System

The system addresses the challenge of manual and time-consuming security enhancements by automating the collection, analysis, and risk assessment of cyber attacks and leaks, facilitating continuous security improvements through automated countermeasure proposals.

JP2026014841APending Publication Date: 2026-01-29SOFTBANK GROUP CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024116315
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-07-19
Publication Date
2026-01-29

AI Technical Summary

Technical Problem

Companies face challenges in effectively collecting and analyzing information on cyber attacks and information leaks from other companies to strengthen their own security management systems, as existing methods are time-consuming and dependent on manual processes, lacking real-time performance and uniformity.

Method used

A system that automatically collects, analyzes, and classifies cyber attack and information leak data using natural language processing, compares it with the company's security management system, conducts risk assessments, and proposes countermeasures, enabling continuous security improvements.

Benefits of technology

Enables companies to efficiently and effectively enhance their security posture by leveraging data from other companies' incidents, automating the risk assessment and countermeasure proposal processes, ensuring timely and uniform security enhancements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026014841000001_ABST
    Figure 2026014841000001_ABST
Patent Text Reader

Abstract

A system is provided.SOLUTION: A system comprising: means for collecting cyberattacks and information leakage cases of other companies; means for analyzing and classifying the collected cyberattacks and information leakage cases of other companies; means for collating collected information with a security management system of the own company; means for performing risk evaluation based on a collation result; means for proposing a countermeasure based on a result of the risk evaluation; and means for notifying a user of contents of the risk evaluation and the countermeasure proposal.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The technology of the present disclosure relates to a system. [Background technology]

[0002] Patent document 1 discloses a persona chatbot control method performed by at least one processor, the method including the steps of receiving a user utterance, adding the user utterance to a prompt including an instruction sentence related to a description of the chatbot character, encoding the prompt, and inputting the encoded prompt into a language model to generate a chatbot utterance in response to the user utterance. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Publication No. 2022-180282 Summary of the Invention [Problem to be solved by the invention]

[0004] In recent years, the number of cyber attacks and information leaks has increased, requiring companies to quickly implement appropriate security measures. However, it is not easy to effectively collect and analyze information on cyber attacks and information leaks that have occurred at other companies, compare it with your own company's management system, and quickly identify the necessary measures. Therefore, a system is needed that allows you to learn from other companies' cases and continuously strengthen your own security management system. [Means for solving the problem]

[0005] This invention is a system including means for collecting information on cyber attacks and information leaks by other companies, means for analyzing and classifying the collected information on cyber attacks and information leaks by other companies, means for comparing the collected information with the company's own security management system, means for conducting a risk assessment based on the comparison results, means for proposing countermeasures based on the results of the risk assessment, and means for notifying the user of the risk assessment and the proposed countermeasures. This system enables the company to extract and analyze appropriate information from other companies' cases and reflect it in its own system, thereby enabling the company to take prompt and effective security measures.

[0006] Understood. Below are definitions of important terms included in the claims.

[0007] "Cyber ​​attacks and information leaks at other companies" refers to specific examples of cyber attacks faced by other companies and organizations and the resulting information leaks.

[0008] "Means of collection" refers to the technologies and methods used to collect data on other companies' cyber attacks and information leaks from various sources on the Internet.

[0009] "Means of analysis and classification" refers to techniques and methods for analyzing collected data using natural language processing technology, etc., and organizing the data based on the type of attack and the scope of its impact.

[0010] "Your company's security management system" refers to the overall security measures maintained by a company or organization, including firewall settings, access control policies, and employee security training.

[0011] "Means of comparison" refers to the technology and methods for comparing other companies' case information with one's own security management system to identify vulnerabilities and areas for improvement.

[0012] "Means for risk assessment" refers to the technology or method for assessing the threats that a company may face based on the results of the comparison and calculating the magnitude of the risk.

[0013] "Means for proposing countermeasures" refers to technologies and methods that specifically present the necessary security measures derived from the results of risk assessment.

[0014] "Means of notifying users" refers to the techniques and methods for notifying users, such as security personnel, of the evaluation results and recommendations. [Brief explanation of the drawings]

[0015] [Figure 1] 1 is a conceptual diagram showing an example of the configuration of a data processing system according to a first embodiment. [Figure 2] 1 is a conceptual diagram showing an example of main functions of a data processing device and a smart device according to a first embodiment. [Figure 3] FIG. 10 is a conceptual diagram showing an example of the configuration of a data processing system according to a second embodiment. [Figure 4] FIG. 10 is a conceptual diagram showing an example of main functions of a data processing device and smart glasses according to a second embodiment. [Figure 5] FIG. 10 is a conceptual diagram showing an example of the configuration of a data processing system according to a third embodiment. [Figure 6] FIG. 11 is a conceptual diagram showing an example of main functions of a data processing device and a headset-type terminal according to a third embodiment. [Figure 7] FIG. 10 is a conceptual diagram showing an example of the configuration of a data processing system according to a fourth embodiment. [Figure 8] FIG. 10 is a conceptual diagram showing an example of main functions of a data processing device and a robot according to a fourth embodiment. [Figure 9] 1 shows an emotion map onto which multiple emotions are mapped. [Figure 10] 1 shows an emotion map onto which multiple emotions are mapped. [Figure 11] FIG. 3 is a sequence diagram showing a processing flow of the data processing system according to the first embodiment. [Figure 12] FIG. 10 is a sequence diagram showing the flow of processing in the data processing system in Application Example 1. [Figure 13] FIG. 10 is a sequence diagram showing the flow of processing in the data processing system according to the second embodiment when an emotion engine is combined. [Figure 14] FIG. 10 is a sequence diagram showing the flow of processing in the data processing system in Application Example 2 when an emotion engine is combined. DETAILED DESCRIPTION OF THE INVENTION

[0016] An example of an embodiment of a system according to the technology of the present disclosure will be described below with reference to the accompanying drawings.

[0017] First, the terms used in the following description will be explained.

[0018] In the following embodiments, a coded processor (hereinafter simply referred to as a "processor") may be a single arithmetic device or a combination of multiple arithmetic devices. Furthermore, a processor may be a single type of arithmetic device or a combination of multiple types of arithmetic devices. Examples of arithmetic devices include a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), a GPGPU (General-Purpose computing on Graphics Processing Units), and an APU (Accelerated Processing Unit).

[0019] In the following embodiments, a coded RAM (Random Access Memory) is a memory in which information is temporarily stored and is used as a working memory by a processor.

[0020] In the following embodiments, the coded storage is one or more non-volatile storage devices that store various programs, various parameters, etc. Examples of non-volatile storage devices include flash memory (SSD (Solid State Drive)), magnetic disks (e.g., hard disks), and magnetic tapes.

[0021] In the following embodiments, a communication I / F (Interface) with a symbol is an interface including a communication processor, an antenna, etc. The communication I / F controls communication between multiple computers. Examples of communication standards applied to the communication I / F include wireless communication standards including 5G (5th Generation Mobile Communication System), Wi-Fi (registered trademark), Bluetooth (registered trademark), etc.

[0022] In the following embodiments, "A and / or B" is synonymous with "at least one of A and B." In other words, "A and / or B" means that it may be only A, only B, or a combination of A and B. Furthermore, in this specification, the same concept as "A and / or B" is also applied when three or more things are expressed connected by "and / or."

[0023] [First embodiment]

[0024] FIG. 1 shows an example of the configuration of a data processing system 10 according to the first embodiment.

[0025] 1, a data processing system 10 includes a data processing device 12 and a smart device 14. An example of the data processing device 12 is a server.

[0026] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[0027] The smart device 14 includes a computer 36, a reception device 38, an output device 40, a camera 42, and a communication I / F 44. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The reception device 38, the output device 40, and the camera 42 are also connected to the bus 52.

[0028] The reception device 38 includes a touch panel 38A, a microphone 38B, and the like, and receives user input. The touch panel 38A detects contact with an indicator (for example, a pen or a finger) to receive user input by the touch of the indicator. The microphone 38B detects the user's voice to receive user input by voice. The control unit 46A transmits data indicating the user input received by the touch panel 38A and the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the data indicating the user input.

[0029] The output device 40 includes a display 40A and a speaker 40B, and presents data to the user 20 by outputting the data in a form of expression that the user 20 can perceive (for example, audio and / or text). The display 40A displays visible information such as text and images in accordance with instructions from the processor 46. The speaker 40B outputs audio in accordance with instructions from the processor 46. The camera 42 is a compact digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor.

[0030] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 control the exchange of various information between the processor 46 and the processor 28 via the network 54.

[0031] FIG. 2 shows an example of the main functions of the data processing device 12 and the smart device 14.

[0032] 2, in the data processing device 12, a specific process is performed by the processor 28. A specific processing program 56 is stored in the storage 32. The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific process is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[0033] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[0034] In the smart device 14, the processor 46 performs the reception output process. The storage 50 stores a reception output program 60. The reception output program 60 is used in conjunction with the specific processing program 56 by the data processing system 10. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.

[0035] Next, a description will be given of the specific processing performed by the specific processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."

[0036] This invention is a system that collects cyber attacks and information leaks that have occurred at other companies, analyzes them, compares them with the company's own security management system, and automatically performs everything from risk assessment to proposing countermeasures. Below, we will explain the processing content of this system's program in natural language, and also provide specific examples.

[0037] Program processing flow

[0038] 1. Collecting information on cyber attacks and information leaks at other companies

[0039] The server automatically collects data on cyber attacks and information leaks by other companies from the Internet and specific sources (security news sites, industry association reports, etc.).

[0040] The collected information includes the date and time of the incident, the type of attack, the scope of impact, and the cause.

[0041] For example, the server obtains information from the "Security News API" that "a certain financial institution was attacked by a phishing attack and customer data was leaked."

[0042] 2. Information analysis and classification

[0043] The server analyzes the acquired information using natural language processing technology, which extracts important elements of cyber attacks and data breaches (such as the type of attack, the scope of impact, and the cause).

[0044] Based on the analysis results, classification is made according to the type of incident and the scope of impact.

[0045] For example, the server classifies the information about phishing attacks it collects as "phishing attacks," "financial industry," and "medium damage scale."

[0046] 3. Checking your company's management system

[0047] The server retrieves information about your company's security controls from a database, including firewall settings, access control policies, and employee security training status.

[0048] The server compares the incident information collected from other companies with the company's own security management system to determine whether the company is vulnerable to similar threats.

[0049] For example, the server checks to see if its phishing protection (email filtering, employee training, etc.) is out of date.

[0050] 4. Risk Assessment

[0051] The server uses the results of the comparison to assess the risk to its company if it were to be exposed to a similar threat. The risk assessment is based on the likelihood and impact of the threat.

[0052] A risk score is calculated and countermeasures are prioritized based on this.

[0053] For example, the server may check for deficiencies in its own phishing prevention measures and rate the risk score as "high."

[0054] 5. Proposal of countermeasures

[0055] The server proposes specific countermeasures based on the results of the risk assessment.

[0056] These suggestions may include technical measures (e.g., updating anti-ransomware software, strengthening firewall rules), policy changes (e.g., reviewing access controls, implementing data encryption), and employee education (e.g., conducting security training).

[0057] For example, the server might suggest "introducing the latest email filtering software" or "conducting phishing training for employees."

[0058] 6. Notification and Reporting

[0059] The server notifies the user (security officer) of the evaluation results and recommendations.

[0060] The server generates a detailed report of the risk assessment and recommendations, which are displayed on the user's management screen.

[0061] If necessary, you can also receive immediate notification of important information via email or alerts.

[0062] For example, the server compiles these risk assessments and recommendations into a report, displays it on the user's management screen, and notifies them by email.

[0063] In this way, the system can effectively leverage cyber attacks and data breaches by other companies to continuously strengthen its own security posture.

[0064] The processing flow will be explained below.

[0065] Step 1:

[0066] The server periodically collects data on cyber attacks and information breaches by other companies from reliable sources (e.g., security news sites and industry reports). The server accesses these sources using APIs or web scraping technology to obtain the latest incident information and stores it in a database.

[0067] Step 2:

[0068] The server analyzes the collected data using natural language processing (NLP) technology, extracting necessary information from the text data (such as the date and time of the incident, the type of attack, the scope of impact, and the cause) and structuring this data.

[0069] Step 3:

[0070] The server classifies the incidents based on the analysis results. The information collected by the server is classified into the type of attack (e.g., ransomware, phishing, internal information leaks, etc.), industry (e.g., finance, healthcare, education, etc.), and scale of damage (e.g., large, medium, small).

[0071] Step 4:

[0072] The server retrieves information about the company's security posture from a database, including firewall settings, access control policies, vulnerability scan results, and employee security training status.

[0073] Step 5:

[0074] The server compares the incident information of other companies with the company's management system. The server performs the comparison process, identifies commonalities and differences between the company's security management system and those of other companies, and identifies vulnerabilities and areas for improvement.

[0075] Step 6:

[0076] The server performs a risk assessment based on the matching results. The server calculates a risk score based on the type of threat and gaps in the company's management system. The risk score is calculated taking into account the likelihood and impact of the threat.

[0077] Step 7:

[0078] The server proposes specific countermeasures based on the results of the risk assessment, including technical measures (e.g., updating anti-ransomware software, strengthening firewall settings), policy changes (e.g., reviewing access control, implementing data encryption), and employee education (e.g., implementing security training).

[0079] Step 8:

[0080] The server notifies the user of the risk assessment and proposed countermeasures. The server generates a detailed report and displays it on the user's management screen. The server also notifies the user immediately of important information via email or alerts.

[0081] Through the above process, a system will be created in which the server utilizes the cases of other companies to continuously strengthen its own security management system.

[0082] Example 1

[0083] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."

[0084] Conventional security systems often do not collect data on cyber attacks or information leaks from other companies, making it difficult to link this data to improvements in one's own security management system. Manually investigating other companies' incidents and reviewing one's own countermeasures takes time and effort, making it difficult to maintain and improve the security level of the entire company. Furthermore, if the risk assessment and countermeasure proposal processes are not systematized, they depend on the knowledge and experience of the individual in charge, making it difficult to implement uniform security measures.

[0085] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.

[0086] In this invention, the server includes: means for automatically collecting information on cyber attacks and information leak incidents by other companies from the Internet or specific information sources; means for preprocessing the collected information on cyber attacks and information leak incidents by other companies using natural language processing technology to extract and classify important elements; means for obtaining information on the company's own security management system from a database and comparing it with the collected information to identify vulnerabilities; means for calculating a risk score based on the comparison result and conducting a risk assessment; means for proposing specific countermeasures such as technical measures, policy changes, and employee training based on the result of the risk assessment; and means for notifying the user of the risk assessment and the proposed countermeasures and displaying them in a detailed report format on the user's management screen. This enables the company to automatically evaluate and improve its own security management system based on the incidents of other companies, thereby efficiently and effectively maintaining and improving its security level.

[0087] A "cyber attack" is a malicious attack on a computer system or network via the Internet.

[0088] "Information leakage" refers to the phenomenon or act of confidential information or personal information leaking to the outside without permission.

[0089] "Natural language processing technology" is a technology that enables computers to understand and process human language.

[0090] A "database" is a system or software for efficiently managing, searching, and updating large amounts of data.

[0091] A "vulnerability" is a weakness in a computer system or network that makes it susceptible to external attacks.

[0092] "Risk assessment" is the process of assessing the extent of damage or impact if a particular threat occurs.

[0093] A "risk score" is a numerical representation of the result of a risk assessment, indicating the severity of a threat and the probability of it occurring.

[0094] "Countermeasure proposals" are proposals on what measures or actions should be taken to address a specific risk.

[0095] "Technical measures" are means of responding to threats using software or hardware.

[0096] "Policy change" means reviewing and revising rules and guidelines within an organization.

[0097] "Employee training" is the training and education of an organization's employees to acquire specific knowledge and skills.

[0098] "Users" refer to the security personnel and operations managers who use this system.

[0099] A "report format" is a document format for organizing information and data and presenting them in a visually easy-to-understand manner.

[0100] The "management screen" is an interface for operating and configuring the system.

[0101] This invention is a system that collects cyber attacks and information leaks that have occurred at other companies, analyzes them, compares them with the company's own security management system, and automatically performs risk assessments and proposes countermeasures. This system is implemented with the involvement of servers, terminals, and users.

[0102] server

[0103] The server is responsible for automatically collecting data on cyber attacks and information leaks by other companies from the internet and specific sources (e.g., security news sites and industry association reports). Specifically, the server connects to the "Security News API" and retrieves data by sending a REST API request. This data includes information such as the date and time of the incident, the type of attack, the scope of impact, and the cause. The collected data is stored in a database (e.g., MySQL or PostgreSQL).

[0104] The server analyzes the collected information using natural language processing technology (for example, SpaCy or the NLTK library). Specifically, it tokenizes the text data, removes unnecessary words, and extracts important elements such as the type of attack and the scope of impact. The extracted information is then classified by category. For example, data is classified as "phishing attack," "financial industry," and "medium damage scale."

[0105] In addition, the server retrieves information about the company's security management system from the database and compares it with collected incident information from other companies to determine whether the company is vulnerable to similar threats. The company's security management information includes firewall settings, access control policies, employee security training status, etc. For example, the server may determine that the company's email filtering is out of date.

[0106] Terminal

[0107] The terminal provides an interface for users to interact with the system. It notifies users of the assessment results and proposed countermeasures generated by the server and displays a management screen that allows users to take appropriate action. Specifically, the terminal displays risk assessments and proposed countermeasures in a detailed report format, and notifies users immediately of important information via email or alerts as needed.

[0108] User

[0109] Users are primarily security personnel who check the evaluation results and countermeasure proposals provided by the server on the management screen and direct the implementation of actual security measures. For example, they receive proposals such as "introducing the latest email filtering software" or "training employees on phishing" and take specific actions to implement them.

[0110] Here are some examples of prompts to input to a generative AI model:

[0111] "Please collect recent phishing attack cases in the financial industry, compare them with your company's phishing countermeasures, conduct a risk assessment, and propose specific countermeasures."

[0112] This system allows companies to automatically evaluate and improve their own security management systems based on the cases of other companies, enabling them to efficiently and effectively maintain and improve their security levels.

[0113] The flow of the identification process in the first embodiment will be described with reference to FIG.

[0114] Step 1:

[0115] The server connects to the Internet and automatically collects data on cyber attacks and information leaks by other companies from specific sources (such as security news sites and industry association reports). The input is the endpoint URL of the security news API, and the output is incident data in JSON format. The server sends REST API requests and receives responses.

[0116] Step 2:

[0117] The server formats the data it receives and converts it into the required format. It then stores it in a database (for example, MySQL or PostgreSQL). The input is the collected JSON-formatted data, and the output is a formatted database record. The server extracts and stores information such as the date and time of the incident, the type of attack, the scope of impact, and the cause.

[0118] Step 3:

[0119] The server analyzes the collected information using natural language processing technology (for example, SpaCy or NLTK library). The input is the text data stored in the database, and the output is the analyzed important elements (type of attack, scope of impact, cause, etc.). The server divides the text data into tokens, removes unnecessary words, and extracts important elements.

[0120] Step 4:

[0121] Based on the analysis results, the server categorizes cyber attacks and information leaks. The input is the analyzed data, and the output is data organized by category. For example, the server might categorize the data as "phishing attacks," "financial industry," or "medium damage scale."

[0122] Step 5:

[0123] The server retrieves information about the company's security management system from a database. The input is a database query containing information about the company's security system, and the output is the retrieved management information. For example, the server retrieves firewall settings, access control policies, and employee security training status.

[0124] Step 6:

[0125] The server compares the incident information collected by other companies with the company's security management system to identify vulnerabilities. The input is the incident information of other companies and the company's management information, and the output is the identified vulnerabilities. The server performs specific comparisons, such as checking to see if the company's email filtering is out of date.

[0126] Step 7:

[0127] The server evaluates the risk of the company based on the matching result. The input is the matching result, and the output is a risk score. The server runs a risk evaluation algorithm and evaluates the risk score of a phishing attack as "high," for example.

[0128] Step 8:

[0129] The server proposes specific countermeasures based on the risk assessment results. The input is the risk assessment results, and the output is the proposed countermeasures. The server proposes technical countermeasures (e.g., installing the latest email filtering software), policy changes (e.g., reviewing access control), and employee training (e.g., conducting phishing drills).

[0130] Step 9:

[0131] The server notifies the user of the risk assessment and proposed countermeasures. The input is the proposed countermeasures, and the output is a notification and a detailed report. The server compiles the assessment results and proposed countermeasures and displays them on the management screen, and notifies users of important information via email or alerts as needed.

[0132] In this way, servers, terminals, and users work together to run the system and effectively evaluate and improve their company's security management system.

[0133] (Application example 1)

[0134] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."

[0135] Currently, it is difficult to effectively collect information on cyber attacks and data leaks that have occurred at other companies and reflect it in one's own security management system. Furthermore, risk assessments and countermeasure proposals based on this information are performed manually, which lack real-time performance and often results in delayed countermeasures. Furthermore, there is a need for more advanced analysis using the latest AI technology.

[0136] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.

[0137] In this invention, the server

[0138] A means of collecting information on cyber attacks and information leaks at other companies,

[0139] A means of analyzing and classifying collected cyber attacks and information leaks from other companies,

[0140] A means of verifying the collected information against your company's security management system, and

[0141] a means for performing a risk assessment based on the matching results;

[0142] A means of proposing countermeasures based on the results of the risk assessment;

[0143] means for notifying a user of the content of the risk assessment and the proposed measures;

[0144] A method to extract the type, scope, and cause of an attack using a generative AI model based on cyber attacks and data breaches by other companies;

[0145] means for providing the extracted information to a user as a prompt sentence;

[0146] This will enable the company to efficiently collect and analyze cyber attacks and information leaks by other companies, and strengthen its own security measures in real time.

[0147] "Cyber ​​attacks and information leaks at other companies" refers to incidents involving unauthorized access or data acquisition that other organizations or companies have experienced.

[0148] "Collection methods" refer to methods and technologies that automatically obtain data from the Internet or specific sources.

[0149] "Means of analysis and classification" refers to techniques and methods for analyzing collected data and categorizing it based on its characteristics.

[0150] "Our company's security management system" refers to the organizational policies and measures for protecting our company's information and systems.

[0151] "Means of comparison" refers to the technology or method for comparing other companies' case information with your own security settings and policies.

[0152] "Risk assessment methods" refer to methods and techniques used to assess a company's vulnerability to similar threats and their impact.

[0153] "Means for proposing countermeasures" refers to techniques and methods for proposing specific security measures based on the results of risk assessment.

[0154] "Means of notification" refers to the technology or method for notifying users of the evaluation results and proposals, including email and push notifications.

[0155] "Methods for extracting attack types, scope of impact, and causes using generative AI models" refers to methods that utilize AI technology to automatically identify and extract specific elements from collected data.

[0156] "Means for providing the extracted information to the user as a prompt" refers to a technique or method for providing the user with instructions or suggestions generated based on the analysis results.

[0157] This invention is a system that collects information on cyber attacks and information leaks from other companies, analyzes it, compares it with the company's own security management system, and automatically performs risk assessments and proposes countermeasures. This system consists of the following main components.

[0158] 1. Collecting information on cyber attacks and information leaks at other companies

[0159] The server automatically collects information about cyber attacks and data breaches by other companies from the internet and specific sources. This information is collected using Python and scraping libraries (BeautifulSoup, Scrapy). The collected information includes the date and time of the incident, the type of attack, the scope of impact, and the cause.

[0160] 2. Information analysis and classification

[0161] The server uses natural language processing technology to analyze the collected information and extract key elements of cyber attacks and data breaches (e.g., type of attack, scope of impact, cause, etc.). The specific technology used is the Transformers library (BERT model, etc.).

[0162] 3. Comparison with the company's management system

[0163] The server retrieves information about the company's security management system from a database (MySQL) and compares it with incident information from other companies to determine whether the company is vulnerable to similar threats. Specific information includes firewall settings, access control policies, and employee security training status.

