System
The advanced cybersecurity system uses generative AI to automate security measures, encrypt data, detect threats in real-time, and provide customized solutions, addressing the challenges of modern cyber threats and enhancing corporate security.
Patent Information
- Application Number
- JP2024118250
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-07-23
- Publication Date
- 2026-02-04
AI Technical Summary
Modern companies face sophisticated cyber threats that traditional static security measures struggle to respond to quickly, lacking real-time threat identification and customized security solutions, especially for small and medium-sized enterprises with limited resources.
An advanced cybersecurity system utilizing generative AI models to automate security countermeasures, encrypt user information, detect threats in real-time, generate alerts, identify threat types, and provide customized security solutions tailored to each company's needs.
Enables rapid response to cyber threats, secure management of user information, real-time threat detection, and optimized security measures, providing comprehensive protection for corporate information systems.
Smart Images

Figure 2026017468000001_ABST
Abstract
Description
[Technical Field]
[0001] The technology of the present disclosure relates to a system. [Background technology]
[0002] Patent document 1 discloses a persona chatbot control method performed by at least one processor, the method including the steps of receiving a user utterance, adding the user utterance to a prompt including an instruction sentence related to a description of the chatbot character, encoding the prompt, and inputting the encoded prompt into a language model to generate a chatbot utterance in response to the user utterance. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Publication No. 2022-180282 Summary of the Invention [Problem to be solved by the invention]
[0004] Modern companies are facing increasingly sophisticated cyber threats as information technology advances. This makes it difficult for traditional static security measures to respond quickly to new attack methods. Many companies, including small and medium-sized enterprises, need to implement advanced security measures with limited resources, but this is not easy. Furthermore, they lack the ability to identify threats in real time and take immediate countermeasures. This creates a demand for automated security measures, real-time threat analysis, and security solutions tailored to corporate needs. [Means for solving the problem]
[0005] To solve the above problems, the present invention provides a system having the following features: It includes a means for automating security countermeasures based on the generated protocols, thereby enabling a rapid response to new attacks. It also includes a means for encrypting and securely storing information from users, thereby reducing the risk of information leaks. It also includes a means for detecting threats in real time and generating alerts, allowing for immediate countermeasures. It includes a means for identifying the type of threat and selecting and executing appropriate defensive measures, thereby enabling effective neutralization of the threat. Finally, it includes a means for generating security solutions customized based on the needs of each company, allowing for the provision of optimal security countermeasures for each company. This configuration allows companies of all sizes to easily implement advanced cybersecurity countermeasures.
[0006] In cybersecurity, a "generated protocol" refers to the procedures and rules for security measures that are automatically created by a generative AI model.
[0007] "Security measures" refer to specific measures and actions taken to protect information systems from cyber threats.
[0008] "User information" refers to data such as personal information and account information about system users.
[0009] "Encryption" is a technology that converts data based on specific rules, making the contents incomprehensible to third parties.
[0010] "Real-time" refers to data and events being processed and responded to almost immediately as they occur.
[0011] A "threat" is any factor or action that could potentially lead to an attack or unauthorized access to an information system.
[0012] An "alert" is a message or signal that warns or notifies a system or user.
[0013] "Defense measures" are specific countermeasures or responses taken against detected threats.
[0014] A "customized security solution" is a method of providing security measures that are tailored to the needs and circumstances of a specific company or user.
[0015] A "generative AI model" is an artificial intelligence that autonomously learns from data and generates new patterns and countermeasures.
[0016] A "database" is a system or structure for systematically storing and managing information.
[0017] "Corporate needs" refer to the requirements and required security levels of a particular company. [Brief explanation of the drawings]
[0018] [Figure 1] 1 is a conceptual diagram showing an example of the configuration of a data processing system according to a first embodiment. [Figure 2] 1 is a conceptual diagram showing an example of main functions of a data processing device and a smart device according to a first embodiment. [Figure 3] FIG. 10 is a conceptual diagram showing an example of the configuration of a data processing system according to a second embodiment. [Figure 4] FIG. 10 is a conceptual diagram showing an example of main functions of a data processing device and smart glasses according to a second embodiment. [Figure 5] FIG. 10 is a conceptual diagram showing an example of the configuration of a data processing system according to a third embodiment. [Figure 6] FIG. 11 is a conceptual diagram showing an example of main functions of a data processing device and a headset-type terminal according to a third embodiment. [Figure 7] FIG. 10 is a conceptual diagram showing an example of the configuration of a data processing system according to a fourth embodiment. [Figure 8] FIG. 10 is a conceptual diagram showing an example of main functions of a data processing device and a robot according to a fourth embodiment. [Figure 9] 1 shows an emotion map onto which multiple emotions are mapped. [Figure 10] 1 shows an emotion map onto which multiple emotions are mapped. [Figure 11] FIG. 3 is a sequence diagram showing a processing flow of the data processing system according to the first embodiment. [Figure 12] FIG. 10 is a sequence diagram showing the flow of processing in the data processing system in Application Example 1. [Figure 13] FIG. 10 is a sequence diagram showing the flow of processing in the data processing system according to the second embodiment when an emotion engine is combined. [Figure 14] FIG. 10 is a sequence diagram showing the flow of processing in the data processing system in Application Example 2 when an emotion engine is combined. DETAILED DESCRIPTION OF THE INVENTION
[0019] An example of an embodiment of a system according to the technology of the present disclosure will be described below with reference to the accompanying drawings.
[0020] First, the terms used in the following description will be explained.
[0021] In the following embodiments, a coded processor (hereinafter simply referred to as a "processor") may be a single arithmetic device or a combination of multiple arithmetic devices. Furthermore, a processor may be a single type of arithmetic device or a combination of multiple types of arithmetic devices. Examples of arithmetic devices include a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), a GPGPU (General-Purpose computing on Graphics Processing Units), and an APU (Accelerated Processing Unit).
[0022] In the following embodiments, a coded RAM (Random Access Memory) is a memory in which information is temporarily stored and is used as a working memory by a processor.
[0023] In the following embodiments, the coded storage is one or more non-volatile storage devices that store various programs, various parameters, etc. Examples of non-volatile storage devices include flash memory (SSD (Solid State Drive)), magnetic disks (e.g., hard disks), and magnetic tapes.
[0024] In the following embodiments, a communication I / F (Interface) with a symbol is an interface including a communication processor, an antenna, etc. The communication I / F controls communication between multiple computers. Examples of communication standards applied to the communication I / F include wireless communication standards including 5G (5th Generation Mobile Communication System), Wi-Fi (registered trademark), Bluetooth (registered trademark), etc.
[0025] In the following embodiments, "A and / or B" is synonymous with "at least one of A and B." In other words, "A and / or B" means that it may be only A, only B, or a combination of A and B. Furthermore, in this specification, the same concept as "A and / or B" is also applied when three or more things are expressed connected by "and / or."
[0026] [First embodiment]
[0027] FIG. 1 shows an example of the configuration of a data processing system 10 according to the first embodiment.
[0028] 1, a data processing system 10 includes a data processing device 12 and a smart device 14. An example of the data processing device 12 is a server.
[0029] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0030] The smart device 14 includes a computer 36, a reception device 38, an output device 40, a camera 42, and a communication I / F 44. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The reception device 38, the output device 40, and the camera 42 are also connected to the bus 52.
[0031] The reception device 38 includes a touch panel 38A, a microphone 38B, and the like, and receives user input. The touch panel 38A detects contact with an indicator (for example, a pen or a finger) to receive user input by the touch of the indicator. The microphone 38B detects the user's voice to receive user input by voice. The control unit 46A transmits data indicating the user input received by the touch panel 38A and the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the data indicating the user input.
[0032] The output device 40 includes a display 40A and a speaker 40B, and presents data to the user 20 by outputting the data in a form of expression that the user 20 can perceive (for example, audio and / or text). The display 40A displays visible information such as text and images in accordance with instructions from the processor 46. The speaker 40B outputs audio in accordance with instructions from the processor 46. The camera 42 is a compact digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor.
[0033] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 control the exchange of various information between the processor 46 and the processor 28 via the network 54.
[0034] FIG. 2 shows an example of the main functions of the data processing device 12 and the smart device 14.
[0035] 2, in the data processing device 12, a specific process is performed by the processor 28. A specific processing program 56 is stored in the storage 32. The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific process is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[0036] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[0037] In the smart device 14, the processor 46 performs the reception output process. The storage 50 stores a reception output program 60. The reception output program 60 is used in conjunction with the specific processing program 56 by the data processing system 10. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.
[0038] Next, a description will be given of the specific processing performed by the specific processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."
[0039] The present invention relates to an advanced cybersecurity system that uses generative AI models to predict and neutralize cyber threats, providing a set of automated security measures to protect enterprise information systems.
[0040] Specifically, the main components of the system are as follows: Users enter basic information (such as name, email address, and password) into a sign-up form and send it to the server. The server receives this information, encrypts it, and stores it securely in a database. This prevents user information from being leaked.
[0041] The server then collects security-related data provided by the company and sends it to the generative AI model, which analyzes the input data and generates the optimal security protocol for the company. The server then provides this protocol to the company and assists with its implementation.
[0042] The device also collects real-time log data on user activity and system events and sends it to the server. The server analyzes this data, identifies threats in real time, and issues alerts to users as needed. For example, if abnormal access or unauthorized file operations are detected, the server can immediately issue an alert and prompt a prompt response.
[0043] The server also identifies the type of threat detected and selects and implements appropriate defense measures. For example, if malware is detected, the server quarantines the file and removes it from the system. It also logs the defense actions taken and their results.
[0044] Finally, the server evaluates each company's individual needs and generates a customized security solution based on them. This provides security measures optimized for each company's specific environment and requirements. For example, companies with high security requirements can be offered special measures such as dual authentication and access restrictions from specific IP addresses.
[0045] As described above, the system of the present invention can provide a high level of protection for corporate information systems by providing secure management of user information, real-time threat detection, rapid response to threats, and customized security solutions.
[0046] The processing flow will be explained below.
[0047] User Registration and Authentication Process
[0048] Step 1:
[0049] A user fills out a sign-up form with basic information such as name, email address, and password.
[0050] Step 2:
[0051] The server receives the input data and temporarily stores the information sent by the user.
[0052] Step 3:
[0053] The server encrypts the data. The server encrypts the user information using the SSL / TLS protocol.
[0054] Step 4:
[0055] The server stores the encrypted data in a database. The server stores the encrypted user information securely in a database.
[0056] Security Protocol Generation Process
[0057] Step 1:
[0058] The server collects security-related data from the company. The server receives data provided by the company.
[0059] Step 2:
[0060] The server sends the data to the generative AI model. The server inputs the company data into the generative AI model and begins analysis.
[0061] Step 3:
[0062] The server receives the analysis results of the generative AI model and obtains the security protocol proposal created by the AI model.
[0063] Step 4:
[0064] The server provides the optimal security protocol to the enterprise, and then proposes the generated protocol to the enterprise and prepares to implement it.
[0065] Real-time threat analysis process
[0066] Step 1:
[0067] The device collects log data. The device collects logs of user activity and system events in real time.
[0068] Step 2:
[0069] The terminal sends the log data to the server. The terminal periodically sends the collected log data to the server.
[0070] Step 3:
[0071] The server analyzes the received data. The server analyzes the received log data using an AI model to detect anomalies.
[0072] Step 4:
[0073] The server detects anomalies and issues an alert to the user. The server notifies the user of the detected threat information.
[0074] Threat Neutralization Process
[0075] Step 1:
[0076] The server identifies the type of threat. The server identifies what kind of threat has been detected.
[0077] Step 2:
[0078] The server selects the defense measures. The server uses a generative AI model to select the defense measures that are most appropriate for the threat.
[0079] Step 3:
[0080] The server executes the defensive action. The server immediately executes the selected defensive measures to protect the system.
[0081] Step 4:
[0082] The server records the actions taken. The server logs the defensive actions taken and their results.
[0083] Customized Security Solution Proposal Process
[0084] Step 1:
[0085] The server assesses the company's needs. The server assesses the security needs from the data provided by the company.
[0086] Step 2:
[0087] The server generates a customized solution: The server uses the AI model to generate a customized security solution that meets the company's needs.
[0088] Step 3:
[0089] The server proposes solutions to companies. The server proposes the customized solutions it has created to companies.
[0090] Through the above processing steps, CyberSecure can provide comprehensive and advanced cybersecurity services to businesses.
[0091] Example 1
[0092] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."
[0093] Current cybersecurity systems have difficulty efficiently detecting threats in real time and implementing appropriate defensive measures. Furthermore, they are not sufficiently customized to meet the unique security needs of each company, leaving security flaws vulnerable to failure. The purpose of this invention is to solve these problems and provide advanced protection for corporate information systems.
[0094] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.
[0095] In this invention, the server includes means for encrypting and storing information from users, means for collecting security data provided by companies and sending it to an analysis model, means for generating security protocols optimal for the companies based on the analyzed data, means for collecting log data of user activities and system events in real time and sending it to a central processing unit, means for detecting threats in real time and generating alerts, means for identifying the type of threat and selecting and executing appropriate defensive measures, and means for generating security solutions customized based on the needs of the companies, thereby enabling secure management of user information, real-time threat detection, rapid response to threats, and security measures optimized for each company.
[0096] "User information" refers to basic information such as name, email address, and password that a user provides to the system.
[0097] "Encryption" is the process of converting data using a specific algorithm to make it unreadable to third parties in order to protect it from unauthorized access.
[0098] "Security data" refers to security-related information such as firewall logs and access logs provided by companies.
[0099] An "analytical model" is a mathematical algorithm or machine learning model used to analyze data, such as a generative AI model.
[0100] A "security protocol" is a set of security rules and procedures established to protect a company's information systems.
[0101] An "activity log" is a record of operations and events that occur when a user uses a system.
[0102] A "central processing unit" is the system's main computer that collects and analyzes data, identifies threats, and generates alerts.
[0103] "Threat detection" refers to the analysis of security data and other information to identify security risks and abnormal behavior in a system.
[0104] "Defense measures" are specific countermeasures or action steps taken against detected threats.
[0105] A "customized security solution" is a security measure that is optimized to meet the specific needs of each company.
[0106] The present invention is an advanced cybersecurity system that uses generative AI models to predict and neutralize cyber threats, and provides a set of automated security measures to protect enterprise information systems. Specific embodiments of the present invention are described in detail below.
[0107] Collecting and storing user information
[0108] First, a user enters basic information such as name, email address, and password into the sign-up form and submits the form data. The server receives the information submitted by the user and encrypts the data using the AES-256 algorithm. The encrypted data is securely stored in a MySQL database. This prevents user information from being leaked.
[0109] Examples:
[0110] Text format
[0111] When a user enters their information into the sign-up form and hits the submit button, the information is transferred to the server, which encrypts the data using the AES-256 algorithm and stores it in a MySQL database.
[0112] Security data collection and analysis
[0113] Corporate security administrators provide security data such as firewall logs and access logs. The server collects the security data and sends it to the generative AI model. The generative AI model analyzes the data using Python and TensorFlow and generates optimal security protocols for the company. These protocols are then sent to the corporate security officer via the server, who assists with implementation.
[0114] Examples:
[0115] Text format
[0116] The server collects security data provided by the company and analyzes it using an AI model built with TensorFlow. As a result, optimal security protocols are generated and notified to the company's security personnel.
[0117] Real-time activity and event logging
[0118] User devices collect activity data and system event logs in real time. Syslog is used for this log collection. The collected log data is sent to a server, which analyzes it in real time to identify abnormal behavior and security threats. Alerts are sent to users and security personnel as needed.
[0119] Examples:
[0120] Text format
[0121] Using Syslog, terminals collect user activity logs and system event logs in real time and send them to the server, which analyzes them instantly and issues alerts as soon as an abnormality is detected.
[0122] Detecting threats and taking preventative measures
[0123] When the server detects a threat, it identifies the type of threat and selects the appropriate defense measures. For example, if malware is detected, the server uses anti-malware software (ClamAV) to quarantine and delete the file. It also records the defense measures taken and their results in a detailed log.
[0124] Examples:
[0125] Text format
[0126] If the server detects a threat, it will take the necessary defensive measures. For example, if ClamAV detects malware, it will quarantine and delete the file. It will then record the defensive measures taken and the results in a detailed log.
[0127] Creating a customized security solution
[0128] The server assesses each company's individual needs and generates a customized security solution based on those needs, such as dual authentication (e.g., authentication applications) or restricting access from specific IP addresses, providing security measures optimized for each company's specific environment and requirements.
[0129] Examples:
[0130] Text format
[0131] Our server assesses your company's specific needs and generates customized security solutions, such as using authentication applications for double authentication and recommending settings to allow access only from specific IP addresses. We then assist you in implementing these solutions.
[0132] This system enables secure management of user information, real-time threat detection, rapid response to threats, and customized security solutions tailored to individual needs, thereby providing advanced protection for corporate information systems.
[0133] The flow of the identification process in the first embodiment will be described with reference to FIG.
[0134] Step 1:
[0135] A user enters basic information into a sign-up form (such as name, email address, and password). The entered data is sent from the device to the server by clicking the submit button. Specifically, the user enters information into a form and presses the "Submit" button.
[0136] Input: User information such as name, email address, and password
[0137] Output: HTTP request with user information
[0138] Step 2:
[0139] The server receives the information sent by the user, encrypts it using the AES-256 algorithm, and securely stores the encrypted data in a database. Specifically, the server receives an HTTP request, performs encryption processing, and then stores the encrypted data in a database.
[0140] Input: HTTP request containing user information
[0141] Output: Encrypted user information
[0142] Step 3:
[0143] A company's security administrator provides the system with security data such as firewall logs and access logs. The server collects this security data and sends it to the generative AI model. After collecting the data, the server transmits it to the AI model and prepares it for analysis.
[0144] Input: Security data (firewall logs, access logs, etc.)
[0145] Output: Security data formatted in a parsable format
[0146] Step 4:
[0147] The generative AI model analyzes the collected data using Python and TensorFlow and generates the optimal security protocol for the company. The server receives the analysis results and notifies the company's security personnel. Specifically, the generative AI model analyzes the data and returns the analysis results to the server.
[0148] Input: Formatted security data
[0149] Output: Best security protocols for businesses
[0150] Step 5:
[0151] The terminal collects user activity logs and system event logs in real time and sends them to the server. The terminal uses Syslog to collect log data and transmits it to the server.
[0152] Input: User activity log, system event log
[0153] Output: Collected log data
[0154] Step 6:
[0155] The server analyzes the received log data in real time to identify abnormal behavior and security threats, and issues alerts to users and security personnel as needed. The server analyzes the log data and generates notifications if an alert condition is met.
[0156] Input: Collected log data
[0157] Output: Threat detection results, alert notifications
[0158] Step 7:
[0159] The server identifies the type of threat detected and selects and executes appropriate defense measures. For example, if malware is detected, the server uses anti-malware software (ClamAV) to quarantine and delete the file. It also records the defense measures taken and their results in a detailed log.
[0160] Input: Threat detection results
[0161] Output: Defense measures execution results, detailed log
[0162] Step 8:
[0163] The server evaluates a company's individual needs and generates and provides customized security solutions based on those needs. Specific solutions include dual authentication and restricting access from specific IP addresses. Support for the implementation of these solutions is also provided.
[0164] Input: Corporate security needs
[0165] Output: Customized security solutions
[0166] (Application example 1)
[0167] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."
[0168] Conventional cybersecurity systems face problems such as insufficient real-time threat detection and appropriate countermeasures. Delays in detecting and countering malicious activity on mobile devices, in particular, pose a high risk of compromising security. It is also difficult to provide customized security solutions that address the unique needs of each company. There is a need to solve these problems and achieve advanced security.
[0169] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.
[0170] In this invention, the server includes means for automating security countermeasures based on the generated protocol, means for encrypting and storing information from a user, means for detecting threats in real time and generating alerts, means for identifying the type of threat and selecting and executing appropriate defensive measures, means for generating customized security solutions based on the needs of a company, means for collecting real-time activity logs of mobile devices and detecting unauthorized activity using a generative model, and means for issuing alerts for detected threats and executing necessary measures, thereby enabling real-time threat detection and countermeasures in a variety of environments including mobile devices.
[0171] "Generated protocols" refer to the procedures and rules for security measures created by a generative AI model.
[0172] "Means for automating security measures" refers to mechanisms that automatically execute defensive actions against threats based on the generated protocols.
[0173] "Means for encrypting and storing information" refers to a mechanism for securely storing information provided by users using encryption technology.
[0174] "Means for detecting threats and generating alerts in real time" refers to a mechanism that monitors abnormal activity within the system in real time, detects threats, and immediately issues an alert.
[0175] "Means for identifying the type of threat and selecting and implementing appropriate defensive measures" refers to a mechanism for determining the most appropriate defensive measures based on the characteristics of the identified threat and implementing them.
[0176] "Means for generating customized security solutions based on the needs of an enterprise" refers to methods and technologies that provide optimized security measures tailored to each enterprise's specific requirements and environment.
[0177] "Means for collecting real-time activity logs of mobile devices" refers to a mechanism for collecting activity logs of mobile information devices in real time.
[0178] "Means for detecting fraudulent activity using generative models" refers to techniques and methods that use generative models to identify fraudulent behavior from log data.
[0179] "Means of issuing alerts for detected threats and taking necessary measures" refers to a mechanism that issues warnings to users and administrators about detected threats and takes defensive measures as necessary.
[0180] The present invention is an advanced cybersecurity system that uses generative AI models to securely manage user information, detect threats in real time, respond quickly, and provide customized security solutions.
[0181] The main components of the system are as follows: Users use a sign-up form to enter their basic information (such as name, email address, and password) and send it to the server. The server receives this information, encrypts it using Fernet encryption technology, and securely stores it in a database. This prevents user information from being leaked.
[0182] A specific example of how we ensure data security is the process of encrypting and storing the basic information a user provides when signing up. For example, if a user provides the name "Yamada Taro" and the email address "taro@example.com," the server will encrypt and store this information.
[0183] The server then collects security-related data provided by the company and sends it to the generative AI model, which analyzes the data and generates optimal security protocols for the company. The server then provides these protocols to the company and assists with their implementation.
[0184] In addition, mobile devices collect activity logs in real time and send them to a server. The server analyzes this log data and uses generative models to detect malicious activity. For example, if access from an abnormal IP address or unauthorized file operations is detected, the server can immediately send an alert and prompt a response.
[0185] As a specific example, consider the case where an access from an unknown IP address is detected in the event log of a smartphone. In this case, the server immediately issues an alert and takes measures to quarantine the relevant file or activity. An example of a prompt for this process could be as follows:
[0186] text
[0187] Use the following log data to detect unauthorized activity:
[0188] Log data: "2023-11-01T12:34:56Z, Access from unknown IP address, Unauthorized modification of file 'example.exe'"
[0189] Expected result: Issue an alert and take action on access from unknown IP addresses and modification of the file 'example.exe' as suspicious.
[0190] The server then takes appropriate defensive measures against detected threats. For example, if malware is found, the server quarantines the file and removes it from the system. It also logs the defensive actions taken and their results.
[0191] Furthermore, the server generates customized security solutions based on each company's specific environment and needs, providing security measures optimized for each company's requirements. For example, for companies with high security requirements, special measures such as dual authentication and access restrictions from specific IP addresses can be proposed.
[0192] As described above, the system of the present invention encrypts user information, detects threats in real time, sends prompt alerts about fraudulent activity, and provides customized security solutions based on the needs of the company, thereby providing a high level of protection for the company's information systems.
[0193] The flow of the specific processing in the application example 1 will be described with reference to FIG.
[0194] (Program processing flow)
[0195] Step 1:
[0196] The user enters basic information (name, email address, password) into the sign-up form and submits it to the server.
[0197] Specifically, a user enters information into a form on a smartphone or computer screen and clicks the "Submit" button. The input data includes the user's name, email address, and password. This data is sent to the server as output.
[0198] Step 2:
[0199] The basic information received by the server is encrypted using encryption technology (Fernet) and stored in a secure database.
[0200] The server takes the data received from the user and encrypts it using Fernet. Specifically, it generates an encryption key and encrypts the user data. As an output, the encrypted data is stored in a secure database.
[0201] Step 3:
[0202] The server collects security-related data provided by companies and sends it to a generative AI model.
[0203] The server receives data on the company's security logs and system status and sends it to the generative AI model. Specifically, the data format is converted and any necessary preprocessing is performed before being input into the generative AI model. This data processing generates the optimal security protocol for the company.
[0204] Step 4:
[0205] The server provides companies with security protocols generated by the AI model and assists them in implementing them.
[0206] The server notifies the company administrator of the generated protocol and provides specific implementation procedures. The output is a textual description of the protocol and an implementation guide, which are optimized to meet the requirements of each company, ensuring smooth implementation.
