System
The system uses generative AI to analyze server behavior in real time, detect suspicious activities, and respond effectively to security threats, addressing the challenge of timely threat detection and response.
Patent Information
- Application Number
- JP2024119863
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-07-25
- Publication Date
- 2026-02-05
AI Technical Summary
Conventional technologies face challenges in detecting server security threats in real time and responding quickly.
A system utilizing a real-time analysis unit, suspicious activity detection unit, threat response unit, and automatic learning unit, powered by generative AI, to analyze server behavior, detect suspicious activities, and implement effective countermeasures.
Enables rapid detection and response to security threats, including internal and external attacks, by learning from past patterns and adapting to new threats, providing comprehensive server security.
Smart Images

Figure 2026018541000001_ABST
Abstract
Description
[Technical Field]
[0001] The technology of the present disclosure relates to a system. [Background technology]
[0002] Patent document 1 discloses a persona chatbot control method performed by at least one processor, the method including the steps of receiving a user utterance, adding the user utterance to a prompt including an instruction sentence related to a description of the chatbot character, encoding the prompt, and inputting the encoded prompt into a language model to generate a chatbot utterance in response to the user utterance. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Publication No. 2022-180282 Summary of the Invention [Problem to be solved by the invention]
[0004] Conventional technologies have had the problem of making it difficult to detect server security threats in real time and respond quickly.
[0005] The system according to the embodiment aims to detect security threats to servers in real time and deal with them promptly. [Means for solving the problem]
[0006] The system according to the embodiment includes a real-time analysis unit, a suspicious activity detection unit, a threat response unit, a report generation unit, and an automatic learning unit. The real-time analysis unit analyzes server behavior in real time using a generation AI. The suspicious activity detection unit detects suspicious activity from data analyzed by the real-time analysis unit. The threat response unit identifies and responds to threats based on the suspicious activity detected by the suspicious activity detection unit. The report generation unit generates a security report based on information about the threats responded to by the threat response unit. The automatic learning unit automatically learns based on the reports generated by the report generation unit and improves security measures. [Effects of the Invention]
[0007] The system according to the embodiment can detect security threats to servers in real time and deal with them quickly. [Brief explanation of the drawings]
[0008] [Figure 1] 1 is a conceptual diagram showing an example of the configuration of a data processing system according to a first embodiment. [Figure 2] 1 is a conceptual diagram showing an example of main functions of a data processing device and a smart device according to a first embodiment. [Figure 3] FIG. 10 is a conceptual diagram showing an example of the configuration of a data processing system according to a second embodiment. [Figure 4] FIG. 10 is a conceptual diagram showing an example of main functions of a data processing device and smart glasses according to a second embodiment. [Figure 5] FIG. 10 is a conceptual diagram showing an example of the configuration of a data processing system according to a third embodiment. [Figure 6] FIG. 11 is a conceptual diagram showing an example of main functions of a data processing device and a headset-type terminal according to a third embodiment. [Figure 7] FIG. 10 is a conceptual diagram showing an example of the configuration of a data processing system according to a fourth embodiment. [Figure 8]FIG. 10 is a conceptual diagram showing an example of main functions of a data processing device and a robot according to a fourth embodiment. [Figure 9] 1 shows an emotion map onto which multiple emotions are mapped. [Figure 10] 1 shows an emotion map onto which multiple emotions are mapped. DETAILED DESCRIPTION OF THE INVENTION
[0009] An example of an embodiment of a system according to the technology of the present disclosure will be described below with reference to the accompanying drawings.
[0010] First, the terms used in the following description will be explained.
[0011] In the following embodiments, a coded processor (hereinafter simply referred to as a "processor") may be a single arithmetic device or a combination of multiple arithmetic devices. Furthermore, the processor may be a single type of arithmetic device or a combination of multiple types of arithmetic devices. Examples of arithmetic devices include a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), a GPGPU (General-Purpose computing on Graphics Processing Units), an APU (Accelerated Processing Unit), or a TPU (Tensor Processing Unit).
[0012] In the following embodiments, a coded RAM (Random Access Memory) is a memory in which information is temporarily stored and is used as a working memory by a processor.
[0013] In the following embodiments, the coded storage is one or more nonvolatile storage devices that store various programs, various parameters, etc. Examples of nonvolatile storage devices include flash memory (SSD (Solid State Drive)), magnetic disks (e.g., hard disks), and magnetic tapes.
[0014] In the following embodiments, a communication I / F (Interface) with a symbol is an interface including a communication processor, an antenna, etc. The communication I / F controls communication between multiple computers. Examples of communication standards applied to the communication I / F include wireless communication standards including 5G (5th Generation Mobile Communication System), Wi-Fi (registered trademark), and Bluetooth (registered trademark).
[0015] In the following embodiments, "A and / or B" is synonymous with "at least one of A and B." In other words, "A and / or B" means that it may be only A, only B, or a combination of A and B. Furthermore, in this specification, the same concept as "A and / or B" is also applied when three or more things are expressed connected by "and / or."
[0016] [First embodiment] FIG. 1 shows an example of the configuration of a data processing system 10 according to the first embodiment.
[0017] 1, a data processing system 10 includes a data processing device 12 and a smart device 14. An example of the data processing device 12 is a server.
[0018] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0019] The smart device 14 includes a computer 36, a reception device 38, an output device 40, a camera 42, and a communication I / F 44. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The reception device 38, the output device 40, and the camera 42 are also connected to the bus 52.
[0020] The reception device 38 includes a touch panel 38A and a microphone 38B, and receives user input. The touch panel 38A detects contact with a pointer (for example, a pen or a finger) to receive user input by the touch of the pointer. The microphone 38B detects the user's voice to receive user input by voice. The control unit 46A transmits data indicating the user input received by the touch panel 38A and the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 (see FIG. 2) acquires the data indicating the user input.
[0021] Output device 40 includes a display 40A and a speaker 40B, and presents data to a user by outputting the data in a form of expression that the user can perceive (e.g., audio and / or text). Display 40A displays visible information such as text and images in accordance with instructions from processor 46. Speaker 40B outputs audio in accordance with instructions from processor 46. Camera 42 is a compact digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor.
[0022] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 control the exchange of various information between the processor 46 and the processor 28 via the network 54.
[0023] FIG. 2 shows an example of the main functions of the data processing device 12 and the smart device 14.
