system
The system addresses the challenge of real-time threat detection and response by integrating machine learning for anomaly detection, continuous retraining, and emotion recognition, ensuring swift and personalized security measures.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- SOFTBANK GROUP CORP
- Filing Date
- 2024-12-12
- Publication Date
- 2026-06-24
Smart Images

Figure 2026103613000001_ABST
Abstract
Description
Technical Field
[0001] The technology of the present disclosure relates to a system.
Background Art
[0002] Patent Document 1 discloses a persona chatbot control method performed by at least one processor, including steps of receiving a user utterance, adding the user utterance to a prompt including an instruction sentence related to an explanation of a character of the chatbot, encoding the prompt, and inputting the encoded prompt into a language model to generate a chatbot utterance in response to the user utterance.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] In recent years, the security threats faced by enterprises have become increasingly sophisticated and complex, and it has become difficult to effectively detect and respond to such threats only with conventional manual response methods. Also, there is a demand for predictive capabilities to quickly respond to unknown threats, but this is not sufficient with conventional technologies either.
Means for Solving the Problems
[0005] This invention provides a means to identify and immediately respond to new threats that could not be detected by conventional systems by utilizing machine learning models to monitor network traffic in real time and detect anomalies. Specifically, it collects network traffic data in real time, detects anomalies using machine learning models, and automatically classifies and addresses incidents. It also predicts future threats based on historical data and enables the AI model to respond to the latest threats through continuous retraining. Furthermore, it also performs security assessment and protection of the system itself.
[0006] "Network traffic data" refers to the information of all data packets transmitted and received over a network, and represents the flow of data recorded within a certain period of time.
[0007] "Real-time monitoring" means continuously monitoring network traffic data as it occurs, allowing for immediate data review and analysis.
[0008] A "machine learning model" is a collection of programs that learn patterns based on vast amounts of data, and use them to detect anomalies or predict future trends.
[0009] An "abnormal traffic pattern" refers to a collection of data that exhibits behavior or trends different from normal network traffic, and may indicate a potential security threat.
[0010] An "incident" refers to a security anomaly or potential threat to an information system, and signifies an event that requires action.
[0011] "Classification" involves dividing detected incidents into multiple categories based on their nature and risk, enabling effective responses.
[0012] "Setting priorities" means determining the urgency of the response based on the degree of risk of an incident, and deciding which events to address first.
[0013] "Initial response" refers to the basic safety measures and response actions taken immediately in response to a detected incident, and is the first step to prevent the damage from escalating.
[0014] "Prediction" is the process of analyzing accumulated data and current conditions to estimate potential future events and trends.
[0015] "Retraining" is the process of updating a machine learning model using new data and information to enable more accurate analysis and prediction.
[0016] "Security assessment and protection" refers to the activity of protecting a system by regularly evaluating its vulnerabilities and taking necessary defensive measures. [Brief explanation of the drawing]
[0017] [Figure 1] This is a conceptual diagram showing an example of the configuration of a data processing system according to the first embodiment. [Figure 2] This is a conceptual diagram showing an example of the essential functions of a data processing device and a smart device according to the first embodiment. [Figure 3] This is a conceptual diagram showing an example of the configuration of a data processing system according to the second embodiment. [Figure 4] This is a conceptual diagram showing an example of the main functions of a data processing device and smart glasses according to the second embodiment. [Figure 5] This is a conceptual diagram showing an example of the configuration of a data processing system according to the third embodiment. [Figure 6] This is a conceptual diagram showing an example of the main functions of a data processing device and a headset-type terminal according to the third embodiment. [Figure 7] This is a conceptual diagram showing an example of the configuration of a data processing system according to the fourth embodiment. [Figure 8] It is a conceptual diagram showing an example of the main functions of a data processing device and a robot according to the fourth embodiment. [Figure 9] It shows an emotion map to which a plurality of emotions are mapped. [Figure 10] It shows an emotion map to which a plurality of emotions are mapped. [Figure 11] It is a sequence diagram showing the processing flow of the data processing system in Example 1. [Figure 12] It is a sequence diagram showing the processing flow of the data processing system in Application Example 1. [Figure 13] It is a sequence diagram showing the processing flow of the data processing system in Example 2 when an emotion engine is combined. [Figure 14] It is a sequence diagram showing the processing flow of the data processing system in Application Example 2 when an emotion engine is combined.
Embodiments for Carrying Out the Invention
[0018] Hereinafter, an example of an embodiment of a system according to the technology of the present disclosure will be described with reference to the accompanying drawings.
[0019] First, the terms used in the following description will be explained.
[0020] In the following embodiments, a processor with a reference number (hereinafter simply referred to as "processor") may be a single arithmetic unit or a combination of a plurality of arithmetic units. Also, the processor may be a single type of arithmetic unit or a combination of a plurality of types of arithmetic units. Examples of arithmetic units include a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), a GPGPU (General-Purpose computing on Graphics Processing Units), an APU (Accelerated Processing Unit), and the like.
[0021] In the following embodiments, signed RAM (Random Access Memory) is a memory that temporarily stores information and is used as work memory by the processor.
[0022] In the following embodiments, the signed storage is one or more non-volatile storage devices that store various programs and various parameters. Examples of non-volatile storage devices include flash memory (SSD (Solid State Drive)), magnetic disks (e.g., hard disks), or magnetic tapes.
[0023] In the following embodiments, the signed communication interface (I / F) is an interface that includes a communication processor and an antenna, etc. The communication interface manages communication between multiple computers. Examples of communication standards applicable to the communication interface include wireless communication standards such as 5G (5th Generation Mobile Communication System), Wi-Fi (registered trademark), or Bluetooth (registered trademark).
[0024] In the following embodiments, "A and / or B" is synonymous with "at least one of A and B." That is, "A and / or B" means that it may be A alone, or B alone, or a combination of A and B. Furthermore, in this specification, the same concept as "A and / or B" applies when expressing three or more things linked by "and / or."
[0025] [First Embodiment]
[0026] Figure 1 shows an example of the configuration of the data processing system 10 according to the first embodiment.
[0027] As shown in Figure 1, the data processing system 10 includes a data processing device 12 and a smart device 14. An example of the data processing device 12 is a server.
[0028] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0029] The smart device 14 comprises a computer 36, a reception device 38, an output device 40, a camera 42, and a communication interface 44. The computer 36 comprises a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The reception device 38, output device 40, and camera 42 are also connected to the bus 52.
[0030] The reception device 38 is equipped with a touch panel 38A and a microphone 38B, etc., and receives user input. The touch panel 38A receives user input by detecting contact with an object (e.g., a pen or finger). The microphone 38B receives user input by detecting the user's voice. The control unit 46A transmits data indicating the user input received by the touch panel 38A and microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the data indicating the user input.
[0031] The output device 40 includes a display 40A and a speaker 40B, and presents data to the user 20 by outputting the data in a form perceptible to the user 20 (e.g., audio and / or text). The display 40A displays visible information such as text and images according to instructions from the processor 46. The speaker 40B outputs audio according to instructions from the processor 46. The camera 42 is a small digital camera equipped with an optical system such as a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor.
[0032] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various types of information between processor 46 and processor 28 via network 54.
[0033] Figure 2 shows an example of the main functions of the data processing device 12 and the smart device 14.
[0034] As shown in Figure 2, in the data processing device 12, a specific processing is performed by the processor 28. A specific processing program 56 is stored in the storage 32. The specific processing program 56 is an example of a "program" related to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 according to the specific processing program 56 executed on the RAM 30.
[0035] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[0036] In the smart device 14, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The reception output program 60 is used in conjunction with a specific processing program 56 by the data processing system 10. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.
[0037] Next, the specific processing performed by the specific processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the smart device 14 as the "terminal".
[0038] This invention is an advanced security system that can monitor network traffic data in real time and automatically detect anomalies and respond to incidents. The embodiments for carrying out this invention are shown below.
[0039] Data acquisition and preprocessing
[0040] The server monitors network traffic and collects packet-level data. This data includes information such as source and destination IP addresses, protocols, and port numbers. The collected data is normalized and converted into a format suitable for analysis by a preprocessing module.
[0041] Anomaly detection
[0042] The machine learning model deployed on the server receives pre-processed data as input and detects anomalies by comparing it to the learned results of normal traffic patterns. This model uses a pre-trained algorithm to identify activity that deviates from normal patterns.
[0043] Incident Response
[0044] When an anomaly is detected, the server automatically executes a response process. Measures such as blocking specific IP addresses, stopping suspicious communications, or isolating data are taken. This allows for rapid threat suppression.
[0045] Notifications and reports
[0046] Users receive real-time notifications about detected threats and the actions taken. These notifications include detailed incident information and recommended next steps, allowing administrators to quickly understand the situation and take further action.
[0047] Prediction and retraining
[0048] The server accurately analyzes data from past incidents to predict future threats. This predictive information is provided to administrators in report format, which can be used to develop long-term security strategies. Furthermore, the AI model itself is regularly retrained and constantly updated to address the latest threats.
[0049] System protection
[0050] Users (administrators) are responsible for regularly evaluating and improving the security of the system itself. They ensure the overall security of the system by checking for security vulnerabilities, applying patches as needed, and adjusting settings.
[0051] As a concrete example, one day the server detects a large volume of data transfer outside of normal business hours and identifies it as an anomaly. The initial response involves immediately stopping the communication and restricting access for the affected users. Furthermore, the notification received by the user includes details of the anomaly and recommended next steps, such as a password change. These features allow for effective countermeasures to be taken before a crisis escalates.
[0052] The following describes the processing flow.
[0053] Step 1:
[0054] The server captures network traffic data and records detailed information such as source and destination IP addresses, port numbers, and communication protocols. This creates a foundation for understanding the overall data flow.
[0055] Step 2:
[0056] The server preprocesses the collected traffic data by analyzing it, removing unnecessary information, and normalizing it. This process prepares the data so that it can be analyzed by machine learning models.
[0057] Step 3:
[0058] A machine learning model on the server takes pre-processed data as input and detects anomalies by comparing it with normal data patterns learned in the past. If data exhibits patterns different from normal or shows mutations, it is identified as an anomaly.
[0059] Step 4:
[0060] The server classifies the incident based on the detected anomaly and sets a priority according to the risk level. High-risk anomalies require a faster response, so the server determines the order of response.
[0061] Step 5:
[0062] The server automatically takes initial action against abnormal activity according to the configured policies. For example, it may immediately block suspicious communications or restrict access to specific devices.
[0063] Step 6:
[0064] Users receive real-time details about detected anomalies and the actions taken via notifications from the server. These notifications include an overview of the incident and recommended countermeasures.
[0065] Step 7:
[0066] The server analyzes past incident data and predicts potential future threats. This provides users with information to prepare in advance, contributing to long-term security improvements.
[0067] Step 8:
[0068] The server periodically retrains the AI model with new data, updating it to respond quickly to the latest threats. This retraining ensures the system is always in optimal condition.
[0069] Step 9:
[0070] Users (administrators) regularly evaluate the system's security and ensure the system's safety by applying patches and updating security settings as needed.
[0071] (Example 1)
[0072] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server," and the smart device 14 will be referred to as the "terminal."
[0073] With the increase in information and communication traffic, security threats in network environments are becoming more diverse. Therefore, it is necessary to monitor traffic data in real time, detect anomalies immediately, and take appropriate action. However, conventional systems suffer from a time lag between anomaly detection and response, making rapid response difficult. To solve this problem, more advanced anomaly detection capabilities and rapid incident response capabilities are required.
[0074] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.
[0075] In this invention, the server includes means for monitoring and collecting information transmission path data in real time, means for preprocessing the collected data and converting it into a format that can be analyzed by a computational model, and means for executing a computational model that detects abnormal information transmission patterns using the preprocessed data. This makes it possible to detect abnormal behavior on the network in real time and respond quickly on the spot.
[0076] "Information transmission path data" is a collection of digital information about communication activities within a network, including details such as source and destination addresses, protocols, communication volume, and timestamps.
[0077] A "computational model" is a mathematical computer program built for the purpose of data analysis and anomaly detection. It uses machine learning algorithms to process input data and identify specific patterns or anomalies.
[0078] "Means" refers to devices, methods, systems, or combinations thereof designed to achieve a specific function or purpose, and in this invention, these are used to realize anomaly detection and real-time response.
[0079] "Real-time monitoring" refers to a process that has the ability to observe and record information almost as soon as it occurs, and to take immediate action as needed.
[0080] An "abnormal information transmission pattern" refers to communication activity that exhibits behavior or characteristics that deviate from normal network communication, and can pose a security threat.
[0081] A "protection incident" refers to an event related to security threats in an information system, such as unauthorized access or data breaches, and involves a series of measures taken to address it.
[0082] This invention is implemented as part of an advanced security system aimed at protecting information systems. This system monitors information transmission path data on a network in real time, and detects and responds to anomalies immediately.
[0083] The server collects information transmission path data via a network interface using specialized software. Specific examples of such software include packet analysis tools and network monitoring applications. The collected data is stored in a database and organized and formatted by a data processing preprocessing module. Preprocessing includes data normalization and removal of outliers.
[0084] The server inputs this pre-processed data into a computational model. This model utilizes machine learning algorithms for anomaly detection and runs on platforms such as TENSORFLOW®. The model, trained on historical normal communication data, analyzes the data in real time and identifies abnormal information transmission patterns. When an anomaly is detected, measures such as immediately blocking specific IP addresses or stopping suspicious communications are automatically taken.
[0085] Users receive real-time notifications from the server via the management console. These notifications include detailed information about detected anomalies and recommended countermeasures. Administrators (users) can then quickly take action based on specific cases.
[0086] As an example, if a large amount of data is sent to a server during the night for purposes other than normal operations, the server will immediately detect the anomaly and block the communication. The following morning, when the user checks, they will be notified of the anomaly via email or SMS, which includes a detailed anomaly report from the server. This email will also include instructions on how to investigate the suspected unauthorized access and determine the next course of action.
[0087] An example of a prompt for a generative AI model is, "Please provide an example of an effective machine learning model for identifying anomalous patterns in network traffic." This prompt facilitates the development and application of new anomaly detection algorithms.
[0088] The flow of the specific processing in Example 1 will be explained using Figure 11.
[0089] Step 1:
[0090] The server collects information transmission path data in real time via the network interface. Specifically, it uses a packet analysis tool to obtain header information and payload data for each packet. The input is raw data flowing from the network, and the output is structured data such as source and destination addresses, protocol, and timestamp.
[0091] Step 2:
[0092] The server sends the collected data to a preprocessing module for data normalization and removal of outliers. Specifically, it uses the Pandas library to create a dataframe, and performs missing value imputation and data type conversion. The input is the collected data, and the output is clean data suitable for analysis.
[0093] Step 3:
[0094] The server inputs preprocessed data into a computational model and performs analysis to detect abnormal information transmission patterns. Specifically, it uses TensorFlow to run a machine learning model and evaluate the data in real time. The input is preprocessed data, and the output is the result of anomaly detection that deviates from normal patterns.
[0095] Step 4:
[0096] The server immediately takes action in response to any detected anomalies. Specifically, it runs a script that uses iptables to block specific IP addresses. It also stops suspicious communications and saves related logs to an isolation folder. The input is the anomaly detection result, and the output is that network security is temporarily ensured.
[0097] Step 5:
[0098] Users receive real-time notifications from the server and learn detailed information about anomalies. Specifically, the system displays incident details and recommended actions via email and a management console. The input is the result of the response process, and the output provides users with information to consider immediate countermeasures.
[0099] Step 6:
[0100] The server predicts future threats using historical incident data. Specifically, it utilizes data analysis tools to analyze trends and generate predictive models. The input is historical incident data, and the output is predictive information provided to administrators to help them with future countermeasures.
[0101] (Application Example 1)
[0102] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server," and the smart device 14 will be referred to as the "terminal."
[0103] With the recent advancements in information and communication technology, network security risks have increased. In particular, there is a growing need to detect anomalies in real time and respond quickly and appropriately. However, current systems struggle to effectively manage a large number of incidents. Furthermore, administrators often cannot grasp the situation in real time and take appropriate countermeasures. It is necessary to address these challenges and improve network security.
[0104] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.
[0105] In this invention, the server includes a device means for monitoring and collecting network traffic data in real time, a device means for preprocessing the collected information and converting it into an analyzable format, and a device means for detecting abnormal communication patterns using the preprocessed information. This makes it possible to immediately detect anomalies on the network and provide administrators with detailed information and safety recommendations in real time.
[0106] "Network traffic data" refers to all data transmitted and received over a network, including source and destination address information, the protocol used, port number, and other relevant information.
[0107] "Preprocessing" refers to the process of converting network traffic data into an analyzable format, including data normalization and transformation to facilitate analysis by machine learning models.
