system
The system addresses the ineffectiveness of existing defenses by using real-time machine learning to detect and deter phishing and spam, ensuring user safety and facilitating legal actions.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- SOFTBANK GROUP CORP
- Filing Date
- 2024-12-12
- Publication Date
- 2026-06-24
Smart Images

Figure 2026103609000001_ABST
Abstract
Description
Technical Field
[0001] The technology of the present disclosure relates to a system.
Background Art
[0002] Patent Document 1 discloses a method for controlling a persona chatbot, which is performed by at least one processor, and includes steps of receiving a user utterance, adding the user utterance to a prompt including an instruction sentence related to an explanation of a chatbot character, encoding the prompt, and inputting the encoded prompt into a language model to generate a chatbot utterance in response to the user utterance.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] There is a problem that phishing fraud and spam by suspicious electronic messages are increasing, posing risks of financial damage and privacy infringement to users. Existing defense systems are not effective in completely eliminating these threats and providing continuous defense, and lack means for identifying and deterring attackers. Therefore, there is a need for a new method for identifying the source and taking appropriate countermeasures.
Means for Solving the Problems
[0005] This invention provides a system that analyzes suspicious electronic messages in real time and accurately detects them using machine learning models. Furthermore, it identifies the source of the detected suspicious message using network information analysis and provides a deterrent effect against attackers by executing a counter-reaction against the identified source. The process and results of the counter-reaction are recorded and stored, and a mechanism is in place to cooperate with legal authorities to provide information as needed. This ensures user safety while realizing sustainable security measures.
[0006] A "suspicious electronic message" is an electronic communication intended to cause financial loss or privacy violations to users through methods such as phishing or spam.
[0007] "Analysis methods" refer to the technologies and algorithms used to detect suspicious electronic messages, particularly those employing machine learning and pattern recognition.
[0008] "Identification means" refers to the function of analyzing network information and communication protocols in order to identify the source of a suspicious electronic message.
[0009] "Counter-response measures" are means of taking countermeasures against an identified source, and include processes that suppress and effectively neutralize the attacker's activities.
[0010] A "recording means" is a system for retaining data on the process and results of the reverse reaction and storing it in a format that allows for later reference and analysis.
[0011] "Means of collaboration" refer to communication protocols and data formats for providing recorded data and analysis results to legal authorities, and are established to support legal proceedings. [Brief explanation of the drawing]
[0012] [Figure 1] This is a conceptual diagram showing an example of the configuration of a data processing system according to the first embodiment. [Figure 2] This is a conceptual diagram showing an example of the essential functions of the data processing device and smart device according to the first embodiment. [Figure 3] This is a conceptual diagram showing an example of the configuration of a data processing system according to the second embodiment. [Figure 4] This is a conceptual diagram showing an example of the main functions of a data processing device and smart glasses according to the second embodiment. [Figure 5] This is a conceptual diagram showing an example of the configuration of a data processing system according to the third embodiment. [Figure 6] This is a conceptual diagram showing an example of the main functions of a data processing device and a headset-type terminal according to the third embodiment. [Figure 7] This is a conceptual diagram showing an example of the configuration of a data processing system according to the fourth embodiment. [Figure 8] This is a conceptual diagram showing an example of the main functions of a data processing device and a robot according to the fourth embodiment. [Figure 9] This shows an emotion map where multiple emotions are mapped. [Figure 10] This shows an emotion map where multiple emotions are mapped. [Figure 11] This is a sequence diagram showing the processing flow of the data processing system in Example 1. [Figure 12] This is a sequence diagram showing the processing flow of the data processing system in Application Example 1. [Figure 13] This is a sequence diagram showing the processing flow of the data processing system in Example 2, when an emotion engine is combined. [Figure 14] This is a sequence diagram showing the processing flow of the data processing system in Application Example 2, which combines an emotion engine. [Modes for carrying out the invention]
[0013] Hereinafter, an example of an embodiment of the system relating to the technology of this disclosure will be described with reference to the attached drawings.
[0014] First, the terms used in the following description will be explained.
[0015] In the following embodiments, the labeled processor (hereinafter simply referred to as "processor") may be a single arithmetic unit or a combination of multiple arithmetic units. Also, the processor may be a single type of arithmetic unit or a combination of multiple types of arithmetic units. Examples of arithmetic units include a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), a GPGPU (General-Purpose computing on Graphics Processing Units), an APU (Accelerated Processing Unit), and the like.
[0016] In the following embodiments, the labeled RAM (Random Access Memory) is a memory in which information is temporarily stored and is used as a work memory by the processor.
[0017] In the following embodiments, the labeled storage is one or more non-volatile storage devices that store various programs and various parameters, etc. Examples of non-volatile storage devices include flash memory (SSD (Solid State Drive)), magnetic disks (e.g., hard disks), or magnetic tapes, and the like.
[0018] In the following embodiments, the labeled communication I / F (Interface) is an interface including a communication processor and an antenna, etc. The communication I / F controls communication between multiple computers. Examples of communication standards applied to the communication I / F include wireless communication standards including 5G (5th Generation Mobile Communication System), Wi-Fi (registered trademark), or Bluetooth (registered trademark), and the like.
[0019] In the following embodiments, "A and / or B" is synonymous with "at least one of A and B." That is, "A and / or B" means that it may be A alone, or B alone, or a combination of A and B. Furthermore, in this specification, the same concept as "A and / or B" applies when expressing three or more things linked by "and / or."
[0020] [First Embodiment]
[0021] Figure 1 shows an example of the configuration of the data processing system 10 according to the first embodiment.
[0022] As shown in Figure 1, the data processing system 10 includes a data processing device 12 and a smart device 14. An example of the data processing device 12 is a server.
[0023] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0024] The smart device 14 comprises a computer 36, a reception device 38, an output device 40, a camera 42, and a communication interface 44. The computer 36 comprises a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The reception device 38, output device 40, and camera 42 are also connected to the bus 52.
[0025] The reception device 38 is equipped with a touch panel 38A and a microphone 38B, etc., and receives user input. The touch panel 38A receives user input by detecting contact with an object (e.g., a pen or finger). The microphone 38B receives user input by detecting the user's voice. The control unit 46A transmits data indicating the user input received by the touch panel 38A and microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the data indicating the user input.
[0026] The output device 40 includes a display 40A and a speaker 40B, and presents data to the user 20 by outputting the data in a form perceptible to the user 20 (e.g., audio and / or text). The display 40A displays visible information such as text and images according to instructions from the processor 46. The speaker 40B outputs audio according to instructions from the processor 46. The camera 42 is a small digital camera equipped with an optical system such as a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor.
[0027] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various types of information between processor 46 and processor 28 via network 54.
[0028] Figure 2 shows an example of the main functions of the data processing device 12 and the smart device 14.
[0029] As shown in Figure 2, in the data processing device 12, a specific processing is performed by the processor 28. A specific processing program 56 is stored in the storage 32. The specific processing program 56 is an example of a "program" related to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 according to the specific processing program 56 executed on the RAM 30.
[0030] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[0031] In the smart device 14, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The reception output program 60 is used in conjunction with a specific processing program 56 by the data processing system 10. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.
[0032] Next, the specific processing performed by the specific processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the smart device 14 as the "terminal".
[0033] In one embodiment of the present invention, an intelligent suspicious email detection module is implemented in the server of a mail system. The server analyzes incoming emails in real time and uses a machine learning algorithm to detect suspicious electronic messages. This algorithm is trained on past phishing and spam email data and comprehensively determines the email body, sender information, link structure, etc.
[0034] When a suspicious email is detected, the server analyzes the IP address and domain information of the email's sender and identifies the sender using specific methods. Based on this identification information, a counter-reaction mechanism is activated, executing a network-based counter-reaction against the identified sender. This puts a burden on the sender, thereby identifying and suppressing the attack.
[0035] The terminal records details of the counter-reaction performed by the server and prepares to securely store and extract the data if cooperation with legal authorities is required. This record includes execution time, target IP address, type of counter-reaction used, and its effect.
[0036] From the user's perspective, the system is integrated into the email interface, providing a secure environment for using email without requiring any special management effort. If an email is detected as suspicious, the user will receive a notification and, if necessary, can review the contents of the suspicious email and receive instructions on the next steps.
[0037] As a concrete example, if this system were implemented on a company's internal email server, upon receiving a phishing email from an external source, the server would immediately detect the email and identify the sender. If the sender was identified as an attacker, it would initiate a counter-reaction and record the details. Subsequently, if necessary, these records would be sent to law enforcement agencies for legal proceedings. This process would deter attacks in a short time and protect the company's information assets.
[0038] The following describes the processing flow.
[0039] Step 1:
[0040] The server scans incoming emails in real time and begins analysis using machine learning algorithms to detect suspicious electronic messages. It analyzes the email body, sender address, link structure, etc., to identify suspicious patterns.
[0041] Step 2:
[0042] If the server determines an email is suspicious, it extracts the sender's IP address and domain information. Using specific methods, it accesses internet resources to obtain more detailed information about the sender.
[0043] Step 3:
[0044] The server plans a network-level counter-response to the identified source. Using a reinforcement learning model, it generates a simulation that loads the source server.
[0045] Step 4:
[0046] The server executes a counter-reaction mechanism, managing the return communication to increase traffic to the source. This places an operational burden on the source and deters its activity.
[0047] Step 5:
[0048] The terminal meticulously records the execution process of the counter-reaction, saving the means used and their effects in a log. This includes the start time of execution, information about the affected source, and the type of counter-reaction.
[0049] Step 6:
[0050] Users can review the information obtained as a result of the system's operation and receive alerts and notifications regarding suspicious emails. If legal action is required, they can receive support in reporting the recorded data to legal authorities.
[0051] Step 7:
[0052] The server uses the data obtained from the series of processes it has carried out to provide feedback in order to update the analysis model and improve performance, and to prepare for the next suspicious email.
[0053] (Example 1)
[0054] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server," and the smart device 14 will be referred to as the "terminal."
[0055] The use of email has led to an increase in information leaks and security threats caused by suspicious electronic messages. Traditional countermeasures have faced challenges in effectively detecting suspicious emails, identifying senders, and taking countermeasures. Furthermore, the systems used to implement these countermeasures often complicate user operations and make it difficult to smoothly handle legal matters.
[0056] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.
[0057] In this invention, the server includes analysis means, identification means, control means, recording means, transmission means, and display means. This makes it possible to detect suspicious electronic messages in real time based on machine learning, identify the sender, automatically perform necessary counter-responses, securely maintain records necessary for legal proceedings, and easily provide appropriate notifications to users.
[0058] "Analysis means" refers to a function that analyzes data from received emails in order to detect suspicious electronic messages, and in particular uses machine learning models to evaluate their content and characteristics.
[0059] "Identification means" refers to a function that analyzes network data based on IP addresses and domain information in order to identify the source of a detected suspicious electronic message.
[0060] The "control means" is a function that selects and appropriately implements a method for performing a network-based reverse response to a identified source.
[0061] A "recording mechanism" is a function that logs detailed information about the reverse reaction that was performed, so that it can be used later for verification, analysis, or legal action.
[0062] "Means of communication" refer to means of providing recorded information to external legal organizations and facilitating necessary legal procedures.
[0063] "Display means" refers to a function that, through an email interface, presents the user with the results of detecting suspicious electronic messages and any necessary notifications.
[0064] This invention is specifically implemented as a system for streamlining the detection and response to suspicious emails in an email system. Embodiments are described below.
[0065] server
[0066] The server is integrated into the mail system and is responsible for continuously monitoring incoming mail. As an analytical tool, the server uses machine learning models to analyze the content, sender information, and link information of received emails. This model is trained on historical phishing and spam email data and is used to detect suspicious patterns. The server further uses identification tools to pinpoint the source of detected suspicious emails and executes network-based counter-reactions via control tools. This includes techniques such as delaying responses to the attacking server and denying connections. These operations are managed by automated programs.
[0067] terminal
[0068] The terminal is responsible for recording details of all counter-reactions performed by the server. Using recording means, it stores the date and time of each counter-reaction, the source IP address, the type of countermeasure used, and its results as a log. This log is stored securely in case it is required by law enforcement authorities.
[0069] User
[0070] Users access this system through an email interface. The display system allows users to immediately understand the status of suspicious emails, providing a secure environment for email use without requiring any special actions. If the server detects a suspicious email, the user receives a notification, allowing them to review the email details and choose the necessary action.
[0071] Specific example
[0072] For example, by implementing this system in a company's information systems, it becomes possible to quickly detect phishing attacks from external sources. In fact, when a server receives a phishing email, it immediately analyzes the email and takes the necessary network response. As a result, the company's information assets are protected from attacks, and a secure business environment is maintained.
[0073] Example of a prompt
[0074] "Please explain the specific steps and actions involved in how your server responds to received phishing emails."
[0075] The flow of the specific processing in Example 1 will be explained using Figure 11.
[0076] Step 1:
[0077] The server sends the received email as input data to the analysis tool. The analysis tool extracts the email body, header information, link URLs, etc. Based on this data, a machine learning model is used to evaluate whether the email is suspicious. Specifically, it checks the link structure of the email and determines whether it contains any unsafe links. An unsuspiciousness score is generated as output.
[0078] Step 2:
[0079] The server uses the score obtained from the analysis means as input and begins identifying the sender using the identification means. Network data analysis technology is used to examine the email sender's IP address and domain information, and an external database is referenced. This process determines whether the sender is a previously reported suspicious source. Specifically, it is compared against a blacklist and, if found, recorded as a suspicious source. The output is detailed information about the identified sender.
[0080] Step 3:
[0081] The server activates the control mechanism based on the source information obtained from the identification mechanism. The control mechanism determines and implements a counter-response against the source. This counter-response may include delaying the connection to the attack source or temporarily blocking communication. Specifically, it sends a command to the attack source server to reduce traffic. The output is the result of the counter-response.
[0082] Step 4:
[0083] The terminal receives the output of the control device and stores the implementation status in the recording device. Specifically, the recording device stores the date and time of the reverse reaction, the target IP address, the method used, and the result in a log file. Detailed log information is generated as output and stored in a format that can be provided to legal authorities as needed.
[0084] (Application Example 1)
[0085] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server," and the smart device 14 will be referred to as the "terminal."
[0086] In today's digital communication environment, users are exposed to a large amount of suspicious communication data, phishing, and spam, and effective and rapid responses to these are required. However, conventional methods have made it difficult to detect suspicious communication data in real time, immediately notify users, and take appropriate defensive measures against the source of the attack. Therefore, there is a need for a means to effectively detect suspicious communication data, improve the speed of response to attacks, and provide communication services to users with peace of mind.
[0087] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.