[0024] 2, in the data processing device 12, a specific process is performed by the processor 28. A specific processing program 56 is stored in the storage 32. The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific process is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[0025] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290. The identification processing unit 290 can estimate the user's emotion using the emotion identification model 59 and perform identification processing using the user's emotion.
[0026] In the smart device 14, the specific processing is performed by the processor 46. The storage 50 stores a specific processing program 60. The specific processing program 60 is used together with the specific processing program 56 by the data processing system 10. The processor 46 reads the specific processing program 60 from the storage 50 and executes the read specific processing program 60 on the RAM 48. The specific processing is realized by the processor 46 operating as the control unit 46A in accordance with the specific processing program 60 executed on the RAM 48. Note that the smart device 14 may have a data generation model and an emotion identification model similar to the data generation model 58 and the emotion identification model 59.
[0027] Note that a device other than the data processing device 12 may have the data generation model 58. For example, a server device (e.g., a generation server) may have the data generation model 58. In this case, the data processing device 12 obtains a processing result (prediction result, etc.) using the data generation model 58 by communicating with the server device having the data generation model 58. Furthermore, the data processing device 12 may be a server device, or may be a terminal device owned by a user (e.g., a mobile phone, a robot, a home appliance, etc.). Next, an example of processing by the data processing system 10 according to the first embodiment will be described.
[0028] (Example 1) A server security system according to an embodiment of the present invention uses generative AI to analyze server behavior in real time, detect suspicious activity, and quickly and effectively identify and address threats. This enables the server security system to provide advanced defense against various security threats targeting corporate servers.
[0029] A server security countermeasure system according to an embodiment includes a real-time analysis unit, a suspicious activity detection unit, a threat response unit, a report generation unit, and an automatic learning unit. The real-time analysis unit analyzes server behavior in real time using a generation AI. For example, the real-time analysis unit analyzes server access logs, communication data, file change histories, and the like to detect suspicious activity that differs from normal behavior. The suspicious activity detection unit detects suspicious activity from the data analyzed by the real-time analysis unit. For example, the suspicious activity detection unit detects large amounts of access that differ from normal access patterns or unauthorized access to specific files. The threat response unit identifies and responds to threats based on the suspicious activity detected by the suspicious activity detection unit. For example, if the threat response unit detects an attack from a specific IP address, it blocks the IP address. Furthermore, if a specific file is unauthorizedly modified, it restores the file to its original state. The report generation unit generates a security report based on information about threats addressed by the threat response unit. For example, the report generation unit generates a report to be provided to a company's security officer based on information about the detected suspicious activity and the addressed threats. The automatic learning unit automatically learns and improves security measures based on the reports generated by the report generation unit. For example, the automatic learning unit automatically learns measures to deal with new attack methods based on data on detected suspicious activity and countermeasures against threats. This allows the server security system according to the embodiment to monitor server security in real time and quickly and effectively counter threats.
[0030] When analyzing server behavior, the real-time analysis unit simultaneously analyzes user operation history or application usage patterns, enabling more detailed anomaly detection. For example, when the generation AI analyzes server behavior, the real-time analysis unit collects user operation history and detects abnormal operations that differ from normal operation patterns. For example, it identifies operations that are frequently performed during specific time periods or operations that are not normally performed. The real-time analysis unit also analyzes application usage patterns and detects abnormal usage patterns. For example, it identifies cases where a specific application is being used more frequently than normal. This enables more detailed anomaly detection by analyzing user operation history and application usage patterns.
[0031] The real-time analysis unit includes the server's hardware status in the data it collects in real time, and can also detect abnormal hardware behavior. For example, the real-time analysis unit uses a generative AI to monitor the server's CPU temperature in real time and detect abnormal temperature increases that exceed the normal temperature range. For example, it identifies cases where the CPU temperature rises sharply during a specific time period. The real-time analysis unit also monitors memory usage and detects abnormal memory use. For example, it identifies cases where a specific process is consuming an abnormally large amount of memory. Furthermore, the real-time analysis unit monitors disk I / O and detects abnormal disk access. For example, it identifies cases where disk access increases suddenly during a specific time period. In this way, abnormal hardware behavior can be detected by monitoring the server's hardware status.
[0032] The real-time analysis unit applies real-time analysis by generative AI to not only cloud environments but also on-premises environments, making it possible to support different infrastructures. For example, the real-time analysis unit can operate generative AI in both cloud and on-premises environments to support different infrastructures. For example, it can simultaneously monitor both cloud and on-premises servers. The real-time analysis unit also synchronizes data between cloud and on-premises environments to provide unified security measures. For example, it can apply security policies on the cloud to the on-premises environment. Furthermore, the real-time analysis unit distributes load between cloud and on-premises environments to achieve efficient resource utilization. For example, it can use resources in the on-premises environment when resources on the cloud are insufficient. This enables real-time analysis by generative AI in both cloud and on-premises environments.
[0033] The real-time analysis unit includes data from IoT devices in the data it analyzes, enabling it to detect abnormalities in devices that connect to the server. For example, the real-time analysis unit uses a generative AI to collect data from IoT devices in real time and detect abnormalities in devices that connect to the server. For example, it analyzes communication data and sensor data from IoT devices to detect abnormal behavior. The real-time analysis unit also monitors the firmware status of IoT devices and detects abnormal firmware changes. For example, it identifies cases where firmware has been illegally changed during a specific time period. Furthermore, the real-time analysis unit monitors the network traffic of IoT devices and detects abnormal traffic patterns. For example, it identifies large amounts of data being sent from a specific device. In this way, by including data from IoT devices, it is possible to detect abnormalities in devices that connect to the server.
[0034] When detecting suspicious activity, the suspicious activity detection unit learns past attack patterns and can also respond to unknown attack methods. For example, the suspicious activity detection unit uses a generation AI to learn past attack patterns and can also respond to unknown attack methods. For example, it predicts new attack patterns based on past attack data. The suspicious activity detection unit also monitors changes in attack patterns in real time and detects unknown attack methods. For example, if a new attack method appears, it quickly identifies that method. Furthermore, the suspicious activity detection unit analyzes the similarity of attack patterns and identifies unknown attack methods. For example, it identifies new attack methods that are similar to existing attack patterns. In this way, by learning past attack patterns, it can also respond to unknown attack methods.