[0108] A "machine learning model" is a computational model that uses large amounts of data to learn normal and abnormal patterns and includes algorithms for detecting anomalies in real time.
[0109] A "security incident" is a security problem or failure caused by unauthorized access or attacks on a network.
[0110] "Setting priorities" refers to the act of identifying the importance and urgency of detected security incidents in order to determine the allocation of resources and the order of responses.
[0111] "Real-time notification" refers to the act of providing information to administrators immediately when a security incident occurs, and is a means of enabling rapid decision-making.
[0112] "Retraining an artificial intelligence model" refers to the process of continuously updating algorithms to improve the model's performance in order to respond to newly emerging threats and attack methods.
[0113] "Evaluating defenses" is the process of identifying system vulnerabilities and improving or adjusting defense strategies as needed, all aimed at ensuring the overall security of the system.
[0114] "Safety recommendations" are advice and guidelines that instruct users on what measures should be taken in response to detected anomalies, and are information intended to guide user behavior.
[0115] The security system implementing the present invention consists of a server, a network monitoring device, a terminal, and a user. The server uses a device that monitors network traffic data in real time and collects packet-level data. This data includes source and destination address information, the protocol used, port number, etc. The collected data is converted into an analyzable format by a preprocessor.
[0116] The server inputs the processed data into a machine learning model to detect abnormal communication patterns. This model learns from a large amount of normal traffic data and has the ability to recognize anomalies in real time. Based on the detected data, security incidents are automatically classified and prioritized.
[0117] The terminal notifies the user in real time of incident information received from the server. The notification includes a description of the anomaly along with security recommendations, enabling the user to take prompt and appropriate action. The user is required to review the system's defense strategy and take countermeasures based on the information provided.
[0118] This system supports continuous improvement by regularly retraining its artificial intelligence model to maintain its ability to respond to the latest threats. Furthermore, by analyzing past incident data and predicting future threats, it can enhance long-term security.
[0119] For example, if a large amount of data transfer is detected outside of normal hours on a given day, the server will automatically notify the server of the anomaly, restrict communication on the terminal, and immediately communicate details and recommended countermeasures to the user.
[0120] An example of a prompt for a generative AI model is, "Design a smartphone app that notifies users of the latest security alerts in real time."
[0121] The flow of a specific process in Application Example 1 will be explained using Figure 12.
[0122] Step 1:
[0123] The server monitors network traffic data in real time and collects packet-level data, including source and destination address information, the protocol used, and port numbers. This data is then normalized and converted into a parseable format. The collected data is the input, and the normalized data is the output.
[0124] Step 2:
[0125] The server inputs pre-processed data into a machine learning model. This model analyzes the data to detect abnormal communication patterns by comparing them to normal traffic patterns. The input to this process is pre-processed data, and the output is a determination of whether the data is normal or abnormal.
[0126] Step 3:
[0127] The server automatically classifies security incidents based on detected anomalies and sets priorities according to their severity. The classified incident information is the input, and the output is a list of incidents with assigned priorities.
[0128] Step 4:
[0129] The server automatically performs initial responses to incidents according to priority. This includes restricting or blocking specific communications. The input for this step is the incident list, and the output is the updated network control status.
[0130] Step 5:
[0131] The terminal receives incident information sent from the server and notifies the user in real time. The notification includes the details of the anomaly and safety recommendations. The input to this process is the notification information from the server, and the output is the notification displayed to the user.
[0132] Step 6:
[0133] The user evaluates network security based on notifications from their device and reviews their defense strategy. Based on the security recommendations received, the user decides whether to change settings or take additional measures. The input for this step is notification information, and the output is the improved network settings.
[0134] Step 7:
[0135] The server periodically retrains its artificial intelligence model to ensure continuous improvement. This step uses historical incident data as training data to update the model and enable it to respond to new threats. The retraining data is the input, and the updated model is the output.
[0136] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.
[0137] This invention combines a network security system with an emotion engine that recognizes user emotions, aiming not only to ensure network security but also to improve the user experience. The embodiments for carrying out this invention are as follows:
[0138] Data acquisition and preprocessing
[0139] The server monitors network traffic data in real time and captures packet data. This data is preprocessed and converted into a format that can be analyzed by machine learning models, forming the basis for anomaly detection.
[0140] Anomaly detection
[0141] The server uses a machine learning model to detect anomalous traffic patterns from pre-processed data. This model learns from past normal data patterns and reliably identifies deviant patterns.
[0142] Recognition of user emotions by an emotion engine
[0143] The device analyzes user input, voice and video data, etc., using an emotion engine to infer the user's emotional state at that time. This engine utilizes natural language processing and facial recognition technology.
[0144] Incident Response
[0145] Based on detected anomalies, the server automatically classifies security incidents and prioritizes them, taking into account user sentiment. For example, if a user is experiencing stress, prompt and appropriate action is required.
[0146] Notifications and user suggestions
[0147] Users receive real-time feedback from the server regarding incidents and responses, along with emotion-based advice. The notifications include follow-up suggestions tailored to the user's current emotional state.
[0148] Prediction and retraining
[0149] The server analyzes historical data to predict future threats. Based on these results, the system retrains its AI model to ensure it is always prepared to address the latest threats.
[0150] System protection
[0151] The user (administrator) will conduct a security assessment of the system and take measures to protect the entire system, including the emotion engine. This will minimize security vulnerabilities in the engine itself.
[0152] For example, if a user attempts to access an important dataset outside of normal business hours, the server will detect this as an anomaly. At that time, the terminal will analyze the user's emotions and detect unusual emotions, such as frustration. Taking this information into consideration, the server will decide to take particularly swift action and send a notification advising the user to remain calm. Such intelligent security responses allow users to recognize the potential risks of their actions and encourage appropriate behavior.
[0153] The following describes the processing flow.
[0154] Step 1:
[0155] The server captures network traffic data in real time and collects information about each packet. This information includes the source and destination IP addresses, port number, and communication protocol.
[0156] Step 2:
[0157] The server preprocesses the collected traffic data and converts it into a format usable by machine learning models. Data normalization and outlier correction are also performed at this stage.
[0158] Step 3:
[0159] The server inputs pre-processed data into a machine learning model to analyze traffic patterns. This model is trained to detect anomalies by comparing them to normal communication patterns.
[0160] Step 4:
[0161] The device transmits user input data and audio / video data to the emotion engine. This data is used to analyze the user's current emotional state.
[0162] Step 5:
[0163] The device's emotion engine uses natural language processing and facial recognition technology to generate results that estimate the user's emotional state. The resulting emotional state is output as, for example, "calm" or "stressed."
[0164] Step 6:
[0165] Based on the results of the emotion engine, the server classifies and prioritizes security incidents related to detected abnormal traffic patterns. If the emotion state is "stressed," it is treated as an unauthorized access attempt requiring immediate attention.
[0166] Step 7:
[0167] The server automatically implements countermeasures based on anomaly detection. These measures include blocking specific communications and temporarily restricting access. It also notifies users in real time of incident details and recommended actions.
[0168] Step 8:
[0169] Users can receive notifications, check the situation, and take additional manual action. Notifications include emotionally-based calming suggestions and specific steps to take.
[0170] Step 9:
[0171] The server analyzes past incident data and current trends to predict future threats. The AI model is regularly retrained to adapt to new threats, ensuring that the system always maintains up-to-date countermeasures.
[0172] Step 10:
[0173] Users (administrators) regularly evaluate the emotion engine and other system components and take measures to improve the overall system security. This increases the system's resilience to external attacks and internal vulnerabilities.
[0174] (Example 2)
[0175] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server" and the smart device 14 as the "terminal".
[0176] In recent years, cyberattacks have increased along with the sophistication of network communications. To address this, advanced anomaly detection in real time and appropriate responses that take into account the emotional state of users are required. However, current network security systems have the challenge of being unable to respond in a way that takes into account the emotional state of users, and their responses after anomaly detection are uniform.
[0177] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.
[0178] In this invention, the server includes a device means for monitoring and collecting network communication data in real time, a device means for analyzing input data and inferring emotions in order to recognize the user's emotional state, and a device means for classifying security events and adjusting priorities based on the detected anomaly and the recognized emotional state of the user. This enables anomaly detection and individualized responses that take into account user emotions.
[0179] "Network communication data" refers to information that travels within a network, and is composed of data units called packets.
[0180] A "device" is a set of hardware or software components designed to perform a specific function.
[0181] "Preprocessing" refers to data cleaning, standardization, and transformation processes performed to convert raw data into an analyzable format.
[0182] A "machine learning algorithm" is a computational method that learns patterns and rules from large amounts of data and uses that knowledge to make predictions and classifications on new data.
[0183] An "artificial intelligence model" is a computational model trained using machine learning, a program that has the ability to automatically make decisions based on given data.
[0184] "Emotional state" refers to a person's emotional or moody state, and is usually inferred using emotion analysis techniques.
[0185] A "security incident" refers to an event that indicates unauthorized access to an information system, abnormal behavior, or a violation of security policies.
[0186] "Priority" is an indicator used to determine the order in which to address multiple events or tasks.
[0187] This invention is a system that integrates network security and user emotional management. Through anomaly detection and recognition of user emotions, this system enables more appropriate security responses.
[0188] The server first continuously monitors network communication data in real time. It captures this data, formats it as needed, and transforms it into a format suitable for analysis. This process includes normalizing the data and imputing missing values. The server leverages libraries in Python and other programming languages, for example, using Scikit-learn to execute machine learning algorithms. This allows for the rapid detection of abnormal communication patterns.
[0189] The device collects and analyzes user voice, text, facial expressions, and other data. It uses an emotion engine to evaluate the user's emotional state. By utilizing libraries such as TensorFlow and PyTorch, it enables more accurate emotion prediction.
[0190] Based on the information obtained through these processes, users are notified in real time of abnormal events and how to respond to them. The notifications are provided in a format and content appropriate to the user's current emotional state, and may include suggestions to help reduce stress.
[0191] As a concrete example, consider a case where a user accesses an important file outside of normal business hours. The server detects this as an anomaly, and if the terminal analyzes the user's emotions and detects stress, the server takes particularly swift and flexible measures and sends a notification to the user urging them to remain calm. In this way, considering both the detected anomaly and the user's emotions enables a more flexible and effective response.
[0192] An example of a prompt for a generative AI model might be, "Explain how to dynamically adjust the priority of network security responses based on the emotional state of a specific user."
[0193] The flow of the specific processing in Example 2 will be explained using Figure 13.
[0194] Step 1:
[0195] The server monitors network communication data in real time and captures data packet by packet. The input is raw data flowing through the network, and the output is structured packet information. This standardizes the data format and converts it into a format suitable for analysis.
[0196] Step 2:
[0197] The server preprocesses the captured data, performing actions such as imputing missing values and removing unnecessary data. The input is the packet information obtained in step 1, and the output is data formatted in a way that can be analyzed by the machine learning model. This preprocessing improves the quality of the data.
[0198] Step 3:
[0199] The server runs a machine learning model on pre-processed data to detect abnormal communication patterns. The input is formatted data, and the output is indicators and alert information showing anomalies. Here, libraries such as Scikit-learn are used to run the model.
[0200] Step 4:
[0201] The device collects text, audio, and image data to determine the user's emotions. Inputs include user communication content and video / audio data from the device, while output is a numerical representation of the user's emotional state. An emotion inference model is run using TensorFlow or similar tools.
[0202] Step 5:
[0203] The server combines anomaly detection information with the user's emotional state to classify security events and determine response priorities. Inputs are anomaly indicators and the results of emotional analysis, while output are prioritized response measures. This combination enables flexible security responses.
[0204] Step 6:
[0205] The user receives real-time notifications from their device based on the generated countermeasures. The input is the suggested countermeasures from the server, and the output is information about risk management that the user receives. The user is expected to respond calmly based on the information presented.
[0206] Step 7:
[0207] The server analyzes historical data and current trends to predict future network risks. The input is historical incident data, and the output is predictive information indicating future risks. The AI model is retrained based on the analysis results.
[0208] Step 8:
[0209] The user (administrator) performs a system-wide security assessment and sets up necessary protective measures. Inputs include system operational status and security logs, while output is an enhanced security plan. This improves system security.
[0210] (Application Example 2)
[0211] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as a "server" and the smart device 14 as a "terminal".
[0212] In network security, there is a growing need not only to detect abnormal traffic but also to provide more appropriate countermeasures that take into account the emotional state of users. Traditional systems primarily deal with technical anomalies, neglecting the emotional state of users and thus failing to provide a proper user experience. Therefore, the challenge is to provide a system that can implement countermeasures that address user emotions while maintaining network security.
[0213] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means.
[0214] In this invention, the server includes means for monitoring and collecting network communication data in real time; means for preprocessing the collected data and converting it into a format that can be analyzed by a machine learning algorithm; means for executing a machine learning algorithm that detects abnormal communication patterns using the preprocessed data; means for executing an emotion recognition engine that analyzes user input and voice / video information and infers the user's emotional state; means for automatically classifying security incidents based on detected anomalies and setting priorities considering the user's emotional information; means for automatically performing initial responses to incidents and sending emotion-based notifications to the user in real time; means for predicting future threats by analyzing past data and current trends; means for periodically retraining the artificial intelligence model to enable it to respond to the latest threats; and means for evaluating and protecting the security of the system. This makes it possible to respond according to the user's emotional state while enhancing network security.
[0215] "Network communication data" refers to data generated in the field of information technology when digital information is exchanged between devices.
[0216] "Real-time monitoring" is the process of observing and recording events that are currently in progress.
[0217] "Preprocessing" refers to the process of data cleansing and filtering to convert raw data into an analyzable format.
[0218] A "machine learning algorithm" is a numerical and logical method that uses computing resources to learn patterns from data and applies them to prediction and anomaly detection.
[0219] An "abnormal communication pattern" refers to a data flow or communication pattern that differs significantly from normal network traffic.
[0220] An "emotion recognition engine" is a software or hardware system that analyzes audio, video, and text data to estimate a person's emotional state.
[0221] A "security incident" is an event that can pose a security risk or threat to an information system, such as unauthorized access or data breaches.
[0222] "Prioritizing" is the process of evaluating the importance of multiple tasks or events and deciding the order in which to address them.
[0223] "Initial response" refers to the first actions and procedures taken when a problem occurs, with the aim of ensuring the smooth implementation of subsequent responses.
[0224] "Real-time transmission" is the process of sending data and information instantly so that recipients can receive it immediately.
[0225] "Past data" refers to archives and histories of digital information that were previously collected and recorded.
[0226] "Current trends" refer to events that are happening now, particularly general movements and directions that can be observed over time.
[0227] An "artificial intelligence model" is a trained algorithm built on machine learning techniques to perform a specific task.
[0228] "Retraining" is the process of updating an existing machine learning model by training it again using new data.
[0229] "System security" refers to a state in which an information system is protected from external threats and internal errors.
[0230] "Protection" means taking the necessary actions or measures to protect an object from danger or threat.
[0231] To implement this invention, a system is required that closely coordinates between the server, terminal, and user. The server acquires network communication data in real time and utilizes machine learning algorithms to detect abnormal patterns. This involves using commonly used data collection software and machine learning platforms. In particular, machine learning libraries such as TensorFlow are suitable for anomaly detection.
[0232] The terminal acquires data, audio, and video information input by the user and processes it using an emotion recognition engine. This engine utilizes natural language processing libraries and facial recognition technology to infer the user's emotions. The data collected by the terminal is shared with the server and used to determine the priority of anomalies and the actions to be taken.
[0233] Users receive notifications from the server and are offered solutions based on their own emotions. These suggestions enable users to make better decisions and contribute to improved network security. For example, if suspicious activity is detected outside of normal business hours and the user feels anxious, the device will send a reassuring message. In this way, flexible responses tailored to individual circumstances are provided without direct user interaction.
[0234] An example of a prompt for a generating AI model is: "If the user's emotional state is anxious, what should be included in the security advice?" This prompt allows the AI to generate appropriate suggestions and provide feedback to the system.
[0235] The flow of a specific process in Application Example 2 will be explained using Figure 14.
[0236] Step 1:
[0237] The server collects network communication data in real time. This process captures data packets and rapidly forwards them. Network traffic is used as input, and raw data packets are obtained as output. This raw data serves as fundamental information for anomaly detection.
[0238] Step 2:
[0239] The server preprocesses the collected raw data. This step involves data shaping and cleaning, converting the data into a format that can be analyzed by machine learning algorithms. The input is raw data packets, and the output is preprocessed and formatted data. Python and R data processing libraries are used for this processing.
[0240] Step 3:
[0241] The server applies machine learning algorithms to pre-processed data to detect abnormal communication patterns. The input is pre-processed data, and the output is the result of the anomaly detection. Abnormal patterns are determined to be deviations from normal communication information.
