System

The system efficiently collects and analyzes data from intelligence agencies and the dark web to train an AI model for simulated attacks, improving security measures against evolving cyber threats.

JP2026014289APending Publication Date: 2026-01-29SOFTBANK GROUP CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024115286
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-07-18
Publication Date
2026-01-29

AI Technical Summary

Technical Problem

Existing security measures are insufficient to counteract the constantly evolving cyber-attacks, requiring significant effort and cost for information gathering and analysis, and there is a need for systems that can quickly learn and enhance security measures against the latest attack methods.

Method used

A system that collects data from intelligence agencies and the dark web, analyzes it to extract and classify attack information, trains an AI model, generates simulated attacks, and reports on the results to diagnose and strengthen security measures.

Benefits of technology

Enables rapid learning of the latest cyber-attack techniques and enhances security measures by conducting simulated attacks, increasing resistance to evolving threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026014289000001_ABST
    Figure 2026014289000001_ABST
Patent Text Reader

Abstract

A system is provided.SOLUTION: A system including means for collecting data on the latest attack methods from information providers and dark web, means for analyzing the collected data to extract and classify important information, means for learning an AI model based on the analyzed data, means for generating a simulated attack using the learned AI model, means for executing the simulated attack and collecting and analyzing the result, and means for generating a report based on the result of the executed simulated attack.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The technology of the present disclosure relates to a system. [Background technology]

[0002] Patent document 1 discloses a persona chatbot control method performed by at least one processor, the method including the steps of receiving a user utterance, adding the user utterance to a prompt including an instruction sentence related to a description of the chatbot character, encoding the prompt, and inputting the encoded prompt into a language model to generate a chatbot utterance in response to the user utterance. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Publication No. 2022-180282 Summary of the Invention [Problem to be solved by the invention]

[0004] In today's Internet environment, new attack methods are constantly emerging, and traditional security measures are often insufficient to deal with them. Companies and organizations are also required to regularly review their security measures to ensure they are resistant to the latest attack methods. However, the information gathering and analysis required, as well as the implementation of simulated attacks, requires a great deal of effort and cost. In this environment, there is a strong demand for systems that can quickly and efficiently learn about the latest attack methods and diagnose and strengthen a company's security environment. [Means for solving the problem]

[0005] The present invention provides a system including means for collecting data on the latest attack techniques from intelligence agencies and the dark web, means for analyzing the collected data to extract and classify important information, means for training an AI model based on the analyzed data, means for generating simulated attacks using the trained AI model, means for executing the simulated attacks and collecting and analyzing the results, and means for generating reports based on the results of the executed simulated attacks, thereby making it possible to learn the latest attack techniques in real time and diagnose and strengthen security measures.

[0006] Definitions of important words

[0007] "Information provider" refers to an institution or organization that provides security-related information.

[0008] The "dark web" refers to a part of the internet that cannot be found through regular search engines and is accessed using specific tools and settings, often serving as a venue for illegal activity and highly anonymous communication.

[0009] "Attack methods" refer to the techniques and tactics used to carry out cyber attacks.

[0010] "Data" refers to a collection of information obtained from intelligence agencies and the dark web.

[0011] "Collect" refers to the act of gathering information.

[0012] "Analyzing" refers to the act of examining collected data and extracting meaningful information.

[0013] "Extraction" refers to the act of extracting necessary information from a large amount of data.

[0014] "Classifying" refers to the act of organizing extracted information into specific categories or types.

[0015] An "AI model" refers to an algorithm or system that has been trained to perform a specific task using artificial intelligence.

[0016] "Learning" refers to the process by which an AI model acquires patterns and features based on data.

[0017] A "mock attack" refers to a simulated attack that imitates an actual attack.

[0018] "Generate" refers to the act of creating something new.

[0019] "Executing" refers to the act of actually carrying out a simulated attack.

[0020] "Results" refers to the data and reactions obtained after a simulated attack is carried out.

[0021] "Collect" refers to the act of gathering results.

[0022] "Analyzing" refers to the act of examining the collected results and finding meaningful information.

[0023] A "report" refers to the results of an analysis organized and compiled in a document or report format.

[0024] "Generate" refers to the act of creating a new report. [Brief explanation of the drawings]

[0025] [Figure 1] 1 is a conceptual diagram showing an example of the configuration of a data processing system according to a first embodiment. [Figure 2] 1 is a conceptual diagram showing an example of main functions of a data processing device and a smart device according to a first embodiment. [Figure 3] FIG. 10 is a conceptual diagram showing an example of the configuration of a data processing system according to a second embodiment. [Figure 4] FIG. 10 is a conceptual diagram showing an example of main functions of a data processing device and smart glasses according to a second embodiment. [Figure 5] FIG. 10 is a conceptual diagram showing an example of the configuration of a data processing system according to a third embodiment. [Figure 6] FIG. 11 is a conceptual diagram showing an example of main functions of a data processing device and a headset-type terminal according to a third embodiment. [Figure 7] FIG. 10 is a conceptual diagram showing an example of the configuration of a data processing system according to a fourth embodiment. [Figure 8] FIG. 10 is a conceptual diagram showing an example of main functions of a data processing device and a robot according to a fourth embodiment. [Figure 9] 1 shows an emotion map onto which multiple emotions are mapped. [Figure 10] 1 shows an emotion map onto which multiple emotions are mapped. [Figure 11] FIG. 3 is a sequence diagram showing a processing flow of the data processing system according to the first embodiment. [Figure 12] FIG. 10 is a sequence diagram showing the flow of processing in the data processing system in Application Example 1. [Figure 13] FIG. 10 is a sequence diagram showing the flow of processing in the data processing system according to the second embodiment when an emotion engine is combined. [Figure 14] FIG. 10 is a sequence diagram showing the flow of processing in the data processing system in Application Example 2 when an emotion engine is combined. DETAILED DESCRIPTION OF THE INVENTION

[0026] An example of an embodiment of a system according to the technology of the present disclosure will be described below with reference to the accompanying drawings.

[0027] First, the terms used in the following description will be explained.

[0028] In the following embodiments, a coded processor (hereinafter simply referred to as a "processor") may be a single arithmetic device or a combination of multiple arithmetic devices. Furthermore, a processor may be a single type of arithmetic device or a combination of multiple types of arithmetic devices. Examples of arithmetic devices include a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), a GPGPU (General-Purpose computing on Graphics Processing Units), and an APU (Accelerated Processing Unit).

[0029] In the following embodiments, a coded RAM (Random Access Memory) is a memory in which information is temporarily stored and is used as a working memory by a processor.

[0030] In the following embodiments, the coded storage is one or more non-volatile storage devices that store various programs, various parameters, etc. Examples of non-volatile storage devices include flash memory (SSD (Solid State Drive)), magnetic disks (e.g., hard disks), and magnetic tapes.

[0031] In the following embodiments, a communication I / F (Interface) with a symbol is an interface including a communication processor, an antenna, etc. The communication I / F controls communication between multiple computers. Examples of communication standards applied to the communication I / F include wireless communication standards including 5G (5th Generation Mobile Communication System), Wi-Fi (registered trademark), Bluetooth (registered trademark), etc.

[0032] In the following embodiments, "A and / or B" is synonymous with "at least one of A and B." In other words, "A and / or B" means that it may be only A, only B, or a combination of A and B. Furthermore, in this specification, the same concept as "A and / or B" is also applied when three or more things are expressed connected by "and / or."

[0033] [First embodiment]

[0034] FIG. 1 shows an example of the configuration of a data processing system 10 according to the first embodiment.

[0035] 1, a data processing system 10 includes a data processing device 12 and a smart device 14. An example of the data processing device 12 is a server.

[0036] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[0037] The smart device 14 includes a computer 36, a reception device 38, an output device 40, a camera 42, and a communication I / F 44. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The reception device 38, the output device 40, and the camera 42 are also connected to the bus 52.

[0038] The reception device 38 includes a touch panel 38A, a microphone 38B, and the like, and receives user input. The touch panel 38A detects contact with an indicator (for example, a pen or a finger) to receive user input by the touch of the indicator. The microphone 38B detects the user's voice to receive user input by voice. The control unit 46A transmits data indicating the user input received by the touch panel 38A and the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the data indicating the user input.

[0039] The output device 40 includes a display 40A and a speaker 40B, and presents data to the user 20 by outputting the data in a form of expression that the user 20 can perceive (for example, audio and / or text). The display 40A displays visible information such as text and images in accordance with instructions from the processor 46. The speaker 40B outputs audio in accordance with instructions from the processor 46. The camera 42 is a compact digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor.

[0040] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 control the exchange of various information between the processor 46 and the processor 28 via the network 54.

[0041] FIG. 2 shows an example of the main functions of the data processing device 12 and the smart device 14.

[0042] 2, in the data processing device 12, a specific process is performed by the processor 28. A specific processing program 56 is stored in the storage 32. The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific process is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[0043] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[0044] In the smart device 14, the processor 46 performs the reception output process. The storage 50 stores a reception output program 60. The reception output program 60 is used in conjunction with the specific processing program 56 by the data processing system 10. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.

[0045] Next, a description will be given of the specific processing performed by the specific processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."

[0046] patent specification

[0047] The present invention relates to a system for efficiently learning the latest cyber-attack techniques and conducting simulated attacks. This system has the following functions:

[0048] 1. Information collection module

[0049] The server collects data on the latest attack techniques from intelligence agencies and the dark web by accessing the intelligence agencies' APIs to retrieve the necessary data, and also scrapes data from forums and marketplaces on the dark web.

[0050] 2. Data Analysis Module

[0051] The device analyzes the collected data. First, it processes the collected data to extract necessary information and organizes information about attack methods. Then, it classifies the extracted information into attack categories such as phishing, malware, and DDoS.

[0052] 3. Model Learning Module

[0053] The server trains the AI ​​model based on the analyzed data, using the analyzed information to train machine learning algorithms and generate models that can identify the latest attack techniques.

[0054] 4. Attack Simulation Module

[0055] Users can use the trained AI model to generate mock attacks, deploy the resulting payloads in their security environment, and observe the response. For example, in the case of a phishing attack, they can send mock phishing emails to their company.

[0056] 5. Result Collection Module

[0057] After conducting the simulated attacks, users collect the results, such as click rates for phishing emails sent and the number of employee reports.

[0058] 6. Report Generation Module

[0059] The device analyzes the collected results and generates a detailed report that includes an analysis of the results of the simulated attacks and recommendations for improving security measures.

[0060] Specific examples

[0061] As an example, let's consider a specific company using this system. The company's server begins collecting data from government security agency APIs and the dark web. Next, the device analyzes the data, extracting and classifying important information about phishing and malware attacks. The server uses the analyzed data to train an AI model, which then generates phishing emails based on that model. The user then sends these mock phishing emails to the company and collects responses from employees. Finally, the device compiles the results into a detailed report, assessing the company's security measures and suggesting areas for improvement.

[0062] Through the above process, the system of the present invention increases resistance to the latest cyber attacks and enables the implementation of effective security measures.

[0063] The processing flow will be explained below.

[0064] Processing flow

[0065] Step 1:

[0066] The server accesses the API of the information provider to obtain data on the latest attack techniques. Specifically, it sends a request to the security agency's API endpoint and receives a response. The response contains information such as the latest attack techniques, their overview, and the date and time of occurrence.

[0067] Step 2:

[0068] The server scrapes data from forums and marketplaces on the dark web. Using specialized scraping tools, it extracts text information from specific web pages. The extracted data includes attack techniques, sales information, and related discussions.

[0069] Step 3:

[0070] The terminal analyzes the data received from the server. First, it parses the acquired JSON data and scraped data and converts it into a meaningful format. This allows it to extract the necessary information (type of attack method, details, date and time of occurrence, etc.).

[0071] Step 4:

[0072] The terminal classifies the extracted information into specific categories, such as phishing attacks, malware attacks, DDoS attacks, etc. This classification allows the data to be used efficiently in subsequent processing.

[0073] Step 5:

[0074] The server trains the AI ​​model based on the classified data. It uses the analyzed information to train machine learning algorithms and generate models that can identify the latest attack techniques. This includes data preprocessing, model training, and evaluation.

[0075] Step 6:

[0076] Users can use the trained AI model to generate simulated attacks, generating specific attack payloads (e.g., phishing email content or malware code) based on attack patterns obtained from the AI ​​model.

[0077] Step 7:

[0078] The user deploys the generated simulated attacks in their company's security environment. For example, they send simulated phishing emails to employees' email addresses and observe the responses. The user then monitors how the attacks are countered.

[0079] Step 8:

[0080] Users collect the results of their simulated attacks, including click rates for phishing emails, the number of reports, and the number of malware detected, which will be used for subsequent analysis.

[0081] Step 9:

[0082] The device generates a detailed report based on the collected results, including an analysis of the simulated attacks, an evaluation of security measures, and suggestions for improvement. The report also includes visualization and statistical information of the results.

[0083] Through the above processing steps, the system of the present invention increases resistance to the latest cyber attacks and enables the implementation of effective security measures.

[0084] Example 1

[0085] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."

[0086] The latest cyberattack methods are evolving daily, and there is a need to quickly implement effective security measures to counter them. However, existing security measures lack systems that can efficiently learn the latest attack methods and conduct simulated attacks, leaving companies and organizations vulnerable to advanced cyberattacks.

[0087] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.

[0088] In this invention, the server includes means for collecting data on the latest attack techniques from intelligence agencies and the dark web, means for analyzing the collected data to extract and classify important information, and means for training an AI model using a machine learning algorithm based on the analyzed data. This makes it possible to quickly and efficiently grasp the latest cyber-attack techniques and to improve security measures by conducting simulated attacks.

[0089] An "information provider" refers to an organization or institution that collects and provides security-related information.

[0090] The "dark web" refers to a group of highly anonymous websites that cannot be accessed through regular search engines.

[0091] "Attack methods" refer to the specific techniques and tactics used in cyber attacks.

[0092] "Data collection methods" refer to the methods and tools used to obtain information.

[0093] "API Access" means access to external data or services through an application programming interface.

[0094] "Web scraping" refers to the technique of extracting information from websites.

[0095] "Data analysis methods" refer to methods and tools used to process and analyze collected data to extract meaningful information.

[0096] A "machine learning algorithm" refers to a computational method for learning patterns and rules based on data.

[0097] "AI model" refers to a model of artificial intelligence that has been trained by machine learning algorithms and is capable of performing specific tasks.

[0098] A "payload" refers to the data or code that is actually sent to the target in a cyber attack.

[0099] "Security environment" refers to the overall security measures and infrastructure of an organization or system.

[0100] "Report generation means" refers to methods and tools for generating reports based on collected and analyzed information.

[0101] The present invention relates to a system for efficiently learning the latest cyber-attack techniques and conducting simulated attacks. This system collects data from intelligence agencies and the dark web, analyzes the collected data, trains an AI model based on the analyzed data, generates simulated attacks using the trained AI model, and generates detailed reports by collecting and analyzing the results of the simulated attacks.

[0102] Information gathering

[0103] The server collects data on the latest attack techniques from the APIs of intelligence providers and the dark web. Intelligence providers often have public APIs that provide security information. The server accesses the APIs using HTTP requests and retrieves information in JSON format. It also uses web scraping libraries such as Python's Beautiful Soup and Scrapy to collect information from the dark web. The collected data is stored in an SQL or NoSQL database.

[0104] Data analysis

[0105] The device takes the collected data and preprocesses it using NLP tools (e.g., NLTK or SpaCy). Preprocessing includes tokenizing the text and removing stop words. The analyzed data is then classified into attack categories such as phishing, malware, and DDoS. Algorithms such as decision trees and support vector machines (SVM) are used for classification. The classified data is then stored in JSON format or in a database.

[0106] Model learning

[0107] The server trains an AI model based on the analyzed data. The server builds a neural network model using machine learning libraries such as TensorFlow and PyTorch. The training process includes data preprocessing, model construction, training, and evaluation. The trained model is deployed as an API server and made accessible to other system components.

[0108] Attack Simulation

[0109] Users use the trained AI model to generate mock attack payloads. In this process, users send requests to the model API and receive the generated payloads. Mock attack payloads include, for example, phishing emails and malware executable files. Users then deploy these payloads in their security environment and monitor their impact.

[0110] Results collection and report generation

[0111] The user collects the results of the simulated attacks, including click rates, the number of employee reports, and security system log data. The terminal analyzes the collected data and generates a detailed report that includes the results of the simulated attacks and an evaluation and improvement of security measures. The report is generated and provided to the user in a format that includes graphs and charts using Pandas and Matplotlib.

[0112] Specific examples

[0113] For example, if a particular company uses this system, the company's server collects data on attack methods from government security agency APIs and the dark web. The device analyzes the data, extracting and classifying important information about phishing and malware attacks. The server uses the analyzed data to train an AI model, which then generates phishing emails based on that model. The user sends these mock phishing emails internally and observes and records employee reactions. Finally, the device compiles the results into a detailed report, assessing the company's security measures and recommending areas for improvement.

[0114] Prompt Sentence Examples

[0115] "Write a Python script to collect data on the latest phishing attack techniques, train an AI model based on the analysis results, and generate simulated phishing attacks."

[0116] The above is an embodiment of the present invention.

[0117] The flow of the identification process in the first embodiment will be described with reference to FIG.

[0118] Step 1: Gather information

[0119] The server collects data on the latest attack techniques from intelligence agencies and the dark web.

[0120] Specifically, the server performs the following operations.

[0121] 1.1 The server sends an HTTP request to the provider's API endpoint, including the API key and the search query.

[0122] Input: API endpoint information, API key, search query

[0123] Output: JSON data obtained as an API response

[0124] 1.2 The server analyzes the JSON data received as an API response and extracts the necessary information.

[0125] Input: JSON data of API response

[0126] Output: Data about the extracted attack techniques

[0127] 1.3 The server accesses dark web forums and marketplaces and scrapes data using Beautiful Soup and Scrapy.

[0128] Input: Dark Web website URL

[0129] Output: Data on attack techniques obtained through scraping

[0130] 1.4 The server stores the collected data in a SQL or NoSQL database.

[0131] Input: Data on extracted attack techniques, data obtained by scraping

[0132] Output: Data stored in the database

[0133] Step 2: Data analysis

[0134] The terminal analyzes the collected data.

[0135] Specifically, the terminal performs the following operations.

[0136] 2.1 The terminal retrieves the collected data from the database.

[0137] Input: Database connection information

[0138] Output: Retrieved data

[0139] 2.2 The device preprocesses the data using NLP tools (NLTK or SpaCy), which includes tokenizing the text and removing stop words.

[0140] Input: Retrieved data

[0141] Output: Preprocessed data

[0142] 2.3 The device classifies the pre-processed data into attack categories such as phishing, malware, DDoS, etc. It uses algorithms such as decision trees and SVM for classification.

[0143] Input: Preprocessed data

[0144] Output: Data categorized by attack category

[0145] 2.4 The device stores the classified data in JSON format or in a database.

[0146] Input: Classified data

[0147] Output: JSON formatted data or data stored in a database

[0148] Step 3: Model training

[0149] The server trains the AI ​​model based on the analyzed data.

[0150] Specifically, the server performs the following operations.

[0151] 3.1 The server retrieves the parsed data from the database.

[0152] Input: Database connection information

[0153] Output: Retrieved data

[0154] 3.2 The server builds the neural network model using TensorFlow and PyTorch libraries.

[0155] Input: Acquired data, machine learning library (TensorFlow, PyTorch)

[0156] Output: Building a neural network model

[0157] 3.3 The server trains the model using the training data. It sets the optimizer (Adam, SGD), number of epochs, and batch size.

[0158] Input: training data, optimizer, number of epochs, batch size

[0159] Output: A trained AI model

[0160] 3.4 The server saves the trained model and deploys it as an API server.

[0161] Input: A trained AI model

[0162] Output: Deployed model API

[0163] Step 4: Attack simulation

[0164] Users use the trained AI model to generate simulated attacks.

[0165] Specifically, the user performs the following operations.

[0166] 4.1 The user sends a request to the model API to generate a mock attack payload, including attack category and target information.

[0167] Input: Model API endpoint, request parameters (attack category, target information)

[0168] Output: Generated mock attack payload

[0169] 4.2 The user deploys the generated payload in their security environment, for example by sending a phishing email using the Gmail API.

[0170] Input: Generated payload, security environment information

[0171] Output: Deployed payload

[0172] 4.3 Users monitor the security environment for responses during simulated attacks, using syslog and incident response systems.

[0173] Input: Security environment information, mock attack payload

[0174] Output: Reaction data of the monitored security environment

[0175] Step 5: Collect results

[0176] After conducting the simulated attacks, the user collects the results.

[0177] Specifically, the user performs the following operations.

[0178] 5.1 The user obtains log and activity data from the security environment.

[0179] Input: Security environment information

[0180] Output: Acquired log data and activity data

[0181] 5.2 The user calculates metrics such as click-through rates and employee reporting numbers.

[0182] Input: Captured log data and activity data

[0183] Output: Calculated metrics

[0184] 5.3 The user stores the collected data in a database.

[0185] Inputs: Calculated metrics, log data, activity data

[0186] Output: Result data stored in a database

[0187] Step 6: Generate reports

[0188] The terminal analyzes the collected results and generates a detailed report.

[0189] Specifically, the terminal performs the following operations.

[0190] 6.1 The terminal retrieves the collected result data from the database.

[0191] Input: Database connection information

[0192] Output: Acquired result data

[0193] 6.2 The device aggregates data and calculates key metrics using the Pandas library.

[0194] Input: Result data, Pandas library

[0195] Output: Aggregated data, calculated metrics

[0196] 6.3 The terminal uses the Matplotlib and Seaborn libraries to create graphs and charts.

[0197] Input: Aggregated data, calculated metrics, Matplotlib library, Seaborn library

[0198] Output: Generated graphs and charts

[0199] 6.4 The terminal will generate a report along with the generated graphs and suggest improvements to security measures.

[0200] Input: Generated graphs, charts, and analysis results

[0201] Output: Detailed report and improvement suggestions

[0202] (Application example 1)

[0203] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."

[0204] Modern cyberattack methods are becoming increasingly complex and diverse, requiring both companies and individual users to implement countermeasures against attacks that cannot be prevented by conventional methods. Furthermore, implementing effective security measures requires the rapid collection of information on the latest attack methods and the rapid application of countermeasures based on that information. However, performing these steps manually is extremely difficult, and there are limited methods for evaluating defense capabilities before an actual attack occurs.

[0205] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.

[0206] In this invention, the server includes means for collecting data on the latest attack techniques from intelligence agencies and the dark web, means for analyzing the collected data to extract and classify important information, means for training an AI model based on the analyzed data, means for generating simulated attacks using the trained AI model, means for executing the simulated attacks and collecting and analyzing their results, means for generating reports based on the results of the executed simulated attacks, and means for notifying the user of the results to their mobile device. This allows users to quickly respond to the latest attack techniques while evaluating and strengthening their company's defenses. Furthermore, notifying the user of the results to their mobile device allows them to take immediate countermeasures.

[0207] An "information provider" is an organization or group that provides information on cyber attack methods.

[0208] The "dark web" is an encrypted part of the internet that cannot be accessed through regular search engines.

[0209] "Data collection means" refers to methods and devices for collecting data on cyber attack techniques from intelligence agencies and the dark web.

[0210] "Analysis means" refers to a method or device that analyzes collected data and extracts and classifies important information.

[0211] An "AI model" is a data model trained using machine learning algorithms.

[0212] A "learning tool" is a method or device that trains an AI model based on collected and analyzed data.