[0164] 4. Risk Assessment

[0165] Based on the matching results, the server assesses the risk to the company if it were exposed to a similar threat. The risk assessment is based on the likelihood and impact of the threat, and a risk score is calculated.

[0166] 5. Proposal of countermeasures

[0167] Based on the results of the risk assessment, the server will propose specific countermeasures, including technical measures (e.g., updating anti-ransomware software, strengthening firewall rules), policy changes (e.g., reviewing access control, implementing data encryption), and employee education (e.g., security training).

[0168] 6. Notification and Reporting

[0169] The server notifies the user of the evaluation results and recommendations. Notification methods include email, alerts, and push notifications (FCM (Firebase Cloud Messaging)). In addition, the evaluation results and recommendations are displayed in a detailed report format on the user's management screen.

[0170] As a concrete example, if a financial institution were to be hit by a phishing attack and customer data were to be leaked, the server would use natural language processing technology to extract from this information the type of attack, the extent of its impact, and the cause. Based on this information, the server would compare the company's phishing countermeasures, conduct a risk assessment, and propose specific countermeasures (for example, the introduction of the latest email filtering software or phishing training for employees).

[0171] Example prompt sentence:

[0172] Analyze a news article stating that "A certain financial institution was subjected to a phishing attack and customer data was leaked," and extract the type of attack, the scope of its impact, and the cause.

[0173] In this way, the system can effectively leverage cyber attacks and data breaches by other companies to continuously strengthen its own security posture.

[0174] The flow of the specific processing in the application example 1 will be described with reference to FIG.

[0175] Step 1:

[0176] Collecting information on cyber attacks and information leaks at other companies

[0177] The server automatically collects information about cyber attacks and data breaches by other companies from the internet and specific sources (news sites and industry association reports). Specifically, it uses Python and scraping libraries (BeautifulSoup, Scrapy) to obtain data such as the date and time of the incident, the type of attack, the scope of impact, and the cause. A URL or API endpoint is given as input, and a list of incident information is generated as output.

[0178] Step 2:

[0179] Information analysis and classification

[0180] The server analyzes the collected information using natural language processing technology. Specifically, it uses the Transformers library (such as the BERT model) to extract key elements of cyber attacks and data breaches (such as the type of attack, the scope of impact, and the cause). The collected raw data is given as input, and the extracted and analyzed data is output. This analysis classifies the type of incident and the scope of impact.

[0181] Step 3:

[0182] Verification with our company's management system

[0183] The server retrieves information about the company's security management system (firewalls, access control policies, employee security training status, etc.) from a database (MySQL). It then compares this information with the collected and analyzed incident information of other companies to determine whether the company is vulnerable to similar threats. The input is the analysis data of other companies and the company's management system information, and the output is the comparison result.

[0184] Step 4:

[0185] Risk Assessment

[0186] The server evaluates the risk of the company being exposed to a similar threat based on the matching results. This risk assessment is based on the likelihood and impact of the threat, and a risk score is calculated. The matching results are given as input, and a numerical risk score is obtained as output.

[0187] Step 5:

[0188] Countermeasure proposals

[0189] The server then proposes specific countermeasures based on the results of the risk assessment, including technical measures (e.g., updating anti-ransomware software, strengthening firewalls), policy changes, employee training, etc. The server receives a risk score as input and generates a proposal as output.

[0190] Step 6:

[0191] Notifications and Reporting

[0192] The server notifies the user of the evaluation results and recommendations via email or push notification (FCM (Firebase Cloud Messaging)). A detailed report is also generated to be displayed on the admin panel. The recommendation data is given as input, and the notification sent to the user and the report for display are obtained as output.

[0193] Step 7:

[0194] Prompt generation and provision of information

[0195] The server uses a generative AI model based on cyber attacks and data breaches by other companies to extract the type of attack, the scope of impact, and the cause. This information is then presented to the user as a prompt. For example, the following prompt:

[0196] Analyze a news article stating that "A certain financial institution was subjected to a phishing attack and customer data was leaked," and extract the type of attack, the scope of its impact, and the cause.

[0197] The input is the analysis data, and the output is the generated prompt sentence.

[0198] Furthermore, an emotion engine that estimates the user's emotion may be combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59 and perform identification processing using the user's emotion.

[0199] This invention combines a system that collects cyber-attacks and information leaks that have occurred at other companies, analyzes them, compares them with the company's own security management system, and automatically performs everything from risk assessment to proposing countermeasures, with an emotion engine that recognizes the user's emotions. Below, we will explain the processing content of this system's program in natural language, and also provide specific examples.

[0200] Program processing flow

[0201] 1. Collecting information on cyber attacks and information leaks at other companies

[0202] The server automatically collects data on cyber attacks and information leaks by other companies from the Internet and specific sources (security news sites, industry association reports, etc.).

[0203] The collected information includes the date and time of the incident, the type of attack, the scope of impact, and the cause.

[0204] For example, the server obtains information from the "Security News API" that "a certain financial institution was attacked by a phishing attack and customer data was leaked."

[0205] 2. Information analysis and classification

[0206] The server analyzes the acquired information using natural language processing technology, which extracts important elements of cyber attacks and data breaches (such as the type of attack, the scope of impact, and the cause).

[0207] Based on the analysis results, classification is made according to the type of incident and the scope of impact.

[0208] For example, the server classifies the information about phishing attacks it collects as "phishing attacks," "financial industry," and "medium damage scale."

[0209] 3. Checking your company's management system

[0210] The server retrieves information about your company's security controls from a database, including firewall settings, access control policies, and employee security training status.

[0211] The server compares the incident information collected from other companies with the company's own security management system to determine whether the company is vulnerable to similar threats.

[0212] For example, the server checks to see if its phishing protection (email filtering, employee training, etc.) is out of date.

[0213] 4. Risk Assessment

[0214] The server uses the results of the comparison to assess the risk to its company if it were to be exposed to a similar threat. The risk assessment is based on the likelihood and impact of the threat.

[0215] A risk score is calculated and countermeasures are prioritized based on this.

[0216] For example, the server may check for deficiencies in its own phishing prevention measures and rate the risk score as "high."

[0217] 5. Proposal of countermeasures

[0218] The server proposes specific countermeasures based on the results of the risk assessment.

[0219] These suggestions include technical measures (e.g., updating anti-ransomware software, strengthening firewall settings), policy changes (e.g., reviewing access controls, implementing data encryption), and employee education (e.g., conducting security training).

[0220] For example, the server might suggest "introducing the latest email filtering software" or "conducting phishing training for employees."

[0221] 6. Notification and Reporting

[0222] The server notifies the user (security officer) of the evaluation results and recommendations.

[0223] The server generates detailed reports that are displayed on the user's management screen, and notifies users immediately of important information via email or alerts.

[0224] For example, the server compiles these risk assessments and recommendations into a report, displays it on the user's management screen, and notifies them by email.

[0225] 7. Use of Emotion Engine

[0226] The server acquires the user's emotion data and analyzes the user's emotion. The emotion engine analyzes the user's text input and voice data to recognize the emotion.

[0227] The server can then tailor the notification content based on the perceived emotion, for example softening the tone of the notification or adding additional explanation if the user is feeling stressed.

[0228] The emotion engine allows the server to select the optimal notification method based on the user's emotional state. For example, if the situation is urgent, the server will provide immediate notification, and if the situation is normal, the server will provide information periodically.

[0229] This system not only suggests effective security measures based on incidents at other companies, but also provides appropriate notifications taking into account the user's emotional state, allowing users to receive information at the appropriate time and in the appropriate way.

[0230] The processing flow will be explained below.

[0231] Step 1:

[0232] The server periodically collects data on cyber attacks and information breaches by other companies from reliable sources (e.g., security news sites and industry reports). The server accesses these sources using APIs or web scraping technology, automatically obtains the latest incident information, and stores it in a database.

[0233] Step 2:

[0234] The server analyzes the collected data using natural language processing (NLP) technology. The server extracts necessary information from the text data (such as the date and time of the incident, the type of attack, the scope of impact, and the cause) and structures this data. For example, the server classifies phishing attack data as "phishing attack," "financial industry," and "medium damage scale."

[0235] Step 3:

[0236] The server retrieves information about your company's security management system from a database, including firewall settings, access control policies, employee security training status, etc. The server periodically updates the data to keep this information up to date.

[0237] Step 4:

[0238] The server compares the incident information collected from other companies with the company's management system. The server performs the comparison process, identifies similarities and differences between the company's security management system and those of other companies, and identifies vulnerabilities and areas for improvement. For example, it checks whether the company's phishing countermeasures are out of date.

[0239] Step 5:

[0240] The server performs a risk assessment based on the matching results. The server calculates a risk score based on the type of threat and gaps in the company's management system. This risk score is calculated taking into account the likelihood and impact of the threat. For example, the server may check for deficiencies in the company's phishing countermeasures and assess the risk score as "high."

[0241] Step 6:

[0242] The server proposes specific countermeasures based on the results of the risk assessment. These countermeasures include technical measures (e.g., updating anti-ransomware software, strengthening firewall settings), policy changes (e.g., reviewing access control, implementing data encryption), and employee education (e.g., implementing security training). For example, the server suggests "introducing the latest email filtering software" and "implementing phishing training for employees."

[0243] Step 7:

[0244] The server notifies the user of the assessment results and proposed countermeasures. The server generates a detailed report and displays it on the user's management screen. Important information is also immediately notified to the user via email or alerts. For example, the server compiles these risk assessments and proposals into a report, displays it on the user's management screen, and notifies the user by email.

[0245] Step 8:

[0246] The server acquires the user's emotional data and analyzes the user's emotions. The emotion engine analyzes the user's text input and voice data to recognize emotions. For example, the device collects the user's voice input, and the emotion engine analyzes it to detect "stress."

[0247] Step 9:

[0248] The server adjusts the content of notifications based on the recognized emotion. For example, if the user is feeling stressed, the notification tone may be softened or additional explanations may be added to make the information easier for the user to receive.

[0249] Step 10:

[0250] The emotion engine allows the server to select the optimal notification method based on the user's emotional state. For example, if the information is urgent, the server will provide immediate notification, and if it is normal, the server will provide periodic information, thereby conveying information in the most appropriate way for the user.

[0251] This allows the server to not only propose effective security measures based on cases from other companies, but also to provide appropriate notifications taking into account the user's emotional state.

[0252] Example 2

[0253] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."

[0254] When a cyber attack or information leak occurs, it is important to learn from similar incidents at other companies and respond quickly and appropriately. However, with conventional systems, the process of collecting and analyzing other companies' incidents, assessing risks, and proposing countermeasures is often done manually, which is time-consuming and laborious. As a result, timely countermeasures may be delayed, potentially exacerbating the damage. Another challenge is how to provide effective notifications while reducing user stress and anxiety.

[0255] The specific processing by the specific processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means.

[0256] In this invention, the server includes means for collecting information on cyber attacks and information leakage incidents by other companies, means for analyzing and classifying the collected information on cyber attacks and information leakage incidents by other companies using natural language processing, means for comparing the collected information with the company's own security management system, means for conducting a risk assessment based on the comparison results and taking into account the possibility and impact of threats, means for proposing specific countermeasures based on the results of the risk assessment, means for notifying the user of the risk assessment and the proposed countermeasures, and means for acquiring user emotion data and adjusting the content of the notification based on the emotion analysis results. This makes it possible to quickly learn lessons from cyber attacks and information leakage incidents by other companies, identify the company's own vulnerabilities, propose appropriate countermeasures, and provide optimal notifications that take the user's emotional state into consideration.

[0257] A "cyber attack" is an attack on a computer system or network, such as unauthorized access, data theft, or destruction.

[0258] "Information leakage" refers to the unintentional or unauthorized leakage of confidential information or personal information to the outside.

[0259] "Collection means" refers to the ability to obtain the required information from the Internet or specific sources.

[0260] "Analysis means" refers to the function of analyzing collected information using natural language processing technology, etc., and extracting important elements.

[0261] "Classification means" refers to a function that categorizes analyzed information based on specific criteria.

[0262] "Matching means" refers to a function for comparing and examining the case information of other companies with one's own security management system and identifying vulnerabilities.

[0263] "Risk assessment means" refers to a function that evaluates the likelihood and impact of a threat and calculates a risk score.

[0264] "Measures proposal means" refers to the function of presenting appropriate measures based on the results of risk assessment.

[0265] "Notification means" refers to a function for notifying the user of the results of risk assessment and proposed measures.

[0266] "Emotional data" refers to information about a user's emotional state.

[0267] "Emotion analysis results" refer to the results obtained by analyzing emotion data.

[0268] This invention combines a system that collects cyber attacks and information leaks that have occurred at other companies, analyzes them, compares them with the company's own security management system, and automatically performs risk assessments and proposes countermeasures, with an emotion engine that recognizes user emotions. Specific embodiments for implementing this system will be described below.

[0269] Collecting information on cyber attacks and information leaks at other companies

[0270] The server automatically collects data on cyber attacks and information leaks by other companies from the internet or specific sources (e.g., security news sites, industry association reports). This data is collected using API requests and web scraping technology. For example, information such as "A certain financial institution was attacked by a phishing attack and customer data was leaked" is obtained from the "Security News API."

[0271] Information analysis and classification

[0272] The server analyzes the information it collects using natural language processing technology (e.g., Python's NLTK or spaCy library) to extract important elements of cyber attacks and information leaks (such as the type of attack, the scope of impact, and the cause). Based on the analysis results, the incidents are classified according to their type and scope of impact. For example, information about phishing attacks collected by the server is classified as "phishing attack," "financial industry," and "medium damage scale."

[0273] Verification of in-house management system

[0274] The server retrieves information about its own security management system from a database, including firewall settings, access control policies, and employee security training. The server compares the collected information about other companies' incidents with its own security management system to determine whether its own company is vulnerable to similar threats. For example, the server may determine that its phishing protection is out of date.

[0275] Risk Assessment

[0276] Based on the matching results, the server assesses the risk to the company if it were exposed to a similar threat. The risk assessment is based on the likelihood and impact of the threat. Machine learning models can be used to calculate the risk score. For example, the server may identify weaknesses in the company's phishing protection and assess the risk score as "high."

[0277] Countermeasure proposals

[0278] Based on the results of the risk assessment, the server uses a generative AI model to propose specific countermeasures. These proposals include technical measures (e.g., updating anti-ransomware software, strengthening firewall settings), policy changes (e.g., reviewing access control, implementing data encryption), and employee education (e.g., security training). For example, the server may suggest "introducing the latest email filtering software" or "implementing phishing training for employees."

[0279] Notifications and Reporting

[0280] The server notifies the user of the assessment results and recommendations. Notifications include displaying the results on the management screen, sending emails about important information, and sending alerts. For example, the server compiles the risk assessment and recommendations into a report, displays it on the user's management screen, and notifies the user of important information by email.

[0281] Using the Emotion Engine

[0282] The server acquires the user's emotional data and analyzes it using an emotion engine. The emotion engine uses libraries such as IBM Watson Tone Analyzer to analyze the user's text input and voice data and recognize emotions. The notification content is adjusted based on the recognized emotion. For example, if the user is feeling stressed, the tone of the notification can be softened and additional explanations can be added. The emotion engine allows the server to select the optimal notification method according to the user's emotional state. For example, if the situation is urgent, an immediate notification can be sent, and if the situation is normal, information can be provided periodically.

[0283] Example prompt sentence:

[0284] "Please obtain information on the latest cyber attacks of other companies and classify the scope of impact and the cause of the attacks. Then, based on this information, please compile a report comparing the results with your own company's security posture."

[0285] "Generate reports that identify vulnerabilities in your security measures and suggest countermeasures accordingly. Tailor notifications based on the user's stress level."

[0286] This system not only suggests effective security measures based on incidents at other companies, but also provides appropriate notifications taking into account the user's emotional state, allowing users to receive information at the appropriate time and in the appropriate way.

[0287] The flow of the identification process in the second embodiment will be described with reference to FIG.

[0288] Step 1:

[0289] Collecting information on cyber attacks and information leaks at other companies

[0290] The server accesses information sources such as security news APIs to obtain data on cyber attacks and information leaks.

[0291] Input: Take the URL of a security news or industry report as input via an API request or other method.

[0292] Data processing: Analyze data such as JSON format obtained via API requests and extract necessary information (e.g., type of attack, date and time of occurrence, scope of impact).

[0293] Output: The extracted data is organized and stored in a database.

[0294] Specifically, a scheduled job is set up for periodic access, and the necessary information is filtered using a naive Bayesian classifier or similar.

[0295] Step 2:

[0296] Information analysis and classification

[0297] The server analyzes the collected data using natural language processing technology and extracts important elements.

[0298] Input: Collected data (e.g., type of attack, scope of impact, cause)

[0299] Data processing: Use a natural language processing library (e.g., NLTK, spaCy) to extract important elements from the text data and run them through a classification algorithm.

[0300] Output: The analyzed data is categorized by attributes such as "type of attack," "industry," and "scale of damage," and stored in a database.

[0301] Specifically, it tokenizes text data, performs partial analysis (noun phrase extraction), and classifies the data by category. For example, it classifies information about phishing attacks into "phishing attacks," "financial industry," and "medium damage scale."

[0302] Step 3:

[0303] Verification of in-house management system

[0304] The server retrieves the company's security management system information from the database and compares it with other companies' case information.

[0305] Input: Your company's security settings information (firewall settings, access control policies, etc.) and other companies' case information

[0306] Data calculation: A matching algorithm identifies gaps between your company's security settings and those of other companies.

[0307] Output: Gap analysis results are obtained and your company's vulnerabilities are identified.

[0308] Specifically, it sets certain thresholds and performs filtering to determine whether or not a match occurs based on those criteria. For example, the server identifies that its phishing protection is out of date.

[0309] Step 4:

[0310] Risk Assessment

[0311] The server performs a risk assessment based on its own vulnerabilities and calculates a risk score.

[0312] Input: Gap analysis results, threat type, impact

[0313] Data computation: Using machine learning models to calculate risk scores and quantify the likelihood and impact of risks.

[0314] Output: Risk scores are obtained and countermeasures are prioritized.

[0315] Specifically, the server adds up the scores for each risk factor and performs a comprehensive risk assessment. For example, the server may assess the risk score for phishing protection as "high."

[0316] Step 5:

[0317] Proposal of measures

[0318] The server uses a generative AI model to propose specific countermeasures.

[0319] Input: Risk assessment results, risk score

[0320] Data processing: Generate countermeasures using a generative AI model and create specific proposals.

[0321] Output: Countermeasure proposals are obtained and stored in a database.

[0322] Specifically, the system uses the proposal generation and feedback functions to automatically generate optimal countermeasures, such as suggesting "the introduction of the latest email filtering software" or "implementing phishing training for employees."

[0323] Step 6:

[0324] Notifications and Reporting

[0325] The server notifies the user of the evaluation results and recommendations and creates a detailed report.

[0326] Input: Risk assessment results, proposed countermeasures

[0327] Data Processing: Notification and reporting algorithms shape the data and provide information to the user.

[0328] Output: Reports are generated and displayed on the user's admin screen. Important information is also sent via email.

[0329] Specifically, it generates a report using an HTML or PDF generation library and sends an email to the user using SMTP.

[0330] Step 7:

[0331] Using the Emotion Engine

[0332] The server acquires the user's emotional data and analyzes it using an emotion engine.

[0333] Input: User text input and voice data

[0334] Data calculation: Analyze using an emotion analysis engine (e.g., IBM Watson Tone Analyzer) to recognize the emotional state.

[0335] Output: The sentiment analysis results are used to adjust the tone and manner of the notification.

[0336] Specifically, it uses text mining and voice analysis technology to identify the user's emotions and optimizes the notification method. For example, if the user is feeling stressed, it softens the tone of the notification and adds additional explanation. Depending on the user's condition, it responds immediately in emergencies and sends regular notifications under normal circumstances.

[0337] In this way, the entire system achieves effective security measures based on examples from other companies and appropriate notifications that take into account the user's emotional state.

[0338] (Application example 2)

[0339] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."

[0340] Current security systems are capable of collecting and analyzing information on cyberattacks from other companies, but the process of incorporating that information into one's own security system is not automated, making it difficult to respond quickly and effectively. Furthermore, there is no notification method that takes into account the user's emotional state, making it difficult to deliver appropriate content or notifications according to the situation. As a result, users may feel stressed or miss important notifications.

[0341] The identification process by the identification processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means. In this invention, the server includes means for collecting information on cyber attacks and information leakage cases by other companies, means for analyzing and classifying the collected information on cyber attacks and information leakage cases by other companies, and means for adjusting the notification content using an emotion engine that recognizes the user's emotions. This makes it possible to quickly reflect the collected information on cyber attacks by other companies in one's own security system and also enables appropriate notifications to be provided according to the user's emotional state.

[0342] "Cyber ​​attacks and information leaks at other companies" refers to specific incidents and examples of cyber attacks and information leaks that have occurred at other companies or organizations.

[0343] "Means of collection" refers to the methods and technologies that allow a server to automatically obtain data on other companies' cyber attacks and information leaks from the Internet or specific sources.

[0344] "Means of analysis and classification" refers to methods and technologies for analyzing information acquired by a server using natural language processing technology, etc., and classifying cyber attacks and information leaks based on their type, scope of impact, etc.

[0345] "Your company's security management system" refers to the entire security policies, settings, measures, etc. that your company or organization has.

[0346] "Means of comparison" refers to methods and technologies for comparing information on cyber attacks and information leaks at other companies with one's own security management system to identify the possibility that one's company may be exposed to similar threats or vulnerabilities.

[0347] "Risk assessment" refers to the process of assessing the risk to a company if it is exposed to the same threats as other companies, based on the likelihood and impact of the threat.

[0348] "Means for proposing countermeasures" refers to methods and technologies by which the server provides specific countermeasures to strengthen the company's security based on the results of risk assessment.

[0349] "Means of notifying users" refers to methods and technologies for communicating the contents of risk assessments and proposed countermeasures to users.

[0350] "Emotion engine" refers to technology that analyzes a user's text input and voice data to recognize the user's emotional state.

[0351] "Means for tailoring notification content" refers to methods and techniques for optimizing the tone and content of notifications based on perceived user sentiment.

[0352] To implement the present invention, the following system configuration and program processing must be executed.

[0353] This system runs on a server and automatically collects and analyzes information on cyber attacks and information leaks from other companies, compares it with the company's own security management system, assesses the risks, proposes countermeasures, and notifies users.It also incorporates an emotion engine that recognizes the user's emotional state, allowing it to adjust the content of notifications according to their emotions.

[0354] Specifically, the server operates as follows.

[0355] Data collection:

[0356] The server collects data on cyber attacks and information leaks by other companies from the internet and specific sources (such as security news sites and industry association reports). This collection process uses external services such as the "Security News API." The information obtained by the server includes the date and time of the incident, the type of attack, the scope of impact, and the cause.

[0357] Information analysis and classification:

[0358] Using natural language processing technology (such as Google Cloud Natural Language API), the information collected by the server is analyzed, and key elements of cyber attacks and data breaches are extracted and classified. The classification process involves tagging the incidents based on their type and scope of impact.

[0359] Checking our management system:

[0360] The server retrieves information about the company's security management system from the database and compares it with incident information collected from other companies. This comparison evaluates whether the company is vulnerable to similar threats. For example, if the company's phishing protection is out of date, this will be identified as a vulnerability.

[0361] Risk Assessment:

[0362] The server performs a risk assessment based on the matching results. The risk assessment calculates a risk score based on the likelihood and impact of the threat. This risk score determines the priority of countermeasures.

[0363] Suggested solutions:

[0364] Based on the results of the risk assessment, the server will propose specific countermeasures, including technical measures (e.g., updating anti-ransomware software and strengthening firewall settings), policy changes (e.g., reviewing access control and implementing data encryption), and employee education (implementing security training).

[0365] Emotion Engine:

[0366] The server obtains the user's emotional data using the Google Cloud Speech-to-Text API and analyzes the user's emotions using an emotion engine. Based on the analysis results, the content of the notification is adjusted. For example, if the user is feeling stressed, the tone of the notification may be softened or additional explanations may be added.