[0242] Step 4:
[0243] The device processes the user's voice and video information using an emotion recognition engine. The input here is voice and video data acquired from the user, and the output is the result of emotion inference. This step involves emotion classification using natural language processing and image processing libraries.
[0244] Step 5:
[0245] The server automatically classifies security incidents and sets priorities by combining anomaly detection results with the user's emotional state. The inputs for this step are anomaly patterns and emotional states, and the output is a list of classified incidents and their priorities. If the emotional state exceeds a certain threshold, the priority is set higher.
[0246] Step 6:
[0247] The user receives real-time notifications from the server. The input here is a categorized incident and a response based on emotion; the output is a notification message to the user. This includes suggestions tailored to the user's emotional state.
[0248] Step 7:
[0249] The server analyzes historical data to predict future threats. The input for this step is collected and analyzed historical data, and the output is a threat prediction. Time series analysis and predictive modeling techniques are utilized for the prediction.
[0250] Step 8:
[0251] The server periodically retrains the generated AI model to ensure it can respond to the latest threats. In this step, the input is a new dataset, and the output is the updated AI model. Retraining is performed to improve the model's accuracy and to better respond to new threat patterns.
[0252] The specific processing unit 290 transmits the result of the specific processing to the smart device 14. In the smart device 14, the control unit 46A causes the output device 40 to output the result of the specific processing. The microphone 38B acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.
[0253] Data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of data generation model 58 is ChatGPT (registered trademark) (Internet search).<URL: https: / / openai.com / blog / chatgpt> ), Gemini (registered trademark) (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[0254] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and the specific processing may also be performed by the smart device 14.
[0255] [Second Embodiment]
[0256] Figure 3 shows an example of the configuration of the data processing system 210 according to the second embodiment.
[0257] As shown in Figure 3, the data processing system 210 includes a data processing device 12 and smart glasses 214. An example of the data processing device 12 is a server.
[0258] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0259] The smart glasses 214 include a computer 36, a microphone 238, a speaker 240, a camera 42, and a communication interface 44. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, and camera 42 are also connected to the bus 52.
[0260] The microphone 238 receives voice signals from the user 20 and receives instructions from the user 20. The microphone 238 captures the voice signals from the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.
[0261] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the area around the user 20 (for example, an imaging range defined by a field of view equivalent to the width of a typical healthy person's field of vision).
[0262] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.
[0263] Figure 4 shows an example of the main functions of the data processing device 12 and the smart glasses 214. As shown in Figure 4, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.
[0264] The specific processing program 56 is an example of a "program" relating to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[0265] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[0266] In the smart glasses 214, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.
[0267] Next, the identification processing performed by the identification processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the smart glasses 214 will be referred to as the "terminal".
[0268] This invention is an advanced security system that can monitor network traffic data in real time and automatically detect anomalies and respond to incidents. The embodiments for carrying out this invention are shown below.
[0269] Data Acquisition and Preprocessing
[0270] The server monitors network traffic and collects packet-level data. This data includes information such as source and destination IP addresses, protocols, and port numbers. The collected data is normalized and converted into a format suitable for analysis by a preprocessing module.
[0271] Anomaly detection
[0272] The machine learning model deployed on the server receives pre-processed data as input and detects anomalies by comparing it to the learned results of normal traffic patterns. This model uses a pre-trained algorithm to identify activity that deviates from normal patterns.
[0273] Incident Response
[0274] When an anomaly is detected, the server automatically executes response processes. These include blocking specific IP addresses, stopping suspicious communications, or isolating data. This allows for rapid threat suppression.
[0275] Notifications and reports
[0276] Users receive real-time notifications about detected threats and the actions taken. These notifications include detailed incident information and recommended next steps, allowing administrators to quickly understand the situation and take further action.
[0277] Prediction and retraining
[0278] The server accurately analyzes data from past incidents to predict future threats. This predictive information is provided to administrators in report format, which can be used to develop long-term security strategies. Furthermore, the AI model itself is regularly retrained and constantly updated to address the latest threats.
[0279] System protection
[0280] Users (administrators) are responsible for regularly evaluating and improving the security of the system itself. They ensure the overall security of the system by checking for security vulnerabilities, applying patches as needed, and adjusting settings.
[0281] As a specific example, one day, the server detects a large amount of data transfer outside normal business hours and determines this as an anomaly. As an initial response, it immediately stops the communication and restricts access to related users. Also, the notifications received by the users include details of the anomaly and recommended next steps, such as guidance on password changes. With these functions, effective countermeasures can be implemented before the crisis spreads.
[0282] The following describes the process flow.
[0283] Step 1:
[0284] The server captures traffic data on the network and records detailed information such as the source and destination IP addresses, port numbers, and communication protocols. This creates a basis for understanding the overall data flow.
[0285] Step 2:
[0286] The server analyzes the collected traffic data to preprocess it, removing unnecessary information and normalizing it. This process prepares the data in a state where it can be analyzed by a machine learning model.
[0287] Step 3:
[0288] The machine learning model on the server takes the preprocessed data as input, compares it with the normal data patterns learned in the past, and detects anomalies. At this time, if there is data showing patterns different from normal or mutations, it is identified as an anomaly.
[0289] Step 4:
[0290] The server classifies the incident based on the detected abnormal event and sets a priority according to the risk level. Since a more rapid response is required for high-risk anomalies, the order of response is determined.
[0291] Step 5:
[0292] The server automatically takes initial action against abnormal activity according to the configured policies. For example, it may immediately block suspicious communications or restrict access to specific devices.
[0293] Step 6:
[0294] Users receive real-time details about detected anomalies and the actions taken via notifications from the server. These notifications include an overview of the incident and recommended countermeasures.
[0295] Step 7:
[0296] The server analyzes past incident data and predicts potential future threats. This provides users with information to prepare in advance, contributing to long-term security improvements.
[0297] Step 8:
[0298] The server periodically retrains the AI model with new data, updating it to respond quickly to the latest threats. This retraining ensures the system is always in optimal condition.
[0299] Step 9:
[0300] Users (administrators) regularly evaluate the system's security and ensure the system's safety by applying patches and updating security settings as needed.
[0301] (Example 1)
[0302] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server," and the smart glasses 214 will be referred to as the "terminal."
[0303] With the increase in information communication, security threats in the network environment are diversifying. Therefore, it is required to monitor traffic data in real time, immediately detect abnormalities, and take appropriate measures. However, in conventional systems, there is a time lag in anomaly detection and response, making it difficult to respond quickly. To solve this problem, a more advanced anomaly detection function and a rapid incident response function are required.
[0304] The specific processing by the specific processing unit 290 of the data processing apparatus 12 in the first embodiment is realized by the following means.
[0305] In this invention, the server includes means for monitoring and collecting information transmission path data in real time, means for preprocessing the collected data and converting it into a form that can be analyzed by a calculation model, and means for executing a calculation model for detecting an abnormal information transmission pattern using the preprocessed data. As a result, abnormal behavior on the network can be detected in real time and responded to promptly on the spot.
[0306] "Information transmission path data" is a collection of digital information related to communication activities within a network, including details such as the addresses of the source and destination, protocols, traffic volume, and timestamps.
[0307] A "calculation model" is a mathematical computer program constructed for the purpose of data analysis and anomaly detection, which uses a machine learning algorithm to process input data and distinguish specific patterns or anomalies.
[0308] "Means" refers to a device, method, system, or combination thereof designed to achieve a specific function or purpose, and in this invention, it is used to realize anomaly detection and real-time response.
[0309] "Monitoring in real time" refers to a process that has the ability to observe, record, and immediately take action as needed almost simultaneously when information occurs.
[0310] An "abnormal information transmission pattern" refers to communication activity that exhibits behavior or characteristics that deviate from normal network communication, and can pose a security threat.
[0311] A "protection incident" refers to an event related to security threats in an information system, such as unauthorized access or data breaches, and involves a series of measures taken to address it.
[0312] This invention is implemented as part of an advanced security system aimed at protecting information systems. This system monitors information transmission path data on a network in real time, and detects and responds to anomalies immediately.
[0313] The server collects information transmission path data via a network interface using specialized software. Specific examples of such software include packet analysis tools and network monitoring applications. The collected data is stored in a database and organized and formatted by a data processing preprocessing module. Preprocessing includes data normalization and removal of outliers.
[0314] The server inputs this pre-processed data into a computational model. This model utilizes machine learning algorithms for anomaly detection and runs on a platform such as TensorFlow. The model, trained on historical normal communication data, analyzes the data in real time and identifies abnormal information transmission patterns. When an anomaly is detected, measures such as immediately blocking specific IP addresses or stopping suspicious communications are automatically taken.
[0315] Users receive real-time notifications from the server via the management console. These notifications include detailed information about detected anomalies and recommended countermeasures. Administrators (users) can then quickly take action based on specific cases.
[0316] As an example, if a large amount of data is sent to a server during the night for purposes other than normal operations, the server will immediately detect the anomaly and block the communication. The following morning, when the user checks, they will be notified of the anomaly via email or SMS, which includes a detailed anomaly report from the server. This email will also include instructions on how to investigate the suspected unauthorized access and determine the next course of action.
[0317] An example of a prompt for a generative AI model is, "Please provide an example of an effective machine learning model for identifying anomalous patterns in network traffic." This prompt facilitates the development and application of new anomaly detection algorithms.
[0318] The flow of the specific processing in Example 1 will be explained using Figure 11.
[0319] Step 1:
[0320] The server collects information transmission path data in real time via the network interface. Specifically, it uses a packet analysis tool to obtain header information and payload data for each packet. The input is raw data flowing from the network, and the output is structured data such as source and destination addresses, protocol, and timestamp.
[0321] Step 2:
[0322] The server sends the collected data to a preprocessing module for data normalization and removal of outliers. Specifically, it uses the Pandas library to create a dataframe, and performs missing value imputation and data type conversion. The input is the collected data, and the output is clean data suitable for analysis.
[0323] Step 3:
[0324] The server inputs preprocessed data into a computational model and performs analysis to detect abnormal information transmission patterns. Specifically, it uses TensorFlow to run a machine learning model and evaluate the data in real time. The input is preprocessed data, and the output is the result of anomaly detection that deviates from normal patterns.
[0325] Step 4:
[0326] The server immediately takes action in response to any detected anomalies. Specifically, it runs a script that uses iptables to block specific IP addresses. It also stops suspicious communications and saves related logs to an isolation folder. The input is the anomaly detection result, and the output is that network security is temporarily ensured.
[0327] Step 5:
[0328] Users receive real-time notifications from the server and learn detailed information about anomalies. Specifically, the system displays incident details and recommended actions via email and a management console. The input is the result of the response process, and the output provides users with information to consider immediate countermeasures.
[0329] Step 6:
[0330] The server predicts future threats using historical incident data. Specifically, it utilizes data analysis tools to analyze trends and generate predictive models. The input is historical incident data, and the output is predictive information provided to administrators to help them with future countermeasures.
[0331] (Application Example 1)
[0332] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server," and the smart glasses 214 will be referred to as the "terminal."
[0333] With the recent advancements in information and communication technology, network security risks have increased. In particular, there is a growing need to detect anomalies in real time and respond quickly and appropriately. However, current systems struggle to effectively manage a large number of incidents. Furthermore, administrators often cannot grasp the situation in real time and take appropriate countermeasures. It is necessary to address these challenges and improve network security.
[0334] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.
[0335] In this invention, the server includes a device means for monitoring and collecting network traffic data in real time, a device means for preprocessing the collected information and converting it into an analyzable format, and a device means for detecting abnormal communication patterns using the preprocessed information. This makes it possible to immediately detect anomalies on the network and provide administrators with detailed information and safety recommendations in real time.
[0336] "Network traffic data" refers to all data transmitted and received over a network, including source and destination address information, the protocol used, port number, and other relevant information.
[0337] "Preprocessing" refers to the process of converting network traffic data into an analyzable format, including data normalization and transformation to facilitate analysis by machine learning models.
[0338] A "machine learning model" is a computational model that uses large amounts of data to learn normal and abnormal patterns and includes algorithms for detecting anomalies in real time.
[0339] A "security incident" is a security problem or failure caused by unauthorized access or attacks on a network.
[0340] "Setting priorities" refers to the act of identifying the importance and urgency of detected security incidents in order to determine the allocation of resources and the order of responses.
[0341] "Real-time notification" refers to the act of providing information to administrators immediately when a security incident occurs, and is a means of enabling rapid decision-making.
[0342] "Retraining an artificial intelligence model" refers to the process of continuously updating algorithms to improve the model's performance in order to respond to newly emerging threats and attack methods.
[0343] "Evaluating defenses" is the process of identifying system vulnerabilities and improving or adjusting defense strategies as needed, all aimed at ensuring the overall security of the system.
[0344] "Safety recommendations" are advice and guidelines that instruct users on what measures should be taken in response to detected anomalies, and are information intended to guide user behavior.
[0345] The security system implementing the present invention consists of a server, a network monitoring device, a terminal, and a user. The server uses a device that monitors network traffic data in real time and collects packet-level data. This data includes source and destination address information, the protocol used, port number, etc. The collected data is converted into an analyzable format by a preprocessor.
[0346] The server inputs the processed data into a machine learning model to detect abnormal communication patterns. This model learns from a large amount of normal traffic data and has the ability to recognize anomalies in real time. Based on the detected data, security incidents are automatically classified and prioritized.
[0347] The terminal notifies the user in real time of incident information received from the server. The notification includes a description of the anomaly along with security recommendations, enabling the user to take prompt and appropriate action. The user is required to review the system's defense strategy and take countermeasures based on the information provided.
[0348] This system supports continuous improvement by regularly retraining its artificial intelligence model to maintain its ability to respond to the latest threats. Furthermore, by analyzing past incident data and predicting future threats, it can enhance long-term security.
[0349] For example, if a large amount of data transfer is detected outside of normal hours on a given day, the server will automatically notify the server of the anomaly, restrict communication on the terminal, and immediately communicate details and recommended countermeasures to the user.
[0350] An example of a prompt for a generative AI model is, "Design a smartphone app that notifies users of the latest security alerts in real time."
[0351] The flow of a specific process in Application Example 1 will be explained using Figure 12.
[0352] Step 1:
[0353] The server monitors network traffic data in real time and collects packet-level data, including source and destination address information, the protocol used, and port numbers. This data is then normalized and converted into a parseable format. The collected data is the input, and the normalized data is the output.
[0354] Step 2:
[0355] The server inputs pre-processed data into a machine learning model. This model analyzes the data to detect abnormal communication patterns by comparing them to normal traffic patterns. The input to this process is pre-processed data, and the output is a determination of whether the data is normal or abnormal.
[0356] Step 3:
[0357] The server automatically classifies security incidents based on detected anomalies and sets priorities according to their severity. The classified incident information is the input, and the output is a list of incidents with assigned priorities.
[0358] Step 4:
[0359] The server automatically performs initial responses to incidents according to priority. This includes restricting or blocking specific communications. The input for this step is the incident list, and the output is the updated network control status.
[0360] Step 5:
[0361] The terminal receives incident information sent from the server and notifies the user in real time. The notification includes the details of the anomaly and safety recommendations. The input to this process is the notification information from the server, and the output is the notification displayed to the user.
[0362] Step 6:
[0363] The user evaluates network security based on notifications from their device and reviews their defense strategy. Based on the security recommendations received, the user decides whether to change settings or take additional measures. The input for this step is notification information, and the output is the improved network settings.
[0364] Step 7:
[0365] The server periodically retrains its artificial intelligence model to ensure continuous improvement. This step uses historical incident data as training data to update the model and enable it to respond to new threats. The retraining data is the input, and the updated model is the output.
[0366] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.
[0367] This invention combines a network security system with an emotion engine that recognizes user emotions, aiming not only to ensure network security but also to improve the user experience. The embodiments for carrying out this invention are as follows:
[0368] Data acquisition and preprocessing
[0369] The server monitors network traffic data in real time and captures packet data. This data is preprocessed and converted into a format that can be analyzed by machine learning models, forming the basis for anomaly detection.
[0370] Anomaly detection
[0371] The server uses a machine learning model to detect anomalous traffic patterns from pre-processed data. This model learns from past normal data patterns and reliably identifies deviant patterns.
[0372] Recognition of user emotions by an emotion engine
[0373] The device analyzes user input, voice and video data, etc., using an emotion engine to infer the user's emotional state at that time. This engine utilizes natural language processing and facial recognition technology.
[0374] Incident Response
[0375] Based on detected anomalies, the server automatically classifies security incidents and prioritizes them, taking into account user sentiment. For example, if a user is experiencing stress, prompt and appropriate action is required.
[0376] Notifications and user suggestions
[0377] Users receive real-time feedback from the server regarding incidents and responses, along with emotion-based advice. The notifications include follow-up suggestions tailored to the user's current emotional state.