[0088] In this invention, the server includes an analysis means for detecting suspicious communication data, an information identification means for identifying the source of the suspicious communication data, and a reaction means for executing defensive measures against the identified source. This enables rapid detection of suspicious communication data and immediate execution of defensive measures.
[0089] "Suspicious communication data" refers to data that exhibits abnormal patterns compared to normal communication flows and may be phishing or spam.
[0090] An "analysis tool" is an element that has the function of analyzing past data and current communication content in order to detect suspicious communication data.
[0091] "Information identification means" refers to elements that have functions based on network information and data analysis to identify the source of suspicious communication data.
[0092] A "response mechanism" is an element that has the function of taking appropriate defensive measures against an identified sender.
[0093] A "recording means" is an element that has the function of saving the history of when a response means was executed, and managing it so that it can be referenced or analyzed later.
[0094] "Means of cooperation" refers to elements that provide stored history to external organizations and have the function of sharing information for legal proceedings or further investigations.
[0095] A "notification mechanism" is an element that has the function of informing the user of the receipt of suspicious communication data.
[0096] To implement this invention, the system has a configuration for detecting suspicious communication data in real time and responding quickly. The server uses analysis means to analyze communication data acquired from the network. A general-purpose server computer is assumed as the hardware to be used, and machine learning libraries such as TENSORFLOW® and Scikit-learn are suitable as software. With this software, the server identifies suspicious communication patterns and prepares to respond immediately.
[0097] Furthermore, the information identification means identifies the source of the transmission based on the analyzed data. Network information analysis tools are used for this purpose. The response means implements defensive measures against the identified source. This ensures the security of the server and suppresses unauthorized communications.
[0098] The user's device receives an immediate alert when suspicious communication is detected via a notification system. At this time, a pre-configured prompt is generated by an AI model, prompting the user to take appropriate action. This allows users to quickly take defensive measures even in busy environments.
[0099] A concrete example would be operating this system within a company's network and immediately taking defensive measures when potentially phishing communications are identified. This would ensure the security of the company's information assets. An example of a prompt message would be, "Suspicious communication has been detected. Please review the details and take appropriate action."
[0100] The flow of a specific process in Application Example 1 will be explained using Figure 12.
[0101] Step 1:
[0102] The server acquires communication data via the network. It receives the input communication data in real time and passes it on to the next analysis process. By storing this data in a buffer, the server can perform continuous data processing.
[0103] Step 2:
[0104] The server uses analysis tools to supply the acquired communication data to a machine learning model. Communication data is taken as input, and flags for suspicious data are generated as output. This analysis extracts data features and identifies anomalous patterns. The server then runs the model using TensorFlow or Scikit-learn to evaluate the data trends.
[0105] Step 3:
[0106] If suspicious data is detected, the server activates information identification measures to identify the source. The input data is the analyzed communication data, and the output is the network information of the identified source. This process utilizes network analysis tools to analyze IP addresses and domains to reveal details about the sender.
[0107] Step 4:
[0108] Against the identified source, the server executes response measures and initiates defensive actions. The output includes a log of the defensive actions taken. This step involves network-level operations such as filtering and blocking communications.
[0109] Step 5:
[0110] The server uses recording devices to save the execution results of the response devices and details of suspicious data to a database. Details of the response devices are provided as input, and the output is the status indicating completion of recording to the database. This prepares the server for subsequent analysis and legal proceedings.
[0111] Step 6:
[0112] The system detects suspicious communications and sends a warning to the user's device using a notification system. The input is information about the detected suspicious data, and the output is a notification displayed to the user. This notification is displayed on the device's screen, allowing the user to check the situation.
[0113] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.
[0114] In one embodiment of the present invention, the server first utilizes a machine learning model to analyze suspicious electronic messages in real time. When a suspicious message is detected, a process to identify its source is initiated, and the source is identified through network information analysis. Once this identification procedure is complete, the server takes a counter-reaction, implementing a network-based response that places a load on the source. These processing steps and results are recorded by the terminal and provided through a coordinating means if information sharing with legal authorities is required.
[0115] Furthermore, the present invention integrates an emotion engine that recognizes the user's emotions. When a user reads an email, the terminal uses the emotion engine to analyze the user's emotional data and evaluate the user's psychological impact on suspicious messages. Based on this information, the system adjusts the content of warnings and the frequency of notifications to prompt the user to take the most appropriate action.
[0116] As a concrete example, when this system is used in a company, the server immediately detects suspicious emails received by employees and verifies the sender. The emotion engine monitors the employee's reaction to receiving the email, and if signs of stress or confusion are detected, it immediately issues a warning and displays reassuring instructions on the screen. This reduces emotional anxiety and enables calm email management.
[0117] This system enables not only technical defenses but also proactive responses based on user experience.
[0118] The following describes the processing flow.
[0119] Step 1:
[0120] The server analyzes received electronic messages using machine learning algorithms to detect characteristic patterns of suspicious emails. The analysis includes checking the email content, sender address, and whether or not there are links.
[0121] Step 2:
[0122] If an email is identified as suspicious, the server extracts the sender's IP address and domain information. Network information analysis is used to identify the sender and determine its exact location and route.
[0123] Step 3:
[0124] The server uses network traffic to execute a counter-reaction against the identified source. This process aims to deter the attack by placing an additional load on the source.
[0125] Step 4:
[0126] The terminal meticulously records data generated during the reverse reaction process. This includes time, IP address, type of reverse reaction, and process results.
[0127] Step 5:
[0128] When a user opens a suspicious email, the device activates an emotion engine to monitor the user's emotional state. This collects emotional data using information from the camera, microphone, input speed, and other sources.
[0129] Step 6:
[0130] If the emotion engine detects signs of stress or confusion in the user, the device immediately issues a warning and displays a message providing guidance and reassurance. This reduces the user's emotional burden.
[0131] Step 7:
[0132] Based on the recorded data, the device will, if necessary, suggest to the user the possibility of collaborating with legal authorities and prepare to assist with appropriate procedures.
[0133] (Example 2)
[0134] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server" and the smart device 14 as the "terminal".
[0135] While conventional information security systems can detect suspicious electronic messages and identify their senders, they often fail to adequately consider the psychological impact on users. In particular, there is a lack of methods to mitigate the stress and confusion users experience when receiving suspicious messages, thus necessitating more comprehensive security measures.
[0136] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.
[0137] In this invention, the server includes information analysis means for detecting suspicious electronic messages, information identification means for identifying the sender, and sentiment analysis means for analyzing emotions and optimizing notifications. This enables comprehensive and efficient countermeasures against fraudulent messages while providing users with a sense of psychological security.
[0138] "Information analysis means" refers to a technical device or method for detecting suspicious electronic messages, and in particular, has the function of analyzing the message content using a machine learning model and determining suspicious elements.
[0139] "Information identification means" refers to a technical device or method used to identify the source of an electronic message, which tracks and determines the source's network information based on communication information analysis.
[0140] A "response mechanism" is a technical device or method for taking a counter-response to a sender identified as suspicious, and has the function of performing deterrent actions such as placing a burden on the sender.
[0141] "Information recording means" refers to a technical device or method for storing information related to the execution of a reverse reaction, and has the function of converting the performed process and its results into data in a format that can be referenced later.
[0142] "Means of collaboration" refers to technical devices or methods for providing recorded information to public institutions, and includes means of communication for sharing information quickly and securely.
[0143] "Emotional analysis means" refers to a technical device or method for analyzing a user's emotions, which evaluates the user's psychological state and acquires data to optimize the system's response.
[0144] "Notification optimization means" refers to a technical device or method for adjusting the content and frequency of notifications sent to the user based on information obtained through sentiment analysis means, and has the function of improving the user experience.
[0145] The system for implementing the present invention is a comprehensive security system for detecting suspicious electronic messages and mitigating the psychological impact on users.
[0146] server
[0147] The server detects the first electronic message it receives using information analysis tools. Specifically, it uses machine learning models such as TensorFlow and PyTorch to detect suspicious patterns hidden within the message content. During detection, natural language processing techniques are used to analyze the message's text data and identify potential risks.
[0148] Next, network analysis tools are used as a means of identifying the source, and the network information of the identified source is checked. Tools such as "Wireshark" and "nmap" are used to identify the source's IP address and hostname, and to determine whether it is a malicious source.
[0149] If the source is determined to be malicious, a network-based response that applies a load is implemented as a means of retaliation. In this case, network tools such as "hping3" are used to take deterrent action against the source attempting malicious communication.
[0150] terminal
[0151] The terminal stores the results of server processing using information recording methods such as "Elastic Stack." The recorded information can later be provided to public institutions through collaborative means. In addition, the terminal displays warnings in a user-friendly format, specifically by adjusting the content and frequency of notifications based on sentiment analysis using notification optimization methods to reduce the user's psychological burden.
[0152] User
[0153] For users, the emotional state when opening an email is monitored through analysis provided by an emotion analysis tool. If software such as "Affectiva" or "Emotion API" detects that the user is experiencing stress, a reassuring message is immediately displayed on the screen.
[0154] For example, when used within a company, the system can immediately issue a warning to employees who receive suspicious emails, reducing psychological stress and encouraging them to take the correct action.
[0155] An example of a prompt might be: "Consider a prompt from a generative AI that evaluates the emotional impact of an received email and immediately warns the user if they feel stressed."
[0156] The flow of the specific processing in Example 2 will be explained using Figure 13.
[0157] Step 1:
[0158] The server receives electronic messages. It receives electronic message data as input, performs spam filtering using tools such as "Apache® SpamAssassin," and determines whether the message is suspicious. As output, it provides messages deemed suspicious to the next analysis step. Specifically, it checks keywords in the message content and the sender address, and performs scoring.
[0159] Step 2:
[0160] The server inputs suspicious messages into a machine learning model for detailed analysis. Filtered message data is used as input. Suspicious patterns are identified from the message content using "TensorFlow" or "PyTorch". For data processing, natural language processing techniques are used to tokenize the text and analyze frequent words and context. The output is a determination of whether or not a suspicious pattern exists. Specifically, the model produces a prediction score, and it is checked whether that score exceeds a certain threshold.
[0161] Step 3:
[0162] The server analyzes network information to identify the source. Input includes message header information and the source IP address. Tools like Wireshark and nmap are used to determine the geographical location of the IP address and associated hostnames. The output is the identified source information. Specifically, the analysis tool consults a database to check if it matches any known malicious sources.
[0163] Step 4:
[0164] If the server determines that the source is malicious, it will take countermeasures as a response. The input is malicious source information obtained through specific means. It attempts to respond by applying a simulated network load to the source using a tool such as "hping3". The output is log information of the countermeasures that were taken. Specifically, a network load packet is sent.
[0165] Step 5:
[0166] The terminal records the processing results from the server. The input is log data from the server, which is output to the "Elastic Stack" and continuously stored. Specifically, the log collection agent acquires the data and stores it in the database.
[0167] Step 6:
[0168] When a user opens an email, the device monitors the user's emotional state using emotion analysis tools. Inputs include the user's facial image and voice data. Analysis is performed using "Affectiva" and "Emotion API." Data processing involves detecting signs of stress and anxiety through facial recognition and voice analysis. The output is the user's emotional information as a result of the analysis. Specifically, the device's camera and microphone capture data and analyze it in real time.
[0169] Step 7:
[0170] The device adjusts the content and frequency of notifications based on the analyzed sentiment information. The input is the sentiment analysis result, and the device generates a corresponding prompt. The output is the notification message provided to the user. Specifically, warnings and instructions are displayed on the device screen.
[0171] (Application Example 2)
[0172] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as a "server" and the smart device 14 as a "terminal".
[0173] With the increase in digital communications, security threats from suspicious communications are on the rise. Furthermore, the psychological impact on users is becoming significant. Conventional security systems focus solely on technical defenses, lacking measures to alleviate the emotional burden on users. This invention aims to provide users with peace of mind by enabling early detection and source identification of suspicious digital communications, analyzing the user's emotional state, and optimizing security responses from a psychological perspective.
[0174] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means.
[0175] In this invention, the server includes analysis means for detecting suspicious digital communications, identification means for identifying the source of the suspicious digital communications, reverse response means for imposing a network load on the identified source, emotion analysis means for analyzing the user's emotional state, and notification adjustment means for adjusting notifications based on the results of the emotion analysis. This not only provides technical protection but also reduces the emotional burden on the user, enabling them to use digital communications with peace of mind.
[0176] "Suspicious digital communications" are digital messages or connections that deviate from normal communication patterns and may pose a security threat.
[0177] "Analysis means" refers to technical means used to detect suspicious digital communications, and includes machine learning models.
[0178] "Identification methods" refer to technical techniques that analyze network information to identify the source of suspicious digital communications.
[0179] A "reverse response method" is a technique used to suppress further suspicious activity by placing a load on the network against the identified source.
[0180] "Recording means" refers to a system for saving the execution status and results of the reverse reaction, intended for later reference or provision to legal authorities.
[0181] "Communication methods" refer to methods of transmitting information to provide stored records to third parties such as legal institutions.
[0182] "Emotional analysis methods" are technologies that analyze a user's psychological state in real time and understand the impact of suspicious digital communications.
[0183] A "notification adjustment mechanism" is a system that uses the results of sentiment analysis to send notifications to users at the appropriate time and with appropriate content.
[0184] To implement this invention, a system is constructed that incorporates the following functions, centered around a server. The server utilizes machine learning models (e.g., TensorFlow or PyTorch) to detect suspicious digital communications in real time. Specifically, the server analyzes emails and network traffic to identify suspicious messages that deviate from normal patterns.
[0185] When the server detects suspicious communication, it identifies the source of the communication by analyzing network information. This process utilizes advanced data analysis techniques. A counter-reaction is then implemented against the identified source, which involves placing a network load on the source. This counter-reaction is intended to deter further suspicious activity from the source.
[0186] In addition, when a user reads an electronic message, the device uses an emotion analysis engine (e.g., Microsoft® Azure® Cognitive Services) to understand the user's emotional state. This data is used to assess the user's level of anxiety and stress and to adjust notification content and warning frequency as needed. As a result, users can respond calmly to suspicious messages.
[0187] To improve the user experience, a message generation AI model creates customized messages based on the results of sentiment analysis. For example, a user who receives a suspicious message may be notified with the message, "A suspicious email has been detected. For your safety, please delete it without opening the link."
[0188] An example of a prompt might be, "Create a message to help the user relax when they feel stressed." Through this prompt, the AI model can generate an appropriate relaxation message and flexibly adjust the content of the notification to the user.
[0189] The flow of a specific process in Application Example 2 will be explained using Figure 14.