[0367] notification:

[0368] The server notifies the user of the evaluation results and proposed measures. The content of the notification is adjusted by the emotion engine. For example, if the issue is highly urgent, an immediate notification will be sent.

[0369] Examples:

[0370] If the user is in a normal emotional state, the server sends a notification suggesting "installation of the latest email filtering software."

[0371] If the user is in a high-stress state, soften the notification and say, "Start with some simple steps to improve your security."

[0372] Example prompt sentence:

[0373] "I would like to implement a system that collects information on the latest cyber attacks that have occurred at other companies and uses that information to evaluate my own company's security posture. In the process, I would also like to add a function that adjusts the content of notifications based on the user's emotions. I would like advice on how to soften the content of notifications when a user is under high stress."

[0374] By operating in this way, the system suggests effective security measures based on cases at other companies and provides appropriate notifications based on the user's emotional state, allowing the user to receive information at the appropriate time and in the appropriate way.

[0375] The flow of the specific processing in the application example 2 will be described with reference to FIG.

[0376] Step 1:

[0377] The server collects data on cyber attacks and information leaks by other companies from the internet or specific information sources. Specifically, it obtains the latest cyber attack information using a security news API, etc. The input in this case is an API request, and the output is JSON data containing cyber attack information.

[0378] Step 2:

[0379] The cyber attack information collected by the server is analyzed using natural language processing technology. Specifically, the Google Cloud Natural Language API is used to extract important elements from the text data (type of attack, scope of impact, cause, etc.). In this case, the input is the JSON data obtained in step 1, and the output is a list of the analyzed elements.

[0380] Step 3:

[0381] The server classifies the analyzed cyber attack information. Specifically, it sets categories based on the type of attack, the scope of impact, the scale of damage, etc., and classifies the information. In this case, the input is the list of elements extracted in step 2, and the output is a list of classified incidents.

[0382] Step 4:

[0383] The server retrieves information about the company's security controls from a database, specifically data such as firewall settings, access control policies, and employee security training status. The input in this case is a database query, and the output is a list of security control information.

[0384] Step 5:

[0385] The server compares the cyber attack information collected from other companies with the company's own security management system. Specifically, it checks for vulnerabilities in phishing countermeasures, email filtering, employee training, etc. The input in this case is the list of incidents from Step 3 and the list of management system information from Step 4, and the output is a list of vulnerabilities.

[0386] Step 6:

[0387] The server performs a risk assessment based on the company's vulnerability list. Specifically, it calculates a risk score based on the type of threat and gaps in the company's management system. In this case, the input is the vulnerability list from step 5, and the output is the risk assessment results and risk score.

[0388] Step 7:

[0389] The server proposes specific countermeasures based on the results of the risk assessment, such as introducing the latest email filtering software and conducting phishing training for employees. The input in this case is the risk assessment result and risk score from Step 6, and the output is a list of countermeasure proposals.

[0390] Step 8:

[0391] The server acquires the user's emotional data. Specifically, it uses the Google Cloud Speech-to-Text API or similar to acquire the user's voice commands and text input, which are then analyzed by the emotion engine. In this case, the input is the user's voice and text data, and the output is the recognized emotional data.

[0392] Step 9:

[0393] The server adjusts the notification content based on the emotion engine. Specifically, it changes the tone and content of the notification according to the user's emotional state. In this case, the input is the emotion data from step 8 and the countermeasure proposal list from step 7, and the output is the adjusted notification content.

[0394] Step 10:

[0395] The server notifies the user of the evaluation results and proposed countermeasures. Specifically, if the situation is urgent, the server notifies immediately, and if it is normal, the server notifies periodically. In this case, the input is the notification content from step 9, and the output is a notification message to the user.

[0396] The specific processing unit 290 transmits the result of the specific processing to the smart device 14. In the smart device 14, the control unit 46A causes the output device 40 to output the result of the specific processing. The microphone 38B acquires audio indicating a user input regarding the result of the specific processing. The control unit 46A transmits audio data indicating the user input acquired by the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.

[0397] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[0398] In the above embodiment, an example in which the specific process is performed by the data processing device 12 has been given, but the technology of the present disclosure is not limited to this, and the specific process may be performed by the smart device 14.

[0399] [Second embodiment]

[0400] FIG. 3 shows an example of the configuration of a data processing system 210 according to the second embodiment.

[0401] 3, the data processing system 210 includes the data processing device 12 and smart glasses 214. An example of the data processing device 12 is a server.

[0402] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[0403] The smart glasses 214 include a computer 36, a microphone 238, a speaker 240, a camera 42, and a communication I / F 44. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The microphone 238, the speaker 240, and the camera 42 are also connected to the bus 52.

[0404] The microphone 238 receives instructions and the like from the user 20 by receiving voice uttered by the user 20. The microphone 238 captures the voice uttered by the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio in accordance with instructions from the processor 46.

[0405] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the surroundings of user 20 (for example, an imaging range defined by an angle of view equivalent to the field of vision of a typical healthy person).

[0406] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 control the exchange of various information between the processor 46 and the processor 28 via the network 54. The exchange of various information between the processor 46 and the processor 28 using the communication I / Fs 44 and 26 is carried out in a secure state.

[0407] Fig. 4 shows an example of the main functions of the data processing device 12 and the smart glasses 214. As shown in Fig. 4, in the data processing device 12, a specific process is performed by the processor 28. A specific process program 56 is stored in the storage 32.

[0408] The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[0409] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[0410] In the smart glasses 214, the processor 46 performs the reception output process. A reception output program 60 is stored in the storage 50. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.

[0411] Next, a description will be given of the identification process performed by the identification processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as the "server" and the smart glasses 214 will be referred to as the "terminal."

[0412] This invention is a system that collects cyber attacks and information leaks that have occurred at other companies, analyzes them, compares them with the company's own security management system, and automatically performs everything from risk assessment to proposing countermeasures. Below, we will explain the processing content of this system's program in natural language, and also provide specific examples.

[0413] Program processing flow

[0414] 1. Collecting information on cyber attacks and information leaks at other companies

[0415] The server automatically collects data on cyber attacks and information leaks by other companies from the Internet and specific sources (security news sites, industry association reports, etc.).

[0416] The collected information includes the date and time of the incident, the type of attack, the scope of impact, and the cause.

[0417] For example, the server obtains information from the "Security News API" that "a certain financial institution was attacked by a phishing attack and customer data was leaked."

[0418] 2. Information analysis and classification

[0419] The server analyzes the acquired information using natural language processing technology, which extracts important elements of cyber attacks and data breaches (such as the type of attack, the scope of impact, and the cause).

[0420] Based on the analysis results, classification is made according to the type of incident and the scope of impact.

[0421] For example, the server classifies the information about phishing attacks it collects as "phishing attacks," "financial industry," and "medium damage scale."

[0422] 3. Checking your company's management system

[0423] The server retrieves information about your company's security controls from a database, including firewall settings, access control policies, and employee security training status.

[0424] The server compares the incident information collected from other companies with the company's own security management system to determine whether the company is vulnerable to similar threats.

[0425] For example, the server checks to see if its phishing protection (email filtering, employee training, etc.) is out of date.

[0426] 4. Risk Assessment

[0427] The server uses the results of the comparison to assess the risk to its company if it were to be exposed to a similar threat. The risk assessment is based on the likelihood and impact of the threat.

[0428] A risk score is calculated and countermeasures are prioritized based on this.

[0429] For example, the server may check for deficiencies in its own phishing prevention measures and rate the risk score as "high."

[0430] 5. Proposal of countermeasures

[0431] The server proposes specific countermeasures based on the results of the risk assessment.

[0432] These suggestions may include technical measures (e.g., updating anti-ransomware software, strengthening firewall rules), policy changes (e.g., reviewing access controls, implementing data encryption), and employee education (e.g., conducting security training).

[0433] For example, the server might suggest "introducing the latest email filtering software" or "conducting phishing training for employees."

[0434] 6. Notification and Reporting

[0435] The server notifies the user (security officer) of the evaluation results and recommendations.

[0436] The server generates a detailed report of the risk assessment and recommendations, which are displayed on the user's management screen.

[0437] If necessary, you can also receive immediate notification of important information via email or alerts.

[0438] For example, the server compiles these risk assessments and recommendations into a report, displays it on the user's management screen, and notifies them by email.

[0439] In this way, the system can effectively leverage cyber attacks and data breaches by other companies to continuously strengthen its own security posture.

[0440] The processing flow will be explained below.

[0441] Step 1:

[0442] The server periodically collects data on cyber attacks and information breaches by other companies from reliable sources (e.g., security news sites and industry reports). The server accesses these sources using APIs or web scraping technology to obtain the latest incident information and stores it in a database.

[0443] Step 2:

[0444] The server analyzes the collected data using natural language processing (NLP) technology, extracting necessary information from the text data (such as the date and time of the incident, the type of attack, the scope of impact, and the cause) and structuring this data.

[0445] Step 3:

[0446] The server classifies the incidents based on the analysis results. The information collected by the server is classified into the type of attack (e.g., ransomware, phishing, internal information leaks, etc.), industry (e.g., finance, healthcare, education, etc.), and scale of damage (e.g., large, medium, small).

[0447] Step 4:

[0448] The server retrieves information about the company's security posture from a database, including firewall settings, access control policies, vulnerability scan results, and employee security training status.

[0449] Step 5:

[0450] The server compares the incident information of other companies with the company's management system. The server performs the comparison process, identifies commonalities and differences between the company's security management system and those of other companies, and identifies vulnerabilities and areas for improvement.

[0451] Step 6:

[0452] The server performs a risk assessment based on the matching results. The server calculates a risk score based on the type of threat and gaps in the company's management system. The risk score is calculated taking into account the likelihood and impact of the threat.

[0453] Step 7:

[0454] The server proposes specific countermeasures based on the results of the risk assessment, including technical measures (e.g., updating anti-ransomware software, strengthening firewall settings), policy changes (e.g., reviewing access control, implementing data encryption), and employee education (e.g., implementing security training).

[0455] Step 8:

[0456] The server notifies the user of the risk assessment and proposed countermeasures. The server generates a detailed report and displays it on the user's management screen. The server also notifies the user immediately of important information via email or alerts.

[0457] Through the above process, a system will be created in which the server utilizes the cases of other companies to continuously strengthen its own security management system.

[0458] Example 1

[0459] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."

[0460] Conventional security systems often do not collect data on cyber attacks or information leaks from other companies, making it difficult to link this data to improvements in one's own security management system. Manually investigating other companies' incidents and reviewing one's own countermeasures takes time and effort, making it difficult to maintain and improve the security level of the entire company. Furthermore, if the risk assessment and countermeasure proposal processes are not systematized, they depend on the knowledge and experience of the individual in charge, making it difficult to implement uniform security measures.

[0461] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.

[0462] In this invention, the server includes: means for automatically collecting information on cyber attacks and information leak incidents by other companies from the Internet or specific information sources; means for preprocessing the collected information on cyber attacks and information leak incidents by other companies using natural language processing technology to extract and classify important elements; means for obtaining information on the company's own security management system from a database and comparing it with the collected information to identify vulnerabilities; means for calculating a risk score based on the comparison result and conducting a risk assessment; means for proposing specific countermeasures such as technical measures, policy changes, and employee training based on the result of the risk assessment; and means for notifying the user of the risk assessment and the proposed countermeasures and displaying them in a detailed report format on the user's management screen. This enables the company to automatically evaluate and improve its own security management system based on the incidents of other companies, thereby efficiently and effectively maintaining and improving its security level.

[0463] A "cyber attack" is a malicious attack on a computer system or network via the Internet.

[0464] "Information leakage" refers to the phenomenon or act of confidential information or personal information leaking to the outside without permission.

[0465] "Natural language processing technology" is a technology that enables computers to understand and process human language.

[0466] A "database" is a system or software for efficiently managing, searching, and updating large amounts of data.

[0467] A "vulnerability" is a weakness in a computer system or network that makes it susceptible to external attacks.

[0468] "Risk assessment" is the process of assessing the extent of damage or impact if a particular threat occurs.

[0469] A "risk score" is a numerical representation of the result of a risk assessment, indicating the severity of a threat and the probability of it occurring.

[0470] "Countermeasure proposals" are proposals on what measures or actions should be taken to address a specific risk.

[0471] "Technical measures" are means of responding to threats using software or hardware.

[0472] "Policy change" means reviewing and revising rules and guidelines within an organization.

[0473] "Employee training" is the training and education of an organization's employees to acquire specific knowledge and skills.

[0474] "Users" refer to the security personnel and operations managers who use this system.

[0475] A "report format" is a document format for organizing information and data and presenting them in a visually easy-to-understand manner.

[0476] The "management screen" is an interface for operating and configuring the system.

[0477] This invention is a system that collects cyber attacks and information leaks that have occurred at other companies, analyzes them, compares them with the company's own security management system, and automatically performs risk assessments and proposes countermeasures. This system is implemented with the involvement of servers, terminals, and users.

[0478] server

[0479] The server is responsible for automatically collecting data on cyber attacks and information leaks by other companies from the internet and specific sources (e.g., security news sites and industry association reports). Specifically, the server connects to the "Security News API" and retrieves data by sending a REST API request. This data includes information such as the date and time of the incident, the type of attack, the scope of impact, and the cause. The collected data is stored in a database (e.g., MySQL or PostgreSQL).

[0480] The server analyzes the collected information using natural language processing technology (for example, SpaCy or the NLTK library). Specifically, it tokenizes the text data, removes unnecessary words, and extracts important elements such as the type of attack and the scope of impact. The extracted information is then classified by category. For example, data is classified as "phishing attack," "financial industry," and "medium damage scale."

[0481] In addition, the server retrieves information about the company's security management system from the database and compares it with collected incident information from other companies to determine whether the company is vulnerable to similar threats. The company's security management information includes firewall settings, access control policies, employee security training status, etc. For example, the server may determine that the company's email filtering is out of date.

[0482] Terminal

[0483] The terminal provides an interface for users to interact with the system. It notifies users of the assessment results and proposed countermeasures generated by the server and displays a management screen that allows users to take appropriate action. Specifically, the terminal displays risk assessments and proposed countermeasures in a detailed report format, and notifies users immediately of important information via email or alerts as needed.

[0484] User

[0485] Users are primarily security personnel who check the evaluation results and countermeasure proposals provided by the server on the management screen and direct the implementation of actual security measures. For example, they receive proposals such as "introducing the latest email filtering software" or "training employees on phishing" and take specific actions to implement them.

[0486] Here are some examples of prompts to input to a generative AI model:

[0487] "Please collect recent phishing attack cases in the financial industry, compare them with your company's phishing countermeasures, conduct a risk assessment, and propose specific countermeasures."

[0488] This system allows companies to automatically evaluate and improve their own security management systems based on the cases of other companies, enabling them to efficiently and effectively maintain and improve their security levels.

[0489] The flow of the identification process in the first embodiment will be described with reference to FIG.

[0490] Step 1:

[0491] The server connects to the Internet and automatically collects data on cyber attacks and information leaks by other companies from specific sources (such as security news sites and industry association reports). The input is the endpoint URL of the security news API, and the output is incident data in JSON format. The server sends REST API requests and receives responses.

[0492] Step 2:

[0493] The server formats the data it receives and converts it into the required format. It then stores it in a database (for example, MySQL or PostgreSQL). The input is the collected JSON-formatted data, and the output is a formatted database record. The server extracts and stores information such as the date and time of the incident, the type of attack, the scope of impact, and the cause.

[0494] Step 3:

[0495] The server analyzes the collected information using natural language processing technology (for example, SpaCy or NLTK library). The input is the text data stored in the database, and the output is the analyzed important elements (type of attack, scope of impact, cause, etc.). The server divides the text data into tokens, removes unnecessary words, and extracts important elements.

[0496] Step 4:

[0497] Based on the analysis results, the server categorizes cyber attacks and information leaks. The input is the analyzed data, and the output is data organized by category. For example, the server might categorize the data as "phishing attacks," "financial industry," or "medium damage scale."

[0498] Step 5:

[0499] The server retrieves information about the company's security management system from a database. The input is a database query containing information about the company's security system, and the output is the retrieved management information. For example, the server retrieves firewall settings, access control policies, and employee security training status.

[0500] Step 6:

[0501] The server compares the incident information collected by other companies with the company's security management system to identify vulnerabilities. The input is the incident information of other companies and the company's management information, and the output is the identified vulnerabilities. The server performs specific comparisons, such as checking to see if the company's email filtering is out of date.

[0502] Step 7:

[0503] The server evaluates the risk of the company based on the matching result. The input is the matching result, and the output is a risk score. The server runs a risk evaluation algorithm and evaluates the risk score of a phishing attack as "high," for example.

[0504] Step 8:

[0505] The server proposes specific countermeasures based on the risk assessment results. The input is the risk assessment results, and the output is the proposed countermeasures. The server proposes technical countermeasures (e.g., installing the latest email filtering software), policy changes (e.g., reviewing access control), and employee training (e.g., conducting phishing drills).

[0506] Step 9:

[0507] The server notifies the user of the risk assessment and proposed countermeasures. The input is the proposed countermeasures, and the output is a notification and a detailed report. The server compiles the assessment results and proposed countermeasures and displays them on the management screen, and notifies users of important information via email or alerts as needed.

[0508] In this way, servers, terminals, and users work together to run the system and effectively evaluate and improve their company's security management system.

[0509] (Application example 1)

[0510] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."

[0511] Currently, it is difficult to effectively collect information on cyber attacks and data leaks that have occurred at other companies and reflect it in one's own security management system. Furthermore, risk assessments and countermeasure proposals based on this information are performed manually, which lack real-time performance and often results in delayed countermeasures. Furthermore, there is a need for more advanced analysis using the latest AI technology.

[0512] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.

[0513] In this invention, the server

[0514] A means of collecting information on cyber attacks and information leaks at other companies,

[0515] A means of analyzing and classifying collected cyber attacks and information leaks from other companies,

[0516] A means of verifying the collected information against your company's security management system, and

[0517] a means for performing a risk assessment based on the matching results;

[0518] A means of proposing countermeasures based on the results of the risk assessment;

[0519] means for notifying a user of the content of the risk assessment and the proposed measures;

[0520] A method to extract the type, scope, and cause of an attack using a generative AI model based on cyber attacks and data breaches by other companies;

[0521] means for providing the extracted information to a user as a prompt sentence;

[0522] This will enable the company to efficiently collect and analyze cyber attacks and information leaks by other companies, and strengthen its own security measures in real time.

[0523] "Cyber ​​attacks and information leaks at other companies" refers to incidents involving unauthorized access or data acquisition that other organizations or companies have experienced.

[0524] "Collection methods" refer to methods and technologies that automatically obtain data from the Internet or specific sources.

[0525] "Means of analysis and classification" refers to techniques and methods for analyzing collected data and categorizing it based on its characteristics.

[0526] "Our company's security management system" refers to the organizational policies and measures for protecting our company's information and systems.

[0527] "Means of comparison" refers to the technology or method for comparing other companies' case information with your own security settings and policies.

[0528] "Risk assessment methods" refer to methods and techniques used to assess a company's vulnerability to similar threats and their impact.

[0529] "Means for proposing countermeasures" refers to techniques and methods for proposing specific security measures based on the results of risk assessment.

[0530] "Means of notification" refers to the technology or method for notifying users of the evaluation results and proposals, including email and push notifications.

[0531] "Methods for extracting attack types, scope of impact, and causes using generative AI models" refers to methods that utilize AI technology to automatically identify and extract specific elements from collected data.

[0532] "Means for providing the extracted information to the user as a prompt" refers to a technique or method for providing the user with instructions or suggestions generated based on the analysis results.

[0533] This invention is a system that collects information on cyber attacks and information leaks from other companies, analyzes it, compares it with the company's own security management system, and automatically performs risk assessments and proposes countermeasures. This system consists of the following main components.

[0534] 1. Collecting information on cyber attacks and information leaks at other companies

[0535] The server automatically collects information about cyber attacks and data breaches by other companies from the internet and specific sources. This information is collected using Python and scraping libraries (BeautifulSoup, Scrapy). The collected information includes the date and time of the incident, the type of attack, the scope of impact, and the cause.

[0536] 2. Information analysis and classification

[0537] The server uses natural language processing technology to analyze the collected information and extract key elements of cyber attacks and data breaches (e.g., type of attack, scope of impact, cause, etc.). The specific technology used is the Transformers library (BERT model, etc.).

[0538] 3. Comparison with the company's management system

[0539] The server retrieves information about the company's security management system from a database (MySQL) and compares it with incident information from other companies to determine whether the company is vulnerable to similar threats. Specific information includes firewall settings, access control policies, and employee security training status.

[0540] 4. Risk Assessment

[0541] Based on the matching results, the server assesses the risk to the company if it were exposed to a similar threat. The risk assessment is based on the likelihood and impact of the threat, and a risk score is calculated.

[0542] 5. Proposal of countermeasures

[0543] Based on the results of the risk assessment, the server will propose specific countermeasures, including technical measures (e.g., updating anti-ransomware software, strengthening firewall rules), policy changes (e.g., reviewing access control, implementing data encryption), and employee education (e.g., security training).

[0544] 6. Notification and Reporting

[0545] The server notifies the user of the evaluation results and recommendations. Notification methods include email, alerts, and push notifications (FCM (Firebase Cloud Messaging)). In addition, the evaluation results and recommendations are displayed in a detailed report format on the user's management screen.

[0546] As a concrete example, if a financial institution were to be hit by a phishing attack and customer data were to be leaked, the server would use natural language processing technology to extract from this information the type of attack, the extent of its impact, and the cause. Based on this information, the server would compare the company's phishing countermeasures, conduct a risk assessment, and propose specific countermeasures (for example, the introduction of the latest email filtering software or phishing training for employees).

[0547] Example prompt sentence:

[0548] Analyze a news article stating that "A certain financial institution was subjected to a phishing attack and customer data was leaked," and extract the type of attack, the scope of its impact, and the cause.

[0549] In this way, the system can effectively leverage cyber attacks and data breaches by other companies to continuously strengthen its own security posture.

[0550] The flow of the specific processing in the application example 1 will be described with reference to FIG.

[0551] Step 1:

[0552] Collecting information on cyber attacks and information leaks at other companies

[0553] The server automatically collects information about cyber attacks and data breaches by other companies from the internet and specific sources (news sites and industry association reports). Specifically, it uses Python and scraping libraries (BeautifulSoup, Scrapy) to obtain data such as the date and time of the incident, the type of attack, the scope of impact, and the cause. A URL or API endpoint is given as input, and a list of incident information is generated as output.

[0554] Step 2:

[0555] Information analysis and classification

[0556] The server analyzes the collected information using natural language processing technology. Specifically, it uses the Transformers library (such as the BERT model) to extract key elements of cyber attacks and data breaches (such as the type of attack, the scope of impact, and the cause). The collected raw data is given as input, and the extracted and analyzed data is output. This analysis classifies the type of incident and the scope of impact.

[0557] Step 3:

[0558] Verification with our company's management system

[0559] The server retrieves information about the company's security management system (firewalls, access control policies, employee security training status, etc.) from a database (MySQL). It then compares this information with the collected and analyzed incident information of other companies to determine whether the company is vulnerable to similar threats. The input is the analysis data of other companies and the company's management system information, and the output is the comparison result.

[0560] Step 4:

[0561] Risk Assessment

[0562] The server evaluates the risk of the company being exposed to a similar threat based on the matching results. This risk assessment is based on the likelihood and impact of the threat, and a risk score is calculated. The matching results are given as input, and a numerical risk score is obtained as output.

[0563] Step 5:

[0564] Countermeasure proposals

[0565] The server then proposes specific countermeasures based on the results of the risk assessment, including technical measures (e.g., updating anti-ransomware software, strengthening firewalls), policy changes, employee training, etc. The server receives a risk score as input and generates a proposal as output.

