unnecessary parts, add new elements, or replace elements in the descriptions and illustrations presented above, as long as you do not deviate from the essence of the technical aspects of this disclosure. Furthermore, in order to avoid confusion and facilitate understanding of the technical aspects of this disclosure, explanations of common technical knowledge and the like that do not require special explanation to enable the implementation of the technical aspects of this disclosure have been omitted from the descriptions and illustrations presented above.
[0806] All documents, patent applications, and technical standards described herein are incorporated by reference to the same extent as if each individual document, patent application, and technical standard were specifically and individually noted to be incorporated by reference.
[0807] The following is further disclosed regarding the embodiments described above.
[0808] (Claim 1)
[0809] Means for collecting network logs and sensor data,
[0810] Means for integrating and preprocessing the aforementioned network logs and sensor data,
[0811] Means for using generative models and machine learning algorithms to detect anomalies based on the integrated and preprocessed data,
[0812] A means for generating an alert when the aforementioned anomaly is detected,
[0813] A means of automatically proposing countermeasures based on the aforementioned alert,
[0814] A system that includes this.
[0815] (Claim 2)
[0816] The system according to claim 1, further comprising means for instructing the blocking of a network segment and the locking of a specific user account as countermeasures after detecting the aforementioned anomaly.
[0817] (Claim 3)
[0818] The system according to claim 1, wherein the generative model and machine learning algorithm are provided with means for continuously receiving feedback to improve their accuracy.
[0819] "Example 1"
[0820] (Claim 1)
[0821] Means for obtaining communication logs from information systems and data from physical sensors,
[0822] A means for processing the aforementioned communication log and physical sensor data in a unified format,
[0823] A means for utilizing a learning model and a data analysis algorithm to identify anomalies based on the processed information,
[0824] A means for generating an alarm when the aforementioned abnormality is detected,
[0825] A means for autonomously proposing countermeasures based on the aforementioned alarm,
[0826] A system that includes this.
[0827] (Claim 2)
[0828] The system according to claim 1, which includes instructions to block a portion of the information network and restrict specific user accounts as countermeasures after detecting the aforementioned anomaly.
[0829] (Claim 3)
[0830] The system according to claim 1, wherein the learning model and data analysis algorithm are continuously evaluated and have means for improving their accuracy.
[0831] "Application Example 1"
[0832] (Claim 1)
[0833] A means for collecting network data and environmental data,
[0834] Means for integrating and preprocessing the aforementioned network data and environmental data,
[0835] Means for using generative models and machine learning algorithms to detect anomalies based on the integrated and preprocessed data,
[0836] A means for generating a warning when the aforementioned abnormality is detected,
[0837] A means of automatically suggesting countermeasures based on the aforementioned warning,
[0838] In order to implement the aforementioned countermeasures, a means for remote control is provided,
[0839] A system that includes this.
[0840] (Claim 2)
[0841] The system according to claim 1, further comprising the function of remotely checking the on-site situation, after detecting the aforementioned anomaly, by instructing the blocking of the network portion and locking of specific user accounts as countermeasures.
[0842] (Claim 3)
[0843] The system according to claim 1, wherein the generative model and machine learning algorithm have a function to continuously receive feedback and improve their accuracy.
[0844] "Example 2 of combining an emotion engine"
[0845] (Claim 1)
[0846] Means for collecting network data and sensor information,
[0847] Means for integrating and preprocessing the aforementioned network data and sensor information,
[0848] Means for using a generative AI model and machine learning algorithm for detecting anomalies based on the integrated and pre-processed information,
[0849] A means for generating a warning when the aforementioned abnormality is detected,
[0850] A means of using an emotion engine to recognize the user's emotional state,
[0851] A means for adjusting the warning content based on the user's emotions recognized by the emotion engine,
[0852] A means for automatically suggesting countermeasures that respond to the user's emotions based on the aforementioned warning,
[0853] A system that includes this.
[0854] (Claim 2)
[0855] The system according to claim 1, further comprising means for changing a part of the network configuration or adjusting user access rights in accordance with the user's emotional state after detecting the aforementioned anomaly.
[0856] (Claim 3)
[0857] The system according to claim 1, wherein the generating AI model and machine learning algorithm are provided with means for continuously receiving feedback based on data regarding the user's emotional state to improve their accuracy.
[0858] "Application example 2 when combining with an emotional engine"
[0859] (Claim 1)
[0860] Means for collecting network data and sensing device data,
[0861] Means for integrating and pre-processing the aforementioned network data and sensing device data,
[0862] Means for using generative models and machine learning techniques to detect anomalies based on the integrated and preprocessed data,
[0863] A means for generating a warning when the aforementioned abnormality is detected,
[0864] A means of automatically proposing countermeasures based on the aforementioned warning,
[0865] A means of analyzing emotions to recognize the emotional state of the user,
[0866] A means for adjusting the content of the warning notification and countermeasures based on the output of the emotion analysis means,
[0867] A system that includes this.
[0868] (Claim 2)
[0869] The system according to claim 1, further comprising means for instructing the blocking of a network segment and the locking of a specific user account as countermeasures after detecting the aforementioned anomaly.
[0870] (Claim 3)
[0871] The system according to claim 1, comprising means for continuously receiving feedback to improve the accuracy of the generative model and machine learning method. [Explanation of Symbols]
[0872] 10, 210, 310, 410 Data Processing Systems 12 Data Processing Devices 14 Smart Devices 214 Smart Glasses 314 Headset-type terminal 414 Robots< / url:> < / url:> < / url:> < / url:>
Claims
1. A means for collecting network data and environmental data, Means for integrating and preprocessing the aforementioned network data and environmental data, Means for using generative models and machine learning algorithms to detect anomalies based on the integrated and preprocessed data, A means for generating a warning when the aforementioned abnormality is detected, A means of automatically suggesting countermeasures based on the aforementioned warning, In order to implement the aforementioned countermeasures, a means for remote control is provided, A system that includes this.
2. The system according to claim 1, further comprising the function of remotely checking the on-site situation, after detecting the aforementioned anomaly, by instructing the blocking of the network portion and locking of specific user accounts as countermeasures.
3. The system according to claim 1, wherein the generative model and machine learning algorithm have a function to continuously receive feedback and improve their accuracy.
Citation Information
Patent Citations
Persona chatbot control method and system
JP2022180282A