[0207] Step 5:
[0208] The mobile device collects activity logs in real time and sends them to the server.
[0209] Specifically, the terminal monitors system logs and user actions, and periodically uploads the data to the server. Real-time log data is collected as input and sent to the server as output.
[0210] Step 6:
[0211] The server analyzes the log data and uses generative models to detect fraudulent activity.
[0212] The server analyzes the received log data in real time and performs anomaly detection using a generative AI model. Specifically, it analyzes IP addresses and user actions contained in the log data to identify anomalies. The output is a list of suspicious activity.
[0213] Step 7:
[0214] The server will send out an alert for any detected threats and take necessary measures.
[0215] Specifically, when an anomaly is detected, an alert is sent, and the relevant file is quarantined or access is blocked. Information about malicious activity is obtained as input, and alert notifications and countermeasures are executed as output.
[0216] Step 8:
[0217] The server logs the actions and results of detecting and preventing threats.
[0218] The server keeps a detailed record of the defensive actions taken and their results, stored in a secure database. Specific actions include logging the success / failure of the action and the next steps. As an output, the complete defensive log is stored in the database.
[0219] Furthermore, an emotion engine that estimates the user's emotion may be combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59 and perform identification processing using the user's emotion.
[0220] The present invention relates to an advanced cybersecurity system that uses generative AI models to predict and neutralize cyber threats. Additionally, the present invention is combined with an emotion engine that recognizes user emotions and adjusts security measures based on the user's psychological state.
[0221] Basic System Configuration
[0222] User Registration and Authentication Process
[0223] Users enter basic information such as name, email address, and password into a sign-up form and submit it. The server receives this data, encrypts it, and stores it securely in a database. This process prevents user information from being leaked.
[0224] Security Protocol Generation
[0225] The server collects security-related data provided by the company and sends it to the generative AI model, which analyzes the data and generates a security protocol that is optimal for the company. The server then provides this protocol to the company and assists with its implementation.
[0226] Real-time Threat Analysis
[0227] The device collects log data on user activity and system events in real time and sends it to the server. The server analyzes this data, identifies threats in real time, and issues alerts to the user as needed. For example, if abnormal access or unauthorized file operations are detected, the server can immediately issue an alert and prompt a prompt response.
[0228] Neutralizing the threat
[0229] The server identifies the type of threat detected and selects and implements appropriate defense measures. For example, if malware is detected, the server quarantines the file and deletes it from the system. It also logs the defense actions taken and their results.
[0230] Customized Security Solutions
[0231] The server evaluates the individual needs of each company and generates customized security solutions based on them. For example, for companies with high security requirements, it can propose special measures such as dual authentication and restricting access from specific IP addresses.
[0232] Adding an Emotion Engine
[0233] Emotion recognition and stress assessment
[0234] By introducing an emotion engine, the system can recognize users' emotions in real time and analyze the data. For example, when a user logs into the system, the emotion engine can assess the user's stress level by analyzing their facial expressions and tone of voice using a camera or microphone.
[0235] Adjusting security measures based on emotions
[0236] The server adjusts security measures based on the user's emotions identified by the emotion engine. For example, if a user is in a state of high stress, the server can implement measures such as limiting the number of login attempts or providing extra careful monitoring.
[0237] Abnormal emotional change monitoring and alerts
[0238] The emotion engine monitors the user's emotional changes in real time, and if an abnormal emotional change (such as sudden anxiety or anger) is detected, the server immediately issues an alert, enabling early detection and response to internal threats and social engineering attacks.
[0239] Specific examples
[0240] For example, if the emotion engine detects that a company employee is feeling stressed at work, the server will temporarily restrict the employee's system access and send an alert to an administrator if an abnormality is detected. Also, if the user's facial expression is unusual, additional authentication measures will be used to prevent unauthorized access.
[0241] As described above, by combining a generative AI model and an emotion engine, the present invention enables real-time, multi-layered security measures and provides advanced protection for corporate information systems.
[0242] The processing flow will be explained below.
[0243] Basic System Configuration
[0244] User Registration and Authentication Process
[0245] Step 1:
[0246] A user fills out a sign-up form with basic information such as name, email address, and password.
[0247] Step 2:
[0248] The server receives the input data and temporarily stores the information sent by the user.
[0249] Step 3:
[0250] The server encrypts the data. The server encrypts the user information using the SSL / TLS protocol.
[0251] Step 4:
[0252] The server stores the encrypted data in a database. The server stores the encrypted user information securely in a database.
[0253] Security Protocol Generation Process
[0254] Step 1:
[0255] The server collects security-related data from the company. The server receives data provided by the company.
[0256] Step 2:
[0257] The server sends the data to the generative AI model. The server inputs the company data into the generative AI model and begins analysis.
[0258] Step 3:
[0259] The server receives the analysis results of the generative AI model and obtains the security protocol proposal created by the AI model.
[0260] Step 4:
[0261] The server provides the optimal security protocol to the enterprise, and then proposes the generated protocol to the enterprise and prepares to implement it.
[0262] Real-time threat analysis process
[0263] Step 1:
[0264] The device collects log data. The device collects logs of user activity and system events in real time.
[0265] Step 2:
[0266] The terminal sends the log data to the server. The terminal periodically sends the collected log data to the server.
[0267] Step 3:
[0268] The server analyzes the received data. The server analyzes the received log data using an AI model to detect anomalies.
[0269] Step 4:
[0270] The server detects anomalies and issues an alert to the user. The server notifies the user of the detected threat information.
[0271] Threat Neutralization Process
[0272] Step 1:
[0273] The server identifies the type of threat. The server identifies what kind of threat has been detected.
[0274] Step 2:
[0275] The server selects the defense measures. The server uses a generative AI model to select the defense measures that are most appropriate for the threat.
[0276] Step 3:
[0277] The server executes the defensive action. The server immediately executes the selected defensive measures to protect the system.
[0278] Step 4:
[0279] The server records the actions taken. The server logs the defensive actions taken and their results.
[0280] Customized Security Solution Proposal Process
[0281] Step 1:
[0282] The server assesses the company's needs. The server assesses the security needs from the data provided by the company.
[0283] Step 2:
[0284] The server generates a customized solution: The server uses the AI model to generate a customized security solution that meets the company's needs.
[0285] Step 3:
[0286] The server proposes solutions to companies. The server proposes the customized solutions it has created to companies.
[0287] Adding an Emotion Engine
[0288] Emotion recognition and stress appraisal processes
[0289] Step 1:
[0290] When a user logs in to the system, the device uses a camera and microphone to collect the user's facial expressions and tone of voice.
[0291] Step 2:
[0292] The device sends the collected data to the emotion engine, which analyzes the user's emotions.
[0293] Step 3:
[0294] The emotion engine evaluates the user's stress level and sends the results to the server.
[0295] Step 4:
[0296] The server adjusts security measures based on the evaluation results of the emotion engine. If the user is in a high stress state, additional security measures are implemented.
[0297] The process of adjusting security measures based on emotions
[0298] Step 1:
[0299] The server receives the evaluation results of the emotion engine and grasps the user's emotional state.
[0300] Step 2:
[0301] The server dynamically changes security settings based on the evaluation results, for example requiring additional authentication measures for users in high stress states.
[0302] Step 3:
[0303] The server executes the changed security settings and applies the configured security measures to the entire system.
[0304] Monitoring and alerting for abnormal emotional changes
[0305] Step 1:
[0306] The device monitors the user's emotional changes in real time by continuously collecting facial expressions and tone of voice.
[0307] Step 2:
[0308] The device sends the collected data to the emotion engine, which analyzes changes in emotions.
[0309] Step 3:
[0310] If the emotion engine detects an abnormal change in emotion, it sends that information to the server.
[0311] Step 4:
[0312] The server issues an alert based on abnormal emotional changes, and the server promptly notifies the administrator and takes appropriate measures.
[0313] Through these processing steps, CyberSecure's system combines generative AI models and emotion engines to provide real-time, multi-layered security measures to highly protect enterprise information systems.
[0314] Example 2
[0315] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."
[0316] As cyber attacks become more sophisticated and diverse, the information security of companies and individuals is threatened, making it difficult to respond adequately with traditional, fixed security measures. Furthermore, while it is known that users' psychological state affects security, the adoption of security measures based on this has been sparse. To solve these problems, a system is needed that enables real-time, advanced threat analysis and security measures based on users' emotional state.
[0317] The specific processing by the specific processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means.
[0318] In this invention, the server includes means for receiving information provided by users, encrypting it, and storing it in a database, means for detecting threats in real time and generating alerts, means for identifying the type of detected threat and selecting and implementing appropriate defensive measures, means for generating customized security solutions based on corporate needs, means for generating security protocols using the generated AI model and automating security measures based on the protocols, means for recognizing user emotions, analyzing the data, and adjusting security measures based on the emotional state, and means for monitoring abnormal emotional changes and issuing an alert when an abnormality is detected. This enables multi-layered security measures in real time, thereby providing advanced protection for corporate and individual information security.
[0319] "User-Provided Information" refers to your name, email address, password, and other personally identifiable information that you enter into the System.
[0320] "Encryption" refers to the process of converting information provided by a user using a specific algorithm to make it unreadable to third parties in order to protect it from unauthorized access or disclosure.
[0321] A "database" refers to an information system that organizes and stores user information and various data within the system, allowing it to be quickly searched and retrieved as needed.
[0322] "Real-time threat detection" refers to the process of continuously monitoring user activity and system events to immediately identify cyber threats, such as abnormal behavior or unauthorized access.
[0323] "Alert" refers to a warning message or notification system that promptly notifies users of detected threats.
[0324] "Threat type identification" refers to the process of identifying the type of cyber threat a detected threat falls into, such as malware, unauthorized access, or phishing.
[0325] "Defensive measures" refer to specific measures or actions that should be taken against identified threats, such as isolating or deleting files or restricting access.
[0326] A "customized security solution" refers to a set of security measures designed based on a company's specific needs and requirements.
[0327] "Generated AI model" refers to a system component that generates security protocols based on algorithms trained using machine learning or deep learning.
[0328] A "security protocol" refers to a set of rules and procedures for ensuring the security of a system, including access control, data encryption, and intrusion detection.
[0329] "Recognizing user emotions" refers to the process of using a camera and microphone to analyze a user's facial expressions and tone of voice to identify emotional states such as stress or anxiety.
[0330] "Adjusting security measures based on emotional state" refers to dynamically changing security measures, such as limiting the number of login attempts or strengthening specific monitoring, taking into account a user's real-time emotional state.
[0331] "Monitoring abnormal emotional changes" refers to the process of continuously monitoring a user's emotional state and detecting any sudden, unusual changes.
[0332] "Issuing an alert" refers to immediately issuing a warning to administrators and users when an abnormal emotional change or cyber threat is detected.
[0333] This invention is a system that utilizes generative AI models and emotion engines to predict and neutralize cyber threats in real time, providing advanced security measures based on the user's emotional state.
[0334] Hardware and Software Configuration
[0335] The main hardware for implementing the present invention includes:
[0336] Server: High-performance server (e.g., with Ubuntu OS)
[0337] Device: PC or smartphone used by the user
[0338] Camera and microphone: Devices for analyzing the user's facial expressions and voice
[0339] Key software includes:
[0340] Generative AI Models: Deep Learning Models Using TensorFlow
[0341] Emotion engine: Facial expression analysis using OpenCV and voice analysis using Amazon Polly
[0342] Database: MySQL or other RDBMS
[0343] System operation procedures and examples
[0344] 1. User Registration and Authentication:
[0345] Users enter and submit information such as their name, email address, and password through a web interface. The server receives this information and encrypts it using the AES encryption algorithm. The encrypted information is then securely stored in a MySQL database.
[0346] 2. Creating a security protocol:
[0347] The server collects security-related data provided by companies and inputs it into a generative AI model. The generative AI model analyzes the data using TensorFlow and generates an optimal security protocol. The server provides this protocol to the company and provides implementation support if necessary.
[0348] 3. Real-time threat analysis:
[0349] The device collects user activity and system event logs in real time and sends them to the server. The server receives this information and analyzes threats in real time. For example, if abnormal access is detected, the server will send an alert to the user saying, "Unauthorized access has been detected. Please take immediate action."
[0350] 4. Neutralize the threat:
[0351] The server identifies the type of threat detected and selects the most appropriate defense against malware, unauthorized access, etc. If malware is detected, the server immediately quarantines the file and deletes it from the system. All defense actions are also recorded as logs, which is useful for later incident analysis.
[0352] 5. Customized security solutions:
[0353] We assess the specific needs of your company and, if you have high security requirements, we will propose a dual authentication system or restrict access from specific IP addresses. These customized security solutions are provided flexibly to suit your company's security policy.
[0354] 6. Introducing the Emotion Engine:
[0355] When a user logs into the system, their facial expressions and tone of voice are collected in real time using a camera and microphone, and sent to the emotion engine, which uses OpenCV and Amazon Polly to analyze the data and assess the user's stress level and emotional state.
[0356] 7. Adjust security measures based on emotions:
[0357] If the emotion engine determines that a user is in a state of high stress, the server will limit the number of login attempts or monitor the user especially carefully. Also, if an abnormal emotional change is detected, such as sudden anxiety or anger, the server will immediately send an alert to the administrator.
[0358] Examples of prompt statements
[0359] "Build a system that analyzes users' emotions in real time and adjusts security measures according to their stress levels."
[0360] "Design an AI model that analyzes log data in real time and sends an alert when it detects abnormal access."
[0361] As described above, by combining a generative AI model and an emotion engine, the present invention enables real-time, multi-layered security measures to provide advanced protection for corporate and personal information systems.
[0362] The flow of the identification process in the second embodiment will be described with reference to FIG.
[0363] Program processing flow
[0364] Step 1: Enter your user registration information
[0365] A user enters basic information such as name, email address, and password into a web form and clicks the submit button.
[0366] Input: Basic information such as name, email address, and password.
[0367] Output: The information entered by the user is sent to the server.
[0368] Step 2: Receiving the data on the server
[0369] The server receives the information entered by the user. Specifically, it receives it as an HTTP POST request.
[0370] Input: Basic information submitted by the user.
[0371] Output: Received user information.
[0372] Step 3: Encrypt the data
[0373] The server encrypts the received user information, specifically using the AES encryption algorithm.
[0374] Input: Received user information.
[0375] Output: Encrypted user information.
[0376] Step 4: Saving to the Database
[0377] The server stores the encrypted user information in a database, specifically a MySQL database.
[0378] Input: Encrypted user information.
[0379] Output: User information stored securely in a database.
[0380] Step 5: Gather security data
[0381] The server collects security-related data such as network logs and system events provided by companies.
[0382] Input: Security-related data provided by the company.
[0383] Output: Collected security data.
[0384] Step 6: Sending data to the generative AI model
[0385] The server sends the collected security data to a generative AI model, specifically, TensorFlow, which analyzes the data.
[0386] Input: Collected security data.
[0387] Output: Analysis results from the generative AI model.
[0388] Step 7: Generate the protocol
[0389] The generative AI model generates optimal security protocols based on the analyzed data.
[0390] Input: The input data to a generative AI model.
[0391] Output: The generated security protocol.
[0392] Step 8: Provide the protocol to companies
[0393] The server provides the generated security protocols to the company and also assists with implementation if necessary.
[0394] Input: The generated security protocol.
[0395] Output: Protocols and supporting services provided to the company.
[0396] Step 9: Collect data on the device
[0397] The device collects real-time log data of user activity and system events.
[0398] Input: Log data of user activity and system events.
[0399] Output: The log data sent to the server.
[0400] Step 10: Sending data to the server
[0401] The terminal transmits the collected data to the server.
[0402] Input: Collected log data.
[0403] Output: The data sent to the server.
[0404] Step 11: Threat analysis on the server
[0405] The server analyzes the received log data and identifies threats in real time, for example, when abnormal access or unauthorized file operations are detected.
[0406] Input: The log data sent to the server.
[0407] Output: Identified threats and alert messages.
[0408] Step 12: Alert the user
[0409] The server immediately sends an alert message to the user in response to the identified threat.
[0410] Input: Identified threats.
[0411] Output: The alert message sent to the user.
[0412] Step 13: Identifying threats
[0413] The server identifies the type of threat detected, categorizing it as malware, unauthorized access, phishing attack, etc.
[0414] Input: Identified threats.
[0415] Output: Classified threat type.
[0416] Step 14: Select a defense
[0417] The server selects appropriate defenses against identified threats.
[0418] Input: Classified threat type.
[0419] Output: The selected defense.
[0420] Step 15: Implementing defenses
[0421] The server then executes the selected defense, for example, quarantining the file in case of malware and deleting it from the system.
[0422] Input: Selected defense.
[0423] Output: The defense measures taken and their logs.
[0424] Step 16: Assess your business needs
[0425] The server assesses the specific security needs of the enterprise.
[0426] Input: Corporate security needs.
[0427] Output: Evaluation results.
[0428] Step 17: Customized Solution Generation
[0429] The server generates customized security solutions based on the evaluation results, including, for example, dual authentication and restricting access from specific IP addresses.
[0430] Input: Evaluation result.
[0431] Output: Customized security solutions.
[0432] Step 18: Start Emotion Recognition
[0433] When a user logs into the system, the camera and microphone are activated.
[0434] Input: The user's state when logging into the system.
[0435] Output: Collected facial and speech data.
[0436] Step 19: Analyze Emotional Data
[0437] The emotion engine analyzes camera footage and audio data, specifically using OpenCV and Amazon Polly.
[0438] Input: Collected facial and speech data.
[0439] Output: Parsed emotion data.
[0440] Step 20: Stress Assessment
[0441] The emotion engine assesses the user's stress level based on the analyzed data.
[0442] Input: Parsed emotion data.
[0443] Output: Stress assessment results.
[0444] Step 21: Adjust security measures based on emotions
[0445] An emotion engine adjusts security measures based on the user's stress level, such as limiting the number of login attempts.
[0446] Input: Stress assessment results.
[0447] Output: Adjusted security measures.
[0448] Step 22: Monitor for unusual emotional changes
[0449] The emotion engine monitors the user's emotional changes in real time.
[0450] Input: Collected and analyzed emotion data.
[0451] Output: Continuous emotion change data.
[0452] Step 23: Alert when abnormal emotions are detected
[0453] If an abnormal emotion change is detected, the emotion engine immediately sends an alert to the server, which then notifies the administrator.
[0454] Input: Emotion data in which anomalies are detected.
[0455] Output: Server and administrator alert notification.
[0456] (Application example 2)
[0457] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."
[0458] Cyberattacks have become increasingly sophisticated and ingenious in recent years, causing many companies to suffer serious damage such as information leaks and system outages. Furthermore, because security measures do not take into account the psychological state of users, there is a high risk of exposure to threats caused by emotionally volatile behavior. Furthermore, real-time threat detection and response is technically difficult, and countermeasures based on user emotions are particularly lacking. To solve these problems, a comprehensive security system that takes user emotions into account using generative AI models is needed.
[0459] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 2 is realized by the following means.
[0460] In this invention, the server includes means for automating security measures based on the generated protocol, means for encrypting and storing information from a user, means for detecting threats in real time and generating alerts, means for identifying the type of threat and selecting and executing appropriate defensive measures, means for generating customized security solutions based on corporate needs, means for recognizing a user's emotions in real time using an emotion engine and assessing their stress level, means for adjusting security measures based on the emotions, means for monitoring abnormal emotional changes and issuing alerts to prompt a response, and means for providing security measures related to smartphones and head-mounted displays using the user's emotional state. This makes it possible to realize multi-layered security measures that take the user's psychological state into account in real time.
[0461] A "generated protocol" is a security procedure created based on data analyzed using a generative AI model.
[0462] "Means for automating security measures" refers to a system that automatically executes the generated protocols and satisfies security requirements.
[0463] "Means for encrypting and storing information from users" refers to technology for safely encrypting personal information and access data provided by users and storing them in a database.
[0464] "Means for detecting threats in real time and generating alerts" refers to a system that monitors activity within the system, immediately detects unauthorized access or abnormal behavior, and issues an alert.
[0465] "Means to identify the type of threat and select and implement appropriate defensive measures" refers to a system that classifies detected threats and automatically selects and implements the most appropriate security measures accordingly.
[0466] "Customized security solutions based on the needs of the enterprise" are defenses that are individually designed to take into account the unique security requirements of each enterprise.
[0467] "Means for recognizing a user's emotions in real time using an emotion engine and assessing stress levels" is a technology that analyzes a user's facial expressions and tone of voice to assess their psychological state and stress in real time.
[0468] The "means for adjusting security measures based on emotions" is a system that dynamically changes security settings and access restrictions according to the user's emotional state as assessed by an emotion engine.
[0469] The "means of monitoring abnormal emotional changes and issuing alerts to prompt a response" is a system that detects any sudden changes in a user's emotions and issues a warning to relevant parties.
[0470] "Means for providing security measures related to smartphones and head-mounted displays by utilizing the user's emotional state" is a technology that adjusts the security settings of smart devices based on the user's psychological state, supporting safe use.
[0471] System Program
[0472] The system program for realizing this application example mainly consists of the following elements:
[0473] 1. User authentication system:
[0474] - Hardware: Smartphone, Head-Mounted Display (HMD)
[0475] - Software: REST API, encryption library
[0476] 2. Emotion Recognition System:
[0477] - Hardware: Camera, microphone
[0478] - Software: OpenCV, TensorFlow / Keras (machine learning library)
[0479] 3. Real-time threat detection system:
[0480] - Hardware: User terminal
[0481] - Software: PyTorch (generative AI model), log analysis software
[0482] 4. Customized security solution system:
[0483] - Hardware: Server
[0484] - Software: Security protocol generation engine, database
[0485] System processing overview and specific examples
[0486] Handling user authentication
[0487] When a user accesses an application using a smartphone or HMD, the server first collects user information, encrypts it, and stores it in a database, thereby preventing information leakage.
[0488] Emotion recognition processing
[0489] When a user logs in, their facial expressions and tone of voice are captured in real time via a camera and microphone, and analyzed using OpenCV and TensorFlow / Keras. The resulting emotion engine evaluates the user's stress level.
[0490] Real-time threat detection and alerting
[0491] The user's device collects system activity and log data in real time and sends it to the server, which then analyzes it with a generative AI model (using PyTorch) to identify anomalies and threats, issuing alerts in real time and implementing necessary defensive measures.
[0492] Customized Security Solutions
[0493] The server generates optimal security protocols based on the company's security requirements, including restricting access from specific IP addresses and dual authentication.
[0494] Adjusting security measures based on emotions
[0495] The emotion engine monitors the user's emotional state in real time, and if a high level of stress is detected, the server automatically adjusts security measures, such as temporarily restricting system access if stress levels are high.
[0496] For example, if the emotion engine detects that a financial institution employee is experiencing stress while working, the server can temporarily restrict the employee's system access and send an alert to administrators. Additionally, if an employee is in an environment that is vulnerable to malicious attacks, the server can automatically adjust protocols to provide a safe working environment.
[0497] Example prompts for generative AI models
[0498] Here are some example prompts for a generative AI model to adjust security measures using an emotion engine:
[0499] "If users are stressed, suggest ways to limit login attempts and restrict system access."
[0500] "Please estimate what security measures would be effective based on the user's facial expression analysis data."
[0501] "Explain how you can analyze a user's emotional state in real time to predict cyber threats."
[0502] By using such prompts, the generative AI model can suggest appropriate countermeasures and prediction methods.
[0503] The flow of the specific processing in the application example 2 will be described with reference to FIG.
[0504] Step 1:
[0505] User Authentication
[0506] A user enters their credentials to log into the application, which are sent to the server where they are encrypted and stored in a database.
[0507] Input: User authentication information (user ID, password, etc.).
[0508] Data processing: Encryption of authentication information.
[0509] Output: Encrypted credentials stored in the database.
[0510] What it does: Receives authentication information via a REST API, encrypts the data using an encryption library, and then stores it in the database.
[0511] Step 2:
[0512] emotion recognition
[0513] The moment a user logs in, the device's camera and microphone are used to capture facial expressions and tone of voice, which are then analyzed by the emotion engine. OpenCV and TensorFlow / Keras are used to evaluate the user's emotional state (e.g., stress level).
[0514] Input: Real-time data from camera and microphone (facial expressions, tone of voice).
[0515] Data processing: Analysis of image and audio data.
[0516] Output: The user's emotional state (stress level) is assessed.
[0517] Specific operation: Data obtained from the camera and microphone is processed using OpenCV to recognize faces and analyze facial expressions. Analysis is performed using an emotion model using TensorFlow / Keras.