[0566] Step 6:

[0567] Notifications and Reporting

[0568] The server notifies the user of the evaluation results and recommendations via email or push notification (FCM (Firebase Cloud Messaging)). A detailed report is also generated to be displayed on the admin panel. The recommendation data is given as input, and the notification sent to the user and the report for display are obtained as output.

[0569] Step 7:

[0570] Prompt generation and provision of information

[0571] The server uses a generative AI model based on cyber attacks and data breaches by other companies to extract the type of attack, the scope of impact, and the cause. This information is then presented to the user as a prompt. For example, the following prompt:

[0572] Analyze a news article stating that "A certain financial institution was subjected to a phishing attack and customer data was leaked," and extract the type of attack, the scope of its impact, and the cause.

[0573] The input is the analysis data, and the output is the generated prompt sentence.

[0574] Furthermore, an emotion engine that estimates the user's emotion may be further combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59, and perform identification processing using the user's emotion.

[0575] This invention combines a system that collects cyber-attacks and information leaks that have occurred at other companies, analyzes them, compares them with the company's own security management system, and automatically performs everything from risk assessment to proposing countermeasures, with an emotion engine that recognizes the user's emotions. Below, we will explain the processing content of this system's program in natural language, and also provide specific examples.

[0576] Program processing flow

[0577] 1. Collecting information on cyber attacks and information leaks at other companies

[0578] The server automatically collects data on cyber attacks and information leaks by other companies from the Internet and specific sources (security news sites, industry association reports, etc.).

[0579] The collected information includes the date and time of the incident, the type of attack, the scope of impact, and the cause.

[0580] For example, the server obtains information from the "Security News API" that "a certain financial institution was attacked by a phishing attack and customer data was leaked."

[0581] 2. Information analysis and classification

[0582] The server analyzes the acquired information using natural language processing technology, which extracts important elements of cyber attacks and data breaches (such as the type of attack, the scope of impact, and the cause).

[0583] Based on the analysis results, classification is made according to the type of incident and the scope of impact.

[0584] For example, the server classifies the information about phishing attacks it collects as "phishing attacks," "financial industry," and "medium damage scale."

[0585] 3. Checking your company's management system

[0586] The server retrieves information about your company's security controls from a database, including firewall settings, access control policies, and employee security training status.

[0587] The server compares the incident information collected from other companies with the company's own security management system to determine whether the company is vulnerable to similar threats.

[0588] For example, the server checks to see if its phishing protection (email filtering, employee training, etc.) is out of date.

[0589] 4. Risk Assessment

[0590] The server uses the results of the comparison to assess the risk to its company if it were to be exposed to a similar threat. The risk assessment is based on the likelihood and impact of the threat.

[0591] A risk score is calculated and countermeasures are prioritized based on this.

[0592] For example, the server may check for deficiencies in its own phishing prevention measures and rate the risk score as "high."

[0593] 5. Proposal of countermeasures

[0594] The server proposes specific countermeasures based on the results of the risk assessment.

[0595] These suggestions include technical measures (e.g., updating anti-ransomware software, strengthening firewall settings), policy changes (e.g., reviewing access controls, implementing data encryption), and employee education (e.g., conducting security training).

[0596] For example, the server might suggest "introducing the latest email filtering software" or "conducting phishing training for employees."

[0597] 6. Notification and Reporting

[0598] The server notifies the user (security officer) of the evaluation results and recommendations.

[0599] The server generates detailed reports that are displayed on the user's management screen, and notifies users immediately of important information via email or alerts.

[0600] For example, the server compiles these risk assessments and recommendations into a report, displays it on the user's management screen, and notifies them by email.

[0601] 7. Use of Emotion Engine

[0602] The server acquires the user's emotion data and analyzes the user's emotion. The emotion engine analyzes the user's text input and voice data to recognize the emotion.

[0603] The server can then tailor the notification content based on the perceived emotion, for example softening the tone of the notification or adding additional explanation if the user is feeling stressed.

[0604] The emotion engine allows the server to select the optimal notification method based on the user's emotional state. For example, if the situation is urgent, the server will provide immediate notification, and if the situation is normal, the server will provide information periodically.

[0605] This system not only suggests effective security measures based on incidents at other companies, but also provides appropriate notifications taking into account the user's emotional state, allowing users to receive information at the appropriate time and in the appropriate way.

[0606] The processing flow will be explained below.

[0607] Step 1:

[0608] The server periodically collects data on cyber attacks and information breaches by other companies from reliable sources (e.g., security news sites and industry reports). The server accesses these sources using APIs or web scraping technology, automatically obtains the latest incident information, and stores it in a database.

[0609] Step 2:

[0610] The server analyzes the collected data using natural language processing (NLP) technology. The server extracts necessary information from the text data (such as the date and time of the incident, the type of attack, the scope of impact, and the cause) and structures this data. For example, the server classifies phishing attack data as "phishing attack," "financial industry," and "medium damage scale."

[0611] Step 3:

[0612] The server retrieves information about your company's security management system from a database, including firewall settings, access control policies, employee security training status, etc. The server periodically updates the data to keep this information up to date.

[0613] Step 4:

[0614] The server compares the incident information collected from other companies with the company's management system. The server performs the comparison process, identifies similarities and differences between the company's security management system and those of other companies, and identifies vulnerabilities and areas for improvement. For example, it checks whether the company's phishing countermeasures are out of date.

[0615] Step 5:

[0616] The server performs a risk assessment based on the matching results. The server calculates a risk score based on the type of threat and gaps in the company's management system. This risk score is calculated taking into account the likelihood and impact of the threat. For example, the server may check for deficiencies in the company's phishing countermeasures and assess the risk score as "high."

[0617] Step 6:

[0618] The server proposes specific countermeasures based on the results of the risk assessment. These countermeasures include technical measures (e.g., updating anti-ransomware software, strengthening firewall settings), policy changes (e.g., reviewing access control, implementing data encryption), and employee education (e.g., implementing security training). For example, the server suggests "introducing the latest email filtering software" and "implementing phishing training for employees."

[0619] Step 7:

[0620] The server notifies the user of the assessment results and proposed countermeasures. The server generates a detailed report and displays it on the user's management screen. Important information is also immediately notified to the user via email or alerts. For example, the server compiles these risk assessments and proposals into a report, displays it on the user's management screen, and notifies the user by email.

[0621] Step 8:

[0622] The server acquires the user's emotional data and analyzes the user's emotions. The emotion engine analyzes the user's text input and voice data to recognize emotions. For example, the device collects the user's voice input, and the emotion engine analyzes it to detect "stress."

[0623] Step 9:

[0624] The server adjusts the content of notifications based on the recognized emotion. For example, if the user is feeling stressed, the notification tone may be softened or additional explanations may be added to make the information easier for the user to receive.

[0625] Step 10:

[0626] The emotion engine allows the server to select the optimal notification method based on the user's emotional state. For example, if the information is urgent, the server will provide immediate notification, and if it is normal, the server will provide periodic information, thereby conveying information in the most appropriate way for the user.

[0627] This allows the server to not only propose effective security measures based on cases from other companies, but also to provide appropriate notifications taking into account the user's emotional state.

[0628] Example 2

[0629] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."

[0630] When a cyber attack or information leak occurs, it is important to learn from similar incidents at other companies and respond quickly and appropriately. However, with conventional systems, the process of collecting and analyzing other companies' incidents, assessing risks, and proposing countermeasures is often done manually, which is time-consuming and laborious. As a result, timely countermeasures may be delayed, potentially exacerbating the damage. Another challenge is how to provide effective notifications while reducing user stress and anxiety.

[0631] The specific processing by the specific processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means.

[0632] In this invention, the server includes means for collecting information on cyber attacks and information leakage incidents by other companies, means for analyzing and classifying the collected information on cyber attacks and information leakage incidents by other companies using natural language processing, means for comparing the collected information with the company's own security management system, means for conducting a risk assessment based on the comparison results and taking into account the possibility and impact of threats, means for proposing specific countermeasures based on the results of the risk assessment, means for notifying the user of the risk assessment and the proposed countermeasures, and means for acquiring user emotion data and adjusting the content of the notification based on the emotion analysis results. This makes it possible to quickly learn lessons from cyber attacks and information leakage incidents by other companies, identify the company's own vulnerabilities, propose appropriate countermeasures, and provide optimal notifications that take the user's emotional state into consideration.

[0633] A "cyber attack" is an attack on a computer system or network, such as unauthorized access, data theft, or destruction.

[0634] "Information leakage" refers to the unintentional or unauthorized leakage of confidential information or personal information to the outside.

[0635] "Collection means" refers to the ability to obtain the required information from the Internet or specific sources.

[0636] "Analysis means" refers to the function of analyzing collected information using natural language processing technology, etc., and extracting important elements.

[0637] "Classification means" refers to a function that categorizes analyzed information based on specific criteria.

[0638] "Matching means" refers to a function for comparing and examining the case information of other companies with one's own security management system and identifying vulnerabilities.

[0639] "Risk assessment means" refers to a function that evaluates the likelihood and impact of a threat and calculates a risk score.

[0640] "Measures proposal means" refers to the function of presenting appropriate measures based on the results of risk assessment.

[0641] "Notification means" refers to a function for notifying the user of the results of risk assessment and proposed measures.

[0642] "Emotional data" refers to information about a user's emotional state.

[0643] "Emotion analysis results" refer to the results obtained by analyzing emotion data.

[0644] This invention combines a system that collects cyber attacks and information leaks that have occurred at other companies, analyzes them, compares them with the company's own security management system, and automatically performs risk assessments and proposes countermeasures, with an emotion engine that recognizes user emotions. Specific embodiments for implementing this system will be described below.

[0645] Collecting information on cyber attacks and information leaks at other companies

[0646] The server automatically collects data on cyber attacks and information leaks by other companies from the internet or specific sources (e.g., security news sites, industry association reports). This data is collected using API requests and web scraping technology. For example, information such as "A certain financial institution was attacked by a phishing attack and customer data was leaked" is obtained from the "Security News API."

[0647] Information analysis and classification

[0648] The server analyzes the information it collects using natural language processing technology (e.g., Python's NLTK or spaCy library) to extract important elements of cyber attacks and information leaks (such as the type of attack, the scope of impact, and the cause). Based on the analysis results, the incidents are classified according to their type and scope of impact. For example, information about phishing attacks collected by the server is classified as "phishing attack," "financial industry," and "medium damage scale."

[0649] Verification of in-house management system

[0650] The server retrieves information about its own security management system from a database, including firewall settings, access control policies, and employee security training. The server compares the collected information about other companies' incidents with its own security management system to determine whether its own company is vulnerable to similar threats. For example, the server may determine that its phishing protection is out of date.

[0651] Risk Assessment

[0652] Based on the matching results, the server assesses the risk to the company if it were exposed to a similar threat. The risk assessment is based on the likelihood and impact of the threat. Machine learning models can be used to calculate the risk score. For example, the server may identify weaknesses in the company's phishing protection and assess the risk score as "high."

[0653] Countermeasure proposals

[0654] Based on the results of the risk assessment, the server uses a generative AI model to propose specific countermeasures. These proposals include technical measures (e.g., updating anti-ransomware software, strengthening firewall settings), policy changes (e.g., reviewing access control, implementing data encryption), and employee education (e.g., security training). For example, the server may suggest "introducing the latest email filtering software" or "implementing phishing training for employees."

[0655] Notifications and Reporting

[0656] The server notifies the user of the assessment results and recommendations. Notifications include displaying the results on the management screen, sending emails about important information, and sending alerts. For example, the server compiles the risk assessment and recommendations into a report, displays it on the user's management screen, and notifies the user of important information by email.

[0657] Using the Emotion Engine

[0658] The server acquires the user's emotional data and analyzes it using an emotion engine. The emotion engine uses libraries such as IBM Watson Tone Analyzer to analyze the user's text input and voice data and recognize emotions. The notification content is adjusted based on the recognized emotion. For example, if the user is feeling stressed, the tone of the notification can be softened and additional explanations can be added. The emotion engine allows the server to select the optimal notification method according to the user's emotional state. For example, if the situation is urgent, an immediate notification can be sent, and if the situation is normal, information can be provided periodically.

[0659] Example prompt sentence:

[0660] "Please obtain information on the latest cyber attacks of other companies and classify the scope of impact and the cause of the attacks. Then, based on this information, please compile a report comparing the results with your own company's security posture."

[0661] "Generate reports that identify vulnerabilities in your security measures and suggest countermeasures accordingly. Tailor notifications based on the user's stress level."

[0662] This system not only suggests effective security measures based on incidents at other companies, but also provides appropriate notifications taking into account the user's emotional state, allowing users to receive information at the appropriate time and in the appropriate way.

[0663] The flow of the identification process in the second embodiment will be described with reference to FIG.

[0664] Step 1:

[0665] Collecting information on cyber attacks and information leaks at other companies

[0666] The server accesses information sources such as security news APIs to obtain data on cyber attacks and information leaks.

[0667] Input: Take the URL of a security news or industry report as input via an API request or other method.

[0668] Data processing: Analyze data such as JSON format obtained via API requests and extract necessary information (e.g., type of attack, date and time of occurrence, scope of impact).

[0669] Output: The extracted data is organized and stored in a database.

[0670] Specifically, a scheduled job is set up for periodic access, and the necessary information is filtered using a naive Bayesian classifier or similar.

[0671] Step 2:

[0672] Information analysis and classification

[0673] The server analyzes the collected data using natural language processing technology and extracts important elements.

[0674] Input: Collected data (e.g., type of attack, scope of impact, cause)

[0675] Data processing: Use a natural language processing library (e.g., NLTK, spaCy) to extract important elements from the text data and run them through a classification algorithm.

[0676] Output: The analyzed data is categorized by attributes such as "type of attack," "industry," and "scale of damage," and stored in a database.

[0677] Specifically, it tokenizes text data, performs partial analysis (noun phrase extraction), and classifies the data by category. For example, it classifies information about phishing attacks into "phishing attacks," "financial industry," and "medium damage scale."

[0678] Step 3:

[0679] Verification of in-house management system

[0680] The server retrieves the company's security management system information from the database and compares it with other companies' case information.

[0681] Input: Your company's security settings information (firewall settings, access control policies, etc.) and other companies' case information

[0682] Data calculation: A matching algorithm identifies gaps between your company's security settings and those of other companies.

[0683] Output: Gap analysis results are obtained and your company's vulnerabilities are identified.

[0684] Specifically, it sets certain thresholds and performs filtering to determine whether or not a match occurs based on those criteria. For example, the server identifies that its phishing protection is out of date.

[0685] Step 4:

[0686] Risk Assessment

[0687] The server performs a risk assessment based on its own vulnerabilities and calculates a risk score.

[0688] Input: Gap analysis results, threat type, impact

[0689] Data computation: Using machine learning models to calculate risk scores and quantify the likelihood and impact of risks.

[0690] Output: Risk scores are obtained and countermeasures are prioritized.

[0691] Specifically, the server adds up the scores for each risk factor and performs a comprehensive risk assessment. For example, the server may assess the risk score for phishing protection as "high."

[0692] Step 5:

[0693] Proposal of measures

[0694] The server uses a generative AI model to propose specific countermeasures.

[0695] Input: Risk assessment results, risk score

[0696] Data processing: Generate countermeasures using a generative AI model and create specific proposals.

[0697] Output: Countermeasure proposals are obtained and stored in a database.

[0698] Specifically, the system uses the proposal generation and feedback functions to automatically generate optimal countermeasures, such as suggesting "the introduction of the latest email filtering software" or "implementing phishing training for employees."

[0699] Step 6:

[0700] Notifications and Reporting

[0701] The server notifies the user of the evaluation results and recommendations and creates a detailed report.

[0702] Input: Risk assessment results, proposed countermeasures

[0703] Data Processing: Notification and reporting algorithms shape the data and provide information to the user.

[0704] Output: Reports are generated and displayed on the user's admin screen. Important information is also sent via email.

[0705] Specifically, it generates a report using an HTML or PDF generation library and sends an email to the user using SMTP.

[0706] Step 7:

[0707] Using the Emotion Engine

[0708] The server acquires the user's emotional data and analyzes it using an emotion engine.

[0709] Input: User text input and voice data

[0710] Data calculation: Analyze using an emotion analysis engine (e.g., IBM Watson Tone Analyzer) to recognize the emotional state.

[0711] Output: The sentiment analysis results are used to adjust the tone and manner of the notification.

[0712] Specifically, it uses text mining and voice analysis technology to identify the user's emotions and optimizes the notification method. For example, if the user is feeling stressed, it softens the tone of the notification and adds additional explanation. Depending on the user's condition, it responds immediately in emergencies and sends regular notifications under normal circumstances.

[0713] In this way, the entire system achieves effective security measures based on examples from other companies and appropriate notifications that take into account the user's emotional state.

[0714] (Application example 2)

[0715] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."

[0716] Current security systems are capable of collecting and analyzing information on cyberattacks from other companies, but the process of incorporating that information into one's own security system is not automated, making it difficult to respond quickly and effectively. Furthermore, there is no notification method that takes into account the user's emotional state, making it difficult to deliver appropriate content or notifications according to the situation. As a result, users may feel stressed or miss important notifications.

[0717] The identification process by the identification processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means. In this invention, the server includes means for collecting information on cyber attacks and information leakage cases by other companies, means for analyzing and classifying the collected information on cyber attacks and information leakage cases by other companies, and means for adjusting the notification content using an emotion engine that recognizes the user's emotions. This makes it possible to quickly reflect the collected information on cyber attacks by other companies in one's own security system and also enables appropriate notifications to be provided according to the user's emotional state.

[0718] "Cyber ​​attacks and information leaks at other companies" refers to specific incidents and examples of cyber attacks and information leaks that have occurred at other companies or organizations.

[0719] "Means of collection" refers to the methods and technologies that allow a server to automatically obtain data on other companies' cyber attacks and information leaks from the Internet or specific sources.

[0720] "Means of analysis and classification" refers to methods and technologies for analyzing information acquired by a server using natural language processing technology, etc., and classifying cyber attacks and information leaks based on their type, scope of impact, etc.

[0721] "Your company's security management system" refers to the entire security policies, settings, measures, etc. that your company or organization has.

[0722] "Means of comparison" refers to methods and technologies for comparing information on cyber attacks and information leaks at other companies with one's own security management system to identify the possibility that one's company may be exposed to similar threats or vulnerabilities.

[0723] "Risk assessment" refers to the process of assessing the risk to a company if it is exposed to the same threats as other companies, based on the likelihood and impact of the threat.

[0724] "Means for proposing countermeasures" refers to methods and technologies by which the server provides specific countermeasures to strengthen the company's security based on the results of risk assessment.

[0725] "Means of notifying users" refers to methods and technologies for communicating the contents of risk assessments and proposed countermeasures to users.

[0726] "Emotion engine" refers to technology that analyzes a user's text input and voice data to recognize the user's emotional state.

[0727] "Means for tailoring notification content" refers to methods and techniques for optimizing the tone and content of notifications based on perceived user sentiment.

[0728] To implement the present invention, the following system configuration and program processing must be executed.

[0729] This system runs on a server and automatically collects and analyzes information on cyber attacks and information leaks from other companies, compares it with the company's own security management system, assesses the risks, proposes countermeasures, and notifies users.It also incorporates an emotion engine that recognizes the user's emotional state, allowing it to adjust the content of notifications according to their emotions.

[0730] Specifically, the server operates as follows.

[0731] Data collection:

[0732] The server collects data on cyber attacks and information leaks by other companies from the internet and specific sources (such as security news sites and industry association reports). This collection process uses external services such as the "Security News API." The information obtained by the server includes the date and time of the incident, the type of attack, the scope of impact, and the cause.

[0733] Information analysis and classification:

[0734] Using natural language processing technology (such as Google Cloud Natural Language API), the information collected by the server is analyzed, and key elements of cyber attacks and data breaches are extracted and classified. The classification process involves tagging the incidents based on their type and scope of impact.

[0735] Checking our management system:

[0736] The server retrieves information about the company's security management system from the database and compares it with incident information collected from other companies. This comparison evaluates whether the company is vulnerable to similar threats. For example, if the company's phishing protection is out of date, this will be identified as a vulnerability.

[0737] Risk Assessment:

[0738] The server performs a risk assessment based on the matching results. The risk assessment calculates a risk score based on the likelihood and impact of the threat. This risk score determines the priority of countermeasures.

[0739] Suggested solutions:

[0740] Based on the results of the risk assessment, the server will propose specific countermeasures, including technical measures (e.g., updating anti-ransomware software and strengthening firewall settings), policy changes (e.g., reviewing access control and implementing data encryption), and employee education (implementing security training).

[0741] Emotion Engine:

[0742] The server obtains the user's emotional data using the Google Cloud Speech-to-Text API and analyzes the user's emotions using an emotion engine. Based on the analysis results, the content of the notification is adjusted. For example, if the user is feeling stressed, the tone of the notification may be softened or additional explanations may be added.

[0743] notification:

[0744] The server notifies the user of the evaluation results and proposed measures. The content of the notification is adjusted by the emotion engine. For example, if the issue is highly urgent, an immediate notification will be sent.

[0745] Examples:

[0746] If the user is in a normal emotional state, the server sends a notification suggesting "installation of the latest email filtering software."

[0747] If the user is in a high-stress state, soften the notification and say, "Start with some simple steps to improve your security."

[0748] Example prompt sentence:

[0749] "I would like to implement a system that collects information on the latest cyber attacks that have occurred at other companies and uses that information to evaluate my own company's security posture. In the process, I would also like to add a function that adjusts the content of notifications based on the user's emotions. I would like advice on how to soften the content of notifications when a user is under high stress."

[0750] By operating in this way, the system suggests effective security measures based on cases at other companies and provides appropriate notifications based on the user's emotional state, allowing the user to receive information at the appropriate time and in the appropriate way.

[0751] The flow of the specific processing in the application example 2 will be described with reference to FIG.

[0752] Step 1:

[0753] The server collects data on cyber attacks and information leaks by other companies from the internet or specific information sources. Specifically, it obtains the latest cyber attack information using a security news API, etc. The input in this case is an API request, and the output is JSON data containing cyber attack information.

[0754] Step 2:

[0755] The cyber attack information collected by the server is analyzed using natural language processing technology. Specifically, the Google Cloud Natural Language API is used to extract important elements from the text data (type of attack, scope of impact, cause, etc.). In this case, the input is the JSON data obtained in step 1, and the output is a list of the analyzed elements.

[0756] Step 3:

[0757] The server classifies the analyzed cyber attack information. Specifically, it sets categories based on the type of attack, the scope of impact, the scale of damage, etc., and classifies the information. In this case, the input is the list of elements extracted in step 2, and the output is a list of classified incidents.

[0758] Step 4:

[0759] The server retrieves information about the company's security controls from a database, specifically data such as firewall settings, access control policies, and employee security training status. The input in this case is a database query, and the output is a list of security control information.

[0760] Step 5:

[0761] The server compares the cyber attack information collected from other companies with the company's own security management system. Specifically, it checks for vulnerabilities in phishing countermeasures, email filtering, employee training, etc. The input in this case is the list of incidents from Step 3 and the list of management system information from Step 4, and the output is a list of vulnerabilities.

[0762] Step 6:

[0763] The server performs a risk assessment based on the company's vulnerability list. Specifically, it calculates a risk score based on the type of threat and gaps in the company's management system. In this case, the input is the vulnerability list from step 5, and the output is the risk assessment results and risk score.

[0764] Step 7:

[0765] The server proposes specific countermeasures based on the results of the risk assessment, such as introducing the latest email filtering software and conducting phishing training for employees. The input in this case is the risk assessment result and risk score from Step 6, and the output is a list of countermeasure proposals.

[0766] Step 8:

[0767] The server acquires the user's emotional data. Specifically, it uses the Google Cloud Speech-to-Text API or similar to acquire the user's voice commands and text input, which are then analyzed by the emotion engine. In this case, the input is the user's voice and text data, and the output is the recognized emotional data.