[0213] A "simulated attack generation means" is a method or device that generates simulated cyber attacks using a trained AI model.

[0214] A "mock attack execution means" is a method or device for executing the generated mock attack and observing its effect.

[0215] A "result collection means" is a method or device for collecting the results of the executed simulated attacks.

[0216] A "results analysis means" is a method or device for analyzing collected results and generating a report.

[0217] A "report generator" is a method or apparatus for generating a detailed report based on the results of a simulated attack.

[0218] "Notification means" refers to a method or device for notifying the user's mobile terminal of the results of the simulated attack and related information.

[0219] The system for realizing this invention is mainly composed of a server, a terminal, and a user. The detailed configuration and usage method are described below.

[0220] Data collection from intelligence agencies and the dark web

[0221] The server first collects data on the latest attack techniques from intelligence agencies' APIs and the dark web. The collected data includes detailed descriptions of the attack techniques, the steps of the attack, and the tools and methods used. This allows for the creation of a comprehensive database of the latest attack techniques.

[0222] Data analysis

[0223] The device analyzes the collected data received from the server. Specifically, it preprocesses the collected data and extracts necessary information. It then classifies the extracted information into attack categories such as phishing, malware, and DDoS.

[0224] Training an AI model

[0225] The server trains the AI ​​model based on the data analyzed by the device. The machine learning algorithm used here is trained to accurately identify cyber attack methods. The trained AI model is then applied to newly collected data, ensuring it is always adaptable to the latest attack methods.

[0226] Generating and Executing Mock Attacks

[0227] Users can use the trained AI model to generate simulated attacks. They can customize the scenarios. The generated simulated attacks are deployed as payloads in their own security environments, and their responses are observed. For example, in the case of a phishing attack, a simulated phishing email is sent internally.

[0228] Collection and analysis of results

[0229] After conducting the simulated attack, the user collects the results, including data such as the click rate for phishing emails sent and the number of employee reports. This data is then further analyzed on the device and used to evaluate the security environment.

[0230] Report generation and notification

[0231] The device generates a detailed report based on the collected results. This report includes an analysis of the simulated attack results and recommendations for improving security measures. The report is then sent to the user's mobile device, allowing for immediate action.

[0232] Hardware and Software Examples

[0233] The specific hardware and software used to realize this system include Python, requests, scrapy, scikit-learn, numpy, and json. Python is the main implementation language of the program, requests is used to collect data from APIs, scrapy is used for web scraping of data, and scikit-learn is used to train machine learning algorithms. numpy helps analyze the data, and json is used to store the results and generate reports.

[0234] Specific examples

[0235] For example, a security department might periodically create and send mock phishing emails to assess employees' security practices. Using this system, the assessment can be performed quickly, accurately, and without hassle.

[0236] Example prompts for generative AI models

[0237] "Please provide us with data on the latest phishing attack techniques."

[0238] "Predict the effectiveness of this simulated phishing email attack."

[0239] In this way, the present invention is a system that increases resistance to the latest cyber attacks and enables effective implementation of security measures.

[0240] The flow of the specific processing in the application example 1 will be described with reference to FIG.

[0241] Step 1:

[0242] The server collects data on the latest attack techniques from information provider APIs and the dark web. The inputs include the API endpoint URL and the website URL to be scraped. The data collection method uses requests to retrieve data from the API and scrape data from the dark web using scrapy. The output is raw attack technique data, including details of the attack technique, attack steps, and information about the tools used.

[0243] Step 2:

[0244] The terminal analyzes the collected data and extracts and classifies the necessary information. The input is the raw data received from the server. Natural language processing (NLP) techniques are used for data analysis to extract important information. The extracted information is then classified into categories such as phishing, malware, and DDoS. The output is analyzed and classified information on attack techniques.

[0245] Step 3:

[0246] The server trains an AI model based on the analyzed data. The input is the analyzed and classified data received from the device. The machine learning algorithm used is scikit-learn, which trains the AI ​​model using the analyzed information. The model training process includes feature extraction, data splitting, model training, and evaluation. The output is an AI model that can identify the latest attack techniques.

[0247] Step 4:

[0248] Users generate mock attacks using the trained AI model. The input is the trained AI model and a customized attack scenario. The model generates a mock attack payload based on the given scenario. The output is the generated mock attack, which specifically includes mock phishing emails and malicious scripts.

[0249] Step 5:

[0250] The user executes the generated mock attacks and collects the results. The input is the payload of the generated mock attacks. The mock attacks are deployed in the user's security environment and their behavior is observed. The collected results include data such as click rates for phishing emails and the number of employee reports. The output is the result data of the mock attacks.

[0251] Step 6:

[0252] The device analyzes the collected results and generates a detailed report. The input is the result data of the simulated attacks. The data analysis method again uses NLP technology to analyze the result data. The report generation includes analyzing the results and suggesting areas for improving security measures. The output is a detailed analysis report, which is sent to the user's mobile device.

[0253] This enables users to quickly implement countermeasures against the latest cyber-attack methods and evaluate and strengthen their defenses.

[0254] Furthermore, an emotion engine that estimates the user's emotion may be combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59 and perform identification processing using the user's emotion.

[0255] patent specification

[0256] This invention relates to a system that efficiently learns the latest cyber-attack techniques and performs simulated attacks, and further combines it with an emotion engine that recognizes the user's emotions. This system has the following functions:

[0257] 1. Information collection module

[0258] The server collects data on the latest attack techniques from intelligence agencies and the dark web by accessing intelligence agency APIs to retrieve data and scraping data from forums and marketplaces on the dark web.

[0259] 2. Data Analysis Module

[0260] The terminal analyzes the collected data, processes it to extract important information, and then classifies it into attack categories such as phishing, malware, and DDoS, which allows for efficient organization of the information.

[0261] 3. Model Learning Module

[0262] The server trains the AI ​​model based on the analyzed data. The analyzed data is used to train machine learning algorithms and generate an AI model that can identify the latest attack techniques.

[0263] 4. Attack Simulation Module

[0264] Users can use the trained AI model to generate mock attacks, deploy the resulting attack payloads in their security environment, and observe their reactions—for example, by creating specific phishing emails and sending them internally.

[0265] 5. Result Collection Module

[0266] Users collect the results of the simulated attacks, such as the click rate of phishing emails and the number of detected malware, which allows them to evaluate the effectiveness of the attacks.

[0267] 6. Report Generation Module

[0268] The device analyzes the collected results and generates a detailed report that includes analysis and recommendations for improving security measures based on the results of the simulated attacks.

[0269] 7. Emotion Engine Module

[0270] The device uses an emotion engine to recognize the user's emotions during the process of simulating attacks and collecting execution results. The emotion engine analyzes the user's reactions and behavior to identify their emotional state. For example, the emotion engine analyzes the facial expressions and behavioral data of an employee who receives a phishing email and recognizes emotions such as stress and confusion.

[0271] 8. Use of Emotional Data

[0272] The content and difficulty of the simulated attacks are adjusted based on the user's emotional data recognized by the emotion engine. For example, if employees are overly confused, the difficulty of the simulated attacks can be lowered or the attack method changed. This increases the effectiveness of countermeasures against real attacks.

[0273] Specific examples

[0274] As an example, let's consider a company using this system. The server collects the latest phishing attack data from government security agency APIs and the dark web. The device analyzes the data and classifies it into phishing categories, and the server uses this data to train an AI model. Based on the trained model, the user generates mock phishing emails and deploys them within the company. The emotion engine analyzes employee reactions and adjusts the content and difficulty of the emails based on these results. Finally, all results are compiled to generate a report that proposes security measures.

[0275] This system will enable companies to increase their resistance to the latest cyber attacks and implement effective security measures. Furthermore, by combining it with an emotion engine, it will be possible to realize more accurate simulations and countermeasures that take into account the user's emotional state.

[0276] The processing flow will be explained below.

[0277] patent specification

[0278] The processing flow of the system will be explained in the following steps.

[0279] Step 1:

[0280] The server accesses the API of the information provider to obtain data on the latest attack techniques. Specifically, it sends a request to the security agency's API endpoint and receives a response. The response contains information such as the latest attack techniques, their overview, and the date and time of occurrence.

[0281] Step 2:

[0282] The server scrapes specific web pages to collect data on attack techniques from the dark web. Using a scraping tool, the server extracts the necessary information from forums and marketplaces on the dark web. The extracted data includes details of attack techniques, sales information, and related discussion content.

[0283] Step 3:

[0284] The device analyzes the collected data. Specifically, it analyzes the acquired JSON data and scraping data to extract information such as the type and details of the attack method, and the date and time of the attack. The analyzed data is organized by attack method.

[0285] Step 4:

[0286] The device classifies the analyzed information into categories such as phishing, malware, and DDoS. For example, among the extracted information, data related to phishing is classified into the phishing category, and data related to malware is classified into the malware category. This allows information to be organized efficiently.

[0287] Step 5:

[0288] The server trains the AI ​​model based on the classified data. The analyzed data is used to train machine learning algorithms and generate an AI model that can identify the latest attack techniques. The trained AI model is capable of mimicking the generation of phishing emails and malware behavior.

[0289] Step 6:

[0290] Users can use the trained AI model to generate simulated attacks, for example by generating phishing email content from the AI ​​model and preparing the email as a simulated attack. The generated attack payload is tailored to their company's security environment.

[0291] Step 7:

[0292] Users deploy the generated simulated attacks in their company's security environment. For example, they can send simulated phishing emails to employees' email addresses and observe their responses. Data is collected about the deployed simulated attacks, including the number of clicks and reports by employees.

[0293] Step 8:

[0294] Users collect the results of the simulated attacks, such as employee reactions to phishing emails and the amount of malware detected, which allows them to evaluate the effectiveness of the attacks.

[0295] Step 9:

[0296] The device generates a detailed report based on the collected results, including an analysis of the simulated attack results, an evaluation of security measures, and recommendations for improvement. The report also includes visualization and statistical information of the results.

[0297] Step 10:

[0298] The device uses an emotion engine to recognize the user's emotions during the process of simulating attacks and collecting execution results. The emotion engine analyzes the user's reactions and behavior to identify their emotional state. For example, the emotion engine analyzes the facial expressions and behavioral data of an employee who receives a phishing email and recognizes emotions such as stress and confusion.

[0299] Step 11:

[0300] The device uses the user's emotional data recognized by the emotion engine to adjust the content and difficulty of the simulated attacks. For example, if an employee is overly confused, the device can lower the difficulty of the simulated attacks or adjust the attack methods. This provides an environment in which employees can learn appropriately.

[0301] Step 12:

[0302] The device then uses the emotion engine to recognize the user's emotional data and includes in a report the evaluation results of the security measures and suggestions for improvement. The report includes an analysis that reflects the emotional data and details of areas for improvement, providing specific advice for strengthening a company's security measures.

[0303] The above is a specific embodiment for carrying out the present invention. This system can increase resistance to the latest cyber attacks and implement effective security measures. Furthermore, by combining it with an emotion engine, it is possible to realize more accurate simulations and measures that take into account the user's emotional state.

[0304] Example 2

[0305] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."

[0306] Today's cyber attacks are becoming more sophisticated and diverse, and organizations and companies need effective training and countermeasures to deal with them. However, conventional attack simulation systems do not take into account the user's emotions and psychological state, which can result in ineffective training. Furthermore, it has been difficult to quickly and accurately grasp the latest attack methods and improve adaptability to actual attacks.

[0307] The specific processing by the specific processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means.

[0308] In this invention, the server includes means for collecting data on the latest attack techniques from information providers and online forums, means for analyzing the collected data to extract and classify important information, means for training an AI model based on the analyzed data, means for generating simulated attacks using the trained AI model, means for executing the simulated attacks and collecting and analyzing the results, means for generating reports based on the results of the executed simulated attacks, means for recognizing a user's emotions using an emotion engine, and means for adjusting the content and difficulty of the simulated attacks based on the recognized emotion data. This provides effective countermeasures against the latest cyber attacks, and by conducting training that takes the user's psychological state into consideration, more realistic attack simulations and countermeasures can be achieved.

[0309] An "information provider" is a public or private organization that provides information about cyber attacks.

[0310] An "online forum" is a bulletin board or discussion site on the Web where users exchange information.

[0311] "Data collection" is the process of obtaining the necessary data from information sources and online forums.

[0312] "Data scraping" is the technique of automatically extracting information from websites.

[0313] "Analysis" is the process of processing collected data to extract useful information.

[0314] "Classification" is the process of organizing extracted information into specific categories.

[0315] An "AI model" is a statistical model created using artificial intelligence technology for making predictions and classifications.

[0316] A "mock attack" is a simulated attack that imitates an actual cyber attack.

[0317] An "emotion engine" is a system for recognizing and analyzing a user's emotional state.

[0318] A "report" is a report summarizing the analysis results, including points for improvement and suggestions.

[0319] The present invention relates to a system that efficiently learns the latest cyber-attack techniques and performs simulated attacks based on them. This system operates by integrating the following functions:

[0320] First, let's look at the information collection module. The server collects data on the latest attack techniques from information providers and online forums. This process involves accessing the APIs of the information providers to obtain the latest data and using web scraping techniques to collect information from online forums. As a specific example, it uses the Python requests library to send GET requests to API endpoints and the BeautifulSoup and Scrapy libraries to scrape text data from forum pages.

[0321] The data analysis module then analyzes the collected data to extract and classify key information. The terminal uses the pandas library to create a data frame and perform initial data cleaning. The data is then classified into security categories such as phishing, malware, and DDoS. This can be achieved by using the Scikit-learn K-means clustering algorithm.

[0322] In the model learning module, the server trains the AI ​​model based on the analyzed data, using techniques such as TensorFlow and PyTorch to train neural networks and generate models that can identify new cyber-attack patterns.

[0323] In the attack simulation module, users can use AI models to generate and execute simulated attacks. For example, using OpenAI's GPT series, a generative AI model, users can input the following prompt text to automatically generate the content of a phishing email:

[0324] Create mock phishing emails using the latest phishing techniques

[0325] The generated mock phishing emails are sent to an internal mailing list and the responses are observed.

[0326] The results collection module allows users to collect and analyze the results of simulated attacks, using data collection tools such as Google Analytics and Splunk to compile information such as click rates for phishing emails and the amount of malware detected.

[0327] The report generation module analyzes the collected data and generates a detailed report using Excel or Tableau to visualize the data and summarize the analysis results. The report includes analysis and recommendations for improvement based on the results of the simulated attacks.

[0328] In addition, the emotion engine module allows the device to recognize the user's emotions using the emotion engine, which combines OpenCV and Emotion SDK to analyze the user's facial expressions and behavioral data to reveal their emotional state.

[0329] Finally, the content and difficulty of the simulated attacks are adjusted based on the user's emotional data recognized by the emotion engine. For example, if an employee is overly confused, the difficulty of the next simulated attack may be lowered.

[0330] This system's series of processes enables companies to respond quickly to the latest cyber-attack techniques and also enables effective training that takes into account the emotional state of users.

[0331] The flow of the identification process in the second embodiment will be described with reference to FIG.

[0332] Step 1: Gather information

[0333] The server accesses the API of an intelligence provider to obtain data on the latest cyber attack methods.

[0334] (Input) API endpoint, authentication token

[0335] (Output) Acquired attack information data

[0336] The server uses the Python requests library to send a GET request to the API endpoint and retrieve the data in JSON format.

[0337] The server uses web scraping technology to collect data on attack methods from online forums.

[0338] (Input) Forum URL and target HTML element

[0339] (Output) Scraped text data

[0340] The server uses the BeautifulSoup and Scrapy libraries to extract relevant text data from the HTML pages of the target forums.

[0341] Step 2: Data analysis

[0342] The terminal analyzes the data received from the server and extracts important information.

[0343] (Input) Collected attack information data

[0344] (Output) A clean data frame

[0345] The terminal uses Python's pandas library to create data frames and handle missing and outlier values.

[0346] The device categorizes the data into security categories such as phishing, malware, and DDoS.

[0347] (Input) Clean data frame

[0348] (Output) Attack data by category

[0349] The device clusters the data using Scikit-learn's K-means clustering algorithm.

[0350] Step 3: Model training

[0351] The server trains the AI ​​model based on the analyzed data.

[0352] (Input) Attack data by category

[0353] (Output) Trained AI model

[0354] The server uses TensorFlow and PyTorch to train neural networks and generate models that identify new cyber attack patterns.

[0355] Step 4: Attack simulation

[0356] Users use the trained AI model to generate simulated attacks.

[0357] (Input) Trained AI model

[0358] (Output) Content of the mock attack (e.g., phishing email)

[0359] Users can use a generative AI model (e.g., GPT-3) to automatically generate the content of a phishing email by entering a prompt like the following:

[0360] Create mock phishing emails using the latest phishing techniques

[0361] The user sends the generated email to an internal mailing list.

[0362] Step 5: Collect results

[0363] The user collects and analyzes the results of the simulated attacks.

[0364] (Input) Results of simulated attacks (e.g., click rate, number of detected malware, etc.)

[0365] (Output) Evaluation data

[0366] Users use data collection tools such as Google Analytics and Splunk to compile data on phishing email click rates and the amount of malware detected.

[0367] Step 6: Generate reports

[0368] The terminal analyzes the collected data and generates a detailed report.

[0369] (Input) Evaluation data

[0370] (Output) Detailed report

[0371] The device uses Excel or Tableau to visualize the data and compiles the analysis results into a report, which includes improvements and suggestions.

[0372] Step 7: Emotion Recognition

[0373] The terminal uses an emotion engine to recognize the user's emotions.

[0374] (Input) User facial expression and behavior data

[0375] (Output) User emotion data

[0376] The device uses OpenCV and the Emotion SDK to analyze the user's facial expressions and identify emotional states such as stress or confusion.

[0377] Step 8: Use emotion data

[0378] The content and difficulty of the simulated attack are adjusted based on the user's emotional data.

[0379] (Input) User emotion data

[0380] (Output) Adjusted simulated attack content

[0381] If the emotion engine determines that an employee is overly confused, it will take action such as lowering the difficulty of the next mock attack.

[0382] These steps will enable companies to respond quickly and effectively to the latest cyberattack techniques, and also provide practical training that takes into account the emotional state of users.

[0383] (Application example 2)

[0384] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."

[0385] Cyber-attack threats continue to evolve, causing increasing damage to businesses and individuals. In particular, phishing emails, malware, and DDoS attacks pose numerous security risks. Furthermore, existing countermeasures often cannot quickly adapt to the latest attack methods, necessitating continuous learning and the implementation of simulated attacks. Furthermore, there is a lack of training that takes into account user emotions and reactions, making it difficult to implement effective security measures. To address these challenges, an efficient and flexible security system is needed.

[0386] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 2 is realized by the following means.

[0387] In this invention, the server includes means for collecting data on the latest attack techniques from intelligence agencies and the dark web, means for analyzing the collected data to extract and classify important information, means for training an AI model based on the analyzed data, means for generating simulated attacks using the trained AI model, means for executing the simulated attacks and collecting and analyzing their results, means for generating reports based on the results of the executed simulated attacks, means for simulating the simulated attacks on a user device, and means for collecting user reaction and emotional data and adjusting the content and difficulty of the simulated attacks. This enables rapid and effective learning of the latest cyber-attack techniques and the implementation of simulated attacks, thereby realizing security measures that take user emotions and reactions into account.

[0388] "Information providers" are experts and organizations that provide data on the latest cyber attack techniques.

[0389] The "dark web" is an area of ​​the internet that cannot be accessed through regular search engines and is home to a lot of illegal information and activity.

[0390] "Means of collecting data" refers to methods and devices for obtaining data on the latest attack techniques from intelligence agencies and the dark web.

[0391] "Means for analyzing data to extract and classify important information" refers to methods and devices for analyzing collected data and selecting and classifying necessary information.

[0392] "Means for training AI models" refers to methods or devices that train artificial intelligence based on analyzed data and create machine learning models for specific purposes.

[0393] "Means for generating simulated attacks" means a method or device for generating attack scenarios using a trained AI model.

[0394] "Means for executing simulated attacks and collecting and analyzing the results" refers to methods and devices for executing the generated simulated attacks and collecting and analyzing their effects and reactions as data.

[0395] A "means for generating a report" refers to a method or device that analyzes the results of a simulated attack and creates a detailed report.

[0396] A "user device" is an electronic device that can be directly operated by a user, such as a smartphone, tablet, or PC.

[0397] A "means for simulating" is a method or device for executing a simulated attack in a virtual environment and observing the results.

[0398] "Means for collecting user reaction and emotional data and adjusting the content and difficulty of the simulated attack" refers to a method or device for evaluating the user's behavior and emotions in response to the simulated attack and changing the content and difficulty of the attack based on that evaluation.

[0399] This invention relates to a system that efficiently learns the latest cyber-attack techniques and conducts simulated attacks, incorporating an emotion engine that recognizes user emotions. Specifically, the system collects data on the latest attack techniques from intelligence agencies and the dark web, analyzes the collected data to extract and classify important information, trains an AI model based on the analyzed data, and generates simulated attacks using the trained AI model. The generated simulated attacks are simulated on the user's device, and the results are collected and analyzed. A report is generated based on the results of the simulated attacks, and user reaction and emotional data are collected to adjust the content and difficulty of the simulated attacks.

[0400] The server uses API access and web scraping techniques to collect data from intelligence agencies and the dark web. The collected data is analyzed and classified into categories such as phishing, malware, and DDoS. The analyzed data is then used to train an AI model to identify the latest attack techniques. The trained AI model is then used to generate mock attacks, which are simulated on user devices.

[0401] The device collects the results of simulated attacks and evaluates their effectiveness. Specifically, it collects data such as the click rate of phishing emails and the number of detected malware, and generates reports to evaluate the success rate of attacks and the performance of defense systems. It also uses an emotion engine to analyze user reactions and behavior, allowing it to adjust the content and difficulty of the simulated attacks.

[0402] For example, a specific phishing email can be created and sent internally, and the emotion engine will analyze employees' facial expressions and behavioral data to recognize emotions such as stress or confusion. Based on these results, the difficulty of the simulated attack can be adjusted or the attack method changed. In this way, companies can increase their resilience against the latest cyberattacks and implement more accurate security measures.

[0403] Example prompt sentence:

[0404] Collect the latest phishing attack data and generate a simulation. Capture users' reactions after receiving the notification with a camera and analyze their emotions using the emotion engine. Adjust the simulation accordingly.

[0405] The hardware used is user devices such as smartphones, tablets, and PCs, and the software is primarily written in Python. The requests library and BeautifulSoup are used for data collection, and TensorFlow and PyTorch are used for machine learning. These technologies enable the entire system to operate efficiently and flexibly.

[0406] The flow of the specific processing in the application example 2 will be described with reference to FIG.

[0407] Step 1:

[0408] The server runs a mechanism to collect data on the latest attack techniques from intelligence agencies and the dark web, using API access to retrieve data from intelligence agencies and web scraping techniques to gather additional data from dark web forums and marketplaces. This data contains a variety of information on attack techniques.

[0409] Input: API endpoint of intelligence provider, dark web URL

[0410] Output: Raw data on the latest attack techniques

[0411] Step 2:

[0412] The server then analyzes the collected data and implements measures to extract and classify key information, specifically using natural language processing techniques to analyze the data and categorize it into attack categories such as phishing, malware, and DDoS.

[0413] Input: Unanalyzed data collected in Step 1

[0414] Output: Categorized analysis data

[0415] Step 3:

[0416] The server runs a trainer for the AI ​​model based on the analyzed data. It uses machine learning algorithms to train the model to identify the latest attack techniques. Specifically, it uses TensorFlow and PyTorch to build the model and train it on the analyzed data.