[0518] Step 3:
[0519] Real-time Threat Detection
[0520] The user device collects future system activity and log data in real time and sends it to the server, which then uses a generative AI model (powered by PyTorch) to detect threats from this data in real time.
[0521] Input: System logs and activity data from the device.
[0522] Data processing: Analyze collected data using generative AI models.
[0523] Output: Information and alerts about detected threats.
[0524] How it works: Log analysis software is used to collect data from user devices, which is then analyzed using a generative AI model built with PyTorch. If an anomaly is detected, an alert is issued immediately.
[0525] Step 4:
[0526] Threat response
[0527] The server automatically selects and implements appropriate defensive measures based on the type of threat detected.
[0528] Input: Information about the detected threat.
[0529] Data manipulation: Select appropriate defenses.
[0530] Output: The defensive measures taken and their results.
[0531] Specific operation: Identifies the type of threat and selects and executes corresponding defense measures (e.g., malware isolation, access restriction) on the server side.
[0532] Step 5:
[0533] Providing customized security solutions
[0534] The server generates a customized security solution tailored to each company's needs.
[0535] Input: Data about your company's security needs.
[0536] Data processing: security protocol generation.
[0537] Output: A customized security solution.
[0538] Specific behavior: Uses a security protocol generation engine to execute countermeasures based on the generated protocol.
[0539] Step 6:
[0540] Adjusting security measures based on emotions
[0541] The emotion engine monitors the user's emotional state, and if a high stress state is detected, the server dynamically adjusts security measures.
[0542] Input: User emotional state data.
[0543] Data manipulation: Adjusting security measures based on emotional state.
[0544] Output: Adjusted security settings.
[0545] Specific actions: The server receives data from the emotion engine and takes actions such as temporarily restricting system access for users with high stress levels.
[0546] Step 7:
[0547] Abnormal Emotion Change Alerts
[0548] The emotion engine monitors the user's emotional state in real time, and the server issues an alert if an abnormality occurs.
[0549] Input: User's emotional change data.
[0550] Data processing: Detection and evaluation of abnormal emotional changes.
[0551] Output: Issue an alert.
[0552] Specific operation: When the emotion engine detects an abnormal change in emotion, it sends the information to the server, which then issues an alert to the administrator and prompts them to take action.
[0553] The specific processing unit 290 transmits the result of the specific processing to the smart device 14. In the smart device 14, the control unit 46A causes the output device 40 to output the result of the specific processing. The microphone 38B acquires audio indicating a user input regarding the result of the specific processing. The control unit 46A transmits audio data indicating the user input acquired by the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.
[0554] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[0555] In the above embodiment, an example in which the specific process is performed by the data processing device 12 has been given, but the technology of the present disclosure is not limited to this, and the specific process may be performed by the smart device 14.
[0556] [Second embodiment]
[0557] FIG. 3 shows an example of the configuration of a data processing system 210 according to the second embodiment.
[0558] 3, the data processing system 210 includes the data processing device 12 and smart glasses 214. An example of the data processing device 12 is a server.
[0559] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0560] The smart glasses 214 include a computer 36, a microphone 238, a speaker 240, a camera 42, and a communication I / F 44. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The microphone 238, the speaker 240, and the camera 42 are also connected to the bus 52.
[0561] The microphone 238 receives instructions and the like from the user 20 by receiving voice uttered by the user 20. The microphone 238 captures the voice uttered by the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio in accordance with instructions from the processor 46.
[0562] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the surroundings of user 20 (for example, an imaging range defined by an angle of view equivalent to the field of vision of a typical healthy person).
[0563] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 are responsible for the exchange of various information between the processor 46 and the processor 28 via the network 54. The exchange of various information between the processor 46 and the processor 28 using the communication I / Fs 44 and 26 is carried out in a secure state.
[0564] Fig. 4 shows an example of the main functions of the data processing device 12 and the smart glasses 214. As shown in Fig. 4, in the data processing device 12, a specific process is performed by the processor 28. A specific process program 56 is stored in the storage 32.
[0565] The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[0566] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[0567] In the smart glasses 214, the reception output process is performed by the processor 46. A reception output program 60 is stored in the storage 50. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.
[0568] Next, a description will be given of the identification process performed by the identification processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as the "server" and the smart glasses 214 will be referred to as the "terminal."
[0569] The present invention relates to an advanced cybersecurity system that uses generative AI models to predict and neutralize cyber threats, providing a set of automated security measures to protect enterprise information systems.
[0570] Specifically, the main components of the system are as follows: Users enter basic information (such as name, email address, and password) into a sign-up form and send it to the server. The server receives this information, encrypts it, and stores it securely in a database. This prevents user information from being leaked.
[0571] The server then collects security-related data provided by the company and sends it to the generative AI model, which analyzes the input data and generates the optimal security protocol for the company. The server then provides this protocol to the company and assists with its implementation.
[0572] The device also collects real-time log data on user activity and system events and sends it to the server. The server analyzes this data, identifies threats in real time, and issues alerts to users as needed. For example, if abnormal access or unauthorized file operations are detected, the server can immediately issue an alert and prompt a prompt response.
[0573] The server also identifies the type of threat detected and selects and implements appropriate defense measures. For example, if malware is detected, the server quarantines the file and removes it from the system. It also logs the defense actions taken and their results.
[0574] Finally, the server evaluates each company's individual needs and generates a customized security solution based on them. This provides security measures optimized for each company's specific environment and requirements. For example, companies with high security requirements can be offered special measures such as dual authentication and access restrictions from specific IP addresses.
[0575] As described above, the system of the present invention can provide a high level of protection for corporate information systems by providing secure management of user information, real-time threat detection, rapid response to threats, and customized security solutions.
[0576] The processing flow will be explained below.
[0577] User Registration and Authentication Process
[0578] Step 1:
[0579] A user fills out a sign-up form with basic information such as name, email address, and password.
[0580] Step 2:
[0581] The server receives the input data and temporarily stores the information sent by the user.
[0582] Step 3:
[0583] The server encrypts the data. The server encrypts the user information using the SSL / TLS protocol.
[0584] Step 4:
[0585] The server stores the encrypted data in a database. The server stores the encrypted user information securely in a database.
[0586] Security Protocol Generation Process
[0587] Step 1:
[0588] The server collects security-related data from the company. The server receives data provided by the company.
[0589] Step 2:
[0590] The server sends the data to the generative AI model. The server inputs the company data into the generative AI model and begins analysis.
[0591] Step 3:
[0592] The server receives the analysis results of the generative AI model and obtains the security protocol proposal created by the AI model.
[0593] Step 4:
[0594] The server provides the optimal security protocol to the enterprise, and then proposes the generated protocol to the enterprise and prepares to implement it.
[0595] Real-time threat analysis process
[0596] Step 1:
[0597] The device collects log data. The device collects logs of user activity and system events in real time.
[0598] Step 2:
[0599] The terminal sends the log data to the server. The terminal periodically sends the collected log data to the server.
[0600] Step 3:
[0601] The server analyzes the received data. The server analyzes the received log data using an AI model to detect anomalies.
[0602] Step 4:
[0603] The server detects anomalies and issues an alert to the user. The server notifies the user of the detected threat information.
[0604] Threat Neutralization Process
[0605] Step 1:
[0606] The server identifies the type of threat. The server identifies what kind of threat has been detected.
[0607] Step 2:
[0608] The server selects the defense measures. The server uses a generative AI model to select the defense measures that are most appropriate for the threat.
[0609] Step 3:
[0610] The server executes the defensive action. The server immediately executes the selected defensive measures to protect the system.
[0611] Step 4:
[0612] The server records the actions taken. The server logs the defensive actions taken and their results.
[0613] Customized Security Solution Proposal Process
[0614] Step 1:
[0615] The server assesses the company's needs. The server assesses the security needs from the data provided by the company.
[0616] Step 2:
[0617] The server generates a customized solution: The server uses the AI model to generate a customized security solution that meets the company's needs.
[0618] Step 3:
[0619] The server proposes solutions to companies. The server proposes the customized solutions it has created to companies.
[0620] Through the above processing steps, CyberSecure can provide comprehensive and advanced cybersecurity services to businesses.
[0621] Example 1
[0622] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."
[0623] Current cybersecurity systems have difficulty efficiently detecting threats in real time and implementing appropriate defensive measures. Furthermore, they are not sufficiently customized to meet the unique security needs of each company, leaving security flaws vulnerable to failure. The purpose of this invention is to solve these problems and provide advanced protection for corporate information systems.
[0624] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.
[0625] In this invention, the server includes means for encrypting and storing information from users, means for collecting security data provided by companies and sending it to an analysis model, means for generating security protocols optimal for the companies based on the analyzed data, means for collecting log data of user activities and system events in real time and sending it to a central processing unit, means for detecting threats in real time and generating alerts, means for identifying the type of threat and selecting and executing appropriate defensive measures, and means for generating security solutions customized based on the needs of the companies, thereby enabling secure management of user information, real-time threat detection, rapid response to threats, and security measures optimized for each company.
[0626] "User information" refers to basic information such as name, email address, and password that a user provides to the system.
[0627] "Encryption" is the process of converting data using a specific algorithm to make it unreadable to third parties in order to protect it from unauthorized access.
[0628] "Security data" refers to security-related information such as firewall logs and access logs provided by companies.
[0629] An "analytical model" is a mathematical algorithm or machine learning model used to analyze data, such as a generative AI model.
[0630] A "security protocol" is a set of security rules and procedures established to protect a company's information systems.
[0631] An "activity log" is a record of operations and events that occur when a user uses a system.
[0632] A "central processing unit" is the system's main computer that collects and analyzes data, identifies threats, and generates alerts.
[0633] "Threat detection" refers to the analysis of security data and other information to identify security risks and abnormal behavior in a system.
[0634] "Defense measures" are specific countermeasures or action steps taken against detected threats.
[0635] A "customized security solution" is a security measure that is optimized to meet the specific needs of each company.
[0636] The present invention is an advanced cybersecurity system that uses generative AI models to predict and neutralize cyber threats, and provides a set of automated security measures to protect enterprise information systems. Specific embodiments of the present invention are described in detail below.
[0637] Collecting and storing user information
[0638] First, a user enters basic information such as name, email address, and password into the sign-up form and submits the form data. The server receives the information submitted by the user and encrypts the data using the AES-256 algorithm. The encrypted data is securely stored in a MySQL database. This prevents user information from being leaked.
[0639] Examples:
[0640] Text format
[0641] When a user enters their information into the sign-up form and hits the submit button, the information is transferred to the server, which encrypts the data using the AES-256 algorithm and stores it in a MySQL database.
[0642] Security data collection and analysis
[0643] Corporate security administrators provide security data such as firewall logs and access logs. The server collects the security data and sends it to the generative AI model. The generative AI model analyzes the data using Python and TensorFlow and generates optimal security protocols for the company. These protocols are then sent to the corporate security officer via the server, who assists with implementation.
[0644] Examples:
[0645] Text format
[0646] The server collects security data provided by the company and analyzes it using an AI model built with TensorFlow. As a result, optimal security protocols are generated and notified to the company's security personnel.
[0647] Real-time activity and event logging
[0648] User devices collect activity data and system event logs in real time. Syslog is used for this log collection. The collected log data is sent to a server, which analyzes it in real time to identify abnormal behavior and security threats. Alerts are sent to users and security personnel as needed.
[0649] Examples:
[0650] Text format
[0651] Using Syslog, terminals collect user activity logs and system event logs in real time and send them to the server, which analyzes them instantly and issues alerts as soon as an abnormality is detected.
[0652] Detecting threats and taking preventative measures
[0653] When the server detects a threat, it identifies the type of threat and selects the appropriate defense measures. For example, if malware is detected, the server uses anti-malware software (ClamAV) to quarantine and delete the file. It also records the defense measures taken and their results in a detailed log.
[0654] Examples:
[0655] Text format
[0656] If the server detects a threat, it will take the necessary defensive measures. For example, if ClamAV detects malware, it will quarantine and delete the file. It will then record the defensive measures taken and the results in a detailed log.
[0657] Creating a customized security solution
[0658] The server assesses each company's individual needs and generates a customized security solution based on those needs, such as dual authentication (e.g., authentication applications) or restricting access from specific IP addresses, providing security measures optimized for each company's specific environment and requirements.
[0659] Examples:
[0660] Text format
[0661] Our server assesses your company's specific needs and generates customized security solutions, such as using authentication applications for double authentication and recommending settings to allow access only from specific IP addresses. We then assist you in implementing these solutions.
[0662] This system enables secure management of user information, real-time threat detection, rapid response to threats, and customized security solutions tailored to individual needs, thereby providing advanced protection for corporate information systems.
[0663] The flow of the identification process in the first embodiment will be described with reference to FIG.
[0664] Step 1:
[0665] A user enters basic information into a sign-up form (such as name, email address, and password). The entered data is sent from the device to the server by clicking the submit button. Specifically, the user enters information into a form and presses the "Submit" button.
[0666] Input: User information such as name, email address, and password
[0667] Output: HTTP request with user information
[0668] Step 2:
[0669] The server receives the information sent by the user, encrypts it using the AES-256 algorithm, and securely stores the encrypted data in a database. Specifically, the server receives an HTTP request, performs encryption processing, and then stores the encrypted data in a database.
[0670] Input: HTTP request containing user information
[0671] Output: Encrypted user information
[0672] Step 3:
[0673] A company's security administrator provides the system with security data such as firewall logs and access logs. The server collects this security data and sends it to the generative AI model. After collecting the data, the server transmits it to the AI model and prepares it for analysis.
[0674] Input: Security data (firewall logs, access logs, etc.)
[0675] Output: Security data formatted in a parsable format
[0676] Step 4:
[0677] The generative AI model analyzes the collected data using Python and TensorFlow and generates the optimal security protocol for the company. The server receives the analysis results and notifies the company's security personnel. Specifically, the generative AI model analyzes the data and returns the analysis results to the server.
[0678] Input: Formatted security data
[0679] Output: Best security protocols for businesses
[0680] Step 5:
[0681] The terminal collects user activity logs and system event logs in real time and sends them to the server. The terminal uses Syslog to collect log data and transmits it to the server.
[0682] Input: User activity log, system event log
[0683] Output: Collected log data
[0684] Step 6:
[0685] The server analyzes the received log data in real time to identify abnormal behavior and security threats, and issues alerts to users and security personnel as needed. The server analyzes the log data and generates notifications if an alert condition is met.
[0686] Input: Collected log data
[0687] Output: Threat detection results, alert notifications
[0688] Step 7:
[0689] The server identifies the type of threat detected and selects and executes appropriate defense measures. For example, if malware is detected, the server uses anti-malware software (ClamAV) to quarantine and delete the file. It also records the defense measures taken and their results in a detailed log.
[0690] Input: Threat detection results
[0691] Output: Defense measures execution results, detailed log
[0692] Step 8:
[0693] The server evaluates a company's individual needs and generates and provides customized security solutions based on those needs. Specific solutions include dual authentication and restricting access from specific IP addresses. Support for the implementation of these solutions is also provided.
[0694] Input: Corporate security needs
[0695] Output: Customized security solutions
[0696] (Application example 1)
[0697] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."
[0698] Conventional cybersecurity systems face problems such as insufficient real-time threat detection and appropriate countermeasures. Delays in detecting and countering malicious activity on mobile devices, in particular, pose a high risk of compromising security. It is also difficult to provide customized security solutions that address the unique needs of each company. There is a need to solve these problems and achieve advanced security.
[0699] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.
[0700] In this invention, the server includes means for automating security countermeasures based on the generated protocol, means for encrypting and storing information from a user, means for detecting threats in real time and generating alerts, means for identifying the type of threat and selecting and executing appropriate defensive measures, means for generating customized security solutions based on the needs of a company, means for collecting real-time activity logs of mobile devices and detecting unauthorized activity using a generative model, and means for issuing alerts for detected threats and executing necessary measures, thereby enabling real-time threat detection and countermeasures in a variety of environments including mobile devices.
[0701] "Generated protocols" refer to the procedures and rules for security measures created by a generative AI model.
[0702] "Means for automating security measures" refers to mechanisms that automatically execute defensive actions against threats based on the generated protocols.
[0703] "Means for encrypting and storing information" refers to a mechanism for securely storing information provided by users using encryption technology.
[0704] "Means for detecting threats and generating alerts in real time" refers to a mechanism that monitors abnormal activity within the system in real time, detects threats, and immediately issues an alert.
[0705] "Means for identifying the type of threat and selecting and implementing appropriate defensive measures" refers to a mechanism for determining the most appropriate defensive measures based on the characteristics of the identified threat and implementing them.
[0706] "Means for generating customized security solutions based on the needs of an enterprise" refers to methods and technologies that provide optimized security measures tailored to each enterprise's specific requirements and environment.
[0707] "Means for collecting real-time activity logs of mobile devices" refers to a mechanism for collecting activity logs of mobile information devices in real time.
[0708] "Means for detecting fraudulent activity using generative models" refers to techniques and methods that use generative models to identify fraudulent behavior from log data.
[0709] "Means of issuing alerts for detected threats and taking necessary measures" refers to a mechanism that issues warnings to users and administrators about detected threats and takes defensive measures as necessary.
[0710] The present invention is an advanced cybersecurity system that uses generative AI models to securely manage user information, detect threats in real time, respond quickly, and provide customized security solutions.
[0711] The main components of the system are as follows: Users use a sign-up form to enter their basic information (such as name, email address, and password) and send it to the server. The server receives this information, encrypts it using Fernet encryption technology, and securely stores it in a database. This prevents user information from being leaked.
[0712] A specific example of how we ensure data security is the process of encrypting and storing the basic information a user provides when signing up. For example, if a user provides the name "Yamada Taro" and the email address "taro@example.com," the server will encrypt and store this information.
[0713] The server then collects security-related data provided by the company and sends it to the generative AI model, which analyzes the data and generates optimal security protocols for the company. The server then provides these protocols to the company and assists with their implementation.
[0714] In addition, mobile devices collect activity logs in real time and send them to a server. The server analyzes this log data and uses generative models to detect malicious activity. For example, if access from an abnormal IP address or unauthorized file operations is detected, the server can immediately send an alert and prompt a response.
[0715] As a specific example, consider the case where an access from an unknown IP address is detected in the event log of a smartphone. In this case, the server immediately issues an alert and takes measures to quarantine the relevant file or activity. An example of a prompt for this process could be as follows:
[0716] text
[0717] Use the following log data to detect unauthorized activity:
[0718] Log data: "2023-11-01T12:34:56Z, Access from unknown IP address, Unauthorized modification of file 'example.exe'"
[0719] Expected result: Issue an alert and take action on access from unknown IP addresses and modification of the file 'example.exe' as suspicious.
[0720] The server then takes appropriate defensive measures against detected threats. For example, if malware is found, the server quarantines the file and removes it from the system. It also logs the defensive actions taken and their results.
[0721] Furthermore, the server generates customized security solutions based on each company's specific environment and needs, providing security measures optimized for each company's requirements. For example, for companies with high security requirements, special measures such as dual authentication and access restrictions from specific IP addresses can be proposed.
[0722] As described above, the system of the present invention encrypts user information, detects threats in real time, sends prompt alerts about fraudulent activity, and provides customized security solutions based on the needs of the company, thereby providing a high level of protection for the company's information systems.
[0723] The flow of the specific processing in the application example 1 will be described with reference to FIG.
[0724] (Program processing flow)
[0725] Step 1:
[0726] The user enters basic information (name, email address, password) into the sign-up form and submits it to the server.
[0727] Specifically, a user enters information into a form on a smartphone or computer screen and clicks the "Submit" button. The input data includes the user's name, email address, and password. This data is sent to the server as output.
[0728] Step 2:
[0729] The basic information received by the server is encrypted using encryption technology (Fernet) and stored in a secure database.
[0730] The server takes the data received from the user and encrypts it using Fernet. Specifically, it generates an encryption key and encrypts the user data. As an output, the encrypted data is stored in a secure database.
[0731] Step 3:
[0732] The server collects security-related data provided by companies and sends it to a generative AI model.
[0733] The server receives data on the company's security logs and system status and sends it to the generative AI model. Specifically, the data format is converted and any necessary preprocessing is performed before being input into the generative AI model. This data processing generates the optimal security protocol for the company.
[0734] Step 4:
[0735] The server provides companies with security protocols generated by the AI model and assists them in implementing them.
[0736] The server notifies the company administrator of the generated protocol and provides specific implementation procedures. The output is a textual description of the protocol and an implementation guide, which are optimized to meet the requirements of each company, ensuring smooth implementation.
[0737] Step 5:
[0738] The mobile device collects activity logs in real time and sends them to the server.
[0739] Specifically, the terminal monitors system logs and user actions, and periodically uploads the data to the server. Real-time log data is collected as input and sent to the server as output.
[0740] Step 6:
[0741] The server analyzes the log data and uses generative models to detect fraudulent activity.
[0742] The server analyzes the received log data in real time and performs anomaly detection using a generative AI model. Specifically, it analyzes IP addresses and user actions contained in the log data to identify anomalies. The output is a list of suspicious activity.
[0743] Step 7:
[0744] The server will send out an alert for any detected threats and take necessary measures.
[0745] Specifically, when an anomaly is detected, an alert is sent, and the relevant file is quarantined or access is blocked. Information about malicious activity is obtained as input, and alert notifications and countermeasures are executed as output.
[0746] Step 8:
[0747] The server logs the actions and results of detecting and preventing threats.
[0748] The server keeps a detailed record of the defensive actions taken and their results, stored in a secure database. Specific actions include logging the success / failure of the action and the next steps. As an output, the complete defensive log is stored in the database.
[0749] Furthermore, an emotion engine that estimates the user's emotion may be further combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59, and perform identification processing using the user's emotion.
[0750] The present invention relates to an advanced cybersecurity system that uses generative AI models to predict and neutralize cyber threats. Additionally, the present invention is combined with an emotion engine that recognizes user emotions and adjusts security measures based on the user's psychological state.
[0751] Basic System Configuration
[0752] User Registration and Authentication Process
[0753] Users enter basic information such as name, email address, and password into a sign-up form and submit it. The server receives this data, encrypts it, and stores it securely in a database. This process prevents user information from being leaked.
[0754] Security Protocol Generation
[0755] The server collects security-related data provided by the company and sends it to the generative AI model, which analyzes the data and generates a security protocol that is optimal for the company. The server then provides this protocol to the company and assists with its implementation.
[0756] Real-time Threat Analysis
[0757] The device collects log data on user activity and system events in real time and sends it to the server. The server analyzes this data, identifies threats in real time, and issues alerts to the user as needed. For example, if abnormal access or unauthorized file operations are detected, the server can immediately issue an alert and prompt a prompt response.
[0758] Neutralizing the threat
[0759] The server identifies the type of threat detected and selects and implements appropriate defense measures. For example, if malware is detected, the server quarantines the file and deletes it from the system. It also logs the defense actions taken and their results.
[0760] Customized Security Solutions
[0761] The server evaluates the individual needs of each company and generates customized security solutions based on them. For example, for companies with high security requirements, it can propose special measures such as dual authentication and restricting access from specific IP addresses.
[0762] Adding an Emotion Engine
[0763] Emotion recognition and stress assessment
[0764] By introducing an emotion engine, the system can recognize users' emotions in real time and analyze the data. For example, when a user logs into the system, the emotion engine can assess the user's stress level by analyzing their facial expressions and tone of voice using a camera or microphone.
[0765] Adjusting security measures based on emotions
[0766] The server adjusts security measures based on the user's emotions identified by the emotion engine. For example, if a user is in a state of high stress, the server can implement measures such as limiting the number of login attempts or providing extra careful monitoring.
[0767] Abnormal emotional change monitoring and alerts
[0768] The emotion engine monitors the user's emotional changes in real time, and if an abnormal emotional change (such as sudden anxiety or anger) is detected, the server immediately issues an alert, enabling early detection and response to internal threats and social engineering attacks.
[0769] Specific examples
[0770] For example, if the emotion engine detects that a company employee is feeling stressed at work, the server will temporarily restrict the employee's system access and send an alert to an administrator if an abnormality is detected. Also, if the user's facial expression is unusual, additional authentication measures will be used to prevent unauthorized access.
[0771] As described above, by combining a generative AI model and an emotion engine, the present invention enables real-time, multi-layered security measures and provides advanced protection for corporate information systems.
[0772] The processing flow will be explained below.
[0773] Basic System Configuration
[0774] User Registration and Authentication Process
[0775] Step 1:
[0776] A user fills out a sign-up form with basic information such as name, email address, and password.
[0777] Step 2:
[0778] The server receives the input data and temporarily stores the information sent by the user.
[0779] Step 3:
[0780] The server encrypts the data. The server encrypts the user information using the SSL / TLS protocol.
[0781] Step 4:
[0782] The server stores the encrypted data in a database. The server stores the encrypted user information securely in a database.