[0768] Step 9:

[0769] The server adjusts the notification content based on the emotion engine. Specifically, it changes the tone and content of the notification according to the user's emotional state. In this case, the input is the emotion data from step 8 and the countermeasure proposal list from step 7, and the output is the adjusted notification content.

[0770] Step 10:

[0771] The server notifies the user of the evaluation results and proposed countermeasures. Specifically, if the situation is urgent, the server notifies immediately, and if it is normal, the server notifies periodically. In this case, the input is the notification content from step 9, and the output is a notification message to the user.

[0772] The specific processing unit 290 transmits the result of the specific processing to the smart glasses 214. In the smart glasses 214, the control unit 46A causes the speaker 240 to output the result of the specific processing. The microphone 238 acquires audio indicating a user input regarding the result of the specific processing. The control unit 46A transmits audio data indicating the user input acquired by the microphone 238 to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.

[0773] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[0774] In the above embodiment, an example in which the specific processing is performed by the data processing device 12 has been given, but the technology of the present disclosure is not limited to this, and the specific processing may be performed by the smart glasses 214.

[0775] [Third embodiment]

[0776] FIG. 5 shows an example of the configuration of a data processing system 310 according to the third embodiment.

[0777] 5, the data processing system 310 includes the data processing device 12 and a headset terminal 314. An example of the data processing device 12 is a server.

[0778] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[0779] The headset type terminal 314 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication I / F 44, and a display 343. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The microphone 238, the speaker 240, the camera 42, and the display 343 are also connected to the bus 52.

[0780] The microphone 238 receives instructions and the like from the user 20 by receiving voice uttered by the user 20. The microphone 238 captures the voice uttered by the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio in accordance with instructions from the processor 46.

[0781] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the surroundings of user 20 (for example, an imaging range defined by an angle of view equivalent to the field of vision of a typical healthy person).

[0782] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 control the exchange of various information between the processor 46 and the processor 28 via the network 54. The exchange of various information between the processor 46 and the processor 28 using the communication I / Fs 44 and 26 is carried out in a secure state.

[0783] Fig. 6 shows an example of the main functions of the data processing device 12 and the headset type terminal 314. As shown in Fig. 6, in the data processing device 12, a specific process is performed by the processor 28. A specific process program 56 is stored in the storage 32.

[0784] The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[0785] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[0786] In the headset type terminal 314, a reception output process is performed by the processor 46. A reception output program 60 is stored in the storage 50. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.

[0787] Next, a description will be given of the identification process performed by the identification processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as the "server" and the headset type terminal 314 will be referred to as the "terminal."

[0788] This invention is a system that collects cyber attacks and information leaks that have occurred at other companies, analyzes them, compares them with the company's own security management system, and automatically performs everything from risk assessment to proposing countermeasures. Below, we will explain the processing content of this system's program in natural language, and also provide specific examples.

[0789] Program processing flow

[0790] 1. Collecting information on cyber attacks and information leaks at other companies

[0791] The server automatically collects data on cyber attacks and information leaks by other companies from the Internet and specific sources (security news sites, industry association reports, etc.).

[0792] The collected information includes the date and time of the incident, the type of attack, the scope of impact, and the cause.

[0793] For example, the server obtains information from the "Security News API" that "a certain financial institution was attacked by a phishing attack and customer data was leaked."

[0794] 2. Information analysis and classification

[0795] The server analyzes the acquired information using natural language processing technology, which extracts important elements of cyber attacks and data breaches (such as the type of attack, the scope of impact, and the cause).

[0796] Based on the analysis results, classification is made according to the type of incident and the scope of impact.

[0797] For example, the server classifies the information about phishing attacks it collects as "phishing attacks," "financial industry," and "medium damage scale."

[0798] 3. Checking your company's management system

[0799] The server retrieves information about your company's security controls from a database, including firewall settings, access control policies, and employee security training status.

[0800] The server compares the incident information collected from other companies with the company's own security management system to determine whether the company is vulnerable to similar threats.

[0801] For example, the server checks to see if its phishing protection (email filtering, employee training, etc.) is out of date.

[0802] 4. Risk Assessment

[0803] The server uses the results of the comparison to assess the risk to its company if it were to be exposed to a similar threat. The risk assessment is based on the likelihood and impact of the threat.

[0804] A risk score is calculated and countermeasures are prioritized based on this.

[0805] For example, the server may check for deficiencies in its own phishing prevention measures and rate the risk score as "high."

[0806] 5. Proposal of countermeasures

[0807] The server proposes specific countermeasures based on the results of the risk assessment.

[0808] These suggestions may include technical measures (e.g., updating anti-ransomware software, strengthening firewall rules), policy changes (e.g., reviewing access controls, implementing data encryption), and employee education (e.g., conducting security training).

[0809] For example, the server might suggest "introducing the latest email filtering software" or "conducting phishing training for employees."

[0810] 6. Notification and Reporting

[0811] The server notifies the user (security officer) of the evaluation results and recommendations.

[0812] The server generates a detailed report of the risk assessment and recommendations, which are displayed on the user's management screen.

[0813] If necessary, you can also receive immediate notification of important information via email or alerts.

[0814] For example, the server compiles these risk assessments and recommendations into a report, displays it on the user's management screen, and notifies them by email.

[0815] In this way, the system can effectively leverage cyber attacks and data breaches by other companies to continuously strengthen its own security posture.

[0816] The processing flow will be explained below.

[0817] Step 1:

[0818] The server periodically collects data on cyber attacks and information breaches by other companies from reliable sources (e.g., security news sites and industry reports). The server accesses these sources using APIs or web scraping technology to obtain the latest incident information and stores it in a database.

[0819] Step 2:

[0820] The server analyzes the collected data using natural language processing (NLP) technology, extracting necessary information from the text data (such as the date and time of the incident, the type of attack, the scope of impact, and the cause) and structuring this data.

[0821] Step 3:

[0822] The server classifies the incidents based on the analysis results. The information collected by the server is classified into the type of attack (e.g., ransomware, phishing, internal information leaks, etc.), industry (e.g., finance, healthcare, education, etc.), and scale of damage (e.g., large, medium, small).

[0823] Step 4:

[0824] The server retrieves information about the company's security posture from a database, including firewall settings, access control policies, vulnerability scan results, and employee security training status.

[0825] Step 5:

[0826] The server compares the incident information of other companies with the company's management system. The server performs the comparison process, identifies commonalities and differences between the company's security management system and those of other companies, and identifies vulnerabilities and areas for improvement.

[0827] Step 6:

[0828] The server performs a risk assessment based on the matching results. The server calculates a risk score based on the type of threat and gaps in the company's management system. The risk score is calculated taking into account the likelihood and impact of the threat.

[0829] Step 7:

[0830] The server proposes specific countermeasures based on the results of the risk assessment, including technical measures (e.g., updating anti-ransomware software, strengthening firewall settings), policy changes (e.g., reviewing access control, implementing data encryption), and employee education (e.g., implementing security training).

[0831] Step 8:

[0832] The server notifies the user of the risk assessment and proposed countermeasures. The server generates a detailed report and displays it on the user's management screen. The server also notifies the user immediately of important information via email or alerts.

[0833] Through the above process, a system will be created in which the server utilizes the cases of other companies to continuously strengthen its own security management system.

[0834] Example 1

[0835] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."

[0836] Conventional security systems often do not collect data on cyber attacks or information leaks from other companies, making it difficult to link this data to improvements in one's own security management system. Manually investigating other companies' incidents and reviewing one's own countermeasures takes time and effort, making it difficult to maintain and improve the security level of the entire company. Furthermore, if the risk assessment and countermeasure proposal processes are not systematized, they depend on the knowledge and experience of the individual in charge, making it difficult to implement uniform security measures.

[0837] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.

[0838] In this invention, the server includes: means for automatically collecting information on cyber attacks and information leak incidents by other companies from the Internet or specific information sources; means for preprocessing the collected information on cyber attacks and information leak incidents by other companies using natural language processing technology to extract and classify important elements; means for obtaining information on the company's own security management system from a database and comparing it with the collected information to identify vulnerabilities; means for calculating a risk score based on the comparison result and conducting a risk assessment; means for proposing specific countermeasures such as technical measures, policy changes, and employee training based on the result of the risk assessment; and means for notifying the user of the risk assessment and the proposed countermeasures and displaying them in a detailed report format on the user's management screen. This enables the company to automatically evaluate and improve its own security management system based on the incidents of other companies, thereby efficiently and effectively maintaining and improving its security level.

[0839] A "cyber attack" is a malicious attack on a computer system or network via the Internet.

[0840] "Information leakage" refers to the phenomenon or act of confidential information or personal information leaking to the outside without permission.

[0841] "Natural language processing technology" is a technology that enables computers to understand and process human language.

[0842] A "database" is a system or software for efficiently managing, searching, and updating large amounts of data.

[0843] A "vulnerability" is a weakness in a computer system or network that makes it susceptible to external attacks.

[0844] "Risk assessment" is the process of assessing the extent of damage or impact if a particular threat occurs.

[0845] A "risk score" is a numerical representation of the result of a risk assessment, indicating the severity of a threat and the probability of it occurring.

[0846] "Countermeasure proposals" are proposals on what measures or actions should be taken to address a specific risk.

[0847] "Technical measures" are means of responding to threats using software or hardware.

[0848] "Policy change" means reviewing and revising rules and guidelines within an organization.

[0849] "Employee training" is the training and education of an organization's employees to acquire specific knowledge and skills.

[0850] "Users" refer to the security personnel and operations managers who use this system.

[0851] A "report format" is a document format for organizing information and data and presenting them in a visually easy-to-understand manner.

[0852] The "management screen" is an interface for operating and configuring the system.

[0853] This invention is a system that collects cyber attacks and information leaks that have occurred at other companies, analyzes them, compares them with the company's own security management system, and automatically performs risk assessments and proposes countermeasures. This system is implemented with the involvement of servers, terminals, and users.

[0854] server

[0855] The server is responsible for automatically collecting data on cyber attacks and information leaks by other companies from the internet and specific sources (e.g., security news sites and industry association reports). Specifically, the server connects to the "Security News API" and retrieves data by sending a REST API request. This data includes information such as the date and time of the incident, the type of attack, the scope of impact, and the cause. The collected data is stored in a database (e.g., MySQL or PostgreSQL).

[0856] The server analyzes the collected information using natural language processing technology (for example, SpaCy or the NLTK library). Specifically, it tokenizes the text data, removes unnecessary words, and extracts important elements such as the type of attack and the scope of impact. The extracted information is then classified by category. For example, data is classified as "phishing attack," "financial industry," and "medium damage scale."

[0857] In addition, the server retrieves information about the company's security management system from the database and compares it with collected incident information from other companies to determine whether the company is vulnerable to similar threats. The company's security management information includes firewall settings, access control policies, employee security training status, etc. For example, the server may determine that the company's email filtering is out of date.

[0858] Terminal

[0859] The terminal provides an interface for users to interact with the system. It notifies users of the assessment results and proposed countermeasures generated by the server and displays a management screen that allows users to take appropriate action. Specifically, the terminal displays risk assessments and proposed countermeasures in a detailed report format, and notifies users immediately of important information via email or alerts as needed.

[0860] User

[0861] Users are primarily security personnel who check the evaluation results and countermeasure proposals provided by the server on the management screen and direct the implementation of actual security measures. For example, they receive proposals such as "introducing the latest email filtering software" or "training employees on phishing" and take specific actions to implement them.

[0862] Here are some examples of prompts to input to a generative AI model:

[0863] "Please collect recent phishing attack cases in the financial industry, compare them with your company's phishing countermeasures, conduct a risk assessment, and propose specific countermeasures."

[0864] This system allows companies to automatically evaluate and improve their own security management systems based on the cases of other companies, enabling them to efficiently and effectively maintain and improve their security levels.

[0865] The flow of the identification process in the first embodiment will be described with reference to FIG.

[0866] Step 1:

[0867] The server connects to the Internet and automatically collects data on cyber attacks and information leaks by other companies from specific sources (such as security news sites and industry association reports). The input is the endpoint URL of the security news API, and the output is incident data in JSON format. The server sends REST API requests and receives responses.

[0868] Step 2:

[0869] The server formats the data it receives and converts it into the required format. It then stores it in a database (for example, MySQL or PostgreSQL). The input is the collected JSON-formatted data, and the output is a formatted database record. The server extracts and stores information such as the date and time of the incident, the type of attack, the scope of impact, and the cause.

[0870] Step 3:

[0871] The server analyzes the collected information using natural language processing technology (for example, SpaCy or NLTK library). The input is the text data stored in the database, and the output is the analyzed important elements (type of attack, scope of impact, cause, etc.). The server divides the text data into tokens, removes unnecessary words, and extracts important elements.

[0872] Step 4:

[0873] Based on the analysis results, the server categorizes cyber attacks and information leaks. The input is the analyzed data, and the output is data organized by category. For example, the server might categorize the data as "phishing attacks," "financial industry," or "medium damage scale."

[0874] Step 5:

[0875] The server retrieves information about the company's security management system from a database. The input is a database query containing information about the company's security system, and the output is the retrieved management information. For example, the server retrieves firewall settings, access control policies, and employee security training status.

[0876] Step 6:

[0877] The server compares the incident information collected by other companies with the company's security management system to identify vulnerabilities. The input is the incident information of other companies and the company's management information, and the output is the identified vulnerabilities. The server performs specific comparisons, such as checking to see if the company's email filtering is out of date.

[0878] Step 7:

[0879] The server evaluates the risk of the company based on the matching result. The input is the matching result, and the output is a risk score. The server runs a risk evaluation algorithm and evaluates the risk score of a phishing attack as "high," for example.

[0880] Step 8:

[0881] The server proposes specific countermeasures based on the risk assessment results. The input is the risk assessment results, and the output is the proposed countermeasures. The server proposes technical countermeasures (e.g., installing the latest email filtering software), policy changes (e.g., reviewing access control), and employee training (e.g., conducting phishing drills).

[0882] Step 9:

[0883] The server notifies the user of the risk assessment and proposed countermeasures. The input is the proposed countermeasures, and the output is a notification and a detailed report. The server compiles the assessment results and proposed countermeasures and displays them on the management screen, and notifies users of important information via email or alerts as needed.

[0884] In this way, servers, terminals, and users work together to run the system and effectively evaluate and improve their company's security management system.

[0885] (Application example 1)

[0886] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."

[0887] Currently, it is difficult to effectively collect information on cyber attacks and data leaks that have occurred at other companies and reflect it in one's own security management system. Furthermore, risk assessments and countermeasure proposals based on this information are performed manually, which lack real-time performance and often results in delayed countermeasures. Furthermore, there is a need for more advanced analysis using the latest AI technology.

[0888] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.

[0889] In this invention, the server

[0890] A means of collecting information on cyber attacks and information leaks at other companies,

[0891] A means of analyzing and classifying collected cyber attacks and information leaks from other companies,

[0892] A means of verifying the collected information against your company's security management system, and

[0893] a means for performing a risk assessment based on the matching results;

[0894] A means of proposing countermeasures based on the results of the risk assessment;

[0895] means for notifying a user of the content of the risk assessment and the proposed measures;

[0896] A method to extract the type, scope, and cause of an attack using a generative AI model based on cyber attacks and data breaches by other companies;

[0897] means for providing the extracted information to a user as a prompt sentence;

[0898] This will enable the company to efficiently collect and analyze cyber attacks and information leaks by other companies, and strengthen its own security measures in real time.

[0899] "Cyber ​​attacks and information leaks at other companies" refers to incidents involving unauthorized access or data acquisition that other organizations or companies have experienced.

[0900] "Collection methods" refer to methods and technologies that automatically obtain data from the Internet or specific sources.

[0901] "Means of analysis and classification" refers to techniques and methods for analyzing collected data and categorizing it based on its characteristics.

[0902] "Our company's security management system" refers to the organizational policies and measures for protecting our company's information and systems.

[0903] "Means of comparison" refers to the technology or method for comparing other companies' case information with your own security settings and policies.

[0904] "Risk assessment methods" refer to methods and techniques used to assess a company's vulnerability to similar threats and their impact.

[0905] "Means for proposing countermeasures" refers to techniques and methods for proposing specific security measures based on the results of risk assessment.

[0906] "Means of notification" refers to the technology or method for notifying users of the evaluation results and proposals, including email and push notifications.

[0907] "Methods for extracting attack types, scope of impact, and causes using generative AI models" refers to methods that utilize AI technology to automatically identify and extract specific elements from collected data.

[0908] "Means for providing the extracted information to the user as a prompt" refers to a technique or method for providing the user with instructions or suggestions generated based on the analysis results.

[0909] This invention is a system that collects information on cyber attacks and information leaks from other companies, analyzes it, compares it with the company's own security management system, and automatically performs risk assessments and proposes countermeasures. This system consists of the following main components.

[0910] 1. Collecting information on cyber attacks and information leaks at other companies

[0911] The server automatically collects information about cyber attacks and data breaches by other companies from the internet and specific sources. This information is collected using Python and scraping libraries (BeautifulSoup, Scrapy). The collected information includes the date and time of the incident, the type of attack, the scope of impact, and the cause.

[0912] 2. Information analysis and classification

[0913] The server uses natural language processing technology to analyze the collected information and extract key elements of cyber attacks and data breaches (e.g., type of attack, scope of impact, cause, etc.). The specific technology used is the Transformers library (BERT model, etc.).

[0914] 3. Comparison with the company's management system

[0915] The server retrieves information about the company's security management system from a database (MySQL) and compares it with incident information from other companies to determine whether the company is vulnerable to similar threats. Specific information includes firewall settings, access control policies, and employee security training status.

[0916] 4. Risk Assessment

[0917] Based on the matching results, the server assesses the risk to the company if it were exposed to a similar threat. The risk assessment is based on the likelihood and impact of the threat, and a risk score is calculated.

[0918] 5. Proposal of countermeasures

[0919] Based on the results of the risk assessment, the server will propose specific countermeasures, including technical measures (e.g., updating anti-ransomware software, strengthening firewall rules), policy changes (e.g., reviewing access control, implementing data encryption), and employee education (e.g., security training).

[0920] 6. Notification and Reporting

[0921] The server notifies the user of the evaluation results and recommendations. Notification methods include email, alerts, and push notifications (FCM (Firebase Cloud Messaging)). In addition, the evaluation results and recommendations are displayed in a detailed report format on the user's management screen.

[0922] As a concrete example, if a financial institution were to be hit by a phishing attack and customer data were to be leaked, the server would use natural language processing technology to extract from this information the type of attack, the extent of its impact, and the cause. Based on this information, the server would compare the company's phishing countermeasures, conduct a risk assessment, and propose specific countermeasures (for example, the introduction of the latest email filtering software or phishing training for employees).

[0923] Example prompt sentence:

[0924] Analyze a news article stating that "A certain financial institution was subjected to a phishing attack and customer data was leaked," and extract the type of attack, the scope of its impact, and the cause.

[0925] In this way, the system can effectively leverage cyber attacks and data breaches by other companies to continuously strengthen its own security posture.

[0926] The flow of the specific processing in the application example 1 will be described with reference to FIG.

[0927] Step 1:

[0928] Collecting information on cyber attacks and information leaks at other companies

[0929] The server automatically collects information about cyber attacks and data breaches by other companies from the internet and specific sources (news sites and industry association reports). Specifically, it uses Python and scraping libraries (BeautifulSoup, Scrapy) to obtain data such as the date and time of the incident, the type of attack, the scope of impact, and the cause. A URL or API endpoint is given as input, and a list of incident information is generated as output.

[0930] Step 2:

[0931] Information analysis and classification

[0932] The server analyzes the collected information using natural language processing technology. Specifically, it uses the Transformers library (such as the BERT model) to extract key elements of cyber attacks and data breaches (such as the type of attack, the scope of impact, and the cause). The collected raw data is given as input, and the extracted and analyzed data is output. This analysis classifies the type of incident and the scope of impact.

[0933] Step 3:

[0934] Verification with our company's management system

[0935] The server retrieves information about the company's security management system (firewalls, access control policies, employee security training status, etc.) from a database (MySQL). It then compares this information with the collected and analyzed incident information of other companies to determine whether the company is vulnerable to similar threats. The input is the analysis data of other companies and the company's management system information, and the output is the comparison result.

[0936] Step 4:

[0937] Risk Assessment

[0938] The server evaluates the risk of the company being exposed to a similar threat based on the matching results. This risk assessment is based on the likelihood and impact of the threat, and a risk score is calculated. The matching results are given as input, and a numerical risk score is obtained as output.

[0939] Step 5:

[0940] Countermeasure proposals

[0941] The server then proposes specific countermeasures based on the results of the risk assessment, including technical measures (e.g., updating anti-ransomware software, strengthening firewalls), policy changes, employee training, etc. The server receives a risk score as input and generates a proposal as output.

[0942] Step 6:

[0943] Notifications and Reporting

[0944] The server notifies the user of the evaluation results and recommendations via email or push notification (FCM (Firebase Cloud Messaging)). A detailed report is also generated to be displayed on the admin panel. The recommendation data is given as input, and the notification sent to the user and the report for display are obtained as output.

[0945] Step 7:

[0946] Prompt generation and provision of information

[0947] The server uses a generative AI model based on cyber attacks and data breaches by other companies to extract the type of attack, the scope of impact, and the cause. This information is then presented to the user as a prompt. For example, the following prompt:

[0948] Analyze a news article stating that "A certain financial institution was subjected to a phishing attack and customer data was leaked," and extract the type of attack, the scope of its impact, and the cause.

[0949] The input is the analysis data, and the output is the generated prompt sentence.

[0950] Furthermore, an emotion engine that estimates the user's emotion may be further combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59, and perform identification processing using the user's emotion.

[0951] This invention combines a system that collects cyber-attacks and information leaks that have occurred at other companies, analyzes them, compares them with the company's own security management system, and automatically performs everything from risk assessment to proposing countermeasures, with an emotion engine that recognizes the user's emotions. Below, we will explain the processing content of this system's program in natural language, and also provide specific examples.

[0952] Program processing flow

[0953] 1. Collecting information on cyber attacks and information leaks at other companies

[0954] The server automatically collects data on cyber attacks and information leaks by other companies from the Internet and specific sources (security news sites, industry association reports, etc.).

[0955] The collected information includes the date and time of the incident, the type of attack, the scope of impact, and the cause.

[0956] For example, the server obtains information from the "Security News API" that "a certain financial institution was attacked by a phishing attack and customer data was leaked."

[0957] 2. Information analysis and classification

[0958] The server analyzes the acquired information using natural language processing technology, which extracts important elements of cyber attacks and data breaches (such as the type of attack, the scope of impact, and the cause).

[0959] Based on the analysis results, classification is made according to the type of incident and the scope of impact.

[0960] For example, the server classifies the information about phishing attacks it collects as "phishing attacks," "financial industry," and "medium damage scale."

[0961] 3. Checking your company's management system

[0962] The server retrieves information about your company's security controls from a database, including firewall settings, access control policies, and employee security training status.

[0963] The server compares the incident information collected from other companies with the company's own security management system to determine whether the company is vulnerable to similar threats.

[0964] For example, the server checks to see if its phishing protection (email filtering, employee training, etc.) is out of date.

[0965] 4. Risk Assessment

[0966] The server uses the results of the comparison to assess the risk to its company if it were to be exposed to a similar threat. The risk assessment is based on the likelihood and impact of the threat.

[0967] A risk score is calculated and countermeasures are prioritized based on this.

[0968] For example, the server may check for deficiencies in its own phishing prevention measures and rate the risk score as "high."

[0969] 5. Proposal of countermeasures

[0970] The server proposes specific countermeasures based on the results of the risk assessment.

[0971] These suggestions include technical measures (e.g., updating anti-ransomware software, strengthening firewall settings), policy changes (e.g., reviewing access controls, implementing data encryption), and employee education (e.g., conducting security training).

[0972] For example, the server might suggest "introducing the latest email filtering software" or "conducting phishing training for employees."

[0973] 6. Notification and Reporting

[0974] The server notifies the user (security officer) of the evaluation results and recommendations.