[0417] Input: Data parsed in step 2

[0418] Output: The trained AI model

[0419] Step 4:

[0420] The server executes a means to generate simulated attacks using the trained AI model, generating attack scenarios and converting them into a format that can be executed on the user device.

[0421] Input: The AI ​​model trained in Step 3

[0422] Output: mock attack scenarios and payloads

[0423] Step 5:

[0424] Users deploy the generated simulated attacks in their own security environment and execute them on user devices such as smartphones and PCs. The results of the simulated attacks are collected from the device's sensors and log data.

[0425] Input: The mock attack generated in step 4

[0426] Output: Execution result data (e.g., click rate of phishing emails and number of detected malware)

[0427] Step 6:

[0428] The device executes procedures to analyze the results of the simulated attacks and generate detailed reports, such as creating statistics and graphs of the results, documenting the success rate of the attacks and the evaluation of the defense system.

[0429] Input: The execution result data collected in Step 5

[0430] Output: Detailed report

[0431] Step 7:

[0432] The device uses an emotion engine to recognize the user's emotions during the process of simulating attacks and collecting the results. Specifically, it collects user behavior data from cameras and sensors and uses an emotion analysis algorithm to evaluate the user's level of stress and confusion.

[0433] Input: User camera footage and sensor data

[0434] Output: User emotion data

[0435] Step 8:

[0436] The server uses the emotion data to adjust the content and difficulty of the simulated attack. Specifically, it changes the attack scenario and difficulty according to the user's emotional state, and provides adaptive training for real attacks.

[0437] Input: User emotion data collected in step 7

[0438] Output: Adjusted attack scenarios and difficulty levels

[0439] Example prompt sentence:

[0440] Collect the latest phishing attack data and generate a simulation. Capture users' reactions after receiving the notification with a camera and analyze their emotions using the emotion engine. Adjust the simulation accordingly.

[0441] The specific processing unit 290 transmits the result of the specific processing to the smart device 14. In the smart device 14, the control unit 46A causes the output device 40 to output the result of the specific processing. The microphone 38B acquires audio indicating a user input regarding the result of the specific processing. The control unit 46A transmits audio data indicating the user input acquired by the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.

[0442] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[0443] In the above embodiment, an example in which the specific process is performed by the data processing device 12 has been given, but the technology of the present disclosure is not limited to this, and the specific process may be performed by the smart device 14.

[0444] [Second embodiment]

[0445] FIG. 3 shows an example of the configuration of a data processing system 210 according to the second embodiment.

[0446] 3, the data processing system 210 includes the data processing device 12 and smart glasses 214. An example of the data processing device 12 is a server.

[0447] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[0448] The smart glasses 214 include a computer 36, a microphone 238, a speaker 240, a camera 42, and a communication I / F 44. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The microphone 238, the speaker 240, and the camera 42 are also connected to the bus 52.

[0449] The microphone 238 receives instructions and the like from the user 20 by receiving voice uttered by the user 20. The microphone 238 captures the voice uttered by the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio in accordance with instructions from the processor 46.

[0450] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the surroundings of user 20 (for example, an imaging range defined by an angle of view equivalent to the field of vision of a typical healthy person).

[0451] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 are responsible for the exchange of various information between the processor 46 and the processor 28 via the network 54. The exchange of various information between the processor 46 and the processor 28 using the communication I / Fs 44 and 26 is carried out in a secure state.

[0452] Fig. 4 shows an example of the main functions of the data processing device 12 and the smart glasses 214. As shown in Fig. 4, in the data processing device 12, a specific process is performed by the processor 28. A specific process program 56 is stored in the storage 32.

[0453] The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[0454] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[0455] In the smart glasses 214, the reception output process is performed by the processor 46. A reception output program 60 is stored in the storage 50. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.

[0456] Next, a description will be given of the identification process performed by the identification processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as the "server" and the smart glasses 214 will be referred to as the "terminal."

[0457] patent specification

[0458] The present invention relates to a system for efficiently learning the latest cyber-attack techniques and conducting simulated attacks. This system has the following functions:

[0459] 1. Information collection module

[0460] The server collects data on the latest attack techniques from intelligence agencies and the dark web by accessing the intelligence agencies' APIs to retrieve the necessary data, and also scrapes data from forums and marketplaces on the dark web.

[0461] 2. Data Analysis Module

[0462] The device analyzes the collected data. First, it processes the collected data to extract necessary information and organizes information about attack methods. Then, it classifies the extracted information into attack categories such as phishing, malware, and DDoS.

[0463] 3. Model Learning Module

[0464] The server trains the AI ​​model based on the analyzed data, using the analyzed information to train machine learning algorithms and generate models that can identify the latest attack techniques.

[0465] 4. Attack Simulation Module

[0466] Users can use the trained AI model to generate mock attacks, deploy the resulting payloads in their security environment, and observe the response. For example, in the case of a phishing attack, they can send mock phishing emails to their company.

[0467] 5. Result Collection Module

[0468] After conducting the simulated attacks, users collect the results, such as click rates for phishing emails sent and the number of employee reports.

[0469] 6. Report Generation Module

[0470] The device analyzes the collected results and generates a detailed report that includes an analysis of the results of the simulated attacks and recommendations for improving security measures.

[0471] Specific examples

[0472] As an example, let's consider a specific company using this system. The company's server begins collecting data from government security agency APIs and the dark web. Next, the device analyzes the data, extracting and classifying important information about phishing and malware attacks. The server uses the analyzed data to train an AI model, which then generates phishing emails based on that model. The user then sends these mock phishing emails to the company and collects responses from employees. Finally, the device compiles the results into a detailed report, assessing the company's security measures and suggesting areas for improvement.

[0473] Through the above process, the system of the present invention increases resistance to the latest cyber attacks and enables the implementation of effective security measures.

[0474] The processing flow will be explained below.

[0475] Processing flow

[0476] Step 1:

[0477] The server accesses the API of the information provider to obtain data on the latest attack techniques. Specifically, it sends a request to the security agency's API endpoint and receives a response. The response contains information such as the latest attack techniques, their overview, and the date and time of occurrence.

[0478] Step 2:

[0479] The server scrapes data from forums and marketplaces on the dark web. Using specialized scraping tools, it extracts text information from specific web pages. The extracted data includes attack techniques, sales information, and related discussions.

[0480] Step 3:

[0481] The terminal analyzes the data received from the server. First, it parses the acquired JSON data and scraped data and converts it into a meaningful format. This allows it to extract the necessary information (type of attack method, details, date and time of occurrence, etc.).

[0482] Step 4:

[0483] The terminal classifies the extracted information into specific categories, such as phishing attacks, malware attacks, DDoS attacks, etc. This classification allows the data to be used efficiently in subsequent processing.

[0484] Step 5:

[0485] The server trains the AI ​​model based on the classified data. It uses the analyzed information to train machine learning algorithms and generate models that can identify the latest attack techniques. This includes data preprocessing, model training, and evaluation.

[0486] Step 6:

[0487] Users can use the trained AI model to generate simulated attacks, generating specific attack payloads (e.g., phishing email content or malware code) based on attack patterns obtained from the AI ​​model.

[0488] Step 7:

[0489] The user deploys the generated simulated attacks in their company's security environment. For example, they send simulated phishing emails to employees' email addresses and observe the responses. The user then monitors how the attacks are countered.

[0490] Step 8:

[0491] Users collect the results of their simulated attacks, including click rates for phishing emails, the number of reports, and the number of malware detected, which will be used for subsequent analysis.

[0492] Step 9:

[0493] The device generates a detailed report based on the collected results, including an analysis of the simulated attacks, an evaluation of security measures, and suggestions for improvement. The report also includes visualization and statistical information of the results.

[0494] Through the above processing steps, the system of the present invention increases resistance to the latest cyber attacks and enables the implementation of effective security measures.

[0495] Example 1

[0496] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."

[0497] The latest cyberattack methods are evolving daily, and there is a need to quickly implement effective security measures to counter them. However, existing security measures lack systems that can efficiently learn the latest attack methods and conduct simulated attacks, leaving companies and organizations vulnerable to advanced cyberattacks.

[0498] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.

[0499] In this invention, the server includes means for collecting data on the latest attack techniques from intelligence agencies and the dark web, means for analyzing the collected data to extract and classify important information, and means for training an AI model using a machine learning algorithm based on the analyzed data. This makes it possible to quickly and efficiently grasp the latest cyber-attack techniques and to improve security measures by conducting simulated attacks.

[0500] An "information provider" refers to an organization or institution that collects and provides security-related information.

[0501] The "dark web" refers to a group of highly anonymous websites that cannot be accessed through regular search engines.

[0502] "Attack methods" refer to the specific techniques and tactics used in cyber attacks.

[0503] "Data collection methods" refer to the methods and tools used to obtain information.

[0504] "API Access" means access to external data or services through an application programming interface.

[0505] "Web scraping" refers to the technique of extracting information from websites.

[0506] "Data analysis methods" refer to methods and tools used to process and analyze collected data to extract meaningful information.

[0507] A "machine learning algorithm" refers to a computational method for learning patterns and rules based on data.

[0508] "AI model" refers to a model of artificial intelligence that has been trained by machine learning algorithms and is capable of performing specific tasks.

[0509] A "payload" refers to the data or code that is actually sent to the target in a cyber attack.

[0510] "Security environment" refers to the overall security measures and infrastructure of an organization or system.

[0511] "Report generation means" refers to methods and tools for generating reports based on collected and analyzed information.

[0512] The present invention relates to a system for efficiently learning the latest cyber-attack techniques and conducting simulated attacks. This system collects data from intelligence agencies and the dark web, analyzes the collected data, trains an AI model based on the analyzed data, generates simulated attacks using the trained AI model, and generates detailed reports by collecting and analyzing the results of the simulated attacks.

[0513] Information gathering

[0514] The server collects data on the latest attack techniques from the APIs of intelligence providers and the dark web. Intelligence providers often have public APIs that provide security information. The server accesses the APIs using HTTP requests and retrieves information in JSON format. It also uses web scraping libraries such as Python's Beautiful Soup and Scrapy to collect information from the dark web. The collected data is stored in an SQL or NoSQL database.

[0515] Data analysis

[0516] The device takes the collected data and preprocesses it using NLP tools (e.g., NLTK or SpaCy). Preprocessing includes tokenizing the text and removing stop words. The analyzed data is then classified into attack categories such as phishing, malware, and DDoS. Algorithms such as decision trees and support vector machines (SVM) are used for classification. The classified data is then stored in JSON format or in a database.

[0517] Model learning

[0518] The server trains an AI model based on the analyzed data. The server builds a neural network model using machine learning libraries such as TensorFlow and PyTorch. The training process includes data preprocessing, model construction, training, and evaluation. The trained model is deployed as an API server and made accessible to other system components.

[0519] Attack Simulation

[0520] Users use the trained AI model to generate mock attack payloads. In this process, users send requests to the model API and receive the generated payloads. Mock attack payloads include, for example, phishing emails and malware executable files. Users then deploy these payloads in their security environment and monitor their impact.

[0521] Results collection and report generation

[0522] The user collects the results of the simulated attacks, including click rates, the number of employee reports, and security system log data. The terminal analyzes the collected data and generates a detailed report that includes the results of the simulated attacks and an evaluation and improvement of security measures. The report is generated and provided to the user in a format that includes graphs and charts using Pandas and Matplotlib.

[0523] Specific examples

[0524] For example, if a particular company uses this system, the company's server collects data on attack methods from government security agency APIs and the dark web. The device analyzes the data, extracting and classifying important information about phishing and malware attacks. The server uses the analyzed data to train an AI model, which then generates phishing emails based on that model. The user sends these mock phishing emails internally and observes and records employee reactions. Finally, the device compiles the results into a detailed report, assessing the company's security measures and recommending areas for improvement.

[0525] Prompt Sentence Examples

[0526] "Write a Python script to collect data on the latest phishing attack techniques, train an AI model based on the analysis results, and generate simulated phishing attacks."

[0527] The above is an embodiment of the present invention.

[0528] The flow of the identification process in the first embodiment will be described with reference to FIG.

[0529] Step 1: Gather information

[0530] The server collects data on the latest attack techniques from intelligence agencies and the dark web.

[0531] Specifically, the server performs the following operations.

[0532] 1.1 The server sends an HTTP request to the provider's API endpoint, including the API key and the search query.

[0533] Input: API endpoint information, API key, search query

[0534] Output: JSON data obtained as an API response

[0535] 1.2 The server analyzes the JSON data received as an API response and extracts the necessary information.

[0536] Input: JSON data of API response

[0537] Output: Data about the extracted attack techniques

[0538] 1.3 The server accesses dark web forums and marketplaces and scrapes data using Beautiful Soup and Scrapy.

[0539] Input: Dark Web website URL

[0540] Output: Data on attack techniques obtained through scraping

[0541] 1.4 The server stores the collected data in a SQL or NoSQL database.

[0542] Input: Data on extracted attack techniques, data obtained by scraping

[0543] Output: Data stored in the database

[0544] Step 2: Data analysis

[0545] The terminal analyzes the collected data.

[0546] Specifically, the terminal performs the following operations.

[0547] 2.1 The terminal retrieves the collected data from the database.

[0548] Input: Database connection information

[0549] Output: Retrieved data

[0550] 2.2 The device preprocesses the data using NLP tools (NLTK or SpaCy), which includes tokenizing the text and removing stop words.

[0551] Input: Retrieved data

[0552] Output: Preprocessed data

[0553] 2.3 The device classifies the pre-processed data into attack categories such as phishing, malware, DDoS, etc. It uses algorithms such as decision trees and SVM for classification.

[0554] Input: Preprocessed data

[0555] Output: Data categorized by attack category

[0556] 2.4 The device stores the classified data in JSON format or in a database.

[0557] Input: Classified data

[0558] Output: JSON formatted data or data stored in a database

[0559] Step 3: Model training

[0560] The server trains the AI ​​model based on the analyzed data.

[0561] Specifically, the server performs the following operations.

[0562] 3.1 The server retrieves the parsed data from the database.

[0563] Input: Database connection information

[0564] Output: Retrieved data

[0565] 3.2 The server builds the neural network model using TensorFlow and PyTorch libraries.

[0566] Input: Acquired data, machine learning library (TensorFlow, PyTorch)

[0567] Output: Building a neural network model

[0568] 3.3 The server trains the model using the training data. It sets the optimizer (Adam, SGD), number of epochs, and batch size.

[0569] Input: training data, optimizer, number of epochs, batch size

[0570] Output: A trained AI model

[0571] 3.4 The server saves the trained model and deploys it as an API server.

[0572] Input: A trained AI model

[0573] Output: Deployed model API

[0574] Step 4: Attack simulation

[0575] Users use the trained AI model to generate simulated attacks.

[0576] Specifically, the user performs the following operations.

[0577] 4.1 The user sends a request to the model API to generate a mock attack payload, including attack category and target information.

[0578] Input: Model API endpoint, request parameters (attack category, target information)

[0579] Output: Generated mock attack payload

[0580] 4.2 The user deploys the generated payload in their security environment, for example by sending a phishing email using the Gmail API.

[0581] Input: Generated payload, security environment information

[0582] Output: Deployed payload

[0583] 4.3 Users monitor the security environment for responses during simulated attacks, using syslog and incident response systems.

[0584] Input: Security environment information, mock attack payload

[0585] Output: Reaction data of the monitored security environment

[0586] Step 5: Collect results

[0587] After conducting the simulated attacks, the user collects the results.

[0588] Specifically, the user performs the following operations.

[0589] 5.1 The user obtains log and activity data from the security environment.

[0590] Input: Security environment information

[0591] Output: Acquired log data and activity data

[0592] 5.2 The user calculates metrics such as click-through rates and employee reporting numbers.

[0593] Input: Captured log data and activity data

[0594] Output: Calculated metrics

[0595] 5.3 The user stores the collected data in a database.

[0596] Inputs: Calculated metrics, log data, activity data

[0597] Output: Result data stored in a database

[0598] Step 6: Generate reports

[0599] The terminal analyzes the collected results and generates a detailed report.

[0600] Specifically, the terminal performs the following operations.

[0601] 6.1 The terminal retrieves the collected result data from the database.

[0602] Input: Database connection information

[0603] Output: Acquired result data

[0604] 6.2 The device aggregates data and calculates key metrics using the Pandas library.

[0605] Input: Result data, Pandas library

[0606] Output: Aggregated data, calculated metrics

[0607] 6.3 The terminal uses the Matplotlib and Seaborn libraries to create graphs and charts.

[0608] Input: Aggregated data, calculated metrics, Matplotlib library, Seaborn library

[0609] Output: Generated graphs and charts

[0610] 6.4 The terminal will generate a report along with the generated graphs and suggest improvements to security measures.

[0611] Input: Generated graphs, charts, and analysis results

[0612] Output: Detailed report and improvement suggestions

[0613] (Application example 1)

[0614] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."

[0615] Modern cyberattack methods are becoming increasingly complex and diverse, requiring both companies and individual users to implement countermeasures against attacks that cannot be prevented by conventional methods. Furthermore, implementing effective security measures requires the rapid collection of information on the latest attack methods and the rapid application of countermeasures based on that information. However, performing these steps manually is extremely difficult, and there are limited methods for evaluating defense capabilities before an actual attack occurs.

[0616] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.

[0617] In this invention, the server includes means for collecting data on the latest attack techniques from intelligence agencies and the dark web, means for analyzing the collected data to extract and classify important information, means for training an AI model based on the analyzed data, means for generating simulated attacks using the trained AI model, means for executing the simulated attacks and collecting and analyzing their results, means for generating reports based on the results of the executed simulated attacks, and means for notifying the user of the results to their mobile device. This allows users to quickly respond to the latest attack techniques while evaluating and strengthening their company's defenses. Furthermore, notifying the user of the results to their mobile device allows them to take immediate countermeasures.

[0618] An "information provider" is an organization or group that provides information on cyber attack methods.

[0619] The "dark web" is an encrypted part of the internet that cannot be accessed through regular search engines.

[0620] "Data collection means" refers to methods and devices for collecting data on cyber attack techniques from intelligence agencies and the dark web.

[0621] "Analysis means" refers to a method or device that analyzes collected data and extracts and classifies important information.

[0622] An "AI model" is a data model trained using machine learning algorithms.

[0623] A "learning tool" is a method or device that trains an AI model based on collected and analyzed data.

[0624] A "simulated attack generation means" is a method or device that generates simulated cyber attacks using a trained AI model.

[0625] A "mock attack execution means" is a method or device for executing the generated mock attack and observing its effect.

[0626] A "result collection means" is a method or device for collecting the results of the executed simulated attacks.

[0627] A "results analysis means" is a method or device for analyzing collected results and generating a report.

[0628] A "report generator" is a method or apparatus for generating a detailed report based on the results of a simulated attack.

[0629] "Notification means" refers to a method or device for notifying the user's mobile terminal of the results of the simulated attack and related information.

[0630] The system for realizing this invention is mainly composed of a server, a terminal, and a user. The detailed configuration and usage method are described below.

[0631] Data collection from intelligence agencies and the dark web

[0632] The server first collects data on the latest attack techniques from intelligence agencies' APIs and the dark web. The collected data includes detailed descriptions of the attack techniques, the steps of the attack, and the tools and methods used. This allows for the creation of a comprehensive database of the latest attack techniques.

[0633] Data analysis

[0634] The device analyzes the collected data received from the server. Specifically, it preprocesses the collected data and extracts necessary information. It then classifies the extracted information into attack categories such as phishing, malware, and DDoS.

[0635] Training an AI model

[0636] The server trains the AI ​​model based on the data analyzed by the device. The machine learning algorithm used here is trained to accurately identify cyber attack methods. The trained AI model is then applied to newly collected data, ensuring it is always adaptable to the latest attack methods.

[0637] Generating and Executing Mock Attacks

[0638] Users can use the trained AI model to generate simulated attacks. They can customize the scenarios. The generated simulated attacks are deployed as payloads in their own security environments, and their responses are observed. For example, in the case of a phishing attack, a simulated phishing email is sent internally.

[0639] Collection and analysis of results

[0640] After conducting the simulated attack, the user collects the results, including data such as the click rate for phishing emails sent and the number of employee reports. This data is then further analyzed on the device and used to evaluate the security environment.

[0641] Report generation and notification

[0642] The device generates a detailed report based on the collected results. This report includes an analysis of the simulated attack results and recommendations for improving security measures. The report is then sent to the user's mobile device, allowing for immediate action.

[0643] Hardware and Software Examples

[0644] The specific hardware and software used to realize this system include Python, requests, scrapy, scikit-learn, numpy, and json. Python is the main implementation language of the program, requests is used to collect data from APIs, scrapy is used for web scraping of data, and scikit-learn is used to train machine learning algorithms. numpy helps analyze the data, and json is used to store the results and generate reports.

[0645] Specific examples

[0646] For example, a security department might periodically create and send mock phishing emails to assess employees' security practices. Using this system, the assessment can be performed quickly, accurately, and without hassle.

[0647] Example prompts for generative AI models

[0648] "Please provide us with data on the latest phishing attack techniques."

[0649] "Predict the effectiveness of this simulated phishing email attack."

[0650] In this way, the present invention is a system that increases resistance to the latest cyber attacks and enables effective implementation of security measures.

[0651] The flow of the specific processing in the application example 1 will be described with reference to FIG.

[0652] Step 1:

[0653] The server collects data on the latest attack techniques from information provider APIs and the dark web. The inputs include the API endpoint URL and the website URL to be scraped. The data collection method uses requests to retrieve data from the API and scrape data from the dark web using scrapy. The output is raw attack technique data, including details of the attack technique, attack steps, and information about the tools used.

[0654] Step 2:

[0655] The terminal analyzes the collected data and extracts and classifies the necessary information. The input is the raw data received from the server. Natural language processing (NLP) techniques are used for data analysis to extract important information. The extracted information is then classified into categories such as phishing, malware, and DDoS. The output is analyzed and classified information on attack techniques.

[0656] Step 3:

[0657] The server trains an AI model based on the analyzed data. The input is the analyzed and classified data received from the device. The machine learning algorithm used is scikit-learn, which trains the AI ​​model using the analyzed information. The model training process includes feature extraction, data splitting, model training, and evaluation. The output is an AI model that can identify the latest attack techniques.

[0658] Step 4:

[0659] Users generate mock attacks using the trained AI model. The input is the trained AI model and a customized attack scenario. The model generates a mock attack payload based on the given scenario. The output is the generated mock attack, which specifically includes mock phishing emails and malicious scripts.

[0660] Step 5:

[0661] The user executes the generated mock attacks and collects the results. The input is the payload of the generated mock attacks. The mock attacks are deployed in the user's security environment and their behavior is observed. The collected results include data such as click rates for phishing emails and the number of employee reports. The output is the result data of the mock attacks.

[0662] Step 6:

[0663] The device analyzes the collected results and generates a detailed report. The input is the result data of the simulated attacks. The data analysis method again uses NLP technology to analyze the result data. The report generation includes analyzing the results and suggesting areas for improving security measures. The output is a detailed analysis report, which is sent to the user's mobile device.

[0664] This enables users to quickly implement countermeasures against the latest cyber-attack methods and evaluate and strengthen their defenses.

[0665] Furthermore, an emotion engine that estimates the user's emotion may be further combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59, and perform identification processing using the user's emotion.