[0035] The suspicious activity detection unit can include internal threats in the suspicious activity it detects. For example, the suspicious activity detection unit analyzes the operation history of insiders so that the generation AI can detect internal threats. For example, it identifies cases where a specific insider is performing operations that they normally do not perform. The suspicious activity detection unit also analyzes the access patterns of insiders to detect abnormal access. For example, it identifies cases where a specific insider is accessing files that they normally do not access. Furthermore, the suspicious activity detection unit analyzes the communication data of insiders to detect abnormal communications. For example, it identifies cases where a specific insider is sending large amounts of data to the outside. This allows the detection of internal threats as well, making it possible to respond to fraudulent activities by insiders.
[0036] When detecting suspicious activity, the suspicious activity detection unit can reference security data from different industries and respond to industry-specific threats. For example, the suspicious activity detection unit uses a generation AI to reference security data from different industries to detect industry-specific threats. For example, it identifies abnormal patterns based on security data from the financial and medical industries. The suspicious activity detection unit also learns industry-specific attack methods and can respond to unknown attack methods. For example, it detects phishing attacks in the financial industry and data leaks in the medical industry. Furthermore, the suspicious activity detection unit utilizes industry-specific threat intelligence to detect threats in real time. For example, it identifies new attack methods based on industry-specific threat information. This allows it to respond to industry-specific threats by referring to security data from different industries.
[0037] The suspicious activity detection unit can include physical security in the suspicious activity it detects. For example, the suspicious activity detection unit analyzes physical security data so that the generation AI can detect unauthorized intrusions into a server room. For example, it analyzes the server room's access logs and surveillance camera footage to detect unauthorized intrusions. The suspicious activity detection unit also monitors the status of physical security devices and detects abnormal conditions. For example, it analyzes data from door opening / closing sensors and motion sensors to identify unauthorized intrusions. Furthermore, the suspicious activity detection unit monitors physical security events in real time and detects abnormal events. For example, it identifies abnormal access that occurs during specific time periods. By including physical security, this makes it possible to respond to physical threats such as unauthorized intrusions into server rooms.
[0038] When identifying a threat, the threat response unit predicts the attacker's behavioral patterns and can prevent the next attack. For example, the threat response unit uses a generation AI to predict the attacker's behavioral patterns based on past attack data and prevent the next attack. For example, it predicts attacks during specific time periods or from specific IP addresses. The threat response unit also monitors the attacker's behavioral patterns in real time and predicts the next attack. For example, it identifies when an attacker is attempting to access a specific server. Furthermore, the threat response unit analyzes changes in the attacker's behavioral patterns and predicts new attack methods. For example, it identifies when an attacker is attempting a new attack method. This makes it possible to predict the attacker's behavioral patterns and prevent the next attack.
[0039] When taking action, the threat response unit can simulate multiple response methods and select the most appropriate one. In the threat response unit, for example, a generation AI simulates multiple response methods and selects the most appropriate one. For example, multiple defense methods are tried against a specific attack and the most effective method is selected. The threat response unit also selects a response method based on the simulation results. For example, the most effective response method is selected based on the simulation results. Furthermore, the threat response unit monitors the simulation results in real time and adjusts the response method. For example, the response method is adjusted based on the simulation results. In this way, the optimal response method can be selected by simulating multiple response methods.
[0040] When identifying threats, the threat response department can share information with other companies and organizations and jointly address threats. For example, the generative AI in the threat response department can share information with other companies and organizations and jointly address threats. For example, security incident information can be shared and countermeasures can be jointly implemented. The threat response department also exchanges data using information sharing protocols. For example, security data can be shared using APIs. Furthermore, the threat response department adjusts response methods based on the results of information sharing. For example, it adjusts response methods based on information obtained from other companies and organizations. In this way, by sharing information with other companies and organizations, threats can be jointly addressed.
[0041] The threat response unit can include physical security measures when taking countermeasures. For example, the generation AI of the threat response unit takes countermeasures that include physical security measures. For example, if it detects an unauthorized intrusion into a server room, it will lock down the server room. The threat response unit also strengthens physical access control. For example, it strengthens access control in the server room to prevent unauthorized access. Furthermore, the threat response unit monitors physical security devices and detects abnormal conditions. For example, it analyzes data from door opening / closing sensors and motion sensors to identify unauthorized intrusions. By including physical security measures, physical countermeasures such as locking down the server room become possible.
[0042] When generating a security report, the report generation unit performs a comparative analysis with past reports and can clearly indicate changes in the security situation. For example, the report generation unit uses a generation AI to perform a comparative analysis with the current report based on past security reports. For example, it compares past attack patterns and countermeasures to identify changes in the security situation. The report generation unit also clearly indicates changes in the security situation based on the results of the comparative analysis. For example, it clearly indicates differences between past reports and the current report. Furthermore, the report generation unit monitors the results of the comparative analysis in real time and tracks changes in the security situation. For example, it tracks changes between past reports and the current report in real time. This makes it possible to clearly indicate changes in the security situation by performing a comparative analysis with past reports.
[0043] The report generation unit can include a detailed timeline of the attack and the attacker's behavioral patterns in the report it generates. For example, the generation AI in the report generation unit includes a detailed timeline of the attack in the report. For example, it clearly indicates the start time, progress, and end time of the attack. The report generation unit also includes the attacker's behavioral patterns in the report. For example, it clearly indicates what method the attacker used to carry out the attack and the route they took. Furthermore, the report generation unit includes the scope of the attack's impact in the report. For example, it clearly indicates which systems and data were affected by the attack. In this way, by including a detailed timeline of the attack and the attacker's behavioral patterns, it is possible to provide a more detailed security report.
[0044] The report generation unit automatically translates the generated reports into different languages, allowing for feedback from an international perspective. For example, the report generation unit uses a generation AI to automatically translate security reports into different languages. For example, it translates into multiple languages such as English, French, and Chinese, allowing for feedback from an international perspective. The report generation unit also monitors the accuracy of the translation in real time and corrects the translation as necessary. For example, it automatically corrects translations that are inaccurate. Furthermore, the report generation unit provides the translated reports to the international security community and collects feedback. For example, it shares the reports at international security forums and conferences. This allows for feedback from an international perspective to be obtained by automatically translating into different languages.
[0045] The report generation unit can convert the generated report into a visual note or mind map to make it easier to understand visually. In the report generation unit, for example, the generation AI converts a security report into a visual note. For example, it indicates important points with diagrams and icons to make it easier to understand visually. The report generation unit also converts the security report into a mind map. For example, it visually arranges central themes and related subthemes to make it easier to understand. Furthermore, the report generation unit updates the visual note or mind map in real time to reflect the latest information. For example, it automatically updates when new threat information is added. In this way, by converting the report into a visual note or mind map, it is possible to provide a report that is easier to understand visually.