[0975] The server generates detailed reports that are displayed on the user's management screen, and notifies users immediately of important information via email or alerts.

[0976] For example, the server compiles these risk assessments and recommendations into a report, displays it on the user's management screen, and notifies them by email.

[0977] 7. Use of Emotion Engine

[0978] The server acquires the user's emotion data and analyzes the user's emotion. The emotion engine analyzes the user's text input and voice data to recognize the emotion.

[0979] The server can then tailor the notification content based on the perceived emotion, for example softening the tone of the notification or adding additional explanation if the user is feeling stressed.

[0980] The emotion engine allows the server to select the optimal notification method based on the user's emotional state. For example, if the situation is urgent, the server will provide immediate notification, and if the situation is normal, the server will provide information periodically.

[0981] This system not only suggests effective security measures based on incidents at other companies, but also provides appropriate notifications taking into account the user's emotional state, allowing users to receive information at the appropriate time and in the appropriate way.

[0982] The processing flow will be explained below.

[0983] Step 1:

[0984] The server periodically collects data on cyber attacks and information breaches by other companies from reliable sources (e.g., security news sites and industry reports). The server accesses these sources using APIs or web scraping technology, automatically obtains the latest incident information, and stores it in a database.

[0985] Step 2:

[0986] The server analyzes the collected data using natural language processing (NLP) technology. The server extracts necessary information from the text data (such as the date and time of the incident, the type of attack, the scope of impact, and the cause) and structures this data. For example, the server classifies phishing attack data as "phishing attack," "financial industry," and "medium damage scale."

[0987] Step 3:

[0988] The server retrieves information about your company's security management system from a database, including firewall settings, access control policies, employee security training status, etc. The server periodically updates the data to keep this information up to date.

[0989] Step 4:

[0990] The server compares the incident information collected from other companies with the company's management system. The server performs the comparison process, identifies similarities and differences between the company's security management system and those of other companies, and identifies vulnerabilities and areas for improvement. For example, it checks whether the company's phishing countermeasures are out of date.

[0991] Step 5:

[0992] The server performs a risk assessment based on the matching results. The server calculates a risk score based on the type of threat and gaps in the company's management system. This risk score is calculated taking into account the likelihood and impact of the threat. For example, the server may check for deficiencies in the company's phishing countermeasures and assess the risk score as "high."

[0993] Step 6:

[0994] The server proposes specific countermeasures based on the results of the risk assessment. These countermeasures include technical measures (e.g., updating anti-ransomware software, strengthening firewall settings), policy changes (e.g., reviewing access control, implementing data encryption), and employee education (e.g., implementing security training). For example, the server suggests "introducing the latest email filtering software" and "implementing phishing training for employees."

[0995] Step 7:

[0996] The server notifies the user of the assessment results and proposed countermeasures. The server generates a detailed report and displays it on the user's management screen. Important information is also immediately notified to the user via email or alerts. For example, the server compiles these risk assessments and proposals into a report, displays it on the user's management screen, and notifies the user by email.

[0997] Step 8:

[0998] The server acquires the user's emotional data and analyzes the user's emotions. The emotion engine analyzes the user's text input and voice data to recognize emotions. For example, the device collects the user's voice input, and the emotion engine analyzes it to detect "stress."

[0999] Step 9:

[1000] The server adjusts the content of notifications based on the recognized emotion. For example, if the user is feeling stressed, the notification tone may be softened or additional explanations may be added to make the information easier for the user to receive.

[1001] Step 10:

[1002] The emotion engine allows the server to select the optimal notification method based on the user's emotional state. For example, if the information is urgent, the server will provide immediate notification, and if it is normal, the server will provide periodic information, thereby conveying information in the most appropriate way for the user.

[1003] This allows the server to not only propose effective security measures based on cases from other companies, but also to provide appropriate notifications taking into account the user's emotional state.

[1004] Example 2

[1005] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."

[1006] When a cyber attack or information leak occurs, it is important to learn from similar incidents at other companies and respond quickly and appropriately. However, with conventional systems, the process of collecting and analyzing other companies' incidents, assessing risks, and proposing countermeasures is often done manually, which is time-consuming and laborious. As a result, timely countermeasures may be delayed, potentially exacerbating the damage. Another challenge is how to provide effective notifications while reducing user stress and anxiety.

[1007] The specific processing by the specific processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means.

[1008] In this invention, the server includes means for collecting information on cyber attacks and information leakage incidents by other companies, means for analyzing and classifying the collected information on cyber attacks and information leakage incidents by other companies using natural language processing, means for comparing the collected information with the company's own security management system, means for conducting a risk assessment based on the comparison results and taking into account the possibility and impact of threats, means for proposing specific countermeasures based on the results of the risk assessment, means for notifying the user of the risk assessment and the proposed countermeasures, and means for acquiring user emotion data and adjusting the content of the notification based on the emotion analysis results. This makes it possible to quickly learn lessons from cyber attacks and information leakage incidents by other companies, identify the company's own vulnerabilities, propose appropriate countermeasures, and provide optimal notifications that take the user's emotional state into consideration.

[1009] A "cyber attack" is an attack on a computer system or network, such as unauthorized access, data theft, or destruction.

[1010] "Information leakage" refers to the unintentional or unauthorized leakage of confidential information or personal information to the outside.

[1011] "Collection means" refers to the ability to obtain the required information from the Internet or specific sources.

[1012] "Analysis means" refers to the function of analyzing collected information using natural language processing technology, etc., and extracting important elements.

[1013] "Classification means" refers to a function that categorizes analyzed information based on specific criteria.

[1014] "Matching means" refers to a function for comparing and examining the case information of other companies with one's own security management system and identifying vulnerabilities.

[1015] "Risk assessment means" refers to a function that evaluates the likelihood and impact of a threat and calculates a risk score.

[1016] "Measures proposal means" refers to the function of presenting appropriate measures based on the results of risk assessment.

[1017] "Notification means" refers to a function for notifying the user of the results of risk assessment and proposed measures.

[1018] "Emotional data" refers to information about a user's emotional state.

[1019] "Emotion analysis results" refer to the results obtained by analyzing emotion data.

[1020] This invention combines a system that collects cyber attacks and information leaks that have occurred at other companies, analyzes them, compares them with the company's own security management system, and automatically performs risk assessments and proposes countermeasures, with an emotion engine that recognizes user emotions. Specific embodiments for implementing this system will be described below.

[1021] Collecting information on cyber attacks and information leaks at other companies

[1022] The server automatically collects data on cyber attacks and information leaks by other companies from the internet or specific sources (e.g., security news sites, industry association reports). This data is collected using API requests and web scraping technology. For example, information such as "A certain financial institution was attacked by a phishing attack and customer data was leaked" is obtained from the "Security News API."

[1023] Information analysis and classification

[1024] The server analyzes the information it collects using natural language processing technology (e.g., Python's NLTK or spaCy library) to extract important elements of cyber attacks and information leaks (such as the type of attack, the scope of impact, and the cause). Based on the analysis results, the incidents are classified according to their type and scope of impact. For example, information about phishing attacks collected by the server is classified as "phishing attack," "financial industry," and "medium damage scale."

[1025] Verification of in-house management system

[1026] The server retrieves information about its own security management system from a database, including firewall settings, access control policies, and employee security training. The server compares the collected information about other companies' incidents with its own security management system to determine whether its own company is vulnerable to similar threats. For example, the server may determine that its phishing protection is out of date.

[1027] Risk Assessment

[1028] Based on the matching results, the server assesses the risk to the company if it were exposed to a similar threat. The risk assessment is based on the likelihood and impact of the threat. Machine learning models can be used to calculate the risk score. For example, the server may identify weaknesses in the company's phishing protection and assess the risk score as "high."

[1029] Countermeasure proposals

[1030] Based on the results of the risk assessment, the server uses a generative AI model to propose specific countermeasures. These proposals include technical measures (e.g., updating anti-ransomware software, strengthening firewall settings), policy changes (e.g., reviewing access control, implementing data encryption), and employee education (e.g., security training). For example, the server may suggest "introducing the latest email filtering software" or "implementing phishing training for employees."

[1031] Notifications and Reporting

[1032] The server notifies the user of the assessment results and recommendations. Notifications include displaying the results on the management screen, sending emails about important information, and sending alerts. For example, the server compiles the risk assessment and recommendations into a report, displays it on the user's management screen, and notifies the user of important information by email.

[1033] Using the Emotion Engine

[1034] The server acquires the user's emotional data and analyzes it using an emotion engine. The emotion engine uses libraries such as IBM Watson Tone Analyzer to analyze the user's text input and voice data and recognize emotions. The notification content is adjusted based on the recognized emotion. For example, if the user is feeling stressed, the tone of the notification can be softened and additional explanations can be added. The emotion engine allows the server to select the optimal notification method according to the user's emotional state. For example, if the situation is urgent, an immediate notification can be sent, and if the situation is normal, information can be provided periodically.

[1035] Example prompt sentence:

[1036] "Please obtain information on the latest cyber attacks of other companies and classify the scope of impact and the cause of the attacks. Then, based on this information, please compile a report comparing the results with your own company's security posture."

[1037] "Generate reports that identify vulnerabilities in your security measures and suggest countermeasures accordingly. Tailor notifications based on the user's stress level."

[1038] This system not only suggests effective security measures based on incidents at other companies, but also provides appropriate notifications taking into account the user's emotional state, allowing users to receive information at the appropriate time and in the appropriate way.

[1039] The flow of the identification process in the second embodiment will be described with reference to FIG.

[1040] Step 1:

[1041] Collecting information on cyber attacks and information leaks at other companies

[1042] The server accesses information sources such as security news APIs to obtain data on cyber attacks and information leaks.

[1043] Input: Take the URL of a security news or industry report as input via an API request or other method.

[1044] Data processing: Analyze data such as JSON format obtained via API requests and extract necessary information (e.g., type of attack, date and time of occurrence, scope of impact).

[1045] Output: The extracted data is organized and stored in a database.

[1046] Specifically, a scheduled job is set up for periodic access, and the necessary information is filtered using a naive Bayesian classifier or similar.

[1047] Step 2:

[1048] Information analysis and classification

[1049] The server analyzes the collected data using natural language processing technology and extracts important elements.

[1050] Input: Collected data (e.g., type of attack, scope of impact, cause)

[1051] Data processing: Use a natural language processing library (e.g., NLTK, spaCy) to extract important elements from the text data and run them through a classification algorithm.

[1052] Output: The analyzed data is categorized by attributes such as "type of attack," "industry," and "scale of damage," and stored in a database.

[1053] Specifically, it tokenizes text data, performs partial analysis (noun phrase extraction), and classifies the data by category. For example, it classifies information about phishing attacks into "phishing attacks," "financial industry," and "medium damage scale."

[1054] Step 3:

[1055] Verification of in-house management system

[1056] The server retrieves the company's security management system information from the database and compares it with other companies' case information.

[1057] Input: Your company's security settings information (firewall settings, access control policies, etc.) and other companies' case information

[1058] Data calculation: A matching algorithm identifies gaps between your company's security settings and those of other companies.

[1059] Output: Gap analysis results are obtained and your company's vulnerabilities are identified.

[1060] Specifically, it sets certain thresholds and performs filtering to determine whether or not a match occurs based on those criteria. For example, the server identifies that its phishing protection is out of date.

[1061] Step 4:

[1062] Risk Assessment

[1063] The server performs a risk assessment based on its own vulnerabilities and calculates a risk score.

[1064] Input: Gap analysis results, threat type, impact

[1065] Data computation: Using machine learning models to calculate risk scores and quantify the likelihood and impact of risks.

[1066] Output: Risk scores are obtained and countermeasures are prioritized.

[1067] Specifically, the server adds up the scores for each risk factor and performs a comprehensive risk assessment. For example, the server may assess the risk score for phishing protection as "high."

[1068] Step 5:

[1069] Proposal of measures

[1070] The server uses a generative AI model to propose specific countermeasures.

[1071] Input: Risk assessment results, risk score

[1072] Data processing: Generate countermeasures using a generative AI model and create specific proposals.

[1073] Output: Countermeasure proposals are obtained and stored in a database.

[1074] Specifically, the system uses the proposal generation and feedback functions to automatically generate optimal countermeasures, such as suggesting "the introduction of the latest email filtering software" or "implementing phishing training for employees."

[1075] Step 6:

[1076] Notifications and Reporting

[1077] The server notifies the user of the evaluation results and recommendations and creates a detailed report.

[1078] Input: Risk assessment results, proposed countermeasures

[1079] Data Processing: Notification and reporting algorithms shape the data and provide information to the user.

[1080] Output: Reports are generated and displayed on the user's admin screen. Important information is also sent via email.

[1081] Specifically, it generates a report using an HTML or PDF generation library and sends an email to the user using SMTP.

[1082] Step 7:

[1083] Using the Emotion Engine

[1084] The server acquires the user's emotional data and analyzes it using an emotion engine.

[1085] Input: User text input and voice data

[1086] Data calculation: Analyze using an emotion analysis engine (e.g., IBM Watson Tone Analyzer) to recognize the emotional state.

[1087] Output: The sentiment analysis results are used to adjust the tone and manner of the notification.

[1088] Specifically, it uses text mining and voice analysis technology to identify the user's emotions and optimizes the notification method. For example, if the user is feeling stressed, it softens the tone of the notification and adds additional explanation. Depending on the user's condition, it responds immediately in emergencies and sends regular notifications under normal circumstances.

[1089] In this way, the entire system achieves effective security measures based on examples from other companies and appropriate notifications that take into account the user's emotional state.

[1090] (Application example 2)

[1091] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."

[1092] Current security systems are capable of collecting and analyzing information on cyberattacks from other companies, but the process of incorporating that information into one's own security system is not automated, making it difficult to respond quickly and effectively. Furthermore, there is no notification method that takes into account the user's emotional state, making it difficult to deliver appropriate content or notifications according to the situation. As a result, users may feel stressed or miss important notifications.

[1093] The identification process by the identification processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means. In this invention, the server includes means for collecting information on cyber attacks and information leakage cases by other companies, means for analyzing and classifying the collected information on cyber attacks and information leakage cases by other companies, and means for adjusting the notification content using an emotion engine that recognizes the user's emotions. This makes it possible to quickly reflect the collected information on cyber attacks by other companies in one's own security system and also enables appropriate notifications to be provided according to the user's emotional state.

[1094] "Cyber ​​attacks and information leaks at other companies" refers to specific incidents and examples of cyber attacks and information leaks that have occurred at other companies or organizations.

[1095] "Means of collection" refers to the methods and technologies that allow a server to automatically obtain data on other companies' cyber attacks and information leaks from the Internet or specific sources.

[1096] "Means of analysis and classification" refers to methods and technologies for analyzing information acquired by a server using natural language processing technology, etc., and classifying cyber attacks and information leaks based on their type, scope of impact, etc.

[1097] "Your company's security management system" refers to the entire security policies, settings, measures, etc. that your company or organization has.

[1098] "Means of comparison" refers to methods and technologies for comparing information on cyber attacks and information leaks at other companies with one's own security management system to identify the possibility that one's company may be exposed to similar threats or vulnerabilities.

[1099] "Risk assessment" refers to the process of assessing the risk to a company if it is exposed to the same threats as other companies, based on the likelihood and impact of the threat.

[1100] "Means for proposing countermeasures" refers to methods and technologies by which the server provides specific countermeasures to strengthen the company's security based on the results of risk assessment.

[1101] "Means of notifying users" refers to methods and technologies for communicating the contents of risk assessments and proposed countermeasures to users.

[1102] "Emotion engine" refers to technology that analyzes a user's text input and voice data to recognize the user's emotional state.

[1103] "Means for tailoring notification content" refers to methods and techniques for optimizing the tone and content of notifications based on perceived user sentiment.

[1104] To implement the present invention, the following system configuration and program processing must be executed.

[1105] This system runs on a server and automatically collects and analyzes information on cyber attacks and information leaks from other companies, compares it with the company's own security management system, assesses the risks, proposes countermeasures, and notifies users.It also incorporates an emotion engine that recognizes the user's emotional state, allowing it to adjust the content of notifications according to their emotions.

[1106] Specifically, the server operates as follows.

[1107] Data collection:

[1108] The server collects data on cyber attacks and information leaks by other companies from the internet and specific sources (such as security news sites and industry association reports). This collection process uses external services such as the "Security News API." The information obtained by the server includes the date and time of the incident, the type of attack, the scope of impact, and the cause.

[1109] Information analysis and classification:

[1110] Using natural language processing technology (such as Google Cloud Natural Language API), the information collected by the server is analyzed, and key elements of cyber attacks and data breaches are extracted and classified. The classification process involves tagging the incidents based on their type and scope of impact.

[1111] Checking our management system:

[1112] The server retrieves information about the company's security management system from the database and compares it with incident information collected from other companies. This comparison evaluates whether the company is vulnerable to similar threats. For example, if the company's phishing protection is out of date, this will be identified as a vulnerability.

[1113] Risk Assessment:

[1114] The server performs a risk assessment based on the matching results. The risk assessment calculates a risk score based on the likelihood and impact of the threat. This risk score determines the priority of countermeasures.

[1115] Suggested solutions:

[1116] Based on the results of the risk assessment, the server will propose specific countermeasures, including technical measures (e.g., updating anti-ransomware software and strengthening firewall settings), policy changes (e.g., reviewing access control and implementing data encryption), and employee education (implementing security training).

[1117] Emotion Engine:

[1118] The server obtains the user's emotional data using the Google Cloud Speech-to-Text API and analyzes the user's emotions using an emotion engine. Based on the analysis results, the content of the notification is adjusted. For example, if the user is feeling stressed, the tone of the notification may be softened or additional explanations may be added.

[1119] notification:

[1120] The server notifies the user of the evaluation results and proposed measures. The content of the notification is adjusted by the emotion engine. For example, if the issue is highly urgent, an immediate notification will be sent.

[1121] Examples:

[1122] If the user is in a normal emotional state, the server sends a notification suggesting "installation of the latest email filtering software."

[1123] If the user is in a high-stress state, soften the notification and say, "Start with some simple steps to improve your security."

[1124] Example prompt sentence:

[1125] "I would like to implement a system that collects information on the latest cyber attacks that have occurred at other companies and uses that information to evaluate my own company's security posture. In the process, I would also like to add a function that adjusts the content of notifications based on the user's emotions. I would like advice on how to soften the content of notifications when a user is under high stress."

[1126] By operating in this way, the system suggests effective security measures based on cases at other companies and provides appropriate notifications based on the user's emotional state, allowing the user to receive information at the appropriate time and in the appropriate way.

[1127] The flow of the specific processing in the application example 2 will be described with reference to FIG.

[1128] Step 1:

[1129] The server collects data on cyber attacks and information leaks by other companies from the internet or specific information sources. Specifically, it obtains the latest cyber attack information using a security news API, etc. The input in this case is an API request, and the output is JSON data containing cyber attack information.

[1130] Step 2:

[1131] The cyber attack information collected by the server is analyzed using natural language processing technology. Specifically, the Google Cloud Natural Language API is used to extract important elements from the text data (type of attack, scope of impact, cause, etc.). In this case, the input is the JSON data obtained in step 1, and the output is a list of the analyzed elements.

[1132] Step 3:

[1133] The server classifies the analyzed cyber attack information. Specifically, it sets categories based on the type of attack, the scope of impact, the scale of damage, etc., and classifies the information. In this case, the input is the list of elements extracted in step 2, and the output is a list of classified incidents.

[1134] Step 4:

[1135] The server retrieves information about the company's security controls from a database, specifically data such as firewall settings, access control policies, and employee security training status. The input in this case is a database query, and the output is a list of security control information.

[1136] Step 5:

[1137] The server compares the cyber attack information collected from other companies with the company's own security management system. Specifically, it checks for vulnerabilities in phishing countermeasures, email filtering, employee training, etc. The input in this case is the list of incidents from Step 3 and the list of management system information from Step 4, and the output is a list of vulnerabilities.

[1138] Step 6:

[1139] The server performs a risk assessment based on the company's vulnerability list. Specifically, it calculates a risk score based on the type of threat and gaps in the company's management system. In this case, the input is the vulnerability list from step 5, and the output is the risk assessment results and risk score.

[1140] Step 7:

[1141] The server proposes specific countermeasures based on the results of the risk assessment, such as introducing the latest email filtering software and conducting phishing training for employees. The input in this case is the risk assessment result and risk score from Step 6, and the output is a list of countermeasure proposals.

[1142] Step 8:

[1143] The server acquires the user's emotional data. Specifically, it uses the Google Cloud Speech-to-Text API or similar to acquire the user's voice commands and text input, which are then analyzed by the emotion engine. In this case, the input is the user's voice and text data, and the output is the recognized emotional data.

[1144] Step 9:

[1145] The server adjusts the notification content based on the emotion engine. Specifically, it changes the tone and content of the notification according to the user's emotional state. In this case, the input is the emotion data from step 8 and the countermeasure proposal list from step 7, and the output is the adjusted notification content.

[1146] Step 10:

[1147] The server notifies the user of the evaluation results and proposed countermeasures. Specifically, if the situation is urgent, the server notifies immediately, and if it is normal, the server notifies periodically. In this case, the input is the notification content from step 9, and the output is a notification message to the user.

[1148] The specific processing unit 290 transmits the result of the specific processing to the headset type terminal 314. In the headset type terminal 314, the control unit 46A causes the speaker 240 and the display 343 to output the result of the specific processing. The microphone 238 acquires audio indicating a user input regarding the result of the specific processing. The control unit 46A transmits audio data indicating the user input acquired by the microphone 238 to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.

[1149] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[1150] In the above embodiment, an example was given in which the specific processing is performed by the data processing device 12, but the technology of the present disclosure is not limited to this, and the specific processing may be performed by the headset type terminal 314.

[1151] [Fourth embodiment]

[1152] FIG. 7 shows an example of the configuration of a data processing system 410 according to the fourth embodiment.

[1153] 7, a data processing system 410 includes a data processing device 12 and a robot 414. An example of the data processing device 12 is a server.

[1154] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[1155] The robot 414 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication I / F 44, and a control target 443. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The microphone 238, the speaker 240, the camera 42, and the control target 443 are also connected to the bus 52.

[1156] The microphone 238 receives instructions and the like from the user 20 by receiving voice uttered by the user 20. The microphone 238 captures the voice uttered by the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio in accordance with instructions from the processor 46.

[1157] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the surroundings of user 20 (for example, an imaging range defined by an angle of view equivalent to the field of vision of a typical healthy person).

[1158] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 control the exchange of various information between the processor 46 and the processor 28 via the network 54. The exchange of various information between the processor 46 and the processor 28 using the communication I / Fs 44 and 26 is carried out in a secure state.

[1159] The control object 443 includes a display device, LEDs in the eyes, and motors for driving the arms, hands, and feet. The posture and gestures of the robot 414 are controlled by controlling the motors of the arms, hands, and feet. Some of the emotions of the robot 414 can be expressed by controlling these motors. In addition, the facial expressions of the robot 414 can also be expressed by controlling the light emission state of the LEDs in the eyes of the robot 414.

[1160] Fig. 8 shows an example of the main functions of the data processing device 12 and the robot 414. As shown in Fig. 8, in the data processing device 12, a specific process is performed by the processor 28. A specific process program 56 is stored in the storage 32.

[1161] The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[1162] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[1163] In the robot 414, the processor 46 performs the reception output process. A reception output program 60 is stored in the storage 50. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.

[1164] Next, a description will be given of the specific processing performed by the specific processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."

[1165] This invention is a system that collects cyber attacks and information leaks that have occurred at other companies, analyzes them, compares them with the company's own security management system, and automatically performs everything from risk assessment to proposing countermeasures. Below, we will explain the processing content of this system's program in natural language, and also provide specific examples.

[1166] Program processing flow

[1167] 1. Collecting information on cyber attacks and information leaks at other companies

[1168] The server automatically collects data on cyber attacks and information leaks by other companies from the Internet and specific sources (security news sites, industry association reports, etc.).

[1169] The collected information includes the date and time of the incident, the type of attack, the scope of impact, and the cause.