[0190] Step 1:
[0191] The server captures the received digital communications and inputs their content into a machine learning model. The machine learning model detects suspicious patterns by comparing them to normal communication patterns. The output of this step is the communication data that has been determined to be suspicious.
[0192] Step 2:
[0193] The server extracts source information from suspicious communication data and identifies the source by analyzing network information. This analysis uses traffic analysis and reverse IP address lookup techniques. The output is the information of the identified source.
[0194] Step 3:
[0195] The server then performs a counter-reaction, applying a network load to the identified source. This uses load testing tools to restrict the source's communications and prevent further suspicious activity. The output of this step is a record that the load restriction was implemented.
[0196] Step 4:
[0197] When a user opens a suspicious message, the device uses an emotion analysis engine to analyze the user's face and voice tone. The input is data indicating the user's emotional state, and the output is the analyzed emotion data.
[0198] Step 5:
[0199] The device generates appropriate warnings and reassuring notifications based on the results of sentiment analysis. A generative AI model is used for this notification generation. The input is analyzed sentiment data, and the output is a customized message displayed to the user.
[0200] Step 6:
[0201] The user decides how to respond to the suspicious message based on the displayed notification. For example, they might take action such as not clicking on a suspicious link. The output of this step is a record of the user's actions.
[0202] The specific processing unit 290 transmits the result of the specific processing to the smart device 14. In the smart device 14, the control unit 46A causes the output device 40 to output the result of the specific processing. The microphone 38B acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.
[0203] Data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of data generation model 58 is ChatGPT (registered trademark) (Internet search).<URL: https: / / openai.com / blog / chatgpt> ), Gemini (registered trademark) (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[0204] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and the specific processing may also be performed by the smart device 14.
[0205] [Second Embodiment]
[0206] Figure 3 shows an example of the configuration of the data processing system 210 according to the second embodiment.
[0207] As shown in Figure 3, the data processing system 210 includes a data processing device 12 and smart glasses 214. An example of the data processing device 12 is a server.
[0208] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0209] The smart glasses 214 include a computer 36, a microphone 238, a speaker 240, a camera 42, and a communication interface 44. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, and camera 42 are also connected to the bus 52.
[0210] The microphone 238 receives voice signals from the user 20 and receives instructions from the user 20. The microphone 238 captures the voice signals from the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.
[0211] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the area around the user 20 (for example, an imaging range defined by a field of view equivalent to the width of a typical healthy person's field of vision).
[0212] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.
[0213] Figure 4 shows an example of the main functions of the data processing device 12 and the smart glasses 214. As shown in Figure 4, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.
[0214] The specific processing program 56 is an example of a "program" relating to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[0215] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[0216] In the smart glasses 214, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.
[0217] Next, the identification processing performed by the identification processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the smart glasses 214 will be referred to as the "terminal".
[0218] In one embodiment of the present invention, an intelligent suspicious email detection module is implemented in the server of a mail system. The server analyzes incoming emails in real time and uses a machine learning algorithm to detect suspicious electronic messages. This algorithm is trained on past phishing and spam email data and comprehensively determines the email body, sender information, link structure, etc.
[0219] When a suspicious email is detected, the server analyzes the IP address and domain information of the email's sender and identifies the sender using specific methods. Based on this identification information, a counter-reaction mechanism is activated, executing a network-based counter-reaction against the identified sender. This puts a burden on the sender, thereby identifying and suppressing the attack.
[0220] The terminal records details of the counter-reaction performed by the server and prepares to securely store and extract the data if cooperation with legal authorities is required. This record includes execution time, target IP address, type of counter-reaction used, and its effect.
[0221] From the user's perspective, the system is integrated into the email interface, providing a secure environment for using email without requiring any special management effort. If an email is detected as suspicious, the user will receive a notification and, if necessary, can review the contents of the suspicious email and receive instructions on the next steps.
[0222] As a concrete example, if this system were implemented on a company's internal email server, upon receiving a phishing email from an external source, the server would immediately detect the email and identify the sender. If the sender was identified as an attacker, it would initiate a counter-reaction and record the details. Subsequently, if necessary, these records would be sent to law enforcement agencies for legal proceedings. This process would deter attacks in a short time and protect the company's information assets.
[0223] The following describes the processing flow.
[0224] Step 1:
[0225] The server scans incoming emails in real time and begins analysis using machine learning algorithms to detect suspicious electronic messages. It analyzes the email body, sender address, link structure, etc., to identify suspicious patterns.
[0226] Step 2:
[0227] If the server determines an email is suspicious, it extracts the sender's IP address and domain information. Using specific methods, it accesses internet resources to obtain more detailed information about the sender.
[0228] Step 3:
[0229] The server plans a network-level counter-response to the identified source. Using a reinforcement learning model, it generates a simulation that loads the source server.
[0230] Step 4:
[0231] The server executes a counter-reaction mechanism, managing the return communication to increase traffic to the source. This places an operational burden on the source and deters its activity.
[0232] Step 5:
[0233] The terminal meticulously records the execution process of the counter-reaction, saving the means used and their effects in a log. This includes the start time of execution, information about the affected source, and the type of counter-reaction.
[0234] Step 6:
[0235] Users can review the information obtained as a result of the system's operation and receive alerts and notifications regarding suspicious emails. If legal action is required, they can receive support in reporting the recorded data to legal authorities.
[0236] Step 7:
[0237] The server uses the data obtained from the series of processes it has carried out to provide feedback in order to update the analysis model and improve performance, and to prepare for the next suspicious email.
[0238] (Example 1)
[0239] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server," and the smart glasses 214 will be referred to as the "terminal."
[0240] The use of email has led to an increase in information leaks and security threats caused by suspicious electronic messages. Traditional countermeasures have faced challenges in effectively detecting suspicious emails, identifying senders, and taking countermeasures. Furthermore, the systems used to implement these countermeasures often complicate user operations and make it difficult to smoothly handle legal matters.
[0241] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.
[0242] In this invention, the server includes analysis means, identification means, control means, recording means, transmission means, and display means. This makes it possible to detect suspicious electronic messages in real time based on machine learning, identify the sender, automatically perform necessary counter-responses, securely maintain records necessary for legal proceedings, and easily provide appropriate notifications to users.
[0243] "Analysis means" refers to a function that analyzes data from received emails in order to detect suspicious electronic messages, and in particular uses machine learning models to evaluate their content and characteristics.
[0244] "Identification means" refers to a function that analyzes network data based on IP addresses and domain information in order to identify the source of a detected suspicious electronic message.
[0245] The "control means" is a function that selects and appropriately implements a method for performing a network-based reverse response to a identified source.
[0246] A "recording mechanism" is a function that logs detailed information about the reverse reaction that was performed, so that it can be used later for verification, analysis, or legal action.
[0247] "Means of communication" refer to means of providing recorded information to external legal organizations and facilitating necessary legal procedures.
[0248] "Display means" refers to a function that, through an email interface, presents the user with the results of detecting suspicious electronic messages and any necessary notifications.
[0249] This invention is specifically implemented as a system for streamlining the detection and response to suspicious emails in an email system. Embodiments are described below.
[0250] server
[0251] The server is integrated into the mail system and is responsible for continuously monitoring incoming mail. As an analytical tool, the server uses machine learning models to analyze the content, sender information, and link information of received emails. This model is trained on historical phishing and spam email data and is used to detect suspicious patterns. The server further uses identification tools to pinpoint the source of detected suspicious emails and executes network-based counter-reactions via control tools. This includes techniques such as delaying responses to the attacking server and denying connections. These operations are managed by automated programs.
[0252] terminal
[0253] The terminal is responsible for recording details of all counter-reactions performed by the server. Using recording means, it stores the date and time of each counter-reaction, the source IP address, the type of countermeasure used, and its results as a log. This log is stored securely in case it is required by law enforcement authorities.
[0254] User
[0255] Users access this system through an email interface. The display system allows users to immediately understand the status of suspicious emails, providing a secure environment for email use without requiring any special actions. If the server detects a suspicious email, the user receives a notification, allowing them to review the email details and choose the necessary action.
[0256] Specific example
[0257] For example, by implementing this system in a company's information systems, it becomes possible to quickly detect phishing attacks from external sources. In fact, when a server receives a phishing email, it immediately analyzes the email and takes the necessary network response. As a result, the company's information assets are protected from attacks, and a secure business environment is maintained.
[0258] Example of a prompt
[0259] "Please explain the specific steps and actions involved in how your server responds to received phishing emails."
[0260] The flow of the specific processing in Example 1 will be explained using Figure 11.
[0261] Step 1:
[0262] The server sends the received email as input data to the analysis tool. The analysis tool extracts the email body, header information, link URLs, etc. Based on this data, a machine learning model is used to evaluate whether the email is suspicious. Specifically, it checks the link structure of the email and determines whether it contains any unsafe links. An unsuspiciousness score is generated as output.
[0263] Step 2:
[0264] The server uses the score obtained from the analysis means as input and begins identifying the sender using the identification means. Network data analysis technology is used to examine the email sender's IP address and domain information, and an external database is referenced. This process determines whether the sender is a previously reported suspicious source. Specifically, it is compared against a blacklist and, if found, recorded as a suspicious source. The output is detailed information about the identified sender.
[0265] Step 3:
[0266] The server activates the control mechanism based on the source information obtained from the identification mechanism. The control mechanism determines and implements a counter-response against the source. This counter-response may include delaying the connection to the attack source or temporarily blocking communication. Specifically, it sends a command to the attack source server to reduce traffic. The output is the result of the counter-response.
[0267] Step 4:
[0268] The terminal receives the output of the control device and stores the implementation status in the recording device. Specifically, the recording device stores the date and time of the reverse reaction, the target IP address, the method used, and the result in a log file. Detailed log information is generated as output and stored in a format that can be provided to legal authorities as needed.
[0269] (Application Example 1)
[0270] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server," and the smart glasses 214 will be referred to as the "terminal."
[0271] In today's digital communication environment, users are exposed to a large amount of suspicious communication data, phishing, and spam, and effective and rapid responses to these are required. However, conventional methods have made it difficult to detect suspicious communication data in real time, immediately notify users, and take appropriate defensive measures against the source of the attack. Therefore, there is a need for a means to effectively detect suspicious communication data, improve the speed of response to attacks, and provide communication services to users with peace of mind.
[0272] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.
[0273] In this invention, the server includes an analysis means for detecting suspicious communication data, an information identification means for identifying the source of the suspicious communication data, and a reaction means for executing defensive measures against the identified source. This enables rapid detection of suspicious communication data and immediate execution of defensive measures.
[0274] "Suspicious communication data" refers to data that exhibits abnormal patterns compared to normal communication flows and may be phishing or spam.
[0275] An "analysis tool" is an element that has the function of analyzing past data and current communication content in order to detect suspicious communication data.
[0276] "Information identification means" refers to elements that have functions based on network information and data analysis to identify the source of suspicious communication data.
[0277] A "response mechanism" is an element that has the function of taking appropriate defensive measures against an identified source.
[0278] A "recording means" is an element that has the function of saving the history of when a response means was executed, and managing it so that it can be referenced or analyzed later.
[0279] The "cooperation means" is an element that has the function of providing the stored history to external institutions and sharing information for legal procedures or further investigations.
[0280] The "notification means" is an element that has the function of notifying users of the receipt of suspicious communication data.
[0281] To implement this invention, the system has a configuration for detecting suspicious communication data in real time and responding quickly. The server uses analysis means to analyze the communication data obtained from the network. As the hardware to be used, a general server computer is assumed, and as the software, machine learning libraries such as TensorFlow and Scikit-learn are suitable. With these software, the server identifies suspicious communication patterns and immediately prepares a response.
[0282] Furthermore, the information identification means identifies the source based on the analyzed data. For this, a network information analysis tool is used. The reaction means executes defensive measures against the identified source. Thereby, the security of the server is maintained and unauthorized communication can be suppressed.
[0283] When the user's terminal detects suspicious communication using the notification means, it immediately receives a warning. At this time, a pre-set prompt is generated by the generation AI model to prompt the user to take appropriate actions. Thereby, the user can quickly take defensive measures even in a busy environment.
[0284] A possible specific example is to operate this system within a company's network and immediately take defensive measures when communication with a potential for phishing is identified. Thereby, the security of the company's information assets can be ensured. Examples of prompt messages include guidance such as "Suspicious communication has been detected. Please check the details and take appropriate actions."
[0285] The flow of the specific process in Application Example 1 will be described using FIG. 12.
[0286] Step 1:
[0287] The server acquires communication data via the network. It receives the input communication data in real time and passes it to the next analysis process. By storing this data in a buffer, the server can perform continuous data processing.
[0288] Step 2:
[0289] The server uses analysis means to supply the acquired communication data to a machine learning model. A flag for suspicious data is generated as the input is the communication data and the output. This analysis extracts the features of the data and identifies abnormal patterns. The server uses TensorFlow or Scikit-learn to execute the model and evaluate the data trend.
[0290] Step 3:
[0291] If suspicious data is detected, the server activates information identification means to identify the source. The input data is the analyzed communication data, and the output is the network information of the identified source. In this process, network analysis tools are utilized to analyze the IP address and domain to clarify the details of the sender.
[0292] Step 4:
[0293] For the identified source, the server executes reaction means and starts defense measures. The output includes the log of the executed defense actions. In this step, network-level operations such as filtering and blocking communication are performed.
[0294] Step 5:
[0295] The server uses recording devices to save the execution results of the response devices and details of suspicious data to a database. Details of the response devices are provided as input, and the output is the completion status of the database recording. This prepares the server for subsequent analysis and legal proceedings.
[0296] Step 6:
[0297] The system detects suspicious communications and sends a warning to the user's device using a notification system. The input is information about the detected suspicious data, and the output is a notification displayed to the user. This notification is displayed on the device's screen, allowing the user to check the situation.
[0298] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.
[0299] In one embodiment of the present invention, the server first utilizes a machine learning model to analyze suspicious electronic messages in real time. When a suspicious message is detected, a process to identify its source is initiated, and the source is identified through network information analysis. Once this identification procedure is complete, the server takes a counter-reaction, implementing a network-based response that places a load on the source. These processing steps and results are recorded by the terminal and provided through a coordinating means if information sharing with legal authorities is required.
[0300] Furthermore, the present invention integrates an emotion engine that recognizes the user's emotions. When a user reads an email, the terminal uses the emotion engine to analyze the user's emotional data and evaluate the user's psychological impact on suspicious messages. Based on this information, the system adjusts the content of warnings and the frequency of notifications to prompt the user to take the most appropriate action.
