System

The system efficiently collects, analyzes, and simulates security attack methods to rapidly detect vulnerabilities, addressing the challenge of delayed responses in traditional security systems by automating the process and using virtual environments.

JP2026014191APending Publication Date: 2026-01-29SOFTBANK GROUP CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024115188
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-07-18
Publication Date
2026-01-29

AI Technical Summary

Technical Problem

Existing security systems struggle to quickly understand and implement countermeasures against rapidly evolving security attack methods, requiring significant time and effort for information collection and analysis, leading to delayed vulnerability detection and ineffective responses.

Method used

A system that collects information on security attack techniques from reliable sources, analyzes it using natural language processing, automatically generates security test programs, executes these programs in a virtual environment or container, and notifies administrators of evaluation results, enabling rapid and efficient vulnerability assessment.

Benefits of technology

Enables rapid and efficient detection of vulnerabilities by automatically analyzing and simulating security attacks, allowing for timely implementation of countermeasures without affecting the actual system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026014191000001_ABST
    Figure 2026014191000001_ABST
Patent Text Reader

Abstract

A system is provided.SOLUTION: A system comprising: means for collecting information on a security attack technique from a reliable information source; means for analyzing the collected information using a natural language processing technique and extracting a feature of the attack technique; means for automatically generating a security test program based on the extracted feature; means for executing the generated security test program on a target system and evaluating vulnerability; and means for notifying an administrator of an evaluation result.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The technology of the present disclosure relates to a system. [Background technology]

[0002] Patent document 1 discloses a persona chatbot control method performed by at least one processor, the method including the steps of receiving a user utterance, adding the user utterance to a prompt including an instruction sentence related to a description of the chatbot character, encoding the prompt, and inputting the encoded prompt into a language model to generate a chatbot utterance in response to the user utterance. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Publication No. 2022-180282 Summary of the Invention [Problem to be solved by the invention]

[0004] It shows the "problem that the invention aims to solve" and the "means for solving the problem."

[0005] Security attack methods are evolving rapidly, making it difficult to quickly understand countermeasures and apply them to actual systems. In particular, collecting and analyzing information on the latest attack methods and conducting security tests requires a great deal of time and effort. This can lead to vulnerabilities not being discovered and appropriate countermeasures being delayed. An efficient system to solve these problems is needed. [Means for solving the problem]

[0006] The present invention solves the above-mentioned problems by providing a system that includes: means for collecting information on security attack techniques from reliable information sources; means for analyzing the collected information using natural language processing technology and extracting characteristics of the attack techniques; means for automatically generating a security test program based on the extracted characteristics; means for executing the generated security test program on a target system to evaluate vulnerabilities; and means for notifying an administrator of the evaluation results. This system enables rapid and efficient response to the latest security attack techniques, preventing delays in security countermeasures. Furthermore, the test program can be executed using a virtual environment or container, allowing vulnerability assessment to be performed without affecting the actual system. Furthermore, by using security forums, blogs, and academic paper databases as reliable information sources, the system achieves the collection of the latest and most reliable information.

[0007] Understood. Below are definitions of important terms contained in the claims:

[0008] "Reliable information sources" refer to websites, blogs, forums, academic paper databases, etc. that provide accurate and reliable information about security attack methods.

[0009] "Natural language processing technology" is a technology that enables computers to understand and analyze human language, and refers to the technology of processing text data using processes such as tokenization, keyword extraction, and contextual analysis.

[0010] "Attack characteristics" refers to information about how a particular security attack is carried out, what technologies it uses, what vulnerabilities it exploits, etc.

[0011] A "security test program" is a program designed to simulate specific security attack methods and refers to a tool for assessing system vulnerabilities.

[0012] "Virtual environment" refers to a virtualized computer environment that operates independently of the actual system and is used for secure testing and deployment.

[0013] "Container" refers to a packaging method that uses virtualization technology to isolate software execution environments and centrally manage dependencies and settings.

[0014] A "vulnerability" refers to a weakness, flaw, or security deficiency in a system's defenses against external attacks.

[0015] "Test program execution" refers to the process of running an automatically generated security test program on an actual system or in a virtual environment to simulate attack methods.

[0016] "Evaluation results" refers to information including analytical data obtained by executing a test program, a list of discovered vulnerabilities, and proposed security measures based on the data.

[0017] "Means for notifying administrators" refers to mechanisms within the system for communicating assessment results to administrators in real time or periodically, including email, dashboard notifications, alert systems, etc. [Brief explanation of the drawings]

[0018] [Figure 1] 1 is a conceptual diagram showing an example of the configuration of a data processing system according to a first embodiment. [Figure 2] 1 is a conceptual diagram showing an example of main functions of a data processing device and a smart device according to a first embodiment. [Figure 3] FIG. 10 is a conceptual diagram showing an example of the configuration of a data processing system according to a second embodiment. [Figure 4] FIG. 10 is a conceptual diagram showing an example of main functions of a data processing device and smart glasses according to a second embodiment. [Figure 5] FIG. 10 is a conceptual diagram showing an example of the configuration of a data processing system according to a third embodiment. [Figure 6] FIG. 11 is a conceptual diagram showing an example of main functions of a data processing device and a headset-type terminal according to a third embodiment. [Figure 7] FIG. 10 is a conceptual diagram showing an example of the configuration of a data processing system according to a fourth embodiment. [Figure 8] FIG. 10 is a conceptual diagram showing an example of main functions of a data processing device and a robot according to a fourth embodiment. [Figure 9] 1 shows an emotion map onto which multiple emotions are mapped. [Figure 10] 1 shows an emotion map onto which multiple emotions are mapped. [Figure 11] FIG. 3 is a sequence diagram showing a processing flow of the data processing system according to the first embodiment. [Figure 12] FIG. 10 is a sequence diagram showing the flow of processing in the data processing system in Application Example 1. [Figure 13] FIG. 10 is a sequence diagram showing the flow of processing in the data processing system according to the second embodiment when an emotion engine is combined. [Figure 14] FIG. 10 is a sequence diagram showing the flow of processing in the data processing system in Application Example 2 when an emotion engine is combined. DETAILED DESCRIPTION OF THE INVENTION

[0019] An example of an embodiment of a system according to the technology of the present disclosure will be described below with reference to the accompanying drawings.

[0020] First, the terms used in the following description will be explained.

[0021] In the following embodiments, a coded processor (hereinafter simply referred to as a "processor") may be a single arithmetic device or a combination of multiple arithmetic devices. Furthermore, a processor may be a single type of arithmetic device or a combination of multiple types of arithmetic devices. Examples of arithmetic devices include a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), a GPGPU (General-Purpose computing on Graphics Processing Units), and an APU (Accelerated Processing Unit).

[0022] In the following embodiments, a coded RAM (Random Access Memory) is a memory in which information is temporarily stored and is used as a working memory by a processor.

[0023] In the following embodiments, the coded storage is one or more non-volatile storage devices that store various programs, various parameters, etc. Examples of non-volatile storage devices include flash memory (SSD (Solid State Drive)), magnetic disks (e.g., hard disks), and magnetic tapes.

[0024] In the following embodiments, a communication I / F (Interface) with a symbol is an interface including a communication processor, an antenna, etc. The communication I / F controls communication between multiple computers. Examples of communication standards applied to the communication I / F include wireless communication standards including 5G (5th Generation Mobile Communication System), Wi-Fi (registered trademark), Bluetooth (registered trademark), etc.

[0025] In the following embodiments, "A and / or B" is synonymous with "at least one of A and B." In other words, "A and / or B" means that it may be only A, only B, or a combination of A and B. Furthermore, in this specification, the same concept as "A and / or B" is also applied when three or more things are expressed connected by "and / or."

[0026] [First embodiment]

[0027] FIG. 1 shows an example of the configuration of a data processing system 10 according to the first embodiment.

[0028] 1, a data processing system 10 includes a data processing device 12 and a smart device 14. An example of the data processing device 12 is a server.

[0029] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[0030] The smart device 14 includes a computer 36, a reception device 38, an output device 40, a camera 42, and a communication I / F 44. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The reception device 38, the output device 40, and the camera 42 are also connected to the bus 52.

[0031] The reception device 38 includes a touch panel 38A, a microphone 38B, and the like, and receives user input. The touch panel 38A detects contact with an indicator (for example, a pen or a finger) to receive user input by the touch of the indicator. The microphone 38B detects the user's voice to receive user input by voice. The control unit 46A transmits data indicating the user input received by the touch panel 38A and the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the data indicating the user input.

[0032] The output device 40 includes a display 40A and a speaker 40B, and presents data to the user 20 by outputting the data in a form of expression that the user 20 can perceive (for example, audio and / or text). The display 40A displays visible information such as text and images in accordance with instructions from the processor 46. The speaker 40B outputs audio in accordance with instructions from the processor 46. The camera 42 is a compact digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor.

[0033] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 control the exchange of various information between the processor 46 and the processor 28 via the network 54.

[0034] FIG. 2 shows an example of the main functions of the data processing device 12 and the smart device 14.

[0035] 2, in the data processing device 12, a specific process is performed by the processor 28. A specific processing program 56 is stored in the storage 32. The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific process is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[0036] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[0037] In the smart device 14, the processor 46 performs the reception output process. The storage 50 stores a reception output program 60. The reception output program 60 is used in conjunction with the specific processing program 56 by the data processing system 10. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.

[0038] Next, a description will be given of the specific processing performed by the specific processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."

[0039] Understood. Below is the "Form for Carrying Out the Invention" from the patent specification.

[0040] The present invention is a system that collects and analyzes information about security attack methods, and automatically generates and executes security tests based on that information. Specifically, the system is implemented as follows.

[0041] System configuration:

[0042] 1. Information collection module:

[0043] The server collects information about the latest security attack techniques from trusted sources (security forums, blogs, academic paper databases, etc.) and includes a database that stores the collected logs, metadata, and retrieved content.

[0044] 2. Natural Language Processing Module:

[0045] The information collected by the server is analyzed using natural language processing technology. Specifically, it performs tokenization, keyword extraction, and context analysis to extract the characteristics of attack methods, targets, and attack processes.

[0046] 3. Program Generation Module:

[0047] Based on the analyzed information, the server automatically generates a security test program that simulates attack methods, generating source code to reproduce specific attack scenarios.

[0048] 4. Test Execution Module:

[0049] The server-generated security test programs are run in a virtual environment or container, which is designed to prevent the live system from being affected. The results of the test execution are logged and analyzed.

[0050] 5. Notification module:

[0051] The server notifies administrators of test results via email, dashboard notifications, or instant alerts.

[0052] Specific working example:

[0053] Examples of information collected:

[0054] 1. The server accesses a specific security forum and retrieves the page "The latest XSS attack techniques."

[0055] 2. The server saves the contents of this page in a database.

[0056] Examples of information analysis:

[0057] 3. The server analyzes the stored page content using a natural language processing module and extracts features such as "XSS attacks," "JavaScript injection," and "user input fields."

[0058] Example of program generation:

[0059] 4. The server generates a security test program based on "JavaScript injection" to inject malicious scripts into user input fields. <script>alert('XSS');< / script> The code is included in the test program.

[0060] Specific examples of test execution:

[0061] 5. The server deploys the web service to be tested on the virtual environment and runs the generated test program.

[0062] 6. The server records the execution result in a log file, and the result is "The XSS attack was successful, so the user input field is vulnerable."

[0063] Examples of notification of results:

[0064] 7. The server sends an email to the administrator stating, "An XSS attack vulnerability has been detected. Appropriate security measures are required."

[0065] In this way, the present invention provides a system that can automatically collect and analyze the latest security attack methods and run simulations, thereby efficiently detecting vulnerabilities and quickly taking measures.

[0066] The processing flow will be explained below.

[0067] Understood. Below I will explain the program process in concrete steps.

[0068] Step 1:

[0069] The server contacts trusted information sources to gather information about the latest security attacks, sending HTTP requests to retrieve information from security forums, blogs, and academic paper databases.

[0070] Step 2:

[0071] The server stores the collected information in a local database, including article titles, body text, and metadata.

[0072] Step 3:

[0073] The server then begins analyzing the stored information using natural language processing technology. Specifically, it performs tokenization, keyword extraction, and contextual analysis to extract the characteristics of the attack method, the attack target, and the attack process.

[0074] Step 4:

[0075] The server automatically generates a security test program based on the analysis results, which includes source code to reproduce the extracted features.

[0076] Step 5:

[0077] The server starts a virtual environment or container as a test environment and deploys the system to be tested, thereby preparing an environment where tests can be executed without affecting the actual system.

[0078] Step 6:

[0079] Run server-generated security test programs in the virtual environment, for example by injecting malicious script into user input fields to simulate XSS attacks.

[0080] Step 7:

[0081] The server collects and logs the test results, which include whether the attack was successful and details of any vulnerabilities detected.

[0082] Step 8:

[0083] The server analyzes the test results and notifies administrators, including vulnerability details and recommended countermeasures, via email and dashboard notifications.

[0084] This series of steps enables a fast and effective response to the latest security attack methods.

[0085] Example 1

[0086] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."

[0087] In conventional security testing, it was necessary to manually collect information and create and run test programs to respond to the latest attack methods. This required time and effort, making it difficult to quickly respond to the latest threats. It was also difficult to perform vulnerability assessments without affecting the actual system.

[0088] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.

[0089] In this invention, the server includes means for collecting information on security attack techniques from reliable information sources, means for analyzing the collected information using natural language processing technology and extracting characteristics of the attack techniques, means for automatically generating a security test program based on the extracted characteristics, means for executing the generated security test program in a virtual environment or a container, means for recording and evaluating the test execution results in a log, and means for notifying the administrator of the evaluation results by email or dashboard notification. This enables rapid response to the latest security attack techniques and efficient vulnerability assessment.

[0090] A "trusted information source" is a means of providing accurate and reliable information on security attack methods, such as security forums, blogs, and academic paper databases.

[0091] "Natural language processing technology" is an artificial intelligence technology used to analyze text data and extract important keywords and features, and includes processes such as tokenization, keyword extraction, and context analysis.

[0092] A "security test program" is source code used to simulate specific security attack scenarios and evaluate system vulnerabilities.

[0093] A "virtual environment" is an environment constructed by software rather than by physical hardware, and is used to execute test programs.

[0094] A "container" is a technology that provides an individual virtual space within an operating system, enabling application virtualization.

[0095] The "test execution results" are logs and evaluation data obtained when the generated security test program is executed, and include information such as whether the attack was successful or not.

[0096] "Administrator" means a person or organization responsible for monitoring the security status of a system and taking necessary measures.

[0097] "Email and dashboard notifications" are communication methods for promptly conveying test results and evaluation results to administrators.

[0098] This invention is an automatic security test generation system for responding quickly and effectively to the latest security attack methods. This system includes a series of processes that collect information on attack methods from reliable information sources, analyze it using natural language processing technology, generate, execute, and evaluate a security test program based on the results, and notify the administrator of the results.

[0099] Information Collection Module

[0100] The server periodically accesses reliable information sources on the Internet (e.g., security forums, blogs, academic paper databases) to collect information on the latest security attack techniques. The server uses a crawling script to retrieve HTML pages from specified URLs and stores information such as page content, metadata, and timestamps in a database.

[0101] Natural Language Processing Module

[0102] The server analyzes the collected information using Python and natural language processing libraries (e.g., NLTK, spaCy). The analysis process includes tokenization, keyword extraction, and contextual analysis to extract the characteristics of security attack methods, attack targets, and attack processes. For example, features such as "XSS attack," "JavaScript injection," and "user input field" can be extracted from the page content.

[0103] Program Generation Module

[0104] Based on the analysis results, the server automatically generates a security test program to simulate the attack method. Specifically, it generates code in Python or JavaScript to insert a malicious script. For example, based on "JavaScript injection," it generates a test program to insert a malicious script into a user input field.

[0105] Test Execution Module

[0106] The server runs the generated security test program in a virtual environment or container. Docker is mainly used as the virtual environment to prevent the test program from affecting the actual system. The server prepares a Docker image, starts a virtual container, and runs the test program. The test execution results are recorded in a log file, and the success of the attack is evaluated through log analysis.

[0107] Notification Module

[0108] The server notifies the administrator of the test results via email or dashboard notification. For example, it may notify the administrator that an XSS attack vulnerability has been detected. Appropriate security measures are required.

[0109] Specific operation example

[0110] 1. Examples of information collection:

[0111] The server accesses "https: / / www.example-security-forum.com / latest-xss-attacks" to obtain information about new XSS attack techniques.

[0112] The server saves the page content to a database.

[0113] 2. Examples of information analysis:

[0114] The server analyzes the stored page content and extracts features such as "XSS attacks," "JavaScript injection," and "user input fields."

[0115] 3. Example of program generation:

[0116] The server generates a test program based on "JavaScript injection" to inject malicious scripts into user input fields.

[0117] 4. Specific examples of test execution:

[0118] The server deploys the web application to be tested on Docker and runs the generated test program.

[0119] The server records the execution result in a log file and gets the result "The XSS attack was successful and the user input field is vulnerable."

[0120] 5. Examples of notification of results:

[0121] The server will send an email to the administrator informing them that an XSS attack vulnerability has been detected and that appropriate security measures are required.

[0122] Prompt Sentence Examples

[0123] Create a prompt to input to the generative AI model as follows:

[0124] plaintext

[0125] "We are developing a system that collects information on the latest security attack methods and automatically generates security test programs based on that information. This system collects information from reliable sources, analyzes it using natural language processing, and generates a security test program that simulates the attack method. Finally, it runs this program in a virtual environment and notifies the administrator of the results. As a concrete example of how this system works, please tell us the steps for analyzing XSS attack methods and generating a program to test them."

[0126] The flow of the identification process in the first embodiment will be described with reference to FIG.

[0127] System program processing flow

[0128] Step 1: Gather information

[0129] Input: URL list of security information sources

[0130] Output: HTML page content and metadata

[0131] Specific behavior:

[0132] The server regularly contacts trusted information sources such as security forums, blogs, and academic paper databases.

[0133] The server uses a crawling script to retrieve the HTML page from the specified URL.

[0134] The server stores the retrieved page content, metadata, timestamps, etc. in a database.

[0135] Step 2: Information analysis using natural language processing

[0136] Input: HTML page content stored in the database

[0137] Output: Extracted features and information about attack methods

[0138] Specific behavior:

[0139] The server analyzes the stored page content using Python and natural language processing libraries (e.g., NLTK, spaCy).

[0140] The server tokenizes the text and extracts important keywords and context.

[0141] The server identifies the details of the security attack method based on the characteristics obtained through the analysis.

[0142] Step 3: Automatic generation of security test programs

[0143] Input: Analyzed attack method characteristics and information

[0144] Output: Source code of the security test program

[0145] Specific behavior:

[0146] Based on the analysis results, the server designs a test program to simulate attack methods.

[0147] The server uses Python and JavaScript to generate source code that reproduces attack scenarios.

[0148] For example, based on "JavaScript injection," code is generated to inject malicious scripts into user input fields.

[0149] Step 4: Running test programs in a virtual environment

[0150] Input: Generated security test program

[0151] Output: Test execution results and log files

[0152] Specific behavior:

[0153] The server prepares a virtual environment or container such as Docker.

[0154] The server deploys the web application to be tested on the virtual environment.

[0155] The server runs the generated test program in the virtual environment and records the results in a log file.

[0156] Step 5: Evaluate and record test results

[0157] Input: Log file after test execution

[0158] Output: Vulnerability assessment results

[0159] Specific behavior:

[0160] The server analyzes the test result log and evaluates whether the attack was successful.

[0161] The server records the evaluation result, such as "The user input field is vulnerable because the XSS attack was successful."

[0162] Step 6: Notification of evaluation results

[0163] Input: Test evaluation result

[0164] Output: Notification message to administrator

[0165] Specific behavior:

[0166] The server generates a message to notify the administrator of the evaluation result.

[0167] The server will send an email or dashboard notification to the administrator stating that an XSS attack vulnerability has been detected and appropriate security measures are required.

[0168] (Application example 1)

[0169] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."

[0170] Security vulnerabilities in modern information systems are evolving rapidly, especially in websites and systems. Traditional security measures are largely manual, making it difficult to respond quickly. They also require specialized knowledge and are difficult for average users to understand. For this reason, there is a demand for a system that can automatically collect and analyze the latest security attack methods and easily perform vulnerability testing.

[0171] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.

[0172] In this invention, the server includes means for collecting information on security attack methods from reliable information sources, means for analyzing the collected information using natural language processing technology and extracting characteristics of the attack methods, and means for automatically generating a security test program based on the extracted characteristics, thereby enabling users to easily test the vulnerabilities of websites and systems on their smartphones.

[0173] "Reliable information sources" refers to reliable information sources such as security forums, blogs, and academic paper databases.

[0174] "Natural language processing technology" refers to technology that enables computers to understand and analyze human language.

[0175] A "security testing program" refers to automatically generated software code used to assess the vulnerabilities of a system or website.

[0176] "Target System" means a system or website designated for the purpose of running a test program to assess vulnerabilities.

[0177] A "vulnerability" refers to a security flaw or defect that exists in a system or website.

[0178] "Evaluation results" refers to the result information obtained after executing a security test program.

[0179] "Administrator" means a person responsible for monitoring and managing the security of a system or website.

[0180] "Virtual environment" refers to technology that provides virtual machines that operate independently of physical computer hardware.

[0181] "Container" refers to a technology that packages an application and its dependencies and provides a single execution environment.

[0182] A "smartphone" refers to a mobile phone terminal that can connect to the Internet and run various applications.

[0183] The present invention provides a system that automatically detects and evaluates vulnerabilities in response to the latest security attack methods. The following describes in detail the various modules that make up this system and their processing flows.