[1170] For example, the server obtains information from the "Security News API" that "a certain financial institution was attacked by a phishing attack and customer data was leaked."

[1171] 2. Information analysis and classification

[1172] The server analyzes the acquired information using natural language processing technology, which extracts important elements of cyber attacks and data breaches (such as the type of attack, the scope of impact, and the cause).

[1173] Based on the analysis results, classification is made according to the type of incident and the scope of impact.

[1174] For example, the server classifies the information about phishing attacks it collects as "phishing attacks," "financial industry," and "medium damage scale."

[1175] 3. Checking your company's management system

[1176] The server retrieves information about your company's security controls from a database, including firewall settings, access control policies, and employee security training status.

[1177] The server compares the incident information collected from other companies with the company's own security management system to determine whether the company is vulnerable to similar threats.

[1178] For example, the server checks to see if its phishing protection (email filtering, employee training, etc.) is out of date.

[1179] 4. Risk Assessment

[1180] The server uses the results of the comparison to assess the risk to its company if it were to be exposed to a similar threat. The risk assessment is based on the likelihood and impact of the threat.

[1181] A risk score is calculated and countermeasures are prioritized based on this.

[1182] For example, the server may check for deficiencies in its own phishing prevention measures and rate the risk score as "high."

[1183] 5. Proposal of countermeasures

[1184] The server proposes specific countermeasures based on the results of the risk assessment.

[1185] These suggestions may include technical measures (e.g., updating anti-ransomware software, strengthening firewall rules), policy changes (e.g., reviewing access controls, implementing data encryption), and employee education (e.g., conducting security training).

[1186] For example, the server might suggest "introducing the latest email filtering software" or "conducting phishing training for employees."

[1187] 6. Notification and Reporting

[1188] The server notifies the user (security officer) of the evaluation results and recommendations.

[1189] The server generates a detailed report of the risk assessment and recommendations, which are displayed on the user's management screen.

[1190] If necessary, you can also receive immediate notification of important information via email or alerts.

[1191] For example, the server compiles these risk assessments and recommendations into a report, displays it on the user's management screen, and notifies them by email.

[1192] In this way, the system can effectively leverage cyber attacks and data breaches by other companies to continuously strengthen its own security posture.

[1193] The processing flow will be explained below.

[1194] Step 1:

[1195] The server periodically collects data on cyber attacks and information breaches by other companies from reliable sources (e.g., security news sites and industry reports). The server accesses these sources using APIs or web scraping technology to obtain the latest incident information and stores it in a database.

[1196] Step 2:

[1197] The server analyzes the collected data using natural language processing (NLP) technology, extracting necessary information from the text data (such as the date and time of the incident, the type of attack, the scope of impact, and the cause) and structuring this data.

[1198] Step 3:

[1199] The server classifies the incidents based on the analysis results. The information collected by the server is classified into the type of attack (e.g., ransomware, phishing, internal information leaks, etc.), industry (e.g., finance, healthcare, education, etc.), and scale of damage (e.g., large, medium, small).

[1200] Step 4:

[1201] The server retrieves information about the company's security posture from a database, including firewall settings, access control policies, vulnerability scan results, and employee security training status.

[1202] Step 5:

[1203] The server compares the incident information of other companies with the company's management system. The server performs the comparison process, identifies commonalities and differences between the company's security management system and those of other companies, and identifies vulnerabilities and areas for improvement.

[1204] Step 6:

[1205] The server performs a risk assessment based on the matching results. The server calculates a risk score based on the type of threat and gaps in the company's management system. The risk score is calculated taking into account the likelihood and impact of the threat.

[1206] Step 7:

[1207] The server proposes specific countermeasures based on the results of the risk assessment, including technical measures (e.g., updating anti-ransomware software, strengthening firewall settings), policy changes (e.g., reviewing access control, implementing data encryption), and employee education (e.g., implementing security training).

[1208] Step 8:

[1209] The server notifies the user of the risk assessment and proposed countermeasures. The server generates a detailed report and displays it on the user's management screen. The server also notifies the user immediately of important information via email or alerts.

[1210] Through the above process, a system will be created in which the server utilizes the cases of other companies to continuously strengthen its own security management system.

[1211] Example 1

[1212] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."

[1213] Conventional security systems often do not collect data on cyber attacks or information leaks from other companies, making it difficult to link this data to improvements in one's own security management system. Manually investigating other companies' incidents and reviewing one's own countermeasures takes time and effort, making it difficult to maintain and improve the security level of the entire company. Furthermore, if the risk assessment and countermeasure proposal processes are not systematized, they depend on the knowledge and experience of the individual in charge, making it difficult to implement uniform security measures.

[1214] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.

[1215] In this invention, the server includes: means for automatically collecting information on cyber attacks and information leak incidents by other companies from the Internet or specific information sources; means for preprocessing the collected information on cyber attacks and information leak incidents by other companies using natural language processing technology to extract and classify important elements; means for obtaining information on the company's own security management system from a database and comparing it with the collected information to identify vulnerabilities; means for calculating a risk score based on the comparison result and conducting a risk assessment; means for proposing specific countermeasures such as technical measures, policy changes, and employee training based on the result of the risk assessment; and means for notifying the user of the risk assessment and the proposed countermeasures and displaying them in a detailed report format on the user's management screen. This enables the company to automatically evaluate and improve its own security management system based on the incidents of other companies, thereby efficiently and effectively maintaining and improving its security level.

[1216] A "cyber attack" is a malicious attack on a computer system or network via the Internet.

[1217] "Information leakage" refers to the phenomenon or act of confidential information or personal information leaking to the outside without permission.

[1218] "Natural language processing technology" is a technology that enables computers to understand and process human language.

[1219] A "database" is a system or software for efficiently managing, searching, and updating large amounts of data.

[1220] A "vulnerability" is a weakness in a computer system or network that makes it susceptible to external attacks.

[1221] "Risk assessment" is the process of assessing the extent of damage or impact if a particular threat occurs.

[1222] A "risk score" is a numerical representation of the result of a risk assessment, indicating the severity of a threat and the probability of it occurring.

[1223] "Countermeasure proposals" are proposals on what measures or actions should be taken to address a specific risk.

[1224] "Technical measures" are means of responding to threats using software or hardware.

[1225] "Policy change" means reviewing and revising rules and guidelines within an organization.

[1226] "Employee training" is the training and education of an organization's employees to acquire specific knowledge and skills.

[1227] "Users" refer to the security personnel and operations managers who use this system.

[1228] A "report format" is a document format for organizing information and data and presenting them in a visually easy-to-understand manner.

[1229] The "management screen" is an interface for operating and configuring the system.

[1230] This invention is a system that collects cyber attacks and information leaks that have occurred at other companies, analyzes them, compares them with the company's own security management system, and automatically performs risk assessments and proposes countermeasures. This system is implemented with the involvement of servers, terminals, and users.

[1231] server

[1232] The server is responsible for automatically collecting data on cyber attacks and information leaks by other companies from the internet and specific sources (e.g., security news sites and industry association reports). Specifically, the server connects to the "Security News API" and retrieves data by sending a REST API request. This data includes information such as the date and time of the incident, the type of attack, the scope of impact, and the cause. The collected data is stored in a database (e.g., MySQL or PostgreSQL).

[1233] The server analyzes the collected information using natural language processing technology (for example, SpaCy or the NLTK library). Specifically, it tokenizes the text data, removes unnecessary words, and extracts important elements such as the type of attack and the scope of impact. The extracted information is then classified by category. For example, data is classified as "phishing attack," "financial industry," and "medium damage scale."

[1234] In addition, the server retrieves information about the company's security management system from the database and compares it with collected incident information from other companies to determine whether the company is vulnerable to similar threats. The company's security management information includes firewall settings, access control policies, employee security training status, etc. For example, the server may determine that the company's email filtering is out of date.

[1235] Terminal

[1236] The terminal provides an interface for users to interact with the system. It notifies users of the assessment results and proposed countermeasures generated by the server and displays a management screen that allows users to take appropriate action. Specifically, the terminal displays risk assessments and proposed countermeasures in a detailed report format, and notifies users immediately of important information via email or alerts as needed.

[1237] User

[1238] Users are primarily security personnel who check the evaluation results and countermeasure proposals provided by the server on the management screen and direct the implementation of actual security measures. For example, they receive proposals such as "introducing the latest email filtering software" or "training employees on phishing" and take specific actions to implement them.

[1239] Here are some examples of prompts to input to a generative AI model:

[1240] "Please collect recent phishing attack cases in the financial industry, compare them with your company's phishing countermeasures, conduct a risk assessment, and propose specific countermeasures."

[1241] This system allows companies to automatically evaluate and improve their own security management systems based on the cases of other companies, enabling them to efficiently and effectively maintain and improve their security levels.

[1242] The flow of the identification process in the first embodiment will be described with reference to FIG.

[1243] Step 1:

[1244] The server connects to the Internet and automatically collects data on cyber attacks and information leaks by other companies from specific sources (such as security news sites and industry association reports). The input is the endpoint URL of the security news API, and the output is incident data in JSON format. The server sends REST API requests and receives responses.

[1245] Step 2:

[1246] The server formats the data it receives and converts it into the required format. It then stores it in a database (for example, MySQL or PostgreSQL). The input is the collected JSON-formatted data, and the output is a formatted database record. The server extracts and stores information such as the date and time of the incident, the type of attack, the scope of impact, and the cause.

[1247] Step 3:

[1248] The server analyzes the collected information using natural language processing technology (for example, SpaCy or NLTK library). The input is the text data stored in the database, and the output is the analyzed important elements (type of attack, scope of impact, cause, etc.). The server divides the text data into tokens, removes unnecessary words, and extracts important elements.

[1249] Step 4:

[1250] Based on the analysis results, the server categorizes cyber attacks and information leaks. The input is the analyzed data, and the output is data organized by category. For example, the server might categorize the data as "phishing attacks," "financial industry," or "medium damage scale."

[1251] Step 5:

[1252] The server retrieves information about the company's security management system from a database. The input is a database query containing information about the company's security system, and the output is the retrieved management information. For example, the server retrieves firewall settings, access control policies, and employee security training status.

[1253] Step 6:

[1254] The server compares the incident information collected by other companies with the company's security management system to identify vulnerabilities. The input is the incident information of other companies and the company's management information, and the output is the identified vulnerabilities. The server performs specific comparisons, such as checking to see if the company's email filtering is out of date.

[1255] Step 7:

[1256] The server evaluates the risk of the company based on the matching result. The input is the matching result, and the output is a risk score. The server runs a risk evaluation algorithm and evaluates the risk score of a phishing attack as "high," for example.

[1257] Step 8:

[1258] The server proposes specific countermeasures based on the risk assessment results. The input is the risk assessment results, and the output is the proposed countermeasures. The server proposes technical countermeasures (e.g., installing the latest email filtering software), policy changes (e.g., reviewing access control), and employee training (e.g., conducting phishing drills).

[1259] Step 9:

[1260] The server notifies the user of the risk assessment and proposed countermeasures. The input is the proposed countermeasures, and the output is a notification and a detailed report. The server compiles the assessment results and proposed countermeasures and displays them on the management screen, and notifies users of important information via email or alerts as needed.

[1261] In this way, servers, terminals, and users work together to run the system and effectively evaluate and improve their company's security management system.

[1262] (Application example 1)

[1263] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."

[1264] Currently, it is difficult to effectively collect information on cyber attacks and data leaks that have occurred at other companies and reflect it in one's own security management system. Furthermore, risk assessments and countermeasure proposals based on this information are performed manually, which lack real-time performance and often results in delayed countermeasures. Furthermore, there is a need for more advanced analysis using the latest AI technology.

[1265] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.

[1266] In this invention, the server

[1267] A means of collecting information on cyber attacks and information leaks at other companies,

[1268] A means of analyzing and classifying collected cyber attacks and information leaks from other companies,

[1269] A means of verifying the collected information against your company's security management system, and

[1270] a means for performing a risk assessment based on the matching results;

[1271] A means of proposing countermeasures based on the results of the risk assessment;

[1272] means for notifying a user of the content of the risk assessment and the proposed measures;

[1273] A method to extract the type, scope, and cause of an attack using a generative AI model based on cyber attacks and data breaches by other companies;

[1274] means for providing the extracted information to a user as a prompt sentence;

[1275] This will enable the company to efficiently collect and analyze cyber attacks and information leaks by other companies, and strengthen its own security measures in real time.

[1276] "Cyber ​​attacks and information leaks at other companies" refers to incidents involving unauthorized access or data acquisition that other organizations or companies have experienced.

[1277] "Collection methods" refer to methods and technologies that automatically obtain data from the Internet or specific sources.

[1278] "Means of analysis and classification" refers to techniques and methods for analyzing collected data and categorizing it based on its characteristics.

[1279] "Our company's security management system" refers to the organizational policies and measures for protecting our company's information and systems.

[1280] "Means of comparison" refers to the technology or method for comparing other companies' case information with your own security settings and policies.

[1281] "Risk assessment methods" refer to methods and techniques used to assess a company's vulnerability to similar threats and their impact.

[1282] "Means for proposing countermeasures" refers to techniques and methods for proposing specific security measures based on the results of risk assessment.

[1283] "Means of notification" refers to the technology or method for notifying users of the evaluation results and proposals, including email and push notifications.

[1284] "Methods for extracting attack types, scope of impact, and causes using generative AI models" refers to methods that utilize AI technology to automatically identify and extract specific elements from collected data.

[1285] "Means for providing the extracted information to the user as a prompt" refers to a technique or method for providing the user with instructions or suggestions generated based on the analysis results.

[1286] This invention is a system that collects information on cyber attacks and information leaks from other companies, analyzes it, compares it with the company's own security management system, and automatically performs risk assessments and proposes countermeasures. This system consists of the following main components.

[1287] 1. Collecting information on cyber attacks and information leaks at other companies

[1288] The server automatically collects information about cyber attacks and data breaches by other companies from the internet and specific sources. This information is collected using Python and scraping libraries (BeautifulSoup, Scrapy). The collected information includes the date and time of the incident, the type of attack, the scope of impact, and the cause.

[1289] 2. Information analysis and classification

[1290] The server uses natural language processing technology to analyze the collected information and extract key elements of cyber attacks and data breaches (e.g., type of attack, scope of impact, cause, etc.). The specific technology used is the Transformers library (BERT model, etc.).

[1291] 3. Comparison with the company's management system

[1292] The server retrieves information about the company's security management system from a database (MySQL) and compares it with incident information from other companies to determine whether the company is vulnerable to similar threats. Specific information includes firewall settings, access control policies, and employee security training status.

[1293] 4. Risk Assessment

[1294] Based on the matching results, the server assesses the risk to the company if it were exposed to a similar threat. The risk assessment is based on the likelihood and impact of the threat, and a risk score is calculated.

[1295] 5. Proposal of countermeasures

[1296] Based on the results of the risk assessment, the server will propose specific countermeasures, including technical measures (e.g., updating anti-ransomware software, strengthening firewall rules), policy changes (e.g., reviewing access control, implementing data encryption), and employee education (e.g., security training).

[1297] 6. Notification and Reporting

[1298] The server notifies the user of the evaluation results and recommendations. Notification methods include email, alerts, and push notifications (FCM (Firebase Cloud Messaging)). In addition, the evaluation results and recommendations are displayed in a detailed report format on the user's management screen.

[1299] As a concrete example, if a financial institution were to be hit by a phishing attack and customer data were to be leaked, the server would use natural language processing technology to extract from this information the type of attack, the extent of its impact, and the cause. Based on this information, the server would compare the company's phishing countermeasures, conduct a risk assessment, and propose specific countermeasures (for example, the introduction of the latest email filtering software or phishing training for employees).

[1300] Example prompt sentence:

[1301] Analyze a news article stating that "A certain financial institution was subjected to a phishing attack and customer data was leaked," and extract the type of attack, the scope of its impact, and the cause.

[1302] In this way, the system can effectively leverage cyber attacks and data breaches by other companies to continuously strengthen its own security posture.

[1303] The flow of the specific processing in the application example 1 will be described with reference to FIG.

[1304] Step 1:

[1305] Collecting information on cyber attacks and information leaks at other companies

[1306] The server automatically collects information about cyber attacks and data breaches by other companies from the internet and specific sources (news sites and industry association reports). Specifically, it uses Python and scraping libraries (BeautifulSoup, Scrapy) to obtain data such as the date and time of the incident, the type of attack, the scope of impact, and the cause. A URL or API endpoint is given as input, and a list of incident information is generated as output.

[1307] Step 2:

[1308] Information analysis and classification

[1309] The server analyzes the collected information using natural language processing technology. Specifically, it uses the Transformers library (such as the BERT model) to extract key elements of cyber attacks and data breaches (such as the type of attack, the scope of impact, and the cause). The collected raw data is given as input, and the extracted and analyzed data is output. This analysis classifies the type of incident and the scope of impact.

[1310] Step 3:

[1311] Verification with our company's management system

[1312] The server retrieves information about the company's security management system (firewalls, access control policies, employee security training status, etc.) from a database (MySQL). It then compares this information with the collected and analyzed incident information of other companies to determine whether the company is vulnerable to similar threats. The input is the analysis data of other companies and the company's management system information, and the output is the comparison result.

[1313] Step 4:

[1314] Risk Assessment

[1315] The server evaluates the risk of the company being exposed to a similar threat based on the matching results. This risk assessment is based on the likelihood and impact of the threat, and a risk score is calculated. The matching results are given as input, and a numerical risk score is obtained as output.

[1316] Step 5:

[1317] Countermeasure proposals

[1318] The server then proposes specific countermeasures based on the results of the risk assessment, including technical measures (e.g., updating anti-ransomware software, strengthening firewalls), policy changes, employee training, etc. The server receives a risk score as input and generates a proposal as output.

[1319] Step 6:

[1320] Notifications and Reporting

[1321] The server notifies the user of the evaluation results and recommendations via email or push notification (FCM (Firebase Cloud Messaging)). A detailed report is also generated to be displayed on the admin panel. The recommendation data is given as input, and the notification sent to the user and the report for display are obtained as output.

[1322] Step 7:

[1323] Prompt generation and provision of information

[1324] The server uses a generative AI model based on cyber attacks and data breaches by other companies to extract the type of attack, the scope of impact, and the cause. This information is then presented to the user as a prompt. For example, the following prompt:

[1325] Analyze a news article stating that "A certain financial institution was subjected to a phishing attack and customer data was leaked," and extract the type of attack, the scope of its impact, and the cause.

[1326] The input is the analysis data, and the output is the generated prompt sentence.

[1327] Furthermore, an emotion engine that estimates the user's emotion may be further combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59, and perform identification processing using the user's emotion.

[1328] This invention combines a system that collects cyber-attacks and information leaks that have occurred at other companies, analyzes them, compares them with the company's own security management system, and automatically performs everything from risk assessment to proposing countermeasures, with an emotion engine that recognizes the user's emotions. Below, we will explain the processing content of this system's program in natural language, and also provide specific examples.

[1329] Program processing flow

[1330] 1. Collecting information on cyber attacks and information leaks at other companies

[1331] The server automatically collects data on cyber attacks and information leaks by other companies from the Internet and specific sources (security news sites, industry association reports, etc.).

[1332] The collected information includes the date and time of the incident, the type of attack, the scope of impact, and the cause.

[1333] For example, the server obtains information from the "Security News API" that "a certain financial institution was attacked by a phishing attack and customer data was leaked."

[1334] 2. Information analysis and classification

[1335] The server analyzes the acquired information using natural language processing technology, which extracts important elements of cyber attacks and data breaches (such as the type of attack, the scope of impact, and the cause).

[1336] Based on the analysis results, classification is made according to the type of incident and the scope of impact.

[1337] For example, the server classifies the information about phishing attacks it collects as "phishing attacks," "financial industry," and "medium damage scale."

[1338] 3. Checking your company's management system

[1339] The server retrieves information about your company's security controls from a database, including firewall settings, access control policies, and employee security training status.

[1340] The server compares the incident information collected from other companies with the company's own security management system to determine whether the company is vulnerable to similar threats.

[1341] For example, the server checks to see if its phishing protection (email filtering, employee training, etc.) is out of date.

[1342] 4. Risk Assessment

[1343] The server uses the results of the comparison to assess the risk to its company if it were to be exposed to a similar threat. The risk assessment is based on the likelihood and impact of the threat.

[1344] A risk score is calculated and countermeasures are prioritized based on this.

[1345] For example, the server may check for deficiencies in its own phishing prevention measures and rate the risk score as "high."

[1346] 5. Proposal of countermeasures

[1347] The server proposes specific countermeasures based on the results of the risk assessment.

[1348] These suggestions include technical measures (e.g., updating anti-ransomware software, strengthening firewall settings), policy changes (e.g., reviewing access controls, implementing data encryption), and employee education (e.g., conducting security training).

[1349] For example, the server might suggest "introducing the latest email filtering software" or "conducting phishing training for employees."

[1350] 6. Notification and Reporting

[1351] The server notifies the user (security officer) of the evaluation results and recommendations.

[1352] The server generates detailed reports that are displayed on the user's management screen, and notifies users immediately of important information via email or alerts.

[1353] For example, the server compiles these risk assessments and recommendations into a report, displays it on the user's management screen, and notifies them by email.

[1354] 7. Use of Emotion Engine

[1355] The server acquires the user's emotion data and analyzes the user's emotion. The emotion engine analyzes the user's text input and voice data to recognize the emotion.

[1356] The server can then tailor the notification content based on the perceived emotion, for example softening the tone of the notification or adding additional explanation if the user is feeling stressed.

[1357] The emotion engine allows the server to select the optimal notification method based on the user's emotional state. For example, if the situation is urgent, the server will provide immediate notification, and if the situation is normal, the server will provide information periodically.

[1358] This system not only suggests effective security measures based on incidents at other companies, but also provides appropriate notifications taking into account the user's emotional state, allowing users to receive information at the appropriate time and in the appropriate way.

[1359] The processing flow will be explained below.

[1360] Step 1:

[1361] The server periodically collects data on cyber attacks and information breaches by other companies from reliable sources (e.g., security news sites and industry reports). The server accesses these sources using APIs or web scraping technology, automatically obtains the latest incident information, and stores it in a database.

[1362] Step 2:

[1363] The server analyzes the collected data using natural language processing (NLP) technology. The server extracts necessary information from the text data (such as the date and time of the incident, the type of attack, the scope of impact, and the cause) and structures this data. For example, the server classifies phishing attack data as "phishing attack," "financial industry," and "medium damage scale."

[1364] Step 3:

[1365] The server retrieves information about your company's security management system from a database, including firewall settings, access control policies, employee security training status, etc. The server periodically updates the data to keep this information up to date.

[1366] Step 4:

[1367] The server compares the incident information collected from other companies with the company's management system. The server performs the comparison process, identifies similarities and differences between the company's security management system and those of other companies, and identifies vulnerabilities and areas for improvement. For example, it checks whether the company's phishing countermeasures are out of date.

[1368] Step 5:

[1369] The server performs a risk assessment based on the matching results. The server calculates a risk score based on the type of threat and gaps in the company's management system. This risk score is calculated taking into account the likelihood and impact of the threat. For example, the server may check for deficiencies in the company's phishing countermeasures and assess the risk score as "high."

[1370] Step 6:

[1371] The server proposes specific countermeasures based on the results of the risk assessment. These countermeasures include technical measures (e.g., updating anti-ransomware software, strengthening firewall settings), policy changes (e.g., reviewing access control, implementing data encryption), and employee education (e.g., implementing security training). For example, the server suggests "introducing the latest email filtering software" and "implementing phishing training for employees."

[1372] Step 7:

[1373] The server notifies the user of the assessment results and proposed countermeasures. The server generates a detailed report and displays it on the user's management screen. Important information is also immediately notified to the user via email or alerts. For example, the server compiles these risk assessments and proposals into a report, displays it on the user's management screen, and notifies the user by email.