[0666] patent specification

[0667] This invention relates to a system that efficiently learns the latest cyber-attack techniques and performs simulated attacks, and further combines it with an emotion engine that recognizes the user's emotions. This system has the following functions:

[0668] 1. Information collection module

[0669] The server collects data on the latest attack techniques from intelligence agencies and the dark web by accessing intelligence agency APIs to retrieve data and scraping data from forums and marketplaces on the dark web.

[0670] 2. Data Analysis Module

[0671] The terminal analyzes the collected data, processes it to extract important information, and then classifies it into attack categories such as phishing, malware, and DDoS, which allows for efficient organization of the information.

[0672] 3. Model Learning Module

[0673] The server trains the AI ​​model based on the analyzed data. The analyzed data is used to train machine learning algorithms and generate an AI model that can identify the latest attack techniques.

[0674] 4. Attack Simulation Module

[0675] Users can use the trained AI model to generate mock attacks, deploy the resulting attack payloads in their security environment, and observe their reactions—for example, by creating specific phishing emails and sending them internally.

[0676] 5. Result Collection Module

[0677] Users collect the results of the simulated attacks, such as the click rate of phishing emails and the number of detected malware, which allows them to evaluate the effectiveness of the attacks.

[0678] 6. Report Generation Module

[0679] The device analyzes the collected results and generates a detailed report that includes analysis and recommendations for improving security measures based on the results of the simulated attacks.

[0680] 7. Emotion Engine Module

[0681] The device uses an emotion engine to recognize the user's emotions during the process of simulating attacks and collecting execution results. The emotion engine analyzes the user's reactions and behavior to identify their emotional state. For example, the emotion engine analyzes the facial expressions and behavioral data of an employee who receives a phishing email and recognizes emotions such as stress and confusion.

[0682] 8. Use of Emotional Data

[0683] The content and difficulty of the simulated attacks are adjusted based on the user's emotional data recognized by the emotion engine. For example, if employees are overly confused, the difficulty of the simulated attacks can be lowered or the attack method changed. This increases the effectiveness of countermeasures against real attacks.

[0684] Specific examples

[0685] As an example, let's consider a company using this system. The server collects the latest phishing attack data from government security agency APIs and the dark web. The device analyzes the data and classifies it into phishing categories, and the server uses this data to train an AI model. Based on the trained model, the user generates mock phishing emails and deploys them within the company. The emotion engine analyzes employee reactions and adjusts the content and difficulty of the emails based on these results. Finally, all results are compiled to generate a report that proposes security measures.

[0686] This system will enable companies to increase their resistance to the latest cyber attacks and implement effective security measures. Furthermore, by combining it with an emotion engine, it will be possible to realize more accurate simulations and countermeasures that take into account the user's emotional state.

[0687] The processing flow will be explained below.

[0688] patent specification

[0689] The processing flow of the system will be explained in the following steps.

[0690] Step 1:

[0691] The server accesses the API of the information provider to obtain data on the latest attack techniques. Specifically, it sends a request to the security agency's API endpoint and receives a response. The response contains information such as the latest attack techniques, their overview, and the date and time of occurrence.

[0692] Step 2:

[0693] The server scrapes specific web pages to collect data on attack techniques from the dark web. Using a scraping tool, the server extracts the necessary information from forums and marketplaces on the dark web. The extracted data includes details of attack techniques, sales information, and related discussion content.

[0694] Step 3:

[0695] The device analyzes the collected data. Specifically, it analyzes the acquired JSON data and scraping data to extract information such as the type and details of the attack method, and the date and time of the attack. The analyzed data is organized by attack method.

[0696] Step 4:

[0697] The device classifies the analyzed information into categories such as phishing, malware, and DDoS. For example, among the extracted information, data related to phishing is classified into the phishing category, and data related to malware is classified into the malware category. This allows information to be organized efficiently.

[0698] Step 5:

[0699] The server trains the AI ​​model based on the classified data. The analyzed data is used to train machine learning algorithms and generate an AI model that can identify the latest attack techniques. The trained AI model is capable of mimicking the generation of phishing emails and malware behavior.

[0700] Step 6:

[0701] Users can use the trained AI model to generate simulated attacks, for example by generating phishing email content from the AI ​​model and preparing the email as a simulated attack. The generated attack payload is tailored to their company's security environment.

[0702] Step 7:

[0703] Users deploy the generated simulated attacks in their company's security environment. For example, they can send simulated phishing emails to employees' email addresses and observe their responses. Data is collected about the deployed simulated attacks, including the number of clicks and reports by employees.

[0704] Step 8:

[0705] Users collect the results of the simulated attacks, such as employee reactions to phishing emails and the amount of malware detected, which allows them to evaluate the effectiveness of the attacks.

[0706] Step 9:

[0707] The device generates a detailed report based on the collected results, including an analysis of the simulated attack results, an evaluation of security measures, and recommendations for improvement. The report also includes visualization and statistical information of the results.

[0708] Step 10:

[0709] The device uses an emotion engine to recognize the user's emotions during the process of simulating attacks and collecting execution results. The emotion engine analyzes the user's reactions and behavior to identify their emotional state. For example, the emotion engine analyzes the facial expressions and behavioral data of an employee who receives a phishing email and recognizes emotions such as stress and confusion.

[0710] Step 11:

[0711] The device uses the user's emotional data recognized by the emotion engine to adjust the content and difficulty of the simulated attacks. For example, if an employee is overly confused, the device can lower the difficulty of the simulated attacks or adjust the attack methods. This provides an environment in which employees can learn appropriately.

[0712] Step 12:

[0713] The device then uses the emotion engine to recognize the user's emotional data and includes in a report the evaluation results of the security measures and suggestions for improvement. The report includes an analysis that reflects the emotional data and details of areas for improvement, providing specific advice for strengthening a company's security measures.

[0714] The above is a specific embodiment for carrying out the present invention. This system can increase resistance to the latest cyber attacks and implement effective security measures. Furthermore, by combining it with an emotion engine, it is possible to realize more accurate simulations and measures that take into account the user's emotional state.

[0715] Example 2

[0716] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."

[0717] Today's cyber attacks are becoming more sophisticated and diverse, and organizations and companies need effective training and countermeasures to deal with them. However, conventional attack simulation systems do not take into account the user's emotions and psychological state, which can result in ineffective training. Furthermore, it has been difficult to quickly and accurately grasp the latest attack methods and improve adaptability to actual attacks.

[0718] The specific processing by the specific processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means.

[0719] In this invention, the server includes means for collecting data on the latest attack techniques from information providers and online forums, means for analyzing the collected data to extract and classify important information, means for training an AI model based on the analyzed data, means for generating simulated attacks using the trained AI model, means for executing the simulated attacks and collecting and analyzing the results, means for generating reports based on the results of the executed simulated attacks, means for recognizing a user's emotions using an emotion engine, and means for adjusting the content and difficulty of the simulated attacks based on the recognized emotion data. This provides effective countermeasures against the latest cyber attacks, and by conducting training that takes the user's psychological state into consideration, more realistic attack simulations and countermeasures can be achieved.

[0720] An "information provider" is a public or private organization that provides information about cyber attacks.

[0721] An "online forum" is a bulletin board or discussion site on the Web where users exchange information.

[0722] "Data collection" is the process of obtaining the necessary data from information sources and online forums.

[0723] "Data scraping" is the technique of automatically extracting information from websites.

[0724] "Analysis" is the process of processing collected data to extract useful information.

[0725] "Classification" is the process of organizing extracted information into specific categories.

[0726] An "AI model" is a statistical model created using artificial intelligence technology for making predictions and classifications.

[0727] A "mock attack" is a simulated attack that imitates an actual cyber attack.

[0728] An "emotion engine" is a system for recognizing and analyzing a user's emotional state.

[0729] A "report" is a report summarizing the analysis results, including points for improvement and suggestions.

[0730] The present invention relates to a system that efficiently learns the latest cyber-attack techniques and performs simulated attacks based on them. This system operates by integrating the following functions:

[0731] First, let's look at the information collection module. The server collects data on the latest attack techniques from information providers and online forums. This process involves accessing the APIs of the information providers to obtain the latest data and using web scraping techniques to collect information from online forums. As a specific example, it uses the Python requests library to send GET requests to API endpoints and the BeautifulSoup and Scrapy libraries to scrape text data from forum pages.

[0732] The data analysis module then analyzes the collected data to extract and classify key information. The terminal uses the pandas library to create a data frame and perform initial data cleaning. The data is then classified into security categories such as phishing, malware, and DDoS. This can be achieved by using the Scikit-learn K-means clustering algorithm.

[0733] In the model learning module, the server trains the AI ​​model based on the analyzed data, using techniques such as TensorFlow and PyTorch to train neural networks and generate models that can identify new cyber-attack patterns.

[0734] In the attack simulation module, users can use AI models to generate and execute simulated attacks. For example, using OpenAI's GPT series, a generative AI model, users can input the following prompt text to automatically generate the content of a phishing email:

[0735] Create mock phishing emails using the latest phishing techniques

[0736] The generated mock phishing emails are sent to an internal mailing list and the responses are observed.

[0737] The results collection module allows users to collect and analyze the results of simulated attacks, using data collection tools such as Google Analytics and Splunk to compile information such as click rates for phishing emails and the amount of malware detected.

[0738] The report generation module analyzes the collected data and generates a detailed report using Excel or Tableau to visualize the data and summarize the analysis results. The report includes analysis and recommendations for improvement based on the results of the simulated attacks.

[0739] In addition, the emotion engine module allows the device to recognize the user's emotions using the emotion engine, which combines OpenCV and Emotion SDK to analyze the user's facial expressions and behavioral data to reveal their emotional state.

[0740] Finally, the content and difficulty of the simulated attacks are adjusted based on the user's emotional data recognized by the emotion engine. For example, if an employee is overly confused, the difficulty of the next simulated attack may be lowered.

[0741] This system's series of processes enables companies to respond quickly to the latest cyber-attack techniques and also enables effective training that takes into account the emotional state of users.

[0742] The flow of the identification process in the second embodiment will be described with reference to FIG.

[0743] Step 1: Gather information

[0744] The server accesses the API of an intelligence provider to obtain data on the latest cyber attack methods.

[0745] (Input) API endpoint, authentication token

[0746] (Output) Acquired attack information data

[0747] The server uses the Python requests library to send a GET request to the API endpoint and retrieve the data in JSON format.

[0748] The server uses web scraping technology to collect data on attack methods from online forums.

[0749] (Input) Forum URL and target HTML element

[0750] (Output) Scraped text data

[0751] The server uses the BeautifulSoup and Scrapy libraries to extract relevant text data from the HTML pages of the target forums.

[0752] Step 2: Data analysis

[0753] The terminal analyzes the data received from the server and extracts important information.

[0754] (Input) Collected attack information data

[0755] (Output) A clean data frame

[0756] The terminal uses Python's pandas library to create data frames and handle missing and outlier values.

[0757] The device categorizes the data into security categories such as phishing, malware, and DDoS.

[0758] (Input) Clean data frame

[0759] (Output) Attack data by category

[0760] The device clusters the data using Scikit-learn's K-means clustering algorithm.

[0761] Step 3: Model training

[0762] The server trains the AI ​​model based on the analyzed data.

[0763] (Input) Attack data by category

[0764] (Output) Trained AI model

[0765] The server uses TensorFlow and PyTorch to train neural networks and generate models that identify new cyber attack patterns.

[0766] Step 4: Attack simulation

[0767] Users use the trained AI model to generate simulated attacks.

[0768] (Input) Trained AI model

[0769] (Output) Content of the mock attack (e.g., phishing email)

[0770] Users can use a generative AI model (e.g., GPT-3) to automatically generate the content of a phishing email by entering a prompt like the following:

[0771] Create mock phishing emails using the latest phishing techniques

[0772] The user sends the generated email to an internal mailing list.

[0773] Step 5: Collect results

[0774] The user collects and analyzes the results of the simulated attacks.

[0775] (Input) Results of simulated attacks (e.g., click rate, number of detected malware, etc.)

[0776] (Output) Evaluation data

[0777] Users use data collection tools such as Google Analytics and Splunk to compile data on phishing email click rates and the amount of malware detected.

[0778] Step 6: Generate reports

[0779] The terminal analyzes the collected data and generates a detailed report.

[0780] (Input) Evaluation data

[0781] (Output) Detailed report

[0782] The device uses Excel or Tableau to visualize the data and compiles the analysis results into a report, which includes improvements and suggestions.

[0783] Step 7: Emotion Recognition

[0784] The terminal uses an emotion engine to recognize the user's emotions.

[0785] (Input) User facial expression and behavior data

[0786] (Output) User emotion data

[0787] The device uses OpenCV and the Emotion SDK to analyze the user's facial expressions and identify emotional states such as stress or confusion.

[0788] Step 8: Use emotion data

[0789] The content and difficulty of the simulated attack are adjusted based on the user's emotional data.

[0790] (Input) User emotion data

[0791] (Output) Adjusted simulated attack content

[0792] If the emotion engine determines that an employee is overly confused, it will take action such as lowering the difficulty of the next mock attack.

[0793] These steps will enable companies to respond quickly and effectively to the latest cyberattack techniques, and also provide practical training that takes into account the emotional state of users.

[0794] (Application example 2)

[0795] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."

[0796] Cyber-attack threats continue to evolve, causing increasing damage to businesses and individuals. In particular, phishing emails, malware, and DDoS attacks pose numerous security risks. Furthermore, existing countermeasures often cannot quickly adapt to the latest attack methods, necessitating continuous learning and the implementation of simulated attacks. Furthermore, there is a lack of training that takes into account user emotions and reactions, making it difficult to implement effective security measures. To address these challenges, an efficient and flexible security system is needed.

[0797] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 2 is realized by the following means.

[0798] In this invention, the server includes means for collecting data on the latest attack techniques from intelligence agencies and the dark web, means for analyzing the collected data to extract and classify important information, means for training an AI model based on the analyzed data, means for generating simulated attacks using the trained AI model, means for executing the simulated attacks and collecting and analyzing their results, means for generating reports based on the results of the executed simulated attacks, means for simulating the simulated attacks on a user device, and means for collecting user reaction and emotional data and adjusting the content and difficulty of the simulated attacks. This enables rapid and effective learning of the latest cyber-attack techniques and the implementation of simulated attacks, thereby realizing security measures that take user emotions and reactions into account.

[0799] "Information providers" are experts and organizations that provide data on the latest cyber attack techniques.

[0800] The "dark web" is an area of ​​the internet that cannot be accessed through regular search engines and is home to a lot of illegal information and activity.

[0801] "Means of collecting data" refers to methods and devices for obtaining data on the latest attack techniques from intelligence agencies and the dark web.

[0802] "Means for analyzing data to extract and classify important information" refers to methods and devices for analyzing collected data and selecting and classifying necessary information.

[0803] "Means for training AI models" refers to methods or devices that train artificial intelligence based on analyzed data and create machine learning models for specific purposes.

[0804] "Means for generating simulated attacks" means a method or device for generating attack scenarios using a trained AI model.

[0805] "Means for executing simulated attacks and collecting and analyzing the results" refers to methods and devices for executing the generated simulated attacks and collecting and analyzing their effects and reactions as data.

[0806] A "means for generating a report" refers to a method or device that analyzes the results of a simulated attack and creates a detailed report.

[0807] A "user device" is an electronic device that can be directly operated by a user, such as a smartphone, tablet, or PC.

[0808] A "means for simulating" is a method or device for executing a simulated attack in a virtual environment and observing the results.

[0809] "Means for collecting user reaction and emotional data and adjusting the content and difficulty of the simulated attack" refers to a method or device for evaluating the user's behavior and emotions in response to the simulated attack and changing the content and difficulty of the attack based on that evaluation.

[0810] This invention relates to a system that efficiently learns the latest cyber-attack techniques and conducts simulated attacks, incorporating an emotion engine that recognizes user emotions. Specifically, the system collects data on the latest attack techniques from intelligence agencies and the dark web, analyzes the collected data to extract and classify important information, trains an AI model based on the analyzed data, and generates simulated attacks using the trained AI model. The generated simulated attacks are simulated on the user's device, and the results are collected and analyzed. A report is generated based on the results of the simulated attacks, and user reaction and emotional data are collected to adjust the content and difficulty of the simulated attacks.

[0811] The server uses API access and web scraping techniques to collect data from intelligence agencies and the dark web. The collected data is analyzed and classified into categories such as phishing, malware, and DDoS. The analyzed data is then used to train an AI model to identify the latest attack techniques. The trained AI model is then used to generate mock attacks, which are simulated on user devices.

[0812] The device collects the results of simulated attacks and evaluates their effectiveness. Specifically, it collects data such as the click rate of phishing emails and the number of detected malware, and generates reports to evaluate the success rate of attacks and the performance of defense systems. It also uses an emotion engine to analyze user reactions and behavior, allowing it to adjust the content and difficulty of the simulated attacks.

[0813] For example, a specific phishing email can be created and sent internally, and the emotion engine will analyze employees' facial expressions and behavioral data to recognize emotions such as stress or confusion. Based on these results, the difficulty of the simulated attack can be adjusted or the attack method changed. In this way, companies can increase their resilience against the latest cyberattacks and implement more accurate security measures.

[0814] Example prompt sentence:

[0815] Collect the latest phishing attack data and generate a simulation. Capture users' reactions after receiving the notification with a camera and analyze their emotions using the emotion engine. Adjust the simulation accordingly.

[0816] The hardware used is user devices such as smartphones, tablets, and PCs, and the software is primarily written in Python. The requests library and BeautifulSoup are used for data collection, and TensorFlow and PyTorch are used for machine learning. These technologies enable the entire system to operate efficiently and flexibly.

[0817] The flow of the specific processing in the application example 2 will be described with reference to FIG.

[0818] Step 1:

[0819] The server runs a mechanism to collect data on the latest attack techniques from intelligence agencies and the dark web, using API access to retrieve data from intelligence agencies and web scraping techniques to gather additional data from dark web forums and marketplaces. This data contains a variety of information on attack techniques.

[0820] Input: API endpoint of intelligence provider, dark web URL

[0821] Output: Raw data on the latest attack techniques

[0822] Step 2:

[0823] The server then analyzes the collected data and implements measures to extract and classify key information, specifically using natural language processing techniques to analyze the data and categorize it into attack categories such as phishing, malware, and DDoS.

[0824] Input: Unanalyzed data collected in Step 1

[0825] Output: Categorized analysis data

[0826] Step 3:

[0827] The server runs a trainer for the AI ​​model based on the analyzed data. It uses machine learning algorithms to train the model to identify the latest attack techniques. Specifically, it uses TensorFlow and PyTorch to build the model and train it on the analyzed data.

[0828] Input: Data parsed in step 2

[0829] Output: The trained AI model

[0830] Step 4:

[0831] The server executes a means to generate simulated attacks using the trained AI model, generating attack scenarios and converting them into a format that can be executed on the user device.

[0832] Input: The AI ​​model trained in Step 3

[0833] Output: mock attack scenarios and payloads

[0834] Step 5:

[0835] Users deploy the generated simulated attacks in their own security environment and execute them on user devices such as smartphones and PCs. The results of the simulated attacks are collected from the device's sensors and log data.

[0836] Input: The mock attack generated in step 4

[0837] Output: Execution result data (e.g., click rate of phishing emails and number of detected malware)

[0838] Step 6:

[0839] The device executes procedures to analyze the results of the simulated attacks and generate detailed reports, such as creating statistics and graphs of the results, documenting the success rate of the attacks and the evaluation of the defense system.

[0840] Input: The execution result data collected in Step 5

[0841] Output: Detailed report

[0842] Step 7:

[0843] The device uses an emotion engine to recognize the user's emotions during the process of simulating attacks and collecting the results. Specifically, it collects user behavior data from cameras and sensors and uses an emotion analysis algorithm to evaluate the user's level of stress and confusion.

[0844] Input: User camera footage and sensor data

[0845] Output: User emotion data

[0846] Step 8:

[0847] The server uses the emotion data to adjust the content and difficulty of the simulated attack. Specifically, it changes the attack scenario and difficulty according to the user's emotional state, and provides adaptive training for real attacks.

[0848] Input: User emotion data collected in step 7

[0849] Output: Adjusted attack scenarios and difficulty levels

[0850] Example prompt sentence:

[0851] Collect the latest phishing attack data and generate a simulation. Capture users' reactions after receiving the notification with a camera and analyze their emotions using the emotion engine. Adjust the simulation accordingly.

[0852] The specific processing unit 290 transmits the result of the specific processing to the smart glasses 214. In the smart glasses 214, the control unit 46A causes the speaker 240 to output the result of the specific processing. The microphone 238 acquires audio indicating a user input regarding the result of the specific processing. The control unit 46A transmits audio data indicating the user input acquired by the microphone 238 to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.

[0853] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[0854] In the above embodiment, an example in which the specific processing is performed by the data processing device 12 has been given, but the technology of the present disclosure is not limited to this, and the specific processing may be performed by the smart glasses 214.

[0855] [Third embodiment]

[0856] FIG. 5 shows an example of the configuration of a data processing system 310 according to the third embodiment.

[0857] 5, the data processing system 310 includes the data processing device 12 and a headset type terminal 314. An example of the data processing device 12 is a server.

[0858] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[0859] The headset type terminal 314 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication I / F 44, and a display 343. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The microphone 238, the speaker 240, the camera 42, and the display 343 are also connected to the bus 52.

[0860] The microphone 238 receives instructions and the like from the user 20 by receiving voice uttered by the user 20. The microphone 238 captures the voice uttered by the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio in accordance with instructions from the processor 46.

[0861] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the surroundings of user 20 (for example, an imaging range defined by an angle of view equivalent to the field of vision of a typical healthy person).

[0862] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 are responsible for the exchange of various information between the processor 46 and the processor 28 via the network 54. The exchange of various information between the processor 46 and the processor 28 using the communication I / Fs 44 and 26 is carried out in a secure state.

[0863] Fig. 6 shows an example of the main functions of the data processing device 12 and the headset type terminal 314. As shown in Fig. 6, in the data processing device 12, a specific process is performed by the processor 28. A specific process program 56 is stored in the storage 32.

[0864] The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[0865] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[0866] In the headset type terminal 314, a reception output process is performed by the processor 46. A reception output program 60 is stored in the storage 50. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.

[0867] Next, a description will be given of the identification process performed by the identification processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as the "server" and the headset type terminal 314 will be referred to as the "terminal."

[0868] patent specification

[0869] The present invention relates to a system for efficiently learning the latest cyber-attack techniques and conducting simulated attacks. This system has the following functions:

[0870] 1. Information collection module

[0871] The server collects data on the latest attack techniques from intelligence agencies and the dark web by accessing the intelligence agencies' APIs to retrieve the necessary data, and also scrapes data from forums and marketplaces on the dark web.

[0872] 2. Data Analysis Module

[0873] The device analyzes the collected data. First, it processes the collected data to extract necessary information and organizes information about attack methods. Then, it classifies the extracted information into attack categories such as phishing, malware, and DDoS.

[0874] 3. Model Learning Module

[0875] The server trains the AI ​​model based on the analyzed data, using the analyzed information to train machine learning algorithms and generate models that can identify the latest attack techniques.

[0876] 4. Attack Simulation Module

[0877] Users can use the trained AI model to generate mock attacks, deploy the resulting payloads in their security environment, and observe the response. For example, in the case of a phishing attack, they can send mock phishing emails to their company.

[0878] 5. Result Collection Module

[0879] After conducting the simulated attacks, users collect the results, such as click rates for phishing emails sent and the number of employee reports.