[0783] Security Protocol Generation Process
[0784] Step 1:
[0785] The server collects security-related data from the company. The server receives data provided by the company.
[0786] Step 2:
[0787] The server sends the data to the generative AI model. The server inputs the company data into the generative AI model and begins analysis.
[0788] Step 3:
[0789] The server receives the analysis results of the generative AI model and obtains the security protocol proposal created by the AI model.
[0790] Step 4:
[0791] The server provides the optimal security protocol to the enterprise, and then proposes the generated protocol to the enterprise and prepares to implement it.
[0792] Real-time threat analysis process
[0793] Step 1:
[0794] The device collects log data. The device collects logs of user activity and system events in real time.
[0795] Step 2:
[0796] The terminal sends the log data to the server. The terminal periodically sends the collected log data to the server.
[0797] Step 3:
[0798] The server analyzes the received data. The server analyzes the received log data using an AI model to detect anomalies.
[0799] Step 4:
[0800] The server detects anomalies and issues an alert to the user. The server notifies the user of the detected threat information.
[0801] Threat Neutralization Process
[0802] Step 1:
[0803] The server identifies the type of threat. The server identifies what kind of threat has been detected.
[0804] Step 2:
[0805] The server selects the defense measures. The server uses a generative AI model to select the defense measures that are most appropriate for the threat.
[0806] Step 3:
[0807] The server executes the defensive action. The server immediately executes the selected defensive measures to protect the system.
[0808] Step 4:
[0809] The server records the actions taken. The server logs the defensive actions taken and their results.
[0810] Customized Security Solution Proposal Process
[0811] Step 1:
[0812] The server assesses the company's needs. The server assesses the security needs from the data provided by the company.
[0813] Step 2:
[0814] The server generates a customized solution: The server uses the AI model to generate a customized security solution that meets the company's needs.
[0815] Step 3:
[0816] The server proposes solutions to companies. The server proposes the customized solutions it has created to companies.
[0817] Adding an Emotion Engine
[0818] Emotion recognition and stress appraisal processes
[0819] Step 1:
[0820] When a user logs in to the system, the device uses a camera and microphone to collect the user's facial expressions and tone of voice.
[0821] Step 2:
[0822] The device sends the collected data to the emotion engine, which analyzes the user's emotions.
[0823] Step 3:
[0824] The emotion engine evaluates the user's stress level and sends the results to the server.
[0825] Step 4:
[0826] The server adjusts security measures based on the evaluation results of the emotion engine. If the user is in a high stress state, additional security measures are implemented.
[0827] The process of adjusting security measures based on emotions
[0828] Step 1:
[0829] The server receives the evaluation results of the emotion engine and grasps the user's emotional state.
[0830] Step 2:
[0831] The server dynamically changes security settings based on the evaluation results, for example requiring additional authentication measures for users in high stress states.
[0832] Step 3:
[0833] The server executes the changed security settings and applies the configured security measures to the entire system.
[0834] Monitoring and alerting for abnormal emotional changes
[0835] Step 1:
[0836] The device monitors the user's emotional changes in real time by continuously collecting facial expressions and tone of voice.
[0837] Step 2:
[0838] The device sends the collected data to the emotion engine, which analyzes changes in emotions.
[0839] Step 3:
[0840] If the emotion engine detects an abnormal change in emotion, it sends that information to the server.
[0841] Step 4:
[0842] The server issues an alert based on abnormal emotional changes, and the server promptly notifies the administrator and takes appropriate measures.
[0843] Through these processing steps, CyberSecure's system combines generative AI models and emotion engines to provide real-time, multi-layered security measures to highly protect enterprise information systems.
[0844] Example 2
[0845] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."
[0846] As cyber attacks become more sophisticated and diverse, the information security of companies and individuals is threatened, making it difficult to respond adequately with traditional, fixed security measures. Furthermore, while it is known that users' psychological state affects security, the adoption of security measures based on this has been sparse. To solve these problems, a system is needed that enables real-time, advanced threat analysis and security measures based on users' emotional state.
[0847] The specific processing by the specific processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means.
[0848] In this invention, the server includes means for receiving information provided by users, encrypting it, and storing it in a database, means for detecting threats in real time and generating alerts, means for identifying the type of detected threat and selecting and implementing appropriate defensive measures, means for generating customized security solutions based on corporate needs, means for generating security protocols using the generated AI model and automating security measures based on the protocols, means for recognizing user emotions, analyzing the data, and adjusting security measures based on the emotional state, and means for monitoring abnormal emotional changes and issuing an alert when an abnormality is detected. This enables multi-layered security measures in real time, thereby providing advanced protection for corporate and individual information security.
[0849] "User-Provided Information" refers to your name, email address, password, and other personally identifiable information that you enter into the System.
[0850] "Encryption" refers to the process of converting information provided by a user using a specific algorithm to make it unreadable to third parties in order to protect it from unauthorized access or disclosure.
[0851] A "database" refers to an information system that organizes and stores user information and various data within the system, allowing it to be quickly searched and retrieved as needed.
[0852] "Real-time threat detection" refers to the process of continuously monitoring user activity and system events to immediately identify cyber threats, such as abnormal behavior or unauthorized access.
[0853] "Alert" refers to a warning message or notification system that promptly notifies users of detected threats.
[0854] "Threat type identification" refers to the process of identifying the type of cyber threat a detected threat falls into, such as malware, unauthorized access, or phishing.
[0855] "Defensive measures" refer to specific measures or actions that should be taken against identified threats, such as isolating or deleting files or restricting access.
[0856] A "customized security solution" refers to a set of security measures designed based on a company's specific needs and requirements.
[0857] "Generated AI model" refers to a system component that generates security protocols based on algorithms trained using machine learning or deep learning.
[0858] A "security protocol" refers to a set of rules and procedures for ensuring the security of a system, including access control, data encryption, and intrusion detection.
[0859] "Recognizing user emotions" refers to the process of using a camera and microphone to analyze a user's facial expressions and tone of voice to identify emotional states such as stress or anxiety.
[0860] "Adjusting security measures based on emotional state" refers to dynamically changing security measures, such as limiting the number of login attempts or strengthening specific monitoring, taking into account a user's real-time emotional state.
[0861] "Monitoring abnormal emotional changes" refers to the process of continuously monitoring a user's emotional state and detecting any sudden, unusual changes.
[0862] "Issuing an alert" refers to immediately issuing a warning to administrators and users when an abnormal emotional change or cyber threat is detected.
[0863] This invention is a system that utilizes generative AI models and emotion engines to predict and neutralize cyber threats in real time, providing advanced security measures based on the user's emotional state.
[0864] Hardware and Software Configuration
[0865] The main hardware for implementing the present invention includes:
[0866] Server: High-performance server (e.g., with Ubuntu OS)
[0867] Device: PC or smartphone used by the user
[0868] Camera and microphone: Devices for analyzing the user's facial expressions and voice
[0869] Key software includes:
[0870] Generative AI Models: Deep Learning Models Using TensorFlow
[0871] Emotion engine: Facial expression analysis using OpenCV and voice analysis using Amazon Polly
[0872] Database: MySQL or other RDBMS
[0873] System operation procedures and examples
[0874] 1. User Registration and Authentication:
[0875] Users enter and submit information such as their name, email address, and password through a web interface. The server receives this information and encrypts it using the AES encryption algorithm. The encrypted information is then securely stored in a MySQL database.
[0876] 2. Creating a security protocol:
[0877] The server collects security-related data provided by companies and inputs it into a generative AI model. The generative AI model analyzes the data using TensorFlow and generates an optimal security protocol. The server provides this protocol to the company and provides implementation support if necessary.
[0878] 3. Real-time threat analysis:
[0879] The device collects user activity and system event logs in real time and sends them to the server. The server receives this information and analyzes threats in real time. For example, if abnormal access is detected, the server will send an alert to the user saying, "Unauthorized access has been detected. Please take immediate action."
[0880] 4. Neutralize the threat:
[0881] The server identifies the type of threat detected and selects the most appropriate defense against malware, unauthorized access, etc. If malware is detected, the server immediately quarantines the file and deletes it from the system. All defense actions are also recorded as logs, which is useful for later incident analysis.
[0882] 5. Customized security solutions:
[0883] We assess the specific needs of your company and, if you have high security requirements, we will propose a dual authentication system or restrict access from specific IP addresses. These customized security solutions are provided flexibly to suit your company's security policy.
[0884] 6. Introducing the Emotion Engine:
[0885] When a user logs into the system, their facial expressions and tone of voice are collected in real time using a camera and microphone, and sent to the emotion engine, which uses OpenCV and Amazon Polly to analyze the data and assess the user's stress level and emotional state.
[0886] 7. Adjust security measures based on emotions:
[0887] If the emotion engine determines that a user is in a state of high stress, the server will limit the number of login attempts or monitor the user especially carefully. Also, if an abnormal emotional change is detected, such as sudden anxiety or anger, the server will immediately send an alert to the administrator.
[0888] Examples of prompt statements
[0889] "Build a system that analyzes users' emotions in real time and adjusts security measures according to their stress levels."
[0890] "Design an AI model that analyzes log data in real time and sends an alert when it detects abnormal access."
[0891] As described above, by combining a generative AI model and an emotion engine, the present invention enables real-time, multi-layered security measures to provide advanced protection for corporate and personal information systems.
[0892] The flow of the identification process in the second embodiment will be described with reference to FIG.
[0893] Program processing flow
[0894] Step 1: Enter your user registration information
[0895] A user enters basic information such as name, email address, and password into a web form and clicks the submit button.
[0896] Input: Basic information such as name, email address, and password.
[0897] Output: The information entered by the user is sent to the server.
[0898] Step 2: Receiving the data on the server
[0899] The server receives the information entered by the user. Specifically, it receives it as an HTTP POST request.
[0900] Input: Basic information submitted by the user.
[0901] Output: Received user information.
[0902] Step 3: Encrypt the data
[0903] The server encrypts the received user information, specifically using the AES encryption algorithm.
[0904] Input: Received user information.
[0905] Output: Encrypted user information.
[0906] Step 4: Saving to the Database
[0907] The server stores the encrypted user information in a database, specifically a MySQL database.
[0908] Input: Encrypted user information.
[0909] Output: User information stored securely in a database.
[0910] Step 5: Gather security data
[0911] The server collects security-related data such as network logs and system events provided by companies.
[0912] Input: Security-related data provided by the company.
[0913] Output: Collected security data.
[0914] Step 6: Sending data to the generative AI model
[0915] The server sends the collected security data to a generative AI model, specifically, TensorFlow, which analyzes the data.
[0916] Input: Collected security data.
[0917] Output: Analysis results from the generative AI model.
[0918] Step 7: Generate the protocol
[0919] The generative AI model generates optimal security protocols based on the analyzed data.
[0920] Input: The input data to a generative AI model.
[0921] Output: The generated security protocol.
[0922] Step 8: Provide the protocol to companies
[0923] The server provides the generated security protocols to the company and also assists with implementation if necessary.
[0924] Input: The generated security protocol.
[0925] Output: Protocols and supporting services provided to the company.
[0926] Step 9: Collect data on the device
[0927] The device collects real-time log data of user activity and system events.
[0928] Input: Log data of user activity and system events.
[0929] Output: The log data sent to the server.
[0930] Step 10: Sending data to the server
[0931] The terminal transmits the collected data to the server.
[0932] Input: Collected log data.
[0933] Output: The data sent to the server.
[0934] Step 11: Threat analysis on the server
[0935] The server analyzes the received log data and identifies threats in real time, for example, when abnormal access or unauthorized file operations are detected.
[0936] Input: The log data sent to the server.
[0937] Output: Identified threats and alert messages.
[0938] Step 12: Alert the user
[0939] The server immediately sends an alert message to the user in response to the identified threat.
[0940] Input: Identified threats.
[0941] Output: The alert message sent to the user.
[0942] Step 13: Identifying threats
[0943] The server identifies the type of threat detected, categorizing it as malware, unauthorized access, phishing attack, etc.
[0944] Input: Identified threats.
[0945] Output: Classified threat type.
[0946] Step 14: Select a defense
[0947] The server selects appropriate defenses against identified threats.
[0948] Input: Classified threat type.
[0949] Output: The selected defense.
[0950] Step 15: Implementing defenses
[0951] The server then executes the selected defense, for example, quarantining the file in case of malware and deleting it from the system.
[0952] Input: Selected defense.
[0953] Output: The defense measures taken and their logs.
[0954] Step 16: Assess your business needs
[0955] The server assesses the specific security needs of the enterprise.
[0956] Input: Corporate security needs.
[0957] Output: Evaluation results.
[0958] Step 17: Customized Solution Generation
[0959] The server generates customized security solutions based on the evaluation results, including, for example, dual authentication and restricting access from specific IP addresses.
[0960] Input: Evaluation result.
[0961] Output: Customized security solutions.
[0962] Step 18: Start Emotion Recognition
[0963] When a user logs into the system, the camera and microphone are activated.
[0964] Input: The user's state when logging into the system.
[0965] Output: Collected facial and speech data.
[0966] Step 19: Analyze Emotional Data
[0967] The emotion engine analyzes camera footage and audio data, specifically using OpenCV and Amazon Polly.
[0968] Input: Collected facial and speech data.
[0969] Output: Parsed emotion data.
[0970] Step 20: Stress Assessment
[0971] The emotion engine assesses the user's stress level based on the analyzed data.
[0972] Input: Parsed emotion data.
[0973] Output: Stress assessment results.
[0974] Step 21: Adjust security measures based on emotions
[0975] An emotion engine adjusts security measures based on the user's stress level, such as limiting the number of login attempts.
[0976] Input: Stress assessment results.
[0977] Output: Adjusted security measures.
[0978] Step 22: Monitor for unusual emotional changes
[0979] The emotion engine monitors the user's emotional changes in real time.
[0980] Input: Collected and analyzed emotion data.
[0981] Output: Continuous emotion change data.
[0982] Step 23: Alert when abnormal emotions are detected
[0983] If an abnormal emotion change is detected, the emotion engine immediately sends an alert to the server, which then notifies the administrator.
[0984] Input: Emotion data in which anomalies are detected.
[0985] Output: Server and administrator alert notification.
[0986] (Application example 2)
[0987] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."
[0988] Cyberattacks have become increasingly sophisticated and ingenious in recent years, causing many companies to suffer serious damage such as information leaks and system outages. Furthermore, because security measures do not take into account the psychological state of users, there is a high risk of exposure to threats caused by emotionally volatile behavior. Furthermore, real-time threat detection and response is technically difficult, and countermeasures based on user emotions are particularly lacking. To solve these problems, a comprehensive security system that takes user emotions into account using generative AI models is needed.
[0989] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 2 is realized by the following means.
[0990] In this invention, the server includes means for automating security measures based on the generated protocol, means for encrypting and storing information from a user, means for detecting threats in real time and generating alerts, means for identifying the type of threat and selecting and executing appropriate defensive measures, means for generating customized security solutions based on corporate needs, means for recognizing a user's emotions in real time using an emotion engine and assessing their stress level, means for adjusting security measures based on the emotions, means for monitoring abnormal emotional changes and issuing alerts to prompt a response, and means for providing security measures related to smartphones and head-mounted displays using the user's emotional state. This makes it possible to realize multi-layered security measures that take the user's psychological state into account in real time.
[0991] A "generated protocol" is a security procedure created based on data analyzed using a generative AI model.
[0992] "Means for automating security measures" refers to a system that automatically executes the generated protocols and satisfies security requirements.
[0993] "Means for encrypting and storing information from users" refers to technology for safely encrypting personal information and access data provided by users and storing them in a database.
[0994] "Means for detecting threats in real time and generating alerts" refers to a system that monitors activity within the system, immediately detects unauthorized access or abnormal behavior, and issues an alert.
[0995] "Means to identify the type of threat and select and implement appropriate defensive measures" refers to a system that classifies detected threats and automatically selects and implements the most appropriate security measures accordingly.
[0996] "Customized security solutions based on the needs of the enterprise" are defenses that are individually designed to take into account the unique security requirements of each enterprise.
[0997] "Means for recognizing a user's emotions in real time using an emotion engine and assessing stress levels" is a technology that analyzes a user's facial expressions and tone of voice to assess their psychological state and stress in real time.
[0998] The "means for adjusting security measures based on emotions" is a system that dynamically changes security settings and access restrictions according to the user's emotional state as assessed by an emotion engine.
[0999] The "means of monitoring abnormal emotional changes and issuing alerts to prompt a response" is a system that detects any sudden changes in a user's emotions and issues a warning to relevant parties.
[1000] "Means for providing security measures related to smartphones and head-mounted displays by utilizing the user's emotional state" is a technology that adjusts the security settings of smart devices based on the user's psychological state, supporting safe use.
[1001] System Program
[1002] The system program for realizing this application example mainly consists of the following elements:
[1003] 1. User authentication system:
[1004] - Hardware: Smartphone, Head-Mounted Display (HMD)
[1005] - Software: REST API, encryption library
[1006] 2. Emotion Recognition System:
[1007] - Hardware: Camera, microphone
[1008] - Software: OpenCV, TensorFlow / Keras (machine learning library)
[1009] 3. Real-time threat detection system:
[1010] - Hardware: User terminal
[1011] - Software: PyTorch (generative AI model), log analysis software
[1012] 4. Customized security solution system:
[1013] - Hardware: Server
[1014] - Software: Security protocol generation engine, database
[1015] System processing overview and specific examples
[1016] Handling user authentication
[1017] When a user accesses an application using a smartphone or HMD, the server first collects user information, encrypts it, and stores it in a database, thereby preventing information leakage.
[1018] Emotion recognition processing
[1019] When a user logs in, their facial expressions and tone of voice are captured in real time via a camera and microphone, and analyzed using OpenCV and TensorFlow / Keras. The resulting emotion engine evaluates the user's stress level.
[1020] Real-time threat detection and alerting
[1021] The user's device collects system activity and log data in real time and sends it to the server, which then analyzes it with a generative AI model (using PyTorch) to identify anomalies and threats, issuing alerts in real time and implementing necessary defensive measures.
[1022] Customized Security Solutions
[1023] The server generates optimal security protocols based on the company's security requirements, including restricting access from specific IP addresses and dual authentication.
[1024] Adjusting security measures based on emotions
[1025] The emotion engine monitors the user's emotional state in real time, and if a high level of stress is detected, the server automatically adjusts security measures, such as temporarily restricting system access if stress levels are high.
[1026] For example, if the emotion engine detects that a financial institution employee is experiencing stress while working, the server can temporarily restrict the employee's system access and send an alert to administrators. Additionally, if an employee is in an environment that is vulnerable to malicious attacks, the server can automatically adjust protocols to provide a safe working environment.
[1027] Example prompts for generative AI models
[1028] Here are some example prompts for a generative AI model to adjust security measures using an emotion engine:
[1029] "If users are stressed, suggest ways to limit login attempts and restrict system access."
[1030] "Please estimate what security measures would be effective based on the user's facial expression analysis data."
[1031] "Explain how you can analyze a user's emotional state in real time to predict cyber threats."
[1032] By using such prompts, the generative AI model can suggest appropriate countermeasures and prediction methods.
[1033] The flow of the specific processing in the application example 2 will be described with reference to FIG.
[1034] Step 1:
[1035] User Authentication
[1036] A user enters their credentials to log into the application, which are sent to the server where they are encrypted and stored in a database.
[1037] Input: User authentication information (user ID, password, etc.).
[1038] Data processing: Encryption of authentication information.
[1039] Output: Encrypted credentials stored in the database.
[1040] What it does: Receives authentication information via a REST API, encrypts the data using an encryption library, and then stores it in the database.
[1041] Step 2:
[1042] emotion recognition
[1043] The moment a user logs in, the device's camera and microphone are used to capture facial expressions and tone of voice, which are then analyzed by the emotion engine. OpenCV and TensorFlow / Keras are used to evaluate the user's emotional state (e.g., stress level).
[1044] Input: Real-time data from camera and microphone (facial expressions, tone of voice).
[1045] Data processing: Analysis of image and audio data.
[1046] Output: The user's emotional state (stress level) is assessed.
[1047] Specific operation: Data obtained from the camera and microphone is processed using OpenCV to recognize faces and analyze facial expressions. Analysis is performed using an emotion model using TensorFlow / Keras.
[1048] Step 3:
[1049] Real-time Threat Detection
[1050] The user device collects future system activity and log data in real time and sends it to the server, which then uses a generative AI model (powered by PyTorch) to detect threats from this data in real time.
[1051] Input: System logs and activity data from the device.
[1052] Data processing: Analyze collected data using generative AI models.
[1053] Output: Information and alerts about detected threats.
[1054] How it works: Log analysis software is used to collect data from user devices, which is then analyzed using a generative AI model built with PyTorch. If an anomaly is detected, an alert is issued immediately.
[1055] Step 4:
[1056] Threat response
[1057] The server automatically selects and implements appropriate defensive measures based on the type of threat detected.
[1058] Input: Information about the detected threat.
[1059] Data manipulation: Select appropriate defenses.
[1060] Output: The defensive measures taken and their results.
[1061] Specific operation: Identifies the type of threat and selects and executes corresponding defense measures (e.g., malware isolation, access restriction) on the server side.
[1062] Step 5:
[1063] Providing customized security solutions
[1064] The server generates a customized security solution tailored to each company's needs.
[1065] Input: Data about your company's security needs.
[1066] Data processing: security protocol generation.
[1067] Output: A customized security solution.
[1068] Specific behavior: Uses a security protocol generation engine to execute countermeasures based on the generated protocol.
[1069] Step 6:
[1070] Adjusting security measures based on emotions
[1071] The emotion engine monitors the user's emotional state, and if a high stress state is detected, the server dynamically adjusts security measures.
[1072] Input: User emotional state data.
[1073] Data manipulation: Adjusting security measures based on emotional state.
[1074] Output: Adjusted security settings.
[1075] Specific actions: The server receives data from the emotion engine and takes actions such as temporarily restricting system access for users with high stress levels.
[1076] Step 7:
[1077] Abnormal Emotion Change Alerts
[1078] The emotion engine monitors the user's emotional state in real time, and the server issues an alert if an abnormality occurs.
[1079] Input: User's emotional change data.
[1080] Data processing: Detection and evaluation of abnormal emotional changes.
[1081] Output: Issue an alert.
[1082] Specific operation: When the emotion engine detects an abnormal change in emotion, it sends the information to the server, which then issues an alert to the administrator and prompts them to take action.
[1083] The specific processing unit 290 transmits the result of the specific processing to the smart glasses 214. In the smart glasses 214, the control unit 46A causes the speaker 240 to output the result of the specific processing. The microphone 238 acquires audio indicating a user input regarding the result of the specific processing. The control unit 46A transmits audio data indicating the user input acquired by the microphone 238 to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.
[1084] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[1085] In the above embodiment, an example in which the specific processing is performed by the data processing device 12 has been given, but the technology of the present disclosure is not limited to this, and the specific processing may be performed by the smart glasses 214.
[1086] [Third embodiment]
[1087] FIG. 5 shows an example of the configuration of a data processing system 310 according to the third embodiment.
[1088] 5, the data processing system 310 includes the data processing device 12 and a headset terminal 314. An example of the data processing device 12 is a server.
[1089] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[1090] The headset type terminal 314 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication I / F 44, and a display 343. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The microphone 238, the speaker 240, the camera 42, and the display 343 are also connected to the bus 52.
[1091] The microphone 238 receives instructions and the like from the user 20 by receiving voice uttered by the user 20. The microphone 238 captures the voice uttered by the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio in accordance with instructions from the processor 46.
[1092] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the surroundings of user 20 (for example, an imaging range defined by an angle of view equivalent to the field of vision of a typical healthy person).
[1093] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 are responsible for the exchange of various information between the processor 46 and the processor 28 via the network 54. The exchange of various information between the processor 46 and the processor 28 using the communication I / Fs 44 and 26 is carried out in a secure state.
[1094] Fig. 6 shows an example of the main functions of the data processing device 12 and the headset type terminal 314. As shown in Fig. 6, in the data processing device 12, a specific process is performed by the processor 28. A specific process program 56 is stored in the storage 32.
[1095] The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[1096] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[1097] In the headset type terminal 314, a reception output process is performed by the processor 46. A reception output program 60 is stored in the storage 50. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.
[1098] Next, a description will be given of the identification process performed by the identification processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as the "server" and the headset type terminal 314 will be referred to as the "terminal."
[1099] The present invention relates to an advanced cybersecurity system that uses generative AI models to predict and neutralize cyber threats, providing a set of automated security measures to protect enterprise information systems.
[1100] Specifically, the main components of the system are as follows: Users enter basic information (such as name, email address, and password) into a sign-up form and send it to the server. The server receives this information, encrypts it, and stores it securely in a database. This prevents user information from being leaked.