[0378] Prediction and retraining
[0379] The server analyzes historical data to predict future threats. Based on these results, the system retrains its AI model to ensure it is always prepared to address the latest threats.
[0380] System protection
[0381] The user (administrator) will conduct a security assessment of the system and take measures to protect the entire system, including the emotion engine. This will minimize security vulnerabilities in the engine itself.
[0382] For example, if a user attempts to access an important dataset outside of normal business hours, the server will detect this as an anomaly. At that time, the terminal will analyze the user's emotions and detect unusual emotions, such as frustration. Taking this information into consideration, the server will decide to take particularly swift action and send a notification advising the user to remain calm. Such intelligent security responses allow users to recognize the potential risks of their actions and encourage appropriate behavior.
[0383] The following describes the processing flow.
[0384] Step 1:
[0385] The server captures network traffic data in real time and collects information about each packet. This information includes the source and destination IP addresses, port number, and communication protocol.
[0386] Step 2:
[0387] The server preprocesses the collected traffic data and converts it into a format usable by machine learning models. Data normalization and outlier correction are also performed at this stage.
[0388] Step 3:
[0389] The server inputs pre-processed data into a machine learning model to analyze traffic patterns. This model is trained to detect anomalies by comparing them to normal communication patterns.
[0390] Step 4:
[0391] The device transmits user input data and audio / video data to the emotion engine. This data is used to analyze the user's current emotional state.
[0392] Step 5:
[0393] The device's emotion engine uses natural language processing and facial recognition technology to generate results that estimate the user's emotional state. The resulting emotional state is output as, for example, "calm" or "stressed."
[0394] Step 6:
[0395] Based on the results of the emotion engine, the server classifies and prioritizes security incidents related to detected abnormal traffic patterns. If the emotion state is "stressed," it is treated as an unauthorized access attempt requiring immediate attention.
[0396] Step 7:
[0397] The server automatically implements countermeasures based on anomaly detection. These measures include blocking specific communications and temporarily restricting access. It also notifies users in real time of incident details and recommended actions.
[0398] Step 8:
[0399] Users can receive notifications, check the situation, and take additional manual action. Notifications include emotionally-based calming suggestions and specific steps to take.
[0400] Step 9:
[0401] The server analyzes past incident data and current trends to predict future threats. The AI model is regularly retrained to adapt to new threats, ensuring that the system always maintains up-to-date countermeasures.
[0402] Step 10:
[0403] Users (administrators) regularly evaluate the emotion engine and other system components and take measures to improve the overall system security. This increases the system's resilience to external attacks and internal vulnerabilities.
[0404] (Example 2)
[0405] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server" and the smart glasses 214 will be referred to as the "terminal".
[0406] In recent years, cyberattacks have increased along with the sophistication of network communications. To address this, advanced anomaly detection in real time and appropriate responses that take into account the emotional state of users are required. However, current network security systems have the challenge of being unable to respond in a way that takes into account the emotional state of users, and their responses after anomaly detection are uniform.
[0407] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.
[0408] In this invention, the server includes a device means for monitoring and collecting network communication data in real time, a device means for analyzing input data and inferring emotions in order to recognize the user's emotional state, and a device means for classifying security events and adjusting priorities based on the detected anomaly and the recognized emotional state of the user. This enables anomaly detection and individualized responses that take into account user emotions.
[0409] "Network communication data" refers to information that travels within a network, and is composed of data units called packets.
[0410] A "device" is a set of hardware or software components designed to perform a specific function.
[0411] "Preprocessing" refers to data cleaning, standardization, and transformation processes performed to convert raw data into an analyzable format.
[0412] A "machine learning algorithm" is a computational method that learns patterns and rules from large amounts of data and uses that knowledge to make predictions and classifications on new data.
[0413] An "artificial intelligence model" is a computational model trained using machine learning, a program that has the ability to automatically make decisions based on given data.
[0414] "Emotional state" refers to a person's emotional or moody state, and is usually inferred using emotion analysis techniques.
[0415] A "security incident" refers to an event that indicates unauthorized access to an information system, abnormal behavior, or a violation of security policies.
[0416] "Priority" is an indicator used to determine the order in which to address multiple events or tasks.
[0417] This invention is a system that integrates network security and user emotional management. Through anomaly detection and recognition of user emotions, this system enables more appropriate security responses.
[0418] The server first continuously monitors network communication data in real time. It captures this data, formats it as needed, and transforms it into a format suitable for analysis. This process includes normalizing the data and imputing missing values. The server leverages libraries in Python and other programming languages, for example, using Scikit-learn to execute machine learning algorithms. This allows for the rapid detection of abnormal communication patterns.
[0419] The device collects and analyzes user voice, text, facial expressions, and other data. It uses an emotion engine to evaluate the user's emotional state. By utilizing libraries such as TensorFlow and PyTorch, it enables more accurate emotion prediction.
[0420] Based on the information obtained through these processes, users are notified in real time of abnormal events and how to respond to them. The notifications are provided in a format and content appropriate to the user's current emotional state, and may include suggestions to help reduce stress.
[0421] As a concrete example, consider a case where a user accesses an important file outside of normal business hours. The server detects this as an anomaly, and if the terminal analyzes the user's emotions and detects stress, the server takes particularly swift and flexible measures and sends a notification to the user urging them to remain calm. In this way, considering both the detected anomaly and the user's emotions enables a more flexible and effective response.
[0422] An example of a prompt for a generative AI model might be, "Explain how to dynamically adjust the priority of network security responses based on the emotional state of a specific user."
[0423] The flow of the specific processing in Example 2 will be explained using Figure 13.
[0424] Step 1:
[0425] The server monitors network communication data in real time and captures data packet by packet. The input is raw data flowing through the network, and the output is structured packet information. This standardizes the data format and converts it into a format suitable for analysis.
[0426] Step 2:
[0427] The server preprocesses the captured data, performing actions such as imputing missing values and removing unnecessary data. The input is the packet information obtained in step 1, and the output is data formatted in a way that can be analyzed by the machine learning model. This preprocessing improves the quality of the data.
[0428] Step 3:
[0429] The server runs a machine learning model on pre-processed data to detect abnormal communication patterns. The input is formatted data, and the output is indicators and alert information showing anomalies. Here, libraries such as Scikit-learn are used to run the model.
[0430] Step 4:
[0431] The device collects text, audio, and image data to determine the user's emotions. Inputs include user communication content and video / audio data from the device, while output is a numerical representation of the user's emotional state. An emotion inference model is run using TensorFlow or similar tools.
[0432] Step 5:
[0433] The server combines anomaly detection information with the user's emotional state to classify security events and determine response priorities. Inputs are anomaly indicators and the results of emotional analysis, while output are prioritized response measures. This combination enables flexible security responses.
[0434] Step 6:
[0435] The user receives real-time notifications from their device based on the generated countermeasures. The input is the suggested countermeasures from the server, and the output is information about risk management that the user receives. The user is expected to respond calmly based on the information presented.
[0436] Step 7:
[0437] The server analyzes historical data and current trends to predict future network risks. The input is historical incident data, and the output is predictive information indicating future risks. The AI model is retrained based on the analysis results.
[0438] Step 8:
[0439] The user (administrator) performs a system-wide security assessment and sets up necessary protective measures. Inputs include system operational status and security logs, while output is an enhanced security plan. This improves system security.
[0440] (Application Example 2)
[0441] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server," and the smart glasses 214 will be referred to as the "terminal."
[0442] In network security, there is a growing need not only to detect abnormal traffic but also to provide more appropriate countermeasures that take into account the emotional state of users. Traditional systems primarily deal with technical anomalies, neglecting the emotional state of users and thus failing to provide a proper user experience. Therefore, the challenge is to provide a system that can implement countermeasures that address user emotions while maintaining network security.
[0443] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means.
[0444] In this invention, the server includes means for monitoring and collecting network communication data in real time; means for preprocessing the collected data and converting it into a format that can be analyzed by a machine learning algorithm; means for executing a machine learning algorithm that detects abnormal communication patterns using the preprocessed data; means for executing an emotion recognition engine that analyzes user input and voice / video information and infers the user's emotional state; means for automatically classifying security incidents based on detected anomalies and setting priorities considering the user's emotional information; means for automatically performing initial responses to incidents and sending emotion-based notifications to the user in real time; means for predicting future threats by analyzing past data and current trends; means for periodically retraining the artificial intelligence model to enable it to respond to the latest threats; and means for evaluating and protecting the security of the system. This makes it possible to respond according to the user's emotional state while enhancing network security.
[0445] "Network communication data" refers to data generated in the field of information technology when digital information is exchanged between devices.
[0446] "Real-time monitoring" is the process of observing and recording events that are currently in progress.
[0447] "Preprocessing" refers to the process of data cleansing and filtering to convert raw data into an analyzable format.
[0448] A "machine learning algorithm" is a numerical and logical method that uses computing resources to learn patterns from data and applies them to prediction and anomaly detection.
[0449] An "abnormal communication pattern" refers to a data flow or communication pattern that differs significantly from normal network traffic.
[0450] An "emotion recognition engine" is a software or hardware system that analyzes audio, video, and text data to estimate a person's emotional state.
[0451] A "security incident" is an event that can pose a security risk or threat to an information system, such as unauthorized access or data breaches.
[0452] "Prioritizing" is the process of evaluating the importance of multiple tasks or events and deciding the order in which to address them.
[0453] "Initial response" refers to the first actions and procedures taken when a problem occurs, with the aim of ensuring the smooth implementation of subsequent responses.
[0454] "Real-time transmission" is the process of sending data and information instantly so that recipients can receive it immediately.
[0455] "Past data" refers to archives and histories of digital information that were previously collected and recorded.
[0456] "Current trends" refer to events that are happening now, particularly general movements and directions that can be observed over time.
[0457] An "artificial intelligence model" is a trained algorithm built on machine learning techniques to perform a specific task.
[0458] "Retraining" is the process of updating an existing machine learning model by training it again using new data.
[0459] "System security" refers to a state in which an information system is protected from external threats and internal errors.
[0460] "Protection" means taking the necessary actions or measures to protect an object from danger or threat.
[0461] To implement this invention, a system is required that closely coordinates between the server, terminal, and user. The server acquires network communication data in real time and utilizes machine learning algorithms to detect abnormal patterns. This involves using commonly used data collection software and machine learning platforms. In particular, machine learning libraries such as TensorFlow are suitable for anomaly detection.
[0462] The terminal acquires data, audio, and video information input by the user and processes it using an emotion recognition engine. This engine utilizes natural language processing libraries and facial recognition technology to infer the user's emotions. The data collected by the terminal is shared with the server and used to determine the priority of anomalies and the actions to be taken.
[0463] Users receive notifications from the server and are offered solutions based on their own emotions. These suggestions enable users to make better decisions and contribute to improved network security. For example, if suspicious activity is detected outside of normal business hours and the user feels anxious, the device will send a reassuring message. In this way, flexible responses tailored to individual circumstances are provided without direct user interaction.
[0464] An example of a prompt for a generating AI model is: "If the user's emotional state is anxious, what should be included in the security advice?" This prompt allows the AI to generate appropriate suggestions and provide feedback to the system.
[0465] The flow of a specific process in Application Example 2 will be explained using Figure 14.
[0466] Step 1:
[0467] The server collects network communication data in real time. This process captures data packets and rapidly forwards them. Network traffic is used as input, and raw data packets are obtained as output. This raw data serves as fundamental information for anomaly detection.
[0468] Step 2:
[0469] The server preprocesses the collected raw data. This step involves data shaping and cleaning, converting the data into a format that can be analyzed by machine learning algorithms. The input is raw data packets, and the output is preprocessed and formatted data. Python and R data processing libraries are used for this processing.
[0470] Step 3:
[0471] The server applies machine learning algorithms to pre-processed data to detect abnormal communication patterns. The input is pre-processed data, and the output is the result of the anomaly detection. Abnormal patterns are determined to be deviations from normal communication information.
[0472] Step 4:
[0473] The device processes the user's voice and video information using an emotion recognition engine. The input here is voice and video data acquired from the user, and the output is the result of emotion inference. This step involves emotion classification using natural language processing and image processing libraries.
[0474] Step 5:
[0475] The server automatically classifies security incidents and sets priorities by combining anomaly detection results with the user's emotional state. The inputs for this step are anomaly patterns and emotional states, and the output is a list of classified incidents and their priorities. If the emotional state exceeds a certain threshold, the priority is set higher.
[0476] Step 6:
[0477] The user receives real-time notifications from the server. The input here is a categorized incident and a response based on emotion; the output is a notification message to the user. This includes suggestions tailored to the user's emotional state.
[0478] Step 7:
[0479] The server analyzes historical data to predict future threats. The input for this step is collected and analyzed historical data, and the output is a threat prediction. Time series analysis and predictive modeling techniques are utilized for the prediction.
[0480] Step 8:
[0481] The server periodically retrains the generated AI model to ensure it can respond to the latest threats. In this step, the input is a new dataset, and the output is the updated AI model. Retraining is performed to improve the model's accuracy and to better respond to new threat patterns.
[0482] The specific processing unit 290 transmits the result of the specific processing to the smart glasses 214. In the smart glasses 214, the control unit 46A causes the speaker 240 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.
[0483] Data generation model 58 is a type of so-called generative AI (Artificial Intelligence). One example of data generation model 58 is ChatGPT (Internet search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[0484] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and the specific processing may also be performed by the smart glasses 214.
[0485] [Third Embodiment]
[0486] Figure 5 shows an example of the configuration of the data processing system 310 according to the third embodiment.
[0487] As shown in Figure 5, the data processing system 310 includes a data processing device 12 and a headset terminal 314. An example of the data processing device 12 is a server.
[0488] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0489] The headset terminal 314 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication interface 44, and a display 343. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, camera 42, and display 343 are also connected to the bus 52.
[0490] The microphone 238 receives voice signals from the user 20 and receives instructions from the user 20. The microphone 238 captures the voice signals from the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.
[0491] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the area around the user 20 (for example, an imaging range defined by a field of view equivalent to the width of a typical healthy person's field of vision).
[0492] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.
[0493] Figure 6 shows an example of the main functions of the data processing device 12 and the headset terminal 314. As shown in Figure 6, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.
[0494] The specific processing program 56 is an example of a "program" relating to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[0495] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[0496] In the headset terminal 314, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.
[0497] Next, the specific processing performed by the specific processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the headset terminal 314 will be referred to as the "terminal".
[0498] This invention is an advanced security system that can monitor network traffic data in real time and automatically detect anomalies and respond to incidents. The embodiments for carrying out this invention are shown below.
[0499] Data Acquisition and Preprocessing
[0500] The server monitors network traffic and collects packet-level data. This data includes information such as source and destination IP addresses, protocols, and port numbers. The collected data is normalized and converted into a format suitable for analysis by a preprocessing module.
[0501] Anomaly detection
[0502] The machine learning model deployed on the server receives pre-processed data as input and detects anomalies by comparing it to the learned results of normal traffic patterns. This model uses a pre-trained algorithm to identify activity that deviates from normal patterns.
[0503] Incident Response
[0504] When an anomaly is detected, the server automatically executes response processes. These include blocking specific IP addresses, stopping suspicious communications, or isolating data. This allows for rapid threat suppression.
[0505] Notifications and reports
[0506] Users receive real-time notifications about detected threats and the actions taken. These notifications include detailed incident information and recommended next steps, allowing administrators to quickly understand the situation and take further action.
[0507] Prediction and retraining
[0508] The server accurately analyzes data from past incidents to predict future threats. This predictive information is provided to administrators in report format, which can be used to develop long-term security strategies. Furthermore, the AI model itself is regularly retrained and constantly updated to address the latest threats.
[0509] System protection
[0510] Users (administrators) are responsible for regularly evaluating and improving the security of the system itself. They ensure the overall security of the system by checking for security vulnerabilities, applying patches as needed, and adjusting settings.
[0511] As a concrete example, one day the server detects a large volume of data transfer outside of normal business hours and identifies it as an anomaly. The initial response involves immediately stopping the communication and restricting access for the affected users. Furthermore, the notification received by the user includes details of the anomaly and recommended next steps, such as a password change. These features allow for effective countermeasures to be taken before a crisis escalates.
[0512] The following describes the processing flow.
[0513] Step 1:
[0514] The server captures network traffic data and records detailed information such as source and destination IP addresses, port numbers, and communication protocols. This creates a foundation for understanding the overall data flow.
[0515] Step 2:
[0516] The server preprocesses the collected traffic data by analyzing it, removing unnecessary information, and normalizing it. This process prepares the data so that it can be analyzed by machine learning models.
[0517] Step 3:
[0518] A machine learning model on the server takes pre-processed data as input and detects anomalies by comparing it with normal data patterns learned in the past. If data exhibits patterns different from normal or shows mutations, it is identified as an anomaly.