[0880] 6. Report Generation Module

[0881] The device analyzes the collected results and generates a detailed report that includes an analysis of the results of the simulated attacks and recommendations for improving security measures.

[0882] Specific examples

[0883] As an example, let's consider a specific company using this system. The company's server begins collecting data from government security agency APIs and the dark web. Next, the device analyzes the data, extracting and classifying important information about phishing and malware attacks. The server uses the analyzed data to train an AI model, which then generates phishing emails based on that model. The user then sends these mock phishing emails to the company and collects responses from employees. Finally, the device compiles the results into a detailed report, assessing the company's security measures and suggesting areas for improvement.

[0884] Through the above process, the system of the present invention increases resistance to the latest cyber attacks and enables the implementation of effective security measures.

[0885] The processing flow will be explained below.

[0886] Processing flow

[0887] Step 1:

[0888] The server accesses the API of the information provider to obtain data on the latest attack techniques. Specifically, it sends a request to the security agency's API endpoint and receives a response. The response contains information such as the latest attack techniques, their overview, and the date and time of occurrence.

[0889] Step 2:

[0890] The server scrapes data from forums and marketplaces on the dark web. Using specialized scraping tools, it extracts text information from specific web pages. The extracted data includes attack techniques, sales information, and related discussions.

[0891] Step 3:

[0892] The terminal analyzes the data received from the server. First, it parses the acquired JSON data and scraped data and converts it into a meaningful format. This allows it to extract the necessary information (type of attack method, details, date and time of occurrence, etc.).

[0893] Step 4:

[0894] The terminal classifies the extracted information into specific categories, such as phishing attacks, malware attacks, DDoS attacks, etc. This classification allows the data to be used efficiently in subsequent processing.

[0895] Step 5:

[0896] The server trains the AI ​​model based on the classified data. It uses the analyzed information to train machine learning algorithms and generate models that can identify the latest attack techniques. This includes data preprocessing, model training, and evaluation.

[0897] Step 6:

[0898] Users can use the trained AI model to generate simulated attacks, generating specific attack payloads (e.g., phishing email content or malware code) based on attack patterns obtained from the AI ​​model.

[0899] Step 7:

[0900] The user deploys the generated simulated attacks in their company's security environment. For example, they send simulated phishing emails to employees' email addresses and observe the responses. The user then monitors how the attacks are countered.

[0901] Step 8:

[0902] Users collect the results of their simulated attacks, including click rates for phishing emails, the number of reports, and the number of malware detected, which will be used for subsequent analysis.

[0903] Step 9:

[0904] The device generates a detailed report based on the collected results, including an analysis of the simulated attacks, an evaluation of security measures, and suggestions for improvement. The report also includes visualization and statistical information of the results.

[0905] Through the above processing steps, the system of the present invention increases resistance to the latest cyber attacks and enables the implementation of effective security measures.

[0906] Example 1

[0907] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."

[0908] The latest cyberattack methods are evolving daily, and there is a need to quickly implement effective security measures to counter them. However, existing security measures lack systems that can efficiently learn the latest attack methods and conduct simulated attacks, leaving companies and organizations vulnerable to advanced cyberattacks.

[0909] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.

[0910] In this invention, the server includes means for collecting data on the latest attack techniques from intelligence agencies and the dark web, means for analyzing the collected data to extract and classify important information, and means for training an AI model using a machine learning algorithm based on the analyzed data. This makes it possible to quickly and efficiently grasp the latest cyber-attack techniques and to improve security measures by conducting simulated attacks.

[0911] An "information provider" refers to an organization or institution that collects and provides security-related information.

[0912] The "dark web" refers to a group of highly anonymous websites that cannot be accessed through regular search engines.

[0913] "Attack methods" refer to the specific techniques and tactics used in cyber attacks.

[0914] "Data collection methods" refer to the methods and tools used to obtain information.

[0915] "API Access" means access to external data or services through an application programming interface.

[0916] "Web scraping" refers to the technique of extracting information from websites.

[0917] "Data analysis methods" refer to methods and tools used to process and analyze collected data to extract meaningful information.

[0918] A "machine learning algorithm" refers to a computational method for learning patterns and rules based on data.

[0919] "AI model" refers to a model of artificial intelligence that has been trained by machine learning algorithms and is capable of performing specific tasks.

[0920] A "payload" refers to the data or code that is actually sent to the target in a cyber attack.

[0921] "Security environment" refers to the overall security measures and infrastructure of an organization or system.

[0922] "Report generation means" refers to methods and tools for generating reports based on collected and analyzed information.

[0923] The present invention relates to a system for efficiently learning the latest cyber-attack techniques and conducting simulated attacks. This system collects data from intelligence agencies and the dark web, analyzes the collected data, trains an AI model based on the analyzed data, generates simulated attacks using the trained AI model, and generates detailed reports by collecting and analyzing the results of the simulated attacks.

[0924] Information gathering

[0925] The server collects data on the latest attack techniques from the APIs of intelligence providers and the dark web. Intelligence providers often have public APIs that provide security information. The server accesses the APIs using HTTP requests and retrieves information in JSON format. It also uses web scraping libraries such as Python's Beautiful Soup and Scrapy to collect information from the dark web. The collected data is stored in an SQL or NoSQL database.

[0926] Data analysis

[0927] The device takes the collected data and preprocesses it using NLP tools (e.g., NLTK or SpaCy). Preprocessing includes tokenizing the text and removing stop words. The analyzed data is then classified into attack categories such as phishing, malware, and DDoS. Algorithms such as decision trees and support vector machines (SVM) are used for classification. The classified data is then stored in JSON format or in a database.

[0928] Model learning

[0929] The server trains an AI model based on the analyzed data. The server builds a neural network model using machine learning libraries such as TensorFlow and PyTorch. The training process includes data preprocessing, model construction, training, and evaluation. The trained model is deployed as an API server and made accessible to other system components.

[0930] Attack Simulation

[0931] Users use the trained AI model to generate mock attack payloads. In this process, users send requests to the model API and receive the generated payloads. Mock attack payloads include, for example, phishing emails and malware executable files. Users then deploy these payloads in their security environment and monitor their impact.

[0932] Results collection and report generation

[0933] The user collects the results of the simulated attacks, including click rates, the number of employee reports, and security system log data. The terminal analyzes the collected data and generates a detailed report that includes the results of the simulated attacks and an evaluation and improvement of security measures. The report is generated and provided to the user in a format that includes graphs and charts using Pandas and Matplotlib.

[0934] Specific examples

[0935] For example, if a particular company uses this system, the company's server collects data on attack methods from government security agency APIs and the dark web. The device analyzes the data, extracting and classifying important information about phishing and malware attacks. The server uses the analyzed data to train an AI model, which then generates phishing emails based on that model. The user sends these mock phishing emails internally and observes and records employee reactions. Finally, the device compiles the results into a detailed report, assessing the company's security measures and recommending areas for improvement.

[0936] Prompt Sentence Examples

[0937] "Write a Python script to collect data on the latest phishing attack techniques, train an AI model based on the analysis results, and generate simulated phishing attacks."

[0938] The above is an embodiment of the present invention.

[0939] The flow of the identification process in the first embodiment will be described with reference to FIG.

[0940] Step 1: Gather information

[0941] The server collects data on the latest attack techniques from intelligence agencies and the dark web.

[0942] Specifically, the server performs the following operations.

[0943] 1.1 The server sends an HTTP request to the provider's API endpoint, including the API key and the search query.

[0944] Input: API endpoint information, API key, search query

[0945] Output: JSON data obtained as an API response

[0946] 1.2 The server analyzes the JSON data received as an API response and extracts the necessary information.

[0947] Input: JSON data of API response

[0948] Output: Data about the extracted attack techniques

[0949] 1.3 The server accesses dark web forums and marketplaces and scrapes data using Beautiful Soup and Scrapy.

[0950] Input: Dark Web website URL

[0951] Output: Data on attack techniques obtained through scraping

[0952] 1.4 The server stores the collected data in a SQL or NoSQL database.

[0953] Input: Data on extracted attack techniques, data obtained by scraping

[0954] Output: Data stored in the database

[0955] Step 2: Data analysis

[0956] The terminal analyzes the collected data.

[0957] Specifically, the terminal performs the following operations.

[0958] 2.1 The terminal retrieves the collected data from the database.

[0959] Input: Database connection information

[0960] Output: Retrieved data

[0961] 2.2 The device preprocesses the data using NLP tools (NLTK or SpaCy), which includes tokenizing the text and removing stop words.

[0962] Input: Retrieved data

[0963] Output: Preprocessed data

[0964] 2.3 The device classifies the pre-processed data into attack categories such as phishing, malware, DDoS, etc. It uses algorithms such as decision trees and SVM for classification.

[0965] Input: Preprocessed data

[0966] Output: Data categorized by attack category

[0967] 2.4 The device stores the classified data in JSON format or in a database.

[0968] Input: Classified data

[0969] Output: JSON formatted data or data stored in a database

[0970] Step 3: Model training

[0971] The server trains the AI ​​model based on the analyzed data.

[0972] Specifically, the server performs the following operations.

[0973] 3.1 The server retrieves the parsed data from the database.

[0974] Input: Database connection information

[0975] Output: Retrieved data

[0976] 3.2 The server builds the neural network model using TensorFlow and PyTorch libraries.

[0977] Input: Acquired data, machine learning library (TensorFlow, PyTorch)

[0978] Output: Building a neural network model

[0979] 3.3 The server trains the model using the training data. It sets the optimizer (Adam, SGD), number of epochs, and batch size.

[0980] Input: training data, optimizer, number of epochs, batch size

[0981] Output: A trained AI model

[0982] 3.4 The server saves the trained model and deploys it as an API server.

[0983] Input: A trained AI model

[0984] Output: Deployed model API

[0985] Step 4: Attack simulation

[0986] Users use the trained AI model to generate simulated attacks.

[0987] Specifically, the user performs the following operations.

[0988] 4.1 The user sends a request to the model API to generate a mock attack payload, including attack category and target information.

[0989] Input: Model API endpoint, request parameters (attack category, target information)

[0990] Output: Generated mock attack payload

[0991] 4.2 The user deploys the generated payload in their security environment, for example by sending a phishing email using the Gmail API.

[0992] Input: Generated payload, security environment information

[0993] Output: Deployed payload

[0994] 4.3 Users monitor the security environment for responses during simulated attacks, using syslog and incident response systems.

[0995] Input: Security environment information, mock attack payload

[0996] Output: Reaction data of the monitored security environment

[0997] Step 5: Collect results

[0998] After conducting the simulated attacks, the user collects the results.

[0999] Specifically, the user performs the following operations.

[1000] 5.1 The user obtains log and activity data from the security environment.

[1001] Input: Security environment information

[1002] Output: Acquired log data and activity data

[1003] 5.2 The user calculates metrics such as click-through rates and employee reporting numbers.

[1004] Input: Captured log data and activity data

[1005] Output: Calculated metrics

[1006] 5.3 The user stores the collected data in a database.

[1007] Inputs: Calculated metrics, log data, activity data

[1008] Output: Result data stored in a database

[1009] Step 6: Generate reports

[1010] The terminal analyzes the collected results and generates a detailed report.

[1011] Specifically, the terminal performs the following operations.

[1012] 6.1 The terminal retrieves the collected result data from the database.

[1013] Input: Database connection information

[1014] Output: Acquired result data

[1015] 6.2 The device aggregates data and calculates key metrics using the Pandas library.

[1016] Input: Result data, Pandas library

[1017] Output: Aggregated data, calculated metrics

[1018] 6.3 The terminal uses the Matplotlib and Seaborn libraries to create graphs and charts.

[1019] Input: Aggregated data, calculated metrics, Matplotlib library, Seaborn library

[1020] Output: Generated graphs and charts

[1021] 6.4 The terminal will generate a report along with the generated graphs and suggest improvements to security measures.

[1022] Input: Generated graphs, charts, and analysis results

[1023] Output: Detailed report and improvement suggestions

[1024] (Application example 1)

[1025] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."

[1026] Modern cyberattack methods are becoming increasingly complex and diverse, requiring both companies and individual users to implement countermeasures against attacks that cannot be prevented by conventional methods. Furthermore, implementing effective security measures requires the rapid collection of information on the latest attack methods and the rapid application of countermeasures based on that information. However, performing these steps manually is extremely difficult, and there are limited methods for evaluating defense capabilities before an actual attack occurs.

[1027] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.

[1028] In this invention, the server includes means for collecting data on the latest attack techniques from intelligence agencies and the dark web, means for analyzing the collected data to extract and classify important information, means for training an AI model based on the analyzed data, means for generating simulated attacks using the trained AI model, means for executing the simulated attacks and collecting and analyzing their results, means for generating reports based on the results of the executed simulated attacks, and means for notifying the user of the results to their mobile device. This allows users to quickly respond to the latest attack techniques while evaluating and strengthening their company's defenses. Furthermore, notifying the user of the results to their mobile device allows them to take immediate countermeasures.

[1029] An "information provider" is an organization or group that provides information on cyber attack methods.

[1030] The "dark web" is an encrypted part of the internet that cannot be accessed through regular search engines.

[1031] "Data collection means" refers to methods and devices for collecting data on cyber attack techniques from intelligence agencies and the dark web.

[1032] "Analysis means" refers to a method or device that analyzes collected data and extracts and classifies important information.

[1033] An "AI model" is a data model trained using machine learning algorithms.

[1034] A "learning tool" is a method or device that trains an AI model based on collected and analyzed data.

[1035] A "simulated attack generation means" is a method or device that generates simulated cyber attacks using a trained AI model.

[1036] A "mock attack execution means" is a method or device for executing the generated mock attack and observing its effect.

[1037] A "result collection means" is a method or device for collecting the results of the executed simulated attacks.

[1038] A "results analysis means" is a method or device for analyzing collected results and generating a report.

[1039] A "report generator" is a method or apparatus for generating a detailed report based on the results of a simulated attack.

[1040] "Notification means" refers to a method or device for notifying the user's mobile terminal of the results of the simulated attack and related information.

[1041] The system for realizing this invention is mainly composed of a server, a terminal, and a user. The detailed configuration and usage method are described below.

[1042] Data collection from intelligence agencies and the dark web

[1043] The server first collects data on the latest attack techniques from intelligence agencies' APIs and the dark web. The collected data includes detailed descriptions of the attack techniques, the steps of the attack, and the tools and methods used. This allows for the creation of a comprehensive database of the latest attack techniques.

[1044] Data analysis

[1045] The device analyzes the collected data received from the server. Specifically, it preprocesses the collected data and extracts necessary information. It then classifies the extracted information into attack categories such as phishing, malware, and DDoS.

[1046] Training an AI model

[1047] The server trains the AI ​​model based on the data analyzed by the device. The machine learning algorithm used here is trained to accurately identify cyber attack methods. The trained AI model is then applied to newly collected data, ensuring it is always adaptable to the latest attack methods.

[1048] Generating and Executing Mock Attacks

[1049] Users can use the trained AI model to generate simulated attacks. They can customize the scenarios. The generated simulated attacks are deployed as payloads in their own security environments, and their responses are observed. For example, in the case of a phishing attack, a simulated phishing email is sent internally.

[1050] Collection and analysis of results

[1051] After conducting the simulated attack, the user collects the results, including data such as the click rate for phishing emails sent and the number of employee reports. This data is then further analyzed on the device and used to evaluate the security environment.

[1052] Report generation and notification

[1053] The device generates a detailed report based on the collected results. This report includes an analysis of the simulated attack results and recommendations for improving security measures. The report is then sent to the user's mobile device, allowing for immediate action.

[1054] Hardware and Software Examples

[1055] The specific hardware and software used to realize this system include Python, requests, scrapy, scikit-learn, numpy, and json. Python is the main implementation language of the program, requests is used to collect data from APIs, scrapy is used for web scraping of data, and scikit-learn is used to train machine learning algorithms. numpy helps analyze the data, and json is used to store the results and generate reports.

[1056] Specific examples

[1057] For example, a security department might periodically create and send mock phishing emails to assess employees' security practices. Using this system, the assessment can be performed quickly, accurately, and without hassle.

[1058] Example prompts for generative AI models

[1059] "Please provide us with data on the latest phishing attack techniques."

[1060] "Predict the effectiveness of this simulated phishing email attack."

[1061] In this way, the present invention is a system that increases resistance to the latest cyber attacks and enables effective implementation of security measures.

[1062] The flow of the specific processing in the application example 1 will be described with reference to FIG.

[1063] Step 1:

[1064] The server collects data on the latest attack techniques from information provider APIs and the dark web. The inputs include the API endpoint URL and the website URL to be scraped. The data collection method uses requests to retrieve data from the API and scrape data from the dark web using scrapy. The output is raw attack technique data, including details of the attack technique, attack steps, and information about the tools used.

[1065] Step 2:

[1066] The terminal analyzes the collected data and extracts and classifies the necessary information. The input is the raw data received from the server. Natural language processing (NLP) techniques are used for data analysis to extract important information. The extracted information is then classified into categories such as phishing, malware, and DDoS. The output is analyzed and classified information on attack techniques.

[1067] Step 3:

[1068] The server trains an AI model based on the analyzed data. The input is the analyzed and classified data received from the device. The machine learning algorithm used is scikit-learn, which trains the AI ​​model using the analyzed information. The model training process includes feature extraction, data splitting, model training, and evaluation. The output is an AI model that can identify the latest attack techniques.

[1069] Step 4:

[1070] Users generate mock attacks using the trained AI model. The input is the trained AI model and a customized attack scenario. The model generates a mock attack payload based on the given scenario. The output is the generated mock attack, which specifically includes mock phishing emails and malicious scripts.

[1071] Step 5:

[1072] The user executes the generated mock attacks and collects the results. The input is the payload of the generated mock attacks. The mock attacks are deployed in the user's security environment and their behavior is observed. The collected results include data such as click rates for phishing emails and the number of employee reports. The output is the result data of the mock attacks.

[1073] Step 6:

[1074] The device analyzes the collected results and generates a detailed report. The input is the result data of the simulated attacks. The data analysis method again uses NLP technology to analyze the result data. The report generation includes analyzing the results and suggesting areas for improving security measures. The output is a detailed analysis report, which is sent to the user's mobile device.

[1075] This enables users to quickly implement countermeasures against the latest cyber-attack methods and evaluate and strengthen their defenses.

[1076] Furthermore, an emotion engine that estimates the user's emotion may be further combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59, and perform identification processing using the user's emotion.

[1077] patent specification

[1078] This invention relates to a system that efficiently learns the latest cyber-attack techniques and performs simulated attacks, and further combines it with an emotion engine that recognizes the user's emotions. This system has the following functions:

[1079] 1. Information collection module

[1080] The server collects data on the latest attack techniques from intelligence agencies and the dark web by accessing intelligence agency APIs to retrieve data and scraping data from forums and marketplaces on the dark web.

[1081] 2. Data Analysis Module

[1082] The terminal analyzes the collected data, processes it to extract important information, and then classifies it into attack categories such as phishing, malware, and DDoS, which allows for efficient organization of the information.

[1083] 3. Model Learning Module

[1084] The server trains the AI ​​model based on the analyzed data. The analyzed data is used to train machine learning algorithms and generate an AI model that can identify the latest attack techniques.

[1085] 4. Attack Simulation Module

[1086] Users can use the trained AI model to generate mock attacks, deploy the resulting attack payloads in their security environment, and observe their reactions—for example, by creating specific phishing emails and sending them internally.

[1087] 5. Result Collection Module

[1088] Users collect the results of the simulated attacks, such as the click rate of phishing emails and the number of detected malware, which allows them to evaluate the effectiveness of the attacks.

[1089] 6. Report Generation Module

[1090] The device analyzes the collected results and generates a detailed report that includes analysis and recommendations for improving security measures based on the results of the simulated attacks.

[1091] 7. Emotion Engine Module

[1092] The device uses an emotion engine to recognize the user's emotions during the process of simulating attacks and collecting execution results. The emotion engine analyzes the user's reactions and behavior to identify their emotional state. For example, the emotion engine analyzes the facial expressions and behavioral data of an employee who receives a phishing email and recognizes emotions such as stress and confusion.

[1093] 8. Use of Emotional Data

[1094] The content and difficulty of the simulated attacks are adjusted based on the user's emotional data recognized by the emotion engine. For example, if employees are overly confused, the difficulty of the simulated attacks can be lowered or the attack method changed. This increases the effectiveness of countermeasures against real attacks.

[1095] Specific examples

[1096] As an example, let's consider a company using this system. The server collects the latest phishing attack data from government security agency APIs and the dark web. The device analyzes the data and classifies it into phishing categories, and the server uses this data to train an AI model. Based on the trained model, the user generates mock phishing emails and deploys them within the company. The emotion engine analyzes employee reactions and adjusts the content and difficulty of the emails based on these results. Finally, all results are compiled to generate a report that proposes security measures.

[1097] This system will enable companies to increase their resistance to the latest cyber attacks and implement effective security measures. Furthermore, by combining it with an emotion engine, it will be possible to realize more accurate simulations and countermeasures that take into account the user's emotional state.

[1098] The processing flow will be explained below.

[1099] patent specification

[1100] The processing flow of the system will be explained in the following steps.

[1101] Step 1:

[1102] The server accesses the API of the information provider to obtain data on the latest attack techniques. Specifically, it sends a request to the security agency's API endpoint and receives a response. The response contains information such as the latest attack techniques, their overview, and the date and time of occurrence.

[1103] Step 2:

[1104] The server scrapes specific web pages to collect data on attack techniques from the dark web. Using a scraping tool, the server extracts the necessary information from forums and marketplaces on the dark web. The extracted data includes details of attack techniques, sales information, and related discussion content.

[1105] Step 3:

[1106] The device analyzes the collected data. Specifically, it analyzes the acquired JSON data and scraping data to extract information such as the type and details of the attack method, and the date and time of the attack. The analyzed data is organized by attack method.

[1107] Step 4:

[1108] The device classifies the analyzed information into categories such as phishing, malware, and DDoS. For example, among the extracted information, data related to phishing is classified into the phishing category, and data related to malware is classified into the malware category. This allows information to be organized efficiently.

[1109] Step 5:

[1110] The server trains the AI ​​model based on the classified data. The analyzed data is used to train machine learning algorithms and generate an AI model that can identify the latest attack techniques. The trained AI model is capable of mimicking the generation of phishing emails and malware behavior.

[1111] Step 6:

[1112] Users can use the trained AI model to generate simulated attacks, for example by generating phishing email content from the AI ​​model and preparing the email as a simulated attack. The generated attack payload is tailored to their company's security environment.

[1113] Step 7:

[1114] Users deploy the generated simulated attacks in their company's security environment. For example, they can send simulated phishing emails to employees' email addresses and observe their responses. Data is collected about the deployed simulated attacks, including the number of clicks and reports by employees.

[1115] Step 8:

[1116] Users collect the results of the simulated attacks, such as employee reactions to phishing emails and the amount of malware detected, which allows them to evaluate the effectiveness of the attacks.

[1117] Step 9:

[1118] The device generates a detailed report based on the collected results, including an analysis of the simulated attack results, an evaluation of security measures, and recommendations for improvement. The report also includes visualization and statistical information of the results.

[1119] Step 10:

[1120] The device uses an emotion engine to recognize the user's emotions during the process of simulating attacks and collecting execution results. The emotion engine analyzes the user's reactions and behavior to identify their emotional state. For example, the emotion engine analyzes the facial expressions and behavioral data of an employee who receives a phishing email and recognizes emotions such as stress and confusion.