[0301] As a specific example, when a company uses this system, the server immediately detects suspicious emails received by employees and checks their sources. The emotion engine monitors the employees' reactions when receiving emails. If signs of stress or confusion are detected, it immediately issues a warning and displays instructions on the screen to reassure the user. This reduces emotional anxiety and enables calm email management.
[0302] This system enables not only technical defensive measures but also proactive responses based on the user experience.
[0303] The following describes the process flow.
[0304] Step 1:
[0305] The server analyzes the received electronic message using a machine learning algorithm to detect the characteristic pattern of a suspicious email. The analysis targets the email content, sender address, presence of links, etc.
[0306] Step 2:
[0307] If it is determined to be a suspicious email, the server extracts the message's sender IP address and domain information. It uses network information analysis to identify the sender and understand its exact location and route.
[0308] Step 3:
[0309] The server uses network traffic against the identified sender to execute a reverse reaction. This process aims to impose additional load on the sender and deter attacks.
[0310] Step 4:
[0311] The terminal records in detail the data generated during the reverse reaction process. The recorded content includes time, IP address, type of reverse reaction, process result, etc.
[0312] Step 5:
[0313] When a user opens a suspicious email, the device activates an emotion engine to monitor the user's emotional state. This collects emotional data using information from the camera, microphone, input speed, and other sources.
[0314] Step 6:
[0315] If the emotion engine detects signs of stress or confusion in the user, the device immediately issues a warning and displays a message providing guidance and reassurance. This reduces the user's emotional burden.
[0316] Step 7:
[0317] Based on the recorded data, the device will, if necessary, suggest to the user the possibility of collaborating with legal authorities and prepare to assist with appropriate procedures.
[0318] (Example 2)
[0319] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server" and the smart glasses 214 will be referred to as the "terminal".
[0320] While conventional information security systems can detect suspicious electronic messages and identify their senders, they often fail to adequately consider the psychological impact on users. In particular, there is a lack of methods to mitigate the stress and confusion users experience when receiving suspicious messages, thus necessitating more comprehensive security measures.
[0321] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.
[0322] In this invention, the server includes information analysis means for detecting suspicious electronic messages, information identification means for identifying the sender, and sentiment analysis means for analyzing emotions and optimizing notifications. This enables comprehensive and efficient countermeasures against fraudulent messages while providing users with a sense of psychological security.
[0323] "Information analysis means" refers to a technical device or method for detecting suspicious electronic messages, and in particular, has the function of analyzing the message content using a machine learning model and determining suspicious elements.
[0324] "Information identification means" refers to a technical device or method used to identify the source of an electronic message, which tracks and determines the source's network information based on communication information analysis.
[0325] A "response mechanism" is a technical device or method for taking a counter-response to a sender identified as suspicious, and has the function of performing deterrent actions such as placing a burden on the sender.
[0326] "Information recording means" refers to a technical device or method for storing information related to the execution of a reverse reaction, and has the function of converting the performed process and its results into data in a format that can be referenced later.
[0327] "Means of collaboration" refers to technical devices or methods for providing recorded information to public institutions, and includes means of communication for sharing information quickly and securely.
[0328] "Emotional analysis means" refers to a technical device or method for analyzing a user's emotions, which evaluates the user's psychological state and acquires data to optimize the system's response.
[0329] "Notification optimization means" refers to a technical device or method for adjusting the content and frequency of notifications sent to the user based on information obtained through sentiment analysis means, and has the function of improving the user experience.
[0330] The system for implementing the present invention is a comprehensive security system for detecting suspicious electronic messages and mitigating the psychological impact on users.
[0331] server
[0332] The server detects the first electronic message it receives using information analysis tools. Specifically, it uses machine learning models such as TensorFlow and PyTorch to detect suspicious patterns hidden within the message content. During detection, natural language processing techniques are used to analyze the message's text data and identify potential risks.
[0333] Next, network analysis tools are used as a means of identifying the source, and the network information of the identified source is checked. Tools such as "Wireshark" and "nmap" are used to identify the source's IP address and hostname, and to determine whether it is a malicious source.
[0334] If the source is determined to be malicious, a network-based response that applies a load is implemented as a means of retaliation. In this case, network tools such as "hping3" are used to take deterrent action against the source attempting malicious communication.
[0335] terminal
[0336] The terminal stores the results of server processing using information recording methods such as "Elastic Stack." The recorded information can later be provided to public institutions through collaborative means. In addition, the terminal displays warnings in a user-friendly format, specifically by adjusting the content and frequency of notifications based on sentiment analysis using notification optimization methods to reduce the user's psychological burden.
[0337] User
[0338] For users, the emotional state when opening an email is monitored through analysis provided by an emotion analysis tool. If software such as "Affectiva" or "Emotion API" detects that the user is experiencing stress, a reassuring message is immediately displayed on the screen.
[0339] For example, when used within a company, the system can immediately issue a warning to employees who receive suspicious emails, reducing psychological stress and encouraging them to take the correct action.
[0340] An example of a prompt might be: "Consider a prompt from a generative AI that evaluates the emotional impact of an received email and immediately warns the user if they feel stressed."
[0341] The flow of the specific processing in Example 2 will be explained using Figure 13.
[0342] Step 1:
[0343] The server receives electronic messages. It receives electronic message data as input, performs spam filtering using tools like "Apache SpamAssassin," and determines whether the message is suspicious. As output, it provides messages deemed suspicious to the next analysis step. Specifically, it checks keywords in the message content and the sender address, and performs scoring.
[0344] Step 2:
[0345] The server inputs suspicious messages into a machine learning model for detailed analysis. Filtered message data is used as input. Suspicious patterns are identified from the message content using "TensorFlow" or "PyTorch". For data processing, natural language processing techniques are used to tokenize the text and analyze frequent words and context. The output is a determination of whether or not a suspicious pattern exists. Specifically, the model produces a prediction score, and it is checked whether that score exceeds a certain threshold.
[0346] Step 3:
[0347] The server analyzes network information to identify the source. Input includes message header information and the source IP address. Tools like Wireshark and nmap are used to determine the geographical location of the IP address and associated hostnames. The output is the identified source information. Specifically, the analysis tool consults a database to check if it matches any known malicious sources.
[0348] Step 4:
[0349] If the server determines that the source is malicious, it will take countermeasures as a response. The input is malicious source information obtained through specific means. It attempts to respond by applying a simulated network load to the source using a tool such as "hping3". The output is log information of the countermeasures that were taken. Specifically, a network load packet is sent.
[0350] Step 5:
[0351] The terminal records the processing results from the server. The input is log data from the server, which is output to the "Elastic Stack" and continuously stored. Specifically, the log collection agent acquires the data and stores it in the database.
[0352] Step 6:
[0353] When a user opens an email, the device monitors the user's emotional state using emotion analysis tools. Inputs include the user's facial image and voice data. Analysis is performed using "Affectiva" and "Emotion API." Data processing involves detecting signs of stress and anxiety through facial recognition and voice analysis. The output is the user's emotional information as a result of the analysis. Specifically, the device's camera and microphone capture data and analyze it in real time.
[0354] Step 7:
[0355] The device adjusts the content and frequency of notifications based on the analyzed sentiment information. The input is the sentiment analysis result, and the device generates a corresponding prompt. The output is the notification message provided to the user. Specifically, warnings and instructions are displayed on the device screen.
[0356] (Application Example 2)
[0357] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server" and the smart glasses 214 as the "terminal".
[0358] With the increase in digital communications, security threats from suspicious communications are on the rise. Furthermore, the psychological impact on users is becoming significant. Conventional security systems focus solely on technical defenses, lacking measures to alleviate the emotional burden on users. This invention aims to provide users with peace of mind by enabling early detection and source identification of suspicious digital communications, analyzing the user's emotional state, and optimizing security responses from a psychological perspective.
[0359] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means.
[0360] In this invention, the server includes analysis means for detecting suspicious digital communications, identification means for identifying the source of the suspicious digital communications, reverse response means for imposing a network load on the identified source, emotion analysis means for analyzing the user's emotional state, and notification adjustment means for adjusting notifications based on the results of the emotion analysis. This not only provides technical protection but also reduces the emotional burden on the user, enabling them to use digital communications with peace of mind.
[0361] "Suspicious digital communications" are digital messages or connections that deviate from normal communication patterns and may pose a security threat.
[0362] "Analysis means" refers to technical means used to detect suspicious digital communications, and includes machine learning models.
[0363] "Identification methods" refer to technical techniques that analyze network information to identify the source of suspicious digital communications.
[0364] A "reverse response method" is a technique used to suppress further suspicious activity by placing a load on the network against the identified source.
[0365] "Recording means" refers to a system for saving the execution status and results of the reverse reaction, intended for later reference or provision to legal authorities.
[0366] "Communication methods" refer to methods of transmitting information to provide stored records to third parties such as legal institutions.
[0367] "Emotional analysis methods" are technologies that analyze a user's psychological state in real time and understand the impact of suspicious digital communications.
[0368] A "notification adjustment mechanism" is a system that uses the results of sentiment analysis to send notifications to users at the appropriate time and with appropriate content.
[0369] To implement this invention, a system is constructed that incorporates the following functions, centered around a server. The server utilizes machine learning models (e.g., TensorFlow or PyTorch) to detect suspicious digital communications in real time. Specifically, the server analyzes emails and network traffic to identify suspicious messages that deviate from normal patterns.
[0370] When the server detects suspicious communication, it identifies the source of the communication by analyzing network information. This process utilizes advanced data analysis techniques. A counter-reaction is then implemented against the identified source, which involves placing a network load on the source. This counter-reaction is intended to deter further suspicious activity from the source.
[0371] In addition, the device uses an emotion analysis engine (e.g., Microsoft Azure Cognitive Services) to understand the user's emotional state when they read electronic messages. This data is used to assess the user's level of anxiety and stress and to adjust notification content and warning frequency as needed. As a result, users can respond calmly to suspicious messages.
[0372] To improve the user experience, a message generation AI model creates customized messages based on the results of sentiment analysis. For example, a user who receives a suspicious message may be notified with the message, "A suspicious email has been detected. For your safety, please delete it without opening the link."
[0373] An example of a prompt might be, "Create a message to help the user relax when they feel stressed." Through this prompt, the AI model can generate an appropriate relaxation message and flexibly adjust the content of the notification to the user.
[0374] The flow of a specific process in Application Example 2 will be explained using Figure 14.
[0375] Step 1:
[0376] The server captures the received digital communications and inputs their content into a machine learning model. The machine learning model detects suspicious patterns by comparing them to normal communication patterns. The output of this step is the communication data that has been determined to be suspicious.
[0377] Step 2:
[0378] The server extracts source information from suspicious communication data and identifies the source by analyzing network information. This analysis uses traffic analysis and reverse IP address lookup techniques. The output is the information of the identified source.
[0379] Step 3:
[0380] The server then performs a counter-reaction, applying a network load to the identified source. This uses load testing tools to restrict the source's communications and prevent further suspicious activity. The output of this step is a record that the load restriction was implemented.
[0381] Step 4:
[0382] When a user opens a suspicious message, the device uses an emotion analysis engine to analyze the user's face and voice tone. The input is data indicating the user's emotional state, and the output is the analyzed emotion data.
[0383] Step 5:
[0384] The device generates appropriate warnings and reassuring notifications based on the results of sentiment analysis. A generative AI model is used for this notification generation. The input is analyzed sentiment data, and the output is a customized message displayed to the user.
[0385] Step 6:
[0386] The user decides how to respond to the suspicious message based on the displayed notification. For example, they might take action such as not clicking on a suspicious link. The output of this step is a record of the user's actions.
[0387] The specific processing unit 290 transmits the result of the specific processing to the smart glasses 214. In the smart glasses 214, the control unit 46A causes the speaker 240 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.
[0388] Data generation model 58 is a type of so-called generative AI (Artificial Intelligence). An example of data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[0389] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and the specific processing may also be performed by the smart glasses 214.
[0390] [Third Embodiment]
[0391] Figure 5 shows an example of the configuration of the data processing system 310 according to the third embodiment.
[0392] As shown in Figure 5, the data processing system 310 includes a data processing device 12 and a headset terminal 314. An example of the data processing device 12 is a server.
[0393] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0394] The headset terminal 314 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication interface 44, and a display 343. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, camera 42, and display 343 are also connected to the bus 52.
[0395] The microphone 238 receives voice signals from the user 20 and receives instructions from the user 20. The microphone 238 captures the voice signals from the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.
[0396] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the area around the user 20 (for example, an imaging range defined by a field of view equivalent to the width of a typical healthy person's field of vision).
[0397] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.
[0398] Figure 6 shows an example of the main functions of the data processing device 12 and the headset terminal 314. As shown in Figure 6, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.
[0399] The specific processing program 56 is an example of a "program" relating to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[0400] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[0401] In the headset terminal 314, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.
[0402] Next, the specific processing performed by the specific processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the headset terminal 314 will be referred to as the "terminal".
[0403] In one embodiment of the present invention, an intelligent suspicious email detection module is implemented in the server of a mail system. The server analyzes incoming emails in real time and uses a machine learning algorithm to detect suspicious electronic messages. This algorithm is trained on past phishing and spam email data and comprehensively determines the email body, sender information, link structure, etc.
[0404] When a suspicious email is detected, the server analyzes the IP address and domain information of the email's sender and identifies the sender using specific methods. Based on this identification information, a counter-reaction mechanism is activated, executing a network-based counter-reaction against the identified sender. This puts a burden on the sender, thereby identifying and suppressing the attack.
[0405] The terminal records details of the counter-reaction performed by the server and prepares to securely store and extract the data if cooperation with legal authorities is required. This record includes execution time, target IP address, type of counter-reaction used, and its effect.
[0406] From the user's perspective, the system is integrated into the email interface, providing a secure environment for using email without requiring any special management effort. If an email is detected as suspicious, the user will receive a notification and, if necessary, can review the contents of the suspicious email and receive instructions on the next steps.
[0407] As a concrete example, if this system were implemented on a company's internal email server, upon receiving a phishing email from an external source, the server would immediately detect the email and identify the sender. If the sender was identified as an attacker, it would initiate a counter-reaction and record the details. Subsequently, if necessary, these records would be sent to law enforcement agencies for legal proceedings. This process would deter attacks in a short time and protect the company's information assets.
[0408] The following describes the processing flow.
[0409] Step 1:
[0410] The server scans incoming emails in real time and begins analysis using machine learning algorithms to detect suspicious electronic messages. It analyzes the email body, sender address, link structure, etc., to identify suspicious patterns.
[0411] Step 2:
[0412] If the server determines an email is suspicious, it extracts the sender's IP address and domain information. Using specific methods, it accesses internet resources to obtain more detailed information about the sender.