[0519] Step 4:
[0520] The server classifies the incident based on the detected anomaly and sets a priority according to the risk level. High-risk anomalies require a faster response, so the server determines the order of response.
[0521] Step 5:
[0522] The server automatically takes initial action against abnormal activity according to the configured policies. For example, it may immediately block suspicious communications or restrict access to specific devices.
[0523] Step 6:
[0524] Users receive real-time details about detected anomalies and the actions taken via notifications from the server. These notifications include an overview of the incident and recommended countermeasures.
[0525] Step 7:
[0526] The server analyzes past incident data and predicts potential future threats. This provides users with information to prepare in advance, contributing to long-term security improvements.
[0527] Step 8:
[0528] The server periodically retrains the AI model with new data, updating it to respond quickly to the latest threats. This retraining ensures the system is always in optimal condition.
[0529] Step 9:
[0530] Users (administrators) regularly evaluate the system's security and ensure the system's safety by applying patches and updating security settings as needed.
[0531] (Example 1)
[0532] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."
[0533] With the increase in information and communication traffic, security threats in network environments are becoming more diverse. Therefore, it is necessary to monitor traffic data in real time, detect anomalies immediately, and take appropriate action. However, conventional systems suffer from a time lag between anomaly detection and response, making rapid response difficult. To solve this problem, more advanced anomaly detection capabilities and rapid incident response capabilities are required.
[0534] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.
[0535] In this invention, the server includes means for monitoring and collecting information transmission path data in real time, means for preprocessing the collected data and converting it into a format that can be analyzed by a computational model, and means for executing a computational model that detects abnormal information transmission patterns using the preprocessed data. This makes it possible to detect abnormal behavior on the network in real time and respond quickly on the spot.
[0536] "Information transmission path data" is a collection of digital information about communication activities within a network, including details such as source and destination addresses, protocols, communication volume, and timestamps.
[0537] A "computational model" is a mathematical computer program built for the purpose of data analysis and anomaly detection. It uses machine learning algorithms to process input data and identify specific patterns or anomalies.
[0538] "Means" refers to devices, methods, systems, or combinations thereof designed to achieve a specific function or purpose, and in this invention, these are used to realize anomaly detection and real-time response.
[0539] "Real-time monitoring" refers to a process that has the ability to observe and record information almost as soon as it occurs, and to take immediate action as needed.
[0540] An "abnormal information transmission pattern" refers to communication activity that exhibits behavior or characteristics that deviate from normal network communication, and can pose a security threat.
[0541] A "protection incident" refers to an event related to security threats in an information system, such as unauthorized access or data breaches, and involves a series of measures taken to address it.
[0542] This invention is implemented as part of an advanced security system aimed at protecting information systems. This system monitors information transmission path data on a network in real time, and detects and responds to anomalies immediately.
[0543] The server collects information transmission path data via a network interface using specialized software. Specific examples of such software include packet analysis tools and network monitoring applications. The collected data is stored in a database and organized and formatted by a data processing preprocessing module. Preprocessing includes data normalization and removal of outliers.
[0544] The server inputs this pre-processed data into a computational model. This model utilizes machine learning algorithms for anomaly detection and runs on a platform such as TensorFlow. The model, trained on historical normal communication data, analyzes the data in real time and identifies abnormal information transmission patterns. When an anomaly is detected, measures such as immediately blocking specific IP addresses or stopping suspicious communications are automatically taken.
[0545] Users receive real-time notifications from the server via the management console. These notifications include detailed information about detected anomalies and recommended countermeasures. Administrators (users) can then quickly take action based on specific cases.
[0546] As an example, if a large amount of data is sent to a server during the night for purposes other than normal operations, the server will immediately detect the anomaly and block the communication. The following morning, when the user checks, they will be notified of the anomaly via email or SMS, which includes a detailed anomaly report from the server. This email will also include instructions on how to investigate the suspected unauthorized access and determine the next course of action.
[0547] An example of a prompt for a generative AI model is, "Please provide an example of an effective machine learning model for identifying anomalous patterns in network traffic." This prompt facilitates the development and application of new anomaly detection algorithms.
[0548] The flow of the specific processing in Example 1 will be explained using Figure 11.
[0549] Step 1:
[0550] The server collects information transmission path data in real time via the network interface. Specifically, it uses a packet analysis tool to obtain header information and payload data for each packet. The input is raw data flowing from the network, and the output is structured data such as source and destination addresses, protocol, and timestamp.
[0551] Step 2:
[0552] The server sends the collected data to a preprocessing module for data normalization and removal of outliers. Specifically, it uses the Pandas library to create a dataframe, and performs missing value imputation and data type conversion. The input is the collected data, and the output is clean data suitable for analysis.
[0553] Step 3:
[0554] The server inputs preprocessed data into a computational model and performs analysis to detect abnormal information transmission patterns. Specifically, it uses TensorFlow to run a machine learning model and evaluate the data in real time. The input is preprocessed data, and the output is the result of anomaly detection that deviates from normal patterns.
[0555] Step 4:
[0556] The server immediately takes action in response to any detected anomalies. Specifically, it runs a script that uses iptables to block specific IP addresses. It also stops suspicious communications and saves related logs to an isolation folder. The input is the anomaly detection result, and the output is that network security is temporarily ensured.
[0557] Step 5:
[0558] Users receive real-time notifications from the server and learn detailed information about anomalies. Specifically, the system displays incident details and recommended actions via email and a management console. The input is the result of the response process, and the output provides users with information to consider immediate countermeasures.
[0559] Step 6:
[0560] The server predicts future threats using historical incident data. Specifically, it utilizes data analysis tools to analyze trends and generate predictive models. The input is historical incident data, and the output is predictive information provided to administrators to help them with future countermeasures.
[0561] (Application Example 1)
[0562] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."
[0563] With the recent advancements in information and communication technology, network security risks have increased. In particular, there is a growing need to detect anomalies in real time and respond quickly and appropriately. However, current systems struggle to effectively manage a large number of incidents. Furthermore, administrators often cannot grasp the situation in real time and take appropriate countermeasures. It is necessary to address these challenges and improve network security.
[0564] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.
[0565] In this invention, the server includes a device means for monitoring and collecting network traffic data in real time, a device means for preprocessing the collected information and converting it into an analyzable format, and a device means for detecting abnormal communication patterns using the preprocessed information. This makes it possible to immediately detect anomalies on the network and provide administrators with detailed information and safety recommendations in real time.
[0566] "Network traffic data" refers to all data transmitted and received over a network, including source and destination address information, the protocol used, port number, and other relevant information.
[0567] "Preprocessing" refers to the process of converting network traffic data into an analyzable format, including data normalization and transformation to facilitate analysis by machine learning models.
[0568] A "machine learning model" is a computational model that uses large amounts of data to learn normal and abnormal patterns and includes algorithms for detecting anomalies in real time.
[0569] A "security incident" is a security problem or failure caused by unauthorized access or attacks on a network.
[0570] "Setting priorities" refers to the act of identifying the importance and urgency of detected security incidents in order to determine the allocation of resources and the order of responses.
[0571] "Real-time notification" refers to the act of providing information to administrators immediately when a security incident occurs, and is a means of enabling rapid decision-making.
[0572] "Retraining an artificial intelligence model" refers to the process of continuously updating algorithms to improve the model's performance in order to respond to newly emerging threats and attack methods.
[0573] "Evaluating defenses" is the process of identifying system vulnerabilities and improving or adjusting defense strategies as needed, all aimed at ensuring the overall security of the system.
[0574] "Safety recommendations" are advice and guidelines that instruct users on what measures should be taken in response to detected anomalies, and are information intended to guide user behavior.
[0575] The security system implementing the present invention consists of a server, a network monitoring device, a terminal, and a user. The server uses a device that monitors network traffic data in real time and collects packet-level data. This data includes source and destination address information, the protocol used, port number, etc. The collected data is converted into an analyzable format by a preprocessor.
[0576] The server inputs the processed data into a machine learning model to detect abnormal communication patterns. This model learns from a large amount of normal traffic data and has the ability to recognize anomalies in real time. Based on the detected data, security incidents are automatically classified and prioritized.
[0577] The terminal notifies the user in real time of incident information received from the server. The notification includes a description of the anomaly along with security recommendations, enabling the user to take prompt and appropriate action. The user is required to review the system's defense strategy and take countermeasures based on the information provided.
[0578] This system supports continuous improvement by regularly retraining its artificial intelligence model to maintain its ability to respond to the latest threats. Furthermore, by analyzing past incident data and predicting future threats, it can enhance long-term security.
[0579] For example, if a large amount of data transfer is detected outside of normal hours on a given day, the server will automatically notify the server of the anomaly, restrict communication on the terminal, and immediately communicate details and recommended countermeasures to the user.
[0580] An example of a prompt for a generative AI model is, "Design a smartphone app that notifies users of the latest security alerts in real time."
[0581] The flow of a specific process in Application Example 1 will be explained using Figure 12.
[0582] Step 1:
[0583] The server monitors network traffic data in real time and collects packet-level data, including source and destination address information, the protocol used, and port numbers. This data is then normalized and converted into a parseable format. The collected data is the input, and the normalized data is the output.
[0584] Step 2:
[0585] The server inputs pre-processed data into a machine learning model. This model analyzes the data to detect abnormal communication patterns by comparing them to normal traffic patterns. The input to this process is pre-processed data, and the output is a determination of whether the data is normal or abnormal.
[0586] Step 3:
[0587] The server automatically classifies security incidents based on detected anomalies and sets priorities according to their severity. The classified incident information is the input, and the output is a list of incidents with assigned priorities.
[0588] Step 4:
[0589] The server automatically performs initial responses to incidents according to priority. This includes restricting or blocking specific communications. The input for this step is the incident list, and the output is the updated network control status.
[0590] Step 5:
[0591] The terminal receives incident information sent from the server and notifies the user in real time. The notification includes the nature of the anomaly and safety recommendations. The input to this process is the notification information from the server, and the output is the notification displayed to the user.
[0592] Step 6:
[0593] The user evaluates network security based on notifications from their device and reviews their defense strategy. Based on the security recommendations received, the user decides whether to change settings or take additional measures. The input for this step is notification information, and the output is the improved network settings.
[0594] Step 7:
[0595] The server periodically retrains its artificial intelligence model to ensure continuous improvement. This step uses historical incident data as training data to update the model and enable it to respond to new threats. The retraining data is the input, and the updated model is the output.
[0596] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.
[0597] This invention combines a network security system with an emotion engine that recognizes user emotions, aiming not only to ensure network security but also to improve the user experience. The embodiments for carrying out this invention are as follows:
[0598] Data Acquisition and Preprocessing
[0599] The server monitors network traffic data in real time and captures packet data. This data is preprocessed and converted into a format that can be analyzed by machine learning models, forming the basis for anomaly detection.
[0600] Anomaly detection
[0601] The server uses a machine learning model to detect anomalous traffic patterns from pre-processed data. This model learns from past normal data patterns and reliably identifies deviant patterns.
[0602] Recognition of user emotions by an emotion engine
[0603] The device analyzes user input, voice and video data, etc., using an emotion engine to infer the user's emotional state at that time. This engine utilizes natural language processing and facial recognition technology.
[0604] Incident Response
[0605] Based on detected anomalies, the server automatically classifies security incidents and prioritizes them, taking into account user sentiment. For example, if a user is experiencing stress, prompt and appropriate action is required.
[0606] Notifications and user suggestions
[0607] Users receive real-time feedback from the server regarding incidents and responses, along with emotionally-based advice. The notifications include follow-up suggestions tailored to the user's current emotional state.
[0608] Prediction and retraining
[0609] The server analyzes historical data to predict future threats. Based on these results, the system retrains its AI model to ensure it is always prepared to address the latest threats.
[0610] System protection
[0611] The user (administrator) will conduct a security assessment of the system and take measures to protect the entire system, including the emotion engine. This will minimize security vulnerabilities in the engine itself.
[0612] For example, if a user attempts to access an important dataset outside of normal business hours, the server will detect this as an anomaly. At that time, the terminal will analyze the user's emotions and detect unusual emotions, such as frustration. Taking this information into consideration, the server will decide to take particularly swift action and send a notification advising the user to remain calm. Such intelligent security responses allow users to recognize the potential risks of their actions and encourage appropriate behavior.
[0613] The following describes the processing flow.
[0614] Step 1:
[0615] The server captures network traffic data in real time and collects information about each packet. This information includes the source and destination IP addresses, port number, and communication protocol.
[0616] Step 2:
[0617] The server preprocesses the collected traffic data and converts it into a format usable by machine learning models. Data normalization and outlier correction are also performed at this stage.
[0618] Step 3:
[0619] The server inputs pre-processed data into a machine learning model to analyze traffic patterns. This model is trained to detect anomalies by comparing them to normal communication patterns.
[0620] Step 4:
[0621] The device transmits user input data and audio / video data to the emotion engine. This data is used to analyze the user's current emotional state.
[0622] Step 5:
[0623] The device's emotion engine uses natural language processing and facial recognition technology to generate results that estimate the user's emotional state. The resulting emotional state is output as, for example, "calm" or "stressed."
[0624] Step 6:
[0625] Based on the results of the emotion engine, the server classifies and prioritizes security incidents related to detected abnormal traffic patterns. If the emotion state is "stressed," it is treated as an unauthorized access attempt requiring immediate attention.
[0626] Step 7:
[0627] The server automatically implements countermeasures based on anomaly detection. These measures include blocking specific communications and temporarily restricting access. It also notifies users in real time of incident details and recommended actions.
[0628] Step 8:
[0629] Users can receive notifications, check the situation, and take additional manual action. Notifications include emotionally-based calming suggestions and specific steps to take.
[0630] Step 9:
[0631] The server analyzes past incident data and current trends to predict future threats. The AI model is regularly retrained to adapt to new threats, ensuring that the system always maintains up-to-date countermeasures.
[0632] Step 10:
[0633] Users (administrators) regularly evaluate the emotion engine and other system components and take measures to improve the overall system security. This increases the system's resilience to external attacks and internal vulnerabilities.
[0634] (Example 2)
[0635] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."
[0636] In recent years, cyberattacks have increased along with the sophistication of network communications. To address this, advanced anomaly detection in real time and appropriate responses that take into account the emotional state of users are required. However, current network security systems have the challenge of being unable to respond in a way that takes into account the emotional state of users, and their responses after anomaly detection are uniform.
[0637] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.
[0638] In this invention, the server includes a device means for monitoring and collecting network communication data in real time, a device means for analyzing input data and inferring emotions in order to recognize the user's emotional state, and a device means for classifying security events and adjusting priorities based on the detected anomaly and the recognized emotional state of the user. This enables anomaly detection and individualized responses that take into account user emotions.
[0639] "Network communication data" refers to information that travels within a network, and is composed of data units called packets.
[0640] A "device" is a set of hardware or software components designed to perform a specific function.
[0641] "Preprocessing" refers to data cleaning, standardization, and transformation processes performed to convert raw data into an analyzable format.
[0642] A "machine learning algorithm" is a computational method that learns patterns and rules from large amounts of data and uses that knowledge to make predictions and classifications on new data.
[0643] An "artificial intelligence model" is a computational model trained using machine learning, a program that has the ability to automatically make decisions based on given data.
[0644] "Emotional state" refers to a person's emotional or moody state, and is usually inferred using emotion analysis techniques.
[0645] A "security incident" refers to an event that indicates unauthorized access to an information system, abnormal behavior, or a violation of security policies.
[0646] "Priority" is an indicator used to determine the order in which to address multiple events or tasks.
[0647] This invention is a system that integrates network security and user emotional management. Through anomaly detection and recognition of user emotions, this system enables more appropriate security responses.
[0648] The server first continuously monitors network communication data in real time. It captures this data, formats it as needed, and transforms it into a format suitable for analysis. This process includes normalizing the data and imputing missing values. The server leverages libraries in Python and other programming languages, for example, using Scikit-learn to execute machine learning algorithms. This allows for the rapid detection of abnormal communication patterns.
[0649] The device collects and analyzes user voice, text, facial expressions, and other data. It uses an emotion engine to evaluate the user's emotional state. By utilizing libraries such as TensorFlow and PyTorch, it enables more accurate emotion prediction.
[0650] Based on the information obtained through these processes, users are notified in real time of abnormal events and how to respond to them. The notifications are provided in a format and content appropriate to the user's current emotional state, and may include suggestions to help reduce stress.
[0651] As a concrete example, consider a case where a user accesses an important file outside of normal business hours. The server detects this as an anomaly, and if the terminal analyzes the user's emotions and detects stress, the server takes particularly swift and flexible measures and sends a notification to the user urging them to remain calm. In this way, considering both the detected anomaly and the user's emotions enables a more flexible and effective response.