[0046] When performing automatic learning, the automatic learning unit can cooperate with other AI systems and share learning data with each other. For example, the generation AI of the automatic learning unit cooperates with other AI systems and shares learning data with each other. For example, it collects data from different AI systems and uses it for learning. The automatic learning unit also exchanges data using an API. For example, it exchanges data with other AI systems in real time. Furthermore, the automatic learning unit adjusts the learning algorithm based on the shared data. For example, it optimizes the learning algorithm based on data obtained from other AI systems. In this way, by cooperating with other AI systems, learning data can be shared with each other, enabling more effective automatic learning.
[0047] The automatic learning unit can include the latest threat information from external security research institutions in the learning data. For example, the generation AI in the automatic learning unit includes the latest threat information from external security research institutions in the learning data. For example, it collects the latest attack methods and vulnerability information and uses it for learning. The automatic learning unit also collects the latest threat information in real time and reflects it in the learning data. For example, it collects real-time threat intelligence from security research institutions. Furthermore, the automatic learning unit adjusts the learning algorithm based on the latest threat information. For example, it optimizes the algorithm to respond to new attack methods. In this way, by including the latest threat information from external security research institutions in the learning data, it is possible to respond to the latest threats.
[0048] When performing automatic learning, the automatic learning unit can refer to security data from different industries to respond to industry-specific threats. For example, the generation AI of the automatic learning unit refers to security data from different industries to learn about industry-specific threats. For example, it identifies abnormal patterns based on security data from the financial and medical industries. The automatic learning unit also utilizes industry-specific threat intelligence to learn about threats in real time. For example, it learns about phishing attacks in the financial industry and data leaks in the medical industry. Furthermore, the automatic learning unit adjusts the learning algorithm based on industry-specific threat information. For example, it optimizes the algorithm to respond to industry-specific attack methods. This allows it to respond to industry-specific threats by referring to security data from different industries.
[0049] The automatic learning unit can include physical security data in the data it learns. For example, the generation AI includes physical security data in the learning data. For example, it collects access logs from server rooms and footage from surveillance cameras and uses this for learning. The automatic learning unit also collects data from physical security devices and uses this for learning. For example, it collects data from door opening / closing sensors and motion sensors. Furthermore, the automatic learning unit collects data on physical security events and uses this for learning. For example, it collects data on abnormal access that occurs during specific time periods. In this way, by including physical security data in the learning data, it is possible to respond to physical threats.
[0050] The system according to the embodiment is not limited to the above-described example, and various modifications are possible, for example, as follows.
[0051] When analyzing server behavior, the real-time analysis unit simultaneously analyzes the server's power consumption data and can detect abnormal power consumption. For example, it can identify cases where power consumption increases suddenly during a specific time period. The real-time analysis unit also analyzes the server's power consumption patterns and detects abnormal consumption that differs from normal consumption patterns. For example, it can identify cases where a specific process is consuming an abnormally large amount of power. Furthermore, the real-time analysis unit can suggest efficient server operation based on the power consumption data. For example, it can suggest load balancing during times of high power consumption. In this way, by analyzing the server's power consumption data, abnormal power consumption can be detected and efficient operation can be achieved.
[0052] When analyzing server behavior, the real-time analysis unit can also detect anomalies in network traffic. For example, it can identify sudden increases in network traffic during specific time periods. The real-time analysis unit also analyzes network traffic patterns and detects abnormal traffic that differs from normal traffic patterns. For example, it can identify large amounts of data being sent from specific IP addresses. Furthermore, the real-time analysis unit can propose more efficient server operation based on network traffic data. For example, it can propose load balancing during times of heavy traffic. This allows for the detection of network traffic anomalies and the realization of more efficient operation.
[0053] When analyzing server behavior, the real-time analysis unit simultaneously analyzes the server's software status, enabling it to detect abnormal software behavior. For example, it can identify cases where specific software is consuming an abnormally large number of resources. The real-time analysis unit also analyzes software version information to identify cases where an old version of software is being used. Furthermore, the real-time analysis unit analyzes software error logs to detect abnormal error occurrences. For example, it can identify cases where errors occur frequently during specific time periods. This makes it possible to detect abnormal software behavior by analyzing the server's software status and take prompt action.
[0054] When detecting suspicious activity, the suspicious activity detection unit analyzes the server's physical location information and can detect access from an abnormal location. For example, it can identify access from a location away from the normal location during a specific time period. The suspicious activity detection unit can also analyze location history and detect access from an abnormal location that differs from normal access patterns. For example, it can identify cases where a specific IP address is accessing from an abnormal location. Furthermore, the suspicious activity detection unit can make suggestions to strengthen the server's security measures based on the location information. For example, it can suggest blocking access from an abnormal location. In this way, by analyzing the server's physical location information, it is possible to detect access from an abnormal location and strengthen security measures.
[0055] When detecting suspicious activity, the suspicious activity detection unit can also detect anomalies in the server's communication protocols. For example, it can identify cases where an unusual protocol is being used during a specific time period. The suspicious activity detection unit also analyzes communication protocol patterns and detects anomalous protocol usage that differs from the normal pattern. For example, it can identify cases where a specific IP address is using an abnormal protocol. Furthermore, the suspicious activity detection unit can make suggestions to strengthen server security measures based on communication protocol anomalies. For example, it can suggest blocking the use of an abnormal protocol. This makes it possible to detect anomalies in the server's communication protocols and strengthen security measures.
[0056] The processing flow of the first embodiment will be briefly explained below.
[0057] Step 1: The real-time analysis unit uses generative AI to analyze server behavior in real time, for example, analyzing server access logs, communication data, file change history, etc., to detect suspicious activity that deviates from normal behavior. Step 2: The suspicious activity detection unit detects suspicious activity from the data analyzed by the real-time analysis unit, such as a large number of accesses that differ from normal access patterns or unauthorized access to specific files. Step 3: The threat response unit identifies and responds to threats based on the suspicious activity detected by the suspicious activity detection unit. For example, if an attack from a specific IP address is detected, that IP address will be blocked. Also, if a specific file has been illegally modified, the file will be restored to its original state. Step 4: The report generation unit generates a security report based on information about the threats dealt with by the threat response unit. For example, based on information about detected suspicious activity and dealt with threats, the unit generates a report to be provided to the company's security personnel. Step 5: The automatic learning unit automatically learns and improves security measures based on the reports generated by the report generation unit. For example, it automatically learns countermeasures to deal with new attack methods based on data on detected suspicious activity and countermeasures against threats.