[0413] Step 3:
[0414] The server plans a network-level counter-response to the identified source. Using a reinforcement learning model, it generates a simulation that loads the source server.
[0415] Step 4:
[0416] The server executes a counter-reaction mechanism, managing the return communication to increase traffic to the source. This places an operational burden on the source and deters its activity.
[0417] Step 5:
[0418] The terminal meticulously records the execution process of the counter-reaction, saving the means used and their effects in a log. This includes the start time of execution, information about the affected source, and the type of counter-reaction.
[0419] Step 6:
[0420] Users can review the information obtained as a result of the system's operation and receive alerts and notifications regarding suspicious emails. If legal action is required, they can receive support in reporting the recorded data to legal authorities.
[0421] Step 7:
[0422] The server uses the data obtained from the series of processes it has carried out to provide feedback in order to update the analysis model and improve performance, and to prepare for the next suspicious email.
[0423] (Example 1)
[0424] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."
[0425] The use of email has led to an increase in information leaks and security threats caused by suspicious electronic messages. Traditional countermeasures have faced challenges in effectively detecting suspicious emails, identifying senders, and taking countermeasures. Furthermore, the systems used to implement these countermeasures often complicate user operations and make it difficult to smoothly handle legal matters.
[0426] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.
[0427] In this invention, the server includes analysis means, identification means, control means, recording means, transmission means, and display means. This makes it possible to detect suspicious electronic messages in real time based on machine learning, identify the sender, automatically perform necessary counter-responses, securely maintain records necessary for legal proceedings, and easily provide appropriate notifications to users.
[0428] "Analysis means" refers to a function that analyzes data from received emails in order to detect suspicious electronic messages, and in particular uses machine learning models to evaluate their content and characteristics.
[0429] "Identification means" refers to a function that analyzes network data based on IP addresses and domain information in order to identify the source of a detected suspicious electronic message.
[0430] The "control means" is a function that selects and appropriately implements a method for performing a network-based reverse response to a identified source.
[0431] A "recording mechanism" is a function that logs detailed information about the reverse reaction that was performed, so that it can be used later for verification, analysis, or legal action.
[0432] "Means of communication" refer to means of providing recorded information to external legal organizations and facilitating necessary legal procedures.
[0433] "Display means" refers to a function that, through an email interface, presents the user with the results of detecting suspicious electronic messages and any necessary notifications.
[0434] This invention is specifically implemented as a system for streamlining the detection and response to suspicious emails in an email system. Embodiments are described below.
[0435] server
[0436] The server is integrated into the mail system and is responsible for continuously monitoring incoming mail. As an analytical tool, the server uses machine learning models to analyze the content, sender information, and link information of received emails. This model is trained on historical phishing and spam email data and is used to detect suspicious patterns. The server further uses identification tools to pinpoint the source of detected suspicious emails and executes network-based counter-reactions via control tools. This includes techniques such as delaying responses to the attacking server and denying connections. These operations are managed by automated programs.
[0437] terminal
[0438] The terminal is responsible for recording details of all counter-reactions performed by the server. Using recording means, it stores the date and time of each counter-reaction, the source IP address, the type of countermeasure used, and its results as a log. This log is stored securely in case it is required by law enforcement authorities.
[0439] User
[0440] Users access this system through an email interface. The display system allows users to immediately understand the status of suspicious emails, providing a secure environment for email use without requiring any special actions. If the server detects a suspicious email, the user receives a notification, allowing them to review the email details and choose the necessary action.
[0441] Specific example
[0442] For example, by implementing this system in a company's information systems, it becomes possible to quickly detect phishing attacks from external sources. In fact, when a server receives a phishing email, it immediately analyzes the email and takes the necessary network response. As a result, the company's information assets are protected from attacks, and a secure business environment is maintained.
[0443] Example of a prompt
[0444] "Please explain the specific steps and actions involved in how your server responds to received phishing emails."
[0445] The flow of the specific processing in Example 1 will be explained using Figure 11.
[0446] Step 1:
[0447] The server sends the received email as input data to the analysis tool. The analysis tool extracts the email body, header information, link URLs, etc. Based on this data, a machine learning model is used to evaluate whether the email is suspicious. Specifically, it checks the link structure of the email and determines whether it contains any unsafe links. An unsuspiciousness score is generated as output.
[0448] Step 2:
[0449] The server uses the score obtained from the analysis means as input and begins identifying the sender using the identification means. Network data analysis technology is used to examine the email sender's IP address and domain information, and an external database is referenced. This process determines whether the sender is a previously reported suspicious source. Specifically, it is compared against a blacklist and, if found, recorded as a suspicious source. The output is detailed information about the identified sender.
[0450] Step 3:
[0451] The server activates the control mechanism based on the source information obtained from the identification mechanism. The control mechanism determines and implements a counter-response against the source. This counter-response may include delaying the connection to the attack source or temporarily blocking communication. Specifically, it sends a command to the attack source server to reduce traffic. The output is the result of the counter-response.
[0452] Step 4:
[0453] The terminal receives the output of the control device and stores the implementation status in the recording device. Specifically, the recording device stores the date and time of the reverse reaction, the target IP address, the method used, and the result in a log file. Detailed log information is generated as output and stored in a format that can be provided to legal authorities as needed.
[0454] (Application Example 1)
[0455] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."
[0456] In today's digital communication environment, users are exposed to a large amount of suspicious communication data, phishing, and spam, and effective and rapid responses to these are required. However, conventional methods have made it difficult to detect suspicious communication data in real time, immediately notify users, and take appropriate defensive measures against the source of the attack. Therefore, there is a need for a means to effectively detect suspicious communication data, improve the speed of response to attacks, and provide communication services to users with peace of mind.
[0457] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.
[0458] In this invention, the server includes an analysis means for detecting suspicious communication data, an information identification means for identifying the source of the suspicious communication data, and a reaction means for executing defensive measures against the identified source. This enables rapid detection of suspicious communication data and immediate execution of defensive measures.
[0459] "Suspicious communication data" refers to data that exhibits abnormal patterns compared to normal communication flows and may be phishing or spam.
[0460] An "analysis tool" is an element that has the function of analyzing past data and current communication content in order to detect suspicious communication data.
[0461] "Information identification means" refers to elements that have functions based on network information and data analysis to identify the source of suspicious communication data.
[0462] A "response mechanism" is an element that has the function of taking appropriate defensive measures against an identified source.
[0463] A "recording means" is an element that has the function of saving the history of when a response means was executed, and managing it so that it can be referenced or analyzed later.
[0464] "Means of cooperation" refers to elements that provide stored history to external organizations and have the function of sharing information for legal proceedings or further investigations.
[0465] A "notification mechanism" is an element that has the function of informing the user of the receipt of suspicious communication data.
[0466] To implement this invention, the system has a configuration for detecting suspicious communication data in real time and responding quickly. The server uses analysis means to analyze communication data acquired from the network. A general-purpose server computer is assumed as the hardware to be used, and machine learning libraries such as TensorFlow and Scikit-learn are suitable as the software. With this software, the server identifies suspicious communication patterns and prepares to respond immediately.
[0467] Furthermore, the information identification means identifies the source of the transmission based on the analyzed data. Network information analysis tools are used for this purpose. The response means implements defensive measures against the identified source. This ensures the security of the server and suppresses unauthorized communications.
[0468] The user's device receives an immediate alert when suspicious communication is detected via a notification system. At this time, a pre-configured prompt is generated by an AI model, prompting the user to take appropriate action. This allows users to quickly take defensive measures even in busy environments.
[0469] A concrete example would be operating this system within a company's network and immediately taking defensive measures when potentially phishing communications are identified. This would ensure the security of the company's information assets. An example of a prompt message would be, "Suspicious communication has been detected. Please review the details and take appropriate action."
[0470] The flow of a specific process in Application Example 1 will be explained using Figure 12.
[0471] Step 1:
[0472] The server acquires communication data via the network. It receives the input communication data in real time and passes it on to the next analysis process. By storing this data in a buffer, the server can perform continuous data processing.
[0473] Step 2:
[0474] The server uses analysis tools to supply the acquired communication data to a machine learning model. Communication data is taken as input, and flags for suspicious data are generated as output. This analysis extracts data features and identifies anomalous patterns. The server then runs the model using TensorFlow or Scikit-learn to evaluate the data trends.
[0475] Step 3:
[0476] If suspicious data is detected, the server activates information identification measures to identify the source. The input data is the analyzed communication data, and the output is the network information of the identified source. This process utilizes network analysis tools to analyze IP addresses and domains to reveal details about the sender.
[0477] Step 4:
[0478] Against the identified source, the server executes response measures and initiates defensive actions. The output includes a log of the defensive actions taken. This step involves network-level operations such as filtering and blocking communications.
[0479] Step 5:
[0480] The server uses recording devices to save the execution results of the response devices and details of suspicious data to a database. Details of the response devices are provided as input, and the output is the completion status of the database recording. This prepares the server for subsequent analysis and legal proceedings.
[0481] Step 6:
[0482] The system detects suspicious communications and sends a warning to the user's device using a notification system. The input is information about the detected suspicious data, and the output is a notification displayed to the user. This notification is displayed on the device's screen, allowing the user to check the situation.
[0483] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.
[0484] In one embodiment of the present invention, the server first utilizes a machine learning model to analyze suspicious electronic messages in real time. When a suspicious message is detected, a process to identify its source is initiated, and the source is identified through network information analysis. Once this identification procedure is complete, the server takes a counter-reaction, implementing a network-based response that places a load on the source. These processing steps and results are recorded by the terminal and provided through a coordinating means if information sharing with legal authorities is required.
[0485] Furthermore, the present invention integrates an emotion engine that recognizes the user's emotions. When a user reads an email, the terminal uses the emotion engine to analyze the user's emotional data and evaluate the user's psychological impact on suspicious messages. Based on this information, the system adjusts the content of warnings and the frequency of notifications to prompt the user to take the most appropriate action.
[0486] As a concrete example, when this system is used in a company, the server immediately detects suspicious emails received by employees and verifies the sender. The emotion engine monitors the employee's reaction to receiving the email, and if signs of stress or confusion are detected, it immediately issues a warning and displays reassuring instructions on the screen. This reduces emotional anxiety and enables calm email management.
[0487] This system enables not only technical defenses but also proactive responses based on user experience.
[0488] The following describes the processing flow.
[0489] Step 1:
[0490] The server analyzes received electronic messages using machine learning algorithms to detect characteristic patterns of suspicious emails. The analysis includes checking the email content, sender address, and whether or not there are links.
[0491] Step 2:
[0492] If an email is identified as suspicious, the server extracts the sender's IP address and domain information. Network information analysis is used to identify the sender and determine its exact location and route.
[0493] Step 3:
[0494] The server uses network traffic to execute a counter-reaction against the identified source. This process aims to deter the attack by placing an additional load on the source.
[0495] Step 4:
[0496] The terminal meticulously records data generated during the reverse reaction process. This includes time, IP address, type of reverse reaction, and process results.
[0497] Step 5:
[0498] When a user opens a suspicious email, the device activates an emotion engine to monitor the user's emotional state. This collects emotional data using information from the camera, microphone, input speed, and other sources.
[0499] Step 6:
[0500] If the emotion engine detects signs of stress or confusion in the user, the device immediately issues a warning and displays a message providing guidance and reassurance. This reduces the user's emotional burden.
[0501] Step 7:
[0502] Based on the recorded data, the device will, if necessary, suggest to the user the possibility of collaborating with legal authorities and prepare to assist with appropriate procedures.
[0503] (Example 2)
[0504] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."
[0505] While conventional information security systems can detect suspicious electronic messages and identify their senders, they often fail to adequately consider the psychological impact on users. In particular, there is a lack of methods to mitigate the stress and confusion users experience when receiving suspicious messages, thus necessitating more comprehensive security measures.
[0506] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.
[0507] In this invention, the server includes information analysis means for detecting suspicious electronic messages, information identification means for identifying the sender, and sentiment analysis means for analyzing emotions and optimizing notifications. This enables comprehensive and efficient countermeasures against fraudulent messages while providing users with a sense of psychological security.
[0508] "Information analysis means" refers to a technical device or method for detecting suspicious electronic messages, and in particular, has the function of analyzing the message content using a machine learning model and determining suspicious elements.
[0509] "Information identification means" refers to a technical device or method used to identify the source of an electronic message, which tracks and determines the source's network information based on communication information analysis.
[0510] A "response mechanism" is a technical device or method for taking a counter-response to a sender identified as suspicious, and has the function of performing deterrent actions such as placing a burden on the sender.
[0511] "Information recording means" refers to a technical device or method for storing information related to the execution of a reverse reaction, and has the function of converting the performed process and its results into data in a format that can be referenced later.
[0512] "Means of collaboration" refers to technical devices or methods for providing recorded information to public institutions, and includes means of communication for sharing information quickly and securely.
[0513] "Emotional analysis means" refers to a technical device or method for analyzing a user's emotions, which evaluates the user's psychological state and acquires data to optimize the system's response.
[0514] "Notification optimization means" refers to a technical device or method for adjusting the content and frequency of notifications sent to the user based on information obtained through sentiment analysis means, and has the function of improving the user experience.
[0515] The system for implementing the present invention is a comprehensive security system for detecting suspicious electronic messages and mitigating the psychological impact on users.
[0516] server
[0517] The server detects the first electronic message it receives using information analysis tools. Specifically, it uses machine learning models such as TensorFlow and PyTorch to detect suspicious patterns hidden within the message content. During detection, natural language processing techniques are used to analyze the message's text data and identify potential risks.
[0518] Next, network analysis tools are used as a means of identifying the source, and the network information of the identified source is checked. Tools such as "Wireshark" and "nmap" are used to identify the source's IP address and hostname, and to determine whether it is a malicious source.
[0519] If the source is determined to be malicious, a network-based response that applies a load is implemented as a means of retaliation. In this case, network tools such as "hping3" are used to take deterrent action against the source attempting malicious communication.
[0520] terminal
[0521] The terminal stores the results of server processing using information recording methods such as "Elastic Stack." The recorded information can later be provided to public institutions through collaborative means. In addition, the terminal displays warnings in a user-friendly format, specifically by adjusting the content and frequency of notifications based on sentiment analysis using notification optimization methods to reduce the user's psychological burden.
[0522] User
[0523] For users, the emotional state when opening an email is monitored through analysis provided by an emotion analysis tool. If software such as "Affectiva" or "Emotion API" detects that the user is experiencing stress, a reassuring message is immediately displayed on the screen.
[0524] For example, when used within a company, the system can immediately issue a warning to employees who receive suspicious emails, reducing psychological stress and encouraging them to take the correct action.