[0652] An example of a prompt for a generative AI model might be, "Explain how to dynamically adjust the priority of network security responses based on the emotional state of a specific user."
[0653] The flow of the specific processing in Example 2 will be explained using Figure 13.
[0654] Step 1:
[0655] The server monitors network communication data in real time and captures data packet by packet. The input is raw data flowing through the network, and the output is structured packet information. This standardizes the data format and converts it into a format suitable for analysis.
[0656] Step 2:
[0657] The server preprocesses the captured data, performing actions such as imputing missing values and removing unnecessary data. The input is the packet information obtained in step 1, and the output is data formatted in a way that can be analyzed by the machine learning model. This preprocessing improves the quality of the data.
[0658] Step 3:
[0659] The server runs a machine learning model on pre-processed data to detect abnormal communication patterns. The input is formatted data, and the output is indicators and alert information showing anomalies. Here, libraries such as Scikit-learn are used to run the model.
[0660] Step 4:
[0661] The device collects text, audio, and image data to determine the user's emotions. Input consists of user communication content and video / audio data from the device, while output is a numerical representation of the user's emotional state. An emotion prediction model is run using TensorFlow or similar tools.
[0662] Step 5:
[0663] The server combines anomaly detection information with the user's emotional state to classify security events and determine response priorities. Inputs are anomaly indicators and the results of emotional analysis, while output are prioritized response measures. This combination enables flexible security responses.
[0664] Step 6:
[0665] The user receives real-time notifications from their device based on the generated countermeasures. The input is the suggested countermeasures from the server, and the output is information about risk management that the user receives. The user is expected to respond calmly based on the information presented.
[0666] Step 7:
[0667] The server analyzes historical data and current trends to predict future network risks. The input is historical incident data, and the output is predictive information indicating future risks. The AI model is retrained based on the analysis results.
[0668] Step 8:
[0669] The user (administrator) performs a system-wide security assessment and sets up necessary protective measures. Inputs include system operational status and security logs, while output is an enhanced security plan. This improves system security.
[0670] (Application Example 2)
[0671] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."
[0672] In network security, there is a growing need not only to detect abnormal traffic but also to provide more appropriate countermeasures that take into account the emotional state of users. Traditional systems primarily deal with technical anomalies, neglecting the emotional state of users and thus failing to provide a proper user experience. Therefore, the challenge is to provide a system that can implement countermeasures that address user emotions while maintaining network security.
[0673] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means.
[0674] In this invention, the server includes means for monitoring and collecting network communication data in real time; means for preprocessing the collected data and converting it into a format that can be analyzed by a machine learning algorithm; means for executing a machine learning algorithm that detects abnormal communication patterns using the preprocessed data; means for executing an emotion recognition engine that analyzes user input and voice / video information and infers the user's emotional state; means for automatically classifying security incidents based on detected anomalies and setting priorities considering the user's emotional information; means for automatically performing initial responses to incidents and sending emotion-based notifications to the user in real time; means for predicting future threats by analyzing past data and current trends; means for periodically retraining the artificial intelligence model to enable it to respond to the latest threats; and means for evaluating and protecting the security of the system. This makes it possible to respond according to the user's emotional state while enhancing network security.
[0675] "Network communication data" refers to data generated in the field of information technology when digital information is exchanged between devices.
[0676] "Real-time monitoring" is the process of observing and recording events that are currently in progress.
[0677] "Preprocessing" refers to the process of data cleansing and filtering to convert raw data into an analyzable format.
[0678] A "machine learning algorithm" is a numerical and logical method that uses computing resources to learn patterns from data and applies them to prediction and anomaly detection.
[0679] An "abnormal communication pattern" refers to a data flow or communication pattern that differs significantly from normal network traffic.
[0680] An "emotion recognition engine" is a software or hardware system that analyzes audio, video, and text data to estimate a person's emotional state.
[0681] A "security incident" is an event that can pose a security risk or threat to an information system, such as unauthorized access or data breaches.
[0682] "Prioritizing" is the process of evaluating the importance of multiple tasks or events and deciding the order in which to address them.
[0683] "Initial response" refers to the first actions and procedures taken when a problem occurs, with the aim of ensuring the smooth implementation of subsequent responses.
[0684] "Real-time transmission" is the process of sending data and information instantly so that recipients can receive it immediately.
[0685] "Past data" refers to archives and histories of digital information that were previously collected and recorded.
[0686] "Current trends" refer to events that are happening now, particularly general movements and directions that can be observed over time.
[0687] An "artificial intelligence model" is a trained algorithm built on machine learning techniques to perform a specific task.
[0688] "Retraining" is the process of updating an existing machine learning model by training it again using new data.
[0689] "System security" refers to a state in which an information system is protected from external threats and internal errors.
[0690] "Protection" means taking the necessary actions or measures to protect an object from danger or threat.
[0691] To implement this invention, a system is required that closely coordinates between the server, terminal, and user. The server acquires network communication data in real time and utilizes machine learning algorithms to detect abnormal patterns. This involves using commonly used data collection software and machine learning platforms. In particular, machine learning libraries such as TensorFlow are suitable for anomaly detection.
[0692] The terminal acquires data, audio, and video information input by the user and processes it using an emotion recognition engine. This engine utilizes natural language processing libraries and facial recognition technology to infer the user's emotions. The data collected by the terminal is shared with the server and used to determine the priority of anomalies and the actions to be taken.
[0693] Users receive notifications from the server and are offered solutions based on their own emotions. These suggestions enable users to make better decisions and contribute to improved network security. For example, if suspicious activity is detected outside of normal business hours and the user feels anxious, the device will send a reassuring message. In this way, flexible responses tailored to individual circumstances are provided without direct user interaction.
[0694] An example of a prompt for a generating AI model is: "If the user's emotional state is anxious, what should be included in the security advice?" This prompt allows the AI to generate appropriate suggestions and provide feedback to the system.
[0695] The flow of a specific process in Application Example 2 will be explained using Figure 14.
[0696] Step 1:
[0697] The server collects network communication data in real time. This process captures data packets and rapidly forwards them. Network traffic is used as input, and raw data packets are obtained as output. This raw data serves as fundamental information for anomaly detection.
[0698] Step 2:
[0699] The server preprocesses the collected raw data. This step involves data shaping and cleaning, converting the data into a format that can be analyzed by machine learning algorithms. The input is raw data packets, and the output is preprocessed and formatted data. Python and R data processing libraries are used for this processing.
[0700] Step 3:
[0701] The server applies machine learning algorithms to pre-processed data to detect abnormal communication patterns. The input is pre-processed data, and the output is the result of the anomaly detection. Abnormal patterns are determined to be deviations from normal communication information.
[0702] Step 4:
[0703] The device processes the user's voice and video information using an emotion recognition engine. The input here is voice and video data acquired from the user, and the output is the result of emotion inference. This step involves emotion classification using natural language processing and image processing libraries.
[0704] Step 5:
[0705] The server automatically classifies security incidents and sets priorities by combining anomaly detection results with the user's emotional state. The inputs for this step are anomaly patterns and emotional states, and the output is a list of classified incidents and their priorities. If the emotional state exceeds a certain threshold, the priority is set higher.
[0706] Step 6:
[0707] The user receives real-time notifications from the server. The input here is a categorized incident and a response based on emotion; the output is a notification message to the user. This includes suggestions tailored to the user's emotional state.
[0708] Step 7:
[0709] The server analyzes historical data to predict future threats. The input for this step is collected and analyzed historical data, and the output is a threat prediction. Time series analysis and predictive modeling techniques are used for the prediction.
[0710] Step 8:
[0711] The server periodically retrains the generated AI model to ensure it can respond to the latest threats. In this step, the input is a new dataset, and the output is the updated AI model. Retraining is performed to improve the model's accuracy and to better respond to new threat patterns.
[0712] The specific processing unit 290 transmits the result of the specific processing to the headset terminal 314. In the headset terminal 314, the control unit 46A causes the speaker 240 and display 343 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.
[0713] Data generation model 58 is a type of so-called generative AI (Artificial Intelligence). One example of data generation model 58 is ChatGPT (Internet search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[0714] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and specific processing may also be performed by the headset terminal 314.
[0715] [Fourth Embodiment]
[0716] Figure 7 shows an example of the configuration of the data processing system 410 according to the fourth embodiment.
[0717] As shown in Figure 7, the data processing system 410 includes a data processing device 12 and a robot 414. An example of the data processing device 12 is a server.
[0718] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0719] The robot 414 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication interface 44, and a controlled object 443. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, camera 42, and controlled object 443 are also connected to the bus 52.
[0720] The microphone 238 receives voice signals from the user 20 and receives instructions from the user 20. The microphone 238 captures the voice signals from the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.
[0721] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the area around the user 20 (for example, an imaging range defined by a field of view equivalent to the width of a typical healthy person's field of vision).
[0722] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.
[0723] The controlled object 443 includes a display device, LEDs in the eyes, and motors that drive the arms, hands, and feet. The posture and gestures of the robot 414 are controlled by controlling the motors of the arms, hands, and feet. Some of the robot 414's emotions can be expressed by controlling these motors. Furthermore, the robot 414's facial expressions can also be expressed by controlling the illumination state of the LEDs in its eyes.
[0724] Figure 8 shows an example of the main functions of the data processing device 12 and the robot 414. As shown in Figure 8, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.
[0725] The specific processing program 56 is an example of a "program" relating to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[0726] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[0727] In robot 414, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.
[0728] Next, the specific processing performed by the specific processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".
[0729] This invention is an advanced security system that can monitor network traffic data in real time and automatically detect anomalies and respond to incidents. The embodiments for carrying out this invention are shown below.
[0730] Data Acquisition and Preprocessing
[0731] The server monitors network traffic and collects packet-level data. This data includes information such as source and destination IP addresses, protocols, and port numbers. The collected data is normalized and converted into a format suitable for analysis by a preprocessing module.
[0732] Anomaly detection
[0733] The machine learning model deployed on the server receives pre-processed data as input and detects anomalies by comparing it to the learned results of normal traffic patterns. This model uses a pre-trained algorithm to identify activity that deviates from normal patterns.
[0734] Incident Response
[0735] When an anomaly is detected, the server automatically executes response processes. These include blocking specific IP addresses, stopping suspicious communications, or isolating data. This allows for rapid threat suppression.
[0736] Notifications and reports
[0737] Users receive real-time notifications about detected threats and the actions taken. These notifications include detailed incident information and recommended next steps, allowing administrators to quickly understand the situation and take further action.
[0738] Prediction and retraining
[0739] The server accurately analyzes data from past incidents to predict future threats. This predictive information is provided to administrators in report format, which can be used to develop long-term security strategies. Furthermore, the AI model itself is regularly retrained and constantly updated to address the latest threats.
[0740] System protection
[0741] Users (administrators) are responsible for regularly evaluating and improving the security of the system itself. They ensure the overall security of the system by checking for security vulnerabilities, applying patches as needed, and adjusting settings.
[0742] As a concrete example, one day the server detects a large volume of data transfer outside of normal business hours and identifies it as an anomaly. The initial response involves immediately stopping the communication and restricting access for the affected users. Furthermore, the notification received by the user includes details of the anomaly and recommended next steps, such as a password change. These features allow for effective countermeasures to be taken before a crisis escalates.
[0743] The following describes the processing flow.
[0744] Step 1:
[0745] The server captures network traffic data and records detailed information such as source and destination IP addresses, port numbers, and communication protocols. This creates a foundation for understanding the overall data flow.
[0746] Step 2:
[0747] The server preprocesses the collected traffic data by analyzing it, removing unnecessary information, and normalizing it. This process prepares the data so that it can be analyzed by machine learning models.
[0748] Step 3:
[0749] A machine learning model on the server takes pre-processed data as input and detects anomalies by comparing it with normal data patterns learned in the past. If data exhibits patterns different from normal or shows mutations, it is identified as an anomaly.
[0750] Step 4:
[0751] The server classifies the incident based on the detected anomaly and sets a priority according to the risk level. High-risk anomalies require a faster response, so the server determines the order of response.
[0752] Step 5:
[0753] The server automatically takes initial action against abnormal activity according to the configured policies. For example, it may immediately block suspicious communications or restrict access to specific devices.
[0754] Step 6:
[0755] Users receive real-time details about detected anomalies and the actions taken via notifications from the server. These notifications include an overview of the incident and recommended countermeasures.
[0756] Step 7:
[0757] The server analyzes past incident data and predicts potential future threats. This provides users with information to prepare in advance, contributing to long-term security improvements.
[0758] Step 8:
[0759] The server periodically retrains the AI model with new data, updating it to respond quickly to the latest threats. This retraining ensures the system is always in optimal condition.
[0760] Step 9:
[0761] Users (administrators) regularly evaluate the system's security and ensure the system's safety by applying patches and updating security settings as needed.
[0762] (Example 1)
[0763] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".
[0764] With the increase in information and communication traffic, security threats in network environments are becoming more diverse. Therefore, it is necessary to monitor traffic data in real time, detect anomalies immediately, and take appropriate action. However, conventional systems suffer from a time lag between anomaly detection and response, making rapid response difficult. To solve this problem, more advanced anomaly detection capabilities and rapid incident response capabilities are required.
[0765] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.
[0766] In this invention, the server includes means for monitoring and collecting information transmission path data in real time, means for preprocessing the collected data and converting it into a format that can be analyzed by a computational model, and means for executing a computational model that detects abnormal information transmission patterns using the preprocessed data. This makes it possible to detect abnormal behavior on the network in real time and respond quickly on the spot.
[0767] "Information transmission path data" is a collection of digital information about communication activities within a network, including details such as source and destination addresses, protocols, communication volume, and timestamps.
[0768] A "computational model" is a mathematical computer program built for the purpose of data analysis and anomaly detection. It uses machine learning algorithms to process input data and identify specific patterns or anomalies.
[0769] "Means" refers to devices, methods, systems, or combinations thereof designed to achieve a specific function or purpose, and in this invention, these are used to realize anomaly detection and real-time response.
[0770] "Real-time monitoring" refers to a process that has the ability to observe and record information almost as soon as it occurs, and to take immediate action as needed.
[0771] An "abnormal information transmission pattern" refers to communication activity that exhibits behavior or characteristics that deviate from normal network communication, and can pose a security threat.
[0772] A "protection incident" refers to an event related to security threats in an information system, such as unauthorized access or data breaches, and involves a series of measures taken to address it.
[0773] This invention is implemented as part of an advanced security system aimed at protecting information systems. This system monitors information transmission path data on a network in real time, and detects and responds to anomalies immediately.
[0774] The server collects information transmission path data via a network interface using specialized software. Specific examples of such software include packet analysis tools and network monitoring applications. The collected data is stored in a database and organized and formatted by a data processing preprocessing module. Preprocessing includes data normalization and removal of outliers.
[0775] The server inputs this pre-processed data into a computational model. This model utilizes machine learning algorithms for anomaly detection and runs on a platform such as TensorFlow. The model, trained on historical normal communication data, analyzes the data in real time and identifies abnormal information transmission patterns. When an anomaly is detected, measures such as immediately blocking specific IP addresses or stopping suspicious communications are automatically taken.
[0776] Users receive real-time notifications from the server via the management console. These notifications include detailed information about detected anomalies and recommended countermeasures. Administrators (users) can then quickly take action based on specific cases.
[0777] As an example, if a large amount of data is sent to a server during the night for purposes other than normal operations, the server will immediately detect the anomaly and block the communication. The following morning, when the user checks, they will be notified of the anomaly via email or SMS, which includes a detailed anomaly report from the server. This email will also include instructions on how to investigate the suspected unauthorized access and determine the next course of action.
[0778] An example of a prompt for a generative AI model is, "Please provide an example of an effective machine learning model for identifying anomalous patterns in network traffic." This prompt facilitates the development and application of new anomaly detection algorithms.
[0779] The flow of the specific processing in Example 1 will be explained using Figure 11.
[0780] Step 1:
[0781] The server collects information transmission path data in real time via the network interface. Specifically, it uses a packet analysis tool to obtain header information and payload data for each packet. The input is raw data flowing from the network, and the output is structured data such as source and destination addresses, protocol, and timestamp.
[0782] Step 2:
[0783] The server sends the collected data to a preprocessing module for data normalization and removal of outliers. Specifically, it uses the Pandas library to create a dataframe, and performs missing value imputation and data type conversion. The input is the collected data, and the output is clean data suitable for analysis.
[0784] Step 3:
[0785] The server inputs preprocessed data into a computational model and performs analysis to detect abnormal information transmission patterns. Specifically, it uses TensorFlow to run a machine learning model and evaluate the data in real time. The input is preprocessed data, and the output is the result of anomaly detection that deviates from normal patterns.