[1101] The server then collects security-related data provided by the company and sends it to the generative AI model, which analyzes the input data and generates the optimal security protocol for the company. The server then provides this protocol to the company and assists with its implementation.
[1102] The device also collects real-time log data on user activity and system events and sends it to the server. The server analyzes this data, identifies threats in real time, and issues alerts to users as needed. For example, if abnormal access or unauthorized file operations are detected, the server can immediately issue an alert and prompt a prompt response.
[1103] The server also identifies the type of threat detected and selects and implements appropriate defense measures. For example, if malware is detected, the server quarantines the file and removes it from the system. It also logs the defense actions taken and their results.
[1104] Finally, the server evaluates each company's individual needs and generates a customized security solution based on them. This provides security measures optimized for each company's specific environment and requirements. For example, companies with high security requirements can be offered special measures such as dual authentication and access restrictions from specific IP addresses.
[1105] As described above, the system of the present invention can provide a high level of protection for corporate information systems by providing secure management of user information, real-time threat detection, rapid response to threats, and customized security solutions.
[1106] The processing flow will be explained below.
[1107] User Registration and Authentication Process
[1108] Step 1:
[1109] A user fills out a sign-up form with basic information such as name, email address, and password.
[1110] Step 2:
[1111] The server receives the input data and temporarily stores the information sent by the user.
[1112] Step 3:
[1113] The server encrypts the data. The server encrypts the user information using the SSL / TLS protocol.
[1114] Step 4:
[1115] The server stores the encrypted data in a database. The server stores the encrypted user information securely in a database.
[1116] Security Protocol Generation Process
[1117] Step 1:
[1118] The server collects security-related data from the company. The server receives data provided by the company.
[1119] Step 2:
[1120] The server sends the data to the generative AI model. The server inputs the company data into the generative AI model and begins analysis.
[1121] Step 3:
[1122] The server receives the analysis results of the generative AI model and obtains the security protocol proposal created by the AI model.
[1123] Step 4:
[1124] The server provides the optimal security protocol to the enterprise, and then proposes the generated protocol to the enterprise and prepares to implement it.
[1125] Real-time threat analysis process
[1126] Step 1:
[1127] The device collects log data. The device collects logs of user activity and system events in real time.
[1128] Step 2:
[1129] The terminal sends the log data to the server. The terminal periodically sends the collected log data to the server.
[1130] Step 3:
[1131] The server analyzes the received data. The server analyzes the received log data using an AI model to detect anomalies.
[1132] Step 4:
[1133] The server detects anomalies and issues an alert to the user. The server notifies the user of the detected threat information.
[1134] Threat Neutralization Process
[1135] Step 1:
[1136] The server identifies the type of threat. The server identifies what kind of threat has been detected.
[1137] Step 2:
[1138] The server selects the defense measures. The server uses a generative AI model to select the defense measures that are most appropriate for the threat.
[1139] Step 3:
[1140] The server executes the defensive action. The server immediately executes the selected defensive measures to protect the system.
[1141] Step 4:
[1142] The server records the actions taken. The server logs the defensive actions taken and their results.
[1143] Customized Security Solution Proposal Process
[1144] Step 1:
[1145] The server assesses the company's needs. The server assesses the security needs from the data provided by the company.
[1146] Step 2:
[1147] The server generates a customized solution: The server uses the AI model to generate a customized security solution that meets the company's needs.
[1148] Step 3:
[1149] The server proposes solutions to companies. The server proposes the customized solutions it has created to companies.
[1150] Through the above processing steps, CyberSecure can provide comprehensive and advanced cybersecurity services to businesses.
[1151] Example 1
[1152] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."
[1153] Current cybersecurity systems have difficulty efficiently detecting threats in real time and implementing appropriate defensive measures. Furthermore, they are not sufficiently customized to meet the unique security needs of each company, leaving security flaws vulnerable to failure. The purpose of this invention is to solve these problems and provide advanced protection for corporate information systems.
[1154] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.
[1155] In this invention, the server includes means for encrypting and storing information from users, means for collecting security data provided by companies and sending it to an analysis model, means for generating security protocols optimal for the companies based on the analyzed data, means for collecting log data of user activities and system events in real time and sending it to a central processing unit, means for detecting threats in real time and generating alerts, means for identifying the type of threat and selecting and executing appropriate defensive measures, and means for generating security solutions customized based on the needs of the companies, thereby enabling secure management of user information, real-time threat detection, rapid response to threats, and security measures optimized for each company.
[1156] "User information" refers to basic information such as name, email address, and password that a user provides to the system.
[1157] "Encryption" is the process of converting data using a specific algorithm to make it unreadable to third parties in order to protect it from unauthorized access.
[1158] "Security data" refers to security-related information such as firewall logs and access logs provided by companies.
[1159] An "analytical model" is a mathematical algorithm or machine learning model used to analyze data, such as a generative AI model.
[1160] A "security protocol" is a set of security rules and procedures established to protect a company's information systems.
[1161] An "activity log" is a record of operations and events that occur when a user uses a system.
[1162] A "central processing unit" is the system's main computer that collects and analyzes data, identifies threats, and generates alerts.
[1163] "Threat detection" refers to the analysis of security data and other information to identify security risks and abnormal behavior in a system.
[1164] "Defense measures" are specific countermeasures or action steps taken against detected threats.
[1165] A "customized security solution" is a security measure that is optimized to meet the specific needs of each company.
[1166] The present invention is an advanced cybersecurity system that uses generative AI models to predict and neutralize cyber threats, and provides a set of automated security measures to protect enterprise information systems. Specific embodiments of the present invention are described in detail below.
[1167] Collecting and storing user information
[1168] First, a user enters basic information such as name, email address, and password into the sign-up form and submits the form data. The server receives the information submitted by the user and encrypts the data using the AES-256 algorithm. The encrypted data is securely stored in a MySQL database. This prevents user information from being leaked.
[1169] Examples:
[1170] Text format
[1171] When a user enters their information into the sign-up form and hits the submit button, the information is transferred to the server, which encrypts the data using the AES-256 algorithm and stores it in a MySQL database.
[1172] Security data collection and analysis
[1173] Corporate security administrators provide security data such as firewall logs and access logs. The server collects the security data and sends it to the generative AI model. The generative AI model analyzes the data using Python and TensorFlow and generates optimal security protocols for the company. These protocols are then sent to the corporate security officer via the server, who assists with implementation.
[1174] Examples:
[1175] Text format
[1176] The server collects security data provided by the company and analyzes it using an AI model built with TensorFlow. As a result, optimal security protocols are generated and notified to the company's security personnel.
[1177] Real-time activity and event logging
[1178] User devices collect activity data and system event logs in real time. Syslog is used for this log collection. The collected log data is sent to a server, which analyzes it in real time to identify abnormal behavior and security threats. Alerts are sent to users and security personnel as needed.
[1179] Examples:
[1180] Text format
[1181] Using Syslog, terminals collect user activity logs and system event logs in real time and send them to the server, which analyzes them instantly and issues alerts as soon as an abnormality is detected.
[1182] Detecting threats and taking preventative measures
[1183] When the server detects a threat, it identifies the type of threat and selects the appropriate defense measures. For example, if malware is detected, the server uses anti-malware software (ClamAV) to quarantine and delete the file. It also records the defense measures taken and their results in a detailed log.
[1184] Examples:
[1185] Text format
[1186] If the server detects a threat, it will take the necessary defensive measures. For example, if ClamAV detects malware, it will quarantine and delete the file. It will then record the defensive measures taken and the results in a detailed log.
[1187] Creating a customized security solution
[1188] The server assesses each company's individual needs and generates a customized security solution based on those needs, such as dual authentication (e.g., authentication applications) or restricting access from specific IP addresses, providing security measures optimized for each company's specific environment and requirements.
[1189] Examples:
[1190] Text format
[1191] Our server assesses your company's specific needs and generates customized security solutions, such as using authentication applications for double authentication and recommending settings to allow access only from specific IP addresses. We then assist you in implementing these solutions.
[1192] This system enables secure management of user information, real-time threat detection, rapid response to threats, and customized security solutions tailored to individual needs, thereby providing advanced protection for corporate information systems.
[1193] The flow of the identification process in the first embodiment will be described with reference to FIG.
[1194] Step 1:
[1195] A user enters basic information into a sign-up form (such as name, email address, and password). The entered data is sent from the device to the server by clicking the submit button. Specifically, the user enters information into a form and presses the "Submit" button.
[1196] Input: User information such as name, email address, and password
[1197] Output: HTTP request with user information
[1198] Step 2:
[1199] The server receives the information sent by the user, encrypts it using the AES-256 algorithm, and securely stores the encrypted data in a database. Specifically, the server receives an HTTP request, performs encryption processing, and then stores the encrypted data in a database.
[1200] Input: HTTP request containing user information
[1201] Output: Encrypted user information
[1202] Step 3:
[1203] A company's security administrator provides the system with security data such as firewall logs and access logs. The server collects this security data and sends it to the generative AI model. After collecting the data, the server transmits it to the AI model and prepares it for analysis.
[1204] Input: Security data (firewall logs, access logs, etc.)
[1205] Output: Security data formatted in a parsable format
[1206] Step 4:
[1207] The generative AI model analyzes the collected data using Python and TensorFlow and generates the optimal security protocol for the company. The server receives the analysis results and notifies the company's security personnel. Specifically, the generative AI model analyzes the data and returns the analysis results to the server.
[1208] Input: Formatted security data
[1209] Output: Best security protocols for businesses
[1210] Step 5:
[1211] The terminal collects user activity logs and system event logs in real time and sends them to the server. The terminal uses Syslog to collect log data and transmits it to the server.
[1212] Input: User activity log, system event log
[1213] Output: Collected log data
[1214] Step 6:
[1215] The server analyzes the received log data in real time to identify abnormal behavior and security threats, and issues alerts to users and security personnel as needed. The server analyzes the log data and generates notifications if an alert condition is met.
[1216] Input: Collected log data
[1217] Output: Threat detection results, alert notifications
[1218] Step 7:
[1219] The server identifies the type of threat detected and selects and executes appropriate defense measures. For example, if malware is detected, the server uses anti-malware software (ClamAV) to quarantine and delete the file. It also records the defense measures taken and their results in a detailed log.
[1220] Input: Threat detection results
[1221] Output: Defense measures execution results, detailed log
[1222] Step 8:
[1223] The server evaluates a company's individual needs and generates and provides customized security solutions based on those needs. Specific solutions include dual authentication and restricting access from specific IP addresses. Support for the implementation of these solutions is also provided.
[1224] Input: Corporate security needs
[1225] Output: Customized security solutions
[1226] (Application example 1)
[1227] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."
[1228] Conventional cybersecurity systems face problems such as insufficient real-time threat detection and appropriate countermeasures. Delays in detecting and countering malicious activity on mobile devices, in particular, pose a high risk of compromising security. It is also difficult to provide customized security solutions that address the unique needs of each company. There is a need to solve these problems and achieve advanced security.
[1229] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.
[1230] In this invention, the server includes means for automating security countermeasures based on the generated protocol, means for encrypting and storing information from a user, means for detecting threats in real time and generating alerts, means for identifying the type of threat and selecting and executing appropriate defensive measures, means for generating customized security solutions based on the needs of a company, means for collecting real-time activity logs of mobile devices and detecting unauthorized activity using a generative model, and means for issuing alerts for detected threats and executing necessary measures, thereby enabling real-time threat detection and countermeasures in a variety of environments including mobile devices.
[1231] "Generated protocols" refer to the procedures and rules for security measures created by a generative AI model.
[1232] "Means for automating security measures" refers to mechanisms that automatically execute defensive actions against threats based on the generated protocols.
[1233] "Means for encrypting and storing information" refers to a mechanism for securely storing information provided by users using encryption technology.
[1234] "Means for detecting threats and generating alerts in real time" refers to a mechanism that monitors abnormal activity within the system in real time, detects threats, and immediately issues an alert.
[1235] "Means for identifying the type of threat and selecting and implementing appropriate defensive measures" refers to a mechanism for determining the most appropriate defensive measures based on the characteristics of the identified threat and implementing them.
[1236] "Means for generating customized security solutions based on the needs of an enterprise" refers to methods and technologies that provide optimized security measures tailored to each enterprise's specific requirements and environment.
[1237] "Means for collecting real-time activity logs of mobile devices" refers to a mechanism for collecting activity logs of mobile information devices in real time.
[1238] "Means for detecting fraudulent activity using generative models" refers to techniques and methods that use generative models to identify fraudulent behavior from log data.
[1239] "Means of issuing alerts for detected threats and taking necessary measures" refers to a mechanism that issues warnings to users and administrators about detected threats and takes defensive measures as necessary.
[1240] The present invention is an advanced cybersecurity system that uses generative AI models to securely manage user information, detect threats in real time, respond quickly, and provide customized security solutions.
[1241] The main components of the system are as follows: Users use a sign-up form to enter their basic information (such as name, email address, and password) and send it to the server. The server receives this information, encrypts it using Fernet encryption technology, and securely stores it in a database. This prevents user information from being leaked.
[1242] A specific example of how we ensure data security is the process of encrypting and storing the basic information a user provides when signing up. For example, if a user provides the name "Yamada Taro" and the email address "taro@example.com," the server will encrypt and store this information.
[1243] The server then collects security-related data provided by the company and sends it to the generative AI model, which analyzes the data and generates optimal security protocols for the company. The server then provides these protocols to the company and assists with their implementation.
[1244] In addition, mobile devices collect activity logs in real time and send them to a server. The server analyzes this log data and uses generative models to detect malicious activity. For example, if access from an abnormal IP address or unauthorized file operations is detected, the server can immediately send an alert and prompt a response.
[1245] As a specific example, consider the case where an access from an unknown IP address is detected in the event log of a smartphone. In this case, the server immediately issues an alert and takes measures to quarantine the relevant file or activity. An example of a prompt for this process could be as follows:
[1246] text
[1247] Use the following log data to detect unauthorized activity:
[1248] Log data: "2023-11-01T12:34:56Z, Access from unknown IP address, Unauthorized modification of file 'example.exe'"
[1249] Expected result: Issue an alert and take action on access from unknown IP addresses and modification of the file 'example.exe' as suspicious.
[1250] The server then takes appropriate defensive measures against detected threats. For example, if malware is found, the server quarantines the file and removes it from the system. It also logs the defensive actions taken and their results.
[1251] Furthermore, the server generates customized security solutions based on each company's specific environment and needs, providing security measures optimized for each company's requirements. For example, for companies with high security requirements, special measures such as dual authentication and access restrictions from specific IP addresses can be proposed.
[1252] As described above, the system of the present invention encrypts user information, detects threats in real time, sends prompt alerts about fraudulent activity, and provides customized security solutions based on the needs of the company, thereby providing a high level of protection for the company's information systems.
[1253] The flow of the specific processing in the application example 1 will be described with reference to FIG.
[1254] (Program processing flow)
[1255] Step 1:
[1256] The user enters basic information (name, email address, password) into the sign-up form and submits it to the server.
[1257] Specifically, a user enters information into a form on a smartphone or computer screen and clicks the "Submit" button. The input data includes the user's name, email address, and password. This data is sent to the server as output.
[1258] Step 2:
[1259] The basic information received by the server is encrypted using encryption technology (Fernet) and stored in a secure database.
[1260] The server takes the data received from the user and encrypts it using Fernet. Specifically, it generates an encryption key and encrypts the user data. As an output, the encrypted data is stored in a secure database.
[1261] Step 3:
[1262] The server collects security-related data provided by companies and sends it to a generative AI model.
[1263] The server receives data on the company's security logs and system status and sends it to the generative AI model. Specifically, the data format is converted and any necessary preprocessing is performed before being input into the generative AI model. This data processing generates the optimal security protocol for the company.
[1264] Step 4:
[1265] The server provides companies with security protocols generated by the AI model and assists them in implementing them.
[1266] The server notifies the company administrator of the generated protocol and provides specific implementation procedures. The output is a textual description of the protocol and an implementation guide, which are optimized to meet the requirements of each company, ensuring smooth implementation.
[1267] Step 5:
[1268] The mobile device collects activity logs in real time and sends them to the server.
[1269] Specifically, the terminal monitors system logs and user actions, and periodically uploads the data to the server. Real-time log data is collected as input and sent to the server as output.
[1270] Step 6:
[1271] The server analyzes the log data and uses generative models to detect fraudulent activity.
[1272] The server analyzes the received log data in real time and performs anomaly detection using a generative AI model. Specifically, it analyzes IP addresses and user actions contained in the log data to identify anomalies. The output is a list of suspicious activity.
[1273] Step 7:
[1274] The server will send out an alert for any detected threats and take necessary measures.
[1275] Specifically, when an anomaly is detected, an alert is sent, and the relevant file is quarantined or access is blocked. Information about malicious activity is obtained as input, and alert notifications and countermeasures are executed as output.
[1276] Step 8:
[1277] The server logs the actions and results of detecting and preventing threats.
[1278] The server keeps a detailed record of the defensive actions taken and their results, stored in a secure database. Specific actions include logging the success / failure of the action and the next steps. As an output, the complete defensive log is stored in the database.
[1279] Furthermore, an emotion engine that estimates the user's emotion may be further combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59, and perform identification processing using the user's emotion.
[1280] The present invention relates to an advanced cybersecurity system that uses generative AI models to predict and neutralize cyber threats. Additionally, the present invention is combined with an emotion engine that recognizes user emotions and adjusts security measures based on the user's psychological state.
[1281] Basic System Configuration
[1282] User Registration and Authentication Process
[1283] Users enter basic information such as name, email address, and password into a sign-up form and submit it. The server receives this data, encrypts it, and stores it securely in a database. This process prevents user information from being leaked.
[1284] Security Protocol Generation
[1285] The server collects security-related data provided by the company and sends it to the generative AI model, which analyzes the data and generates a security protocol that is optimal for the company. The server then provides this protocol to the company and assists with its implementation.
[1286] Real-time Threat Analysis
[1287] The device collects log data on user activity and system events in real time and sends it to the server. The server analyzes this data, identifies threats in real time, and issues alerts to the user as needed. For example, if abnormal access or unauthorized file operations are detected, the server can immediately issue an alert and prompt a prompt response.
[1288] Neutralizing the threat
[1289] The server identifies the type of threat detected and selects and implements appropriate defense measures. For example, if malware is detected, the server quarantines the file and deletes it from the system. It also logs the defense actions taken and their results.
[1290] Customized Security Solutions
[1291] The server evaluates the individual needs of each company and generates customized security solutions based on them. For example, for companies with high security requirements, it can propose special measures such as dual authentication and restricting access from specific IP addresses.
[1292] Adding an Emotion Engine
[1293] Emotion recognition and stress assessment
[1294] By introducing an emotion engine, the system can recognize users' emotions in real time and analyze the data. For example, when a user logs into the system, the emotion engine can assess the user's stress level by analyzing their facial expressions and tone of voice using a camera or microphone.
[1295] Adjusting security measures based on emotions
[1296] The server adjusts security measures based on the user's emotions identified by the emotion engine. For example, if a user is in a state of high stress, the server can implement measures such as limiting the number of login attempts or providing extra careful monitoring.
[1297] Abnormal emotional change monitoring and alerts
[1298] The emotion engine monitors the user's emotional changes in real time, and if an abnormal emotional change (such as sudden anxiety or anger) is detected, the server immediately issues an alert, enabling early detection and response to internal threats and social engineering attacks.
[1299] Specific examples
[1300] For example, if the emotion engine detects that a company employee is feeling stressed at work, the server will temporarily restrict the employee's system access and send an alert to an administrator if an abnormality is detected. Also, if the user's facial expression is unusual, additional authentication measures will be used to prevent unauthorized access.
[1301] As described above, by combining a generative AI model and an emotion engine, the present invention enables real-time, multi-layered security measures and provides advanced protection for corporate information systems.
[1302] The processing flow will be explained below.
[1303] Basic System Configuration
[1304] User Registration and Authentication Process
[1305] Step 1:
[1306] A user fills out a sign-up form with basic information such as name, email address, and password.
[1307] Step 2:
[1308] The server receives the input data and temporarily stores the information sent by the user.
[1309] Step 3:
[1310] The server encrypts the data. The server encrypts the user information using the SSL / TLS protocol.
[1311] Step 4:
[1312] The server stores the encrypted data in a database. The server stores the encrypted user information securely in a database.
[1313] Security Protocol Generation Process
[1314] Step 1:
[1315] The server collects security-related data from the company. The server receives data provided by the company.
[1316] Step 2:
[1317] The server sends the data to the generative AI model. The server inputs the company data into the generative AI model and begins analysis.
[1318] Step 3:
[1319] The server receives the analysis results of the generative AI model and obtains the security protocol proposal created by the AI model.
[1320] Step 4:
[1321] The server provides the optimal security protocol to the enterprise, and then proposes the generated protocol to the enterprise and prepares to implement it.
[1322] Real-time threat analysis process
[1323] Step 1:
[1324] The device collects log data. The device collects logs of user activity and system events in real time.
[1325] Step 2:
[1326] The terminal sends the log data to the server. The terminal periodically sends the collected log data to the server.
[1327] Step 3:
[1328] The server analyzes the received data. The server analyzes the received log data using an AI model to detect anomalies.
[1329] Step 4:
[1330] The server detects anomalies and issues an alert to the user. The server notifies the user of the detected threat information.
[1331] Threat Neutralization Process
[1332] Step 1:
[1333] The server identifies the type of threat. The server identifies what kind of threat has been detected.
[1334] Step 2:
[1335] The server selects the defense measures. The server uses a generative AI model to select the defense measures that are most appropriate for the threat.
[1336] Step 3:
[1337] The server executes the defensive action. The server immediately executes the selected defensive measures to protect the system.
[1338] Step 4:
[1339] The server records the actions taken. The server logs the defensive actions taken and their results.
[1340] Customized Security Solution Proposal Process
[1341] Step 1:
[1342] The server assesses the company's needs. The server assesses the security needs from the data provided by the company.
[1343] Step 2:
[1344] The server generates a customized solution: The server uses the AI model to generate a customized security solution that meets the company's needs.
[1345] Step 3:
[1346] The server proposes solutions to companies. The server proposes the customized solutions it has created to companies.
[1347] Adding an Emotion Engine
[1348] Emotion recognition and stress appraisal processes
[1349] Step 1:
[1350] When a user logs in to the system, the device uses a camera and microphone to collect the user's facial expressions and tone of voice.
[1351] Step 2:
[1352] The device sends the collected data to the emotion engine, which analyzes the user's emotions.
[1353] Step 3:
[1354] The emotion engine evaluates the user's stress level and sends the results to the server.
[1355] Step 4:
[1356] The server adjusts security measures based on the evaluation results of the emotion engine. If the user is in a high stress state, additional security measures are implemented.
[1357] The process of adjusting security measures based on emotions
[1358] Step 1:
[1359] The server receives the evaluation results of the emotion engine and grasps the user's emotional state.
[1360] Step 2:
[1361] The server dynamically changes security settings based on the evaluation results, for example requiring additional authentication measures for users in high stress states.
[1362] Step 3:
[1363] The server executes the changed security settings and applies the configured security measures to the entire system.
[1364] Monitoring and alerting for abnormal emotional changes
[1365] Step 1:
[1366] The device monitors the user's emotional changes in real time by continuously collecting facial expressions and tone of voice.
[1367] Step 2:
[1368] The device sends the collected data to the emotion engine, which analyzes changes in emotions.
[1369] Step 3:
[1370] If the emotion engine detects an abnormal change in emotion, it sends that information to the server.
[1371] Step 4:
[1372] The server issues an alert based on abnormal emotional changes, and the server promptly notifies the administrator and takes appropriate measures.
[1373] Through these processing steps, CyberSecure's system combines generative AI models and emotion engines to provide real-time, multi-layered security measures to highly protect enterprise information systems.
[1374] Example 2
[1375] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."
[1376] As cyber attacks become more sophisticated and diverse, the information security of companies and individuals is threatened, making it difficult to respond adequately with traditional, fixed security measures. Furthermore, while it is known that users' psychological state affects security, the adoption of security measures based on this has been sparse. To solve these problems, a system is needed that enables real-time, advanced threat analysis and security measures based on users' emotional state.
[1377] The specific processing by the specific processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means.
[1378] In this invention, the server includes means for receiving information provided by users, encrypting it, and storing it in a database, means for detecting threats in real time and generating alerts, means for identifying the type of detected threat and selecting and implementing appropriate defensive measures, means for generating customized security solutions based on corporate needs, means for generating security protocols using the generated AI model and automating security measures based on the protocols, means for recognizing user emotions, analyzing the data, and adjusting security measures based on the emotional state, and means for monitoring abnormal emotional changes and issuing an alert when an abnormality is detected. This enables multi-layered security measures in real time, thereby providing advanced protection for corporate and individual information security.