[1374] Step 8:

[1375] The server acquires the user's emotional data and analyzes the user's emotions. The emotion engine analyzes the user's text input and voice data to recognize emotions. For example, the device collects the user's voice input, and the emotion engine analyzes it to detect "stress."

[1376] Step 9:

[1377] The server adjusts the content of notifications based on the recognized emotion. For example, if the user is feeling stressed, the notification tone may be softened or additional explanations may be added to make the information easier for the user to receive.

[1378] Step 10:

[1379] The emotion engine allows the server to select the optimal notification method based on the user's emotional state. For example, if the information is urgent, the server will provide immediate notification, and if it is normal, the server will provide periodic information, thereby conveying information in the most appropriate way for the user.

[1380] This allows the server to not only propose effective security measures based on cases from other companies, but also to provide appropriate notifications taking into account the user's emotional state.

[1381] Example 2

[1382] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."

[1383] When a cyber attack or information leak occurs, it is important to learn from similar incidents at other companies and respond quickly and appropriately. However, with conventional systems, the process of collecting and analyzing other companies' incidents, assessing risks, and proposing countermeasures is often done manually, which is time-consuming and laborious. As a result, timely countermeasures may be delayed, potentially exacerbating the damage. Another challenge is how to provide effective notifications while reducing user stress and anxiety.

[1384] The specific processing by the specific processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means.

[1385] In this invention, the server includes means for collecting information on cyber attacks and information leakage incidents by other companies, means for analyzing and classifying the collected information on cyber attacks and information leakage incidents by other companies using natural language processing, means for comparing the collected information with the company's own security management system, means for conducting a risk assessment based on the comparison results and taking into account the possibility and impact of threats, means for proposing specific countermeasures based on the results of the risk assessment, means for notifying the user of the risk assessment and the proposed countermeasures, and means for acquiring user emotion data and adjusting the content of the notification based on the emotion analysis results. This makes it possible to quickly learn lessons from cyber attacks and information leakage incidents by other companies, identify the company's own vulnerabilities, propose appropriate countermeasures, and provide optimal notifications that take the user's emotional state into consideration.

[1386] A "cyber attack" is an attack on a computer system or network, such as unauthorized access, data theft, or destruction.

[1387] "Information leakage" refers to the unintentional or unauthorized leakage of confidential information or personal information to the outside.

[1388] "Collection means" refers to the ability to obtain the required information from the Internet or specific sources.

[1389] "Analysis means" refers to the function of analyzing collected information using natural language processing technology, etc., and extracting important elements.

[1390] "Classification means" refers to a function that categorizes analyzed information based on specific criteria.

[1391] "Matching means" refers to a function for comparing and examining the case information of other companies with one's own security management system and identifying vulnerabilities.

[1392] "Risk assessment means" refers to a function that evaluates the likelihood and impact of a threat and calculates a risk score.

[1393] "Measures proposal means" refers to the function of presenting appropriate measures based on the results of risk assessment.

[1394] "Notification means" refers to a function for notifying the user of the results of risk assessment and proposed measures.

[1395] "Emotional data" refers to information about a user's emotional state.

[1396] "Emotion analysis results" refer to the results obtained by analyzing emotion data.

[1397] This invention combines a system that collects cyber attacks and information leaks that have occurred at other companies, analyzes them, compares them with the company's own security management system, and automatically performs risk assessments and proposes countermeasures, with an emotion engine that recognizes user emotions. Specific embodiments for implementing this system will be described below.

[1398] Collecting information on cyber attacks and information leaks at other companies

[1399] The server automatically collects data on cyber attacks and information leaks by other companies from the internet or specific sources (e.g., security news sites, industry association reports). This data is collected using API requests and web scraping technology. For example, information such as "A certain financial institution was attacked by a phishing attack and customer data was leaked" is obtained from the "Security News API."

[1400] Information analysis and classification

[1401] The server analyzes the information it collects using natural language processing technology (e.g., Python's NLTK or spaCy library) to extract important elements of cyber attacks and information leaks (such as the type of attack, the scope of impact, and the cause). Based on the analysis results, the incidents are classified according to their type and scope of impact. For example, information about phishing attacks collected by the server is classified as "phishing attack," "financial industry," and "medium damage scale."

[1402] Verification of in-house management system

[1403] The server retrieves information about its own security management system from a database, including firewall settings, access control policies, and employee security training. The server compares the collected information about other companies' incidents with its own security management system to determine whether its own company is vulnerable to similar threats. For example, the server may determine that its phishing protection is out of date.

[1404] Risk Assessment

[1405] Based on the matching results, the server assesses the risk to the company if it were exposed to a similar threat. The risk assessment is based on the likelihood and impact of the threat. Machine learning models can be used to calculate the risk score. For example, the server may identify weaknesses in the company's phishing protection and assess the risk score as "high."

[1406] Countermeasure proposals

[1407] Based on the results of the risk assessment, the server uses a generative AI model to propose specific countermeasures. These proposals include technical measures (e.g., updating anti-ransomware software, strengthening firewall settings), policy changes (e.g., reviewing access control, implementing data encryption), and employee education (e.g., security training). For example, the server may suggest "introducing the latest email filtering software" or "implementing phishing training for employees."

[1408] Notifications and Reporting

[1409] The server notifies the user of the assessment results and recommendations. Notifications include displaying the results on the management screen, sending emails about important information, and sending alerts. For example, the server compiles the risk assessment and recommendations into a report, displays it on the user's management screen, and notifies the user of important information by email.

[1410] Using the Emotion Engine

[1411] The server acquires the user's emotional data and analyzes it using an emotion engine. The emotion engine uses libraries such as IBM Watson Tone Analyzer to analyze the user's text input and voice data and recognize emotions. The notification content is adjusted based on the recognized emotion. For example, if the user is feeling stressed, the tone of the notification can be softened and additional explanations can be added. The emotion engine allows the server to select the optimal notification method according to the user's emotional state. For example, if the situation is urgent, an immediate notification can be sent, and if the situation is normal, information can be provided periodically.

[1412] Example prompt sentence:

[1413] "Please obtain information on the latest cyber attacks of other companies and classify the scope of impact and the cause of the attacks. Then, based on this information, please compile a report comparing the results with your own company's security posture."

[1414] "Generate reports that identify vulnerabilities in your security measures and suggest countermeasures accordingly. Tailor notifications based on the user's stress level."

[1415] This system not only suggests effective security measures based on incidents at other companies, but also provides appropriate notifications taking into account the user's emotional state, allowing users to receive information at the appropriate time and in the appropriate way.

[1416] The flow of the identification process in the second embodiment will be described with reference to FIG.

[1417] Step 1:

[1418] Collecting information on cyber attacks and information leaks at other companies

[1419] The server accesses information sources such as security news APIs to obtain data on cyber attacks and information leaks.

[1420] Input: Take the URL of a security news or industry report as input via an API request or other method.

[1421] Data processing: Analyze data such as JSON format obtained via API requests and extract necessary information (e.g., type of attack, date and time of occurrence, scope of impact).

[1422] Output: The extracted data is organized and stored in a database.

[1423] Specifically, a scheduled job is set up for periodic access, and the necessary information is filtered using a naive Bayesian classifier or similar.

[1424] Step 2:

[1425] Information analysis and classification

[1426] The server analyzes the collected data using natural language processing technology and extracts important elements.

[1427] Input: Collected data (e.g., type of attack, scope of impact, cause)

[1428] Data processing: Use a natural language processing library (e.g., NLTK, spaCy) to extract important elements from the text data and run them through a classification algorithm.

[1429] Output: The analyzed data is categorized by attributes such as "type of attack," "industry," and "scale of damage," and stored in a database.

[1430] Specifically, it tokenizes text data, performs partial analysis (noun phrase extraction), and classifies the data by category. For example, it classifies information about phishing attacks into "phishing attacks," "financial industry," and "medium damage scale."

[1431] Step 3:

[1432] Verification of in-house management system

[1433] The server retrieves the company's security management system information from the database and compares it with other companies' case information.

[1434] Input: Your company's security settings information (firewall settings, access control policies, etc.) and other companies' case information

[1435] Data calculation: A matching algorithm identifies gaps between your company's security settings and those of other companies.

[1436] Output: Gap analysis results are obtained and your company's vulnerabilities are identified.

[1437] Specifically, it sets certain thresholds and performs filtering to determine whether or not a match occurs based on those criteria. For example, the server identifies that its phishing protection is out of date.

[1438] Step 4:

[1439] Risk Assessment

[1440] The server performs a risk assessment based on its own vulnerabilities and calculates a risk score.

[1441] Input: Gap analysis results, threat type, impact

[1442] Data computation: Using machine learning models to calculate risk scores and quantify the likelihood and impact of risks.

[1443] Output: Risk scores are obtained and countermeasures are prioritized.

[1444] Specifically, the server adds up the scores for each risk factor and performs a comprehensive risk assessment. For example, the server may assess the risk score for phishing protection as "high."

[1445] Step 5:

[1446] Proposal of measures

[1447] The server uses a generative AI model to propose specific countermeasures.

[1448] Input: Risk assessment results, risk score

[1449] Data processing: Generate countermeasures using a generative AI model and create specific proposals.

[1450] Output: Countermeasure proposals are obtained and stored in a database.

[1451] Specifically, the system uses the proposal generation and feedback functions to automatically generate optimal countermeasures, such as suggesting "the introduction of the latest email filtering software" or "implementing phishing training for employees."

[1452] Step 6:

[1453] Notifications and Reporting

[1454] The server notifies the user of the evaluation results and recommendations and creates a detailed report.

[1455] Input: Risk assessment results, proposed countermeasures

[1456] Data Processing: Notification and reporting algorithms shape the data and provide information to the user.

[1457] Output: Reports are generated and displayed on the user's admin screen. Important information is also sent via email.

[1458] Specifically, it generates a report using an HTML or PDF generation library and sends an email to the user using SMTP.

[1459] Step 7:

[1460] Using the Emotion Engine

[1461] The server acquires the user's emotional data and analyzes it using an emotion engine.

[1462] Input: User text input and voice data

[1463] Data calculation: Analyze using an emotion analysis engine (e.g., IBM Watson Tone Analyzer) to recognize the emotional state.

[1464] Output: The sentiment analysis results are used to adjust the tone and manner of the notification.

[1465] Specifically, it uses text mining and voice analysis technology to identify the user's emotions and optimizes the notification method. For example, if the user is feeling stressed, it softens the tone of the notification and adds additional explanation. Depending on the user's condition, it responds immediately in emergencies and sends regular notifications under normal circumstances.

[1466] In this way, the entire system achieves effective security measures based on examples from other companies and appropriate notifications that take into account the user's emotional state.

[1467] (Application example 2)

[1468] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."

[1469] Current security systems are capable of collecting and analyzing information on cyberattacks from other companies, but the process of incorporating that information into one's own security system is not automated, making it difficult to respond quickly and effectively. Furthermore, there is no notification method that takes into account the user's emotional state, making it difficult to deliver appropriate content or notifications according to the situation. As a result, users may feel stressed or miss important notifications.

[1470] The identification process by the identification processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means. In this invention, the server includes means for collecting information on cyber attacks and information leakage cases by other companies, means for analyzing and classifying the collected information on cyber attacks and information leakage cases by other companies, and means for adjusting the notification content using an emotion engine that recognizes the user's emotions. This makes it possible to quickly reflect the collected information on cyber attacks by other companies in one's own security system and also enables appropriate notifications to be provided according to the user's emotional state.

[1471] "Cyber ​​attacks and information leaks at other companies" refers to specific incidents and examples of cyber attacks and information leaks that have occurred at other companies or organizations.

[1472] "Means of collection" refers to the methods and technologies that allow a server to automatically obtain data on other companies' cyber attacks and information leaks from the Internet or specific sources.

[1473] "Means of analysis and classification" refers to methods and technologies for analyzing information acquired by a server using natural language processing technology, etc., and classifying cyber attacks and information leaks based on their type, scope of impact, etc.

[1474] "Your company's security management system" refers to the entire security policies, settings, measures, etc. that your company or organization has.

[1475] "Means of comparison" refers to methods and technologies for comparing information on cyber attacks and information leaks at other companies with one's own security management system to identify the possibility that one's company may be exposed to similar threats or vulnerabilities.

[1476] "Risk assessment" refers to the process of assessing the risk to a company if it is exposed to the same threats as other companies, based on the likelihood and impact of the threat.

[1477] "Means for proposing countermeasures" refers to methods and technologies by which the server provides specific countermeasures to strengthen the company's security based on the results of risk assessment.

[1478] "Means of notifying users" refers to methods and technologies for communicating the contents of risk assessments and proposed countermeasures to users.

[1479] "Emotion engine" refers to technology that analyzes a user's text input and voice data to recognize the user's emotional state.

[1480] "Means for tailoring notification content" refers to methods and techniques for optimizing the tone and content of notifications based on perceived user sentiment.

[1481] To implement the present invention, the following system configuration and program processing must be executed.

[1482] This system runs on a server and automatically collects and analyzes information on cyber attacks and information leaks from other companies, compares it with the company's own security management system, assesses the risks, proposes countermeasures, and notifies users.It also incorporates an emotion engine that recognizes the user's emotional state, allowing it to adjust the content of notifications according to their emotions.

[1483] Specifically, the server operates as follows.

[1484] Data collection:

[1485] The server collects data on cyber attacks and information leaks by other companies from the internet and specific sources (such as security news sites and industry association reports). This collection process uses external services such as the "Security News API." The information obtained by the server includes the date and time of the incident, the type of attack, the scope of impact, and the cause.

[1486] Information analysis and classification:

[1487] Using natural language processing technology (such as Google Cloud Natural Language API), the information collected by the server is analyzed, and key elements of cyber attacks and data breaches are extracted and classified. The classification process involves tagging the incidents based on their type and scope of impact.

[1488] Checking our management system:

[1489] The server retrieves information about the company's security management system from the database and compares it with incident information collected from other companies. This comparison evaluates whether the company is vulnerable to similar threats. For example, if the company's phishing protection is out of date, this will be identified as a vulnerability.

[1490] Risk Assessment:

[1491] The server performs a risk assessment based on the matching results. The risk assessment calculates a risk score based on the likelihood and impact of the threat. This risk score determines the priority of countermeasures.

[1492] Suggested solutions:

[1493] Based on the results of the risk assessment, the server will propose specific countermeasures, including technical measures (e.g., updating anti-ransomware software and strengthening firewall settings), policy changes (e.g., reviewing access control and implementing data encryption), and employee education (implementing security training).

[1494] Emotion Engine:

[1495] The server obtains the user's emotional data using the Google Cloud Speech-to-Text API and analyzes the user's emotions using an emotion engine. Based on the analysis results, the content of the notification is adjusted. For example, if the user is feeling stressed, the tone of the notification may be softened or additional explanations may be added.

[1496] notification:

[1497] The server notifies the user of the evaluation results and proposed measures. The content of the notification is adjusted by the emotion engine. For example, if the issue is highly urgent, an immediate notification will be sent.

[1498] Examples:

[1499] If the user is in a normal emotional state, the server sends a notification suggesting "installation of the latest email filtering software."

[1500] If the user is in a high-stress state, soften the notification and say, "Start with some simple steps to improve your security."

[1501] Example prompt sentence:

[1502] "I would like to implement a system that collects information on the latest cyber attacks that have occurred at other companies and uses that information to evaluate my own company's security posture. In the process, I would also like to add a function that adjusts the content of notifications based on the user's emotions. I would like advice on how to soften the content of notifications when a user is under high stress."

[1503] By operating in this way, the system suggests effective security measures based on cases at other companies and provides appropriate notifications based on the user's emotional state, allowing the user to receive information at the appropriate time and in the appropriate way.

[1504] The flow of the specific processing in the application example 2 will be described with reference to FIG.

[1505] Step 1:

[1506] The server collects data on cyber attacks and information leaks by other companies from the internet or specific information sources. Specifically, it obtains the latest cyber attack information using a security news API, etc. The input in this case is an API request, and the output is JSON data containing cyber attack information.

[1507] Step 2:

[1508] The cyber attack information collected by the server is analyzed using natural language processing technology. Specifically, the Google Cloud Natural Language API is used to extract important elements from the text data (type of attack, scope of impact, cause, etc.). In this case, the input is the JSON data obtained in step 1, and the output is a list of the analyzed elements.

[1509] Step 3:

[1510] The server classifies the analyzed cyber attack information. Specifically, it sets categories based on the type of attack, the scope of impact, the scale of damage, etc., and classifies the information. In this case, the input is the list of elements extracted in step 2, and the output is a list of classified incidents.

[1511] Step 4:

[1512] The server retrieves information about the company's security controls from a database, specifically data such as firewall settings, access control policies, and employee security training status. The input in this case is a database query, and the output is a list of security control information.

[1513] Step 5:

[1514] The server compares the cyber attack information collected from other companies with the company's own security management system. Specifically, it checks for vulnerabilities in phishing countermeasures, email filtering, employee training, etc. The input in this case is the list of incidents from Step 3 and the list of management system information from Step 4, and the output is a list of vulnerabilities.

[1515] Step 6:

[1516] The server performs a risk assessment based on the company's vulnerability list. Specifically, it calculates a risk score based on the type of threat and gaps in the company's management system. In this case, the input is the vulnerability list from step 5, and the output is the risk assessment results and risk score.

[1517] Step 7:

[1518] The server proposes specific countermeasures based on the results of the risk assessment, such as introducing the latest email filtering software and conducting phishing training for employees. The input in this case is the risk assessment result and risk score from Step 6, and the output is a list of countermeasure proposals.

[1519] Step 8:

[1520] The server acquires the user's emotional data. Specifically, it uses the Google Cloud Speech-to-Text API or similar to acquire the user's voice commands and text input, which are then analyzed by the emotion engine. In this case, the input is the user's voice and text data, and the output is the recognized emotional data.

[1521] Step 9:

[1522] The server adjusts the notification content based on the emotion engine. Specifically, it changes the tone and content of the notification according to the user's emotional state. In this case, the input is the emotion data from step 8 and the countermeasure proposal list from step 7, and the output is the adjusted notification content.

[1523] Step 10:

[1524] The server notifies the user of the evaluation results and proposed countermeasures. Specifically, if the situation is urgent, the server notifies immediately, and if it is normal, the server notifies periodically. In this case, the input is the notification content from step 9, and the output is a notification message to the user.

[1525] The specific processing unit 290 transmits the result of the specific processing to the robot 414. In the robot 414, the control unit 46A causes the speaker 240 and the control target 443 to output the result of the specific processing. The microphone 238 acquires voice indicating a user input regarding the result of the specific processing. The control unit 46A transmits voice data indicating the user input acquired by the microphone 238 to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the voice data.

[1526] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[1527] In the above embodiment, an example in which the specific processing is performed by the data processing device 12 has been given, but the technology of the present disclosure is not limited to this, and the specific processing may be performed by the robot 414.

[1528] The emotion identification model 59 as an emotion engine may determine the user's emotion according to a specific mapping. Specifically, the emotion identification model 59 may determine the user's emotion according to an emotion map (see FIG. 9), which is a specific mapping. Similarly, the emotion identification model 59 may determine the robot's emotion, and the identification processing unit 290 may perform identification processing using the robot's emotion.

[1529] FIG. 9 is a diagram illustrating an emotion map 400 on which multiple emotions are mapped. In the emotion map 400, emotions are arranged in concentric circles radiating from the center. Emotions closer to the center of the concentric circles are more primitive. Emotions representing states and actions arising from a state of mind are arranged on the outer edges of the concentric circles. The concept of emotion includes both affect and mental states. Emotions generally generated from reactions occurring in the brain are arranged on the left side of the concentric circles. Emotions generally induced by situational judgment are arranged on the right side of the concentric circles. Emotions generally generated from reactions occurring in the brain and induced by situational judgment are arranged on the upper and lower sides of the concentric circles. Furthermore, the emotion of "pleasure" is arranged on the upper side of the concentric circles, and the emotion of "discomfort" is arranged on the lower side. In this way, in the emotion map 400, multiple emotions are mapped based on the structure by which emotions are generated, and emotions that tend to occur simultaneously are mapped close to each other.

[1530] These emotions are distributed in the 3 o'clock direction on emotion map 400, and typically fluctuate between relief and anxiety. In the right half of emotion map 400, situational awareness dominates over internal sensations, resulting in a sense of calm.

[1531] The inside of emotion map 400 represents what is going on in the mind, and the outside of emotion map 400 represents behavior, so the further you go outside emotion map 400, the more visible the emotions become (the more they are expressed in behavior).

[1532] Human emotions are based on various balances, such as posture and blood sugar levels. When these balances deviate from the ideal, a state of discomfort is indicated, and when they approach the ideal, a state of pleasure is indicated. Emotions can also be created for robots, automobiles, and motorcycles, based on various balances, such as posture and remaining battery life. When these balances deviate from the ideal, a state of discomfort is indicated, and when they approach the ideal, a state of pleasure is indicated. An emotion map can be generated, for example, based on Dr. Mitsuyoshi's emotion map (Research on Voice Emotion Recognition and Emotional Brain Physiological Signal Analysis Systems, Tokushima University, Doctoral Dissertation: https: / / ci.nii.ac.jp / naid / 500000375379). The left half of the emotion map lists emotions belonging to the "reaction" domain, where sensation is dominant. The right half of the emotion map lists emotions belonging to the "situation" domain, where situational awareness is dominant.

[1533] The emotion map defines two emotions that promote learning. One is a negative emotion on the situation side, around the middle of "repentance" or "reflection." In other words, this occurs when the robot experiences negative emotions such as "I never want to feel this way again" or "I don't want to be scolded again." The other is a positive emotion on the response side, around "desire." In other words, this occurs when the robot experiences positive feelings such as "I want more" or "I want to know more."

[1534] The emotion identification model 59 inputs user input into a pre-trained neural network, obtains emotion values ​​indicating each emotion shown in the emotion map 400, and determines the user's emotion. This neural network is pre-trained based on multiple pieces of training data that are combinations of user input and emotion values ​​indicating each emotion shown in the emotion map 400. Furthermore, this neural network is trained so that emotions that are located close to each other have similar values, as in the emotion map 900 shown in FIG. 10. FIG. 10 shows an example in which multiple emotions, "relieved," "calm," and "reassuring," have similar emotion values.

[1535] The system according to the present disclosure has been described above mainly with respect to the functions of the data processing device 12, but the system according to the present disclosure is not necessarily implemented on a server. The system according to the present disclosure may be implemented as a general information processing system. The present disclosure may be implemented, for example, as a software program running on a personal computer or an application running on a smartphone, etc. The method according to the present disclosure may be provided to users in the form of SaaS (Software as a Service).

[1536] In the above embodiment, an example was given in which the specific processing is performed by one computer 22, but the technology of the present disclosure is not limited to this, and the specific processing may be distributed and performed by a plurality of computers including the computer 22. For example, the data generation model 58 may be provided in an external device of the data processing device 12, and data may be generated in the external device in accordance with input data.

[1537] In the above embodiment, an example in which the specific processing program 56 is stored in the storage 32 has been described, but the technology of the present disclosure is not limited to this. For example, the specific processing program 56 may be stored in a portable, computer-readable, non-transitory storage medium such as a USB (Universal Serial Bus) memory. The specific processing program 56 stored in the non-transitory storage medium is installed in the computer 22 of the data processing device 12. The processor 28 executes the specific processing in accordance with the specific processing...

Claims

1. A means of collecting information on cyber attacks and information leaks at other companies, A means of analyzing and classifying collected cyber attacks and information leaks from other companies, A means of verifying the collected information against your company's security management system, and a means for performing a risk assessment based on the matching results; A means of proposing countermeasures based on the results of the risk assessment; means for notifying a user of the content of the risk assessment and the proposed measures; A system including:

2. The system according to claim 1, wherein the analysis means analyzes the collected cyber attacks and information leak cases of other companies using natural language processing technology.

3. The system of claim 1 , wherein the risk assessment means calculates a risk score based on the type of threat and gaps in the company's management system.

Citation Information

Patent Citations

  • Persona chatbot control method and system

    JP2022180282A