[0786] Step 4:
[0787] The server immediately takes action in response to any detected anomalies. Specifically, it runs a script that uses iptables to block specific IP addresses. It also stops suspicious communications and saves related logs to an isolation folder. The input is the anomaly detection result, and the output is that network security is temporarily ensured.
[0788] Step 5:
[0789] Users receive real-time notifications from the server and learn detailed information about anomalies. Specifically, the system displays incident details and recommended actions via email and a management console. The input is the result of the response process, and the output provides users with information to consider immediate countermeasures.
[0790] Step 6:
[0791] The server predicts future threats using historical incident data. Specifically, it utilizes data analysis tools to analyze trends and generate predictive models. The input is historical incident data, and the output is predictive information provided to administrators to help them with future countermeasures.
[0792] (Application Example 1)
[0793] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".
[0794] With the recent advancements in information and communication technology, network security risks have increased. In particular, there is a growing need to detect anomalies in real time and respond quickly and appropriately. However, current systems struggle to effectively manage a large number of incidents. Furthermore, administrators often cannot grasp the situation in real time and take appropriate countermeasures. It is necessary to address these challenges and improve network security.
[0795] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.
[0796] In this invention, the server includes a device means for monitoring and collecting network traffic data in real time, a device means for preprocessing the collected information and converting it into an analyzable format, and a device means for detecting abnormal communication patterns using the preprocessed information. This makes it possible to immediately detect anomalies on the network and provide administrators with detailed information and safety recommendations in real time.
[0797] "Network traffic data" refers to all data transmitted and received over a network, including source and destination address information, the protocol used, port number, and other relevant information.
[0798] "Preprocessing" refers to the process of converting network traffic data into an analyzable format, including data normalization and transformation to facilitate analysis by machine learning models.
[0799] A "machine learning model" is a computational model that uses large amounts of data to learn normal and abnormal patterns and includes algorithms for detecting anomalies in real time.
[0800] A "security incident" is a security problem or failure caused by unauthorized access or attacks on a network.
[0801] "Setting priorities" refers to the act of identifying the importance and urgency of detected security incidents in order to determine the allocation of resources and the order of responses.
[0802] "Real-time notification" refers to the act of providing information to administrators immediately when a security incident occurs, and is a means of enabling rapid decision-making.
[0803] "Retraining an artificial intelligence model" refers to the process of continuously updating algorithms to improve the model's performance in order to respond to newly emerging threats and attack methods.
[0804] "Evaluating defenses" is the process of identifying system vulnerabilities and improving or adjusting defense strategies as needed, all aimed at ensuring the overall security of the system.
[0805] "Safety recommendations" are advice and guidelines that instruct users on what measures should be taken in response to detected anomalies, and are information intended to guide user behavior.
[0806] The security system implementing the present invention consists of a server, a network monitoring device, a terminal, and a user. The server uses a device that monitors network traffic data in real time and collects packet-level data. This data includes source and destination address information, the protocol used, port number, etc. The collected data is converted into an analyzable format by a preprocessor.
[0807] The server inputs the processed data into a machine learning model to detect abnormal communication patterns. This model learns from a large amount of normal traffic data and has the ability to recognize anomalies in real time. Based on the detected data, security incidents are automatically classified and prioritized.
[0808] The terminal notifies the user in real time of incident information received from the server. The notification includes a description of the anomaly along with security recommendations, enabling the user to take prompt and appropriate action. The user is required to review the system's defense strategy and take countermeasures based on the information provided.
[0809] This system supports continuous improvement by regularly retraining its artificial intelligence model to maintain its ability to respond to the latest threats. Furthermore, by analyzing past incident data and predicting future threats, it can enhance long-term security.
[0810] For example, if a large amount of data transfer is detected outside of normal hours on a given day, the server will automatically notify the server of the anomaly, restrict communication on the terminal, and immediately communicate details and recommended countermeasures to the user.
[0811] An example of a prompt for a generative AI model is, "Design a smartphone app that notifies users of the latest security alerts in real time."
[0812] The flow of a specific process in Application Example 1 will be explained using Figure 12.
[0813] Step 1:
[0814] The server monitors network traffic data in real time and collects packet-level data, including source and destination address information, the protocol used, and port numbers. This data is then normalized and converted into a parseable format. The collected data is the input, and the normalized data is the output.
[0815] Step 2:
[0816] The server inputs pre-processed data into a machine learning model. This model analyzes the data to detect abnormal communication patterns by comparing them to normal traffic patterns. The input to this process is pre-processed data, and the output is a determination of whether the data is normal or abnormal.
[0817] Step 3:
[0818] The server automatically classifies security incidents based on detected anomalies and sets priorities according to their severity. The classified incident information is the input, and the output is a list of incidents with assigned priorities.
[0819] Step 4:
[0820] The server automatically performs initial responses to incidents according to priority. This includes restricting or blocking specific communications. The input for this step is the incident list, and the output is the updated network control status.
[0821] Step 5:
[0822] The terminal receives incident information sent from the server and notifies the user in real time. The notification includes the nature of the anomaly and safety recommendations. The input to this process is the notification information from the server, and the output is the notification displayed to the user.
[0823] Step 6:
[0824] The user evaluates network security based on notifications from their device and reviews their defense strategy. Based on the security recommendations received, the user decides whether to change settings or take additional measures. The input for this step is notification information, and the output is the improved network settings.
[0825] Step 7:
[0826] The server periodically retrains its artificial intelligence model to ensure continuous improvement. This step uses historical incident data as training data to update the model and enable it to respond to new threats. The retraining data is the input, and the updated model is the output.
[0827] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.
[0828] This invention combines a network security system with an emotion engine that recognizes user emotions, aiming not only to ensure network security but also to improve the user experience. The embodiments for carrying out this invention are as follows:
[0829] Data Acquisition and Preprocessing
[0830] The server monitors network traffic data in real time and captures packet data. This data is preprocessed and converted into a format that can be analyzed by machine learning models, forming the basis for anomaly detection.
[0831] Anomaly detection
[0832] The server uses a machine learning model to detect anomalous traffic patterns from pre-processed data. This model learns from past normal data patterns and reliably identifies deviant patterns.
[0833] Recognition of user emotions by an emotion engine
[0834] The device analyzes user input, voice and video data, etc., using an emotion engine to infer the user's emotional state at that time. This engine utilizes natural language processing and facial recognition technology.
[0835] Incident Response
[0836] Based on detected anomalies, the server automatically classifies security incidents and prioritizes them, taking into account user sentiment. For example, if a user is experiencing stress, prompt and appropriate action is required.
[0837] Notifications and user suggestions
[0838] Users receive real-time feedback from the server regarding incidents and responses, along with emotionally-based advice. The notifications include follow-up suggestions tailored to the user's current emotional state.
[0839] Prediction and retraining
[0840] The server analyzes historical data to predict future threats. Based on these results, the system retrains its AI model to ensure it is always prepared to address the latest threats.
[0841] System protection
[0842] The user (administrator) will conduct a security assessment of the system and take measures to protect the entire system, including the emotion engine. This will minimize security vulnerabilities in the engine itself.
[0843] For example, if a user attempts to access an important dataset outside of normal business hours, the server will detect this as an anomaly. At that time, the terminal will analyze the user's emotions and detect unusual emotions, such as frustration. Taking this information into consideration, the server will decide to take particularly swift action and send a notification advising the user to remain calm. Such intelligent security responses allow users to recognize the potential risks of their actions and encourage appropriate behavior.
[0844] The following describes the processing flow.
[0845] Step 1:
[0846] The server captures network traffic data in real time and collects information about each packet. This information includes the source and destination IP addresses, port number, and communication protocol.
[0847] Step 2:
[0848] The server preprocesses the collected traffic data and converts it into a format usable by machine learning models. Data normalization and outlier correction are also performed at this stage.
[0849] Step 3:
[0850] The server inputs pre-processed data into a machine learning model to analyze traffic patterns. This model is trained to detect anomalies by comparing them to normal communication patterns.
[0851] Step 4:
[0852] The device transmits user input data and audio / video data to the emotion engine. This data is used to analyze the user's current emotional state.
[0853] Step 5:
[0854] The device's emotion engine uses natural language processing and facial recognition technology to generate results that estimate the user's emotional state. The resulting emotional state is output as, for example, "calm" or "stressed."
[0855] Step 6:
[0856] Based on the results of the emotion engine, the server classifies and prioritizes security incidents related to detected abnormal traffic patterns. If the emotion state is "stressed," it is treated as an unauthorized access attempt requiring immediate attention.
[0857] Step 7:
[0858] The server automatically implements countermeasures based on anomaly detection. These measures include blocking specific communications and temporarily restricting access. It also notifies users in real time of incident details and recommended actions.
[0859] Step 8:
[0860] Users can receive notifications, check the situation, and take additional manual action. Notifications include emotionally-based calming suggestions and specific steps to take.
[0861] Step 9:
[0862] The server analyzes past incident data and current trends to predict future threats. The AI model is regularly retrained to adapt to new threats, ensuring that the system always maintains up-to-date countermeasures.
[0863] Step 10:
[0864] Users (administrators) regularly evaluate the emotion engine and other system components and take measures to improve the overall system security. This increases the system's resilience to external attacks and internal vulnerabilities.
[0865] (Example 2)
[0866] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".
[0867] In recent years, cyberattacks have increased along with the sophistication of network communications. To address this, advanced anomaly detection in real time and appropriate responses that take into account the emotional state of users are required. However, current network security systems have the challenge of being unable to respond in a way that takes into account the emotional state of users, and their responses after anomaly detection are uniform.
[0868] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.
[0869] In this invention, the server includes a device means for monitoring and collecting network communication data in real time, a device means for analyzing input data and inferring emotions in order to recognize the user's emotional state, and a device means for classifying security events and adjusting priorities based on the detected anomaly and the recognized emotional state of the user. This enables anomaly detection and individualized responses that take into account user emotions.
[0870] "Network communication data" refers to information that travels within a network, and is composed of data units called packets.
[0871] A "device" is a set of hardware or software components designed to perform a specific function.
[0872] "Preprocessing" refers to data cleaning, standardization, and transformation processes performed to convert raw data into an analyzable format.
[0873] A "machine learning algorithm" is a computational method that learns patterns and rules from large amounts of data and uses that knowledge to make predictions and classifications on new data.
[0874] An "artificial intelligence model" is a computational model trained using machine learning, a program that has the ability to automatically make decisions based on given data.
[0875] "Emotional state" refers to a person's emotional or moody state, and is usually inferred using emotion analysis techniques.
[0876] A "security incident" refers to an event that indicates unauthorized access to an information system, abnormal behavior, or a violation of security policies.
[0877] "Priority" is an indicator used to determine the order in which to address multiple events or tasks.
[0878] This invention is a system that integrates network security and user emotional management. Through anomaly detection and recognition of user emotions, this system enables more appropriate security responses.
[0879] The server first continuously monitors network communication data in real time. It captures this data, formats it as needed, and transforms it into a format suitable for analysis. This process includes normalizing the data and imputing missing values. The server leverages libraries in Python and other programming languages, for example, using Scikit-learn to execute machine learning algorithms. This allows for the rapid detection of abnormal communication patterns.
[0880] The device collects and analyzes user voice, text, facial expressions, and other data. It uses an emotion engine to evaluate the user's emotional state. By utilizing libraries such as TensorFlow and PyTorch, it enables more accurate emotion prediction.
[0881] Based on the information obtained through these processes, users are notified in real time of abnormal events and how to respond to them. The notifications are provided in a format and content appropriate to the user's current emotional state, and may include suggestions to help reduce stress.
[0882] As a concrete example, consider a case where a user accesses an important file outside of normal business hours. The server detects this as an anomaly, and if the terminal analyzes the user's emotions and detects stress, the server takes particularly swift and flexible measures and sends a notification to the user urging them to remain calm. In this way, considering both the detected anomaly and the user's emotions enables a more flexible and effective response.
[0883] An example of a prompt for a generative AI model might be, "Explain how to dynamically adjust the priority of network security responses based on the emotional state of a specific user."
[0884] The flow of the specific processing in Example 2 will be explained using Figure 13.
[0885] Step 1:
[0886] The server monitors network communication data in real time and captures data packet by packet. The input is raw data flowing through the network, and the output is structured packet information. This standardizes the data format and converts it into a format suitable for analysis.
[0887] Step 2:
[0888] The server preprocesses the captured data, performing actions such as imputing missing values and removing unnecessary data. The input is the packet information obtained in step 1, and the output is data formatted in a way that can be analyzed by the machine learning model. This preprocessing improves the quality of the data.
[0889] Step 3:
[0890] The server runs a machine learning model on pre-processed data to detect abnormal communication patterns. The input is formatted data, and the output is indicators and alert information showing anomalies. Here, libraries such as Scikit-learn are used to run the model.
[0891] Step 4:
[0892] The device collects text, audio, and image data to determine the user's emotions. Input consists of user communication content and video / audio data from the device, while output is a numerical representation of the user's emotional state. An emotion prediction model is run using TensorFlow or similar tools.
[0893] Step 5:
[0894] The server combines anomaly detection information with the user's emotional state to classify security events and determine response priorities. Inputs are anomaly indicators and the results of emotional analysis, while output are prioritized response measures. This combination enables flexible security responses.
[0895] Step 6:
[0896] The user receives real-time notifications from their device based on the generated countermeasures. The input is the suggested countermeasures from the server, and the output is information about risk management that the user receives. The user is expected to respond calmly based on the information presented.
[0897] Step 7:
[0898] The server analyzes historical data and current trends to predict future network risks. The input is historical incident data, and the output is predictive information indicating future risks. The AI model is retrained based on the analysis results.
[0899] Step 8:
[0900] The user (administrator) performs a system-wide security assessment and sets up necessary protective measures. Inputs include system operational status and security logs, while output is an enhanced security plan. This improves system security.
[0901] (Application Example 2)
[0902] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".
[0903] In network security, there is a growing need not only to detect abnormal traffic but also to provide more appropriate countermeasures that take into account the emotional state of users. Traditional systems primarily deal with technical anomalies, neglecting the emotional state of users and thus failing to provide a proper user experience. Therefore, the challenge is to provide a system that can implement countermeasures that address user emotions while maintaining network security.
[0904] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means.
[0905] In this invention, the server includes means for monitoring and collecting network communication data in real time; means for preprocessing the collected data and converting it into a format that can be analyzed by a machine learning algorithm; means for executing a machine learning algorithm that detects abnormal communication patterns using the preprocessed data; means for executing an emotion recognition engine that analyzes user input and voice / video information and infers the user's emotional state; means for automatically classifying security incidents based on detected anomalies and setting priorities considering the user's emotional information; means for automatically performing initial responses to incidents and sending emotion-based notifications to the user in real time; means for predicting future threats by analyzing past data and current trends; means for periodically retraining the artificial intelligence model to enable it to respond to the latest threats; and means for evaluating and protecting the security of the system. This makes it possible to respond according to the user's emotional state while enhancing network security.
[0906] "Network communication data" refers to data generated in the field of information technology when digital information is exchanged between devices.
[0907] "Real-time monitoring" is the process of observing and recording events that are currently in progress.
[0908] "Preprocessing" refers to the process of data cleansing and filtering to convert raw data into an analyzable format.
[0909] A "machine learning algorithm" is a numerical and logical method that uses computing resources to learn patterns from data and applies them to prediction and anomaly detection.
[0910] An "abnormal communication pattern" refers to a data flow or communication pattern that differs significantly from normal network traffic.
[0911] An "emotion recognition engine" is a software or hardware system that analyzes audio, video, and text data to estimate a person's emotional state.
[0912] A "security incident" is an event that can pose a security risk or threat to an information system, such as unauthorized access or data breaches.
[0913] "Prioritizing" is the process of evaluating the importance of multiple tasks or events and deciding the order in which to address them.
[0914] "Initial response" refers to the first actions and procedures taken when a problem occurs, with the aim of ensuring the smooth implementation of subsequent responses.
[0915] "Real-time transmission" is the process of sending data and information instantly so that recipients can receive it immediately.
[0916] "Past data" refers to archives and histories of digital information that were previously collected and recorded.
[0917] "Current trends" refer to events that are happening now, particularly general movements and directions that can be observed over time.
[0918] An "artificial intelligence model" is a trained algorithm built on machine learning techniques to perform a specific task.
[0919] "Retraining" is the process of updating an existing machine learning model by training it again using new data.
[0920] "System security" refers to a state in which an information system is protected from external threats and internal errors.
[0921] "Protection" means taking the necessary actions or measures to protect an object from danger or threat.
[0922] To implement this invention, a system is required that closely coordinates between the server, terminal, and user. The server acquires network communication data in real time and utilizes machine learning algorithms to detect abnormal patterns. This involves using commonly used data collection software and machine learning platforms. In particular, machine learning libraries such as TensorFlow are suitable for anomaly detection.