[0184] System configuration

[0185] 1. Information collection module

[0186] The server collects information about the latest security attacks from security forums, blogs, and academic paper databases, using HTTP requests to retrieve the data.

[0187] 2. Natural Language Processing Module

[0188] The server analyzes the collected information using natural language processing technology (e.g., SpaCy or NLTK). This analysis includes tokenization, keyword extraction, and contextual analysis to extract the characteristics of the attack method, the attack target, and the attack process.

[0189] 3. Program Generation Module

[0190] The server automatically generates a security test program that reproduces the attack scenario based on the analysis results. For example, when a test program for an XSS attack is generated, the contents of the program include: <script>alert('XSS');< / script> It includes codes such as:

[0191] 4. Test Execution Module

[0192] The server runs the generated security test program on the virtual environment or container, and the execution results are logged and evaluated for vulnerabilities.

[0193] 5. Notification Module

[0194] The server notifies administrators of the results of the evaluation via email, dashboard notifications, and immediate alerts.

[0195] Hardware and software used

[0196] Server: Plays a central role in collecting information, analyzing, generating programs, running tests, and sending notifications.

[0197] Natural language processing software: SpaCy, NLTK

[0198] Virtual environment software: virtual machines, containers (e.g., Docker)

[0199] Notification software: SMTP client (e.g., smtplib)

[0200] Specific examples and prompts to input to the generative AI model

[0201] As a concrete example, content can be automatically generated by inputting the following prompt sentence into a generative AI model (e.g., ChatGPT):

[0202] Example prompt sentence:

[0203] Design a smartphone application that automatically collects and analyzes the latest security attack methods, and generates and executes security tests. Specifically, the following functions are required:

[0204] Ability to gather information from security forums and blogs

[0205] A function that uses natural language processing technology to extract characteristics of attack methods

[0206] Ability to generate attack scenarios from extracted information

[0207] Ability to run test programs in a virtual environment

[0208] Ability to notify users of test results

[0209] Also, please implement the following program in Python.

[0210] From the above explanation, the detailed functions of the security system provided by the embodiment of the present invention and the specific implementation method thereof will be clear.

[0211] The flow of the specific processing in the application example 1 will be described with reference to FIG.

[0212] System processing flow

[0213] Step 1:

[0214] The server uses HTTP requests to collect information about the latest security attack techniques from reliable sources such as security forums, blogs, and academic paper databases. This information is stored on the server in raw HTML or text format. The input data is a URL, and the output data is the collected raw data.

[0215] Step 2:

[0216] The server analyzes the collected information using natural language processing technology. Specifically, it uses SpaCy and NLTK to perform tokenization, keyword extraction, and context analysis to extract the characteristics of the attack method. The input data at this stage is the raw data collected in step 1, and the output data is the analyzed characteristics of the attack method.

[0217] Step 3:

[0218] The server automatically generates a security test program based on the attack characteristics extracted in step 2. For example, if an XSS attack is extracted as a characteristic, it generates a security test program based on a specific script code (e.g., <script>alert('XSS');< / script> ) is generated. The input data are the analyzed features, and the output data is the automatically generated test program.

[0219] Step 4:

[0220] The server runs the generated security test program in a virtual environment or container. This virtual environment is built using Docker or similar, and the test program is executed against the specified website or system. The input data is the test program and target URL, and the output data is a log of the execution results.

[0221] Step 5:

[0222] The server analyzes the execution results of the test program and evaluates whether there are any vulnerabilities. Specifically, it checks the contents of the log file and determines whether the attack was successful. The input data is the execution result log, and the output data is the vulnerability evaluation result.

[0223] Step 6:

[0224] The server notifies the administrator of the evaluation results. Notification methods include email, dashboard notification, and immediate alerts. The input data is the evaluation results, and the output data is a notification message.

[0225] Furthermore, an emotion engine that estimates the user's emotion may be combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59 and perform identification processing using the user's emotion.

[0226] Understood. Below is the "Description of the Invention" of the patent specification based on the invention combining the emotion engine.

[0227] The present invention is a system that collects and analyzes information on new security attack methods, and executes security test programs automatically generated based on that information, and further improves the accuracy of security measures by combining it with an emotion engine that recognizes user emotions. Specific embodiments of the present invention are described below.

[0228] System configuration:

[0229] 1. Information collection module:

[0230] The server collects information on the latest security attack methods from security forums, blogs, academic paper databases, etc. This allows for a comprehensive collection of reliable and up-to-date information.

[0231] 2. Natural Language Processing Module:

[0232] The information collected by the server is analyzed using natural language processing technology. Specifically, text data is tokenized, keywords are extracted, and context is analyzed to extract the characteristics of the attack method, the target of the attack, and the attack process.

[0233] 3. Program Generation Module:

[0234] The server automatically generates a security test program based on the analyzed information, which contains the code necessary to reproduce the extracted features and detect system vulnerabilities.

[0235] 4. Test Execution Module:

[0236] The security test program generated by the server is executed in a virtual environment or container. By using a virtual environment or container, tests can be performed without affecting the actual system.

[0237] 5. Emotion Engine Module:

[0238] The server uses an emotion engine to recognize the user's emotions. While the user is operating the system, the emotion engine collects and analyzes data such as the user's facial expressions, tone of voice, and input patterns.

[0239] 6. Result analysis and notification module:

[0240] The server analyzes the test results and emotion recognition results in an integrated manner and notifies administrators via email, dashboard notifications, real-time alerts, and other methods.

[0241] Specific working example:

[0242] Examples of information collection:

[0243] 1. The server accesses a security forum and collects articles on "the latest XSS attack techniques."

[0244] 2. The server stores the collected articles in a database.

[0245] Examples of information analysis:

[0246] 3. The server analyzes the stored articles using natural language processing and extracts features including "XSS attacks," "JavaScript injection," and "user input fields."

[0247] Example of program generation:

[0248] 4. The server generates a security test program based on the extracted features to simulate the insertion of malicious scripts into user input fields. The generated code includes, for example, <script>alert('XSS');< / script> Includes:

[0249] Specific examples of test execution:

[0250] 5. The server starts the virtual environment and deploys the web service under test.

[0251] 6. Run the server-generated test program to simulate an XSS attack within the virtual environment.

[0252] Examples of emotion recognition:

[0253] 7. While the user is using the system, the server uses an emotion engine to collect and analyze the user's emotional data (facial expressions, tone of voice, input patterns, etc.).

[0254] 8. Based on the emotional data collected by the server, the user's reaction to the attack method test results is evaluated.

[0255] Examples of notification of results:

[0256] 9. The server analyzes the vulnerability test results and emotion recognition results in an integrated manner and generates a detailed result such as "A specific input field is vulnerable and the user expressed anxiety."

[0257] 10. The server will send an email to the administrator detailing the results and recommending corrective action.

[0258] In this way, the present invention makes it possible to respond quickly and effectively to the latest security attack methods, and by incorporating user emotions, it becomes possible to further improve the accuracy of security measures.

[0259] The processing flow will be explained below.

[0260] Understood. Below, we will explain in detail each processing step of an embodiment of the invention that combines an emotion engine.

[0261] Step 1:

[0262] The server accesses reliable information sources such as security forums, blogs, and academic paper databases to gather information on the latest security attack techniques. The server sends HTTP requests and stores the retrieved information in a local database.

[0263] Step 2:

[0264] The information collected by the server is analyzed using a natural language processing module. Text data is tokenized, and keywords and contextual analysis are performed to extract the characteristics of attack methods, targets, and attack processes.

[0265] Step 3:

[0266] The server automatically generates a security test program based on the analysis results. The generated program contains code to reproduce the extracted features and evaluate the system's vulnerabilities.

[0267] Step 4:

[0268] The server starts a virtual environment or container as a test environment. The system to be tested is deployed on the virtual environment or container, preparing an environment where tests can be executed without affecting the actual system.

[0269] Step 5:

[0270] Run server-generated security test programs in the virtual environment, for example injecting malicious script into user input fields to simulate XSS attacks.

[0271] Step 6:

[0272] While the user is operating the system, the server uses an emotion engine to recognize the user's emotions. It collects data such as the user's facial expressions, tone of voice, and input patterns in real time and analyzes their emotional state.

[0273] Step 7:

[0274] The server logs the results of the test execution and analyzes them for vulnerabilities and the likelihood of successful attacks, including whether the attack was successful and details of any vulnerabilities detected.

[0275] Step 8:

[0276] The server integrates and analyzes the analysis results of the emotion engine and the test results, evaluating the user's emotions regarding the discovery of the vulnerability (e.g., anxiety, satisfaction, surprise, etc.).

[0277] Step 9:

[0278] The server generates a detailed report for administrators based on the consolidated analysis results, including vulnerability details, attack methods, user emotional reactions, and recommended countermeasures.

[0279] Step 10:

[0280] The server generates reports and notifies administrators via email, dashboard notifications, and instant alerts.

[0281] This series of steps enables rapid and accurate responses to the latest security attack methods, and by combining user emotions, a system is realized that can implement more effective security measures.

[0282] Example 2

[0283] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."

[0284] Conventional security testing systems have difficulty responding quickly to the latest security attack methods, and do not perform vulnerability assessments that take user emotions into consideration. This makes it difficult to implement effective security measures, and it is not possible to fully alleviate user anxiety.

[0285] The identification process by the identification processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means. In this invention, the server includes means for collecting information on security attack methods from reliable information sources, means for analyzing the collected information using natural language processing technology and extracting characteristics of the attack methods, means for automatically generating a security test program based on the extracted characteristics, means for executing the generated security test program on the target system and evaluating vulnerabilities, means for notifying an administrator of the evaluation results, means for recognizing user emotions, and means for analyzing the results based on the recognized emotions. This makes it possible to respond quickly and effectively to the latest security attack methods and implement security measures that take user emotions into consideration.

[0286] A "trusted information source" is a source that provides reliable, up-to-date security-related information, such as security forums, online articles, or public databases.

[0287] "Natural language processing technology" is a technology that tokenizes text data, extracts keywords, and performs context analysis to understand the meaning and intent of text.

[0288] A "security test program" is automatically generated code or script that reproduces attack methods in order to detect system vulnerabilities.

[0289] "Vulnerability assessment" is the process of running generated security test programs to identify and evaluate security weaknesses in a system.

[0290] The "means for recognizing user emotions" refers to a technology or device for collecting data such as the user's facial expressions, tone of voice, and input patterns, and analyzing the user's emotions.

[0291] "Means for notifying the administrator" refers to methods such as email, dashboard notification, and real-time alerts for notifying the administrator of test results and analysis results.

[0292] Understood. Now, here is the patent specification, "Form for Carrying Out the Invention."

[0293] The present invention is a system that collects and analyzes information on the latest security attack methods from reliable information sources, and automatically generates and executes security test programs. Furthermore, it is possible to recognize user emotions and improve the effectiveness of security measures. Detailed embodiments for implementing the present invention are described below.

[0294] System configuration:

[0295] Information gathering module:

[0296] The server periodically collects information about the latest security attack techniques from trusted sources such as security forums, online articles, and public databases using RSS feeds and web scraping techniques.

[0297] Hardware and software used:

[0298] Server: A general server computer (e.g., a Linux server)

[0299] Software: RSS feed readers, web scraping tools, database management systems (e.g., MySQL)

[0300] Examples:

[0301] The server collects articles about "New SQL Injection Attack Techniques" from "Security Blog XYZ" via an RSS feed and stores them in a database.

[0302] Natural Language Processing Module:

[0303] The information collected by the server is analyzed using natural language processing technology. Specifically, the NLTK library and Spacy are used to tokenize text data, extract keywords, and perform contextual analysis to extract the characteristics of attack methods, targets, and attack processes.

[0304] Software used:

[0305] NLTK (Natural Language Toolkit)

[0306] Spacy (natural language processing library)

[0307] Examples:

[0308] The server tokenizes the article from "Security Blog XYZ" and extracts the keywords "SQL injection," "database," and "invalid input."

[0309] Program Generation Module:

[0310] Based on the analysis results, the server automatically generates a security test program using a generative AI model (e.g., OpenAI's GPT series), and provides the extracted features as input prompts.

[0311] Software used:

[0312] Generative AI models (e.g., OpenAI GPT series)

[0313] Examples:

[0314] The server inputs the prompt "Generate a script to simulate an SQL injection attack" into the AI ​​model and generates a test script containing an SQL query such as "SELECT FROM users WHERE user_id = '1' OR '1'='1'".

[0315] Test Execution Module:

[0316] The server runs the generated security test program in a virtual environment or container, allowing vulnerability assessment to be performed without affecting the actual system.

[0317] Hardware and software used:

[0318] Virtual environment (e.g. VirtualBox)

[0319] Container management tools (e.g., Docker)

[0320] Examples:

[0321] The server launches a Docker container, deploys the web application under test, and then runs the generated SQL injection test script to check for vulnerabilities.

[0322] Emotion Recognition Module:

[0323] The server uses an emotion engine to recognize the user's emotions. While the user is operating the system, emotion data is collected in real time through facial expression recognition APIs and voice analysis APIs.

[0324] Software used:

[0325] Facial expression recognition API (e.g. Microsoft Azure Cognitive Services)

[0326] Speech analysis API (e.g. IBM Watson)

[0327] Examples:

[0328] While the user is checking the security test results, the server analyzes the user's webcam footage and detects anxiety or surprise from the user's facial expressions.

[0329] Results Analysis and Notification Module:

[0330] The server analyzes the test results and emotion recognition results in an integrated manner, and generates a detailed report to notify the administrator via email or dashboard notification.

[0331] Software used:

[0332] Email sending system (e.g., SMTP server)

[0333] Dashboard notification systems (e.g. Grafana)

[0334] Examples:

[0335] The server generates a report stating "SQL injection vulnerability detected. User expressed concern about the consequences" and notifies the administrator via email.

[0336] With these configurations, the present invention can respond quickly and effectively to the latest security attack methods, and can implement security measures that take user feelings into consideration.

[0337] Example of an input prompt for a generative AI model:

[0338] Gather information on the latest security attack techniques from the following data sources and analyze the text data using natural language processing techniques.

[0339] Data sources collected: security forums, online articles, public databases

[0340] Analysis targets: SQL injection attacks, JavaScript injection, user input fields

[0341] Based on the analysis results, automatically generate a security test program and run the test in a virtual environment. In addition, recognize the user's emotions (facial expressions, tone of voice, input patterns), comprehensively analyze the results, and notify the administrator.

[0342] The above is the details of the mode for carrying out the invention.

[0343] The flow of the identification process in the second embodiment will be described with reference to FIG.

[0344] Step 1: Gather information

[0345] The server collects information about the latest security attack techniques from trusted sources. Specifically, it uses RSS feed readers and web scraping tools to gather data from security forums, online articles, and public databases. The input to this collection process is the URL of the information source or the RSS feed link, and the output is a database that stores the collected security-related information.

[0346] Specific operation: The server retrieves the article "New SQL Injection Attack Technique" from "Security Blog XYZ" via an RSS feed and saves it in the database.

[0347] Step 2: Natural Language Analysis

[0348] The information collected by the server is analyzed using natural language processing technology. The input is security-related information stored in a database, and the output is characteristic information on attack methods extracted through analysis. Specifically, the NLTK library and Spacy are used to tokenize text data, extract keywords, and perform contextual analysis.

[0349] Specific operation: The server tokenizes the article from "Security Blog XYZ" and extracts keywords such as "SQL injection," "database," and "invalid input."

[0350] Step 3: Generate security test programs

[0351] Based on the analysis results, the server automatically generates a security test program using a generative AI model. The input is the analyzed feature information, and the output is the generated security test program. Specifically, a prompt statement is input into the generative AI model, and the result is used to generate a test script.

[0352] How it works: The server inputs the prompt "Generate a script that simulates an SQL injection attack" into the AI ​​model, and generates a test script containing an SQL query such as "SELECT FROM users WHERE user_id = '1' OR '1'='1'".

[0353] Step 4: Test Run

[0354] The server runs the generated security test program in a virtual environment or container. The input is the generated test program and the system under test, and the output is the test execution results. By using a virtual environment or container, vulnerability assessment can be performed without affecting the actual system.

[0355] Specific operation: The server launches a Docker container, deploys the web application to be tested, and runs the generated test script to check for vulnerabilities.

[0356] Step 5: Emotion Recognition

[0357] The server uses an emotion engine to recognize the user's emotions. The input is data such as the user's facial expressions, tone of voice, and input patterns, and the output is analyzed emotional data of the user. Specifically, it uses facial expression recognition APIs and voice analysis APIs to collect and analyze changes in the user's emotions in real time.

[0358] Specific operation: While the user is checking the system's security test results, the server analyzes the webcam footage using a facial expression recognition API to detect anxiety or surprise from the user's facial expressions.

[0359] Step 6: Results analysis and notification

[0360] The server performs an integrated analysis of the test results and emotion recognition results, and generates a detailed report to notify the administrator. The input is the test execution results and emotion data, and the output is a detailed report. Notification methods include email and dashboard notifications.

[0361] Specific behavior: The server generates a report stating "SQL injection vulnerability detected. User expressed concern about the consequences" and notifies the administrator via email.

[0362] (Application example 2)

[0363] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."

[0364] In recent years, security attack methods have rapidly evolved, and conventional countermeasures are no longer sufficient to deal with them. Furthermore, the emotions felt by users while operating a system are an important factor that cannot be ignored, and there is a need to realize more effective security measures that take this into consideration. However, it is technically difficult to simultaneously address these factors, and currently no suitable system exists.

[0365] The identification process by the identification processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means. In this invention, the server includes means for collecting information on security attack methods from reliable information sources, means for analyzing the collected information using natural language processing technology and extracting characteristics of the attack methods, means for automatically generating a security test program based on the extracted characteristics, means for executing the generated security test program on the target system and evaluating vulnerabilities, means for analyzing a user's facial expressions, voice, and input patterns using emotion analysis technology and collecting user emotion data, and means for comprehensively analyzing the vulnerability assessment results and the emotion data and notifying the administrator. This makes it possible to respond quickly and effectively to the latest security attack methods and obtain feedback based on the user's emotions.

[0366] A "trusted information source" is a source that provides up-to-date and reliable information, such as a security forum or academic paper database.

[0367] "Natural language processing technology" is a technology that analyzes text data and extracts keywords and features based on context.

[0368] A "security test program" is a program that is automatically generated based on analyzed information to detect system vulnerabilities.

[0369] A "virtual environment" is a virtualized environment in which programs can be tested without affecting the actual system.

[0370] A "container" is a technology that packages an application's execution environment into a single package and executes it in a virtually isolated manner.

[0371] "Emotion analysis technology" is a technology that analyzes emotions from a user's facial expressions, voice, and input patterns.

[0372] "User emotion data" refers to information about a user's emotions collected using emotion analysis technology.

[0373] "Vulnerability assessment" is the process of running a generated security test program to assess the vulnerability of a system.

[0374] "Notifying the administrator" refers to the act of reporting the vulnerability assessment results and user emotional data to the administrator and urging them to take appropriate measures.

[0375] The present invention is a system that collects and analyzes the latest information on security attack techniques, executes security test programs automatically generated based on the analysis results, and further recognizes user emotions to improve the accuracy of security countermeasures. Specific embodiments of the present invention are described below.

[0376] System configuration

[0377] Information Collection Module

[0378] The server collects information about security attack methods from reliable sources, such as security forums and academic paper databases, and uses the requests library for its hardware and software.

[0379] Natural Language Processing Module

[0380] The server analyzes the collected information using natural language processing technology to extract characteristics of the attack method. Specifically, it tokenizes the text data and performs keyword extraction and context analysis. The software used is the spacy library.

[0381] Program Generation Module

[0382] The server automatically generates a security test program based on the analyzed information. This program contains code to reproduce the extracted characteristics and detect system vulnerabilities. The code is generated using a text editor.

[0383] Test Execution Module

[0384] The server runs the generated security test program in a virtual environment to evaluate vulnerabilities. By using a virtual environment or container, it is possible to perform testing without affecting the actual system. The hardware used is a virtualizable server, and the software uses Docker or other virtualization tools.

[0385] Emotion Recognition Module

[0386] The device uses emotion analysis technology to analyze the user's facial expressions, voice, and input patterns to collect user emotion data. Data is collected using the camera and microphone and analyzed using the cv2 and emotion_recognition libraries.

[0387] Results Analysis and Notification Module

[0388] The server analyzes the test results and emotion recognition results and notifies administrators. Specifically, it reports the results via email, dashboard notifications, and real-time alerts. The software used is the requests library, which sends data to a web service that notifies users appropriately.

[0389] Specific examples

[0390] For example, the server accesses a security forum to collect articles about the latest XSS attack techniques and stores them in a database. It then uses natural language processing technology to analyze the collected information and extracts features of XSS attacks, JavaScript injection, and user input fields. Based on these features, the server generates a security test program that simulates the injection of a malicious script into a user input field, and runs the test in a virtual environment.

[0391] The device uses a camera and microphone to collect the user's facial expressions and tone of voice while the user is operating the system, and analyzes the emotional data. Finally, the test results and the user's emotional data are analyzed comprehensively, and the system notifies the administrator of the detailed results, stating that "a specific input field was found to be vulnerable and the user expressed anxiety."

[0392] Prompt Sentence Examples

[0393] "Please generate a security test program that includes the latest XSS attack techniques and run it in a virtual environment. Also, please analyze the user's facial expressions and tone of voice, and report any feelings of anxiety or other anxiety the user may have."

[0394] By using the above specific means, the present invention enables quick and effective responses to the latest security attack methods, and also provides feedback based on user emotions, thereby improving the accuracy of security measures.