[1379] "User-Provided Information" refers to your name, email address, password, and other personally identifiable information that you enter into the System.
[1380] "Encryption" refers to the process of converting information provided by a user using a specific algorithm to make it unreadable to third parties in order to protect it from unauthorized access or disclosure.
[1381] A "database" refers to an information system that organizes and stores user information and various data within the system, allowing it to be quickly searched and retrieved as needed.
[1382] "Real-time threat detection" refers to the process of continuously monitoring user activity and system events to immediately identify cyber threats, such as abnormal behavior or unauthorized access.
[1383] "Alert" refers to a warning message or notification system that promptly notifies users of detected threats.
[1384] "Threat type identification" refers to the process of identifying the type of cyber threat a detected threat falls into, such as malware, unauthorized access, or phishing.
[1385] "Defensive measures" refer to specific measures or actions that should be taken against identified threats, such as isolating or deleting files or restricting access.
[1386] A "customized security solution" refers to a set of security measures designed based on a company's specific needs and requirements.
[1387] "Generated AI model" refers to a system component that generates security protocols based on algorithms trained using machine learning or deep learning.
[1388] A "security protocol" refers to a set of rules and procedures for ensuring the security of a system, including access control, data encryption, and intrusion detection.
[1389] "Recognizing user emotions" refers to the process of using a camera and microphone to analyze a user's facial expressions and tone of voice to identify emotional states such as stress or anxiety.
[1390] "Adjusting security measures based on emotional state" refers to dynamically changing security measures, such as limiting the number of login attempts or strengthening specific monitoring, taking into account a user's real-time emotional state.
[1391] "Monitoring abnormal emotional changes" refers to the process of continuously monitoring a user's emotional state and detecting any sudden, unusual changes.
[1392] "Issuing an alert" refers to immediately issuing a warning to administrators and users when an abnormal emotional change or cyber threat is detected.
[1393] This invention is a system that utilizes generative AI models and emotion engines to predict and neutralize cyber threats in real time, providing advanced security measures based on the user's emotional state.
[1394] Hardware and Software Configuration
[1395] The main hardware for implementing the present invention includes:
[1396] Server: High-performance server (e.g., with Ubuntu OS)
[1397] Device: PC or smartphone used by the user
[1398] Camera and microphone: Devices for analyzing the user's facial expressions and voice
[1399] Key software includes:
[1400] Generative AI Models: Deep Learning Models Using TensorFlow
[1401] Emotion engine: Facial expression analysis using OpenCV and voice analysis using Amazon Polly
[1402] Database: MySQL or other RDBMS
[1403] System operation procedures and examples
[1404] 1. User Registration and Authentication:
[1405] Users enter and submit information such as their name, email address, and password through a web interface. The server receives this information and encrypts it using the AES encryption algorithm. The encrypted information is then securely stored in a MySQL database.
[1406] 2. Creating a security protocol:
[1407] The server collects security-related data provided by companies and inputs it into a generative AI model. The generative AI model analyzes the data using TensorFlow and generates an optimal security protocol. The server provides this protocol to the company and provides implementation support if necessary.
[1408] 3. Real-time threat analysis:
[1409] The device collects user activity and system event logs in real time and sends them to the server. The server receives this information and analyzes threats in real time. For example, if abnormal access is detected, the server will send an alert to the user saying, "Unauthorized access has been detected. Please take immediate action."
[1410] 4. Neutralize the threat:
[1411] The server identifies the type of threat detected and selects the most appropriate defense against malware, unauthorized access, etc. If malware is detected, the server immediately quarantines the file and deletes it from the system. All defense actions are also recorded as logs, which is useful for later incident analysis.
[1412] 5. Customized security solutions:
[1413] We assess the specific needs of your company and, if you have high security requirements, we will propose a dual authentication system or restrict access from specific IP addresses. These customized security solutions are provided flexibly to suit your company's security policy.
[1414] 6. Introducing the Emotion Engine:
[1415] When a user logs into the system, their facial expressions and tone of voice are collected in real time using a camera and microphone, and sent to the emotion engine, which uses OpenCV and Amazon Polly to analyze the data and assess the user's stress level and emotional state.
[1416] 7. Adjust security measures based on emotions:
[1417] If the emotion engine determines that a user is in a state of high stress, the server will limit the number of login attempts or monitor the user especially carefully. Also, if an abnormal emotional change is detected, such as sudden anxiety or anger, the server will immediately send an alert to the administrator.
[1418] Examples of prompt statements
[1419] "Build a system that analyzes users' emotions in real time and adjusts security measures according to their stress levels."
[1420] "Design an AI model that analyzes log data in real time and sends an alert when it detects abnormal access."
[1421] As described above, by combining a generative AI model and an emotion engine, the present invention enables real-time, multi-layered security measures to provide advanced protection for corporate and personal information systems.
[1422] The flow of the identification process in the second embodiment will be described with reference to FIG.
[1423] Program processing flow
[1424] Step 1: Enter your user registration information
[1425] A user enters basic information such as name, email address, and password into a web form and clicks the submit button.
[1426] Input: Basic information such as name, email address, and password.
[1427] Output: The information entered by the user is sent to the server.
[1428] Step 2: Receiving the data on the server
[1429] The server receives the information entered by the user. Specifically, it receives it as an HTTP POST request.
[1430] Input: Basic information submitted by the user.
[1431] Output: Received user information.
[1432] Step 3: Encrypt the data
[1433] The server encrypts the received user information, specifically using the AES encryption algorithm.
[1434] Input: Received user information.
[1435] Output: Encrypted user information.
[1436] Step 4: Saving to the Database
[1437] The server stores the encrypted user information in a database, specifically a MySQL database.
[1438] Input: Encrypted user information.
[1439] Output: User information stored securely in a database.
[1440] Step 5: Gather security data
[1441] The server collects security-related data such as network logs and system events provided by companies.
[1442] Input: Security-related data provided by the company.
[1443] Output: Collected security data.
[1444] Step 6: Sending data to the generative AI model
[1445] The server sends the collected security data to a generative AI model, specifically, TensorFlow, which analyzes the data.
[1446] Input: Collected security data.
[1447] Output: Analysis results from the generative AI model.
[1448] Step 7: Generate the protocol
[1449] The generative AI model generates optimal security protocols based on the analyzed data.
[1450] Input: The input data to a generative AI model.
[1451] Output: The generated security protocol.
[1452] Step 8: Provide the protocol to companies
[1453] The server provides the generated security protocols to the company and also assists with implementation if necessary.
[1454] Input: The generated security protocol.
[1455] Output: Protocols and supporting services provided to the company.
[1456] Step 9: Collect data on the device
[1457] The device collects real-time log data of user activity and system events.
[1458] Input: Log data of user activity and system events.
[1459] Output: The log data sent to the server.
[1460] Step 10: Sending data to the server
[1461] The terminal transmits the collected data to the server.
[1462] Input: Collected log data.
[1463] Output: The data sent to the server.
[1464] Step 11: Threat analysis on the server
[1465] The server analyzes the received log data and identifies threats in real time, for example, when abnormal access or unauthorized file operations are detected.
[1466] Input: The log data sent to the server.
[1467] Output: Identified threats and alert messages.
[1468] Step 12: Alert the user
[1469] The server immediately sends an alert message to the user in response to the identified threat.
[1470] Input: Identified threats.
[1471] Output: The alert message sent to the user.
[1472] Step 13: Identifying threats
[1473] The server identifies the type of threat detected, categorizing it as malware, unauthorized access, phishing attack, etc.
[1474] Input: Identified threats.
[1475] Output: Classified threat type.
[1476] Step 14: Select a defense
[1477] The server selects appropriate defenses against identified threats.
[1478] Input: Classified threat type.
[1479] Output: The selected defense.
[1480] Step 15: Implementing defenses
[1481] The server then executes the selected defense, for example, quarantining the file in case of malware and deleting it from the system.
[1482] Input: Selected defense.
[1483] Output: The defense measures taken and their logs.
[1484] Step 16: Assess your business needs
[1485] The server assesses the specific security needs of the enterprise.
[1486] Input: Corporate security needs.
[1487] Output: Evaluation results.
[1488] Step 17: Customized Solution Generation
[1489] The server generates customized security solutions based on the evaluation results, including, for example, dual authentication and restricting access from specific IP addresses.
[1490] Input: Evaluation result.
[1491] Output: Customized security solutions.
[1492] Step 18: Start Emotion Recognition
[1493] When a user logs into the system, the camera and microphone are activated.
[1494] Input: The user's state when logging into the system.
[1495] Output: Collected facial and speech data.
[1496] Step 19: Analyze Emotional Data
[1497] The emotion engine analyzes camera footage and audio data, specifically using OpenCV and Amazon Polly.
[1498] Input: Collected facial and speech data.
[1499] Output: Parsed emotion data.
[1500] Step 20: Stress Assessment
[1501] The emotion engine assesses the user's stress level based on the analyzed data.
[1502] Input: Parsed emotion data.
[1503] Output: Stress assessment results.
[1504] Step 21: Adjust security measures based on emotions
[1505] An emotion engine adjusts security measures based on the user's stress level, such as limiting the number of login attempts.
[1506] Input: Stress assessment results.
[1507] Output: Adjusted security measures.
[1508] Step 22: Monitor for unusual emotional changes
[1509] The emotion engine monitors the user's emotional changes in real time.
[1510] Input: Collected and analyzed emotion data.
[1511] Output: Continuous emotion change data.
[1512] Step 23: Alert when abnormal emotions are detected
[1513] If an abnormal emotion change is detected, the emotion engine immediately sends an alert to the server, which then notifies the administrator.
[1514] Input: Emotion data in which anomalies are detected.
[1515] Output: Server and administrator alert notification.
[1516] (Application example 2)
[1517] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."
[1518] Cyberattacks have become increasingly sophisticated and ingenious in recent years, causing many companies to suffer serious damage such as information leaks and system outages. Furthermore, because security measures do not take into account the psychological state of users, there is a high risk of exposure to threats caused by emotionally volatile behavior. Furthermore, real-time threat detection and response is technically difficult, and countermeasures based on user emotions are particularly lacking. To solve these problems, a comprehensive security system that takes user emotions into account using generative AI models is needed.
[1519] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 2 is realized by the following means.
[1520] In this invention, the server includes means for automating security measures based on the generated protocol, means for encrypting and storing information from a user, means for detecting threats in real time and generating alerts, means for identifying the type of threat and selecting and executing appropriate defensive measures, means for generating customized security solutions based on corporate needs, means for recognizing a user's emotions in real time using an emotion engine and assessing their stress level, means for adjusting security measures based on the emotions, means for monitoring abnormal emotional changes and issuing alerts to prompt a response, and means for providing security measures related to smartphones and head-mounted displays using the user's emotional state. This makes it possible to realize multi-layered security measures that take the user's psychological state into account in real time.
[1521] A "generated protocol" is a security procedure created based on data analyzed using a generative AI model.
[1522] "Means for automating security measures" refers to a system that automatically executes the generated protocols and satisfies security requirements.
[1523] "Means for encrypting and storing information from users" refers to technology for safely encrypting personal information and access data provided by users and storing them in a database.
[1524] "Means for detecting threats in real time and generating alerts" refers to a system that monitors activity within the system, immediately detects unauthorized access or abnormal behavior, and issues an alert.
[1525] "Means to identify the type of threat and select and implement appropriate defensive measures" refers to a system that classifies detected threats and automatically selects and implements the most appropriate security measures accordingly.
[1526] "Customized security solutions based on the needs of the enterprise" are defenses that are individually designed to take into account the unique security requirements of each enterprise.
[1527] "Means for recognizing a user's emotions in real time using an emotion engine and assessing stress levels" is a technology that analyzes a user's facial expressions and tone of voice to assess their psychological state and stress in real time.
[1528] The "means for adjusting security measures based on emotions" is a system that dynamically changes security settings and access restrictions according to the user's emotional state as assessed by an emotion engine.
[1529] The "means of monitoring abnormal emotional changes and issuing alerts to prompt a response" is a system that detects any sudden changes in a user's emotions and issues a warning to relevant parties.
[1530] "Means for providing security measures related to smartphones and head-mounted displays by utilizing the user's emotional state" is a technology that adjusts the security settings of smart devices based on the user's psychological state, supporting safe use.
[1531] System Program
[1532] The system program for realizing this application example mainly consists of the following elements:
[1533] 1. User authentication system:
[1534] - Hardware: Smartphone, Head-Mounted Display (HMD)
[1535] - Software: REST API, encryption library
[1536] 2. Emotion Recognition System:
[1537] - Hardware: Camera, microphone
[1538] - Software: OpenCV, TensorFlow / Keras (machine learning library)
[1539] 3. Real-time threat detection system:
[1540] - Hardware: User terminal
[1541] - Software: PyTorch (generative AI model), log analysis software
[1542] 4. Customized security solution system:
[1543] - Hardware: Server
[1544] - Software: Security protocol generation engine, database
[1545] System processing overview and specific examples
[1546] Handling user authentication
[1547] When a user accesses an application using a smartphone or HMD, the server first collects user information, encrypts it, and stores it in a database, thereby preventing information leakage.
[1548] Emotion recognition processing
[1549] When a user logs in, their facial expressions and tone of voice are captured in real time via a camera and microphone, and analyzed using OpenCV and TensorFlow / Keras. The resulting emotion engine evaluates the user's stress level.
[1550] Real-time threat detection and alerting
[1551] The user's device collects system activity and log data in real time and sends it to the server, which then analyzes it with a generative AI model (using PyTorch) to identify anomalies and threats, issuing alerts in real time and implementing necessary defensive measures.
[1552] Customized Security Solutions
[1553] The server generates optimal security protocols based on the company's security requirements, including restricting access from specific IP addresses and dual authentication.
[1554] Adjusting security measures based on emotions
[1555] The emotion engine monitors the user's emotional state in real time, and if a high level of stress is detected, the server automatically adjusts security measures, such as temporarily restricting system access if stress levels are high.
[1556] For example, if the emotion engine detects that a financial institution employee is experiencing stress while working, the server can temporarily restrict the employee's system access and send an alert to administrators. Additionally, if an employee is in an environment that is vulnerable to malicious attacks, the server can automatically adjust protocols to provide a safe working environment.
[1557] Example prompts for generative AI models
[1558] Here are some example prompts for a generative AI model to adjust security measures using an emotion engine:
[1559] "If users are stressed, suggest ways to limit login attempts and restrict system access."
[1560] "Please estimate what security measures would be effective based on the user's facial expression analysis data."
[1561] "Explain how you can analyze a user's emotional state in real time to predict cyber threats."
[1562] By using such prompts, the generative AI model can suggest appropriate countermeasures and prediction methods.
[1563] The flow of the specific processing in the application example 2 will be described with reference to FIG.
[1564] Step 1:
[1565] User Authentication
[1566] A user enters their credentials to log into the application, which are sent to the server where they are encrypted and stored in a database.
[1567] Input: User authentication information (user ID, password, etc.).
[1568] Data processing: Encryption of authentication information.
[1569] Output: Encrypted credentials stored in the database.
[1570] What it does: Receives authentication information via a REST API, encrypts the data using an encryption library, and then stores it in the database.
[1571] Step 2:
[1572] emotion recognition
[1573] The moment a user logs in, the device's camera and microphone are used to capture facial expressions and tone of voice, which are then analyzed by the emotion engine. OpenCV and TensorFlow / Keras are used to evaluate the user's emotional state (e.g., stress level).
[1574] Input: Real-time data from camera and microphone (facial expressions, tone of voice).
[1575] Data processing: Analysis of image and audio data.
[1576] Output: The user's emotional state (stress level) is assessed.
[1577] Specific operation: Data obtained from the camera and microphone is processed using OpenCV to recognize faces and analyze facial expressions. Analysis is performed using an emotion model using TensorFlow / Keras.
[1578] Step 3:
[1579] Real-time Threat Detection
[1580] The user device collects future system activity and log data in real time and sends it to the server, which then uses a generative AI model (powered by PyTorch) to detect threats from this data in real time.
[1581] Input: System logs and activity data from the device.
[1582] Data processing: Analyze collected data using generative AI models.
[1583] Output: Information and alerts about detected threats.
[1584] How it works: Log analysis software is used to collect data from user devices, which is then analyzed using a generative AI model built with PyTorch. If an anomaly is detected, an alert is issued immediately.
[1585] Step 4:
[1586] Threat response
[1587] The server automatically selects and implements appropriate defensive measures based on the type of threat detected.
[1588] Input: Information about the detected threat.
[1589] Data manipulation: Select appropriate defenses.
[1590] Output: The defensive measures taken and their results.
[1591] Specific operation: Identifies the type of threat and selects and executes corresponding defense measures (e.g., malware isolation, access restriction) on the server side.
[1592] Step 5:
[1593] Providing customized security solutions
[1594] The server generates a customized security solution tailored to each company's needs.
[1595] Input: Data about your company's security needs.
[1596] Data processing: security protocol generation.
[1597] Output: A customized security solution.
[1598] Specific behavior: Uses a security protocol generation engine to execute countermeasures based on the generated protocol.
[1599] Step 6:
[1600] Adjusting security measures based on emotions
[1601] The emotion engine monitors the user's emotional state, and if a high stress state is detected, the server dynamically adjusts security measures.
[1602] Input: User emotional state data.
[1603] Data manipulation: Adjusting security measures based on emotional state.
[1604] Output: Adjusted security settings.
[1605] Specific actions: The server receives data from the emotion engine and takes actions such as temporarily restricting system access for users with high stress levels.
[1606] Step 7:
[1607] Abnormal Emotion Change Alerts
[1608] The emotion engine monitors the user's emotional state in real time, and the server issues an alert if an abnormality occurs.
[1609] Input: User's emotional change data.
[1610] Data processing: Detection and evaluation of abnormal emotional changes.
[1611] Output: Issue an alert.
[1612] Specific operation: When the emotion engine detects an abnormal change in emotion, it sends the information to the server, which then issues an alert to the administrator and prompts them to take action.
[1613] The specific processing unit 290 transmits the result of the specific processing to the headset type terminal 314. In the headset type terminal 314, the control unit 46A causes the speaker 240 and the display 343 to output the result of the specific processing. The microphone 238 acquires audio indicating a user input regarding the result of the specific processing. The control unit 46A transmits audio data indicating the user input acquired by the microphone 238 to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.
[1614] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[1615] In the above embodiment, an example was given in which the specific processing is performed by the data processing device 12, but the technology of the present disclosure is not limited to this, and the specific processing may be performed by the headset type terminal 314.
[1616] [Fourth embodiment]
[1617] FIG. 7 shows an example of the configuration of a data processing system 410 according to the fourth embodiment.
[1618] 7, a data processing system 410 includes a data processing device 12 and a robot 414. An example of the data processing device 12 is a server.
[1619] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[1620] The robot 414 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication I / F 44, and a control target 443. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The microphone 238, the speaker 240, the camera 42, and the control target 443 are also connected to the bus 52.
[1621] The microphone 238 receives instructions and the like from the user 20 by receiving voice uttered by the user 20. The microphone 238 captures the voice uttered by the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio in accordance with instructions from the processor 46.
[1622] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the surroundings of user 20 (for example, an imaging range defined by an angle of view equivalent to the field of vision of a typical healthy person).
[1623] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 are responsible for the exchange of various information between the processor 46 and the processor 28 via the network 54. The exchange of various information between the processor 46 and the processor 28 using the communication I / Fs 44 and 26 is carried out in a secure state.
[1624] The control object 443 includes a display device, LEDs in the eyes, and motors for driving the arms, hands, and feet. The posture and gestures of the robot 414 are controlled by controlling the motors of the arms, hands, and feet. Some of the emotions of the robot 414 can be expressed by controlling these motors. In addition, the facial expressions of the robot 414 can also be expressed by controlling the light emission state of the LEDs in the eyes of the robot 414.
[1625] Fig. 8 shows an example of the main functions of the data processing device 12 and the robot 414. As shown in Fig. 8, in the data processing device 12, a specific process is performed by the processor 28. A specific process program 56 is stored in the storage 32.
[1626] The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[1627] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[1628] In the robot 414, the processor 46 performs the reception output process. A reception output program 60 is stored in the storage 50. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.
[1629] Next, a description will be given of the specific processing performed by the specific processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."
[1630] The present invention relates to an advanced cybersecurity system that uses generative AI models to predict and neutralize cyber threats, providing a set of automated security measures to protect enterprise information systems.
[1631] Specifically, the main components of the system are as follows: Users enter basic information (such as name, email address, and password) into a sign-up form and send it to the server. The server receives this information, encrypts it, and stores it securely in a database. This prevents user information from being leaked.
[1632] The server then collects security-related data provided by the company and sends it to the generative AI model, which analyzes the input data and generates the optimal security protocol for the company. The server then provides this protocol to the company and assists with its implementation.
[1633] The device also collects real-time log data on user activity and system events and sends it to the server. The server analyzes this data, identifies threats in real time, and issues alerts to users as needed. For example, if abnormal access or unauthorized file operations are detected, the server can immediately issue an alert and prompt a prompt response.
[1634] The server also identifies the type of threat detected and selects and implements appropriate defense measures. For example, if malware is detected, the server quarantines the file and removes it from the system. It also logs the defense actions taken and their results.
[1635] Finally, the server evaluates each company's individual needs and generates a customized security solution based on them. This provides security measures optimized for each company's specific environment and requirements. For example, companies with high security requirements can be offered special measures such as dual authentication and access restrictions from specific IP addresses.
[1636] As described above, the system of the present invention can provide a high level of protection for corporate information systems by providing secure management of user information, real-time threat detection, rapid response to threats, and customized security solutions.
[1637] The processing flow will be explained below.
[1638] User Registration and Authentication Process
[1639] Step 1:
[1640] A user fills out a sign-up form with basic information such as name, email address, and password.
[1641] Step 2:
[1642] The server receives the input data and temporarily stores the information sent by the user.
[1643] Step 3:
[1644] The server encrypts the data. The server encrypts the user information using the SSL / TLS protocol.
[1645] Step 4:
[1646] The server stores the encrypted data in a database. The server stores the encrypted user information securely in a database.
[1647] Security Protocol Generation Process
[1648] Step 1:
[1649] The server collects security-related data from the company. The server receives data provided by the company.
[1650] Step 2:
[1651] The server sends the data to the generative AI model. The server inputs the company data into the generative AI model and begins analysis.
[1652] Step 3:
[1653] The server receives the analysis results of the generative AI model and obtains the security protocol proposal created by the AI model.
[1654] Step 4:
[1655] The server provides the optimal security protocol to the enterprise, and then proposes the generated protocol to the enterprise and prepares to implement it.
[1656] Real-time threat analysis process
[1657] Step 1:
[1658] The device collects log data. The device collects logs of user activity and system events in real time.
[1659] Step 2:
[1660] The terminal sends the log data to the server. The terminal periodically sends the collected log data to the server.
[1661] Step 3:
[1662] The server analyzes the received data. The server analyzes the received log data using an AI model to detect anomalies.
[1663] Step 4:
[1664] The server detects anomalies and issues an alert to the user. The server notifies the user of the detected threat information.
[1665] Threat Neutralization Process
[1666] Step 1:
[1667] The server identifies the type of threat. The server identifies what kind of threat has been detected.
[1668] Step 2:
[1669] The server selects the defense measures. The server uses a generative AI model to select the defense measures that are most appropriate for the threat.
[1670] Step 3:
[1671] The server executes the defensive action. The server immediately executes the selected defensive measures to protect the system.
[1672] Step 4:
[1673] The server records the actions taken. The server logs the defensive actions taken and their results.
[1674] Customized Security Solution Proposal Process
[1675] Step 1:
[1676] The server assesses the company's needs. The server assesses the security needs from the data provided by the company.
[1677] Step 2:
[1678] The server generates a customized solution: The server uses the AI model to generate a customized security solution that meets the company's needs.
[1679] Step 3:
[1680] The server proposes solutions to companies. The server proposes the customized solutions it has created to companies.
[1681] Through the above processing steps, CyberSecure can provide comprehensive and advanced cybersecurity services to businesses.
[1682] Example 1
[1683] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."
[1684] Current cybersecurity systems have difficulty efficiently detecting threats in real time and implementing appropriate defensive measures. Furthermore, they are not sufficiently customized to meet the unique security needs of each company, leaving security flaws vulnerable to failure. The purpose of this invention is to solve these problems and provide advanced protection for corporate information systems.
[1685] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.