[1121] Step 11:

[1122] The device uses the user's emotional data recognized by the emotion engine to adjust the content and difficulty of the simulated attacks. For example, if an employee is overly confused, the device can lower the difficulty of the simulated attacks or adjust the attack methods. This provides an environment in which employees can learn appropriately.

[1123] Step 12:

[1124] The device then uses the emotion engine to recognize the user's emotional data and includes in a report the evaluation results of the security measures and suggestions for improvement. The report includes an analysis that reflects the emotional data and details of areas for improvement, providing specific advice for strengthening a company's security measures.

[1125] The above is a specific embodiment for carrying out the present invention. This system can increase resistance to the latest cyber attacks and implement effective security measures. Furthermore, by combining it with an emotion engine, it is possible to realize more accurate simulations and measures that take into account the user's emotional state.

[1126] Example 2

[1127] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."

[1128] Today's cyber attacks are becoming more sophisticated and diverse, and organizations and companies need effective training and countermeasures to deal with them. However, conventional attack simulation systems do not take into account the user's emotions and psychological state, which can result in ineffective training. Furthermore, it has been difficult to quickly and accurately grasp the latest attack methods and improve adaptability to actual attacks.

[1129] The specific processing by the specific processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means.

[1130] In this invention, the server includes means for collecting data on the latest attack techniques from information providers and online forums, means for analyzing the collected data to extract and classify important information, means for training an AI model based on the analyzed data, means for generating simulated attacks using the trained AI model, means for executing the simulated attacks and collecting and analyzing the results, means for generating reports based on the results of the executed simulated attacks, means for recognizing a user's emotions using an emotion engine, and means for adjusting the content and difficulty of the simulated attacks based on the recognized emotion data. This provides effective countermeasures against the latest cyber attacks, and by conducting training that takes the user's psychological state into consideration, more realistic attack simulations and countermeasures can be achieved.

[1131] An "information provider" is a public or private organization that provides information about cyber attacks.

[1132] An "online forum" is a bulletin board or discussion site on the Web where users exchange information.

[1133] "Data collection" is the process of obtaining the necessary data from information sources and online forums.

[1134] "Data scraping" is the technique of automatically extracting information from websites.

[1135] "Analysis" is the process of processing collected data to extract useful information.

[1136] "Classification" is the process of organizing extracted information into specific categories.

[1137] An "AI model" is a statistical model created using artificial intelligence technology for making predictions and classifications.

[1138] A "mock attack" is a simulated attack that imitates an actual cyber attack.

[1139] An "emotion engine" is a system for recognizing and analyzing a user's emotional state.

[1140] A "report" is a report summarizing the analysis results, including points for improvement and suggestions.

[1141] The present invention relates to a system that efficiently learns the latest cyber-attack techniques and performs simulated attacks based on them. This system operates by integrating the following functions:

[1142] First, let's look at the information collection module. The server collects data on the latest attack techniques from information providers and online forums. This process involves accessing the APIs of the information providers to obtain the latest data and using web scraping techniques to collect information from online forums. As a specific example, it uses the Python requests library to send GET requests to API endpoints and the BeautifulSoup and Scrapy libraries to scrape text data from forum pages.

[1143] The data analysis module then analyzes the collected data to extract and classify key information. The terminal uses the pandas library to create a data frame and perform initial data cleaning. The data is then classified into security categories such as phishing, malware, and DDoS. This can be achieved by using the Scikit-learn K-means clustering algorithm.

[1144] In the model learning module, the server trains the AI ​​model based on the analyzed data, using techniques such as TensorFlow and PyTorch to train neural networks and generate models that can identify new cyber-attack patterns.

[1145] In the attack simulation module, users can use AI models to generate and execute simulated attacks. For example, using OpenAI's GPT series, a generative AI model, users can input the following prompt text to automatically generate the content of a phishing email:

[1146] Create mock phishing emails using the latest phishing techniques

[1147] The generated mock phishing emails are sent to an internal mailing list and the responses are observed.

[1148] The results collection module allows users to collect and analyze the results of simulated attacks, using data collection tools such as Google Analytics and Splunk to compile information such as click rates for phishing emails and the amount of malware detected.

[1149] The report generation module analyzes the collected data and generates a detailed report using Excel or Tableau to visualize the data and summarize the analysis results. The report includes analysis and recommendations for improvement based on the results of the simulated attacks.

[1150] In addition, the emotion engine module allows the device to recognize the user's emotions using the emotion engine, which combines OpenCV and Emotion SDK to analyze the user's facial expressions and behavioral data to reveal their emotional state.

[1151] Finally, the content and difficulty of the simulated attacks are adjusted based on the user's emotional data recognized by the emotion engine. For example, if an employee is overly confused, the difficulty of the next simulated attack may be lowered.

[1152] This system's series of processes enables companies to respond quickly to the latest cyber-attack techniques and also enables effective training that takes into account the emotional state of users.

[1153] The flow of the identification process in the second embodiment will be described with reference to FIG.

[1154] Step 1: Gather information

[1155] The server accesses the API of an intelligence provider to obtain data on the latest cyber attack methods.

[1156] (Input) API endpoint, authentication token

[1157] (Output) Acquired attack information data

[1158] The server uses the Python requests library to send a GET request to the API endpoint and retrieve the data in JSON format.

[1159] The server uses web scraping technology to collect data on attack methods from online forums.

[1160] (Input) Forum URL and target HTML element

[1161] (Output) Scraped text data

[1162] The server uses the BeautifulSoup and Scrapy libraries to extract relevant text data from the HTML pages of the target forums.

[1163] Step 2: Data analysis

[1164] The terminal analyzes the data received from the server and extracts important information.

[1165] (Input) Collected attack information data

[1166] (Output) A clean data frame

[1167] The terminal uses Python's pandas library to create data frames and handle missing and outlier values.

[1168] The device categorizes the data into security categories such as phishing, malware, and DDoS.

[1169] (Input) Clean data frame

[1170] (Output) Attack data by category

[1171] The device clusters the data using Scikit-learn's K-means clustering algorithm.

[1172] Step 3: Model training

[1173] The server trains the AI ​​model based on the analyzed data.

[1174] (Input) Attack data by category

[1175] (Output) Trained AI model

[1176] The server uses TensorFlow and PyTorch to train neural networks and generate models that identify new cyber attack patterns.

[1177] Step 4: Attack simulation

[1178] Users use the trained AI model to generate simulated attacks.

[1179] (Input) Trained AI model

[1180] (Output) Content of the mock attack (e.g., phishing email)

[1181] Users can use a generative AI model (e.g., GPT-3) to automatically generate the content of a phishing email by entering a prompt like the following:

[1182] Create mock phishing emails using the latest phishing techniques

[1183] The user sends the generated email to an internal mailing list.

[1184] Step 5: Collect results

[1185] The user collects and analyzes the results of the simulated attacks.

[1186] (Input) Results of simulated attacks (e.g., click rate, number of detected malware, etc.)

[1187] (Output) Evaluation data

[1188] Users use data collection tools such as Google Analytics and Splunk to compile data on phishing email click rates and the amount of malware detected.

[1189] Step 6: Generate reports

[1190] The terminal analyzes the collected data and generates a detailed report.

[1191] (Input) Evaluation data

[1192] (Output) Detailed report

[1193] The device uses Excel or Tableau to visualize the data and compiles the analysis results into a report, which includes improvements and suggestions.

[1194] Step 7: Emotion Recognition

[1195] The terminal uses an emotion engine to recognize the user's emotions.

[1196] (Input) User facial expression and behavior data

[1197] (Output) User emotion data

[1198] The device uses OpenCV and the Emotion SDK to analyze the user's facial expressions and identify emotional states such as stress or confusion.

[1199] Step 8: Use emotion data

[1200] The content and difficulty of the simulated attack are adjusted based on the user's emotional data.

[1201] (Input) User emotion data

[1202] (Output) Adjusted simulated attack content

[1203] If the emotion engine determines that an employee is overly confused, it will take action such as lowering the difficulty of the next mock attack.

[1204] These steps will enable companies to respond quickly and effectively to the latest cyberattack techniques, and also provide practical training that takes into account the emotional state of users.

[1205] (Application example 2)

[1206] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."

[1207] Cyber-attack threats continue to evolve, causing increasing damage to businesses and individuals. In particular, phishing emails, malware, and DDoS attacks pose numerous security risks. Furthermore, existing countermeasures often cannot quickly adapt to the latest attack methods, necessitating continuous learning and the implementation of simulated attacks. Furthermore, there is a lack of training that takes into account user emotions and reactions, making it difficult to implement effective security measures. To address these challenges, an efficient and flexible security system is needed.

[1208] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 2 is realized by the following means.

[1209] In this invention, the server includes means for collecting data on the latest attack techniques from intelligence agencies and the dark web, means for analyzing the collected data to extract and classify important information, means for training an AI model based on the analyzed data, means for generating simulated attacks using the trained AI model, means for executing the simulated attacks and collecting and analyzing their results, means for generating reports based on the results of the executed simulated attacks, means for simulating the simulated attacks on a user device, and means for collecting user reaction and emotional data and adjusting the content and difficulty of the simulated attacks. This enables rapid and effective learning of the latest cyber-attack techniques and the implementation of simulated attacks, thereby realizing security measures that take user emotions and reactions into account.

[1210] "Information providers" are experts and organizations that provide data on the latest cyber attack techniques.

[1211] The "dark web" is an area of ​​the internet that cannot be accessed through regular search engines and is home to a lot of illegal information and activity.

[1212] "Means of collecting data" refers to methods and devices for obtaining data on the latest attack techniques from intelligence agencies and the dark web.

[1213] "Means for analyzing data to extract and classify important information" refers to methods and devices for analyzing collected data and selecting and classifying necessary information.

[1214] "Means for training AI models" refers to methods or devices that train artificial intelligence based on analyzed data and create machine learning models for specific purposes.

[1215] "Means for generating simulated attacks" means a method or device for generating attack scenarios using a trained AI model.

[1216] "Means for executing simulated attacks and collecting and analyzing the results" refers to methods and devices for executing the generated simulated attacks and collecting and analyzing their effects and reactions as data.

[1217] A "means for generating a report" refers to a method or device that analyzes the results of a simulated attack and creates a detailed report.

[1218] A "user device" is an electronic device that can be directly operated by a user, such as a smartphone, tablet, or PC.

[1219] A "means for simulating" is a method or device for executing a simulated attack in a virtual environment and observing the results.

[1220] "Means for collecting user reaction and emotional data and adjusting the content and difficulty of the simulated attack" refers to a method or device for evaluating the user's behavior and emotions in response to the simulated attack and changing the content and difficulty of the attack based on that evaluation.

[1221] This invention relates to a system that efficiently learns the latest cyber-attack techniques and conducts simulated attacks, incorporating an emotion engine that recognizes user emotions. Specifically, the system collects data on the latest attack techniques from intelligence agencies and the dark web, analyzes the collected data to extract and classify important information, trains an AI model based on the analyzed data, and generates simulated attacks using the trained AI model. The generated simulated attacks are simulated on the user's device, and the results are collected and analyzed. A report is generated based on the results of the simulated attacks, and user reaction and emotional data are collected to adjust the content and difficulty of the simulated attacks.

[1222] The server uses API access and web scraping techniques to collect data from intelligence agencies and the dark web. The collected data is analyzed and classified into categories such as phishing, malware, and DDoS. The analyzed data is then used to train an AI model to identify the latest attack techniques. The trained AI model is then used to generate mock attacks, which are simulated on user devices.

[1223] The device collects the results of simulated attacks and evaluates their effectiveness. Specifically, it collects data such as the click rate of phishing emails and the number of detected malware, and generates reports to evaluate the success rate of attacks and the performance of defense systems. It also uses an emotion engine to analyze user reactions and behavior, allowing it to adjust the content and difficulty of the simulated attacks.

[1224] For example, a specific phishing email can be created and sent internally, and the emotion engine will analyze employees' facial expressions and behavioral data to recognize emotions such as stress or confusion. Based on these results, the difficulty of the simulated attack can be adjusted or the attack method changed. In this way, companies can increase their resilience against the latest cyberattacks and implement more accurate security measures.

[1225] Example prompt sentence:

[1226] Collect the latest phishing attack data and generate a simulation. Capture users' reactions after receiving the notification with a camera and analyze their emotions using the emotion engine. Adjust the simulation accordingly.

[1227] The hardware used is user devices such as smartphones, tablets, and PCs, and the software is primarily written in Python. The requests library and BeautifulSoup are used for data collection, and TensorFlow and PyTorch are used for machine learning. These technologies enable the entire system to operate efficiently and flexibly.

[1228] The flow of the specific processing in the application example 2 will be described with reference to FIG.

[1229] Step 1:

[1230] The server runs a mechanism to collect data on the latest attack techniques from intelligence agencies and the dark web, using API access to retrieve data from intelligence agencies and web scraping techniques to gather additional data from dark web forums and marketplaces. This data contains a variety of information on attack techniques.

[1231] Input: API endpoint of intelligence provider, dark web URL

[1232] Output: Raw data on the latest attack techniques

[1233] Step 2:

[1234] The server then analyzes the collected data and implements measures to extract and classify key information, specifically using natural language processing techniques to analyze the data and categorize it into attack categories such as phishing, malware, and DDoS.

[1235] Input: Unanalyzed data collected in Step 1

[1236] Output: Categorized analysis data

[1237] Step 3:

[1238] The server runs a trainer for the AI ​​model based on the analyzed data. It uses machine learning algorithms to train the model to identify the latest attack techniques. Specifically, it uses TensorFlow and PyTorch to build the model and train it on the analyzed data.

[1239] Input: Data parsed in step 2

[1240] Output: The trained AI model

[1241] Step 4:

[1242] The server executes a means to generate simulated attacks using the trained AI model, generating attack scenarios and converting them into a format that can be executed on the user device.

[1243] Input: The AI ​​model trained in Step 3

[1244] Output: mock attack scenarios and payloads

[1245] Step 5:

[1246] Users deploy the generated simulated attacks in their own security environment and execute them on user devices such as smartphones and PCs. The results of the simulated attacks are collected from the device's sensors and log data.

[1247] Input: The mock attack generated in step 4

[1248] Output: Execution result data (e.g., click rate of phishing emails and number of detected malware)

[1249] Step 6:

[1250] The device executes procedures to analyze the results of the simulated attacks and generate detailed reports, such as creating statistics and graphs of the results, documenting the success rate of the attacks and the evaluation of the defense system.

[1251] Input: The execution result data collected in Step 5

[1252] Output: Detailed report

[1253] Step 7:

[1254] The device uses an emotion engine to recognize the user's emotions during the process of simulating attacks and collecting the results. Specifically, it collects user behavior data from cameras and sensors and uses an emotion analysis algorithm to evaluate the user's level of stress and confusion.

[1255] Input: User camera footage and sensor data

[1256] Output: User emotion data

[1257] Step 8:

[1258] The server uses the emotion data to adjust the content and difficulty of the simulated attack. Specifically, it changes the attack scenario and difficulty according to the user's emotional state, and provides adaptive training for real attacks.

[1259] Input: User emotion data collected in step 7

[1260] Output: Adjusted attack scenarios and difficulty levels

[1261] Example prompt sentence:

[1262] Collect the latest phishing attack data and generate a simulation. Capture users' reactions after receiving the notification with a camera and analyze their emotions using the emotion engine. Adjust the simulation accordingly.

[1263] The specific processing unit 290 transmits the result of the specific processing to the headset type terminal 314. In the headset type terminal 314, the control unit 46A causes the speaker 240 and the display 343 to output the result of the specific processing. The microphone 238 acquires audio indicating a user input regarding the result of the specific processing. The control unit 46A transmits audio data indicating the user input acquired by the microphone 238 to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.

[1264] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[1265] In the above embodiment, an example was given in which the specific processing is performed by the data processing device 12, but the technology of the present disclosure is not limited to this, and the specific processing may be performed by the headset type terminal 314.

[1266] [Fourth embodiment]

[1267] FIG. 7 shows an example of the configuration of a data processing system 410 according to the fourth embodiment.

[1268] 7, a data processing system 410 includes a data processing device 12 and a robot 414. An example of the data processing device 12 is a server.

[1269] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[1270] The robot 414 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication I / F 44, and a control target 443. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The microphone 238, the speaker 240, the camera 42, and the control target 443 are also connected to the bus 52.

[1271] The microphone 238 receives instructions and the like from the user 20 by receiving voice uttered by the user 20. The microphone 238 captures the voice uttered by the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio in accordance with instructions from the processor 46.

[1272] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the surroundings of user 20 (for example, an imaging range defined by an angle of view equivalent to the field of vision of a typical healthy person).

[1273] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 are responsible for the exchange of various information between the processor 46 and the processor 28 via the network 54. The exchange of various information between the processor 46 and the processor 28 using the communication I / Fs 44 and 26 is carried out in a secure state.

[1274] The control object 443 includes a display device, LEDs in the eyes, and motors for driving the arms, hands, and feet. The posture and gestures of the robot 414 are controlled by controlling the motors of the arms, hands, and feet. Some of the emotions of the robot 414 can be expressed by controlling these motors. In addition, the facial expressions of the robot 414 can also be expressed by controlling the light emission state of the LEDs in the eyes of the robot 414.

[1275] Fig. 8 shows an example of the main functions of the data processing device 12 and the robot 414. As shown in Fig. 8, in the data processing device 12, a specific process is performed by the processor 28. A specific process program 56 is stored in the storage 32.

[1276] The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[1277] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[1278] In the robot 414, the processor 46 performs the reception output process. A reception output program 60 is stored in the storage 50. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.

[1279] Next, a description will be given of the specific processing performed by the specific processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."

[1280] patent specification

[1281] The present invention relates to a system for efficiently learning the latest cyber-attack techniques and conducting simulated attacks. This system has the following functions:

[1282] 1. Information collection module

[1283] The server collects data on the latest attack techniques from intelligence agencies and the dark web by accessing the intelligence agencies' APIs to retrieve the necessary data, and also scrapes data from forums and marketplaces on the dark web.

[1284] 2. Data Analysis Module

[1285] The device analyzes the collected data. First, it processes the collected data to extract necessary information and organizes information about attack methods. Then, it classifies the extracted information into attack categories such as phishing, malware, and DDoS.

[1286] 3. Model Learning Module

[1287] The server trains the AI ​​model based on the analyzed data, using the analyzed information to train machine learning algorithms and generate models that can identify the latest attack techniques.

[1288] 4. Attack Simulation Module

[1289] Users can use the trained AI model to generate mock attacks, deploy the resulting payloads in their security environment, and observe the response. For example, in the case of a phishing attack, they can send mock phishing emails to their company.

[1290] 5. Result Collection Module

[1291] After conducting the simulated attacks, users collect the results, such as click rates for phishing emails sent and the number of employee reports.

[1292] 6. Report Generation Module

[1293] The device analyzes the collected results and generates a detailed report that includes an analysis of the results of the simulated attacks and recommendations for improving security measures.

[1294] Specific examples

[1295] As an example, let's consider a specific company using this system. The company's server begins collecting data from government security agency APIs and the dark web. Next, the device analyzes the data, extracting and classifying important information about phishing and malware attacks. The server uses the analyzed data to train an AI model, which then generates phishing emails based on that model. The user then sends these mock phishing emails to the company and collects responses from employees. Finally, the device compiles the results into a detailed report, assessing the company's security measures and suggesting areas for improvement.

[1296] Through the above process, the system of the present invention increases resistance to the latest cyber attacks and enables the implementation of effective security measures.

[1297] The processing flow will be explained below.

[1298] Processing flow

[1299] Step 1:

[1300] The server accesses the API of the information provider to obtain data on the latest attack techniques. Specifically, it sends a request to the security agency's API endpoint and receives a response. The response contains information such as the latest attack techniques, their overview, and the date and time of occurrence.

[1301] Step 2:

[1302] The server scrapes data from forums and marketplaces on the dark web. Using specialized scraping tools, it extracts text information from specific web pages. The extracted data includes attack techniques, sales information, and related discussions.

[1303] Step 3:

[1304] The terminal analyzes the data received from the server. First, it parses the acquired JSON data and scraped data and converts it into a meaningful format. This allows it to extract the necessary information (type of attack method, details, date and time of occurrence, etc.).

[1305] Step 4:

[1306] The terminal classifies the extracted information into specific categories, such as phishing attacks, malware attacks, DDoS attacks, etc. This classification allows the data to be used efficiently in subsequent processing.

[1307] Step 5:

[1308] The server trains the AI ​​model based on the classified data. It uses the analyzed information to train machine learning algorithms and generate models that can identify the latest attack techniques. This includes data preprocessing, model training, and evaluation.

[1309] Step 6:

[1310] Users can use the trained AI model to generate simulated attacks, generating specific attack payloads (e.g., phishing email content or malware code) based on attack patterns obtained from the AI ​​model.

[1311] Step 7:

[1312] The user deploys the generated simulated attacks in their company's security environment. For example, they send simulated phishing emails to employees' email addresses and observe the responses. The user then monitors how the attacks are countered.

[1313] Step 8:

[1314] Users collect the results of their simulated attacks, including click rates for phishing emails, the number of reports, and the number of malware detected, which will be used for subsequent analysis.

[1315] Step 9:

[1316] The device generates a detailed report based on the collected results, including an analysis of the simulated attacks, an evaluation of security measures, and suggestions for improvement. The report also includes visualization and statistical information of the results.

[1317] Through the above processing steps, the system of the present invention increases resistance to the latest cyber attacks and enables the implementation of effective security measures.

[1318] Example 1

[1319] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."

[1320] The latest cyberattack methods are evolving daily, and there is a need to quickly implement effective security measures to counter them. However, existing security measures lack systems that can efficiently learn the latest attack methods and conduct simulated attacks, leaving companies and organizations vulnerable to advanced cyberattacks.

[1321] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.

[1322] In this invention, the server includes means for collecting data on the latest attack techniques from intelligence agencies and the dark web, means for analyzing the collected data to extract and classify important information, and means for training an AI model using a machine learning algorithm based on the analyzed data. This makes it possible to quickly and efficiently grasp the latest cyber-attack techniques and to improve security measures by conducting simulated attacks.

[1323] An "information provider" refers to an organization or institution that collects and provides security-related information.

[1324] The "dark web" refers to a group of highly anonymous websites that cannot be accessed through regular search engines.

[1325] "Attack methods" refer to the specific techniques and tactics used in cyber attacks.

[1326] "Data collection methods" refer to the methods and tools used to obtain information.

[1327] "API Access" means access to external data or services through an application programming interface.

[1328] "Web scraping" refers to the technique of extracting information from websites.

[1329] "Data analysis methods" refer to methods and tools used to process and analyze collected data to extract meaningful information.

[1330] A "machine learning algorithm" refers to a computational method for learning patterns and rules based on data.

[1331] "AI model" refers to a model of artificial intelligence that has been trained by machine learning algorithms and is capable of performing specific tasks.

[1332] A "payload" refers to the data or code that is actually sent to the target in a cyber attack.

[1333] "Security environment" refers to the overall security measures and infrastructure of an organization or system.

[1334] "Report generation means" refers to methods and tools for generating reports based on collected and analyzed information.

[1335] The present invention relates to a system for efficiently learning the latest cyber-attack techniques and conducting simulated attacks. This system collects data from intelligence agencies and the dark web, analyzes the collected data, trains an AI model based on the analyzed data, generates simulated attacks using the trained AI model, and generates detailed reports by collecting and analyzing the results of the simulated attacks.