[0395] The flow of the specific processing in the application example 2 will be described with reference to FIG.

[0396] Step 1:

[0397] The server collects the latest information on security attack techniques from trusted sources, specifically by accessing security forums and academic paper databases to retrieve relevant articles and papers, using the requests library to collect data via an Internet connection.

[0398] Input: URL of a security forum or academic paper database

[0399] Output: Raw data on attack techniques (articles and papers)

[0400] Step 2:

[0401] The information collected by the server is analyzed using natural language processing technology. Specifically, the text data is tokenized using the spacy library, and keywords and contextual analysis are performed to extract the characteristics of attack methods.

[0402] Input: Raw data on attack techniques (articles and papers)

[0403] Output: Characteristics of the analyzed attack method (e.g., "XSS attack," "JavaScript injection," etc.)

[0404] Step 3:

[0405] The server automatically generates a security test program based on the extracted features. Specifically, it uses a programming language to reproduce the features and generate code to detect system vulnerabilities. The code is constructed using a text editor.

[0406] Input: Analyzed attack characteristics

[0407] Output: Security test program code

[0408] Step 4:

[0409] The server runs the generated security test program in a virtual environment. Specifically, a virtual environment is set up using a virtualization tool such as Docker, and the test program is run. This step evaluates the system's vulnerabilities.

[0410] Input: Security test program code

[0411] Output: Vulnerability assessment results

[0412] Step 5:

[0413] The device uses emotion analysis technology to analyze the user's facial expressions, voice, and input patterns to collect emotion data. Specifically, data is collected using the camera and microphone, and analyzed using the cv2 and emotion_recognition libraries.

[0414] Input: facial expression data, voice data, input patterns during user operation

[0415] Output: Analyzed user emotion data

[0416] Step 6:

[0417] The server analyzes the test results and emotion recognition results in an integrated manner and notifies the administrator via email or a web dashboard using the requests library.

[0418] Input: Vulnerability assessment results, analyzed user emotion data

[0419] Output: Notification message to administrator (e.g. "A specific input field is vulnerable and the user expressed concern")

[0420] Through the above steps, the system of the present invention can respond quickly and effectively to the latest security attack methods, and can obtain feedback based on the user's emotions, thereby improving the accuracy of security measures.

[0421] The specific processing unit 290 transmits the result of the specific processing to the smart device 14. In the smart device 14, the control unit 46A causes the output device 40 to output the result of the specific processing. The microphone 38B acquires audio indicating a user input regarding the result of the specific processing. The control unit 46A transmits audio data indicating the user input acquired by the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.

[0422] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[0423] In the above embodiment, an example in which the specific process is performed by the data processing device 12 has been given, but the technology of the present disclosure is not limited to this, and the specific process may be performed by the smart device 14.

[0424] [Second embodiment]

[0425] FIG. 3 shows an example of the configuration of a data processing system 210 according to the second embodiment.

[0426] 3, the data processing system 210 includes the data processing device 12 and smart glasses 214. An example of the data processing device 12 is a server.

[0427] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[0428] The smart glasses 214 include a computer 36, a microphone 238, a speaker 240, a camera 42, and a communication I / F 44. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The microphone 238, the speaker 240, and the camera 42 are also connected to the bus 52.

[0429] The microphone 238 receives instructions and the like from the user 20 by receiving voice uttered by the user 20. The microphone 238 captures the voice uttered by the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio in accordance with instructions from the processor 46.

[0430] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the surroundings of user 20 (for example, an imaging range defined by an angle of view equivalent to the field of vision of a typical healthy person).

[0431] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 are responsible for the exchange of various information between the processor 46 and the processor 28 via the network 54. The exchange of various information between the processor 46 and the processor 28 using the communication I / Fs 44 and 26 is carried out in a secure state.

[0432] Fig. 4 shows an example of the main functions of the data processing device 12 and the smart glasses 214. As shown in Fig. 4, in the data processing device 12, a specific process is performed by the processor 28. A specific process program 56 is stored in the storage 32.

[0433] The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[0434] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[0435] In the smart glasses 214, the reception output process is performed by the processor 46. A reception output program 60 is stored in the storage 50. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.

[0436] Next, a description will be given of the identification process performed by the identification processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as the "server" and the smart glasses 214 will be referred to as the "terminal."

[0437] Understood. Below is the "Form for Carrying Out the Invention" from the patent specification.

[0438] The present invention is a system that collects and analyzes information about security attack methods, and automatically generates and executes security tests based on that information. Specifically, the system is implemented as follows.

[0439] System configuration:

[0440] 1. Information collection module:

[0441] The server collects information about the latest security attack techniques from trusted sources (security forums, blogs, academic paper databases, etc.) and includes a database that stores the collected logs, metadata, and retrieved content.

[0442] 2. Natural Language Processing Module:

[0443] The information collected by the server is analyzed using natural language processing technology. Specifically, it performs tokenization, keyword extraction, and context analysis to extract the characteristics of attack methods, targets, and attack processes.

[0444] 3. Program Generation Module:

[0445] Based on the analyzed information, the server automatically generates a security test program that simulates attack methods, generating source code to reproduce specific attack scenarios.

[0446] 4. Test Execution Module:

[0447] The server-generated security test programs are run in a virtual environment or container, which is designed to prevent the live system from being affected. The results of the test execution are logged and analyzed.

[0448] 5. Notification module:

[0449] The server notifies administrators of test results via email, dashboard notifications, or instant alerts.

[0450] Specific working example:

[0451] Examples of information collected:

[0452] 1. The server accesses a specific security forum and retrieves the page "The latest XSS attack techniques."

[0453] 2. The server saves the contents of this page in a database.

[0454] Examples of information analysis:

[0455] 3. The server analyzes the stored page content using a natural language processing module and extracts features such as "XSS attacks," "JavaScript injection," and "user input fields."

[0456] Example of program generation:

[0457] 4. The server generates a security test program based on "JavaScript injection" to inject malicious scripts into user input fields. <script>alert('XSS');< / script> The code is included in the test program.

[0458] Specific examples of test execution:

[0459] 5. The server deploys the web service to be tested on the virtual environment and runs the generated test program.

[0460] 6. The server records the execution result in a log file, and the result is "The XSS attack was successful, so the user input field is vulnerable."

[0461] Examples of notification of results:

[0462] 7. The server sends an email to the administrator stating, "An XSS attack vulnerability has been detected. Appropriate security measures are required."

[0463] In this way, the present invention provides a system that can automatically collect and analyze the latest security attack methods and run simulations, thereby efficiently detecting vulnerabilities and quickly taking measures.

[0464] The processing flow will be explained below.

[0465] Understood. Below I will explain the program process in concrete steps.

[0466] Step 1:

[0467] The server contacts trusted information sources to gather information about the latest security attacks, sending HTTP requests to retrieve information from security forums, blogs, and academic paper databases.

[0468] Step 2:

[0469] The server stores the collected information in a local database, including article titles, body text, and metadata.

[0470] Step 3:

[0471] The server then begins analyzing the stored information using natural language processing technology. Specifically, it performs tokenization, keyword extraction, and contextual analysis to extract the characteristics of the attack method, the attack target, and the attack process.

[0472] Step 4:

[0473] The server automatically generates a security test program based on the analysis results, which includes source code to reproduce the extracted features.

[0474] Step 5:

[0475] The server starts a virtual environment or container as a test environment and deploys the system to be tested, thereby preparing an environment where tests can be executed without affecting the actual system.

[0476] Step 6:

[0477] Run server-generated security test programs in the virtual environment, for example by injecting malicious script into user input fields to simulate XSS attacks.

[0478] Step 7:

[0479] The server collects and logs the test results, which include whether the attack was successful and details of any vulnerabilities detected.

[0480] Step 8:

[0481] The server analyzes the test results and notifies administrators, including vulnerability details and recommended countermeasures, via email and dashboard notifications.

[0482] This series of steps enables a fast and effective response to the latest security attack methods.

[0483] Example 1

[0484] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."

[0485] In conventional security testing, it was necessary to manually collect information and create and run test programs to respond to the latest attack methods. This required time and effort, making it difficult to quickly respond to the latest threats. It was also difficult to perform vulnerability assessments without affecting the actual system.

[0486] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.

[0487] In this invention, the server includes means for collecting information on security attack techniques from reliable information sources, means for analyzing the collected information using natural language processing technology and extracting characteristics of the attack techniques, means for automatically generating a security test program based on the extracted characteristics, means for executing the generated security test program in a virtual environment or a container, means for recording and evaluating the test execution results in a log, and means for notifying the administrator of the evaluation results by email or dashboard notification. This enables rapid response to the latest security attack techniques and efficient vulnerability assessment.

[0488] A "trusted information source" is a means of providing accurate and reliable information on security attack methods, such as security forums, blogs, and academic paper databases.

[0489] "Natural language processing technology" is an artificial intelligence technology used to analyze text data and extract important keywords and features, and includes processes such as tokenization, keyword extraction, and context analysis.

[0490] A "security test program" is source code used to simulate specific security attack scenarios and evaluate system vulnerabilities.

[0491] A "virtual environment" is an environment constructed by software rather than by physical hardware, and is used to execute test programs.

[0492] A "container" is a technology that provides an individual virtual space within an operating system, enabling application virtualization.

[0493] The "test execution results" are logs and evaluation data obtained when the generated security test program is executed, and include information such as whether the attack was successful or not.

[0494] "Administrator" means a person or organization responsible for monitoring the security status of a system and taking necessary measures.

[0495] "Email and dashboard notifications" are communication methods for promptly conveying test results and evaluation results to administrators.

[0496] This invention is an automatic security test generation system for responding quickly and effectively to the latest security attack methods. This system includes a series of processes that collect information on attack methods from reliable information sources, analyze it using natural language processing technology, generate, execute, and evaluate a security test program based on the results, and notify the administrator of the results.

[0497] Information Collection Module

[0498] The server periodically accesses reliable information sources on the Internet (e.g., security forums, blogs, academic paper databases) to collect information on the latest security attack techniques. The server uses a crawling script to retrieve HTML pages from specified URLs and stores information such as page content, metadata, and timestamps in a database.

[0499] Natural Language Processing Module

[0500] The server analyzes the collected information using Python and natural language processing libraries (e.g., NLTK, spaCy). The analysis process includes tokenization, keyword extraction, and contextual analysis to extract the characteristics of security attack methods, attack targets, and attack processes. For example, features such as "XSS attack," "JavaScript injection," and "user input field" can be extracted from the page content.

[0501] Program Generation Module

[0502] Based on the analysis results, the server automatically generates a security test program to simulate the attack method. Specifically, it generates code in Python or JavaScript to insert a malicious script. For example, based on "JavaScript injection," it generates a test program to insert a malicious script into a user input field.

[0503] Test Execution Module

[0504] The server runs the generated security test program in a virtual environment or container. Docker is mainly used as the virtual environment to prevent the test program from affecting the actual system. The server prepares a Docker image, starts a virtual container, and runs the test program. The test execution results are recorded in a log file, and the success of the attack is evaluated through log analysis.

[0505] Notification Module

[0506] The server notifies the administrator of the test results via email or dashboard notification. For example, it may notify the administrator that an XSS attack vulnerability has been detected. Appropriate security measures are required.

[0507] Specific operation example

[0508] 1. Examples of information collection:

[0509] The server accesses "https: / / www.example-security-forum.com / latest-xss-attacks" to obtain information about new XSS attack techniques.

[0510] The server saves the page content to a database.

[0511] 2. Examples of information analysis:

[0512] The server analyzes the stored page content and extracts features such as "XSS attacks," "JavaScript injection," and "user input fields."

[0513] 3. Example of program generation:

[0514] The server generates a test program based on "JavaScript injection" to inject malicious scripts into user input fields.

[0515] 4. Specific examples of test execution:

[0516] The server deploys the web application to be tested on Docker and runs the generated test program.

[0517] The server records the execution result in a log file and gets the result "The XSS attack was successful and the user input field is vulnerable."

[0518] 5. Examples of notification of results:

[0519] The server will send an email to the administrator informing them that an XSS attack vulnerability has been detected and that appropriate security measures are required.

[0520] Prompt Sentence Examples

[0521] Create a prompt to input to the generative AI model as follows:

[0522] plaintext

[0523] "We are developing a system that collects information on the latest security attack methods and automatically generates security test programs based on that information. This system collects information from reliable sources, analyzes it using natural language processing, and generates a security test program that simulates the attack method. Finally, it runs this program in a virtual environment and notifies the administrator of the results. As a concrete example of how this system works, please tell us the steps for analyzing XSS attack methods and generating a program to test them."

[0524] The flow of the identification process in the first embodiment will be described with reference to FIG.

[0525] System program processing flow

[0526] Step 1: Gather information

[0527] Input: URL list of security information sources

[0528] Output: HTML page content and metadata

[0529] Specific behavior:

[0530] The server regularly contacts trusted information sources such as security forums, blogs, and academic paper databases.

[0531] The server uses a crawling script to retrieve the HTML page from the specified URL.

[0532] The server stores the retrieved page content, metadata, timestamps, etc. in a database.

[0533] Step 2: Information analysis using natural language processing

[0534] Input: HTML page content stored in the database

[0535] Output: Extracted features and information about attack methods

[0536] Specific behavior:

[0537] The server analyzes the stored page content using Python and natural language processing libraries (e.g., NLTK, spaCy).

[0538] The server tokenizes the text and extracts important keywords and context.

[0539] The server identifies the details of the security attack method based on the characteristics obtained through the analysis.

[0540] Step 3: Automatic generation of security test programs

[0541] Input: Analyzed attack method characteristics and information

[0542] Output: Source code of the security test program

[0543] Specific behavior:

[0544] Based on the analysis results, the server designs a test program to simulate attack methods.

[0545] The server uses Python and JavaScript to generate source code that reproduces attack scenarios.

[0546] For example, based on "JavaScript injection," code is generated to inject malicious scripts into user input fields.

[0547] Step 4: Running test programs in a virtual environment

[0548] Input: Generated security test program

[0549] Output: Test execution results and log files

[0550] Specific behavior:

[0551] The server prepares a virtual environment or container such as Docker.

[0552] The server deploys the web application to be tested on the virtual environment.

[0553] The server runs the generated test program in the virtual environment and records the results in a log file.

[0554] Step 5: Evaluate and record test results

[0555] Input: Log file after test execution

[0556] Output: Vulnerability assessment results

[0557] Specific behavior:

[0558] The server analyzes the test result log and evaluates whether the attack was successful.

[0559] The server records the evaluation result, such as "The user input field is vulnerable because the XSS attack was successful."

[0560] Step 6: Notification of evaluation results

[0561] Input: Test evaluation result

[0562] Output: Notification message to administrator

[0563] Specific behavior:

[0564] The server generates a message to notify the administrator of the evaluation result.

[0565] The server will send an email or dashboard notification to the administrator stating that an XSS attack vulnerability has been detected and appropriate security measures are required.

[0566] (Application example 1)

[0567] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."

[0568] Security vulnerabilities in modern information systems are evolving rapidly, especially in websites and systems. Traditional security measures are largely manual, making it difficult to respond quickly. They also require specialized knowledge and are difficult for average users to understand. For this reason, there is a demand for a system that can automatically collect and analyze the latest security attack methods and easily perform vulnerability testing.

[0569] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.

[0570] In this invention, the server includes means for collecting information on security attack methods from reliable information sources, means for analyzing the collected information using natural language processing technology and extracting characteristics of the attack methods, and means for automatically generating a security test program based on the extracted characteristics, thereby enabling users to easily test the vulnerabilities of websites and systems on their smartphones.

[0571] "Reliable information sources" refers to reliable information sources such as security forums, blogs, and academic paper databases.

[0572] "Natural language processing technology" refers to technology that enables computers to understand and analyze human language.

[0573] A "security testing program" refers to automatically generated software code used to assess the vulnerabilities of a system or website.

[0574] "Target System" means a system or website designated for the purpose of running a test program to assess vulnerabilities.

[0575] A "vulnerability" refers to a security flaw or defect that exists in a system or website.

[0576] "Evaluation results" refers to the result information obtained after executing a security test program.

[0577] "Administrator" means a person responsible for monitoring and managing the security of a system or website.

[0578] "Virtual environment" refers to technology that provides virtual machines that operate independently of physical computer hardware.

[0579] "Container" refers to a technology that packages an application and its dependencies and provides a single execution environment.

[0580] A "smartphone" refers to a mobile phone terminal that can connect to the Internet and run various applications.

[0581] The present invention is a system that automatically detects and evaluates vulnerabilities in response to the latest security attack methods. The following describes in detail the various modules that make up this system and their processing flows.

[0582] System configuration

[0583] 1. Information collection module

[0584] The server collects information about the latest security attacks from security forums, blogs, and academic paper databases, using HTTP requests to retrieve the data.

[0585] 2. Natural Language Processing Module

[0586] The server analyzes the collected information using natural language processing technology (e.g., SpaCy or NLTK). This analysis includes tokenization, keyword extraction, and contextual analysis to extract the characteristics of the attack method, the attack target, and the attack process.

[0587] 3. Program Generation Module

[0588] The server automatically generates a security test program that reproduces the attack scenario based on the analysis results. For example, when a test program for an XSS attack is generated, the contents of the program include: <script>alert('XSS');< / script> It includes codes such as:

[0589] 4. Test Execution Module

[0590] The server runs the generated security test program on the virtual environment or container, logs the execution results, and evaluates whether there are any vulnerabilities.

[0591] 5. Notification Module

[0592] The server notifies administrators of the results of the evaluation via email, dashboard notifications, and immediate alerts.

[0593] Hardware and software used

[0594] Server: Plays a central role in collecting information, analyzing, generating programs, running tests, and sending notifications.

[0595] Natural language processing software: SpaCy, NLTK

[0596] Virtual environment software: virtual machines, containers (e.g., Docker)

[0597] Notification software: SMTP client (e.g., smtplib)

[0598] Specific examples and prompts to input to the generative AI model

[0599] As a concrete example, content can be automatically generated by inputting the following prompt sentence into a generative AI model (e.g., ChatGPT):

[0600] Example prompt sentence:

[0601] Design a smartphone application that automatically collects and analyzes the latest security attack methods, and generates and executes security tests. Specifically, the following functions are required:

[0602] Ability to gather information from security forums and blogs

[0603] A function that uses natural language processing technology to extract characteristics of attack methods

[0604] Ability to generate attack scenarios from extracted information

[0605] Ability to run test programs in a virtual environment

[0606] Ability to notify users of test results

[0607] Also, please implement the following program in Python.

[0608] From the above explanation, the detailed functions of the security system provided by the embodiment of the present invention and the specific implementation method thereof will be clear.

[0609] The flow of the specific processing in the application example 1 will be described with reference to FIG.

[0610] System processing flow

[0611] Step 1:

[0612] The server uses HTTP requests to collect information about the latest security attack techniques from reliable sources such as security forums, blogs, and academic paper databases. This information is stored on the server in raw HTML or text format. The input data is a URL, and the output data is the collected raw data.

[0613] Step 2:

[0614] The server analyzes the collected information using natural language processing technology. Specifically, it uses SpaCy and NLTK to perform tokenization, keyword extraction, and context analysis to extract the characteristics of the attack method. The input data at this stage is the raw data collected in step 1, and the output data is the analyzed characteristics of the attack method.

[0615] Step 3:

[0616] The server automatically generates a security test program based on the attack characteristics extracted in step 2. For example, if an XSS attack is extracted as a characteristic, it generates a security test program based on a specific script code (e.g., <script>alert('XSS');< / script> ) is generated. The input data are the analyzed features, and the output data is the automatically generated test program.

[0617] Step 4:

[0618] The server runs the generated security test program in a virtual environment or container. This virtual environment is built using Docker or similar, and the test program is executed against the specified website or system. The input data is the test program and target URL, and the output data is a log of the execution results.

[0619] Step 5:

[0620] The server analyzes the execution results of the test program and evaluates whether there are any vulnerabilities. Specifically, it checks the contents of the log file and determines whether the attack was successful. The input data is the execution result log, and the output data is the vulnerability evaluation result.

[0621] Step 6:

[0622] The server notifies the administrator of the evaluation results. Notification methods include email, dashboard notification, and immediate alerts. The input data is the evaluation results, and the output data is a notification message.

[0623] Furthermore, an emotion engine that estimates the user's emotion may be further combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59, and perform identification processing using the user's emotion.

[0624] Understood. Below is the "Description of the Invention" of the patent specification based on the invention combining the emotion engine.

[0625] The present invention is a system that collects and analyzes information on new security attack methods, and executes security test programs automatically generated based on that information, and further improves the accuracy of security measures by combining it with an emotion engine that recognizes user emotions. Specific embodiments of the present invention are described below.

[0626] System configuration:

[0627] 1. Information collection module:

[0628] The server collects information on the latest security attack methods from security forums, blogs, academic paper databases, etc. This allows for a comprehensive collection of reliable and up-to-date information.

[0629] 2. Natural Language Processing Module:

[0630] The information collected by the server is analyzed using natural language processing technology. Specifically, text data is tokenized, keywords are extracted, and context is analyzed to extract the characteristics of the attack method, the target of the attack, and the attack process.

[0631] 3. Program Generation Module:

[0632] The server automatically generates a security test program based on the analyzed information, which contains the code necessary to reproduce the extracted features and detect system vulnerabilities.

[0633] 4. Test Execution Module:

[0634] The security test program generated by the server is executed in a virtual environment or container. By using a virtual environment or container, tests can be performed without affecting the actual system.

[0635] 5. Emotion Engine Module:

[0636] The server uses an emotion engine to recognize the user's emotions. While the user is operating the system, the emotion engine collects and analyzes data such as the user's facial expressions, tone of voice, and input patterns.