[1686] In this invention, the server includes means for encrypting and storing information from users, means for collecting security data provided by companies and sending it to an analysis model, means for generating security protocols optimal for the companies based on the analyzed data, means for collecting log data of user activities and system events in real time and sending it to a central processing unit, means for detecting threats in real time and generating alerts, means for identifying the type of threat and selecting and executing appropriate defensive measures, and means for generating security solutions customized based on the needs of the companies, thereby enabling secure management of user information, real-time threat detection, rapid response to threats, and security measures optimized for each company.
[1687] "User information" refers to basic information such as name, email address, and password that a user provides to the system.
[1688] "Encryption" is the process of converting data using a specific algorithm to make it unreadable to third parties in order to protect it from unauthorized access.
[1689] "Security data" refers to security-related information such as firewall logs and access logs provided by companies.
[1690] An "analytical model" is a mathematical algorithm or machine learning model used to analyze data, such as a generative AI model.
[1691] A "security protocol" is a set of security rules and procedures established to protect a company's information systems.
[1692] An "activity log" is a record of operations and events that occur when a user uses a system.
[1693] A "central processing unit" is the system's main computer that collects and analyzes data, identifies threats, and generates alerts.
[1694] "Threat detection" refers to the analysis of security data and other information to identify security risks and abnormal behavior in a system.
[1695] "Defense measures" are specific countermeasures or action steps taken against detected threats.
[1696] A "customized security solution" is a security measure that is optimized to meet the specific needs of each company.
[1697] The present invention is an advanced cybersecurity system that uses generative AI models to predict and neutralize cyber threats, and provides a set of automated security measures to protect enterprise information systems. Specific embodiments of the present invention are described in detail below.
[1698] Collecting and storing user information
[1699] First, a user enters basic information such as name, email address, and password into the sign-up form and submits the form data. The server receives the information submitted by the user and encrypts the data using the AES-256 algorithm. The encrypted data is securely stored in a MySQL database. This prevents user information from being leaked.
[1700] Examples:
[1701] Text format
[1702] When a user enters their information into the sign-up form and hits the submit button, the information is transferred to the server, which encrypts the data using the AES-256 algorithm and stores it in a MySQL database.
[1703] Security data collection and analysis
[1704] Corporate security administrators provide security data such as firewall logs and access logs. The server collects the security data and sends it to the generative AI model. The generative AI model analyzes the data using Python and TensorFlow and generates optimal security protocols for the company. These protocols are then sent to the corporate security officer via the server, who assists with implementation.
[1705] Examples:
[1706] Text format
[1707] The server collects security data provided by the company and analyzes it using an AI model built with TensorFlow. As a result, optimal security protocols are generated and notified to the company's security personnel.
[1708] Real-time activity and event logging
[1709] User devices collect activity data and system event logs in real time. Syslog is used for this log collection. The collected log data is sent to a server, which analyzes it in real time to identify abnormal behavior and security threats. Alerts are sent to users and security personnel as needed.
[1710] Examples:
[1711] Text format
[1712] Using Syslog, terminals collect user activity logs and system event logs in real time and send them to the server, which analyzes them instantly and issues alerts as soon as an abnormality is detected.
[1713] Detecting threats and taking preventative measures
[1714] When the server detects a threat, it identifies the type of threat and selects the appropriate defense measures. For example, if malware is detected, the server uses anti-malware software (ClamAV) to quarantine and delete the file. It also records the defense measures taken and their results in a detailed log.
[1715] Examples:
[1716] Text format
[1717] If the server detects a threat, it will take the necessary defensive measures. For example, if ClamAV detects malware, it will quarantine and delete the file. It will then record the defensive measures taken and the results in a detailed log.
[1718] Creating a customized security solution
[1719] The server assesses each company's individual needs and generates a customized security solution based on those needs, such as dual authentication (e.g., authentication applications) or restricting access from specific IP addresses, providing security measures optimized for each company's specific environment and requirements.
[1720] Examples:
[1721] Text format
[1722] Our server assesses your company's specific needs and generates customized security solutions, such as using authentication applications for double authentication and recommending settings to allow access only from specific IP addresses. We then assist you in implementing these solutions.
[1723] This system enables secure management of user information, real-time threat detection, rapid response to threats, and customized security solutions tailored to individual needs, thereby providing advanced protection for corporate information systems.
[1724] The flow of the identification process in the first embodiment will be described with reference to FIG.
[1725] Step 1:
[1726] A user enters basic information into a sign-up form (such as name, email address, and password). The entered data is sent from the device to the server by clicking the submit button. Specifically, the user enters information into a form and presses the "Submit" button.
[1727] Input: User information such as name, email address, and password
[1728] Output: HTTP request with user information
[1729] Step 2:
[1730] The server receives the information sent by the user, encrypts it using the AES-256 algorithm, and securely stores the encrypted data in a database. Specifically, the server receives an HTTP request, performs encryption processing, and then stores the encrypted data in a database.
[1731] Input: HTTP request containing user information
[1732] Output: Encrypted user information
[1733] Step 3:
[1734] A company's security administrator provides the system with security data such as firewall logs and access logs. The server collects this security data and sends it to the generative AI model. After collecting the data, the server transmits it to the AI model and prepares it for analysis.
[1735] Input: Security data (firewall logs, access logs, etc.)
[1736] Output: Security data formatted in a parsable format
[1737] Step 4:
[1738] The generative AI model analyzes the collected data using Python and TensorFlow and generates the optimal security protocol for the company. The server receives the analysis results and notifies the company's security personnel. Specifically, the generative AI model analyzes the data and returns the analysis results to the server.
[1739] Input: Formatted security data
[1740] Output: Best security protocols for businesses
[1741] Step 5:
[1742] The terminal collects user activity logs and system event logs in real time and sends them to the server. The terminal uses Syslog to collect log data and transmits it to the server.
[1743] Input: User activity log, system event log
[1744] Output: Collected log data
[1745] Step 6:
[1746] The server analyzes the received log data in real time to identify abnormal behavior and security threats, and issues alerts to users and security personnel as needed. The server analyzes the log data and generates notifications if an alert condition is met.
[1747] Input: Collected log data
[1748] Output: Threat detection results, alert notifications
[1749] Step 7:
[1750] The server identifies the type of threat detected and selects and executes appropriate defense measures. For example, if malware is detected, the server uses anti-malware software (ClamAV) to quarantine and delete the file. It also records the defense measures taken and their results in a detailed log.
[1751] Input: Threat detection results
[1752] Output: Defense measures execution results, detailed log
[1753] Step 8:
[1754] The server evaluates a company's individual needs and generates and provides customized security solutions based on those needs. Specific solutions include dual authentication and restricting access from specific IP addresses. Support for the implementation of these solutions is also provided.
[1755] Input: Corporate security needs
[1756] Output: Customized security solutions
[1757] (Application example 1)
[1758] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."
[1759] Conventional cybersecurity systems face problems such as insufficient real-time threat detection and appropriate countermeasures. Delays in detecting and countering malicious activity on mobile devices, in particular, pose a high risk of compromising security. It is also difficult to provide customized security solutions that address the unique needs of each company. There is a need to solve these problems and achieve advanced security.
[1760] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.
[1761] In this invention, the server includes means for automating security countermeasures based on the generated protocol, means for encrypting and storing information from a user, means for detecting threats in real time and generating alerts, means for identifying the type of threat and selecting and executing appropriate defensive measures, means for generating customized security solutions based on the needs of a company, means for collecting real-time activity logs of mobile devices and detecting unauthorized activity using a generative model, and means for issuing alerts for detected threats and executing necessary measures, thereby enabling real-time threat detection and countermeasures in a variety of environments including mobile devices.
[1762] "Generated protocols" refer to the procedures and rules for security measures created by a generative AI model.
[1763] "Means for automating security measures" refers to mechanisms that automatically execute defensive actions against threats based on the generated protocols.
[1764] "Means for encrypting and storing information" refers to a mechanism for securely storing information provided by users using encryption technology.
[1765] "Means for detecting threats and generating alerts in real time" refers to a mechanism that monitors abnormal activity within the system in real time, detects threats, and immediately issues an alert.
[1766] "Means for identifying the type of threat and selecting and implementing appropriate defensive measures" refers to a mechanism for determining the most appropriate defensive measures based on the characteristics of the identified threat and implementing them.
[1767] "Means for generating customized security solutions based on the needs of an enterprise" refers to methods and technologies that provide optimized security measures tailored to each enterprise's specific requirements and environment.
[1768] "Means for collecting real-time activity logs of mobile devices" refers to a mechanism for collecting activity logs of mobile information devices in real time.
[1769] "Means for detecting fraudulent activity using generative models" refers to techniques and methods that use generative models to identify fraudulent behavior from log data.
[1770] "Means of issuing alerts for detected threats and taking necessary measures" refers to a mechanism that issues warnings to users and administrators about detected threats and takes defensive measures as necessary.
[1771] The present invention is an advanced cybersecurity system that uses generative AI models to securely manage user information, detect threats in real time, respond quickly, and provide customized security solutions.
[1772] The main components of the system are as follows: Users use a sign-up form to enter their basic information (such as name, email address, and password) and send it to the server. The server receives this information, encrypts it using Fernet encryption technology, and securely stores it in a database. This prevents user information from being leaked.
[1773] A specific example of how we ensure data security is the process of encrypting and storing the basic information a user provides when signing up. For example, if a user provides the name "Yamada Taro" and the email address "taro@example.com," the server will encrypt and store this information.
[1774] The server then collects security-related data provided by the company and sends it to the generative AI model, which analyzes the data and generates optimal security protocols for the company. The server then provides these protocols to the company and assists with their implementation.
[1775] In addition, mobile devices collect activity logs in real time and send them to a server. The server analyzes this log data and uses generative models to detect malicious activity. For example, if access from an abnormal IP address or unauthorized file operations is detected, the server can immediately send an alert and prompt a response.
[1776] As a specific example, consider the case where an access from an unknown IP address is detected in the event log of a smartphone. In this case, the server immediately issues an alert and takes measures to quarantine the relevant file or activity. An example of a prompt for this process could be as follows:
[1777] text
[1778] Use the following log data to detect unauthorized activity:
[1779] Log data: "2023-11-01T12:34:56Z, Access from unknown IP address, Unauthorized modification of file 'example.exe'"
[1780] Expected result: Issue an alert and take action on access from unknown IP addresses and modification of the file 'example.exe' as suspicious.
[1781] The server then takes appropriate defensive measures against detected threats. For example, if malware is found, the server quarantines the file and removes it from the system. It also logs the defensive actions taken and their results.
[1782] Furthermore, the server generates customized security solutions based on each company's specific environment and needs, providing security measures optimized for each company's requirements. For example, for companies with high security requirements, special measures such as dual authentication and access restrictions from specific IP addresses can be proposed.
[1783] As described above, the system of the present invention encrypts user information, detects threats in real time, sends prompt alerts about fraudulent activity, and provides customized security solutions based on the needs of the company, thereby providing a high level of protection for the company's information systems.
[1784] The flow of the specific processing in the application example 1 will be described with reference to FIG.
[1785] (Program processing flow)
[1786] Step 1:
[1787] The user enters basic information (name, email address, password) into the sign-up form and submits it to the server.
[1788] Specifically, a user enters information into a form on a smartphone or computer screen and clicks the "Submit" button. The input data includes the user's name, email address, and password. This data is sent to the server as output.
[1789] Step 2:
[1790] The basic information received by the server is encrypted using encryption technology (Fernet) and stored in a secure database.
[1791] The server takes the data received from the user and encrypts it using Fernet. Specifically, it generates an encryption key and encrypts the user data. As an output, the encrypted data is stored in a secure database.
[1792] Step 3:
[1793] The server collects security-related data provided by companies and sends it to a generative AI model.
[1794] The server receives data on the company's security logs and system status and sends it to the generative AI model. Specifically, the data format is converted and any necessary preprocessing is performed before being input into the generative AI model. This data processing generates the optimal security protocol for the company.
[1795] Step 4:
[1796] The server provides companies with security protocols generated by the AI model and assists them in implementing them.
[1797] The server notifies the company administrator of the generated protocol and provides specific implementation procedures. The output is a textual description of the protocol and an implementation guide, which are optimized to meet the requirements of each company, ensuring smooth implementation.
[1798] Step 5:
[1799] The mobile device collects activity logs in real time and sends them to the server.
[1800] Specifically, the terminal monitors system logs and user actions, and periodically uploads the data to the server. Real-time log data is collected as input and sent to the server as output.
[1801] Step 6:
[1802] The server analyzes the log data and uses generative models to detect fraudulent activity.
[1803] The server analyzes the received log data in real time and performs anomaly detection using a generative AI model. Specifically, it analyzes IP addresses and user actions contained in the log data to identify anomalies. The output is a list of suspicious activity.
[1804] Step 7:
[1805] The server will send out an alert for any detected threats and take necessary measures.
[1806] Specifically, when an anomaly is detected, an alert is sent, and the relevant file is quarantined or access is blocked. Information about malicious activity is obtained as input, and alert notifications and countermeasures are executed as output.
[1807] Step 8:
[1808] The server logs the actions and results of detecting and preventing threats.
[1809] The server keeps a detailed record of the defensive actions taken and their results, stored in a secure database. Specific actions include logging the success / failure of the action and the next steps. As an output, the complete defensive log is stored in the database.
[1810] Furthermore, an emotion engine that estimates the user's emotion may be further combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59, and perform identification processing using the user's emotion.
[1811] The present invention relates to an advanced cybersecurity system that uses generative AI models to predict and neutralize cyber threats. Additionally, the present invention is combined with an emotion engine that recognizes user emotions and adjusts security measures based on the user's psychological state.
[1812] Basic System Configuration
[1813] User Registration and Authentication Process
[1814] Users enter basic information such as name, email address, and password into a sign-up form and submit it. The server receives this data, encrypts it, and stores it securely in a database. This process prevents user information from being leaked.
[1815] Security Protocol Generation
[1816] The server collects security-related data provided by the company and sends it to the generative AI model, which analyzes the data and generates a security protocol that is optimal for the company. The server then provides this protocol to the company and assists with its implementation.
[1817] Real-time Threat Analysis
[1818] The device collects log data on user activity and system events in real time and sends it to the server. The server analyzes this data, identifies threats in real time, and issues alerts to the user as needed. For example, if abnormal access or unauthorized file operations are detected, the server can immediately issue an alert and prompt a prompt response.
[1819] Neutralizing the threat
[1820] The server identifies the type of threat detected and selects and implements appropriate defense measures. For example, if malware is detected, the server quarantines the file and deletes it from the system. It also logs the defense actions taken and their results.
[1821] Customized Security Solutions
[1822] The server evaluates the individual needs of each company and generates customized security solutions based on them. For example, for companies with high security requirements, it can propose special measures such as dual authentication and restricting access from specific IP addresses.
[1823] Adding an Emotion Engine
[1824] Emotion recognition and stress assessment
[1825] By introducing an emotion engine, the system can recognize users' emotions in real time and analyze the data. For example, when a user logs into the system, the emotion engine can assess the user's stress level by analyzing their facial expressions and tone of voice using a camera or microphone.
[1826] Adjusting security measures based on emotions
[1827] The server adjusts security measures based on the user's emotions identified by the emotion engine. For example, if a user is in a state of high stress, the server can implement measures such as limiting the number of login attempts or providing extra careful monitoring.
[1828] Abnormal emotional change monitoring and alerts
[1829] The emotion engine monitors the user's emotional changes in real time, and if an abnormal emotional change (such as sudden anxiety or anger) is detected, the server immediately issues an alert, enabling early detection and response to internal threats and social engineering attacks.
[1830] Specific examples
[1831] For example, if the emotion engine detects that a company employee is feeling stressed at work, the server will temporarily restrict the employee's system access and send an alert to an administrator if an abnormality is detected. Also, if the user's facial expression is unusual, additional authentication measures will be used to prevent unauthorized access.
[1832] As described above, by combining a generative AI model and an emotion engine, the present invention enables real-time, multi-layered security measures and provides advanced protection for corporate information systems.
[1833] The processing flow will be explained below.
[1834] Basic System Configuration
[1835] User Registration and Authentication Process
[1836] Step 1:
[1837] A user fills out a sign-up form with basic information such as name, email address, and password.
[1838] Step 2:
[1839] The server receives the input data and temporarily stores the information sent by the user.
[1840] Step 3:
[1841] The server encrypts the data. The server encrypts the user information using the SSL / TLS protocol.
[1842] Step 4:
[1843] The server stores the encrypted data in a database. The server stores the encrypted user information securely in a database.
[1844] Security Protocol Generation Process
[1845] Step 1:
[1846] The server collects security-related data from the company. The server receives data provided by the company.
[1847] Step 2:
[1848] The server sends the data to the generative AI model. The server inputs the company data into the generative AI model and begins analysis.
[1849] Step 3:
[1850] The server receives the analysis results of the generative AI model and obtains the security protocol proposal created by the AI model.
[1851] Step 4:
[1852] The server provides the optimal security protocol to the enterprise, and then proposes the generated protocol to the enterprise and prepares to implement it.
[1853] Real-time threat analysis process
[1854] Step 1:
[1855] The device collects log data. The device collects logs of user activity and system events in real time.
[1856] Step 2:
[1857] The terminal sends the log data to the server. The terminal periodically sends the collected log data to the server.
[1858] Step 3:
[1859] The server analyzes the received data. The server analyzes the received log data using an AI model to detect anomalies.
[1860] Step 4:
[1861] The server detects anomalies and issues an alert to the user. The server notifies the user of the detected threat information.
[1862] Threat Neutralization Process
[1863] Step 1:
[1864] The server identifies the type of threat. The server identifies what kind of threat has been detected.
[1865] Step 2:
[1866] The server selects the defense measures. The server uses a generative AI model to select the defense measures that are most appropriate for the threat.
[1867] Step 3:
[1868] The server executes the defensive action. The server immediately executes the selected defensive measures to protect the system.
[1869] Step 4:
[1870] The server records the actions taken. The server logs the defensive actions taken and their results.
[1871] Customized Security Solution Proposal Process
[1872] Step 1:
[1873] The server assesses the company's needs. The server assesses the security needs from the data provided by the company.
[1874] Step 2:
[1875] The server generates a customized solution: The server uses the AI model to generate a customized security solution that meets the company's needs.
[1876] Step 3:
[1877] The server proposes solutions to companies. The server proposes the customized solutions it has created to companies.
[1878] Adding an Emotion Engine
[1879] Emotion recognition and stress appraisal processes
[1880] Step 1:
[1881] When a user logs in to the system, the device uses a camera and microphone to collect the user's facial expressions and tone of voice.
[1882] Step 2:
[1883] The device sends the collected data to the emotion engine, which analyzes the user's emotions.
[1884] Step 3:
[1885] The emotion engine evaluates the user's stress level and sends the results to the server.
[1886] Step 4:
[1887] The server adjusts security measures based on the evaluation results of the emotion engine. If the user is in a high stress state, additional security measures are implemented.
[1888] The process of adjusting security measures based on emotions
[1889] Step 1:
[1890] The server receives the evaluation results of the emotion engine and grasps the user's emotional state.
[1891] Step 2:
[1892] The server dynamically changes security settings based on the evaluation results, for example requiring additional authentication measures for users in high stress states.
[1893] Step 3:
[1894] The server executes the changed security settings and applies the configured security measures to the entire system.
[1895] Monitoring and alerting for abnormal emotional changes
[1896] Step 1:
[1897] The device monitors the user's emotional changes in real time by continuously collecting facial expressions and tone of voice.
[1898] Step 2:
[1899] The device sends the collected data to the emotion engine, which analyzes changes in emotions.
[1900] Step 3:
[1901] If the emotion engine detects an abnormal change in emotion, it sends that information to the server.
[1902] Step 4:
[1903] The server issues an alert based on abnormal emotional changes, and the server promptly notifies the administrator and takes appropriate measures.
[1904] Through these processing steps, CyberSecure's system combines generative AI models and emotion engines to provide real-time, multi-layered security measures to highly protect enterprise information systems.
[1905] Example 2
[1906] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."
[1907] As cyber attacks become more sophisticated and diverse, the information security of companies and individuals is threatened, making it difficult to respond adequately with traditional, fixed security measures. Furthermore, while it is known that users' psychological state affects security, the adoption of security measures based on this has been sparse. To solve these problems, a system is needed that enables real-time, advanced threat analysis and security measures based on users' emotional state.
[1908] The specific processing by the specific processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means.
[1909] In this invention, the server includes means for receiving information provided by users, encrypting it, and storing it in a database, means for detecting threats in real time and generating alerts, means for identifying the type of detected threat and selecting and implementing appropriate defensive measures, means for generating customized security solutions based on corporate needs, means for generating security protocols using the generated AI model and automating security measures based on the protocols, means for recognizing user emotions, analyzing the data, and adjusting security measures based on the emotional state, and means for monitoring abnormal emotional changes and issuing an alert when an abnormality is detected. This enables multi-layered security measures in real time, thereby providing advanced protection for corporate and individual information security.
[1910] "User-Provided Information" refers to your name, email address, password, and other personally identifiable information that you enter into the System.
[1911] "Encryption" refers to the process of converting information provided by a user using a specific algorithm to make it unreadable to third parties in order to protect it from unauthorized access or disclosure.
[1912] A "database" refers to an information system that organizes and stores user information and various data within the system, allowing it to be quickly searched and retrieved as needed.
[1913] "Real-time threat detection" refers to the process of continuously monitoring user activity and system events to immediately identify cyber threats, such as abnormal behavior or unauthorized access.
[1914] "Alert" refers to a warning message or notification system that promptly notifies users of detected threats.
[1915] "Threat type identification" refers to the process of identifying the type of cyber threat a detected threat falls into, such as malware, unauthorized access, or phishing.
[1916] "Defensive measures" refer to specific measures or actions that should be taken against identified threats, such as isolating or deleting files or restricting access.
[1917] A "customized security solution" refers to a set of security measures designed based on a company's specific needs and requirements.
[1918] "Generated AI model" refers to a system component that generates security protocols based on algorithms trained using machine learning or deep learning.
[1919] A "security protocol" refers to a set of rules and procedures for ensuring the security of a system, including access control, data encryption, and intrusion detection.
[1920] "Recognizing user emotions" refers to the process of using a camera and microphone to analyze a user's facial expressions and tone of voice to identify emotional states such as stress or anxiety.
[1921] "Adjusting security measures based on emotional state" refers to dynamically changing security measures, such as limiting the number of login attempts or strengthening specific monitoring, taking into account a user's real-time emotional state.
[1922] "Monitoring abnormal emotional changes" refers to the process of continuously monitoring a user's emotional state and detecting any sudden, unusual changes.
[1923] "Issuing an alert" refers to immediately issuing a warning to administrators and users when an abnormal emotional change or cyber threat is detected.
[1924] This invention is a system that utilizes generative AI models and emotion engines to predict and neutralize cyber threats in real time, providing advanced security measures based on the user's emotional state.
[1925] Hardware and Software Configuration
[1926] The main hardware for implementing the present invention includes:
[1927] Server: High-performance server (e.g., with Ubuntu OS)
[1928] Device: PC or smartphone used by the user
[1929] Camera and microphone: Devices for analyzing the user's facial expressions and voice
[1930] Key software includes:
[1931] Generative AI Models: Deep Learning Models Using TensorFlow
[1932] Emotion engine: Facial expression analysis using OpenCV and voice analysis using Amazon Polly
[1933] Database: MySQL or other RDBMS
[1934] System operation procedures and examples
[1935] 1. User Registration and Authentication:
[1936] Users enter and submit information such as their name, email address, and password through a web interface. The server receives this information and encrypts it using the AES encryption algorithm. The encrypted information is then securely stored in a MySQL database.
[1937] 2. Creating a security protocol:
[1938] The server collects security-related data provided by companies and inputs it into a generative AI model. The generative AI model analyzes the data using TensorFlow and generates an optimal security protocol. The server provides this protocol to the company and provides implementation support if necessary.
[1939] 3. Real-time threat analysis:
[1940] The device collects user activity and system event logs in real time and sends them to the server. The server receives this information and analyzes threats in real time. For example, if abnormal access is detected, the server will send an alert to the user saying, "Unauthorized access has been detected. Please take immediate action."
[1941] 4. Neutralize the threat:
[1942] The server identifies the type of threat detected and selects the most appropriate defense against malware, unauthorized access, etc. If malware is detected, the server immediately quarantines the file and deletes it from the system. All defense actions are also recorded as logs, which is useful for later incident analysis.
[1943] 5. Customized security solutions:
[1944] We assess the specific needs of your company and, if you have high security requirements, we will propose a dual authentication system or restrict access from specific IP addresses. These customized security solutions are provided flexibly to suit your company's security policy.