[0058] (Example 2) A server security system according to an embodiment of the present invention uses generative AI to analyze server behavior in real time, detect suspicious activity, and quickly and effectively identify and address threats. This enables the server security system to provide advanced defense against various security threats targeting corporate servers.
[0059] A server security countermeasure system according to an embodiment includes a real-time analysis unit, a suspicious activity detection unit, a threat response unit, a report generation unit, and an automatic learning unit. The real-time analysis unit analyzes server behavior in real time using a generation AI. For example, the real-time analysis unit analyzes server access logs, communication data, file change histories, and the like to detect suspicious activity that differs from normal behavior. The suspicious activity detection unit detects suspicious activity from the data analyzed by the real-time analysis unit. For example, the suspicious activity detection unit detects large amounts of access that differ from normal access patterns or unauthorized access to specific files. The threat response unit identifies and responds to threats based on the suspicious activity detected by the suspicious activity detection unit. For example, if the threat response unit detects an attack from a specific IP address, it blocks the IP address. Furthermore, if a specific file is unauthorizedly modified, it restores the file to its original state. The report generation unit generates a security report based on information about threats addressed by the threat response unit. For example, the report generation unit generates a report to be provided to a company's security officer based on information about the detected suspicious activity and the addressed threats. The automatic learning unit automatically learns and improves security measures based on the reports generated by the report generation unit. For example, the automatic learning unit automatically learns measures to deal with new attack methods based on data on detected suspicious activity and countermeasures against threats. This allows the server security system according to the embodiment to monitor server security in real time and quickly and effectively counter threats.
[0060] When analyzing server behavior, the real-time analysis unit simultaneously analyzes user operation history or application usage patterns, enabling more detailed anomaly detection. For example, when the generation AI analyzes server behavior, the real-time analysis unit collects user operation history and detects abnormal operations that differ from normal operation patterns. For example, it identifies operations that are frequently performed during specific time periods or operations that are not normally performed. The real-time analysis unit also analyzes application usage patterns and detects abnormal usage patterns. For example, it identifies cases where a specific application is being used more frequently than normal. This enables more detailed anomaly detection by analyzing user operation history and application usage patterns.
[0061] The real-time analysis unit includes the server's hardware status in the data it collects in real time, and can also detect abnormal hardware behavior. For example, the real-time analysis unit uses a generative AI to monitor the server's CPU temperature in real time and detect abnormal temperature increases that exceed the normal temperature range. For example, it identifies cases where the CPU temperature rises sharply during a specific time period. The real-time analysis unit also monitors memory usage and detects abnormal memory use. For example, it identifies cases where a specific process is consuming an abnormally large amount of memory. Furthermore, the real-time analysis unit monitors disk I / O and detects abnormal disk access. For example, it identifies cases where disk access increases suddenly during a specific time period. In this way, abnormal hardware behavior can be detected by monitoring the server's hardware status.
[0062] The real-time analysis unit uses an emotion estimation function to monitor the emotional state of the server administrator in real time and issue a warning when stress or fatigue increases. For example, the real-time analysis unit uses a generative AI to analyze the server administrator's facial expressions and estimate their emotional state in real time. For example, a camera can be used to monitor the administrator's facial expressions and detect signs of stress or fatigue. The real-time analysis unit also analyzes the administrator's voice to estimate their emotional state. For example, voice analysis technology can be used to analyze the tone and speed of the administrator's voice to detect signs of stress or fatigue. The real-time analysis unit can also analyze the administrator's biometric data (heart rate and electrodermal activity) to estimate their emotional state. For example, it can detect signs of stress or fatigue based on fluctuations in heart rate. This allows the system to monitor the server administrator's emotional state and issue a warning when stress or fatigue increases, thereby reducing the administrator's burden.
[0063] The real-time analysis unit applies real-time analysis by generative AI to not only cloud environments but also on-premises environments, making it possible to support different infrastructures. For example, the real-time analysis unit can operate generative AI in both cloud and on-premises environments to support different infrastructures. For example, it can simultaneously monitor both cloud and on-premises servers. The real-time analysis unit also synchronizes data between cloud and on-premises environments to provide unified security measures. For example, it can apply security policies on the cloud to the on-premises environment. Furthermore, the real-time analysis unit distributes load between cloud and on-premises environments to achieve efficient resource utilization. For example, it can use resources in the on-premises environment when resources on the cloud are insufficient. This enables real-time analysis by generative AI in both cloud and on-premises environments.
[0064] The real-time analysis unit includes data from IoT devices in the data it analyzes, enabling it to detect abnormalities in devices that connect to the server. For example, the real-time analysis unit uses a generative AI to collect data from IoT devices in real time and detect abnormalities in devices that connect to the server. For example, it analyzes communication data and sensor data from IoT devices to detect abnormal behavior. The real-time analysis unit also monitors the firmware status of IoT devices and detects abnormal firmware changes. For example, it identifies cases where firmware has been illegally changed during a specific time period. Furthermore, the real-time analysis unit monitors the network traffic of IoT devices and detects abnormal traffic patterns. For example, it identifies large amounts of data being sent from a specific device. In this way, by including data from IoT devices, it is possible to detect abnormalities in devices that connect to the server.
[0065] The real-time analysis unit uses an emotion estimation function to analyze the emotional state of the server user and can provide support when the user feels anxious or dissatisfied. For example, the real-time analysis unit uses a generative AI to analyze the facial expressions of the server user and estimate the emotional state in real time. For example, a camera may be used to monitor the user's facial expressions and detect signs of anxiety or dissatisfaction. The real-time analysis unit also analyzes the user's voice to estimate the emotional state. For example, voice analysis technology may be used to analyze the tone and speed of the user's voice to detect signs of anxiety or dissatisfaction. The real-time analysis unit may also analyze the user's biometric data (heart rate and electrodermal activity) to estimate the emotional state. For example, signs of anxiety or dissatisfaction may be detected based on fluctuations in heart rate. This allows the server user's emotional state to be analyzed and support to be provided when the user feels anxious or dissatisfied, thereby improving user satisfaction.