[0637] 6. Result analysis and notification module:

[0638] The server analyzes the test results and emotion recognition results in an integrated manner and notifies administrators via email, dashboard notifications, real-time alerts, and other methods.

[0639] Specific working example:

[0640] Examples of information collected:

[0641] 1. The server accesses a security forum and collects articles on "the latest XSS attack techniques."

[0642] 2. The server stores the collected articles in a database.

[0643] Examples of information analysis:

[0644] 3. The server analyzes the stored articles using natural language processing and extracts features including "XSS attacks," "JavaScript injection," and "user input fields."

[0645] Example of program generation:

[0646] 4. The server generates a security test program based on the extracted features to simulate the insertion of malicious scripts into user input fields. The generated code includes, for example, <script>alert('XSS');< / script> Includes:

[0647] Specific examples of test execution:

[0648] 5. The server starts the virtual environment and deploys the web service under test.

[0649] 6. Run the server-generated test program to simulate an XSS attack within the virtual environment.

[0650] Examples of emotion recognition:

[0651] 7. While the user is using the system, the server uses an emotion engine to collect and analyze the user's emotional data (facial expressions, tone of voice, input patterns, etc.).

[0652] 8. Based on the emotional data collected by the server, the user's reaction to the attack method test results is evaluated.

[0653] Examples of notification of results:

[0654] 9. The server analyzes the vulnerability test results and emotion recognition results in an integrated manner and generates a detailed result such as "A specific input field is vulnerable and the user expressed anxiety."

[0655] 10. The server will send an email to the administrator detailing the results and recommending corrective action.

[0656] In this way, the present invention makes it possible to respond quickly and effectively to the latest security attack methods, and by incorporating user emotions, it becomes possible to further improve the accuracy of security measures.

[0657] The processing flow will be explained below.

[0658] Understood. Below, we will explain in detail each processing step of an embodiment of the invention that combines an emotion engine.

[0659] Step 1:

[0660] The server accesses reliable information sources such as security forums, blogs, and academic paper databases to gather information on the latest security attack techniques. The server sends HTTP requests and stores the retrieved information in a local database.

[0661] Step 2:

[0662] The information collected by the server is analyzed using a natural language processing module. Text data is tokenized, and keywords and contextual analysis are performed to extract the characteristics of attack methods, targets, and attack processes.

[0663] Step 3:

[0664] The server automatically generates a security test program based on the analysis results. The generated program contains code to reproduce the extracted features and evaluate the system's vulnerabilities.

[0665] Step 4:

[0666] The server starts a virtual environment or container as a test environment. The system to be tested is deployed on the virtual environment or container, preparing an environment where tests can be executed without affecting the actual system.

[0667] Step 5:

[0668] Run server-generated security test programs in the virtual environment, for example injecting malicious script into user input fields to simulate XSS attacks.

[0669] Step 6:

[0670] While the user is operating the system, the server uses an emotion engine to recognize the user's emotions. It collects data such as the user's facial expressions, tone of voice, and input patterns in real time and analyzes their emotional state.

[0671] Step 7:

[0672] The server logs the results of the test execution and analyzes them for vulnerabilities and the likelihood of successful attacks, including whether the attack was successful and details of any vulnerabilities detected.

[0673] Step 8:

[0674] The server integrates and analyzes the analysis results of the emotion engine and the test results, evaluating the user's emotions regarding the discovery of the vulnerability (e.g., anxiety, satisfaction, surprise, etc.).

[0675] Step 9:

[0676] The server generates a detailed report for administrators based on the consolidated analysis results, including vulnerability details, attack methods, user emotional reactions, and recommended countermeasures.

[0677] Step 10:

[0678] The server generates reports and notifies administrators via email, dashboard notifications, and instant alerts.

[0679] This series of steps enables rapid and accurate responses to the latest security attack methods, and by combining user emotions, a system is realized that can implement more effective security measures.

[0680] Example 2

[0681] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."

[0682] Conventional security testing systems have difficulty responding quickly to the latest security attack methods, and do not perform vulnerability assessments that take user emotions into consideration. This makes it difficult to implement effective security measures, and it is not possible to fully alleviate user anxiety.

[0683] The identification process by the identification processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means. In this invention, the server includes means for collecting information on security attack methods from reliable information sources, means for analyzing the collected information using natural language processing technology and extracting characteristics of the attack methods, means for automatically generating a security test program based on the extracted characteristics, means for executing the generated security test program on the target system and evaluating vulnerabilities, means for notifying an administrator of the evaluation results, means for recognizing user emotions, and means for analyzing the results based on the recognized emotions. This makes it possible to respond quickly and effectively to the latest security attack methods and implement security measures that take user emotions into consideration.

[0684] A "trusted information source" is a source that provides reliable, up-to-date security-related information, such as security forums, online articles, or public databases.

[0685] "Natural language processing technology" is a technology that tokenizes text data, extracts keywords, and performs context analysis to understand the meaning and intent of text.

[0686] A "security test program" is automatically generated code or script that reproduces attack methods in order to detect system vulnerabilities.

[0687] "Vulnerability assessment" is the process of running generated security test programs to identify and evaluate security weaknesses in a system.

[0688] The "means for recognizing user emotions" refers to a technology or device for collecting data such as the user's facial expressions, tone of voice, and input patterns, and analyzing the user's emotions.

[0689] "Means for notifying the administrator" refers to methods such as email, dashboard notification, and real-time alerts for notifying the administrator of test results and analysis results.

[0690] Understood. Now, here is the patent specification, "Form for Carrying Out the Invention."

[0691] The present invention is a system that collects and analyzes information on the latest security attack methods from reliable information sources, and automatically generates and executes security test programs. Furthermore, it is possible to recognize user emotions and improve the effectiveness of security measures. Detailed embodiments for implementing the present invention are described below.

[0692] System configuration:

[0693] Information gathering module:

[0694] The server periodically collects information about the latest security attack techniques from trusted sources such as security forums, online articles, and public databases using RSS feeds and web scraping techniques.

[0695] Hardware and software used:

[0696] Server: A general server computer (e.g., a Linux server)

[0697] Software: RSS feed readers, web scraping tools, database management systems (e.g., MySQL)

[0698] Examples:

[0699] The server collects articles about "New SQL Injection Attack Techniques" from "Security Blog XYZ" via an RSS feed and stores them in a database.

[0700] Natural Language Processing Module:

[0701] The information collected by the server is analyzed using natural language processing technology. Specifically, the NLTK library and Spacy are used to tokenize text data, extract keywords, and perform contextual analysis to extract the characteristics of attack methods, targets, and attack processes.

[0702] Software used:

[0703] NLTK (Natural Language Toolkit)

[0704] Spacy (natural language processing library)

[0705] Examples:

[0706] The server tokenizes the article from "Security Blog XYZ" and extracts the keywords "SQL injection," "database," and "invalid input."

[0707] Program Generation Module:

[0708] Based on the analysis results, the server automatically generates a security test program using a generative AI model (e.g., OpenAI's GPT series), and provides the extracted features as input prompts.

[0709] Software used:

[0710] Generative AI models (e.g., OpenAI GPT series)

[0711] Examples:

[0712] The server inputs the prompt "Generate a script to simulate an SQL injection attack" into the AI ​​model and generates a test script containing an SQL query such as "SELECT FROM users WHERE user_id = '1' OR '1'='1'".

[0713] Test Execution Module:

[0714] The server runs the generated security test program in a virtual environment or container, allowing vulnerability assessment to be performed without affecting the actual system.

[0715] Hardware and software used:

[0716] Virtual environment (e.g. VirtualBox)

[0717] Container management tools (e.g., Docker)

[0718] Examples:

[0719] The server launches a Docker container, deploys the web application under test, and then runs the generated SQL injection test script to check for vulnerabilities.

[0720] Emotion Recognition Module:

[0721] The server uses an emotion engine to recognize the user's emotions. While the user is operating the system, emotion data is collected in real time through facial expression recognition APIs and voice analysis APIs.

[0722] Software used:

[0723] Facial expression recognition API (e.g. Microsoft Azure Cognitive Services)

[0724] Speech analysis API (e.g. IBM Watson)

[0725] Examples:

[0726] While the user is checking the security test results, the server analyzes the user's webcam footage and detects anxiety or surprise from the user's facial expressions.

[0727] Results Analysis and Notification Module:

[0728] The server analyzes the test results and emotion recognition results in an integrated manner, and generates a detailed report to notify the administrator via email or dashboard notification.

[0729] Software used:

[0730] Email sending system (e.g., SMTP server)

[0731] Dashboard notification systems (e.g. Grafana)

[0732] Examples:

[0733] The server generates a report stating "SQL injection vulnerability detected. User expressed concern about the consequences" and notifies the administrator via email.

[0734] With these configurations, the present invention can respond quickly and effectively to the latest security attack methods, and can implement security measures that take user feelings into consideration.

[0735] Example of an input prompt for a generative AI model:

[0736] Gather information on the latest security attack techniques from the following data sources and analyze the text data using natural language processing techniques.

[0737] Data sources collected: security forums, online articles, public databases

[0738] Analysis targets: SQL injection attacks, JavaScript injection, user input fields

[0739] Based on the analysis results, automatically generate a security test program and run the test in a virtual environment. Furthermore, recognize the user's emotions (facial expressions, tone of voice, input patterns), comprehensively analyze the results, and notify the administrator.

[0740] The above is a detailed description of the mode for carrying out the invention.

[0741] The flow of the identification process in the second embodiment will be described with reference to FIG.

[0742] Step 1: Gather information

[0743] The server collects information about the latest security attack techniques from trusted sources. Specifically, it uses RSS feed readers and web scraping tools to gather data from security forums, online articles, and public databases. The input to this collection process is the URL of the information source or the RSS feed link, and the output is a database that stores the collected security-related information.

[0744] Specific operation: The server retrieves the article "New SQL Injection Attack Technique" from "Security Blog XYZ" via an RSS feed and saves it in the database.

[0745] Step 2: Natural Language Analysis

[0746] The information collected by the server is analyzed using natural language processing technology. The input is security-related information stored in a database, and the output is characteristic information on attack methods extracted through analysis. Specifically, the NLTK library and Spacy are used to tokenize text data, extract keywords, and perform contextual analysis.

[0747] Specific operation: The server tokenizes the article from "Security Blog XYZ" and extracts keywords such as "SQL injection," "database," and "invalid input."

[0748] Step 3: Generate security test programs

[0749] Based on the analysis results, the server automatically generates a security test program using a generative AI model. The input is the analyzed feature information, and the output is the generated security test program. Specifically, a prompt statement is input into the generative AI model, and the result is used to generate a test script.

[0750] How it works: The server inputs the prompt "Generate a script that simulates an SQL injection attack" into the AI ​​model, and generates a test script containing an SQL query such as "SELECT FROM users WHERE user_id = '1' OR '1'='1'".

[0751] Step 4: Test Run

[0752] The server runs the generated security test program in a virtual environment or container. The input is the generated test program and the system under test, and the output is the test execution results. By using a virtual environment or container, vulnerability assessment can be performed without affecting the actual system.

[0753] Specific operation: The server launches a Docker container, deploys the web application to be tested, and runs the generated test script to check for vulnerabilities.

[0754] Step 5: Emotion Recognition

[0755] The server uses an emotion engine to recognize the user's emotions. The input is data such as the user's facial expressions, tone of voice, and input patterns, and the output is analyzed emotional data of the user. Specifically, it uses facial expression recognition APIs and voice analysis APIs to collect and analyze changes in the user's emotions in real time.

[0756] Specific operation: While the user is checking the system's security test results, the server analyzes the webcam footage using a facial expression recognition API to detect anxiety or surprise from the user's facial expressions.

[0757] Step 6: Results analysis and notification

[0758] The server performs an integrated analysis of the test results and emotion recognition results, and generates a detailed report to notify the administrator. The input is the test execution results and emotion data, and the output is a detailed report. Notification methods include email and dashboard notifications.

[0759] Specific behavior: The server generates a report stating "SQL injection vulnerability detected. User expressed concern about the consequences" and notifies the administrator via email.

[0760] (Application example 2)

[0761] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."

[0762] In recent years, security attack methods have rapidly evolved, and conventional countermeasures are no longer sufficient to deal with them. Furthermore, the emotions felt by users while operating a system are an important factor that cannot be ignored, and there is a need to implement more effective security measures that take this into consideration. However, it is technically difficult to simultaneously address these factors, and currently no suitable system exists.

[0763] The identification process by the identification processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means. In this invention, the server includes means for collecting information on security attack methods from reliable information sources, means for analyzing the collected information using natural language processing technology and extracting characteristics of the attack methods, means for automatically generating a security test program based on the extracted characteristics, means for executing the generated security test program on the target system and evaluating vulnerabilities, means for analyzing a user's facial expressions, voice, and input patterns using emotion analysis technology and collecting user emotion data, and means for comprehensively analyzing the vulnerability assessment results and the emotion data and notifying the administrator. This makes it possible to respond quickly and effectively to the latest security attack methods and obtain feedback based on the user's emotions.

[0764] A "trusted information source" is a source that provides up-to-date and reliable information, such as a security forum or academic paper database.

[0765] "Natural language processing technology" is a technology that analyzes text data and extracts keywords and features based on context.

[0766] A "security test program" is a program that is automatically generated based on analyzed information to detect system vulnerabilities.

[0767] A "virtual environment" is a virtualized environment in which programs can be tested without affecting the actual system.

[0768] A "container" is a technology that packages an application's execution environment into a single package and executes it in a virtually isolated manner.

[0769] "Emotion analysis technology" is a technology that analyzes emotions from a user's facial expressions, voice, and input patterns.

[0770] "User emotion data" refers to information about a user's emotions collected using emotion analysis technology.

[0771] "Vulnerability assessment" is the process of running a generated security test program to assess the vulnerability of a system.

[0772] "Notifying the administrator" refers to the act of reporting the vulnerability assessment results and user emotional data to the administrator and urging them to take appropriate measures.

[0773] The present invention is a system that collects and analyzes the latest information on security attack techniques, executes security test programs automatically generated based on the analysis results, and further recognizes user emotions to improve the accuracy of security countermeasures. Specific embodiments of the present invention are described below.

[0774] System configuration

[0775] Information Collection Module

[0776] The server collects information about security attack methods from reliable sources, such as security forums and academic paper databases, and uses the requests library for its hardware and software.

[0777] Natural Language Processing Module

[0778] The server analyzes the collected information using natural language processing technology to extract characteristics of the attack method. Specifically, it tokenizes the text data and performs keyword extraction and context analysis. The software used is the spacy library.

[0779] Program Generation Module

[0780] The server automatically generates a security test program based on the analyzed information. This program contains code to reproduce the extracted characteristics and detect system vulnerabilities. The code is generated using a text editor.

[0781] Test Execution Module

[0782] The server runs the generated security test program in a virtual environment to evaluate vulnerabilities. By using a virtual environment or container, it is possible to perform testing without affecting the actual system. The hardware used is a virtualizable server, and the software uses Docker or other virtualization tools.

[0783] Emotion Recognition Module

[0784] The device uses emotion analysis technology to analyze the user's facial expressions, voice, and input patterns to collect user emotion data. Data is collected using the camera and microphone and analyzed using the cv2 and emotion_recognition libraries.

[0785] Results Analysis and Notification Module

[0786] The server analyzes the test results and emotion recognition results and notifies administrators. Specifically, it reports the results via email, dashboard notifications, and real-time alerts. The software used is the requests library, which sends data to a web service that notifies users appropriately.

[0787] Specific examples

[0788] For example, the server accesses a security forum to collect articles about the latest XSS attack techniques and stores them in a database. It then uses natural language processing technology to analyze the collected information and extracts features of XSS attacks, JavaScript injection, and user input fields. Based on these features, the server generates a security test program that simulates the injection of a malicious script into a user input field, and runs the test in a virtual environment.

[0789] The device uses a camera and microphone to collect the user's facial expressions and tone of voice while the user is operating the system, and analyzes the emotional data. Finally, the test results and the user's emotional data are analyzed comprehensively, and the system notifies the administrator of the detailed results, stating that "a specific input field was found to be vulnerable and the user expressed anxiety."

[0790] Prompt Sentence Examples

[0791] "Please generate a security test program that includes the latest XSS attack techniques and run it in a virtual environment. Also, please analyze the user's facial expressions and tone of voice, and report any feelings of anxiety or other anxiety felt by the user."

[0792] By using the above specific means, the present invention enables quick and effective responses to the latest security attack methods, and also provides feedback based on user emotions, thereby improving the accuracy of security measures.

[0793] The flow of the specific processing in the application example 2 will be described with reference to FIG.

[0794] Step 1:

[0795] The server collects the latest information on security attack techniques from trusted sources, specifically by accessing security forums and academic paper databases to retrieve relevant articles and papers, using the requests library to collect data via an Internet connection.

[0796] Input: URL of a security forum or academic paper database

[0797] Output: Raw data on attack techniques (articles and papers)

[0798] Step 2:

[0799] The information collected by the server is analyzed using natural language processing technology. Specifically, the text data is tokenized using the spacy library, and keywords and contextual analysis are performed to extract the characteristics of attack methods.

[0800] Input: Raw data on attack techniques (articles and papers)

[0801] Output: Characteristics of the analyzed attack method (e.g., "XSS attack," "JavaScript injection," etc.)

[0802] Step 3:

[0803] The server automatically generates a security test program based on the extracted features. Specifically, it uses a programming language to reproduce the features and generates code to detect system vulnerabilities. The code is constructed using a text editor.

[0804] Input: Analyzed attack characteristics

[0805] Output: Security test program code

[0806] Step 4:

[0807] The server runs the generated security test program in a virtual environment. Specifically, a virtual environment is set up using a virtualization tool such as Docker, and the test program is run. This step evaluates the system's vulnerabilities.

[0808] Input: Security test program code

[0809] Output: Vulnerability assessment results

[0810] Step 5:

[0811] The device uses emotion analysis technology to analyze the user's facial expressions, voice, and input patterns to collect emotion data. Specifically, data is collected using the camera and microphone, and analyzed using the cv2 and emotion_recognition libraries.

[0812] Input: facial expression data, voice data, input patterns during user operation

[0813] Output: Analyzed user emotion data

[0814] Step 6:

[0815] The server analyzes the test results and emotion recognition results in an integrated manner and notifies the administrator via email or a web dashboard using the requests library.

[0816] Input: Vulnerability assessment results, analyzed user emotion data

[0817] Output: Notification message to administrator (e.g. "A specific input field is vulnerable and the user expressed concern")

[0818] Through the above steps, the system of the present invention can respond quickly and effectively to the latest security attack methods, and can obtain feedback based on the user's emotions, thereby improving the accuracy of security measures.

[0819] The specific processing unit 290 transmits the result of the specific processing to the smart glasses 214. In the smart glasses 214, the control unit 46A causes the speaker 240 to output the result of the specific processing. The microphone 238 acquires audio indicating a user input regarding the result of the specific processing. The control unit 46A transmits audio data indicating the user input acquired by the microphone 238 to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.

[0820] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[0821] In the above embodiment, an example in which the specific processing is performed by the data processing device 12 has been given, but the technology of the present disclosure is not limited to this, and the specific processing may be performed by the smart glasses 214.

[0822] [Third embodiment]

[0823] FIG. 5 shows an example of the configuration of a data processing system 310 according to the third embodiment.

[0824] 5, the data processing system 310 includes the data processing device 12 and a headset type terminal 314. An example of the data processing device 12 is a server.

[0825] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[0826] The headset type terminal 314 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication I / F 44, and a display 343. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The microphone 238, the speaker 240, the camera 42, and the display 343 are also connected to the bus 52.

[0827] The microphone 238 receives instructions and the like from the user 20 by receiving voice uttered by the user 20. The microphone 238 captures the voice uttered by the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio in accordance with instructions from the processor 46.

[0828] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the surroundings of user 20 (for example, an imaging range defined by an angle of view equivalent to the field of vision of a typical healthy person).

[0829] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 are responsible for the exchange of various information between the processor 46 and the processor 28 via the network 54. The exchange of various information between the processor 46 and the processor 28 using the communication I / Fs 44 and 26 is carried out in a secure state.

[0830] Fig. 6 shows an example of the main functions of the data processing device 12 and the headset type terminal 314. As shown in Fig. 6, in the data processing device 12, a specific process is performed by the processor 28. A specific process program 56 is stored in the storage 32.

[0831] The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[0832] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[0833] In the headset type terminal 314, a reception output process is performed by the processor 46. A reception output program 60 is stored in the storage 50. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.

[0834] Next, a description will be given of the identification process performed by the identification processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as the "server" and the headset type terminal 314 will be referred to as the "terminal."

[0835] Understood. Below is the "Form for Carrying Out the Invention" from the patent specification.

[0836] The present invention is a system that collects and analyzes information about security attack methods, and automatically generates and executes security tests based on that information. Specifically, the system is implemented as follows.

[0837] System configuration:

[0838] 1. Information collection module:

[0839] The server collects information about the latest security attack techniques from trusted sources (security forums, blogs, academic paper databases, etc.) and includes a database that stores the collected logs, metadata, and retrieved content.

[0840] 2. Natural Language Processing Module:

[0841] The information collected by the server is analyzed using natural language processing technology. Specifically, it performs tokenization, keyword extraction, and context analysis to extract the characteristics of attack methods, targets, and attack processes.

[0842] 3. Program Generation Module:

[0843] Based on the analyzed information, the server automatically generates a security test program that simulates attack methods, generating source code to reproduce specific attack scenarios.

[0844] 4. Test Execution Module:

[0845] The server-generated security test programs are run in a virtual environment or container, which is designed to prevent the live system from being affected. The results of the test execution are logged and analyzed.