[1945] 6. Introducing the Emotion Engine:
[1946] When a user logs into the system, their facial expressions and tone of voice are collected in real time using a camera and microphone, and sent to the emotion engine, which uses OpenCV and Amazon Polly to analyze the data and assess the user's stress level and emotional state.
[1947] 7. Adjust security measures based on emotions:
[1948] If the emotion engine determines that a user is in a state of high stress, the server will limit the number of login attempts or monitor the user especially carefully. Also, if an abnormal emotional change is detected, such as sudden anxiety or anger, the server will immediately send an alert to the administrator.
[1949] Examples of prompt statements
[1950] "Build a system that analyzes users' emotions in real time and adjusts security measures according to their stress levels."
[1951] "Design an AI model that analyzes log data in real time and sends an alert when it detects abnormal access."
[1952] As described above, by combining a generative AI model and an emotion engine, the present invention enables real-time, multi-layered security measures to provide advanced protection for corporate and personal information systems.
[1953] The flow of the identification process in the second embodiment will be described with reference to FIG.
[1954] Program processing flow
[1955] Step 1: Enter your user registration information
[1956] A user enters basic information such as name, email address, and password into a web form and clicks the submit button.
[1957] Input: Basic information such as name, email address, and password.
[1958] Output: The information entered by the user is sent to the server.
[1959] Step 2: Receiving the data on the server
[1960] The server receives the information entered by the user. Specifically, it receives it as an HTTP POST request.
[1961] Input: Basic information submitted by the user.
[1962] Output: Received user information.
[1963] Step 3: Encrypt the data
[1964] The server encrypts the received user information, specifically using the AES encryption algorithm.
[1965] Input: Received user information.
[1966] Output: Encrypted user information.
[1967] Step 4: Saving to the Database
[1968] The server stores the encrypted user information in a database, specifically a MySQL database.
[1969] Input: Encrypted user information.
[1970] Output: User information stored securely in a database.
[1971] Step 5: Gather security data
[1972] The server collects security-related data such as network logs and system events provided by companies.
[1973] Input: Security-related data provided by the company.
[1974] Output: Collected security data.
[1975] Step 6: Sending data to the generative AI model
[1976] The server sends the collected security data to a generative AI model, specifically, TensorFlow, which analyzes the data.
[1977] Input: Collected security data.
[1978] Output: Analysis results from the generative AI model.
[1979] Step 7: Generate the protocol
[1980] The generative AI model generates optimal security protocols based on the analyzed data.
[1981] Input: The input data to a generative AI model.
[1982] Output: The generated security protocol.
[1983] Step 8: Provide the protocol to companies
[1984] The server provides the generated security protocols to the company and also assists with implementation if necessary.
[1985] Input: The generated security protocol.
[1986] Output: Protocols and supporting services provided to the company.
[1987] Step 9: Collect data on the device
[1988] The device collects real-time log data of user activity and system events.
[1989] Input: Log data of user activity and system events.
[1990] Output: The log data sent to the server.
[1991] Step 10: Sending data to the server
[1992] The terminal transmits the collected data to the server.
[1993] Input: Collected log data.
[1994] Output: The data sent to the server.
[1995] Step 11: Threat analysis on the server
[1996] The server analyzes the received log data and identifies threats in real time, for example, when abnormal access or unauthorized file operations are detected.
[1997] Input: The log data sent to the server.
[1998] Output: Identified threats and alert messages.
[1999] Step 12: Alert the user
[2000] The server immediately sends an alert message to the user in response to the identified threat.
[2001] Input: Identified threats.
[2002] Output: The alert message sent to the user.
[2003] Step 13: Identifying threats
[2004] The server identifies the type of threat detected, categorizing it as malware, unauthorized access, phishing attack, etc.
[2005] Input: Identified threats.
[2006] Output: Classified threat type.
[2007] Step 14: Select a defense
[2008] The server selects appropriate defenses against identified threats.
[2009] Input: Classified threat type.
[2010] Output: The selected defense.
[2011] Step 15: Implementing defenses
[2012] The server then executes the selected defense, for example, quarantining the file in case of malware and deleting it from the system.
[2013] Input: Selected defense.
[2014] Output: The defense measures taken and their logs.
[2015] Step 16: Assess your business needs
[2016] The server assesses the specific security needs of the enterprise.
[2017] Input: Corporate security needs.
[2018] Output: Evaluation results.
[2019] Step 17: Customized Solution Generation
[2020] The server generates customized security solutions based on the evaluation results, including, for example, dual authentication and restricting access from specific IP addresses.
[2021] Input: Evaluation result.
[2022] Output: Customized security solutions.
[2023] Step 18: Start Emotion Recognition
[2024] When a user logs into the system, the camera and microphone are activated.
[2025] Input: The user's state when logging into the system.
[2026] Output: Collected facial and speech data.
[2027] Step 19: Analyze Emotional Data
[2028] The emotion engine analyzes camera footage and audio data, specifically using OpenCV and Amazon Polly.
[2029] Input: Collected facial and speech data.
[2030] Output: Parsed emotion data.
[2031] Step 20: Stress Assessment
[2032] The emotion engine assesses the user's stress level based on the analyzed data.
[2033] Input: Parsed emotion data.
[2034] Output: Stress assessment results.
[2035] Step 21: Adjust security measures based on emotions
[2036] An emotion engine adjusts security measures based on the user's stress level, such as limiting the number of login attempts.
[2037] Input: Stress assessment results.
[2038] Output: Adjusted security measures.
[2039] Step 22: Monitor for unusual emotional changes
[2040] The emotion engine monitors the user's emotional changes in real time.
[2041] Input: Collected and analyzed emotion data.
[2042] Output: Continuous emotion change data.
[2043] Step 23: Alert when abnormal emotions are detected
[2044] If an abnormal emotion change is detected, the emotion engine immediately sends an alert to the server, which then notifies the administrator.
[2045] Input: Emotion data in which anomalies are detected.
[2046] Output: Server and administrator alert notification.
[2047] (Application example 2)
[2048] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."
[2049] Cyberattacks have become increasingly sophisticated and ingenious in recent years, causing many companies to suffer serious damage such as information leaks and system outages. Furthermore, because security measures do not take into account the psychological state of users, there is a high risk of exposure to threats caused by emotionally volatile behavior. Furthermore, real-time threat detection and response is technically difficult, and countermeasures based on user emotions are particularly lacking. To solve these problems, a comprehensive security system that takes user emotions into account using generative AI models is needed.
[2050] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 2 is realized by the following means.
[2051] In this invention, the server includes means for automating security measures based on the generated protocol, means for encrypting and storing information from a user, means for detecting threats in real time and generating alerts, means for identifying the type of threat and selecting and executing appropriate defensive measures, means for generating customized security solutions based on corporate needs, means for recognizing a user's emotions in real time using an emotion engine and assessing their stress level, means for adjusting security measures based on the emotions, means for monitoring abnormal emotional changes and issuing alerts to prompt a response, and means for providing security measures related to smartphones and head-mounted displays using the user's emotional state. This makes it possible to realize multi-layered security measures that take the user's psychological state into account in real time.
[2052] A "generated protocol" is a security procedure created based on data analyzed using a generative AI model.
[2053] "Means for automating security measures" refers to a system that automatically executes the generated protocols and satisfies security requirements.
[2054] "Means for encrypting and storing information from users" refers to technology for safely encrypting personal information and access data provided by users and storing them in a database.
[2055] "Means for detecting threats in real time and generating alerts" refers to a system that monitors activity within the system, immediately detects unauthorized access or abnormal behavior, and issues an alert.
[2056] "Means to identify the type of threat and select and implement appropriate defensive measures" refers to a system that classifies detected threats and automatically selects and implements the most appropriate security measures accordingly.
[2057] "Customized security solutions based on the needs of the enterprise" are defenses that are individually designed to take into account the unique security requirements of each enterprise.
[2058] "Means for recognizing a user's emotions in real time using an emotion engine and assessing stress levels" is a technology that analyzes a user's facial expressions and tone of voice to assess their psychological state and stress in real time.
[2059] The "means for adjusting security measures based on emotions" is a system that dynamically changes security settings and access restrictions according to the user's emotional state as assessed by an emotion engine.
[2060] The "means of monitoring abnormal emotional changes and issuing alerts to prompt a response" is a system that detects any sudden changes in a user's emotions and issues a warning to relevant parties.
[2061] "Means for providing security measures related to smartphones and head-mounted displays by utilizing the user's emotional state" is a technology that adjusts the security settings of smart devices based on the user's psychological state, supporting safe use.
[2062] System Program
[2063] The system program for realizing this application example mainly consists of the following elements:
[2064] 1. User authentication system:
[2065] - Hardware: Smartphone, Head-Mounted Display (HMD)
[2066] - Software: REST API, encryption library
[2067] 2. Emotion Recognition System:
[2068] - Hardware: Camera, microphone
[2069] - Software: OpenCV, TensorFlow / Keras (machine learning library)
[2070] 3. Real-time threat detection system:
[2071] - Hardware: User terminal
[2072] - Software: PyTorch (generative AI model), log analysis software
[2073] 4. Customized security solution system:
[2074] - Hardware: Server
[2075] - Software: Security protocol generation engine, database
[2076] System processing overview and specific examples
[2077] Handling user authentication
[2078] When a user accesses an application using a smartphone or HMD, the server first collects user information, encrypts it, and stores it in a database, thereby preventing information leakage.
[2079] Emotion recognition processing
[2080] When a user logs in, their facial expressions and tone of voice are captured in real time via a camera and microphone, and analyzed using OpenCV and TensorFlow / Keras. The resulting emotion engine evaluates the user's stress level.
[2081] Real-time threat detection and alerting
[2082] The user's device collects system activity and log data in real time and sends it to the server, which then analyzes it with a generative AI model (using PyTorch) to identify anomalies and threats, issuing alerts in real time and implementing necessary defensive measures.
[2083] Customized Security Solutions
[2084] The server generates optimal security protocols based on the company's security requirements, including restricting access from specific IP addresses and dual authentication.
[2085] Adjusting security measures based on emotions
[2086] The emotion engine monitors the user's emotional state in real time, and if a high level of stress is detected, the server automatically adjusts security measures, such as temporarily restricting system access if stress levels are high.
[2087] For example, if the emotion engine detects that a financial institution employee is experiencing stress while working, the server can temporarily restrict the employee's system access and send an alert to administrators. Additionally, if an employee is in an environment that is vulnerable to malicious attacks, the server can automatically adjust protocols to provide a safe working environment.
[2088] Example prompts for generative AI models
[2089] Here are some example prompts for a generative AI model to adjust security measures using an emotion engine:
[2090] "If users are stressed, suggest ways to limit login attempts and restrict system access."
[2091] "Please estimate what security measures would be effective based on the user's facial expression analysis data."
[2092] "Explain how you can analyze a user's emotional state in real time to predict cyber threats."
[2093] By using such prompts, the generative AI model can suggest appropriate countermeasures and prediction methods.
[2094] The flow of the specific processing in the application example 2 will be described with reference to FIG.
[2095] Step 1:
[2096] User Authentication
[2097] A user enters their credentials to log into the application, which are sent to the server where they are encrypted and stored in a database.
[2098] Input: User authentication information (user ID, password, etc.).
[2099] Data processing: Encryption of authentication information.
[2100] Output: Encrypted credentials stored in the database.
[2101] What it does: Receives authentication information via a REST API, encrypts the data using an encryption library, and then stores it in the database.
[2102] Step 2:
[2103] emotion recognition
[2104] The moment a user logs in, the device's camera and microphone are used to capture facial expressions and tone of voice, which are then analyzed by the emotion engine. OpenCV and TensorFlow / Keras are used to evaluate the user's emotional state (e.g., stress level).
[2105] Input: Real-time data from camera and microphone (facial expressions, tone of voice).
[2106] Data processing: Analysis of image and audio data.
[2107] Output: The user's emotional state (stress level) is assessed.
[2108] Specific operation: Data obtained from the camera and microphone is processed using OpenCV to recognize faces and analyze facial expressions. Analysis is performed using an emotion model using TensorFlow / Keras.
[2109] Step 3:
[2110] Real-time Threat Detection
[2111] The user device collects future system activity and log data in real time and sends it to the server, which then uses a generative AI model (powered by PyTorch) to detect threats from this data in real time.
[2112] Input: System logs and activity data from the device.
[2113] Data processing: Analyze collected data using generative AI models.
[2114] Output: Information and alerts about detected threats.
[2115] How it works: Log analysis software is used to collect data from user devices, which is then analyzed using a generative AI model built with PyTorch. If an anomaly is detected, an alert is issued immediately.
[2116] Step 4:
[2117] Threat response
[2118] The server automatically selects and implements appropriate defensive measures based on the type of threat detected.
[2119] Input: Information about the detected threat.
[2120] Data manipulation: Select appropriate defenses.
[2121] Output: The defensive measures taken and their results.
[2122] Specific operation: Identifies the type of threat and selects and executes corresponding defense measures (e.g., malware isolation, access restriction) on the server side.
[2123] Step 5:
[2124] Providing customized security solutions
[2125] The server generates a customized security solution tailored to each company's needs.
[2126] Input: Data about your company's security needs.
[2127] Data processing: security protocol generation.
[2128] Output: A customized security solution.
[2129] Specific behavior: Uses a security protocol generation engine to execute countermeasures based on the generated protocol.
[2130] Step 6:
[2131] Adjusting security measures based on emotions
[2132] The emotion engine monitors the user's emotional state, and if a high stress state is detected, the server dynamically adjusts security measures.
[2133] Input: User emotional state data.
[2134] Data manipulation: Adjusting security measures based on emotional state.
[2135] Output: Adjusted security settings.
[2136] Specific actions: The server receives data from the emotion engine and takes actions such as temporarily restricting system access for users with high stress levels.
[2137] Step 7:
[2138] Abnormal Emotion Change Alerts
[2139] The emotion engine monitors the user's emotional state in real time, and the server issues an alert if an abnormality occurs.
[2140] Input: User's emotional change data.
[2141] Data processing: Detection and evaluation of abnormal emotional changes.
[2142] Output: Issue an alert.
[2143] Specific operation: When the emotion engine detects an abnormal change in emotion, it sends the information to the server, which then issues an alert to the administrator and prompts them to take action.
[2144] The specific processing unit 290 transmits the result of the specific processing to the robot 414. In the robot 414, the control unit 46A causes the speaker 240 and the control target 443 to output the result of the specific processing. The microphone 238 acquires voice indicating a user input regarding the result of the specific processing. The control unit 46A transmits voice data indicating the user input acquired by the microphone 238 to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the voice data.
[2145] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[2146] In the above embodiment, an example was given in which the specific processing is performed by the data processing device 12, but the technology of the present disclosure is not limited to this, and the specific processing may be performed by the robot 414.
[2147] The emotion identification model 59 as an emotion engine may determine the user's emotion according to a specific mapping. Specifically, the emotion identification model 59 may determine the user's emotion according to an emotion map (see FIG. 9), which is a specific mapping. Similarly, the emotion identification model 59 may determine the robot's emotion, and the identification processing unit 290 may perform identification processing using the robot's emotion.
[2148] FIG. 9 is a diagram illustrating an emotion map 400 on which multiple emotions are mapped. In the emotion map 400, emotions are arranged in concentric circles radiating from the center. Emotions closer to the center of the concentric circles are more primitive. Emotions representing states and actions arising from a state of mind are arranged on the outer edges of the concentric circles. The concept of emotion includes both affect and mental states. Emotions generally generated from reactions occurring in the brain are arranged on the left side of the concentric circles. Emotions generally induced by situational judgment are arranged on the right side of the concentric circles. Emotions generally generated from reactions occurring in the brain and induced by situational judgment are arranged on the upper and lower sides of the concentric circles. Furthermore, the emotion of "pleasure" is arranged on the upper side of the concentric circles, and the emotion of "discomfort" is arranged on the lower side. In this way, in the emotion map 400, multiple emotions are mapped based on the structure by which emotions are generated, and emotions that tend to occur simultaneously are mapped close to each other.
[2149] These emotions are distributed in the 3 o'clock direction on emotion map 400, and typically fluctuate between relief and anxiety. In the right half of emotion map 400, situational awareness dominates over internal sensations, resulting in a sense of calm.
[2150] The inside of emotion map 400 represents what is going on in the mind, and the outside of emotion map 400 represents behavior, so the further you go outside emotion map 400, the more visible the emotions become (the more they are expressed in behavior).
[2151] Human emotions are based on various balances, such as posture and blood sugar levels. When these balances deviate from the ideal, a state of discomfort is indicated, and when they approach the ideal, a state of pleasure is indicated. Emotions can also be created for robots, automobiles, and motorcycles, based on various balances, such as posture and remaining battery life. When these balances deviate from the ideal, a state of discomfort is indicated, and when they approach the ideal, a state of pleasure is indicated. An emotion map can be generated, for example, based on Dr. Mitsuyoshi's emotion map (Research on Voice Emotion Recognition and Emotional Brain Physiological Signal Analysis Systems, Tokushima University, Doctoral Dissertation: https: / / ci.nii.ac.jp / naid / 500000375379). The left half of the emotion map lists emotions belonging to the "reaction" domain, where sensation is dominant. The right half of the emotion map lists emotions belonging to the "situation" domain, where situational awareness is dominant.
[2152] The emotion map defines two emotions that promote learning. One is a negative emotion on the situation side, around the middle of "repentance" or "reflection." In other words, this occurs when the robot experiences negative emotions such as "I never want to feel this way again" or "I don't want to be scolded again." The other is a positive emotion on the response side, around "desire." In other words, this occurs when the robot experiences positive feelings such as "I want more" or "I want to know more."
[2153] The emotion identification model 59 inputs user input into a pre-trained neural network, obtains emotion values indicating each emotion shown in the emotion map 400, and determines the user's emotion. This neural network is pre-trained based on multiple pieces of training data that are combinations of user input and emotion values indicating each emotion shown in the emotion map 400. Furthermore, this neural network is trained so that emotions that are located close to each other have similar values, as in the emotion map 900 shown in FIG. 10. FIG. 10 shows an example in which multiple emotions, "relieved," "calm," and "reassuring," have similar emotion values.
[2154] The system according to the present disclosure has been described above mainly with respect to the functions of the data processing device 12, but the system according to the present disclosure is not necessarily implemented on a server. The system according to the present disclosure may be implemented as a general information processing system. The present disclosure may be implemented, for example, as a software program running on a personal computer or an application running on a smartphone, etc. The method according to the present disclosure may be provided to users in the form of SaaS (Software as a Service).
[2155] In the above embodiment, an example was given in which the specific processing is performed by one computer 22, but the technology of the present disclosure is not limited to this, and the specific processing may be distributed and performed by a plurality of computers including the computer 22. For example, the data generation model 58 may be provided in an external device of the data processing device 12, and data may be generated in the external device in accordance with input data.
[2156] In the above embodiment, an example in which the specific processing program 56 is stored in the storage 32 has been described, but the technology of the present disclosure is not limited to this. For example, the specific processing program 56 may be stored in a portable, computer-readable, non-transitory storage medium such as a USB (Universal Serial Bus) memory. The specific processing program 56 stored in the non-transitory storage medium is installed in the computer 22 of the data processing device 12. The processor 28 executes the specific processing in accordance with the specific processing program 56.
[2157] Alternatively, the specific processing program 56 may be stored in a storage device such as a server connected to the data processing device 12 via the network 54, and the specific processing program 56 may be downloaded and installed on the computer 22 in response to a request from the data processing device 12.
[2158] It is not necessary to store all of the specific processing program 56 in a storage device such as a server connected to the data processing device 12 via the network 54, or to store all of the specific processing program 56 in the storage 32; only a portion of the specific processing program 56 may be stored.
[2159] The hardware resource for executing a specific process can be any of the following processors: An example of a processor is a CPU, which is a general-purpose processor that functions as a hardware resource for executing a specific process by executing software, i.e., a program. Another example of a processor is a dedicated electrical circuit, such as an FPGA (Field-Programmable Gate Array), a PLD (Programmable Logic Device), or an ASIC (Application Specific Integrated Circuit), which is a processor with a circuit configuration designed specifically for executing a specific process. Each processor has built-in or connected memory, and each processor uses the memory to execute the specific process.
[2160] The hardware resource that executes the specific processing may be configured with one of these various processors, or may be configured with a combination of two or more processors of the same or different types (for example, a combination of multiple FPGAs, or a combination of a CPU and an FPGA). Also, the hardware resource that executes the specific processing may be a single processor.
[2161] As an example of a system configured with a single processor, first, one processor is configured by combining one or more CPUs and software, and this processor functions as a hardware resource that executes a specific process. Second, there is a system that uses a processor that realizes the functions of an entire system including multiple hardware resources that execute a specific process on a single IC chip, as typified by SoC (System-on-a-chip). In this way, a specific process is realized using one or more of the above-mentioned various processors as hardware resources.
[2162] Furthermore, the hardware structure of these various processors can be, more specifically, an electric circuit that combines circuit elements such as semiconductor devices. The specific processing described above is merely an example. Therefore, it goes without saying that unnecessary steps may be deleted, new steps may be added, or the processing order may be rearranged, without departing from the spirit of the invention.
[2163] The above-described description and illustrations are a detailed explanation of the parts related to the technology of the present disclosure and are merely an example of the technology of the present disclosure. For example, the above description of the configuration, functions, actions, and effects is an explanation of an example of the configuration, functions, actions, and effects of the parts related to the technology of the present disclosure. Therefore, it goes without saying that unnecessary parts may be deleted, new elements may be added, or replacements may be made to the above-described description and illustrations within the scope of the gist of the technology of the present disclosure. Furthermore, to avoid confusion and facilitate understanding of the parts related to the technology of the present disclosure, the above-described description and illustrations omit explanations of common technical knowledge that do not require particular explanation to enable the implementation of the technology of the present disclosure.
[2164] All publications, patent applications, and technical standards mentioned in this specification are herein incorporated by reference to the same extent as if each individual publication, patent application, or technical standard was specifically and individually indicated to be incorporated by reference.
[2165] The following is further disclosed regarding the above embodiment.
[2166] (Claim 1)
[2167] a means for automating security measures based on the generated protocol;
[2168] a means for encrypting and storing information from a user;
[2169] A means of detecting and alerting on threats in real time;
[2170] How to identify the type of threat and select and implement appropriate defense measures;
[2171] A means to generate customized security solutions based on the needs of the enterprise;
[2172] A system including:
[2173] (Claim 2)
[2174] 10. The system of claim 1, wherein the system uses a generative model for threat detection.
[2175] (Claim 3)
[2176] 10. The system of claim 1, including means for storing user information using a database and ensuring data security.
[2177] "Example 1"
[2178] (Claim 1)
[2179] a means for encrypting and storing information from a user;
[2180] a means for collecting security data provided by the company and transmitting it to an analytical model;
[2181] A means for generating optimal security protocols for the enterprise based on the analyzed data;
[2182] means for collecting and transmitting real-time user activity and system event log data to a central processing unit;
[2183] A means of detecting and alerting on threats in real time;
[2184] How to identify the type of threat and select and implement appropriate defense measures;
[2185] A means to generate customized security solutions based on the needs of the enterprise;
[2186] A system including:
[2187] (Claim 2)
[2188] 10. The system of claim 1, wherein the system uses a generative AI model for threat detection.
[2189] (Claim 3)
[2190] 10. The system of claim 1, including means for storing user information using a database and ensuring data security.
[2191] "Application Example 1"
[2192] New Claims
[2193] (Claim 1)
[2194] a means for automating security measures based on the generated protocol;
[2195] a means for encrypting and storing information from a user;
[2196] A means of detecting and alerting on threats in real time;
[2197] How to identify the type of threat and select and implement appropriate defense measures;
[2198] A means to generate customized security solutions based on the needs of the enterprise;
[2199] A means for collecting real-time activity logs of mobile devices and detecting fraudulent activity using a generative model; and
[2200] A means to alert you to detected threats and take necessary measures;
[2201] A system including:
[2202] (Claim 2)
[2203] 10. The system of claim 1, wherein the system uses a generative model for threat detection.
[2204] (Claim 3)
[2205] 10. The system of claim 1, including means for storing user information using a database and ensuring data security.
[2206] "Example 2: Combining Emotion Engines"
[2207] (Claim 1)
[2208] means for receiving, encrypting and storin...
Claims
1. a means for automating security measures based on the generated protocol; means for encrypting and storing information from users; A means of detecting and alerting on threats in real time; How to identify the type of threat and select and implement appropriate defense measures; A means of generating customized security solutions based on the needs of the enterprise; A system including:
2. The system of claim 1 , wherein the threat detection uses a generative model.
3. 10. The system of claim 1, further comprising means for storing user information using a database and for ensuring data security.
Citation Information
Patent Citations
Persona chatbot control method and system
JP2022180282A