[0066] When detecting suspicious activity, the suspicious activity detection unit learns past attack patterns and can also respond to unknown attack methods. For example, the suspicious activity detection unit uses a generation AI to learn past attack patterns and can also respond to unknown attack methods. For example, it predicts new attack patterns based on past attack data. The suspicious activity detection unit also monitors changes in attack patterns in real time and detects unknown attack methods. For example, if a new attack method appears, it quickly identifies that method. Furthermore, the suspicious activity detection unit analyzes the similarity of attack patterns and identifies unknown attack methods. For example, it identifies new attack methods that are similar to existing attack patterns. In this way, by learning past attack patterns, it can also respond to unknown attack methods.
[0067] The suspicious activity detection unit can include internal threats in the suspicious activity it detects. For example, the suspicious activity detection unit analyzes the operation history of insiders so that the generation AI can detect internal threats. For example, it identifies cases where a specific insider is performing operations that they normally do not perform. The suspicious activity detection unit also analyzes the access patterns of insiders to detect abnormal access. For example, it identifies cases where a specific insider is accessing files that they normally do not access. Furthermore, the suspicious activity detection unit analyzes the communication data of insiders to detect abnormal communications. For example, it identifies cases where a specific insider is sending large amounts of data to the outside. This allows the detection of internal threats as well, making it possible to respond to fraudulent activities by insiders.
[0068] The suspicious activity detection unit uses an emotion estimation function to analyze the emotional state of the server administrator and can perform additional security checks if the administrator feels anxious. For example, the suspicious activity detection unit uses a generative AI to analyze the server administrator's facial expressions and estimate their emotional state in real time. For example, it uses a camera to monitor the administrator's facial expressions and detect signs of anxiety. The suspicious activity detection unit also analyzes the administrator's voice to estimate their emotional state. For example, it uses voice analysis technology to analyze the tone and speed of the administrator's voice and detect signs of anxiety. The suspicious activity detection unit also analyzes the administrator's biometric data (heart rate and electrodermal activity) to estimate their emotional state. For example, it detects signs of anxiety based on fluctuations in heart rate. This allows the server administrator's emotional state to be analyzed and additional security checks to be performed if the administrator feels anxious, thereby strengthening security.
[0069] When detecting suspicious activity, the suspicious activity detection unit can reference security data from different industries and respond to industry-specific threats. For example, the suspicious activity detection unit uses a generation AI to reference security data from different industries to detect industry-specific threats. For example, it identifies abnormal patterns based on security data from the financial and medical industries. The suspicious activity detection unit also learns industry-specific attack methods and can respond to unknown attack methods. For example, it detects phishing attacks in the financial industry and data leaks in the medical industry. Furthermore, the suspicious activity detection unit utilizes industry-specific threat intelligence to detect threats in real time. For example, it identifies new attack methods based on industry-specific threat information. This allows it to respond to industry-specific threats by referring to security data from different industries.
[0070] The suspicious activity detection unit can include physical security in the suspicious activity it detects. For example, the suspicious activity detection unit analyzes physical security data so that the generation AI can detect unauthorized intrusions into a server room. For example, it analyzes the server room's access logs and surveillance camera footage to detect unauthorized intrusions. The suspicious activity detection unit also monitors the status of physical security devices and detects abnormal conditions. For example, it analyzes data from door opening / closing sensors and motion sensors to identify unauthorized intrusions. Furthermore, the suspicious activity detection unit monitors physical security events in real time and detects abnormal events. For example, it identifies abnormal access that occurs during specific time periods. By including physical security, this makes it possible to respond to physical threats such as unauthorized intrusions into server rooms.
[0071] The suspicious activity detection unit uses an emotion estimation function to analyze the emotional state of the server user and can suggest security enhancements if the user feels anxious. For example, the suspicious activity detection unit uses a generative AI to analyze the server user's facial expressions and estimate their emotional state in real time. For example, it uses a camera to monitor the user's facial expressions and detect signs of anxiety. The suspicious activity detection unit also analyzes the user's voice to estimate their emotional state. For example, it uses voice analysis technology to analyze the tone and speed of the user's voice to detect signs of anxiety. Furthermore, the suspicious activity detection unit analyzes the user's biometric data (heart rate and electrodermal activity) to estimate their emotional state. For example, it detects signs of anxiety based on fluctuations in heart rate. This allows the server user's emotional state to be analyzed and security enhancements to be suggested if the user feels anxious, thereby improving the user's sense of security.
[0072] When identifying a threat, the threat response unit predicts the attacker's behavioral patterns and can prevent the next attack. For example, the threat response unit uses a generation AI to predict the attacker's behavioral patterns based on past attack data and prevent the next attack. For example, it predicts attacks during specific time periods or from specific IP addresses. The threat response unit also monitors the attacker's behavioral patterns in real time and predicts the next attack. For example, it identifies when an attacker is attempting to access a specific server. Furthermore, the threat response unit analyzes changes in the attacker's behavioral patterns and predicts new attack methods. For example, it identifies when an attacker is attempting a new attack method. This makes it possible to predict the attacker's behavioral patterns and prevent the next attack.
[0073] When taking action, the threat response unit can simulate multiple response methods and select the most appropriate one. In the threat response unit, for example, a generation AI simulates multiple response methods and selects the most appropriate one. For example, multiple defense methods are tried against a specific attack and the most effective method is selected. The threat response unit also selects a response method based on the simulation results. For example, the most effective response method is selected based on the simulation results. Furthermore, the threat response unit monitors the simulation results in real time and adjusts the response method. For example, the response method is adjusted based on the simulation results. In this way, the optimal response method can be selected by simulating multiple response methods.
[0074] The threat response unit uses an emotion estimation function to analyze the emotional state of the server administrator and can automatically take action if the administrator feels stressed. For example, the threat response unit uses a generative AI to analyze the server administrator's facial expressions and estimate their emotional state in real time. For example, a camera can be used to monitor the administrator's facial expressions and detect signs of stress. The threat response unit also analyzes the administrator's voice to estimate their emotional state. For example, voice analysis technology can be used to analyze the tone and speed of the administrator's voice to detect signs of stress. Furthermore, the threat response unit analyzes the administrator's biometric data (heart rate and electrodermal activity) to estimate their emotional state. For example, it can detect signs of stress based on fluctuations in heart rate. This allows the server administrator's emotional state to be analyzed and automatic action to be taken if the administrator feels stressed, thereby reducing the burden on the administrator.