[0846] 5. Notification module:

[0847] The server notifies administrators of test results via email, dashboard notifications, or instant alerts.

[0848] Specific working example:

[0849] Examples of information collection:

[0850] 1. The server accesses a specific security forum and retrieves the page "The latest XSS attack techniques."

[0851] 2. The server saves the contents of this page in a database.

[0852] Examples of information analysis:

[0853] 3. The server analyzes the stored page content using a natural language processing module and extracts features such as "XSS attacks," "JavaScript injection," and "user input fields."

[0854] Example of program generation:

[0855] 4. The server generates a security test program based on "JavaScript injection" to inject malicious scripts into user input fields. <script>alert('XSS');< / script> The code is included in the test program.

[0856] Specific examples of test execution:

[0857] 5. The server deploys the web service to be tested on the virtual environment and runs the generated test program.

[0858] 6. The server records the execution result in a log file, and the result is "The XSS attack was successful, so the user input field is vulnerable."

[0859] Examples of notification of results:

[0860] 7. The server sends an email to the administrator stating, "An XSS attack vulnerability has been detected. Appropriate security measures are required."

[0861] In this way, the present invention provides a system that can automatically collect and analyze the latest security attack methods and run simulations, thereby efficiently detecting vulnerabilities and quickly taking measures.

[0862] The processing flow will be explained below.

[0863] Understood. Below I will explain the program process in concrete steps.

[0864] Step 1:

[0865] The server contacts trusted information sources to gather information about the latest security attacks, sending HTTP requests to retrieve information from security forums, blogs, and academic paper databases.

[0866] Step 2:

[0867] The server stores the collected information in a local database, including article titles, body text, and metadata.

[0868] Step 3:

[0869] The server then begins analyzing the stored information using natural language processing technology. Specifically, it performs tokenization, keyword extraction, and contextual analysis to extract the characteristics of the attack method, the attack target, and the attack process.

[0870] Step 4:

[0871] The server automatically generates a security test program based on the analysis results, which includes source code to reproduce the extracted features.

[0872] Step 5:

[0873] The server starts a virtual environment or container as a test environment and deploys the system to be tested, thereby preparing an environment where tests can be executed without affecting the actual system.

[0874] Step 6:

[0875] Run server-generated security test programs in the virtual environment, for example by injecting malicious script into user input fields to simulate XSS attacks.

[0876] Step 7:

[0877] The server collects and logs the test results, which include whether the attack was successful and details of any vulnerabilities detected.

[0878] Step 8:

[0879] The server analyzes the test results and notifies administrators, including vulnerability details and recommended countermeasures, via email and dashboard notifications.

[0880] This series of steps enables a fast and effective response to the latest security attack methods.

[0881] Example 1

[0882] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."

[0883] In conventional security testing, it was necessary to manually collect information and create and run test programs to respond to the latest attack methods. This required time and effort, making it difficult to quickly respond to the latest threats. It was also difficult to perform vulnerability assessments without affecting the actual system.

[0884] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.

[0885] In this invention, the server includes means for collecting information on security attack techniques from reliable information sources, means for analyzing the collected information using natural language processing technology and extracting characteristics of the attack techniques, means for automatically generating a security test program based on the extracted characteristics, means for executing the generated security test program in a virtual environment or a container, means for recording and evaluating the test execution results in a log, and means for notifying the administrator of the evaluation results by email or dashboard notification. This enables rapid response to the latest security attack techniques and efficient vulnerability assessment.

[0886] A "trusted information source" is a means of providing accurate and reliable information on security attack methods, such as security forums, blogs, and academic paper databases.

[0887] "Natural language processing technology" is an artificial intelligence technology used to analyze text data and extract important keywords and features, and includes processes such as tokenization, keyword extraction, and context analysis.

[0888] A "security test program" is source code used to simulate specific security attack scenarios and evaluate system vulnerabilities.

[0889] A "virtual environment" is an environment constructed by software rather than by physical hardware, and is used to execute test programs.

[0890] A "container" is a technology that provides an individual virtual space within an operating system, enabling application virtualization.

[0891] The "test execution results" are logs and evaluation data obtained when the generated security test program is executed, and include information such as whether the attack was successful or not.

[0892] "Administrator" means a person or organization responsible for monitoring the security status of a system and taking necessary measures.

[0893] "Email and dashboard notifications" are communication methods for promptly conveying test results and evaluation results to administrators.

[0894] This invention is an automatic security test generation system for responding quickly and effectively to the latest security attack methods. This system includes a series of processes that collect information on attack methods from reliable information sources, analyze it using natural language processing technology, generate, execute, and evaluate a security test program based on the results, and notify the administrator of the results.

[0895] Information Collection Module

[0896] The server periodically accesses reliable information sources on the Internet (e.g., security forums, blogs, academic paper databases) to collect information on the latest security attack techniques. The server uses a crawling script to retrieve HTML pages from specified URLs and stores information such as page content, metadata, and timestamps in a database.

[0897] Natural Language Processing Module

[0898] The server analyzes the collected information using Python and natural language processing libraries (e.g., NLTK, spaCy). The analysis process includes tokenization, keyword extraction, and contextual analysis to extract the characteristics of security attack methods, attack targets, and attack processes. For example, features such as "XSS attack," "JavaScript injection," and "user input field" can be extracted from the page content.

[0899] Program Generation Module

[0900] Based on the analysis results, the server automatically generates a security test program to simulate the attack method. Specifically, it generates code in Python or JavaScript to insert a malicious script. For example, based on "JavaScript injection," it generates a test program to insert a malicious script into a user input field.

[0901] Test Execution Module

[0902] The server runs the generated security test program in a virtual environment or container. Docker is mainly used as the virtual environment to prevent the test program from affecting the actual system. The server prepares a Docker image, starts a virtual container, and runs the test program. The test execution results are recorded in a log file, and the success of the attack is evaluated through log analysis.

[0903] Notification Module

[0904] The server notifies the administrator of the test results via email or dashboard notification. For example, it may notify the administrator that an XSS attack vulnerability has been detected. Appropriate security measures are required.

[0905] Specific operation example

[0906] 1. Examples of information collection:

[0907] The server accesses "https: / / www.example-security-forum.com / latest-xss-attacks" to obtain information about new XSS attack techniques.

[0908] The server saves the page content to a database.

[0909] 2. Examples of information analysis:

[0910] The server analyzes the stored page content and extracts features such as "XSS attacks," "JavaScript injection," and "user input fields."

[0911] 3. Example of program generation:

[0912] The server generates a test program based on "JavaScript injection" to inject malicious scripts into user input fields.

[0913] 4. Specific examples of test execution:

[0914] The server deploys the web application to be tested on Docker and runs the generated test program.

[0915] The server records the execution result in a log file and gets the result "The XSS attack was successful and the user input field is vulnerable."

[0916] 5. Examples of notification of results:

[0917] The server will send an email to the administrator informing them that an XSS attack vulnerability has been detected and that appropriate security measures are required.

[0918] Prompt Sentence Examples

[0919] Create a prompt to input to the generative AI model as follows:

[0920] plaintext

[0921] "We are developing a system that collects information on the latest security attack methods and automatically generates security test programs based on that information. This system collects information from reliable sources, analyzes it using natural language processing, and generates a security test program that simulates the attack method. Finally, it runs this program in a virtual environment and notifies the administrator of the results. As a concrete example of how this system works, please tell us the steps for analyzing XSS attack methods and generating a program to test them."

[0922] The flow of the identification process in the first embodiment will be described with reference to FIG.

[0923] System program processing flow

[0924] Step 1: Gather information

[0925] Input: URL list of security information sources

[0926] Output: HTML page content and metadata

[0927] Specific behavior:

[0928] The server regularly contacts trusted information sources such as security forums, blogs, and academic paper databases.

[0929] The server uses a crawling script to retrieve the HTML page from the specified URL.

[0930] The server stores the retrieved page content, metadata, timestamps, etc. in a database.

[0931] Step 2: Information analysis using natural language processing

[0932] Input: HTML page content stored in the database

[0933] Output: Extracted features and information about attack methods

[0934] Specific behavior:

[0935] The server analyzes the stored page content using Python and natural language processing libraries (e.g., NLTK, spaCy).

[0936] The server tokenizes the text and extracts important keywords and context.

[0937] The server identifies the details of the security attack method based on the characteristics obtained through the analysis.

[0938] Step 3: Automatic generation of security test programs

[0939] Input: Analyzed attack method characteristics and information

[0940] Output: Source code of the security test program

[0941] Specific behavior:

[0942] Based on the analysis results, the server designs a test program to simulate attack methods.

[0943] The server uses Python and JavaScript to generate source code that reproduces attack scenarios.

[0944] For example, based on "JavaScript injection," code is generated to inject malicious scripts into user input fields.

[0945] Step 4: Running test programs in a virtual environment

[0946] Input: Generated security test program

[0947] Output: Test execution results and log files

[0948] Specific behavior:

[0949] The server prepares a virtual environment or container such as Docker.

[0950] The server deploys the web application to be tested on the virtual environment.

[0951] The server runs the generated test program in the virtual environment and records the results in a log file.

[0952] Step 5: Evaluate and record test results

[0953] Input: Log file after test execution

[0954] Output: Vulnerability assessment results

[0955] Specific behavior:

[0956] The server analyzes the test result log and evaluates whether the attack was successful.

[0957] The server records the evaluation result, such as "The user input field is vulnerable because the XSS attack was successful."

[0958] Step 6: Notification of evaluation results

[0959] Input: Test evaluation result

[0960] Output: Notification message to administrator

[0961] Specific behavior:

[0962] The server generates a message to notify the administrator of the evaluation result.

[0963] The server will send an email or dashboard notification to the administrator stating that an XSS attack vulnerability has been detected and appropriate security measures are required.

[0964] (Application example 1)

[0965] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."

[0966] Security vulnerabilities in modern information systems are evolving rapidly, especially in websites and systems. Traditional security measures are largely manual, making it difficult to respond quickly. They also require specialized knowledge and are difficult for average users to understand. For this reason, there is a demand for a system that can automatically collect and analyze the latest security attack methods and easily perform vulnerability testing.

[0967] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.

[0968] In this invention, the server includes means for collecting information on security attack methods from reliable information sources, means for analyzing the collected information using natural language processing technology and extracting characteristics of the attack methods, and means for automatically generating a security test program based on the extracted characteristics, thereby enabling users to easily test the vulnerabilities of websites and systems on their smartphones.

[0969] "Reliable information sources" refers to reliable information sources such as security forums, blogs, and academic paper databases.

[0970] "Natural language processing technology" refers to technology that enables computers to understand and analyze human language.

[0971] A "security testing program" refers to automatically generated software code used to assess the vulnerabilities of a system or website.

[0972] "Target System" means a system or website designated for the purpose of running a test program to assess vulnerabilities.

[0973] A "vulnerability" refers to a security flaw or defect that exists in a system or website.

[0974] "Evaluation results" refers to the result information obtained after executing a security test program.

[0975] "Administrator" means a person responsible for monitoring and managing the security of a system or website.

[0976] "Virtual environment" refers to technology that provides virtual machines that operate independently of physical computer hardware.

[0977] "Container" refers to a technology that packages an application and its dependencies and provides a single execution environment.

[0978] A "smartphone" refers to a mobile phone terminal that can connect to the Internet and run various applications.

[0979] The present invention provides a system that automatically detects and evaluates vulnerabilities in response to the latest security attack methods. The following describes in detail the various modules that make up this system and their processing flows.

[0980] System configuration

[0981] 1. Information collection module

[0982] The server collects information about the latest security attacks from security forums, blogs, and academic paper databases, using HTTP requests to retrieve the data.

[0983] 2. Natural Language Processing Module

[0984] The server analyzes the collected information using natural language processing technology (e.g., SpaCy or NLTK). This analysis includes tokenization, keyword extraction, and contextual analysis to extract the characteristics of the attack method, the attack target, and the attack process.

[0985] 3. Program Generation Module

[0986] The server automatically generates a security test program that reproduces the attack scenario based on the analysis results. For example, when a test program for an XSS attack is generated, the contents of the program include: <script>alert('XSS');< / script> It includes codes such as:

[0987] 4. Test Execution Module

[0988] The server runs the generated security test program on the virtual environment or container, and the execution results are logged and evaluated for vulnerabilities.

[0989] 5. Notification Module

[0990] The server notifies administrators of the results of the evaluation via email, dashboard notifications, and immediate alerts.

[0991] Hardware and software used

[0992] Server: Plays a central role in collecting information, analyzing, generating programs, running tests, and sending notifications.

[0993] Natural language processing software: SpaCy, NLTK

[0994] Virtual environment software: virtual machines, containers (e.g., Docker)

[0995] Notification software: SMTP client (e.g., smtplib)

[0996] Specific examples and prompts to input to the generative AI model

[0997] As a concrete example, content can be automatically generated by inputting the following prompt sentence into a generative AI model (e.g., ChatGPT):

[0998] Example prompt sentence:

[0999] Design a smartphone application that automatically collects and analyzes the latest security attack methods, and generates and executes security tests. Specifically, the following functions are required:

[1000] Ability to gather information from security forums and blogs

[1001] A function that uses natural language processing technology to extract characteristics of attack methods

[1002] Ability to generate attack scenarios from extracted information

[1003] Ability to run test programs in a virtual environment

[1004] Ability to notify users of test results

[1005] Also, please implement the following program in Python.

[1006] From the above explanation, the detailed functions of the security system provided by the embodiment of the present invention and the specific implementation method thereof will be clear.

[1007] The flow of the specific processing in the application example 1 will be described with reference to FIG.

[1008] System processing flow

[1009] Step 1:

[1010] The server uses HTTP requests to collect information about the latest security attack techniques from reliable sources such as security forums, blogs, and academic paper databases. This information is stored on the server in raw HTML or text format. The input data is a URL, and the output data is the collected raw data.

[1011] Step 2:

[1012] The server analyzes the collected information using natural language processing technology. Specifically, it uses SpaCy and NLTK to perform tokenization, keyword extraction, and context analysis to extract the characteristics of the attack method. The input data at this stage is the raw data collected in step 1, and the output data is the analyzed characteristics of the attack method.

[1013] Step 3:

[1014] The server automatically generates a security test program based on the attack characteristics extracted in step 2. For example, if an XSS attack is extracted as a characteristic, it generates a security test program based on a specific script code (e.g., <script>alert('XSS');< / script> ) is generated. The input data are the analyzed features, and the output data is the automatically generated test program.

[1015] Step 4:

[1016] The server runs the generated security test program in a virtual environment or container. This virtual environment is built using Docker or similar, and the test program is executed against the specified website or system. The input data is the test program and target URL, and the output data is a log of the execution results.

[1017] Step 5:

[1018] The server analyzes the execution results of the test program and evaluates whether there are any vulnerabilities. Specifically, it checks the contents of the log file and determines whether the attack was successful. The input data is the execution result log, and the output data is the vulnerability evaluation result.

[1019] Step 6:

[1020] The server notifies the administrator of the evaluation results. Notification methods include email, dashboard notification, and immediate alerts. The input data is the evaluation results, and the output data is a notification message.

[1021] Furthermore, an emotion engine that estimates the user's emotion may be further combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59, and perform identification processing using the user's emotion.

[1022] Understood. Below is the "Description of the Invention" of the patent specification based on the invention combining the emotion engine.

[1023] The present invention is a system that collects and analyzes information on new security attack methods, and executes security test programs automatically generated based on that information, and further improves the accuracy of security measures by combining it with an emotion engine that recognizes user emotions. Specific embodiments of the present invention are described below.

[1024] System configuration:

[1025] 1. Information collection module:

[1026] The server collects information on the latest security attack methods from security forums, blogs, academic paper databases, etc. This allows for a comprehensive collection of reliable and up-to-date information.

[1027] 2. Natural Language Processing Module:

[1028] The information collected by the server is analyzed using natural language processing technology. Specifically, text data is tokenized, keywords are extracted, and context is analyzed to extract the characteristics of the attack method, the target of the attack, and the attack process.

[1029] 3. Program Generation Module:

[1030] The server automatically generates a security test program based on the analyzed information, which contains the code necessary to reproduce the extracted features and detect system vulnerabilities.

[1031] 4. Test Execution Module:

[1032] The security test program generated by the server is executed in a virtual environment or container. By using a virtual environment or container, tests can be performed without affecting the actual system.

[1033] 5. Emotion Engine Module:

[1034] The server uses an emotion engine to recognize the user's emotions. While the user is operating the system, the emotion engine collects and analyzes data such as the user's facial expressions, tone of voice, and input patterns.

[1035] 6. Result analysis and notification module:

[1036] The server analyzes the test results and emotion recognition results in an integrated manner and notifies administrators via email, dashboard notifications, real-time alerts, and other methods.

[1037] Specific working example:

[1038] Examples of information collected:

[1039] 1. The server accesses a security forum and collects articles on "the latest XSS attack techniques."

[1040] 2. The server stores the collected articles in a database.

[1041] Examples of information analysis:

[1042] 3. The server analyzes the stored articles using natural language processing and extracts features including "XSS attacks," "JavaScript injection," and "user input fields."

[1043] Example of program generation:

[1044] 4. The server generates a security test program based on the extracted features to simulate the insertion of malicious scripts into user input fields. The generated code includes, for example, <script>alert('XSS');< / script> Includes:

[1045] Specific examples of test execution:

[1046] 5. The server starts the virtual environment and deploys the web service under test.

[1047] 6. Run the server-generated test program to simulate an XSS attack within the virtual environment.

[1048] Examples of emotion recognition:

[1049] 7. While the user is using the system, the server uses an emotion engine to collect and analyze the user's emotional data (facial expressions, tone of voice, input patterns, etc.).

[1050] 8. Based on the emotional data collected by the server, the user's reaction to the attack method test results is evaluated.

[1051] Examples of notification of results:

[1052] 9. The server analyzes the vulnerability test results and emotion recognition results in an integrated manner and generates a detailed result such as "A specific input field is vulnerable and the user expressed anxiety."

[1053] 10. The server will send an email to the administrator detailing the results and recommending corrective action.

[1054] In this way, the present invention makes it possible to respond quickly and effectively to the latest security attack methods, and by incorporating user emotions, it becomes possible to further improve the accuracy of security measures.

[1055] The processing flow will be explained below.

[1056] Understood. Below, we will explain in detail each processing step of an embodiment of the invention that combines an emotion engine.

[1057] Step 1:

[1058] The server accesses reliable information sources such as security forums, blogs, and academic paper databases to gather information on the latest security attack techniques. The server sends HTTP requests and stores the retrieved information in a local database.

[1059] Step 2:

[1060] The information collected by the server is analyzed using a natural language processing module. Text data is tokenized, and keywords and contextual analysis are performed to extract the characteristics of attack methods, targets, and attack processes.

[1061] Step 3:

[1062] The server automatically generates a security test program based on the analysis results. The generated program contains code to reproduce the extracted features and evaluate the system's vulnerabilities.

[1063] Step 4:

[1064] The server starts a virtual environment or container as a test environment. The system to be tested is deployed on the virtual environment or container, preparing an environment where tests can be executed without affecting the actual system.

[1065] Step 5:

[1066] Run server-generated security test programs in the virtual environment, for example injecting malicious script into user input fields to simulate XSS attacks.

[1067] Step 6:

[1068] While the user is operating the system, the server uses an emotion engine to recognize the user's emotions. It collects data such as the user's facial expressions, tone of voice, and input patterns in real time and analyzes their emotional state.

[1069] Step 7:

[1070] The server logs the results of the test execution and analyzes them for vulnerabilities and the likelihood of successful attacks, including whether the attack was successful and details of any vulnerabilities detected.

[1071] Step 8:

[1072] The server integrates and analyzes the analysis results of the emotion engine and the test results, evaluating the user's emotions regarding the discovery of the vulnerability (e.g., anxiety, satisfaction, surprise, etc.).

[1073] Step 9:

[1074] The server generates a detailed report for administrators based on the consolidated analysis results, including vulnerability details, attack methods, user emotional reactions, and recommended countermeasures.

[1075] Step 10:

[1076] The server generates reports and notifies administrators via email, dashboard notifications, and instant alerts.

[1077] This series of steps enables rapid and accurate responses to the latest security attack methods, and by combining user emotions, a system is realized that can implement more effective security measures.

[1078] Example 2

[1079] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."

[1080] Conventional security testing systems have difficulty responding quickly to the latest security attack methods, and do not perform vulnerability assessments that take user emotions into consideration. This makes it difficult to implement effective security measures, and it is not possible to fully alleviate user anxiety.

[1081] The identification process by the identification processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means. In this invention, the server includes means for collecting information on security attack methods from reliable information sources, means for analyzing the collected information using natural language processing technology and extracting characteristics of the attack methods, means for automatically generating a security test program based on the extracted characteristics, means for executing the generated security test program on the target system and evaluating vulnerabilities, means for notifying an administrator of the evaluation results, means for recognizing user emotions, and means for analyzing the results based on the recognized emotions. This makes it possible to respond quickly and effectively to the latest security attack methods and implement security measures that take user emotions into consideration.

[1082] A "trusted information source" is a source that provides reliable, up-to-date security-related information, such as security forums, online articles, or public databases.

[1083] "Natural language processing technology" is a technology that tokenizes text data, extracts keywords, and performs context analysis to understand the meaning and intent of text.

[1084] A "security test program" is automatically generated code or script that reproduces attack methods in order to detect system vulnerabilities.

[1085] "Vulnerability assessment" is the process of running generated security test programs to identify and evaluate security weaknesses in a system.

[1086] The "means for recognizing user emotions" refers to a technology or device for collecting data such as the user's facial expressions, tone of voice, and input patterns, and analyzing the user's emotions.