[0923] The terminal acquires data, audio, and video information input by the user and processes it using an emotion recognition engine. This engine utilizes natural language processing libraries and facial recognition technology to infer the user's emotions. The data collected by the terminal is shared with the server and used to determine the priority of anomalies and the actions to be taken.
[0924] Users receive notifications from the server and are offered solutions based on their own emotions. These suggestions enable users to make better decisions and contribute to improved network security. For example, if suspicious activity is detected outside of normal business hours and the user feels anxious, the device will send a reassuring message. In this way, flexible responses tailored to individual circumstances are provided without direct user interaction.
[0925] An example of a prompt for a generating AI model is: "If the user's emotional state is anxious, what should be included in the security advice?" This prompt allows the AI to generate appropriate suggestions and provide feedback to the system.
[0926] The flow of a specific process in Application Example 2 will be explained using Figure 14.
[0927] Step 1:
[0928] The server collects network communication data in real time. This process captures data packets and rapidly forwards them. Network traffic is used as input, and raw data packets are obtained as output. This raw data serves as fundamental information for anomaly detection.
[0929] Step 2:
[0930] The server preprocesses the collected raw data. This step involves data shaping and cleaning, converting the data into a format that can be analyzed by machine learning algorithms. The input is raw data packets, and the output is preprocessed and formatted data. Python and R data processing libraries are used for this processing.
[0931] Step 3:
[0932] The server applies machine learning algorithms to pre-processed data to detect abnormal communication patterns. The input is pre-processed data, and the output is the result of the anomaly detection. Abnormal patterns are determined to be deviations from normal communication information.
[0933] Step 4:
[0934] The device processes the user's voice and video information using an emotion recognition engine. The input here is voice and video data acquired from the user, and the output is the result of emotion inference. This step involves emotion classification using natural language processing and image processing libraries.
[0935] Step 5:
[0936] The server automatically classifies security incidents and sets priorities by combining anomaly detection results with the user's emotional state. The inputs for this step are anomaly patterns and emotional states, and the output is a list of classified incidents and their priorities. If the emotional state exceeds a certain threshold, the priority is set higher.
[0937] Step 6:
[0938] The user receives real-time notifications from the server. The input here is a categorized incident and a response based on emotion; the output is a notification message to the user. This includes suggestions tailored to the user's emotional state.
[0939] Step 7:
[0940] The server analyzes historical data to predict future threats. The input for this step is collected and analyzed historical data, and the output is a threat prediction. Time series analysis and predictive modeling techniques are used for the prediction.
[0941] Step 8:
[0942] The server periodically retrains the generated AI model to ensure it can respond to the latest threats. In this step, the input is a new dataset, and the output is the updated AI model. Retraining is performed to improve the model's accuracy and to better respond to new threat patterns.
[0943] The specific processing unit 290 transmits the result of the specific processing to the robot 414. In the robot 414, the control unit 46A causes the speaker 240 and the controlled object 443 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.
[0944] Data generation model 58 is a type of so-called generative AI (Artificial Intelligence). One example of data generation model 58 is ChatGPT (Internet search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[0945] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and the specific processing may also be performed by the robot 414.
[0946] Furthermore, the emotion identification model 59, acting as an emotion engine, may determine the user's emotion according to a specific mapping. Specifically, the emotion identification model 59 may determine the user's emotion according to a specific mapping, which is an emotion map (see Figure 9). Similarly, the emotion identification model 59 may also determine the robot's emotion, and the identification processing unit 290 may perform identification processing using the robot's emotion.
[0947] Figure 9 shows an emotion map 400 in which multiple emotions are mapped. In the emotion map 400, emotions are arranged in concentric circles radiating from the center. The closer to the center of the concentric circles, the more primitive the emotions are located. Further out of the concentric circles, emotions representing states and actions arising from mental states are located. Emotion is a concept that includes feelings and mental states. On the left side of the concentric circles, emotions that are generally generated from reactions occurring in the brain are located. On the right side of the concentric circles, emotions that are generally induced by situational judgment are located. In the upper and lower directions of the concentric circles, emotions that are generally generated from reactions occurring in the brain and induced by situational judgment are located. Also, the upper side of the concentric circles is where "pleasant" emotions are located, and the lower side is where "unpleasant" emotions are located. In this way, in the emotion map 400, multiple emotions are mapped based on the structure in which emotions arise, and emotions that are likely to occur simultaneously are mapped close together.
[0948] These emotions are distributed at the 3 o'clock position on the Emotion Map 400, and usually fluctuate between feelings of security and anxiety. In the right half of the Emotion Map 400, situational awareness takes precedence over internal feelings, resulting in a calm impression.
[0949] The inside of the Emotion Map 400 represents inner thoughts, while the outside represents actions. Therefore, the further you go from the outside of the Emotion Map 400, the more visible (expressed in actions) your emotions become.
[0950] Here, human emotions are based on various balances, such as posture and blood sugar levels. When these balances deviate from the ideal, it results in discomfort, and when they approach the ideal, it results in pleasure. Similarly, in robots, cars, motorcycles, etc., emotions can be created based on various balances, such as posture and battery level. When these balances deviate from the ideal, it results in discomfort, and when they approach the ideal, it results in pleasure. The emotion map can be generated, for example, based on Dr. Mitsuyoshi's emotion map (Research on a system for analyzing brain physiological signals of speech emotion recognition and emotion, Tokushima University, doctoral dissertation: https: / / ci.nii.ac.jp / naid / 500000375379). The left half of the emotion map contains emotions belonging to a region called "response," where sensation is dominant. The right half of the emotion map contains emotions belonging to a region called "situation," where situational awareness is dominant.
[0951] The emotion map defines two emotions that promote learning. One is the emotion around the middle of the negative "repentance" and "reflection" on the situation side. In other words, it is when the robot experiences negative emotions such as "I never want to feel this way again" or "I don't want to be scolded again." The other is the emotion around the positive "desire" on the reaction side. In other words, it is when the robot has positive feelings such as "I want more" or "I want to know more."
[0952] The emotion identification model 59 inputs user input into a pre-trained neural network, obtains emotion values representing each emotion shown in the emotion map 400, and determines the user's emotion. This neural network is pre-trained based on multiple training data sets, which are combinations of user input and emotion values representing each emotion shown in the emotion map 400. Furthermore, this neural network is trained so that emotions located close together have similar values, as shown in the emotion map 900 in Figure 10. Figure 10 shows an example where multiple emotions such as "reassured," "calm," and "confident" have similar emotion values.
[0953] The above description primarily focuses on the functions of the data processing device 12 in relation to this disclosure. However, the system related to this disclosure is not necessarily implemented on a server. The system related to this disclosure may be implemented as a general information processing system. This disclosure may be implemented, for example, as a software program that runs on a personal computer or as an application that runs on a smartphone. The method related to this disclosure may be provided to users in SaaS (Software as a Service) format.
[0954] In the above embodiment, an example was given in which a specific process is performed by a single computer 22. However, the technology of this disclosure is not limited thereto, and a distributed processing of the specific process may be performed by multiple computers, including computer 22. For example, a data generation model 58 may be provided in an external device of the data processing device 12, and the external device may generate data according to the input data.
[0955] In the above embodiment, an example was given in which the specific processing program 56 is stored in the storage 32, but the technology of this disclosure is not limited thereto. For example, the specific processing program 56 may be stored in a portable, computer-readable, non-temporary storage medium such as a USB (Universal Serial Bus) memory. The specific processing program 56 stored in the non-temporary storage medium is installed in the computer 22 of the data processing device 12. The processor 28 executes specific processing according to the specific processing program 56.
[0956] Alternatively, the specific processing program 56 may be stored in a storage device such as a server connected to the data processing device 12 via the network 54, and the specific processing program 56 may be downloaded and installed on the computer 22 in response to a request from the data processing device 12.
[0957] Furthermore, it is not necessary to store the entirety of the specific processing program 56 in a storage device such as a server connected to the data processing device 12 via the network 54, or to store the entirety of the specific processing program 56 in the storage 32; it is acceptable to store only a portion of the specific processing program 56.
[0958] The following types of processors can be used as hardware resources to perform specific processing. Examples of processors include a CPU, a general-purpose processor that functions as a hardware resource to perform specific processing by executing software, i.e., a program. Other examples of processors include dedicated electrical circuits, such as FPGAs (Field-Programmable Gate Arrays), PLDs (Programmable Logic Devices), or ASICs (Application Specific Integrated Circuits), which have circuit configurations specifically designed to perform specific processing. All of these processors have built-in or connected memory, and all of them perform specific processing by using memory.
[0959] The hardware resource that performs a specific process may consist of one of these various processors, or it may consist of a combination of two or more processors of the same or different types (for example, a combination of multiple FPGAs, or a combination of a CPU and an FPGA). Alternatively, the hardware resource that performs a specific process may consist of a single processor.
[0960] Examples of configurations using a single processor include, firstly, a configuration in which one or more CPUs and software are combined to form a single processor, and this processor functions as a hardware resource that performs a specific process. Secondly, there is a configuration using a processor that realizes the functions of the entire system, including multiple hardware resources that perform a specific process, on a single IC chip, as exemplified by SoCs (System-on-a-chip). In this way, a specific process is realized using one or more of the above types of processors as hardware resources.
[0961] Furthermore, the hardware structure of these various processors can more specifically utilize electrical circuits that combine circuit elements such as semiconductor devices. Also, the specific processing described above is merely an example. Therefore, it goes without saying that unnecessary steps can be deleted, new steps added, or the processing order rearranged, as long as it does not deviate from the main purpose.
[0962] The descriptions and illustrations presented above are detailed explanations of the technical aspects of this disclosure and are merely examples of the technical aspects. For example, the above descriptions of the structure, function, operation, and effect are examples of the structure, function, operation, and effect of the technical aspects of this disclosure. Therefore, it goes without saying that you may delete unnecessary parts, add new elements, or replace elements in the descriptions and illustrations presented above, as long as you do not deviate from the essence of the technical aspects of this disclosure. Furthermore, in order to avoid confusion and facilitate understanding of the technical aspects of this disclosure, explanations of common technical knowledge and the like that do not require special explanation to enable the implementation of the technical aspects of this disclosure have been omitted from the descriptions and illustrations presented above.
[0963] All documents, patent applications, and technical standards described herein are incorporated by reference to the same extent as if each individual document, patent application, and technical standard were specifically and individually noted as being incorporated by reference.
[0964] The following is further disclosed regarding the embodiments described above.
[0965] (Claim 1)
[0966] A means of monitoring and collecting network traffic data in real time,
[0967] A means for preprocessing collected data and converting it into a format that can be analyzed by machine learning models,
[0968] A means for running a machine learning model that detects abnormal traffic patterns using preprocessed data,
[0969] A means for automatically classifying and prioritizing security incidents based on detected anomalies,
[0970] A means of automatically performing an initial response to an incident,
[0971] A method for predicting future threats by analyzing past data and current trends,
[0972] A means of regularly retraining AI models to enable them to respond to the latest threats,
[0973] Means for evaluating and protecting the security of a system,
[0974] A system that includes this.
[0975] (Claim 2)
[0976] The system according to claim 1, comprising means for automatically restricting network communications based on detected abnormal traffic patterns.
[0977] (Claim 3)
[0978] The system according to claim 1, comprising means for sending a real-time notification to an administrator when an incident is detected.
[0979] "Example 1"
[0980] (Claim 1)
[0981] A means of monitoring and collecting information transmission path data in real time,
[0982] A means for preprocessing the collected data and converting it into a format that can be analyzed by the computational model,
[0983] A means for executing a computational model that detects abnormal information transmission patterns using preprocessed data,
[0984] A means for automatically classifying and prioritizing protection incidents based on detected anomalies,
[0985] A means of automatically performing an initial response to an incident,
[0986] A means of predicting future threats by analyzing past data and current trends,
[0987] A means of periodically retraining computational models to enable them to respond to the latest threats,
[0988] Means for evaluating and strengthening the protection of information systems,
[0989] A system that includes this.
[0990] (Claim 2)
[0991] The system according to claim 1, comprising means for automatically restricting information communication based on detected abnormal information transmission patterns.
[0992] (Claim 3)
[0993] The system according to claim 1, comprising means for sending a real-time notification to an administrator when an incident is detected.
[0994] "Application Example 1"
[0995] (Claim 1)
[0996] A device for monitoring and collecting network traffic data in real time,
[0997] A device means for preprocessing collected information and converting it into a format that can be analyzed by a machine learning model,
[0998] A device means for executing a machine learning model that detects abnormal communication patterns using preprocessed information,
[0999] A device means that automatically classifies security incidents based on detected anomalies and sets priorities,
[1000] A device means for automatically performing an initial response to an incident,
[1001] A device and means for predicting future threats by analyzing past records and current trends,
[1002] A device and means for periodically retraining artificial intelligence models to enable them to respond to the latest threats,
[1003] Devices and means for evaluating and protecting the defense of a system,
[1004] A device that provides users with detailed information and safety recommendations regarding anomaly detection in communications in real time,
[1005] A system that includes this.
[1006] (Claim 2)
[1007] The system according to claim 1, comprising a device that automatically restricts the communication network based on detected abnormal communication patterns.
[1008] (Claim 3)
[1009] The system according to claim 1, comprising a device that sends a message to an administrator in real time when an incident is detected.
[1010] "Example 2 of combining an emotion engine"
[1011] (Claim 1)
[1012] A device and means for monitoring and collecting network communication data in real time,
[1013] A device means for preprocessing collected data and converting it into a format that can be analyzed by a machine learning algorithm,
[1014] A device means for executing an artificial intelligence model that detects abnormal communication patterns using preprocessed data,
[1015] A device or means for analyzing input data and inferring emotions in order to recognize the user's emotional state,
[1016] A device means for classifying security events and adjusting their priority based on the emotional state of the user that was detected as an anomaly,
[1017] A device that provides the user with information about an event and suggests countermeasures based on their emotional state,
[1018] A device and means for predicting future risks by analyzing past data and current trends,
[1019] A device and means for periodically retraining an artificial intelligence model to enable it to deal with the latest threats,
[1020] Devices and means for evaluating and maintaining the safety of the system,
[1021] A system that includes this.
[1022] (Claim 2)
[1023] The system according to claim 1, comprising a device that automatically restricts network activity based on detected abnormal communication patterns.
[1024] (Claim 3)
[1025] The system according to claim 1, comprising a device that sends a real-time notification to an administrator when an event is detected.
[1026] "Application example 2 when combining with an emotional engine"
[1027] (Claim 1)
[1028] A means of monitoring and collecting network communication data in real time,
[1029] A means for preprocessing collected data and converting it into a format that can be analyzed by machine learning algorithms,
[1030] A means for executing a machine learning algorithm that detects abnormal communication patterns using preprocessed data,
[1031] A means for executing an emotion recognition engine that analyzes user input and audio / video information to infer the user's emotional state,
[1032] A means for automatically classifying security incidents based on detected anomalies and setting priorities while considering user sentiment information,
[1033] A means to automatically perform initial responses to incidents and send emotion-based notifications to users in real time,
[1034] A means of predicting future threats by analyzing past data and current trends,
[1035] A means of regularly retraining artificial intelligence models to enable them to respond to the latest threats,
[1036] Means for evaluating and protecting the security of the system,
[1037] A system that includes this.
[1038] (Claim 2)
[1039] The system according to claim 1, comprising means for automatically restricting network access based on detected abnormal communication patterns and suggesting countermeasures that respond to the user's emotions.
[1040] (Claim 3)
[1041] The system according to claim 1, comprising means for sending a real-time notification to an administrator containing emotion-based information when an incident is detected. [Explanation of Symbols]
[1042] 10, 210, 310, 410 Data Processing Systems 12 Data Processing Devices 14 Smart Devices 214 Smart Glasses 314 Headset-type terminal 414 Robots< / url:> < / url:> < / url:> < / url:>
Claims
1. A device for monitoring and collecting network traffic data in real time, A device means for preprocessing collected information and converting it into a format that can be analyzed by a machine learning model, A device means for executing a machine learning model that detects abnormal communication patterns using preprocessed information, A device means that automatically classifies security incidents based on detected anomalies and sets priorities, A device means for automatically performing an initial response to an incident, A device and means for predicting future threats by analyzing past records and current trends, A device and means for periodically retraining artificial intelligence models to enable them to respond to the latest threats, Devices and means for evaluating and protecting the defense of a system, A device that provides users with detailed information and safety recommendations regarding anomaly detection in communications in real time, A system that includes this.
2. The system according to claim 1, comprising a device that automatically restricts the communication network based on detected abnormal communication patterns.
3. The system according to claim 1, comprising a device that sends a message to an administrator in real time when an incident is detected.
Citation Information
Patent Citations
Persona chatbot control method and system
JP2022180282A