[1336] Information gathering

[1337] The server collects data on the latest attack techniques from the APIs of intelligence providers and the dark web. Intelligence providers often have public APIs that provide security information. The server accesses the APIs using HTTP requests and retrieves information in JSON format. It also uses web scraping libraries such as Python's Beautiful Soup and Scrapy to collect information from the dark web. The collected data is stored in an SQL or NoSQL database.

[1338] Data analysis

[1339] The device takes the collected data and preprocesses it using NLP tools (e.g., NLTK or SpaCy). Preprocessing includes tokenizing the text and removing stop words. The analyzed data is then classified into attack categories such as phishing, malware, and DDoS. Algorithms such as decision trees and support vector machines (SVM) are used for classification. The classified data is then stored in JSON format or in a database.

[1340] Model learning

[1341] The server trains an AI model based on the analyzed data. The server builds a neural network model using machine learning libraries such as TensorFlow and PyTorch. The training process includes data preprocessing, model construction, training, and evaluation. The trained model is deployed as an API server and made accessible to other system components.

[1342] Attack Simulation

[1343] Users use the trained AI model to generate mock attack payloads. In this process, users send requests to the model API and receive the generated payloads. Mock attack payloads include, for example, phishing emails and malware executable files. Users then deploy these payloads in their security environment and monitor their impact.

[1344] Results collection and report generation

[1345] The user collects the results of the simulated attacks, including click rates, the number of employee reports, and security system log data. The terminal analyzes the collected data and generates a detailed report that includes the results of the simulated attacks and an evaluation and improvement of security measures. The report is generated and provided to the user in a format that includes graphs and charts using Pandas and Matplotlib.

[1346] Specific examples

[1347] For example, if a particular company uses this system, the company's server collects data on attack methods from government security agency APIs and the dark web. The device analyzes the data, extracting and classifying important information about phishing and malware attacks. The server uses the analyzed data to train an AI model, which then generates phishing emails based on that model. The user sends these mock phishing emails internally and observes and records employee reactions. Finally, the device compiles the results into a detailed report, assessing the company's security measures and recommending areas for improvement.

[1348] Prompt Sentence Examples

[1349] "Write a Python script to collect data on the latest phishing attack techniques, train an AI model based on the analysis results, and generate simulated phishing attacks."

[1350] The above is an embodiment of the present invention.

[1351] The flow of the identification process in the first embodiment will be described with reference to FIG.

[1352] Step 1: Gather information

[1353] The server collects data on the latest attack techniques from intelligence agencies and the dark web.

[1354] Specifically, the server performs the following operations.

[1355] 1.1 The server sends an HTTP request to the provider's API endpoint, including the API key and the search query.

[1356] Input: API endpoint information, API key, search query

[1357] Output: JSON data obtained as an API response

[1358] 1.2 The server analyzes the JSON data received as an API response and extracts the necessary information.

[1359] Input: JSON data of API response

[1360] Output: Data about the extracted attack techniques

[1361] 1.3 The server accesses dark web forums and marketplaces and scrapes data using Beautiful Soup and Scrapy.

[1362] Input: Dark Web website URL

[1363] Output: Data on attack techniques obtained through scraping

[1364] 1.4 The server stores the collected data in a SQL or NoSQL database.

[1365] Input: Data on extracted attack techniques, data obtained by scraping

[1366] Output: Data stored in the database

[1367] Step 2: Data analysis

[1368] The terminal analyzes the collected data.

[1369] Specifically, the terminal performs the following operations.

[1370] 2.1 The terminal retrieves the collected data from the database.

[1371] Input: Database connection information

[1372] Output: Retrieved data

[1373] 2.2 The device preprocesses the data using NLP tools (NLTK or SpaCy), which includes tokenizing the text and removing stop words.

[1374] Input: Retrieved data

[1375] Output: Preprocessed data

[1376] 2.3 The device classifies the pre-processed data into attack categories such as phishing, malware, DDoS, etc. It uses algorithms such as decision trees and SVM for classification.

[1377] Input: Preprocessed data

[1378] Output: Data categorized by attack category

[1379] 2.4 The device stores the classified data in JSON format or in a database.

[1380] Input: Classified data

[1381] Output: JSON formatted data or data stored in a database

[1382] Step 3: Model training

[1383] The server trains the AI ​​model based on the analyzed data.

[1384] Specifically, the server performs the following operations.

[1385] 3.1 The server retrieves the parsed data from the database.

[1386] Input: Database connection information

[1387] Output: Retrieved data

[1388] 3.2 The server builds the neural network model using TensorFlow and PyTorch libraries.

[1389] Input: Acquired data, machine learning library (TensorFlow, PyTorch)

[1390] Output: Building a neural network model

[1391] 3.3 The server trains the model using the training data. It sets the optimizer (Adam, SGD), number of epochs, and batch size.

[1392] Input: training data, optimizer, number of epochs, batch size

[1393] Output: A trained AI model

[1394] 3.4 The server saves the trained model and deploys it as an API server.

[1395] Input: A trained AI model

[1396] Output: Deployed model API

[1397] Step 4: Attack simulation

[1398] Users use the trained AI model to generate simulated attacks.

[1399] Specifically, the user performs the following operations.

[1400] 4.1 The user sends a request to the model API to generate a mock attack payload, including attack category and target information.

[1401] Input: Model API endpoint, request parameters (attack category, target information)

[1402] Output: Generated mock attack payload

[1403] 4.2 The user deploys the generated payload in their security environment, for example by sending a phishing email using the Gmail API.

[1404] Input: Generated payload, security environment information

[1405] Output: Deployed payload

[1406] 4.3 Users monitor the security environment for responses during simulated attacks, using syslog and incident response systems.

[1407] Input: Security environment information, mock attack payload

[1408] Output: Reaction data of the monitored security environment

[1409] Step 5: Collect results

[1410] After conducting the simulated attacks, the user collects the results.

[1411] Specifically, the user performs the following operations.

[1412] 5.1 The user obtains log and activity data from the security environment.

[1413] Input: Security environment information

[1414] Output: Acquired log data and activity data

[1415] 5.2 The user calculates metrics such as click-through rates and employee reporting numbers.

[1416] Input: Captured log data and activity data

[1417] Output: Calculated metrics

[1418] 5.3 The user stores the collected data in a database.

[1419] Inputs: Calculated metrics, log data, activity data

[1420] Output: Result data stored in a database

[1421] Step 6: Generate reports

[1422] The terminal analyzes the collected results and generates a detailed report.

[1423] Specifically, the terminal performs the following operations.

[1424] 6.1 The terminal retrieves the collected result data from the database.

[1425] Input: Database connection information

[1426] Output: Acquired result data

[1427] 6.2 The device aggregates data and calculates key metrics using the Pandas library.

[1428] Input: Result data, Pandas library

[1429] Output: Aggregated data, calculated metrics

[1430] 6.3 The terminal uses the Matplotlib and Seaborn libraries to create graphs and charts.

[1431] Input: Aggregated data, calculated metrics, Matplotlib library, Seaborn library

[1432] Output: Generated graphs and charts

[1433] 6.4 The terminal will generate a report along with the generated graphs and suggest improvements to security measures.

[1434] Input: Generated graphs, charts, and analysis results

[1435] Output: Detailed report and improvement suggestions

[1436] (Application example 1)

[1437] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."

[1438] Modern cyberattack methods are becoming increasingly complex and diverse, requiring both companies and individual users to implement countermeasures against attacks that cannot be prevented by conventional methods. Furthermore, implementing effective security measures requires the rapid collection of information on the latest attack methods and the rapid application of countermeasures based on that information. However, performing these steps manually is extremely difficult, and there are limited methods for evaluating defense capabilities before an actual attack occurs.

[1439] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.

[1440] In this invention, the server includes means for collecting data on the latest attack techniques from intelligence agencies and the dark web, means for analyzing the collected data to extract and classify important information, means for training an AI model based on the analyzed data, means for generating simulated attacks using the trained AI model, means for executing the simulated attacks and collecting and analyzing their results, means for generating reports based on the results of the executed simulated attacks, and means for notifying the user of the results to their mobile device. This allows users to quickly respond to the latest attack techniques while evaluating and strengthening their company's defenses. Furthermore, notifying the user of the results to their mobile device allows them to take immediate countermeasures.

[1441] An "information provider" is an organization or group that provides information on cyber attack methods.

[1442] The "dark web" is an encrypted part of the internet that cannot be accessed through regular search engines.

[1443] "Data collection means" refers to methods and devices for collecting data on cyber attack techniques from intelligence agencies and the dark web.

[1444] "Analysis means" refers to a method or device that analyzes collected data and extracts and classifies important information.

[1445] An "AI model" is a data model trained using machine learning algorithms.

[1446] A "learning tool" is a method or device that trains an AI model based on collected and analyzed data.

[1447] A "simulated attack generation means" is a method or device that generates simulated cyber attacks using a trained AI model.

[1448] A "mock attack execution means" is a method or device for executing the generated mock attack and observing its effect.

[1449] A "result collection means" is a method or device for collecting the results of the executed simulated attacks.

[1450] A "results analysis means" is a method or device for analyzing collected results and generating a report.

[1451] A "report generator" is a method or apparatus for generating a detailed report based on the results of a simulated attack.

[1452] "Notification means" refers to a method or device for notifying the user's mobile terminal of the results of the simulated attack and related information.

[1453] The system for realizing this invention is mainly composed of a server, a terminal, and a user. The detailed configuration and usage method are described below.

[1454] Data collection from intelligence agencies and the dark web

[1455] The server first collects data on the latest attack techniques from intelligence agencies' APIs and the dark web. The collected data includes detailed descriptions of the attack techniques, the steps of the attack, and the tools and methods used. This allows for the creation of a comprehensive database of the latest attack techniques.

[1456] Data analysis

[1457] The device analyzes the collected data received from the server. Specifically, it preprocesses the collected data and extracts necessary information. It then classifies the extracted information into attack categories such as phishing, malware, and DDoS.

[1458] Training an AI model

[1459] The server trains the AI ​​model based on the data analyzed by the device. The machine learning algorithm used here is trained to accurately identify cyber attack methods. The trained AI model is then applied to newly collected data, ensuring it is always adaptable to the latest attack methods.

[1460] Generating and Executing Mock Attacks

[1461] Users can use the trained AI model to generate simulated attacks. They can customize the scenarios. The generated simulated attacks are deployed as payloads in their own security environments, and their responses are observed. For example, in the case of a phishing attack, a simulated phishing email is sent internally.

[1462] Collection and analysis of results

[1463] After conducting the simulated attack, the user collects the results, including data such as the click rate for phishing emails sent and the number of employee reports. This data is then further analyzed on the device and used to evaluate the security environment.

[1464] Report generation and notification

[1465] The device generates a detailed report based on the collected results. This report includes an analysis of the simulated attack results and recommendations for improving security measures. The report is then sent to the user's mobile device, allowing for immediate action.

[1466] Hardware and Software Examples

[1467] The specific hardware and software used to realize this system include Python, requests, scrapy, scikit-learn, numpy, and json. Python is the main implementation language of the program, requests is used to collect data from APIs, scrapy is used for web scraping of data, and scikit-learn is used to train machine learning algorithms. numpy helps analyze the data, and json is used to store the results and generate reports.

[1468] Specific examples

[1469] For example, a security department might periodically create and send mock phishing emails to assess employees' security practices. Using this system, the assessment can be performed quickly, accurately, and without hassle.

[1470] Example prompts for generative AI models

[1471] "Please provide us with data on the latest phishing attack techniques."

[1472] "Predict the effectiveness of this simulated phishing email attack."

[1473] In this way, the present invention is a system that increases resistance to the latest cyber attacks and enables effective implementation of security measures.

[1474] The flow of the specific processing in the application example 1 will be described with reference to FIG.

[1475] Step 1:

[1476] The server collects data on the latest attack techniques from information provider APIs and the dark web. The inputs include the API endpoint URL and the website URL to be scraped. The data collection method uses requests to retrieve data from the API and scrape data from the dark web using scrapy. The output is raw attack technique data, including details of the attack technique, attack steps, and information about the tools used.

[1477] Step 2:

[1478] The terminal analyzes the collected data and extracts and classifies the necessary information. The input is the raw data received from the server. Natural language processing (NLP) techniques are used for data analysis to extract important information. The extracted information is then classified into categories such as phishing, malware, and DDoS. The output is analyzed and classified information on attack techniques.

[1479] Step 3:

[1480] The server trains an AI model based on the analyzed data. The input is the analyzed and classified data received from the device. The machine learning algorithm used is scikit-learn, which trains the AI ​​model using the analyzed information. The model training process includes feature extraction, data splitting, model training, and evaluation. The output is an AI model that can identify the latest attack techniques.

[1481] Step 4:

[1482] Users generate mock attacks using the trained AI model. The input is the trained AI model and a customized attack scenario. The model generates a mock attack payload based on the given scenario. The output is the generated mock attack, which specifically includes mock phishing emails and malicious scripts.

[1483] Step 5:

[1484] The user executes the generated mock attacks and collects the results. The input is the payload of the generated mock attacks. The mock attacks are deployed in the user's security environment and their behavior is observed. The collected results include data such as click rates for phishing emails and the number of employee reports. The output is the result data of the mock attacks.

[1485] Step 6:

[1486] The device analyzes the collected results and generates a detailed report. The input is the result data of the simulated attacks. The data analysis method again uses NLP technology to analyze the result data. The report generation includes analyzing the results and suggesting areas for improving security measures. The output is a detailed analysis report, which is sent to the user's mobile device.

[1487] This enables users to quickly implement countermeasures against the latest cyber-attack methods and evaluate and strengthen their defenses.

[1488] Furthermore, an emotion engine that estimates the user's emotion may be further combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59, and perform identification processing using the user's emotion.

[1489] patent specification

[1490] This invention relates to a system that efficiently learns the latest cyber-attack techniques and performs simulated attacks, and further combines it with an emotion engine that recognizes the user's emotions. This system has the following functions:

[1491] 1. Information collection module

[1492] The server collects data on the latest attack techniques from intelligence agencies and the dark web by accessing intelligence agency APIs to retrieve data and scraping data from forums and marketplaces on the dark web.

[1493] 2. Data Analysis Module

[1494] The terminal analyzes the collected data, processes it to extract important information, and then classifies it into attack categories such as phishing, malware, and DDoS, which allows for efficient organization of the information.

[1495] 3. Model Learning Module

[1496] The server trains the AI ​​model based on the analyzed data. The analyzed data is used to train machine learning algorithms and generate an AI model that can identify the latest attack techniques.

[1497] 4. Attack Simulation Module

[1498] Users can use the trained AI model to generate mock attacks, deploy the resulting attack payloads in their security environment, and observe their reactions—for example, by creating specific phishing emails and sending them internally.

[1499] 5. Result Collection Module

[1500] Users collect the results of the simulated attacks, such as the click rate of phishing emails and the number of detected malware, which allows them to evaluate the effectiveness of the attacks.

[1501] 6. Report Generation Module

[1502] The device analyzes the collected results and generates a detailed report that includes analysis and recommendations for improving security measures based on the results of the simulated attacks.

[1503] 7. Emotion Engine Module

[1504] The device uses an emotion engine to recognize the user's emotions during the process of simulating attacks and collecting execution results. The emotion engine analyzes the user's reactions and behavior to identify their emotional state. For example, the emotion engine analyzes the facial expressions and behavioral data of an employee who receives a phishing email and recognizes emotions such as stress and confusion.

[1505] 8. Use of Emotional Data

[1506] The content and difficulty of the simulated attacks are adjusted based on the user's emotional data recognized by the emotion engine. For example, if employees are overly confused, the difficulty of the simulated attacks can be lowered or the attack method changed. This increases the effectiveness of countermeasures against real attacks.

[1507] Specific examples

[1508] As an example, let's consider a company using this system. The server collects the latest phishing attack data from government security agency APIs and the dark web. The device analyzes the data and classifies it into phishing categories, and the server uses this data to train an AI model. Based on the trained model, the user generates mock phishing emails and deploys them within the company. The emotion engine analyzes employee reactions and adjusts the content and difficulty of the emails based on these results. Finally, all results are compiled to generate a report that proposes security measures.

[1509] This system will enable companies to increase their resistance to the latest cyber attacks and implement effective security measures. Furthermore, by combining it with an emotion engine, it will be possible to realize more accurate simulations and countermeasures that take into account the user's emotional state.

[1510] The processing flow will be explained below.

[1511] patent specification

[1512] The processing flow of the system will be explained in the following steps.

[1513] Step 1:

[1514] The server accesses the API of the information provider to obtain data on the latest attack techniques. Specifically, it sends a request to the security agency's API endpoint and receives a response. The response contains information such as the latest attack techniques, their overview, and the date and time of occurrence.

[1515] Step 2:

[1516] The server scrapes specific web pages to collect data on attack techniques from the dark web. Using a scraping tool, the server extracts the necessary information from forums and marketplaces on the dark web. The extracted data includes details of attack techniques, sales information, and related discussion content.

[1517] Step 3:

[1518] The device analyzes the collected data. Specifically, it analyzes the acquired JSON data and scraping data to extract information such as the type and details of the attack method, and the date and time of the attack. The analyzed data is organized by attack method.

[1519] Step 4:

[1520] The device classifies the analyzed information into categories such as phishing, malware, and DDoS. For example, among the extracted information, data related to phishing is classified into the phishing category, and data related to malware is classified into the malware category. This allows information to be organized efficiently.

[1521] Step 5:

[1522] The server trains the AI ​​model based on the classified data. The analyzed data is used to train machine learning algorithms and generate an AI model that can identify the latest attack techniques. The trained AI model is capable of mimicking the generation of phishing emails and malware behavior.

[1523] Step 6:

[1524] Users can use the trained AI model to generate simulated attacks, for example by generating phishing email content from the AI ​​model and preparing the email as a simulated attack. The generated attack payload is tailored to their company's security environment.

[1525] Step 7:

[1526] Users deploy the generated simulated attacks in their company's security environment. For example, they can send simulated phishing emails to employees' email addresses and observe their responses. Data is collected about the deployed simulated attacks, including the number of clicks and reports by employees.

[1527] Step 8:

[1528] Users collect the results of the simulated attacks, such as employee reactions to phishing emails and the amount of malware detected, which allows them to evaluate the effectiveness of the attacks.

[1529] Step 9:

[1530] The device generates a detailed report based on the collected results, including an analysis of the simulated attack results, an evaluation of security measures, and recommendations for improvement. The report also includes visualization and statistical information of the results.

[1531] Step 10:

[1532] The device uses an emotion engine to recognize the user's emotions during the process of simulating attacks and collecting execution results. The emotion engine analyzes the user's reactions and behavior to identify their emotional state. For example, the emotion engine analyzes the facial expressions and behavioral data of an employee who receives a phishing email and recognizes emotions such as stress and confusion.

[1533] Step 11:

[1534] The device uses the user's emotional data recognized by the emotion engine to adjust the content and difficulty of the simulated attacks. For example, if an employee is overly confused, the device can lower the difficulty of the simulated attacks or adjust the attack methods. This provides an environment in which employees can learn appropriately.

[1535] Step 12:

[1536] The device then uses the emotion engine to recognize the user's emotional data and includes in a report the evaluation results of the security measures and suggestions for improvement. The report includes an analysis that reflects the emotional data and details of areas for improvement, providing specific advice for strengthening a company's security measures.

[1537] The above is a specific embodiment for carrying out the present invention. This system can increase resistance to the latest cyber attacks and implement effective security measures. Furthermore, by combining it with an emotion engine, it is possible to realize more accurate simulations and measures that take into account the user's emotional state.

[1538] Example 2

[1539] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."

[1540] Today's cyber attacks are becoming more sophisticated and diverse, and organizations and companies need effective training and countermeasures to deal with them. However, conventional attack simulation systems do not take into account the user's emotions and psychological state, which can result in ineffective training. Furthermore, it has been difficult to quickly and accurately grasp the latest attack methods and improve adaptability to actual attacks.

[1541] The specific processing by the specific processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means.

[1542] In this invention, the server includes means for collecting data on the latest attack techniques from information providers and online forums, means for analyzing the collected data to extract and classify important information, means for training an AI model based on the analyzed data, means for generating simulated attacks using the trained AI model, means for executing the simulated attacks and collecting and analyzing the results, means for generating reports based on the results of the executed simulated attacks, means for recognizing a user's emotions using an emotion engine, and means for adjusting the content and difficulty of the simulated attacks based on the recognized emotion data. This provides effective countermeasures against the latest cyber attacks, and by conducting training that takes the user's psychological state into consideration, more realistic attack simulations and countermeasures can be achieved.

[1543] An "information provider" is a public or private organization that provides information about cyber attacks.

[1544] An "online forum" is a bulletin board or discussion site on the Web where users exchange information.

[1545] "Data collection" is the process of obtaining the necessary data from information sources and online forums.

[1546] "Data scraping" is the technique of automatically extracting information from websites.

[1547] "Analysis" is the process of processing collected data to extract useful information.

[1548] "Classification" is the process of organizing extracted information into specific categories.

[1549] An "AI model" is a statistical model created using artificial intelligence technology for making predictions and classifications.

[1550] A "mock attack" is a simulated attack that imitates an actual cyber attack.

[1551] An "emotion engine" is a system for recognizing and analyzing a user's emotional state.

[1552] A "report" is a report summarizing the analysis results, including points for improvement and suggestions.

[1553] The present invention relates to a system that efficiently learns the latest cyber-attack techniques and performs simulated attacks based on them. This system operates by integrating the following functions:

[1554] First, let's look at the information collection module. The server collects data on the latest attack techniques from information providers and online forums. This process involves accessing the APIs of the information providers to obtain the latest data and using web scraping techniques to collect information from online forums. As a specific example, it uses the Python requests library to send GET requests to API endpoints and the BeautifulSoup and Scrapy libraries to scrape text data from forum pages.

[1555] The data analysis module then analyzes the collected data to extract and classify key information. The terminal uses the pandas library to create a data frame and perform initial data cleaning. The data is then classified into security categories such as phishing, malware, and DDoS. This can be achieved by using the Scikit-learn K-means clustering algorithm.

[1556] In the model learning module, the server trains the AI ​​model based on the analyzed data, using techniques such as TensorFlow and PyTorch to train neural networks and generate models that can identify new cyber-attack patterns.

[1557] In the attack simulation module, users can use AI models to generate and execute simulated attacks. For example, using OpenAI's GPT series, a generative AI model, users can input the following prompt text to automatically generate the content of a phishing email:

[1558] Create mock phishing emails using the latest phishing techniques

[1559] The generated mock phishing emails are sent to an internal mailing list and the responses are observed.

[1560] The results collection module allows users to collect and analyze the results of simulated attacks, using data collection tools such as Google Analytics and Splunk to compile information such as click rates for phishing emails and the amount of malware detected.

[1561] The report generation module analyzes the collected data and generates a detailed report using Excel or Tableau to visualize the data and summarize the analysis results. The report includes analysis and recommendations for improvement based on the results of the simulated attacks.

[1562] In addition, the emotion engine module allows the device to recognize the user's emotions using the emotion engine, which combines OpenCV and Emotion SDK to analyze the user's facial expressions and behavioral data to reveal their emotional state.

[1563] Finally, the content and difficulty of the simulated attacks are adjusted based on the user's emotional data recognized by the emotion engine. For example, if an employee is overly confused, the difficulty of the next simulated attack may be lowered.

[1564] This system's series of processes enables companies to respond quickly to the latest cyber-attack techniques and also enables effective training that takes into account the emotional state of users.