[1087] "Means for notifying the administrator" refers to methods such as email, dashboard notification, and real-time alerts for notifying the administrator of test results and analysis results.

[1088] Understood. Now, here is the patent specification, "Form for Carrying Out the Invention."

[1089] The present invention is a system that collects and analyzes information on the latest security attack methods from reliable information sources, and automatically generates and executes security test programs. Furthermore, it is possible to recognize user emotions and improve the effectiveness of security measures. Detailed embodiments for implementing the present invention are described below.

[1090] System configuration:

[1091] Information gathering module:

[1092] The server periodically collects information about the latest security attack techniques from trusted sources such as security forums, online articles, and public databases using RSS feeds and web scraping techniques.

[1093] Hardware and software used:

[1094] Server: A general server computer (e.g., a Linux server)

[1095] Software: RSS feed readers, web scraping tools, database management systems (e.g., MySQL)

[1096] Examples:

[1097] The server collects articles about "New SQL Injection Attack Techniques" from "Security Blog XYZ" via an RSS feed and stores them in a database.

[1098] Natural Language Processing Module:

[1099] The information collected by the server is analyzed using natural language processing technology. Specifically, the NLTK library and Spacy are used to tokenize text data, extract keywords, and perform contextual analysis to extract the characteristics of attack methods, targets, and attack processes.

[1100] Software used:

[1101] NLTK (Natural Language Toolkit)

[1102] Spacy (natural language processing library)

[1103] Examples:

[1104] The server tokenizes the article from "Security Blog XYZ" and extracts the keywords "SQL injection," "database," and "invalid input."

[1105] Program Generation Module:

[1106] Based on the analysis results, the server automatically generates a security test program using a generative AI model (e.g., OpenAI's GPT series), and provides the extracted features as input prompts.

[1107] Software used:

[1108] Generative AI models (e.g., OpenAI GPT series)

[1109] Examples:

[1110] The server inputs the prompt "Generate a script to simulate an SQL injection attack" into the AI ​​model and generates a test script containing an SQL query such as "SELECT FROM users WHERE user_id = '1' OR '1'='1'".

[1111] Test Execution Module:

[1112] The server runs the generated security test program in a virtual environment or container, allowing vulnerability assessment to be performed without affecting the actual system.

[1113] Hardware and software used:

[1114] Virtual environment (e.g. VirtualBox)

[1115] Container management tools (e.g., Docker)

[1116] Examples:

[1117] The server launches a Docker container, deploys the web application under test, and then runs the generated SQL injection test script to check for vulnerabilities.

[1118] Emotion Recognition Module:

[1119] The server uses an emotion engine to recognize the user's emotions. While the user is operating the system, emotion data is collected in real time through facial expression recognition APIs and voice analysis APIs.

[1120] Software used:

[1121] Facial expression recognition API (e.g. Microsoft Azure Cognitive Services)

[1122] Speech analysis API (e.g. IBM Watson)

[1123] Examples:

[1124] While the user is checking the security test results, the server analyzes the user's webcam footage and detects anxiety or surprise from the user's facial expressions.

[1125] Results Analysis and Notification Module:

[1126] The server analyzes the test results and emotion recognition results in an integrated manner, and generates a detailed report to notify the administrator via email or dashboard notification.

[1127] Software used:

[1128] Email sending system (e.g., SMTP server)

[1129] Dashboard notification systems (e.g. Grafana)

[1130] Examples:

[1131] The server generates a report stating "SQL injection vulnerability detected. User expressed concern about the consequences" and notifies the administrator via email.

[1132] With these configurations, the present invention can respond quickly and effectively to the latest security attack methods, and can implement security measures that take user feelings into consideration.

[1133] Example of an input prompt for a generative AI model:

[1134] Gather information on the latest security attack techniques from the following data sources and analyze the text data using natural language processing techniques.

[1135] Data sources collected: security forums, online articles, public databases

[1136] Analysis targets: SQL injection attacks, JavaScript injection, user input fields

[1137] Based on the analysis results, automatically generate a security test program and run the test in a virtual environment. Furthermore, recognize the user's emotions (facial expressions, tone of voice, input patterns), comprehensively analyze the results, and notify the administrator.

[1138] The above is a detailed description of the mode for carrying out the invention.

[1139] The flow of the identification process in the second embodiment will be described with reference to FIG.

[1140] Step 1: Gather information

[1141] The server collects information about the latest security attack techniques from trusted sources. Specifically, it uses RSS feed readers and web scraping tools to gather data from security forums, online articles, and public databases. The input to this collection process is the URL of the information source or the RSS feed link, and the output is a database that stores the collected security-related information.

[1142] Specific operation: The server retrieves the article "New SQL Injection Attack Technique" from "Security Blog XYZ" via an RSS feed and saves it in the database.

[1143] Step 2: Natural Language Analysis

[1144] The information collected by the server is analyzed using natural language processing technology. The input is security-related information stored in a database, and the output is characteristic information on attack methods extracted through analysis. Specifically, the NLTK library and Spacy are used to tokenize text data, extract keywords, and perform contextual analysis.

[1145] Specific operation: The server tokenizes the article from "Security Blog XYZ" and extracts keywords such as "SQL injection," "database," and "invalid input."

[1146] Step 3: Generate security test programs

[1147] Based on the analysis results, the server automatically generates a security test program using a generative AI model. The input is the analyzed feature information, and the output is the generated security test program. Specifically, a prompt statement is input into the generative AI model, and the result is used to generate a test script.

[1148] How it works: The server inputs the prompt "Generate a script that simulates an SQL injection attack" into the AI ​​model, and generates a test script containing an SQL query such as "SELECT FROM users WHERE user_id = '1' OR '1'='1'".

[1149] Step 4: Test Run

[1150] The server runs the generated security test program in a virtual environment or container. The input is the generated test program and the system under test, and the output is the test execution results. By using a virtual environment or container, vulnerability assessment can be performed without affecting the actual system.

[1151] Specific operation: The server launches a Docker container, deploys the web application to be tested, and runs the generated test script to check for vulnerabilities.

[1152] Step 5: Emotion Recognition

[1153] The server uses an emotion engine to recognize the user's emotions. The input is data such as the user's facial expressions, tone of voice, and input patterns, and the output is analyzed emotional data of the user. Specifically, it uses facial expression recognition APIs and voice analysis APIs to collect and analyze changes in the user's emotions in real time.

[1154] Specific operation: While the user is checking the system's security test results, the server analyzes the webcam footage using a facial expression recognition API to detect anxiety or surprise from the user's facial expressions.

[1155] Step 6: Results analysis and notification

[1156] The server performs an integrated analysis of the test results and emotion recognition results, and generates a detailed report to notify the administrator. The input is the test execution results and emotion data, and the output is a detailed report. Notification methods include email and dashboard notifications.

[1157] Specific behavior: The server generates a report stating "SQL injection vulnerability detected. User expressed concern about the consequences" and notifies the administrator via email.

[1158] (Application example 2)

[1159] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."

[1160] In recent years, security attack methods have rapidly evolved, and conventional countermeasures are no longer sufficient to deal with them. Furthermore, the emotions felt by users while operating a system are an important factor that cannot be ignored, and there is a need to implement more effective security measures that take this into consideration. However, it is technically difficult to simultaneously address these factors, and currently no suitable system exists.

[1161] The identification process by the identification processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means. In this invention, the server includes means for collecting information on security attack methods from reliable information sources, means for analyzing the collected information using natural language processing technology and extracting characteristics of the attack methods, means for automatically generating a security test program based on the extracted characteristics, means for executing the generated security test program on the target system and evaluating vulnerabilities, means for analyzing a user's facial expressions, voice, and input patterns using emotion analysis technology and collecting user emotion data, and means for comprehensively analyzing the vulnerability assessment results and the emotion data and notifying the administrator. This makes it possible to respond quickly and effectively to the latest security attack methods and obtain feedback based on the user's emotions.

[1162] A "trusted information source" is a source that provides up-to-date and reliable information, such as a security forum or academic paper database.

[1163] "Natural language processing technology" is a technology that analyzes text data and extracts keywords and features based on context.

[1164] A "security test program" is a program that is automatically generated based on analyzed information to detect system vulnerabilities.

[1165] A "virtual environment" is a virtualized environment in which programs can be tested without affecting the actual system.

[1166] A "container" is a technology that packages an application's execution environment into a single package and executes it in a virtually isolated manner.

[1167] "Emotion analysis technology" is a technology that analyzes emotions from a user's facial expressions, voice, and input patterns.

[1168] "User emotion data" refers to information about a user's emotions collected using emotion analysis technology.

[1169] "Vulnerability assessment" is the process of running a generated security test program to assess the vulnerability of a system.

[1170] "Notifying the administrator" refers to the act of reporting the vulnerability assessment results and user emotional data to the administrator and urging them to take appropriate measures.

[1171] The present invention is a system that collects and analyzes the latest information on security attack techniques, executes security test programs automatically generated based on the analysis results, and further recognizes user emotions to improve the accuracy of security countermeasures. Specific embodiments of the present invention are described below.

[1172] System configuration

[1173] Information Collection Module

[1174] The server collects information about security attack methods from reliable sources, such as security forums and academic paper databases, and uses the requests library for its hardware and software.

[1175] Natural Language Processing Module

[1176] The server analyzes the collected information using natural language processing technology to extract characteristics of the attack method. Specifically, it tokenizes the text data and performs keyword extraction and context analysis. The software used is the spacy library.

[1177] Program Generation Module

[1178] The server automatically generates a security test program based on the analyzed information. This program contains code to reproduce the extracted characteristics and detect system vulnerabilities. The code is generated using a text editor.

[1179] Test Execution Module

[1180] The server runs the generated security test program in a virtual environment to evaluate vulnerabilities. By using a virtual environment or container, it is possible to perform testing without affecting the actual system. The hardware used is a virtualizable server, and the software uses Docker or other virtualization tools.

[1181] Emotion Recognition Module

[1182] The device uses emotion analysis technology to analyze the user's facial expressions, voice, and input patterns to collect user emotion data. Data is collected using the camera and microphone and analyzed using the cv2 and emotion_recognition libraries.

[1183] Results Analysis and Notification Module

[1184] The server analyzes the test results and emotion recognition results and notifies administrators. Specifically, it reports the results via email, dashboard notifications, and real-time alerts. The software used is the requests library, which sends data to a web service that notifies users appropriately.

[1185] Specific examples

[1186] For example, the server accesses a security forum to collect articles about the latest XSS attack techniques and stores them in a database. It then uses natural language processing technology to analyze the collected information and extracts features of XSS attacks, JavaScript injection, and user input fields. Based on these features, the server generates a security test program that simulates the injection of a malicious script into a user input field, and runs the test in a virtual environment.

[1187] The device uses a camera and microphone to collect the user's facial expressions and tone of voice while the user is operating the system, and analyzes the emotional data. Finally, the test results and the user's emotional data are analyzed comprehensively, and the system notifies the administrator of the detailed results, stating that "a specific input field was found to be vulnerable and the user expressed anxiety."

[1188] Prompt Sentence Examples

[1189] "Please generate a security test program that includes the latest XSS attack techniques and run it in a virtual environment. Also, please analyze the user's facial expressions and tone of voice, and report any feelings of anxiety or other anxiety felt by the user."

[1190] By using the above specific means, the present invention enables quick and effective responses to the latest security attack methods, and also provides feedback based on user emotions, thereby improving the accuracy of security measures.

[1191] The flow of the specific processing in the application example 2 will be described with reference to FIG.

[1192] Step 1:

[1193] The server collects the latest information on security attack techniques from trusted sources, specifically by accessing security forums and academic paper databases to retrieve relevant articles and papers, using the requests library to collect data via an Internet connection.

[1194] Input: URL of a security forum or academic paper database

[1195] Output: Raw data on attack techniques (articles and papers)

[1196] Step 2:

[1197] The information collected by the server is analyzed using natural language processing technology. Specifically, the text data is tokenized using the spacy library, and keywords and contextual analysis are performed to extract the characteristics of attack methods.

[1198] Input: Raw data on attack techniques (articles and papers)

[1199] Output: Characteristics of the analyzed attack method (e.g., "XSS attack," "JavaScript injection," etc.)

[1200] Step 3:

[1201] The server automatically generates a security test program based on the extracted features. Specifically, it uses a programming language to reproduce the features and generates code to detect system vulnerabilities. The code is constructed using a text editor.

[1202] Input: Analyzed attack characteristics

[1203] Output: Security test program code

[1204] Step 4:

[1205] The server runs the generated security test program in a virtual environment. Specifically, a virtual environment is set up using a virtualization tool such as Docker, and the test program is run. This step evaluates the system's vulnerabilities.

[1206] Input: Security test program code

[1207] Output: Vulnerability assessment results

[1208] Step 5:

[1209] The device uses emotion analysis technology to analyze the user's facial expressions, voice, and input patterns to collect emotion data. Specifically, data is collected using the camera and microphone, and analyzed using the cv2 and emotion_recognition libraries.

[1210] Input: facial expression data, voice data, input patterns during user operation

[1211] Output: Analyzed user emotion data

[1212] Step 6:

[1213] The server analyzes the test results and emotion recognition results in an integrated manner and notifies the administrator via email or a web dashboard using the requests library.

[1214] Input: Vulnerability assessment results, analyzed user emotion data

[1215] Output: Notification message to administrator (e.g. "A specific input field is vulnerable and the user expressed concern")

[1216] Through the above steps, the system of the present invention can respond quickly and effectively to the latest security attack methods, and can obtain feedback based on the user's emotions, thereby improving the accuracy of security measures.

[1217] The specific processing unit 290 transmits the result of the specific processing to the headset type terminal 314. In the headset type terminal 314, the control unit 46A causes the speaker 240 and the display 343 to output the result of the specific processing. The microphone 238 acquires audio indicating a user input regarding the result of the specific processing. The control unit 46A transmits audio data indicating the user input acquired by the microphone 238 to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.

[1218] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[1219] In the above embodiment, an example was given in which the specific processing is performed by the data processing device 12, but the technology of the present disclosure is not limited to this, and the specific processing may be performed by the headset type terminal 314.

[1220] [Fourth embodiment]

[1221] FIG. 7 shows an example of the configuration of a data processing system 410 according to the fourth embodiment.

[1222] 7, a data processing system 410 includes a data processing device 12 and a robot 414. An example of the data processing device 12 is a server.

[1223] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[1224] The robot 414 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication I / F 44, and a control target 443. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The microphone 238, the speaker 240, the camera 42, and the control target 443 are also connected to the bus 52.

[1225] The microphone 238 receives instructions and the like from the user 20 by receiving voice uttered by the user 20. The microphone 238 captures the voice uttered by the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio in accordance with instructions from the processor 46.

[1226] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the surroundings of user 20 (for example, an imaging range defined by an angle of view equivalent to the field of vision of a typical healthy person).

[1227] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 are responsible for the exchange of various information between the processor 46 and the processor 28 via the network 54. The exchange of various information between the processor 46 and the processor 28 using the communication I / Fs 44 and 26 is carried out in a secure state.

[1228] The control object 443 includes a display device, LEDs in the eyes, and motors for driving the arms, hands, and feet. The posture and gestures of the robot 414 are controlled by controlling the motors of the arms, hands, and feet. Some of the emotions of the robot 414 can be expressed by controlling these motors. In addition, the facial expressions of the robot 414 can also be expressed by controlling the light emission state of the LEDs in the eyes of the robot 414.

[1229] Fig. 8 shows an example of the main functions of the data processing device 12 and the robot 414. As shown in Fig. 8, in the data processing device 12, a specific process is performed by the processor 28. A specific process program 56 is stored in the storage 32.

[1230] The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[1231] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[1232] In the robot 414, the processor 46 performs the reception output process. A reception output program 60 is stored in the storage 50. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.

[1233] Next, a description will be given of the specific processing performed by the specific processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."

[1234] Understood. Below is the "Form for Carrying Out the Invention" from the patent specification.

[1235] The present invention is a system that collects and analyzes information about security attack methods, and automatically generates and executes security tests based on that information. Specifically, the system is implemented as follows.

[1236] System configuration:

[1237] 1. Information collection module:

[1238] The server collects information about the latest security attack techniques from trusted sources (security forums, blogs, academic paper databases, etc.) and includes a database that stores the collected logs, metadata, and retrieved content.

[1239] 2. Natural Language Processing Module:

[1240] The information collected by the server is analyzed using natural language processing technology. Specifically, it performs tokenization, keyword extraction, and context analysis to extract the characteristics of attack methods, targets, and attack processes.

[1241] 3. Program Generation Module:

[1242] Based on the analyzed information, the server automatically generates a security test program that simulates attack methods, generating source code to reproduce specific attack scenarios.

[1243] 4. Test Execution Module:

[1244] The server-generated security test programs are run in a virtual environment or container, which is designed to prevent the live system from being affected. The results of the test execution are logged and analyzed.

[1245] 5. Notification module:

[1246] The server notifies administrators of test results via email, dashboard notifications, or instant alerts.

[1247] Specific working example:

[1248] Examples of information collection:

[1249] 1. The server accesses a specific security forum and retrieves the page "The latest XSS attack techniques."

[1250] 2. The server saves the contents of this page in a database.

[1251] Examples of information analysis:

[1252] 3. The server analyzes the stored page content using a natural language processing module and extracts features such as "XSS attacks," "JavaScript injection," and "user input fields."

[1253] Example of program generation:

[1254] 4. The server generates a security test program based on "JavaScript injection" to inject malicious scripts into user input fields. <script>alert('XSS');< / script> The code is included in the test program.

[1255] Specific examples of test execution:

[1256] 5. The server deploys the web service to be tested on the virtual environment and runs the generated test program.

[1257] 6. The server records the execution result in a log file, and the result is "The XSS attack was successful, so the user input field is vulnerable."

[1258] Examples of notification of results:

[1259] 7. The server sends an email to the administrator stating, "An XSS attack vulnerability has been detected. Appropriate security measures are required."

[1260] In this way, the present invention provides a system that can automatically collect and analyze the latest security attack methods and run simulations, thereby efficiently detecting vulnerabilities and quickly taking measures.

[1261] The processing flow will be explained below.

[1262] Understood. Below I will explain the program process in concrete steps.

[1263] Step 1:

[1264] The server contacts trusted information sources to gather information about the latest security attacks, sending HTTP requests to retrieve information from security forums, blogs, and academic paper databases.

[1265] Step 2:

[1266] The server stores the collected information in a local database, including article titles, body text, and metadata.

[1267] Step 3:

[1268] The server then begins analyzing the stored information using natural language processing technology. Specifically, it performs tokenization, keyword extraction, and contextual analysis to extract the characteristics of the attack method, the attack target, and the attack process.

[1269] Step 4:

[1270] The server automatically generates a security test program based on the analysis results, which includes source code to reproduce the extracted features.

[1271] Step 5:

[1272] The server starts a virtual environment or container as a test environment and deploys the system to be tested, thereby preparing an environment where tests can be executed without affecting the actual system.

[1273] Step 6:

[1274] Run server-generated security test programs in the virtual environment, for example by injecting malicious script into user input fields to simulate XSS attacks.

[1275] Step 7:

[1276] The server collects and logs the test results, which include whether the attack was successful and details of any vulnerabilities detected.

[1277] Step 8:

[1278] The server analyzes the test results and notifies administrators, including vulnerability details and recommended countermeasures, via email and dashboard notifications.

[1279] This series of steps enables a fast and effective response to the latest security attack methods.

[1280] Example 1

[1281] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."

[1282] In conventional security testing, it was necessary to manually collect information and create and run test programs to respond to the latest attack methods. This required time and effort, making it difficult to quickly respond to the latest threats. It was also difficult to perform vulnerability assessments without affecting the actual system.

[1283] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.

[1284] In this invention, the server includes means for collecting information on security attack techniques from reliable information sources, means for analyzing the collected information using natural language processing technology and extracting characteristics of the attack techniques, means for automatically generating a security test program based on the extracted characteristics, means for executing the generated security test program in a virtual environment or a container, means for recording and evaluating the test execution results in a log, and means for notifying the administrator of the evaluation results by email or dashboard notification. This enables rapid response to the latest security attack techniques and efficient vulnerability assessment.

[1285] A "trusted information source" is a means of providing accurate and reliable information on security attack methods, such as security forums, blogs, and academic paper databases.

[1286] "Natural language processing technology" is an artificial intelligence technology used to analyze text data and extract important keywords and features, and includes processes such as tokenization, keyword extraction, and context analysis.

[1287] A "security test program" is source code used to simulate specific security attack scenarios and evaluate system vulnerabilities.

[1288] A "virtual environment" is an environment constructed by software rather than by physical hardware, and is used to execute test programs.

[1289] A "container" is a technology that provides an individual virtual space within an operating system, enabling application virtualization.

[1290] The "test execution results" are logs and evaluation data obtained when the generated security test program is executed, and include information such as whether the attack was successful or not.

[1291] "Administrator" means a person or organization responsible for monitoring the security status of a system and taking necessary measures.

[1292] "Email and dashboard notifications" are communication methods for promptly conveying test results and evaluation results to administrators.

[1293] This invention is an automatic security test generation system for responding quickly and effectively to the latest security attack methods. This system includes a series of processes that collect information on attack methods from reliable information sources, analyze it using natural language processing technology, generate, execute, and evaluate a security test program based on the results, and notify the administrator of the results.

[1294] Information Collection Module

[1295] The server periodically accesses reliable information sources on the Internet (e.g., security forums, blogs, academic paper databases) to collect information on the latest security attack techniques. The server uses a crawling script to retrieve HTML pages from specified URLs and stores information such as page content, metadata, and timestamps in a database.