[0525] An example of a prompt might be: "Consider a prompt from a generative AI that evaluates the emotional impact of an received email and immediately warns the user if they feel stressed."
[0526] The flow of the specific processing in Example 2 will be explained using Figure 13.
[0527] Step 1:
[0528] The server receives electronic messages. It receives electronic message data as input, performs spam filtering using tools like "Apache SpamAssassin," and determines whether the message is suspicious. As output, it provides messages deemed suspicious to the next analysis step. Specifically, it checks keywords in the message content and the sender address, and performs scoring.
[0529] Step 2:
[0530] The server inputs suspicious messages into a machine learning model for detailed analysis. Filtered message data is used as input. Suspicious patterns are identified from the message content using "TensorFlow" or "PyTorch". For data processing, natural language processing techniques are used to tokenize the text and analyze frequent words and context. The output is a determination of whether or not a suspicious pattern exists. Specifically, the model produces a prediction score, and it is checked whether that score exceeds a certain threshold.
[0531] Step 3:
[0532] The server analyzes network information to identify the source. Input includes message header information and the source IP address. Tools like Wireshark and nmap are used to determine the geographical location of the IP address and associated hostnames. The output is the identified source information. Specifically, the analysis tool consults a database to check if it matches any known malicious sources.
[0533] Step 4:
[0534] If the server determines that the source is malicious, it will take countermeasures as a response. The input is malicious source information obtained through specific means. It attempts to respond by applying a simulated network load to the source using a tool such as "hping3". The output is log information of the countermeasures that were taken. Specifically, a network load packet is sent.
[0535] Step 5:
[0536] The terminal records the processing results from the server. The input is log data from the server, which is output to the "Elastic Stack" and continuously stored. Specifically, the log collection agent acquires the data and stores it in the database.
[0537] Step 6:
[0538] When a user opens an email, the device monitors the user's emotional state using emotion analysis tools. Inputs include the user's facial image and voice data. Analysis is performed using "Affectiva" and "Emotion API." Data processing involves detecting signs of stress and anxiety through facial recognition and voice analysis. The output is the user's emotional information as a result of the analysis. Specifically, the device's camera and microphone capture data and analyze it in real time.
[0539] Step 7:
[0540] The device adjusts the content and frequency of notifications based on the analyzed sentiment information. The input is the sentiment analysis result, and the device generates a corresponding prompt. The output is the notification message provided to the user. Specifically, warnings and instructions are displayed on the device screen.
[0541] (Application Example 2)
[0542] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."
[0543] With the increase in digital communications, security threats from suspicious communications are on the rise. Furthermore, the psychological impact on users is becoming significant. Conventional security systems focus solely on technical defenses, lacking measures to alleviate the emotional burden on users. This invention aims to provide users with peace of mind by enabling early detection and source identification of suspicious digital communications, analyzing the user's emotional state, and optimizing security responses from a psychological perspective.
[0544] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means.
[0545] In this invention, the server includes analysis means for detecting suspicious digital communications, identification means for identifying the source of the suspicious digital communications, reverse response means for imposing a network load on the identified source, emotion analysis means for analyzing the user's emotional state, and notification adjustment means for adjusting notifications based on the results of the emotion analysis. This not only provides technical protection but also reduces the emotional burden on the user, enabling them to use digital communications with peace of mind.
[0546] "Suspicious digital communications" are digital messages or connections that deviate from normal communication patterns and may pose a security threat.
[0547] "Analysis means" refers to technical means used to detect suspicious digital communications, and includes machine learning models.
[0548] "Identification methods" refer to technical techniques that analyze network information to identify the source of suspicious digital communications.
[0549] A "reverse response method" is a technique used to suppress further suspicious activity by placing a load on the network against the identified source.
[0550] "Recording means" refers to a system for saving the execution status and results of the reverse reaction, intended for later reference or provision to legal authorities.
[0551] "Communication methods" refer to methods of transmitting information to provide stored records to third parties such as legal institutions.
[0552] "Emotional analysis methods" are technologies that analyze a user's psychological state in real time and understand the impact of suspicious digital communications.
[0553] A "notification adjustment mechanism" is a system that uses the results of sentiment analysis to send notifications to users at the appropriate time and with appropriate content.
[0554] To implement this invention, a system is constructed that incorporates the following functions, centered around a server. The server utilizes machine learning models (e.g., TensorFlow or PyTorch) to detect suspicious digital communications in real time. Specifically, the server analyzes emails and network traffic to identify suspicious messages that deviate from normal patterns.
[0555] When the server detects suspicious communication, it identifies the source of the communication by analyzing network information. This process utilizes advanced data analysis techniques. A counter-reaction is then implemented against the identified source, which involves placing a network load on the source. This counter-reaction is intended to deter further suspicious activity from the source.
[0556] In addition, the device uses an emotion analysis engine (e.g., Microsoft Azure Cognitive Services) to understand the user's emotional state when they read electronic messages. This data is used to assess the user's level of anxiety and stress and to adjust notification content and warning frequency as needed. As a result, users can respond calmly to suspicious messages.
[0557] To improve the user experience, a message generation AI model creates customized messages based on the results of sentiment analysis. For example, a user who receives a suspicious message may be notified with the message, "A suspicious email has been detected. For your safety, please delete it without opening the link."
[0558] An example of a prompt might be, "Create a message to help the user relax when they feel stressed." Through this prompt, the AI model can generate an appropriate relaxation message and flexibly adjust the content of the notification to the user.
[0559] The flow of a specific process in Application Example 2 will be explained using Figure 14.
[0560] Step 1:
[0561] The server captures the received digital communications and inputs their content into a machine learning model. The machine learning model detects suspicious patterns by comparing them to normal communication patterns. The output of this step is the communication data that has been determined to be suspicious.
[0562] Step 2:
[0563] The server extracts source information from suspicious communication data and identifies the source by analyzing network information. This analysis uses traffic analysis and reverse IP address lookup techniques. The output is the information of the identified source.
[0564] Step 3:
[0565] The server then performs a counter-reaction, applying a network load to the identified source. This uses load testing tools to restrict the source's communications and prevent further suspicious activity. The output of this step is a record that the load restriction was implemented.
[0566] Step 4:
[0567] When a user opens a suspicious message, the device uses an emotion analysis engine to analyze the user's face and voice tone. The input is data indicating the user's emotional state, and the output is the analyzed emotion data.
[0568] Step 5:
[0569] The device generates appropriate warnings and reassuring notifications based on the results of sentiment analysis. A generative AI model is used for this notification generation. The input is analyzed sentiment data, and the output is a customized message displayed to the user.
[0570] Step 6:
[0571] The user decides how to respond to the suspicious message based on the displayed notification. For example, they might take action such as not clicking on a suspicious link. The output of this step is a record of the user's actions.
[0572] The specific processing unit 290 transmits the result of the specific processing to the headset terminal 314. In the headset terminal 314, the control unit 46A causes the speaker 240 and display 343 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.
[0573] Data generation model 58 is a type of so-called generative AI (Artificial Intelligence). One example of data generation model 58 is ChatGPT (Internet search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[0574] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and specific processing may also be performed by the headset terminal 314.
[0575] [Fourth Embodiment]
[0576] Figure 7 shows an example of the configuration of the data processing system 410 according to the fourth embodiment.
[0577] As shown in Figure 7, the data processing system 410 includes a data processing device 12 and a robot 414. An example of the data processing device 12 is a server.
[0578] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0579] The robot 414 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication interface 44, and a controlled object 443. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, camera 42, and controlled object 443 are also connected to the bus 52.
[0580] The microphone 238 receives voice signals from the user 20 and receives instructions from the user 20. The microphone 238 captures the voice signals from the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.
[0581] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the area around the user 20 (for example, an imaging range defined by a field of view equivalent to the width of a typical healthy person's field of vision).
[0582] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.
[0583] The controlled object 443 includes a display device, LEDs in the eyes, and motors that drive the arms, hands, and feet. The posture and gestures of the robot 414 are controlled by controlling the motors of the arms, hands, and feet. Some of the robot 414's emotions can be expressed by controlling these motors. Furthermore, the robot 414's facial expressions can also be expressed by controlling the illumination state of the LEDs in its eyes.
[0584] Figure 8 shows an example of the main functions of the data processing device 12 and the robot 414. As shown in Figure 8, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.
[0585] The specific processing program 56 is an example of a "program" relating to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[0586] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[0587] In robot 414, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.
[0588] Next, the specific processing performed by the specific processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".
[0589] In one embodiment of the present invention, an intelligent suspicious email detection module is implemented in the server of a mail system. The server analyzes incoming emails in real time and uses a machine learning algorithm to detect suspicious electronic messages. This algorithm is trained on past phishing and spam email data and comprehensively determines the email body, sender information, link structure, etc.
[0590] When a suspicious email is detected, the server analyzes the IP address and domain information of the email's sender and identifies the sender using specific methods. Based on this identification information, a counter-reaction mechanism is activated, executing a network-based counter-reaction against the identified sender. This puts a burden on the sender, thereby identifying and suppressing the attack.
[0591] The terminal records details of the counter-reaction performed by the server and prepares to securely store and extract the data if cooperation with legal authorities is required. This record includes execution time, target IP address, type of counter-reaction used, and its effect.
[0592] From the user's perspective, the system is integrated into the email interface, providing a secure environment for using email without requiring any special management effort. If an email is detected as suspicious, the user will receive a notification and, if necessary, can review the contents of the suspicious email and receive instructions on the next steps.
[0593] As a concrete example, if this system were implemented on a company's internal email server, upon receiving a phishing email from an external source, the server would immediately detect the email and identify the sender. If the sender was identified as an attacker, it would initiate a counter-reaction and record the details. Subsequently, if necessary, these records would be sent to law enforcement agencies for legal proceedings. This process would deter attacks in a short time and protect the company's information assets.
[0594] The following describes the processing flow.
[0595] Step 1:
[0596] The server scans incoming emails in real time and begins analysis using machine learning algorithms to detect suspicious electronic messages. It analyzes the email body, sender address, link structure, etc., to identify suspicious patterns.
[0597] Step 2:
[0598] If the server determines an email is suspicious, it extracts the sender's IP address and domain information. Using specific methods, it accesses internet resources to obtain more detailed information about the sender.
[0599] Step 3:
[0600] The server plans a network-level counter-response to the identified source. Using a reinforcement learning model, it generates a simulation that loads the source server.
[0601] Step 4:
[0602] The server executes a counter-reaction mechanism, managing the return communication to increase traffic to the source. This places an operational burden on the source and deters its activity.
[0603] Step 5:
[0604] The terminal meticulously records the execution process of the counter-reaction, saving the means used and their effects in a log. This includes the start time of execution, information about the affected source, and the type of counter-reaction.
[0605] Step 6:
[0606] Users can review the information obtained as a result of the system's operation and receive alerts and notifications regarding suspicious emails. If legal action is required, they can receive support in reporting the recorded data to legal authorities.
[0607] Step 7:
[0608] The server uses the data obtained from the series of processes it has carried out to provide feedback in order to update the analysis model and improve performance, and to prepare for the next suspicious email.
[0609] (Example 1)
[0610] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".
[0611] The use of email has led to an increase in information leaks and security threats caused by suspicious electronic messages. Traditional countermeasures have faced challenges in effectively detecting suspicious emails, identifying senders, and taking countermeasures. Furthermore, the systems used to implement these countermeasures often complicate user operations and make it difficult to smoothly handle legal matters.
[0612] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.
[0613] In this invention, the server includes analysis means, identification means, control means, recording means, transmission means, and display means. This makes it possible to detect suspicious electronic messages in real time based on machine learning, identify the sender, automatically perform necessary counter-responses, securely maintain records necessary for legal proceedings, and easily provide appropriate notifications to users.
[0614] "Analysis means" refers to a function that analyzes data from received emails in order to detect suspicious electronic messages, and in particular uses machine learning models to evaluate their content and characteristics.
[0615] "Identification means" refers to a function that analyzes network data based on IP addresses and domain information in order to identify the source of a detected suspicious electronic message.
[0616] The "control means" is a function that selects and appropriately implements a method for performing a network-based reverse response to a identified source.
[0617] A "recording mechanism" is a function that logs detailed information about the reverse reaction that was performed, so that it can be used later for verification, analysis, or legal action.
[0618] "Means of communication" refer to means of providing recorded information to external legal organizations and facilitating necessary legal procedures.
[0619] "Display means" refers to a function that, through an email interface, presents the user with the results of detecting suspicious electronic messages and any necessary notifications.
[0620] This invention is specifically implemented as a system for streamlining the detection and response to suspicious emails in an email system. Embodiments are described below.
[0621] server
[0622] The server is integrated into the mail system and is responsible for continuously monitoring incoming mail. As an analytical tool, the server uses machine learning models to analyze the content, sender information, and link information of received emails. This model is trained on historical phishing and spam email data and is used to detect suspicious patterns. The server further uses identification tools to pinpoint the source of detected suspicious emails and executes network-based counter-reactions via control tools. This includes techniques such as delaying responses to the attacking server and denying connections. These operations are managed by automated programs.
[0623] terminal
[0624] The terminal is responsible for recording details of all counter-reactions performed by the server. Using recording means, it stores the date and time of each counter-reaction, the source IP address, the type of countermeasure used, and its results as a log. This log is stored securely in case it is required by law enforcement authorities.
[0625] User
[0626] Users access this system through an email interface. The display system allows users to immediately understand the status of suspicious emails, providing a secure environment for email use without requiring any special actions. If the server detects a suspicious email, the user receives a notification, allowing them to review the email details and choose the necessary action.
[0627] Specific example
[0628] For example, by implementing this system in a company's information systems, it becomes possible to quickly detect phishing attacks from external sources. In fact, when a server receives a phishing email, it immediately analyzes the email and takes the necessary network response. As a result, the company's information assets are protected from attacks, and a secure business environment is maintained.
[0629] Example of a prompt
[0630] "Please explain the specific steps and actions involved in how your server responds to received phishing emails."
[0631] The flow of the specific processing in Example 1 will be explained using Figure 11.
[0632] Step 1:
[0633] The server sends the received email as input data to the analysis tool. The analysis tool extracts the email body, header information, link URLs, etc. Based on this data, a machine learning model is used to evaluate whether the email is suspicious. Specifically, it checks the link structure of the email and determines whether it contains any unsafe links. An unsuspiciousness score is generated as output.
[0634] Step 2:
[0635] The server uses the score obtained from the analysis means as input and begins identifying the sender using the identification means. Network data analysis technology is used to examine the email sender's IP address and domain information, and an external database is referenced. This process determines whether the sender is a previously reported suspicious source. Specifically, it is compared against a blacklist and, if found, recorded as a suspicious source. The output is detailed information about the identified sender.