[1565] The flow of the identification process in the second embodiment will be described with reference to FIG.

[1566] Step 1: Gather information

[1567] The server accesses the API of an intelligence provider to obtain data on the latest cyber attack methods.

[1568] (Input) API endpoint, authentication token

[1569] (Output) Acquired attack information data

[1570] The server uses the Python requests library to send a GET request to the API endpoint and retrieve the data in JSON format.

[1571] The server uses web scraping technology to collect data on attack methods from online forums.

[1572] (Input) Forum URL and target HTML element

[1573] (Output) Scraped text data

[1574] The server uses the BeautifulSoup and Scrapy libraries to extract relevant text data from the HTML pages of the target forums.

[1575] Step 2: Data analysis

[1576] The terminal analyzes the data received from the server and extracts important information.

[1577] (Input) Collected attack information data

[1578] (Output) A clean data frame

[1579] The terminal uses Python's pandas library to create data frames and handle missing and outlier values.

[1580] The device categorizes the data into security categories such as phishing, malware, and DDoS.

[1581] (Input) Clean data frame

[1582] (Output) Attack data by category

[1583] The device clusters the data using Scikit-learn's K-means clustering algorithm.

[1584] Step 3: Model training

[1585] The server trains the AI ​​model based on the analyzed data.

[1586] (Input) Attack data by category

[1587] (Output) Trained AI model

[1588] The server uses TensorFlow and PyTorch to train neural networks and generate models that identify new cyber attack patterns.

[1589] Step 4: Attack simulation

[1590] Users use the trained AI model to generate simulated attacks.

[1591] (Input) Trained AI model

[1592] (Output) Content of the mock attack (e.g., phishing email)

[1593] Users can use a generative AI model (e.g., GPT-3) to automatically generate the content of a phishing email by entering a prompt like the following:

[1594] Create mock phishing emails using the latest phishing techniques

[1595] The user sends the generated email to an internal mailing list.

[1596] Step 5: Collect results

[1597] The user collects and analyzes the results of the simulated attacks.

[1598] (Input) Results of simulated attacks (e.g., click rate, number of detected malware, etc.)

[1599] (Output) Evaluation data

[1600] Users use data collection tools such as Google Analytics and Splunk to compile data on phishing email click rates and the amount of malware detected.

[1601] Step 6: Generate reports

[1602] The terminal analyzes the collected data and generates a detailed report.

[1603] (Input) Evaluation data

[1604] (Output) Detailed report

[1605] The device uses Excel or Tableau to visualize the data and compiles the analysis results into a report, which includes improvements and suggestions.

[1606] Step 7: Emotion Recognition

[1607] The terminal uses an emotion engine to recognize the user's emotions.

[1608] (Input) User facial expression and behavior data

[1609] (Output) User emotion data

[1610] The device uses OpenCV and the Emotion SDK to analyze the user's facial expressions and identify emotional states such as stress or confusion.

[1611] Step 8: Use emotion data

[1612] The content and difficulty of the simulated attack are adjusted based on the user's emotional data.

[1613] (Input) User emotion data

[1614] (Output) Adjusted simulated attack content

[1615] If the emotion engine determines that an employee is overly confused, it will take action such as lowering the difficulty of the next mock attack.

[1616] These steps will enable companies to respond quickly and effectively to the latest cyberattack techniques, and also provide practical training that takes into account the emotional state of users.

[1617] (Application example 2)

[1618] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."

[1619] Cyber-attack threats continue to evolve, causing increasing damage to businesses and individuals. In particular, phishing emails, malware, and DDoS attacks pose numerous security risks. Furthermore, existing countermeasures often cannot quickly adapt to the latest attack methods, necessitating continuous learning and the implementation of simulated attacks. Furthermore, there is a lack of training that takes into account user emotions and reactions, making it difficult to implement effective security measures. To address these challenges, an efficient and flexible security system is needed.

[1620] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 2 is realized by the following means.

[1621] In this invention, the server includes means for collecting data on the latest attack techniques from intelligence agencies and the dark web, means for analyzing the collected data to extract and classify important information, means for training an AI model based on the analyzed data, means for generating simulated attacks using the trained AI model, means for executing the simulated attacks and collecting and analyzing their results, means for generating reports based on the results of the executed simulated attacks, means for simulating the simulated attacks on a user device, and means for collecting user reaction and emotional data and adjusting the content and difficulty of the simulated attacks. This enables rapid and effective learning of the latest cyber-attack techniques and the implementation of simulated attacks, thereby realizing security measures that take user emotions and reactions into account.

[1622] "Information providers" are experts and organizations that provide data on the latest cyber attack techniques.

[1623] The "dark web" is an area of ​​the internet that cannot be accessed through regular search engines and is home to a lot of illegal information and activity.

[1624] "Means of collecting data" refers to methods and devices for obtaining data on the latest attack techniques from intelligence agencies and the dark web.

[1625] "Means for analyzing data to extract and classify important information" refers to methods and devices for analyzing collected data and selecting and classifying necessary information.

[1626] "Means for training AI models" refers to methods or devices that train artificial intelligence based on analyzed data and create machine learning models for specific purposes.

[1627] "Means for generating simulated attacks" means a method or device for generating attack scenarios using a trained AI model.

[1628] "Means for executing simulated attacks and collecting and analyzing the results" refers to methods and devices for executing the generated simulated attacks and collecting and analyzing their effects and reactions as data.

[1629] A "means for generating a report" refers to a method or device that analyzes the results of a simulated attack and creates a detailed report.

[1630] A "user device" is an electronic device that can be directly operated by a user, such as a smartphone, tablet, or PC.

[1631] A "means for simulating" is a method or device for executing a simulated attack in a virtual environment and observing the results.

[1632] "Means for collecting user reaction and emotional data and adjusting the content and difficulty of the simulated attack" refers to a method or device for evaluating the user's behavior and emotions in response to the simulated attack and changing the content and difficulty of the attack based on that evaluation.

[1633] This invention relates to a system that efficiently learns the latest cyber-attack techniques and conducts simulated attacks, incorporating an emotion engine that recognizes user emotions. Specifically, the system collects data on the latest attack techniques from intelligence agencies and the dark web, analyzes the collected data to extract and classify important information, trains an AI model based on the analyzed data, and generates simulated attacks using the trained AI model. The generated simulated attacks are simulated on the user's device, and the results are collected and analyzed. A report is generated based on the results of the simulated attacks, and user reaction and emotional data are collected to adjust the content and difficulty of the simulated attacks.

[1634] The server uses API access and web scraping techniques to collect data from intelligence agencies and the dark web. The collected data is analyzed and classified into categories such as phishing, malware, and DDoS. The analyzed data is then used to train an AI model to identify the latest attack techniques. The trained AI model is then used to generate mock attacks, which are simulated on user devices.

[1635] The device collects the results of simulated attacks and evaluates their effectiveness. Specifically, it collects data such as the click rate of phishing emails and the number of detected malware, and generates reports to evaluate the success rate of attacks and the performance of defense systems. It also uses an emotion engine to analyze user reactions and behavior, allowing it to adjust the content and difficulty of the simulated attacks.

[1636] For example, a specific phishing email can be created and sent internally, and the emotion engine will analyze employees' facial expressions and behavioral data to recognize emotions such as stress or confusion. Based on these results, the difficulty of the simulated attack can be adjusted or the attack method changed. In this way, companies can increase their resilience against the latest cyberattacks and implement more accurate security measures.

[1637] Example prompt sentence:

[1638] Collect the latest phishing attack data and generate a simulation. Capture users' reactions after receiving the notification with a camera and analyze their emotions using the emotion engine. Adjust the simulation accordingly.

[1639] The hardware used is user devices such as smartphones, tablets, and PCs, and the software is primarily written in Python. The requests library and BeautifulSoup are used for data collection, and TensorFlow and PyTorch are used for machine learning. These technologies enable the entire system to operate efficiently and flexibly.

[1640] The flow of the specific processing in the application example 2 will be described with reference to FIG.

[1641] Step 1:

[1642] The server runs a mechanism to collect data on the latest attack techniques from intelligence agencies and the dark web, using API access to retrieve data from intelligence agencies and web scraping techniques to gather additional data from dark web forums and marketplaces. This data contains a variety of information on attack techniques.

[1643] Input: API endpoint of intelligence provider, dark web URL

[1644] Output: Raw data on the latest attack techniques

[1645] Step 2:

[1646] The server then analyzes the collected data and implements measures to extract and classify key information, specifically using natural language processing techniques to analyze the data and categorize it into attack categories such as phishing, malware, and DDoS.

[1647] Input: Unanalyzed data collected in Step 1

[1648] Output: Categorized analysis data

[1649] Step 3:

[1650] The server runs a trainer for the AI ​​model based on the analyzed data. It uses machine learning algorithms to train the model to identify the latest attack techniques. Specifically, it uses TensorFlow and PyTorch to build the model and train it on the analyzed data.

[1651] Input: Data parsed in step 2

[1652] Output: The trained AI model

[1653] Step 4:

[1654] The server executes a means to generate simulated attacks using the trained AI model, generating attack scenarios and converting them into a format that can be executed on the user device.

[1655] Input: The AI ​​model trained in Step 3

[1656] Output: mock attack scenarios and payloads

[1657] Step 5:

[1658] Users deploy the generated simulated attacks in their own security environment and execute them on user devices such as smartphones and PCs. The results of the simulated attacks are collected from the device's sensors and log data.

[1659] Input: The mock attack generated in step 4

[1660] Output: Execution result data (e.g., click rate of phishing emails and number of detected malware)

[1661] Step 6:

[1662] The device executes procedures to analyze the results of the simulated attacks and generate detailed reports, such as creating statistics and graphs of the results, documenting the success rate of the attacks and the evaluation of the defense system.

[1663] Input: The execution result data collected in Step 5

[1664] Output: Detailed report

[1665] Step 7:

[1666] The device uses an emotion engine to recognize the user's emotions during the process of simulating attacks and collecting the results. Specifically, it collects user behavior data from cameras and sensors and uses an emotion analysis algorithm to evaluate the user's level of stress and confusion.

[1667] Input: User camera footage and sensor data

[1668] Output: User emotion data

[1669] Step 8:

[1670] The server uses the emotion data to adjust the content and difficulty of the simulated attack. Specifically, it changes the attack scenario and difficulty according to the user's emotional state, and provides adaptive training for real attacks.

[1671] Input: User emotion data collected in step 7

[1672] Output: Adjusted attack scenarios and difficulty levels

[1673] Example prompt sentence:

[1674] Collect the latest phishing attack data and generate a simulation. Capture users' reactions after receiving the notification with a camera and analyze their emotions using the emotion engine. Adjust the simulation accordingly.

[1675] The specific processing unit 290 transmits the result of the specific processing to the robot 414. In the robot 414, the control unit 46A causes the speaker 240 and the control target 443 to output the result of the specific processing. The microphone 238 acquires voice indicating a user input regarding the result of the specific processing. The control unit 46A transmits voice data indicating the user input acquired by the microphone 238 to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the voice data.

[1676] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[1677] In the above embodiment, an example was given in which the specific processing is performed by the data processing device 12, but the technology of the present disclosure is not limited to this, and the specific processing may be performed by the robot 414.

[1678] The emotion identification model 59 as an emotion engine may determine the user's emotion according to a specific mapping. Specifically, the emotion identification model 59 may determine the user's emotion according to an emotion map (see FIG. 9), which is a specific mapping. Similarly, the emotion identification model 59 may determine the robot's emotion, and the identification processing unit 290 may perform identification processing using the robot's emotion.

[1679] FIG. 9 is a diagram illustrating an emotion map 400 on which multiple emotions are mapped. In the emotion map 400, emotions are arranged in concentric circles radiating from the center. Emotions closer to the center of the concentric circles are more primitive. Emotions representing states and actions arising from a state of mind are arranged on the outer edges of the concentric circles. The concept of emotion includes both affect and mental states. Emotions generally generated from reactions occurring in the brain are arranged on the left side of the concentric circles. Emotions generally induced by situational judgment are arranged on the right side of the concentric circles. Emotions generally generated from reactions occurring in the brain and induced by situational judgment are arranged on the upper and lower sides of the concentric circles. Furthermore, the emotion of "pleasure" is arranged on the upper side of the concentric circles, and the emotion of "discomfort" is arranged on the lower side. In this way, in the emotion map 400, multiple emotions are mapped based on the structure by which emotions are generated, and emotions that tend to occur simultaneously are mapped close to each other.

[1680] These emotions are distributed in the 3 o'clock direction on emotion map 400, and typically fluctuate between relief and anxiety. In the right half of emotion map 400, situational awareness dominates over internal sensations, resulting in a sense of calm.

[1681] The inside of emotion map 400 represents what is going on in the mind, and the outside of emotion map 400 represents behavior, so the further you go outside emotion map 400, the more visible the emotions become (the more they are expressed in behavior).

[1682] Human emotions are based on various balances, such as posture and blood sugar levels. When these balances deviate from the ideal, a state of discomfort is indicated, and when they approach the ideal, a state of pleasure is indicated. Emotions can also be created for robots, automobiles, and motorcycles, based on various balances, such as posture and remaining battery life. When these balances deviate from the ideal, a state of discomfort is indicated, and when they approach the ideal, a state of pleasure is indicated. An emotion map can be generated, for example, based on Dr. Mitsuyoshi's emotion map (Research on Voice Emotion Recognition and Emotional Brain Physiological Signal Analysis Systems, Tokushima University, Doctoral Dissertation: https: / / ci.nii.ac.jp / naid / 500000375379). The left half of the emotion map lists emotions belonging to the "reaction" domain, where sensation is dominant. The right half of the emotion map lists emotions belonging to the "situation" domain, where situational awareness is dominant.

[1683] The emotion map defines two emotions that promote learning. One is a negative emotion on the situation side, around the middle of "repentance" or "reflection." In other words, this occurs when the robot experiences negative emotions such as "I never want to feel this way again" or "I don't want to be scolded again." The other is a positive emotion on the response side, around "desire." In other words, this occurs when the robot experiences positive feelings such as "I want more" or "I want to know more."

[1684] The emotion identification model 59 inputs user input into a pre-trained neural network, obtains emotion values ​​indicating each emotion shown in the emotion map 400, and determines the user's emotion. This neural network is pre-trained based on multiple pieces of training data that are combinations of user input and emotion values ​​indicating each emotion shown in the emotion map 400. Furthermore, this neural network is trained so that emotions that are located close to each other have similar values, as in the emotion map 900 shown in FIG. 10. FIG. 10 shows an example in which multiple emotions, "relieved," "calm," and "reassuring," have similar emotion values.

[1685] The system according to the present disclosure has been described above mainly with respect to the functions of the data processing device 12, but the system according to the present disclosure is not necessarily implemented on a server. The system according to the present disclosure may be implemented as a general information processing system. The present disclosure may be implemented, for example, as a software program running on a personal computer or an application running on a smartphone, etc. The method according to the present disclosure may be provided to users in the form of SaaS (Software as a Service).

[1686] In the above embodiment, an example was given in which the specific processing is performed by one computer 22, but the technology of the present disclosure is not limited to this, and the specific processing may be distributed and performed by a plurality of computers including the computer 22. For example, the data generation model 58 may be provided in an external device of the data processing device 12, and data may be generated in the external device in accordance with input data.

[1687] In the above embodiment, an example in which the specific processing program 56 is stored in the storage 32 has been described, but the technology of the present disclosure is not limited to this. For example, the specific processing program 56 may be stored in a portable, computer-readable, non-transitory storage medium such as a USB (Universal Serial Bus) memory. The specific processing program 56 stored in the non-transitory storage medium is installed in the computer 22 of the data processing device 12. The processor 28 executes the specific processing in accordance with the specific processing program 56.

[1688] Alternatively, the specific processing program 56 may be stored in a storage device such as a server connected to the data processing device 12 via the network 54, and the specific processing program 56 may be downloaded and installed on the computer 22 in response to a request from the data processing device 12.

[1689] It is not necessary to store all of the specific processing program 56 in a storage device such as a server connected to the data processing device 12 via the network 54, or to store all of the specific processing program 56 in the storage 32; only a portion of the specific processing program 56 may be stored.

[1690] The hardware resource for executing a specific process can be any of the following processors: An example of a processor is a CPU, which is a general-purpose processor that functions as a hardware resource for executing a specific process by executing software, i.e., a program. Another example of a processor is a dedicated electrical circuit, such as an FPGA (Field-Programmable Gate Array), a PLD (Programmable Logic Device), or an ASIC (Application Specific Integrated Circuit), which is a processor with a circuit configuration designed specifically for executing a specific process. Each processor has built-in or connected memory, and each processor uses the memory to execute the specific process.

[1691] The hardware resource that executes the specific processing may be configured with one of these various processors, or may be configured with a combination of two or more processors of the same or different types (for example, a combination of multiple FPGAs, or a combination of a CPU and an FPGA). Also, the hardware resource that executes the specific processing may be a single processor.

[1692] As an example of a system configured with a single processor, first, one processor is configured by combining one or more CPUs and software, and this processor functions as a hardware resource that executes a specific process. Second, there is a system that uses a processor that realizes the functions of an entire system including multiple hardware resources that execute a specific process on a single IC chip, as typified by SoC (System-on-a-chip). In this way, a specific process is realized using one or more of the above-mentioned various processors as hardware resources.

[1693] Furthermore, the hardware structure of these various processors can be, more specifically, an electric circuit that combines circuit elements such as semiconductor devices. The specific processing described above is merely an example. Therefore, it goes without saying that unnecessary steps may be deleted, new steps may be added, or the processing order may be rearranged, without departing from the spirit of the invention.

[1694] The above-described description and illustrations are a detailed explanation of the parts related to the technology of the present disclosure and are merely an example of the technology of the present disclosure. For example, the above description of the configuration, functions, actions, and effects is an explanation of an example of the configuration, functions, actions, and effects of the parts related to the technology of the present disclosure. Therefore, it goes without saying that unnecessary parts may be deleted, new elements may be added, or replacements may be made to the above-described description and illustrations within the scope of the gist of the technology of the present disclosure. Furthermore, to avoid confusion and facilitate understanding of the parts related to the technology of the present disclosure, the above-described description and illustrations omit explanations of common technical knowledge that do not require particular explanation to enable the implementation of the technology of the present disclosure.

[1695] All publications, patent applications, and technical standards mentioned in this specification are herein incorporated by reference to the same extent as if each individual publication, patent application, or technical standard was specifically and individually indicated to be incorporated by reference.

[1696] The following is further disclosed regarding the above embodiment.

[1697] Claims

[1698] (Claim 1)

[1699] A means of gathering data on the latest attack techniques from intelligence agencies and the dark web,

[1700] A means of analyzing the collected data to extract and classify key information;

[1701] A means of training an AI model based on the analyzed data;

[1702] a means for generating simulated attacks using the trained AI model;

[1703] A means of conducting simulated attacks and collecting and analyzing the results;

[1704] means for generating a report based on the results of the executed simulated attacks;

[1705] A system including:

[1706] (Claim 2)

[1707] The system of claim 1, wherein API access and web scraping are used as means for collecting data from the information providers and the dark web.

[1708] (Claim 3)

[1709] The system of claim 1, further comprising means for classifying the analyzed data into categories such as phishing, malware, and DDoS.

[1710] "Example 1"

[1711] (Claim 1)

[1712] A means of gathering data on the latest attack techniques from intelligence agencies and the dark web,

[1713] A means of analyzing the collected data to extract and classify key information;

[1714] A means of training an AI model using machine learning algorithms based on the analyzed data; and

[1715] A means for a user to generate a mock attack payload using the trained AI model;

[1716] A means of executing simulated attacks and monitoring and recording the response of the security environment;

[1717] means for generating a report based on the results of the executed simulated attacks;

[1718] A system including:

[1719] (Claim 2)

[1720] The system of claim 1, wherein API access is used as a means of collecting data from information providers.

[1721] (Claim 3)

[1722] 10. The system of claim 1, wherein web scraping is used as a means of collecting data from information providers and the dark web.

[1723] "Application Example 1"

[1724] (Claim 1)

[1725] A means of gathering data on the latest attack techniques from intelligence agencies and the dark web,

[1726] A means of analyzing the collected data to extract and classify key information;

[1727] A means of training an AI model based on the analyzed data;

[1728] a means for generating simulated attacks using the trained AI model;

[1729] A means of conducting simulated attacks and collecting and analyzing the results;

[1730] means for generating a report based on the results of the executed simulated attacks;

[1731] A means of notifying the user of the results on their mobile device;

[1732] A system including:

[1733] (Claim 2)

[1734] The system of claim 1, wherein API access and web scraping are used as means for collecting data from the information providers and the dark web.

[1735] (Claim 3)

[1736] The system according to claim 1, further comprising means for classifying the analyzed data into categories such as phishing, malware, and DDoS, and notifying the user through a smartphone application.

[1737] "Example 2: Combining Emotion Engines"

[1738] (Claim 1)

[1739] A means of gathering data on the latest attack techniques from intelligence agencies and online forums;

[1740] A means of analyzing the collected data to extract and classify key information;

[1741] A means of training an AI model based on the analyzed data;

[1742] a means for generating simulated attacks using the trained AI model;

[1743] A means of conducting simulated attacks and collecting and analyzing the results;

[1744] means for generating a report based on the results of the executed simulated attacks;

[1745] means for recognizing a user's emotion using an emotion engine;

[1746] a means for adjusting the content and difficulty of the simulated attack based on the recognized emotion data;

[1747] A system including:

[1748] (Claim 2)

[1749] The system of claim 1, wherein API access and data scraping are used as means for collecting data from the information providers and online forums.

[1750] (Claim 3)

[1751] The system of claim 1, further comprising means for classifying the analyzed data into security categories such as phishing, malware, and DDoS.

[1752] "Application example 2 when combining emotion engines"

[1753] (Claim 1)

[1754] A means of gathering data on the latest attack techniques from intelligence agencies and the dark web,

[1755] A means of analyzing the collected data to extract and classify key information;

[1756] A means of training an AI model based on the analyzed data;

[1757] a means for generating simulated attacks using the trained AI model;

[1758] A means of conducting simulated attacks and collecting and analyzing the results;

[1759] means for generating a report based on the results of the executed simulated attacks;

[1760] means for simulating a mock attack on a user device;

[1761] a means for collecting user reaction and emotion data and adjusting the content and difficulty of the simulated attack;

[1762] A system including:

[1763] (Claim 2)

[1764] The system of claim 1, wherein API access and web scraping are used as means for collecting data from the information providers and the dark web.

[1765] (Claim 3)

[1766] The system of claim 1, further comprising means for classifying the analyzed data into categories such as phishing, malware, and DDoS. [Explanation of symbols]

[1767] 10, 210, 310, 410 Data Processing Systems 12 Data Processing Device 14 Smart Devices 214 Smart Glasses 314 Headset-type terminal 414 Robot< / url:> < / url:> < / url:> < / url:>

Claims

1. A means of gathering data on the latest attack techniques from intelligence agencies and the dark web, A means of analyzing the collected data to extract and classify key information; A means of training an AI model based on the analyzed data; a means for generating simulated attacks using the trained AI model; A means of conducting simulated attacks and collecting and analyzing the results; means for generating a report based on the results of the executed simulated attacks; A system including:

2. The system of claim 1 , wherein API access and web scraping are used as means for collecting data from the information providers and the dark web.

3. The system of claim 1 , further comprising means for classifying the analyzed data into categories such as phishing, malware, and DDoS.

Citation Information

Patent Citations

  • Persona chatbot control method and system

    JP2022180282A