[1296] Natural Language Processing Module

[1297] The server analyzes the collected information using Python and natural language processing libraries (e.g., NLTK, spaCy). The analysis process includes tokenization, keyword extraction, and contextual analysis to extract the characteristics of security attack methods, attack targets, and attack processes. For example, features such as "XSS attack," "JavaScript injection," and "user input field" can be extracted from the page content.

[1298] Program Generation Module

[1299] Based on the analysis results, the server automatically generates a security test program to simulate the attack method. Specifically, it generates code in Python or JavaScript to insert a malicious script. For example, based on "JavaScript injection," it generates a test program to insert a malicious script into a user input field.

[1300] Test Execution Module

[1301] The server runs the generated security test program in a virtual environment or container. Docker is mainly used as the virtual environment to prevent the test program from affecting the actual system. The server prepares a Docker image, starts a virtual container, and runs the test program. The test execution results are recorded in a log file, and the success of the attack is evaluated through log analysis.

[1302] Notification Module

[1303] The server notifies the administrator of the test results via email or dashboard notification. For example, it may notify the administrator that an XSS attack vulnerability has been detected. Appropriate security measures are required.

[1304] Specific operation example

[1305] 1. Examples of information collection:

[1306] The server accesses "https: / / www.example-security-forum.com / latest-xss-attacks" to obtain information about new XSS attack techniques.

[1307] The server saves the page content to a database.

[1308] 2. Examples of information analysis:

[1309] The server analyzes the stored page content and extracts features such as "XSS attacks," "JavaScript injection," and "user input fields."

[1310] 3. Example of program generation:

[1311] The server generates a test program based on "JavaScript injection" to inject malicious scripts into user input fields.

[1312] 4. Specific examples of test execution:

[1313] The server deploys the web application to be tested on Docker and runs the generated test program.

[1314] The server records the execution result in a log file and gets the result "The XSS attack was successful and the user input field is vulnerable."

[1315] 5. Examples of notification of results:

[1316] The server will send an email to the administrator informing them that an XSS attack vulnerability has been detected and that appropriate security measures are required.

[1317] Prompt Sentence Examples

[1318] Create a prompt to input to the generative AI model as follows:

[1319] plaintext

[1320] "We are developing a system that collects information on the latest security attack methods and automatically generates security test programs based on that information. This system collects information from reliable sources, analyzes it using natural language processing, and generates a security test program that simulates the attack method. Finally, it runs this program in a virtual environment and notifies the administrator of the results. As a concrete example of how this system works, please tell us the steps for analyzing XSS attack methods and generating a program to test them."

[1321] The flow of the identification process in the first embodiment will be described with reference to FIG.

[1322] System program processing flow

[1323] Step 1: Gather information

[1324] Input: URL list of security information sources

[1325] Output: HTML page content and metadata

[1326] Specific behavior:

[1327] The server regularly contacts trusted information sources such as security forums, blogs, and academic paper databases.

[1328] The server uses a crawling script to retrieve the HTML page from the specified URL.

[1329] The server stores the retrieved page content, metadata, timestamps, etc. in a database.

[1330] Step 2: Information analysis using natural language processing

[1331] Input: HTML page content stored in the database

[1332] Output: Extracted features and information about attack methods

[1333] Specific behavior:

[1334] The server analyzes the stored page content using Python and natural language processing libraries (e.g., NLTK, spaCy).

[1335] The server tokenizes the text and extracts important keywords and context.

[1336] The server identifies the details of the security attack method based on the characteristics obtained through the analysis.

[1337] Step 3: Automatic generation of security test programs

[1338] Input: Analyzed attack method characteristics and information

[1339] Output: Source code of the security test program

[1340] Specific behavior:

[1341] Based on the analysis results, the server designs a test program to simulate attack methods.

[1342] The server uses Python and JavaScript to generate source code that reproduces attack scenarios.

[1343] For example, based on "JavaScript injection," code is generated to inject malicious scripts into user input fields.

[1344] Step 4: Running test programs in a virtual environment

[1345] Input: Generated security test program

[1346] Output: Test execution results and log files

[1347] Specific behavior:

[1348] The server prepares a virtual environment or container such as Docker.

[1349] The server deploys the web application to be tested on the virtual environment.

[1350] The server runs the generated test program in the virtual environment and records the results in a log file.

[1351] Step 5: Evaluate and record test results

[1352] Input: Log file after test execution

[1353] Output: Vulnerability assessment results

[1354] Specific behavior:

[1355] The server analyzes the test result log and evaluates whether the attack was successful.

[1356] The server records the evaluation result, such as "The user input field is vulnerable because the XSS attack was successful."

[1357] Step 6: Notification of evaluation results

[1358] Input: Test evaluation result

[1359] Output: Notification message to administrator

[1360] Specific behavior:

[1361] The server generates a message to notify the administrator of the evaluation result.

[1362] The server will send an email or dashboard notification to the administrator stating that an XSS attack vulnerability has been detected and appropriate security measures are required.

[1363] (Application example 1)

[1364] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."

[1365] Security vulnerabilities in modern information systems are evolving rapidly, especially in websites and systems. Traditional security measures are largely manual, making it difficult to respond quickly. They also require specialized knowledge and are difficult for average users to understand. For this reason, there is a demand for a system that can automatically collect and analyze the latest security attack methods and easily perform vulnerability testing.

[1366] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.

[1367] In this invention, the server includes means for collecting information on security attack methods from reliable information sources, means for analyzing the collected information using natural language processing technology and extracting characteristics of the attack methods, and means for automatically generating a security test program based on the extracted characteristics, thereby enabling users to easily test the vulnerabilities of websites and systems on their smartphones.

[1368] "Reliable information sources" refers to reliable information sources such as security forums, blogs, and academic paper databases.

[1369] "Natural language processing technology" refers to technology that enables computers to understand and analyze human language.

[1370] A "security testing program" refers to automatically generated software code used to assess the vulnerabilities of a system or website.

[1371] "Target System" means a system or website designated for the purpose of running a test program to assess vulnerabilities.

[1372] A "vulnerability" refers to a security flaw or defect that exists in a system or website.

[1373] "Evaluation results" refers to the result information obtained after executing a security test program.

[1374] "Administrator" means a person responsible for monitoring and managing the security of a system or website.

[1375] "Virtual environment" refers to technology that provides virtual machines that operate independently of physical computer hardware.

[1376] "Container" refers to a technology that packages an application and its dependencies and provides a single execution environment.

[1377] A "smartphone" refers to a mobile phone terminal that can connect to the Internet and run various applications.

[1378] The present invention provides a system that automatically detects and evaluates vulnerabilities in response to the latest security attack methods. The following describes in detail the various modules that make up this system and their processing flows.

[1379] System configuration

[1380] 1. Information collection module

[1381] The server collects information about the latest security attacks from security forums, blogs, and academic paper databases, using HTTP requests to retrieve the data.

[1382] 2. Natural Language Processing Module

[1383] The server analyzes the collected information using natural language processing technology (e.g., SpaCy or NLTK). This analysis includes tokenization, keyword extraction, and contextual analysis to extract the characteristics of the attack method, the attack target, and the attack process.

[1384] 3. Program Generation Module

[1385] The server automatically generates a security test program that reproduces the attack scenario based on the analysis results. For example, when a test program for an XSS attack is generated, the contents of the program include: <script>alert('XSS');< / script> It includes codes such as:

[1386] 4. Test Execution Module

[1387] The server runs the generated security test program on the virtual environment or container, and the execution results are logged and evaluated for vulnerabilities.

[1388] 5. Notification Module

[1389] The server notifies administrators of the results of the evaluation via email, dashboard notifications, and immediate alerts.

[1390] Hardware and software used

[1391] Server: Plays a central role in collecting information, analyzing, generating programs, running tests, and sending notifications.

[1392] Natural language processing software: SpaCy, NLTK

[1393] Virtual environment software: virtual machines, containers (e.g., Docker)

[1394] Notification software: SMTP client (e.g., smtplib)

[1395] Specific examples and prompts to input to the generative AI model

[1396] As a concrete example, content can be automatically generated by inputting the following prompt sentence into a generative AI model (e.g., ChatGPT):

[1397] Example prompt sentence:

[1398] Design a smartphone application that automatically collects and analyzes the latest security attack methods, and generates and executes security tests. Specifically, the following functions are required:

[1399] Ability to gather information from security forums and blogs

[1400] A function that uses natural language processing technology to extract characteristics of attack methods

[1401] Ability to generate attack scenarios from extracted information

[1402] Ability to run test programs in a virtual environment

[1403] Ability to notify users of test results

[1404] Also, please implement the following program in Python.

[1405] From the above explanation, the detailed functions of the security system provided by the embodiment of the present invention and the specific implementation method thereof will be clear.

[1406] The flow of the specific processing in the application example 1 will be described with reference to FIG.

[1407] System processing flow

[1408] Step 1:

[1409] The server uses HTTP requests to collect information about the latest security attack techniques from reliable sources such as security forums, blogs, and academic paper databases. This information is stored on the server in raw HTML or text format. The input data is a URL, and the output data is the collected raw data.

[1410] Step 2:

[1411] The server analyzes the collected information using natural language processing technology. Specifically, it uses SpaCy and NLTK to perform tokenization, keyword extraction, and context analysis to extract the characteristics of the attack method. The input data at this stage is the raw data collected in step 1, and the output data is the analyzed characteristics of the attack method.

[1412] Step 3:

[1413] The server automatically generates a security test program based on the attack characteristics extracted in step 2. For example, if an XSS attack is extracted as a characteristic, it generates a security test program based on a specific script code (e.g., <script>alert('XSS');< / script> ) is generated. The input data are the analyzed features, and the output data is the automatically generated test program.

[1414] Step 4:

[1415] The server runs the generated security test program in a virtual environment or container. This virtual environment is built using Docker or similar, and the test program is executed against the specified website or system. The input data is the test program and target URL, and the output data is a log of the execution results.

[1416] Step 5:

[1417] The server analyzes the execution results of the test program and evaluates whether there are any vulnerabilities. Specifically, it checks the contents of the log file and determines whether the attack was successful. The input data is the execution result log, and the output data is the vulnerability evaluation result.

[1418] Step 6:

[1419] The server notifies the administrator of the evaluation results. Notification methods include email, dashboard notification, and immediate alerts. The input data is the evaluation results, and the output data is a notification message.

[1420] Furthermore, an emotion engine that estimates the user's emotion may be further combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59, and perform identification processing using the user's emotion.

[1421] Understood. Below is the "Description of the Invention" of the patent specification based on the invention combining the emotion engine.

[1422] The present invention is a system that collects and analyzes information on new security attack methods, and executes security test programs automatically generated based on that information, and further improves the accuracy of security measures by combining it with an emotion engine that recognizes user emotions. Specific embodiments of the present invention are described below.

[1423] System configuration:

[1424] 1. Information collection module:

[1425] The server collects information on the latest security attack methods from security forums, blogs, academic paper databases, etc. This allows for a comprehensive collection of reliable and up-to-date information.

[1426] 2. Natural Language Processing Module:

[1427] The information collected by the server is analyzed using natural language processing technology. Specifically, text data is tokenized, keywords are extracted, and context is analyzed to extract the characteristics of the attack method, the target of the attack, and the attack process.

[1428] 3. Program Generation Module:

[1429] The server automatically generates a security test program based on the analyzed information, which contains the code necessary to reproduce the extracted features and detect system vulnerabilities.

[1430] 4. Test Execution Module:

[1431] The security test program generated by the server is executed in a virtual environment or container. By using a virtual environment or container, tests can be performed without affecting the actual system.

[1432] 5. Emotion Engine Module:

[1433] The server uses an emotion engine to recognize the user's emotions. While the user is operating the system, the emotion engine collects and analyzes data such as the user's facial expressions, tone of voice, and input patterns.

[1434] 6. Result analysis and notification module:

[1435] The server analyzes the test results and emotion recognition results in an integrated manner and notifies administrators via email, dashboard notifications, real-time alerts, and other methods.

[1436] Specific working example:

[1437] Examples of information collection:

[1438] 1. The server accesses a security forum and collects articles on "the latest XSS attack techniques."

[1439] 2. The server stores the collected articles in a database.

[1440] Examples of information analysis:

[1441] 3. The server analyzes the stored articles using natural language processing and extracts features including "XSS attacks," "JavaScript injection," and "user input fields."

[1442] Example of program generation:

[1443] 4. The server generates a security test program based on the extracted features to simulate the insertion of malicious scripts into user input fields. The generated code includes, for example, <script>alert('XSS');< / script> Includes:

[1444] Specific examples of test execution:

[1445] 5. The server starts the virtual environment and deploys the web service under test.

[1446] 6. Run the server-generated test program to simulate an XSS attack within the virtual environment.

[1447] Examples of emotion recognition:

[1448] 7. While the user is using the system, the server uses an emotion engine to collect and analyze the user's emotional data (facial expressions, tone of voice, input patterns, etc.).

[1449] 8. Based on the emotional data collected by the server, the user's reaction to the attack method test results is evaluated.

[1450] Examples of notification of results:

[1451] 9. The server analyzes the vulnerability test results and emotion recognition results in an integrated manner and generates a detailed result such as "A specific input field is vulnerable and the user expressed anxiety."

[1452] 10. The server will send an email to the administrator detailing the results and recommending corrective action.

[1453] In this way, the present invention makes it possible to respond quickly and effectively to the latest security attack methods, and by incorporating user emotions, it becomes possible to further improve the accuracy of security measures.

[1454] The processing flow will be explained below.

[1455] Understood. Below, we will explain in detail each processing step of an embodiment of the invention that combines an emotion engine.

[1456] Step 1:

[1457] The server accesses reliable information sources such as security forums, blogs, and academic paper databases to gather information on the latest security attack techniques. The server sends HTTP requests and stores the retrieved information in a local database.

[1458] Step 2:

[1459] The information collected by the server is analyzed using a natural language processing module. Text data is tokenized, and keywords and contextual analysis are performed to extract the characteristics of attack methods, targets, and attack processes.

[1460] Step 3:

[1461] The server automatically generates a security test program based on the analysis results. The generated program contains code to reproduce the extracted features and evaluate the system's vulnerabilities.

[1462] Step 4:

[1463] The server starts a virtual environment or container as a test environment. The system to be tested is deployed on the virtual environment or container, preparing an environment where tests can be executed without affecting the actual system.

[1464] Step 5:

[1465] Run server-generated security test programs in the virtual environment, for example injecting malicious script into user input fields to simulate XSS attacks.

[1466] Step 6:

[1467] While the user is operating the system, the server uses an emotion engine to recognize the user's emotions. It collects data such as the user's facial expressions, tone of voice, and input patterns in real time and analyzes their emotional state.

[1468] Step 7:

[1469] The server logs the results of the test execution and analyzes them for vulnerabilities and the likelihood of successful attacks, including whether the attack was successful and details of any vulnerabilities detected.

[1470] Step 8:

[1471] The server integrates and analyzes the analysis results of the emotion engine and the test results, evaluating the user's emotions regarding the discovery of the vulnerability (e.g., anxiety, satisfaction, surprise, etc.).

[1472] Step 9:

[1473] The server generates a detailed report for administrators based on the consolidated analysis results, including vulnerability details, attack methods, user emotional reactions, and recommended countermeasures.

[1474] Step 10:

[1475] The server generates reports and notifies administrators via email, dashboard notifications, and instant alerts.

[1476] This series of steps enables rapid and accurate responses to the latest security attack methods, and by combining user emotions, a system is realized that can implement more effective security measures.

[1477] Example 2

[1478] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."

[1479] Conventional security testing systems have difficulty responding quickly to the latest security attack methods, and do not perform vulnerability assessments that take user emotions into consideration. This makes it difficult to implement effective security measures, and it is not possible to fully alleviate user anxiety.

[1480] The identification process by the identification processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means. In this invention, the server includes means for collecting information on security attack methods from reliable information sources, means for analyzing the collected information using natural language processing technology and extracting characteristics of the attack methods, means for automatically generating a security test program based on the extracted characteristics, means for executing the generated security test program on the target system and evaluating vulnerabilities, means for notifying an administrator of the evaluation results, means for recognizing user emotions, and means for analyzing the results based on the recognized emotions. This makes it possible to respond quickly and effectively to the latest security attack methods and implement security measures that take user emotions into consideration.

[1481] A "trusted information source" is a source that provides reliable, up-to-date security-related information, such as security forums, online articles, or public databases.

[1482] "Natural language processing technology" is a technology that tokenizes text data, extracts keywords, and performs context analysis to understand the meaning and intent of text.

[1483] A "security test program" is automatically generated code or script that reproduces attack methods in order to detect system vulnerabilities.

[1484] "Vulnerability assessment" is the process of running generated security test programs to identify and evaluate security weaknesses in a system.

[1485] The "means for recognizing user emotions" refers to a technology or device for collecting data such as the user's facial expressions, tone of voice, and input patterns, and analyzing the user's emotions.

[1486] "Means for notifying the administrator" refers to methods such as email, dashboard notification, and real-time alerts for notifying the administrator of test results and analysis results.

[1487] Understood. Now, here is the patent specification, "Form for Carrying Out the Invention."

[1488] The present invention is a system that collects and analyzes information on the latest security attack methods from reliable information sources, and automatically generates and executes security test programs. Furthermore, it is possible to recognize user emotions and improve the effectiveness of security measures. Detailed embodiments for implementing the present invention are described below.

[1489] System configuration:

[1490] Information gathering module:

[1491] The server periodically collects information about the latest security attack techniques from trusted sources such as security forums, online articles, and public databases using RSS feeds and web scraping techniques.

[1492] Hardware and software used:

[1493] Server: A general server computer (e.g., a Linux server)

[1494] Software: RSS feed readers, web scraping tools, database management systems (e.g., MySQL)

[1495] Examples:

[1496] The server collects articles about "New SQL Injection Attack Techniques" from "Security Blog XYZ" via an RSS feed and stores them in a database.

[1497] Natural Language Processing Module:

[1498] The information collected by the server is analyzed using natural language processing technology. Specifically, the NLTK library and Spacy are used to tokenize text data, extract keywords, and perform contextual analysis to extract the characteristics of attack methods, targets, and attack processes.

[1499] Software used:

[1500] NLTK (Natural Language Toolkit)

[1501] Spacy (natural language processing library)

[1502] Examples:

[1503] The server tokenizes the article from "Security Blog XYZ" and extracts the keywords "SQL injection," "database," and "invalid input."

[1504] Program Generation Module:

[1505] Based on the analysis results, the server automatically generates a security test program using a generative AI model (e.g., OpenAI's GPT series), and provides the extracted features as input prompts.

[1506] Software used:

[1507] Generative AI models (e.g., OpenAI GPT series)

[1508] Examples:

[1509] The server inputs the prompt "Generate a script to simulate an SQL injection attack" into the AI ​​model and generates a test script containing an SQL query such as "SELECT FROM users WHERE user_id = '1' OR '1'='1'".

[1510] Test Execution Module:

[1511] The server runs the generated security test program in a virtual environment or container, allowing vulnerability assessment to be performed without affecting the actual system.

[1512] Hardware and software used:

[1513] Virtual environment (e.g. VirtualBox)

[1514] Container management tools (e.g., Docker)

[1515] Examples:

[1516] The server launches a Docker container, deploys the web application under test, and then runs the generated SQL injection test script to check for vulnerabilities.

[1517] Emotion Recognition Module:

[1518] The server uses an emotion engine to recognize the user's emotions. While the user is operating the system, emotion data is collected in real time through facial expression recognition APIs and voice analysis APIs.

[1519] Software used:

[1520] Facial expression recognition API (e.g. Microsoft Azure Cognitive Services)

[1521] Speech analysis API (e.g. IBM Watson)

[1522] Examples:

[1523] While the user is checking the security test results, the server analyzes the user's webcam footage and detects anxiety or surprise from the user's facial expressions.

[1524] Results Analysis and Notification Module:

[1525] The server analyzes the test results and emotion recognition results in an integrated manner, and generates a detailed report to notify the administrator via email or dashboard notification.

[1526] Software used:

[1527] Email sending system (e.g., SMTP server)

[1528] Dashboard notification systems (e.g. Grafana)

[1529] Examples:

[1530] The server generates a report stating "SQL injection vulnerability detected. User expressed concern about the consequences" and notifies the administrator via email.

[1531] With these configurations, the present invention can respond quickly and effectively to the latest security attack methods, and can implement security measures that take user feelings into consideration.

[1532] Example of an input prompt for a generative AI model:

[1533] Gather information on the latest security attack techniques from the following data sources and analyze the text data using natural language processing techniques.

[1534] Data sources collected: security forums, online articles, public databases

[1535] Analysis targets: SQL injection attacks, JavaScript injection, user input fields

[1536] Based on the analysis results, automatically generate a security test program and run the test in a virtual environment. In addition, recognize the user's emotions (facial expressions, tone of voice, input patterns), comprehensively analyze the results, and notify the administrator.

[1537] The above is the details of the mode for carrying out the invention.

[1538] The flow of the identification process in the second embodiment will be described with reference to FIG.

[1539] Step 1: Gather information

[1540] The server collects information about the latest security attack techniques from trusted sources. Specifically, it uses RSS feed readers and web scraping tools to gather data from security forums, online articles, and public databases. The input to this collection process is the URL of the information source or the RSS feed link, and the output is a database that stores the collected security-related information.

[1541] Specific operation: The server retrieves the article "New SQL Injection Attack Technique" from "Security Blog XYZ" via an RSS feed and saves it in the database.

[1542] Step 2: Natural Language Analysis

[1543] The information collected by the server is analyzed using natural language processing technology. The input is security-related information stored in a database, and the output is characteristic information on attack methods extracted through analysis. Specifically, the NLTK library and Spacy are used to tokenize text data, extract keywords, and perform contextual analysis.