[0636] Step 3:
[0637] The server activates the control mechanism based on the source information obtained from the identification mechanism. The control mechanism determines and implements a counter-response against the source. This counter-response may include delaying the connection to the attack source or temporarily blocking communication. Specifically, it sends a command to the attack source server to reduce traffic. The output is the result of the counter-response.
[0638] Step 4:
[0639] The terminal receives the output of the control device and stores the implementation status in the recording device. Specifically, the recording device stores the date and time of the reverse reaction, the target IP address, the method used, and the result in a log file. Detailed log information is generated as output and stored in a format that can be provided to legal authorities as needed.
[0640] (Application Example 1)
[0641] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".
[0642] In today's digital communication environment, users are exposed to a large amount of suspicious communication data, phishing, and spam, and effective and rapid responses to these are required. However, conventional methods have made it difficult to detect suspicious communication data in real time, immediately notify users, and take appropriate defensive measures against the source of the attack. Therefore, there is a need for a means to effectively detect suspicious communication data, improve the speed of response to attacks, and provide communication services to users with peace of mind.
[0643] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.
[0644] In this invention, the server includes an analysis means for detecting suspicious communication data, an information identification means for identifying the source of the suspicious communication data, and a reaction means for executing defensive measures against the identified source. This enables rapid detection of suspicious communication data and immediate execution of defensive measures.
[0645] "Suspicious communication data" refers to data that exhibits abnormal patterns compared to normal communication flows and may be phishing or spam.
[0646] An "analysis tool" is an element that has the function of analyzing past data and current communication content in order to detect suspicious communication data.
[0647] "Information identification means" refers to elements that have functions based on network information and data analysis to identify the source of suspicious communication data.
[0648] A "response mechanism" is an element that has the function of taking appropriate defensive measures against an identified source.
[0649] A "recording means" is an element that has the function of saving the history of when a response means was executed, and managing it so that it can be referenced or analyzed later.
[0650] "Means of cooperation" refers to elements that provide stored history to external organizations and have the function of sharing information for legal proceedings or further investigations.
[0651] A "notification mechanism" is an element that has the function of informing the user of the receipt of suspicious communication data.
[0652] To implement this invention, the system has a configuration for detecting suspicious communication data in real time and responding quickly. The server uses analysis means to analyze communication data acquired from the network. A general-purpose server computer is assumed as the hardware to be used, and machine learning libraries such as TensorFlow and Scikit-learn are suitable as the software. With this software, the server identifies suspicious communication patterns and prepares to respond immediately.
[0653] Furthermore, the information identification means identifies the source of the transmission based on the analyzed data. Network information analysis tools are used for this purpose. The response means implements defensive measures against the identified source. This ensures the security of the server and suppresses unauthorized communications.
[0654] The user's device receives an immediate alert when suspicious communication is detected via a notification system. At this time, a pre-configured prompt is generated by an AI model, prompting the user to take appropriate action. This allows users to quickly take defensive measures even in busy environments.
[0655] A concrete example would be operating this system within a company's network and immediately taking defensive measures when potentially phishing communications are identified. This would ensure the security of the company's information assets. An example of a prompt message would be, "Suspicious communication has been detected. Please review the details and take appropriate action."
[0656] The flow of a specific process in Application Example 1 will be explained using Figure 12.
[0657] Step 1:
[0658] The server acquires communication data via the network. It receives the input communication data in real time and passes it on to the next analysis process. By storing this data in a buffer, the server can perform continuous data processing.
[0659] Step 2:
[0660] The server uses analysis tools to supply the acquired communication data to a machine learning model. Communication data is taken as input, and flags for suspicious data are generated as output. This analysis extracts data features and identifies anomalous patterns. The server then runs the model using TensorFlow or Scikit-learn to evaluate the data trends.
[0661] Step 3:
[0662] If suspicious data is detected, the server activates information identification measures to identify the source. The input data is the analyzed communication data, and the output is the network information of the identified source. This process utilizes network analysis tools to analyze IP addresses and domains to reveal details about the sender.
[0663] Step 4:
[0664] Against the identified source, the server executes response measures and initiates defensive actions. The output includes a log of the defensive actions taken. This step involves network-level operations such as filtering and blocking communications.
[0665] Step 5:
[0666] The server uses recording devices to save the execution results of the response devices and details of suspicious data to a database. Details of the response devices are provided as input, and the output is the completion status of the database recording. This prepares the server for subsequent analysis and legal proceedings.
[0667] Step 6:
[0668] The system detects suspicious communications and sends a warning to the user's device using a notification system. The input is information about the detected suspicious data, and the output is a notification displayed to the user. This notification is displayed on the device's screen, allowing the user to check the situation.
[0669] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.
[0670] In one embodiment of the present invention, the server first utilizes a machine learning model to analyze suspicious electronic messages in real time. When a suspicious message is detected, a process to identify its source is initiated, and the source is identified through network information analysis. Once this identification procedure is complete, the server takes a counter-reaction, implementing a network-based response that places a load on the source. These processing steps and results are recorded by the terminal and provided through a coordinating means if information sharing with legal authorities is required.
[0671] Furthermore, the present invention integrates an emotion engine that recognizes the user's emotions. When a user reads an email, the terminal uses the emotion engine to analyze the user's emotional data and evaluate the user's psychological impact on suspicious messages. Based on this information, the system adjusts the content of warnings and the frequency of notifications to prompt the user to take the most appropriate action.
[0672] As a concrete example, when this system is used in a company, the server immediately detects suspicious emails received by employees and verifies the sender. The emotion engine monitors the employee's reaction to receiving the email, and if signs of stress or confusion are detected, it immediately issues a warning and displays reassuring instructions on the screen. This reduces emotional anxiety and enables calm email management.
[0673] This system enables not only technical defenses but also proactive responses based on user experience.
[0674] The following describes the processing flow.
[0675] Step 1:
[0676] The server analyzes received electronic messages using machine learning algorithms to detect characteristic patterns of suspicious emails. The analysis includes checking the email content, sender address, and whether or not there are links.
[0677] Step 2:
[0678] If an email is identified as suspicious, the server extracts the sender's IP address and domain information. Network information analysis is used to identify the sender and determine its exact location and route.
[0679] Step 3:
[0680] The server uses network traffic to execute a counter-reaction against the identified source. This process aims to deter the attack by placing an additional load on the source.
[0681] Step 4:
[0682] The terminal meticulously records data generated during the reverse reaction process. This includes time, IP address, type of reverse reaction, and process results.
[0683] Step 5:
[0684] When a user opens a suspicious email, the device activates an emotion engine to monitor the user's emotional state. This collects emotional data using information from the camera, microphone, input speed, and other sources.
[0685] Step 6:
[0686] If the emotion engine detects signs of stress or confusion in the user, the device immediately issues a warning and displays a message providing guidance and reassurance. This reduces the user's emotional burden.
[0687] Step 7:
[0688] Based on the recorded data, the device will, if necessary, suggest to the user the possibility of collaborating with legal authorities and prepare to assist with appropriate procedures.
[0689] (Example 2)
[0690] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".
[0691] While conventional information security systems can detect suspicious electronic messages and identify their senders, they often fail to adequately consider the psychological impact on users. In particular, there is a lack of methods to mitigate the stress and confusion users experience when receiving suspicious messages, thus necessitating more comprehensive security measures.
[0692] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.
[0693] In this invention, the server includes information analysis means for detecting suspicious electronic messages, information identification means for identifying the sender, and sentiment analysis means for analyzing emotions and optimizing notifications. This enables comprehensive and efficient countermeasures against fraudulent messages while providing users with a sense of psychological security.
[0694] "Information analysis means" refers to a technical device or method for detecting suspicious electronic messages, and in particular, has the function of analyzing the message content using a machine learning model and determining suspicious elements.
[0695] "Information identification means" refers to a technical device or method used to identify the source of an electronic message, which tracks and determines the source's network information based on communication information analysis.
[0696] A "response mechanism" is a technical device or method for taking a counter-response to a sender identified as suspicious, and has the function of performing deterrent actions such as placing a burden on the sender.
[0697] "Information recording means" refers to a technical device or method for storing information related to the execution of a reverse reaction, and has the function of converting the performed process and its results into data in a format that can be referenced later.
[0698] "Means of collaboration" refers to technical devices or methods for providing recorded information to public institutions, and includes means of communication for sharing information quickly and securely.
[0699] "Emotional analysis means" refers to a technical device or method for analyzing a user's emotions, which evaluates the user's psychological state and acquires data to optimize the system's response.
[0700] "Notification optimization means" refers to a technical device or method for adjusting the content and frequency of notifications sent to the user based on information obtained through sentiment analysis means, and has the function of improving the user experience.
[0701] The system for implementing the present invention is a comprehensive security system for detecting suspicious electronic messages and mitigating the psychological impact on users.
[0702] server
[0703] The server detects the first electronic message it receives using information analysis tools. Specifically, it uses machine learning models such as TensorFlow and PyTorch to detect suspicious patterns hidden within the message content. During detection, natural language processing techniques are used to analyze the message's text data and identify potential risks.
[0704] Next, network analysis tools are used as a means of identifying the source, and the network information of the identified source is checked. Tools such as "Wireshark" and "nmap" are used to identify the source's IP address and hostname, and to determine whether it is a malicious source.
[0705] If the source is determined to be malicious, a network-based response that applies a load is implemented as a means of retaliation. In this case, network tools such as "hping3" are used to take deterrent action against the source attempting malicious communication.
[0706] terminal
[0707] The terminal stores the results of server processing using information recording methods such as "Elastic Stack." The recorded information can later be provided to public institutions through collaborative means. In addition, the terminal displays warnings in a user-friendly format, specifically by adjusting the content and frequency of notifications based on sentiment analysis using notification optimization methods to reduce the user's psychological burden.
[0708] User
[0709] For users, the emotional state when opening an email is monitored through analysis provided by an emotion analysis tool. If software such as "Affectiva" or "Emotion API" detects that the user is experiencing stress, a reassuring message is immediately displayed on the screen.
[0710] For example, when used within a company, the system can immediately issue a warning to employees who receive suspicious emails, reducing psychological stress and encouraging them to take the correct action.
[0711] An example of a prompt might be: "Consider a prompt from a generative AI that evaluates the emotional impact of an received email and immediately warns the user if they feel stressed."
[0712] The flow of the specific processing in Example 2 will be explained using Figure 13.
[0713] Step 1:
[0714] The server receives electronic messages. It receives electronic message data as input, performs spam filtering using tools like "Apache SpamAssassin," and determines whether the message is suspicious. As output, it provides messages deemed suspicious to the next analysis step. Specifically, it checks keywords in the message content and the sender address, and performs scoring.
[0715] Step 2:
[0716] The server inputs suspicious messages into a machine learning model for detailed analysis. Filtered message data is used as input. Suspicious patterns are identified from the message content using "TensorFlow" or "PyTorch". For data processing, natural language processing techniques are used to tokenize the text and analyze frequent words and context. The output is a determination of whether or not a suspicious pattern exists. Specifically, the model produces a prediction score, and it is checked whether that score exceeds a certain threshold.
[0717] Step 3:
[0718] The server analyzes network information to identify the source. Input includes message header information and the source IP address. Tools like Wireshark and nmap are used to determine the geographical location of the IP address and associated hostnames. The output is the identified source information. Specifically, the analysis tool consults a database to check if it matches any known malicious sources.
[0719] Step 4:
[0720] If the server determines that the source is malicious, it will take countermeasures as a response. The input is malicious source information obtained through specific means. It attempts to respond by applying a simulated network load to the source using a tool such as "hping3". The output is log information of the countermeasures that were taken. Specifically, a network load packet is sent.
[0721] Step 5:
[0722] The terminal records the processing results from the server. The input is log data from the server, which is output to the "Elastic Stack" and continuously stored. Specifically, the log collection agent acquires the data and stores it in the database.
[0723] Step 6:
[0724] When a user opens an email, the device monitors the user's emotional state using emotion analysis tools. Inputs include the user's facial image and voice data. Analysis is performed using "Affectiva" and "Emotion API." Data processing involves detecting signs of stress and anxiety through facial recognition and voice analysis. The output is the user's emotional information as a result of the analysis. Specifically, the device's camera and microphone capture data and analyze it in real time.
[0725] Step 7:
[0726] The device adjusts the content and frequency of notifications based on the analyzed sentiment information. The input is the sentiment analysis result, and the device generates a corresponding prompt. The output is the notification message provided to the user. Specifically, warnings and instructions are displayed on the device screen.
[0727] (Application Example 2)
[0728] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".
[0729] With the increase in digital communications, security threats from suspicious communications are on the rise. Furthermore, the psychological impact on users is becoming significant. Conventional security systems focus solely on technical defenses, lacking measures to alleviate the emotional burden on users. This invention aims to provide users with peace of mind by enabling early detection and source identification of suspicious digital communications, analyzing the user's emotional state, and optimizing security responses from a psychological perspective.
[0730] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means.
[0731] In this invention, the server includes analysis means for detecting suspicious digital communications, identification means for identifying the source of the suspicious digital communications, reverse response means for imposing a network load on the identified source, emotion analysis means for analyzing the user's emotional state, and notification adjustment means for adjusting notifications based on the results of the emotion analysis. This not only provides technical protection but also reduces the emotional burden on the user, enabling them to use digital communications with peace of mind.
[0732] "Suspicious digital communications" are digital messages or connections that deviate from normal communication patterns and may pose a security threat.
[0733] "Analysis means" refers to technical means used to detect suspicious digital communications, and includes machine learning models.
[0734] "Identification methods" refer to technical techniques that analyze network information to identify the source of suspicious digital communications.
[0735] A "reverse response method" is a technique used to suppress further suspicious activity by placing a load on the network against the identified source.
[0736] "Recording means" refers to a system for saving the execution status and results of the reverse reaction, intended for later reference or provision to legal authorities.
[0737] "Communication methods" refer to methods of transmitting information to provide stored records to third parties such as legal institutions.
[0738] "Emotional analysis methods" are technologies that analyze a user's psychological state in real time and understand the impact of suspicious digital communications.
[0739] A "notification adjustment mechanism" is a system that uses the results of sentiment analysis to send notifications to users at the appropriate time and with appropriate content.
[0740] To implement this invention, a system is constructed that incorporates the following functions, centered around a server. The server utilizes machine learning models (e.g., TensorFlow or PyTorch) to detect suspicious digital communications in real time. Specifically, the server analyzes emails and network traffic to identify suspicious messages that deviate from normal patterns.