[0075] When identifying threats, the threat response department can share information with other companies and organizations and jointly address threats. For example, the generative AI in the threat response department can share information with other companies and organizations and jointly address threats. For example, security incident information can be shared and countermeasures can be jointly implemented. The threat response department also exchanges data using information sharing protocols. For example, security data can be shared using APIs. Furthermore, the threat response department adjusts response methods based on the results of information sharing. For example, it adjusts response methods based on information obtained from other companies and organizations. In this way, by sharing information with other companies and organizations, threats can be jointly addressed.
[0076] The threat response unit can include physical security measures when taking countermeasures. For example, the generation AI of the threat response unit takes countermeasures that include physical security measures. For example, if it detects an unauthorized intrusion into a server room, it will lock down the server room. The threat response unit also strengthens physical access control. For example, it strengthens access control in the server room to prevent unauthorized access. Furthermore, the threat response unit monitors physical security devices and detects abnormal conditions. For example, it analyzes data from door opening / closing sensors and motion sensors to identify unauthorized intrusions. By including physical security measures, physical countermeasures such as locking down the server room become possible.
[0077] The threat response unit uses an emotion estimation function to analyze the emotional state of the server user and can suggest ways to deal with the situation if the user feels anxious. For example, the threat response unit uses a generation AI to analyze the server user's facial expressions and estimate their emotional state in real time. For example, a camera can be used to monitor the user's facial expressions and detect signs of anxiety. The threat response unit also analyzes the user's voice to estimate their emotional state. For example, voice analysis technology can be used to analyze the tone and speed of the user's voice to detect signs of anxiety. Furthermore, the threat response unit analyzes the user's biometric data (heart rate and electrodermal activity) to estimate their emotional state. For example, signs of anxiety can be detected based on fluctuations in heart rate. This allows the server user's emotional state to be analyzed and ways to deal with the situation if the user feels anxious, thereby improving the user's sense of security.
[0078] When generating a security report, the report generation unit performs a comparative analysis with past reports and can clearly indicate changes in the security situation. For example, the report generation unit uses a generation AI to perform a comparative analysis with the current report based on past security reports. For example, it compares past attack patterns and countermeasures to identify changes in the security situation. The report generation unit also clearly indicates changes in the security situation based on the results of the comparative analysis. For example, it clearly indicates differences between past reports and the current report. Furthermore, the report generation unit monitors the results of the comparative analysis in real time and tracks changes in the security situation. For example, it tracks changes between past reports and the current report in real time. This makes it possible to clearly indicate changes in the security situation by performing a comparative analysis with past reports.
[0079] The report generation unit can include a detailed timeline of the attack and the attacker's behavioral patterns in the report it generates. For example, the generation AI in the report generation unit includes a detailed timeline of the attack in the report. For example, it clearly indicates the start time, progress, and end time of the attack. The report generation unit also includes the attacker's behavioral patterns in the report. For example, it clearly indicates what method the attacker used to carry out the attack and the route they took. Furthermore, the report generation unit includes the scope of the attack's impact in the report. For example, it clearly indicates which systems and data were affected by the attack. In this way, by including a detailed timeline of the attack and the attacker's behavioral patterns, it is possible to provide a more detailed security report.
[0080] The report generation unit can use an emotion estimation function to analyze the emotional state of the administrator receiving the report and provide the report in an easy-to-understand format. For example, the report generation unit uses a generation AI to analyze the administrator's facial expressions and estimate the administrator's emotional state in real time. For example, the report generation unit uses a camera to monitor the administrator's facial expressions and provide the report in an easy-to-understand format. The report generation unit also analyzes the administrator's voice to estimate the administrator's emotional state. For example, it uses voice analysis technology to analyze the tone and speed of the administrator's voice and provides the report in an easy-to-understand format. Furthermore, the report generation unit analyzes the administrator's biometric data (heart rate and electrodermal activity) to estimate the administrator's emotional state. For example, it provides the report in an easy-to-understand format based on heart rate fluctuations. In this way, the burden on the administrator can be reduced by analyzing the administrator's emotional state and providing the report in an easy-to-understand format.
[0081] The report generation unit automatically translates the generated reports into different languages, allowing for feedback from an international perspective. For example, the report generation unit uses a generation AI to automatically translate security reports into different languages. For example, it translates into multiple languages such as English, French, and Chinese, allowing for feedback from an international perspective. The report generation unit also monitors the accuracy of the translation in real time and corrects the translation as necessary. For example, it automatically corrects translations that are inaccurate. Furthermore, the report generation unit provides the translated reports to the international security community and collects feedback. For example, it shares the reports at international security forums and conferences. This allows for feedback from an international perspective to be obtained by automatically translating into different languages.
[0082] The report generation unit can convert the generated report into a visual note or mind map to make it easier to understand visually. In the report generation unit, for example, the generation AI converts a security report into a visual note. For example, it indicates important points with diagrams and icons to make it easier to understand visually. The report generation unit also converts the security report into a mind map. For example, it visually arranges central themes and related subthemes to make it easier to understand. Furthermore, the report generation unit updates the visual note or mind map in real time to reflect the latest information. For example, it automatically updates when new threat information is added. In this way, by converting the report into a visual note or mind map, it is possible to provide a report that is easier to understand visually.
[0083] The report generation unit can use an emotion estimation function to analyze the emotional state of a user receiving the report and provide the report in a format that elicits positive emotions. For example, the report generation unit uses a generation AI to analyze the user's facial expressions and estimate the emotional state in real time. For example, the report generation unit uses a camera to monitor the user's facial expressions and provide a report in a format that elicits positive emotions. The report generation unit also analyzes the user's voice and estimates the emotional state. For example, it uses voice analysis technology to analyze the tone and speed of the user's voice and provides a report in a format that elicits positive emotions. Furthermore, the report generation unit analyzes the user's biometric data (heart rate and electrodermal activity) and estimates the emotional state. For example, it provides a report in a format that elicits positive emotions based on heart rate fluctuations. In this way, analyzing the user's emotional state and providing a report in a format that elicits positive emotions improves user satisfaction.