[1544] Specific operation: The server tokenizes the article from "Security Blog XYZ" and extracts keywords such as "SQL injection," "database," and "invalid input."

[1545] Step 3: Generate security test programs

[1546] Based on the analysis results, the server automatically generates a security test program using a generative AI model. The input is the analyzed feature information, and the output is the generated security test program. Specifically, a prompt statement is input into the generative AI model, and the result is used to generate a test script.

[1547] How it works: The server inputs the prompt "Generate a script that simulates an SQL injection attack" into the AI ​​model, and generates a test script containing an SQL query such as "SELECT FROM users WHERE user_id = '1' OR '1'='1'".

[1548] Step 4: Test Run

[1549] The server runs the generated security test program in a virtual environment or container. The input is the generated test program and the system under test, and the output is the test execution results. By using a virtual environment or container, vulnerability assessment can be performed without affecting the actual system.

[1550] Specific operation: The server launches a Docker container, deploys the web application to be tested, and runs the generated test script to check for vulnerabilities.

[1551] Step 5: Emotion Recognition

[1552] The server uses an emotion engine to recognize the user's emotions. The input is data such as the user's facial expressions, tone of voice, and input patterns, and the output is analyzed emotional data of the user. Specifically, it uses facial expression recognition APIs and voice analysis APIs to collect and analyze changes in the user's emotions in real time.

[1553] Specific operation: While the user is checking the system's security test results, the server analyzes the webcam footage using a facial expression recognition API to detect anxiety or surprise from the user's facial expressions.

[1554] Step 6: Results analysis and notification

[1555] The server performs an integrated analysis of the test results and emotion recognition results, and generates a detailed report to notify the administrator. The input is the test execution results and emotion data, and the output is a detailed report. Notification methods include email and dashboard notifications.

[1556] Specific behavior: The server generates a report stating "SQL injection vulnerability detected. User expressed concern about the consequences" and notifies the administrator via email.

[1557] (Application example 2)

[1558] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."

[1559] In recent years, security attack methods have rapidly evolved, and conventional countermeasures are no longer sufficient to deal with them. Furthermore, the emotions felt by users while operating a system are an important factor that cannot be ignored, and there is a need to realize more effective security measures that take this into consideration. However, it is technically difficult to simultaneously address these factors, and currently no suitable system exists.

[1560] The identification process by the identification processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means. In this invention, the server includes means for collecting information on security attack methods from reliable information sources, means for analyzing the collected information using natural language processing technology and extracting characteristics of the attack methods, means for automatically generating a security test program based on the extracted characteristics, means for executing the generated security test program on the target system and evaluating vulnerabilities, means for analyzing a user's facial expressions, voice, and input patterns using emotion analysis technology and collecting user emotion data, and means for comprehensively analyzing the vulnerability assessment results and the emotion data and notifying the administrator. This makes it possible to respond quickly and effectively to the latest security attack methods and obtain feedback based on the user's emotions.

[1561] A "trusted information source" is a source that provides up-to-date and reliable information, such as a security forum or academic paper database.

[1562] "Natural language processing technology" is a technology that analyzes text data and extracts keywords and features based on context.

[1563] A "security test program" is a program that is automatically generated based on analyzed information to detect system vulnerabilities.

[1564] A "virtual environment" is a virtualized environment in which programs can be tested without affecting the actual system.

[1565] A "container" is a technology that packages an application's execution environment into a single package and executes it in a virtually isolated manner.

[1566] "Emotion analysis technology" is a technology that analyzes emotions from a user's facial expressions, voice, and input patterns.

[1567] "User emotion data" refers to information about a user's emotions collected using emotion analysis technology.

[1568] "Vulnerability assessment" is the process of running a generated security test program to assess the vulnerability of a system.

[1569] "Notifying the administrator" refers to the act of reporting the vulnerability assessment results and user emotional data to the administrator and urging them to take appropriate measures.

[1570] The present invention is a system that collects and analyzes the latest information on security attack techniques, executes security test programs automatically generated based on the analysis results, and further recognizes user emotions to improve the accuracy of security countermeasures. Specific embodiments of the present invention are described below.

[1571] System configuration

[1572] Information Collection Module

[1573] The server collects information about security attack methods from reliable sources, such as security forums and academic paper databases, and uses the requests library for its hardware and software.

[1574] Natural Language Processing Module

[1575] The server analyzes the collected information using natural language processing technology to extract characteristics of the attack method. Specifically, it tokenizes the text data and performs keyword extraction and context analysis. The software used is the spacy library.

[1576] Program Generation Module

[1577] The server automatically generates a security test program based on the analyzed information. This program contains code to reproduce the extracted characteristics and detect system vulnerabilities. The code is generated using a text editor.

[1578] Test Execution Module

[1579] The server runs the generated security test program in a virtual environment to evaluate vulnerabilities. By using a virtual environment or container, it is possible to perform testing without affecting the actual system. The hardware used is a virtualizable server, and the software uses Docker or other virtualization tools.

[1580] Emotion Recognition Module

[1581] The device uses emotion analysis technology to analyze the user's facial expressions, voice, and input patterns to collect user emotion data. Data is collected using the camera and microphone and analyzed using the cv2 and emotion_recognition libraries.

[1582] Results Analysis and Notification Module

[1583] The server analyzes the test results and emotion recognition results and notifies administrators. Specifically, it reports the results via email, dashboard notifications, and real-time alerts. The software used is the requests library, which sends data to a web service that notifies users appropriately.

[1584] Specific examples

[1585] For example, the server accesses a security forum to collect articles about the latest XSS attack techniques and stores them in a database. It then uses natural language processing technology to analyze the collected information and extracts features of XSS attacks, JavaScript injection, and user input fields. Based on these features, the server generates a security test program that simulates the injection of a malicious script into a user input field, and runs the test in a virtual environment.

[1586] The device uses a camera and microphone to collect the user's facial expressions and tone of voice while the user is operating the system, and analyzes the emotional data. Finally, the test results and the user's emotional data are analyzed comprehensively, and the system notifies the administrator of the detailed results, stating that "a specific input field was found to be vulnerable and the user expressed anxiety."

[1587] Prompt Sentence Examples

[1588] "Please generate a security test program that includes the latest XSS attack techniques and run it in a virtual environment. Also, please analyze the user's facial expressions and tone of voice, and report any feelings of anxiety or other anxiety the user may have."

[1589] By using the above specific means, the present invention enables quick and effective responses to the latest security attack methods, and also provides feedback based on user emotions, thereby improving the accuracy of security measures.

[1590] The flow of the specific processing in the application example 2 will be described with reference to FIG.

[1591] Step 1:

[1592] The server collects the latest information on security attack techniques from trusted sources, specifically by accessing security forums and academic paper databases to retrieve relevant articles and papers, using the requests library to collect data via an Internet connection.

[1593] Input: URL of a security forum or academic paper database

[1594] Output: Raw data on attack techniques (articles and papers)

[1595] Step 2:

[1596] The information collected by the server is analyzed using natural language processing technology. Specifically, the text data is tokenized using the spacy library, and keywords and contextual analysis are performed to extract the characteristics of attack methods.

[1597] Input: Raw data on attack techniques (articles and papers)

[1598] Output: Characteristics of the analyzed attack method (e.g., "XSS attack," "JavaScript injection," etc.)

[1599] Step 3:

[1600] The server automatically generates a security test program based on the extracted features. Specifically, it uses a programming language to reproduce the features and generate code to detect system vulnerabilities. The code is constructed using a text editor.

[1601] Input: Analyzed attack characteristics

[1602] Output: Security test program code

[1603] Step 4:

[1604] The server runs the generated security test program in a virtual environment. Specifically, a virtual environment is set up using a virtualization tool such as Docker, and the test program is run. This step evaluates the system's vulnerabilities.

[1605] Input: Security test program code

[1606] Output: Vulnerability assessment results

[1607] Step 5:

[1608] The device uses emotion analysis technology to analyze the user's facial expressions, voice, and input patterns to collect emotion data. Specifically, data is collected using the camera and microphone, and analyzed using the cv2 and emotion_recognition libraries.

[1609] Input: facial expression data, voice data, input patterns during user operation

[1610] Output: Analyzed user emotion data

[1611] Step 6:

[1612] The server analyzes the test results and emotion recognition results in an integrated manner and notifies the administrator via email or a web dashboard using the requests library.

[1613] Input: Vulnerability assessment results, analyzed user emotion data

[1614] Output: Notification message to administrator (e.g. "A specific input field is vulnerable and the user expressed concern")

[1615] Through the above steps, the system of the present invention can respond quickly and effectively to the latest security attack methods, and can obtain feedback based on the user's emotions, thereby improving the accuracy of security measures.

[1616] The specific processing unit 290 transmits the result of the specific processing to the robot 414. In the robot 414, the control unit 46A causes the speaker 240 and the control target 443 to output the result of the specific processing. The microphone 238 acquires voice indicating a user input regarding the result of the specific processing. The control unit 46A transmits voice data indicating the user input acquired by the microphone 238 to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the voice data.

[1617] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[1618] In the above embodiment, an example was given in which the specific processing is performed by the data processing device 12, but the technology of the present disclosure is not limited to this, and the specific processing may be performed by the robot 414.

[1619] The emotion identification model 59 as an emotion engine may determine the user's emotion according to a specific mapping. Specifically, the emotion identification model 59 may determine the user's emotion according to an emotion map (see FIG. 9), which is a specific mapping. Similarly, the emotion identification model 59 may determine the robot's emotion, and the identification processing unit 290 may perform identification processing using the robot's emotion.

[1620] FIG. 9 is a diagram illustrating an emotion map 400 on which multiple emotions are mapped. In the emotion map 400, emotions are arranged in concentric circles radiating from the center. Emotions closer to the center of the concentric circles are more primitive. Emotions representing states and actions arising from a state of mind are arranged on the outer edges of the concentric circles. The concept of emotion includes both affect and mental states. Emotions generally generated from reactions occurring in the brain are arranged on the left side of the concentric circles. Emotions generally induced by situational judgment are arranged on the right side of the concentric circles. Emotions generally generated from reactions occurring in the brain and induced by situational judgment are arranged on the upper and lower sides of the concentric circles. Furthermore, the emotion of "pleasure" is arranged on the upper side of the concentric circles, and the emotion of "discomfort" is arranged on the lower side. In this way, in the emotion map 400, multiple emotions are mapped based on the structure by which emotions are generated, and emotions that tend to occur simultaneously are mapped close to each other.

[1621] These emotions are distributed in the 3 o'clock direction on emotion map 400, and typically fluctuate between relief and anxiety. In the right half of emotion map 400, situational awareness dominates over internal sensations, resulting in a sense of calm.

[1622] The inside of emotion map 400 represents what is going on in the mind, and the outside of emotion map 400 represents behavior, so the further you go outside emotion map 400, the more visible the emotions become (the more they are expressed in behavior).

[1623] Human emotions are based on various balances, such as posture and blood sugar levels. When these balances deviate from the ideal, a state of discomfort is indicated, and when they approach the ideal, a state of pleasure is indicated. Emotions can also be created for robots, automobiles, and motorcycles, based on various balances, such as posture and remaining battery life. When these balances deviate from the ideal, a state of discomfort is indicated, and when they approach the ideal, a state of pleasure is indicated. An emotion map can be generated, for example, based on Dr. Mitsuyoshi's emotion map (Research on Voice Emotion Recognition and Emotional Brain Physiological Signal Analysis Systems, Tokushima University, Doctoral Dissertation: https: / / ci.nii.ac.jp / naid / 500000375379). The left half of the emotion map lists emotions belonging to the "reaction" domain, where sensation is dominant. The right half of the emotion map lists emotions belonging to the "situation" domain, where situational awareness is dominant.

[1624] The emotion map defines two emotions that promote learning. One is a negative emotion on the situation side, around the middle of "repentance" or "reflection." In other words, this occurs when the robot experiences negative emotions such as "I never want to feel this way again" or "I don't want to be scolded again." The other is a positive emotion on the response side, around "desire." In other words, this occurs when the robot experiences positive feelings such as "I want more" or "I want to know more."

[1625] The emotion identification model 59 inputs user input into a pre-trained neural network, obtains emotion values ​​indicating each emotion shown in the emotion map 400, and determines the user's emotion. This neural network is pre-trained based on multiple pieces of training data that are combinations of user input and emotion values ​​indicating each emotion shown in the emotion map 400. Furthermore, this neural network is trained so that emotions that are located close to each other have similar values, as in the emotion map 900 shown in FIG. 10. FIG. 10 shows an example in which multiple emotions, "relieved," "calm," and "reassuring," have similar emotion values.

[1626] The system according to the present disclosure has been described above mainly with respect to the functions of the data processing device 12, but the system according to the present disclosure is not necessarily implemented on a server. The system according to the present disclosure may be implemented as a general information processing system. The present disclosure may be implemented, for example, as a software program running on a personal computer or an application running on a smartphone, etc. The method according to the present disclosure may be provided to users in the form of SaaS (Software as a Service).

[1627] In the above embodiment, an example was given in which the specific processing is performed by one computer 22, but the technology of the present disclosure is not limited to this, and the specific processing may be distributed and performed by a plurality of computers including the computer 22. For example, the data generation model 58 may be provided in an external device of the data processing device 12, and data may be generated in the external device in accordance with input data.

[1628] In the above embodiment, an example in which the specific processing program 56 is stored in the storage 32 has been described, but the technology of the present disclosure is not limited to this. For example, the specific processing program 56 may be stored in a portable, computer-readable, non-transitory storage medium such as a USB (Universal Serial Bus) memory. The specific processing program 56 stored in the non-transitory storage medium is installed in the computer 22 of the data processing device 12. The processor 28 executes the specific processing in accordance with the specific processing program 56.

[1629] Alternatively, the specific processing program 56 may be stored in a storage device such as a server connected to the data processing device 12 via the network 54, and the specific processing program 56 may be downloaded and installed on the computer 22 in response to a request from the data processing device 12.

[1630] It is not necessary to store all of the specific processing program 56 in a storage device such as a server connected to the data processing device 12 via the network 54, or to store all of the specific processing program 56 in the storage 32; only a portion of the specific processing program 56 may be stored.

[1631] The hardware resource for executing a specific process can be any of the following processors: An example of a processor is a CPU, which is a general-purpose processor that functions as a hardware resource for executing a specific process by executing software, i.e., a program. Another example of a processor is a dedicated electrical circuit, such as an FPGA (Field-Programmable Gate Array), a PLD (Programmable Logic Device), or an ASIC (Application Specific Integrated Circuit), which is a processor with a circuit configuration designed specifically for executing a specific process. Each processor has built-in or connected memory, and each processor uses the memory to execute the specific process.

[1632] The hardware resource that executes the specific processing may be configured with one of these various processors, or may be configured with a combination of two or more processors of the same or different types (for example, a combination of multiple FPGAs, or a combination of a CPU and an FPGA). Also, the hardware resource that executes the specific processing may be a single processor.

[1633] As an example of a system configured with a single processor, first, one processor is configured by combining one or more CPUs and software, and this processor functions as a hardware resource that executes a specific process. Second, there is a system that uses a processor that realizes the functions of an entire system including multiple hardware resources that execute a specific process on a single IC chip, as typified by SoC (System-on-a-chip). In this way, a specific process is realized using one or more of the above-mentioned various processors as hardware resources.

[1634] Furthermore, the hardware structure of these various processors can be, more specifically, an electric circuit that combines circuit elements such as semiconductor devices. The specific processing described above is merely an example. Therefore, it goes without saying that unnecessary steps may be deleted, new steps may be added, or the processing order may be rearranged, without departing from the spirit of the invention.

[1635] The above-described description and illustrations are a detailed explanation of the parts related to the technology of the present disclosure and are merely an example of the technology of the present disclosure. For example, the above description of the configuration, functions, actions, and effects is an explanation of an example of the configuration, functions, actions, and effects of the parts related to the technology of the present disclosure. Therefore, it goes without saying that unnecessary parts may be deleted, new elements may be added, or replacements may be made to the above-described description and illustrations within the scope of the gist of the technology of the present disclosure. Furthermore, to avoid confusion and facilitate understanding of the parts related to the technology of the present disclosure, the above-described description and illustrations omit explanations of common technical knowledge that do not require particular explanation to enable the implementation of the technology of the present disclosure.

[1636] All publications, patent applications, and technical standards mentioned in this specification are herein incorporated by reference to the same extent as if each individual publication, patent application, or technical standard was specifically and individually indicated to be incorporated by reference.

[1637] The following is further disclosed regarding the above embodiment.

[1638] Understood. Below is a draft of the patent claims based on the characteristic parts of the invention.

[1639] (Claim 1)

[1640] A means of collecting information on security attack techniques from reliable information sources;

[1641] A method for analyzing collected information using natural language processing technology and extracting characteristics of attack methods;

[1642] A means for automatically generating a security test program based on the extracted features;

[1643] A means for executing the generated security test program on a target system to evaluate vulnerabilities;

[1644] a means for notifying the administrator of the evaluation results;

[1645] A system including:

[1646] (Claim 2)

[1647] 10. The system of claim 1, further comprising means for executing a test program using a virtual environment or container to perform vulnerability assessment without impacting a live system.

[1648] (Claim 3)

[1649] 10. The system of claim 1, further comprising means for using security forums, blogs, and academic paper databases as trusted information sources.

[1650] "Example 1"

[1651] (Claim 1)

[1652] A means of collecting information on security attack techniques from reliable information sources;

[1653] A method for analyzing collected information using natural language processing technology and extracting characteristics of attack methods;

[1654] A means for automatically generating a security test program based on the extracted features;

[1655] A means for executing the generated security test program in a virtual environment or a container;

[1656] a means of logging and evaluating the results of test execution;

[1657] A means for notifying the administrator of the evaluation results via email or dashboard notification;

[1658] A system including:

[1659] (Claim 2)

[1660] 10. The system of claim 1, further comprising means for executing a test program using a virtual environment or container to perform vulnerability assessment without impacting a live system.

[1661] (Claim 3)

[1662] 10. The system of claim 1, further comprising means for using security forums, blogs, and academic paper databases as trusted information sources.

[1663] "Application Example 1"

[1664] (Claim 1)

[1665] A means of collecting information on security attack techniques from reliable information sources;

[1666] A method for analyzing collected information using natural language processing technology and extracting characteristics of attack methods;

[1667] A means for automatically generating a security test program based on the extracted features;

[1668] A means for executing the generated security test program on a target system to evaluate vulnerabilities;

[1669] a means for notifying the administrator of the evaluation results;

[1670] A method for easily testing the vulnerabilities of users' websites and systems on their smartphones,

[1671] A system including:

[1672] (Claim 2)

[1673] 10. The system of claim 1, further comprising means for executing a test program using a virtual environment or container to perform vulnerability assessment without impacting a live system.

[1674] (Claim 3)

[1675] 10. The system of claim 1, further comprising means for using security forums, blogs, and academic paper databases as trusted information sources.

[1676] "Example 2: Combining Emotion Engines"

[1677] (Claim 1)

[1678] A means of collecting information on security attack techniques from reliable information sources;

[1679] A method for analyzing collected information using natural language processing technology and extracting characteristics of attack methods;

[1680] A means for automatically generating a security test program based on the extracted features;

[1681] A means for executing the generated security test program on a target system to evaluate vulnerabilities;

[1682] a means for notifying the administrator of the evaluation results;

[1683] means for recognizing a user's emotion;

[1684] means for analyzing the results based on the recognized emotions;

[1685] A system including:

[1686] (Claim 2)

[1687] 10. The system of claim 1, further comprising means for executing a test program using a virtual environment or container to perform vulnerability assessment without impacting a live system.

[1688] (Claim 3)

[1689] 10. The system of claim 1, further comprising means for using expert forums, online articles, and public databases as reliable information sources.

[1690] "Application example 2 when combining emotion engines"

[1691] (Claim 1)

[1692] A means of collecting information on security attack techniques from reliable information sources;

[1693] A method for analyzing collected information using natural language processing technology and extracting characteristics of attack methods;

[1694] A means for automatically generating a security test program based on the extracted features;

[1695] A means for executing the generated security test program on a target system to evaluate vulnerabilities;

[1696] A means for analyzing a user's facial expressions, voice, and input patterns using emotion analysis technology to collect emotion data of the user;

[1697] A method for comprehensively analyzing vulnerability assessment results and emotion data and notifying administrators;

[1698] A system including:

[1699] (Claim 2)

[1700] 10. The system of claim 1, further comprising means for executing a test program using a virtual environment or container to perform vulnerability assessment without impacting a live system.

[1701] (Claim 3)

[1702] 10. The system of claim 1, further comprising means for using security forums, academic paper databases as trusted information sources. [Explanation of symbols]

[1703] 10, 210, 310, 410 Data Processing Systems 12 Data Processing Device 14 Smart Devices 214 Smart Glasses 314 Headset-type terminal 414 Robot< / url:> < / url:> < / url:> < / url:>

Claims

1. A means of collecting information on security attack techniques from reliable information sources; A method for analyzing collected information using natural language processing technology and extracting characteristics of attack methods; A means for automatically generating a security test program based on the extracted features; A means for executing the generated security test program on a target system to evaluate vulnerabilities; a means for notifying the administrator of the evaluation results; A system including:

2. The system of claim 1 , further comprising means for executing a test program using a virtual environment or a container to perform vulnerability assessment without affecting an actual system.

3. The system of claim 1 , further comprising means for using security forums, blogs, and academic paper databases as trusted information sources.

Citation Information

Patent Citations

  • Persona chatbot control method and system

    JP2022180282A