[0741] When the server detects suspicious communication, it identifies the source of the communication by analyzing network information. This process utilizes advanced data analysis techniques. A counter-reaction is then implemented against the identified source, which involves placing a network load on the source. This counter-reaction is intended to deter further suspicious activity from the source.
[0742] In addition, the device uses an emotion analysis engine (e.g., Microsoft Azure Cognitive Services) to understand the user's emotional state when they read electronic messages. This data is used to assess the user's level of anxiety and stress and to adjust notification content and warning frequency as needed. As a result, users can respond calmly to suspicious messages.
[0743] To improve the user experience, a message generation AI model creates customized messages based on the results of sentiment analysis. For example, a user who receives a suspicious message may be notified with the message, "A suspicious email has been detected. For your safety, please delete it without opening the link."
[0744] An example of a prompt might be, "Create a message to help the user relax when they feel stressed." Through this prompt, the AI model can generate an appropriate relaxation message and flexibly adjust the content of the notification to the user.
[0745] The flow of a specific process in Application Example 2 will be explained using Figure 14.
[0746] Step 1:
[0747] The server captures the received digital communications and inputs their content into a machine learning model. The machine learning model detects suspicious patterns by comparing them to normal communication patterns. The output of this step is the communication data that has been determined to be suspicious.
[0748] Step 2:
[0749] The server extracts source information from suspicious communication data and identifies the source by analyzing network information. This analysis uses traffic analysis and reverse IP address lookup techniques. The output is the information of the identified source.
[0750] Step 3:
[0751] The server then performs a counter-reaction, applying a network load to the identified source. This uses load testing tools to restrict the source's communications and prevent further suspicious activity. The output of this step is a record that the load restriction was implemented.
[0752] Step 4:
[0753] When a user opens a suspicious message, the device uses an emotion analysis engine to analyze the user's face and voice tone. The input is data indicating the user's emotional state, and the output is the analyzed emotion data.
[0754] Step 5:
[0755] The device generates appropriate warnings and reassuring notifications based on the results of sentiment analysis. A generative AI model is used for this notification generation. The input is analyzed sentiment data, and the output is a customized message displayed to the user.
[0756] Step 6:
[0757] The user decides how to respond to the suspicious message based on the displayed notification. For example, they might take action such as not clicking on a suspicious link. The output of this step is a record of the user's actions.
[0758] The specific processing unit 290 transmits the result of the specific processing to the robot 414. In the robot 414, the control unit 46A causes the speaker 240 and the controlled object 443 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.
[0759] Data generation model 58 is a type of so-called generative AI (Artificial Intelligence). One example of data generation model 58 is ChatGPT (Internet search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[0760] In the above embodiment, an example was given in which the specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and the specific processing may also be performed by the robot 414.
[0761] Furthermore, the emotion identification model 59, acting as an emotion engine, may determine the user's emotion according to a specific mapping. Specifically, the emotion identification model 59 may determine the user's emotion according to a specific mapping, which is an emotion map (see Figure 9). Similarly, the emotion identification model 59 may also determine the robot's emotion, and the identification processing unit 290 may perform identification processing using the robot's emotion.
[0762] Figure 9 shows an emotion map 400 in which multiple emotions are mapped. In the emotion map 400, emotions are arranged in concentric circles radiating from the center. The closer to the center of the concentric circles, the more primitive the emotions are located. Further out of the concentric circles, emotions representing states and actions arising from mental states are located. Emotion is a concept that includes feelings and mental states. On the left side of the concentric circles, emotions that are generally generated from reactions occurring in the brain are located. On the right side of the concentric circles, emotions that are generally induced by situational judgment are located. Above and below the concentric circles, emotions that are generally generated from reactions occurring in the brain and induced by situational judgment are located. In addition, the emotion of "pleasure" is located on the upper side of the concentric circles, and the emotion of "displeasure" is located on the lower side. Thus, in the emotion map 400, multiple emotions are mapped based on the structure in which emotions arise, and emotions that are likely to occur simultaneously are mapped close together.
[0763] These emotions are distributed at the 3 o'clock position on the Emotion Map 400, and usually fluctuate between feelings of security and anxiety. In the right half of the Emotion Map 400, situational awareness takes precedence over internal feelings, resulting in a calm impression.
[0764] The inside of the Emotion Map 400 represents inner thoughts, while the outside represents actions. Therefore, the further you go from the outside of the Emotion Map 400, the more visible (expressed in actions) your emotions become.
[0765] Here, human emotions are based on various balances, such as posture and blood sugar levels. When these balances deviate from the ideal, it results in discomfort, and when they approach the ideal, it results in pleasure. Similarly, in robots, cars, motorcycles, etc., emotions can be created based on various balances, such as posture and battery level. When these balances deviate from the ideal, it results in discomfort, and when they approach the ideal, it results in pleasure. The emotion map can be generated, for example, based on Dr. Mitsuyoshi's emotion map (Research on a system for analyzing brain physiological signals of speech emotion recognition and emotion, Tokushima University, doctoral dissertation: https: / / ci.nii.ac.jp / naid / 500000375379). The left half of the emotion map contains emotions belonging to a region called "response," where sensation is dominant. The right half of the emotion map contains emotions belonging to a region called "situation," where situational awareness is dominant.
[0766] The emotion map defines two emotions that promote learning. One is the emotion around the middle of the negative "repentance" and "reflection" on the situation side. In other words, it is when the robot experiences negative emotions such as "I never want to feel this way again" or "I don't want to be scolded again." The other is the emotion around the positive "desire" on the reaction side. In other words, it is when the robot has positive feelings such as "I want more" or "I want to know more."
[0767] The emotion identification model 59 inputs user input into a pre-trained neural network, obtains emotion values representing each emotion shown in the emotion map 400, and determines the user's emotion. This neural network is pre-trained based on multiple training data sets, which are combinations of user input and emotion values representing each emotion shown in the emotion map 400. Furthermore, this neural network is trained so that emotions located close together have similar values, as shown in the emotion map 900 in Figure 10. Figure 10 shows an example where multiple emotions such as "reassured," "calm," and "confident" have similar emotion values.
[0768] The above description primarily focuses on the functions of the data processing device 12 in relation to this disclosure. However, the system related to this disclosure is not necessarily implemented on a server. The system related to this disclosure may be implemented as a general information processing system. This disclosure may be implemented, for example, as a software program that runs on a personal computer or as an application that runs on a smartphone. The method related to this disclosure may be provided to users in SaaS (Software as a Service) format.
[0769] In the above embodiment, an example was given in which a specific process is performed by a single computer 22. However, the technology of this disclosure is not limited thereto, and a distributed processing of the specific process may be performed by multiple computers, including computer 22. For example, a data generation model 58 may be provided in an external device of the data processing device 12, and the external device may generate data according to the input data.
[0770] In the above embodiment, an example was given in which the specific processing program 56 is stored in the storage 32, but the technology of this disclosure is not limited thereto. For example, the specific processing program 56 may be stored in a portable, computer-readable, non-temporary storage medium such as a USB (Universal Serial Bus) memory. The specific processing program 56 stored in the non-temporary storage medium is installed in the computer 22 of the data processing device 12. The processor 28 executes specific processing according to the specific processing program 56.
[0771] Alternatively, the specific processing program 56 may be stored in a storage device such as a server connected to the data processing device 12 via the network 54, and the specific processing program 56 may be downloaded and installed on the computer 22 in response to a request from the data processing device 12.
[0772] Furthermore, it is not necessary to store the entirety of the specific processing program 56 in a storage device such as a server connected to the data processing device 12 via the network 54, or to store the entirety of the specific processing program 56 in the storage 32; it is acceptable to store only a portion of the specific processing program 56.
[0773] The following types of processors can be used as hardware resources to perform specific processing. Examples of processors include a CPU, a general-purpose processor that functions as a hardware resource to perform specific processing by executing software, i.e., a program. Other examples of processors include dedicated electrical circuits, such as FPGAs (Field-Programmable Gate Arrays), PLDs (Programmable Logic Devices), or ASICs (Application Specific Integrated Circuits), which have circuit configurations specifically designed to perform specific processing. All of these processors have built-in or connected memory, and all of them perform specific processing by using memory.
[0774] The hardware resource that performs a specific process may consist of one of these various processors, or it may consist of a combination of two or more processors of the same or different types (for example, a combination of multiple FPGAs, or a combination of a CPU and an FPGA). Alternatively, the hardware resource that performs a specific process may consist of a single processor.
[0775] Examples of configurations using a single processor include, firstly, a configuration in which one or more CPUs and software are combined to form a single processor, and this processor functions as a hardware resource that performs a specific process. Secondly, there is a configuration using a processor that realizes the functions of the entire system, including multiple hardware resources that perform a specific process, on a single IC chip, as exemplified by SoCs (System-on-a-chip). In this way, a specific process is realized using one or more of the above types of processors as hardware resources.
[0776] Furthermore, the hardware structure of these various processors can more specifically utilize electrical circuits that combine circuit elements such as semiconductor devices. Also, the specific processing described above is merely an example. Therefore, it goes without saying that unnecessary steps can be deleted, new steps added, or the processing order rearranged, as long as it does not deviate from the main purpose.
[0777] The descriptions and illustrations presented above are detailed explanations of the technical aspects of this disclosure and are merely examples of the technical aspects. For example, the above descriptions of the structure, function, operation, and effect are examples of the structure, function, operation, and effect of the technical aspects of this disclosure. Therefore, it goes without saying that you may delete unnecessary parts, add new elements, or replace elements in the descriptions and illustrations presented above, as long as you do not deviate from the essence of the technical aspects of this disclosure. Furthermore, in order to avoid confusion and facilitate understanding of the technical aspects of this disclosure, explanations of common technical knowledge and the like that do not require special explanation to enable the implementation of the technical aspects of this disclosure have been omitted from the descriptions and illustrations presented above.
[0778] All documents, patent applications, and technical standards described herein are incorporated by reference to the same extent as if each individual document, patent application, and technical standard were specifically and individually noted as being incorporated by reference.
[0779] The following is further disclosed regarding the embodiments described above.
[0780] (Claim 1)
[0781] An analytical means for detecting suspicious electronic messages,
[0782] A means for identifying the source of the suspicious electronic message,
[0783] A reverse response means that performs a reverse response to the identified source,
[0784] Recording means for storing records relating to the execution of the reverse reaction,
[0785] A means of providing the aforementioned records to legal authorities,
[0786] A system that includes this.
[0787] (Claim 2)
[0788] The system according to claim 1, wherein the analysis means detects suspicious electronic messages using a machine learning model.
[0789] (Claim 3)
[0790] The system according to claim 1, wherein the identifying means identifies the source of the transmission based on network information analysis.
[0791] "Example 1"
[0792] (Claim 1)
[0793] An analysis means for detecting suspicious electronic messages,
[0794] An identification means for identifying the source of the suspicious electronic message,
[0795] A control means that performs a network-based reverse response to the identified source,
[0796] A recording means for recording information regarding the execution of the reverse reaction,
[0797] A means of providing the recorded information to an external legal organization,
[0798] A display means that provides notifications to the user via an email interface,
[0799] A communication system that includes this.
[0800] (Claim 2)
[0801] The system according to claim 1, wherein the analysis means uses a machine learning model to detect suspicious electronic messages and evaluates them using a scoring system.
[0802] (Claim 3)
[0803] The system according to claim 1, wherein the identification means identifies the source of the transmission based on network data analysis.
[0804] "Application Example 1"
[0805] (Claim 1)
[0806] An analysis method for detecting suspicious communication data,
[0807] Information identification means for identifying the source of the suspicious communication data,
[0808] A response means for executing defensive measures against the identified source,
[0809] Recording means for storing a history of the execution of the aforementioned reaction,
[0810] A means of cooperation to provide the aforementioned history to an external organization,
[0811] The analysis means includes a notification means that sends a notification to the user when it detects abnormal communication data,
[0812] An information processing system that includes this.
[0813] (Claim 2)
[0814] The information processing system according to claim 1, wherein the analysis means detects suspicious communication data using a data processing model.
[0815] (Claim 3)
[0816] The information processing system according to claim 1, wherein the information identification means identifies the source of the transmission based on network data analysis.
[0817] "Example 2 of combining an emotion engine"
[0818] (Claim 1)
[0819] Information analysis means for detecting suspicious electronic messages,
[0820] Information identification means for identifying the source of the suspicious electronic message,
[0821] A response means that performs a reverse response to the identified sender,
[0822] Information recording means for storing records relating to the execution of the reverse reaction,
[0823] A means of providing the aforementioned records to public institutions,
[0824] A sentiment analysis method that analyzes user emotions and evaluates the psychological impact of suspicious messages,
[0825] Notification optimization means that adjusts the content and frequency of notifications based on the aforementioned sentiment analysis,
[0826] A system that includes this.
[0827] (Claim 2)
[0828] The system according to claim 1, wherein the information analysis means detects suspicious electronic messages using a machine learning model.
[0829] (Claim 3)
[0830] The system according to claim 1, wherein the information identification means identifies the source of the transmission based on the analysis of communication information.
[0831] "Application example 2 when combining with an emotional engine"
[0832] (Claim 1)
[0833] An analytical means for detecting suspicious digital communications,
[0834] A means for identifying the source of the suspicious digital communication,
[0835] A reverse response means that imposes a network load on the identified source,
[0836] A recording means for storing information regarding the execution of the reverse reaction,
[0837] A means of providing the aforementioned information to a legal authority,
[0838] A means of analyzing the emotional state of a user,
[0839] A notification adjustment means that adjusts notifications based on the results of the aforementioned sentiment analysis,
[0840] A system that includes this.
[0841] (Claim 2)
[0842] The system according to claim 1, wherein the analysis means detects suspicious digital communications using a machine learning model.
[0843] (Claim 3)
[0844] The system according to claim 1, wherein the identifying means analyzes network information to identify the source of the transmission. [Explanation of Symbols]
[0845] 10, 210, 310, 410 Data Processing Systems 12 Data Processing Devices 14 Smart Devices 214 Smart Glasses 314 Headset-type terminal 414 Robots< / url:> < / url:> < / url:> < / url:>
Claims
1. An analysis method for detecting suspicious communication data, Information identification means for identifying the source of the suspicious communication data, A response means for executing defensive measures against the identified source, Recording means for storing a history of the execution of the aforementioned reaction, A means of cooperation to provide the aforementioned history to an external organization, The analysis means includes a notification means that sends a notification to the user when it detects abnormal communication data, An information processing system that includes this.
2. The information processing system according to claim 1, wherein the analysis means detects suspicious communication data using a data processing model.
3. The information processing system according to claim 1, wherein the information identification means identifies the source of the transmission based on network data analysis.
Citation Information
Patent Citations
Persona chatbot control method and system
JP2022180282A