[0084] When performing automatic learning, the automatic learning unit can cooperate with other AI systems and share learning data with each other. For example, the generation AI of the automatic learning unit cooperates with other AI systems and shares learning data with each other. For example, it collects data from different AI systems and uses it for learning. The automatic learning unit also exchanges data using an API. For example, it exchanges data with other AI systems in real time. Furthermore, the automatic learning unit adjusts the learning algorithm based on the shared data. For example, it optimizes the learning algorithm based on data obtained from other AI systems. In this way, by cooperating with other AI systems, learning data can be shared with each other, enabling more effective automatic learning.
[0085] The automatic learning unit can include the latest threat information from external security research institutions in the learning data. For example, the generation AI in the automatic learning unit includes the latest threat information from external security research institutions in the learning data. For example, it collects the latest attack methods and vulnerability information and uses it for learning. The automatic learning unit also collects the latest threat information in real time and reflects it in the learning data. For example, it collects real-time threat intelligence from security research institutions. Furthermore, the automatic learning unit adjusts the learning algorithm based on the latest threat information. For example, it optimizes the algorithm to respond to new attack methods. In this way, by including the latest threat information from external security research institutions in the learning data, it is possible to respond to the latest threats.
[0086] The automatic learning unit uses an emotion estimation function to analyze the emotional state of the server administrator and can adjust the learning content when the administrator feels stressed. For example, the automatic learning unit uses a generation AI to analyze the server administrator's facial expressions and estimate their emotional state in real time. For example, it uses a camera to monitor the administrator's facial expressions and adjusts the learning content when it detects signs of stress. The automatic learning unit also analyzes the administrator's voice to estimate their emotional state. For example, it uses voice analysis technology to analyze the tone and speed of the administrator's voice and adjusts the learning content when it detects signs of stress. Furthermore, the automatic learning unit analyzes the administrator's biometric data (heart rate and electrodermal activity) to estimate their emotional state. For example, it adjusts the learning content when it detects signs of stress based on fluctuations in heart rate. This allows the server administrator's emotional state to be analyzed and the learning content to be adjusted when they feel stressed, thereby reducing the burden on the administrator.
[0087] When performing automatic learning, the automatic learning unit can refer to security data from different industries to respond to industry-specific threats. For example, the generation AI of the automatic learning unit refers to security data from different industries to learn about industry-specific threats. For example, it identifies abnormal patterns based on security data from the financial and medical industries. The automatic learning unit also utilizes industry-specific threat intelligence to learn about threats in real time. For example, it learns about phishing attacks in the financial industry and data leaks in the medical industry. Furthermore, the automatic learning unit adjusts the learning algorithm based on industry-specific threat information. For example, it optimizes the algorithm to respond to industry-specific attack methods. This allows it to respond to industry-specific threats by referring to security data from different industries.
[0088] The automatic learning unit can include physical security data in the data it learns. For example, the generation AI includes physical security data in the learning data. For example, it collects access logs from server rooms and footage from surveillance cameras and uses this for learning. The automatic learning unit also collects data from physical security devices and uses this for learning. For example, it collects data from door opening / closing sensors and motion sensors. Furthermore, the automatic learning unit collects data on physical security events and uses this for learning. For example, it collects data on abnormal access that occurs during specific time periods. In this way, by including physical security data in the learning data, it is possible to respond to physical threats.
[0089] The automatic learning unit uses an emotion estimation function to analyze the emotional state of the server user and adjusts the learning content when the user feels anxious. For example, the automatic learning unit uses a generation AI to analyze the server user's facial expressions and estimate the emotional state in real time. For example, it uses a camera to monitor the user's facial expressions and adjusts the learning content when it detects signs of anxiety. The automatic learning unit also analyzes the user's voice to estimate the emotional state. For example, it uses voice analysis technology to analyze the tone and speed of the user's voice and adjusts the learning content when it detects signs of anxiety. Furthermore, the automatic learning unit analyzes the user's biometric data (heart rate and electrodermal activity) to estimate the emotional state. For example, it adjusts the learning content when it detects signs of anxiety based on fluctuations in heart rate. In this way, the automatic learning unit analyzes the server user's emotional state and adjusts the learning content when it feels anxious, thereby improving the user's sense of security.
[0090] The system according to the embodiment is not limited to the above-described example, and various modifications are possible, for example, as follows.
[0091] When analyzing server behavior, the real-time analysis unit simultaneously analyzes the server's power consumption data and can detect abnormal power consumption. For example, it can identify cases where power consumption increases suddenly during a specific time period. The real-time analysis unit also analyzes the server's power consumption patterns and detects abnormal consumption that differs from normal consumption patterns. For example, it can identify cases where a specific process is consuming an abnormally large amount of power. Furthermore, the real-time analysis unit can suggest efficient server operation based on the power consumption data. For example, it can suggest load balancing during times of high power consumption. In this way, by analyzing the server's power consumption data, abnormal power consumption can be detected and efficient operation can be achieved.
[0092] The real-time analysis unit uses emotion estimation to analyze the emotional state of the server user and can adjust resource allocation when the user feels stressed. For example, the generation AI analyzes the user's facial expressions to estimate their emotional state in real time. For example, a camera can be used to monitor the user's facial expressions and detect signs of stress. The real-time analysis unit also analyzes the user's voice to estimate their emotional state. For example, voice analysis technology can be used to analyze the tone and speed of the user's voice to detect signs of stress. The real-time analysis unit also analyzes the user's biometric data (heart rate and electrodermal activity) to estimate their emotional state. For example, it can detect signs of stress based on fluctuations in heart rate. This allows the server user's emotional state to be analyzed and resource allocation to be adjusted when the user feels stressed, thereby reducing the user's burden.
[0093] When analyzing server behavior, the real-time analysis unit can also detect anomalies in network traffic. For example, it can identify sudden increases in network traffic during specific time periods. The real-time analysis unit also analyzes network traffic patterns and detects abnormal traffic that differs from normal traffic patterns. For example, it can identify large amounts of data being sent from specific IP addresses. Furthermore, the real-time analysis unit can propose more efficient server operation based on network traffic data. For example, it can propose load balancing during times of heavy traffic. This allows for the detection of network traffic anomalies and the realization of more efficient operation.
[0094] The real-time analysis unit uses an emotion estimation function to analyze the emotional state of the server administrator and can automatically suggest taking a break if the administrator feels fatigued. For example, the generative AI analyzes the administrator's facial expressions to estimate their emotional state in real time. For example, a camera can be used to monitor the administrator's facial expressions and detect signs of fatigue. The real-time analysis unit also analyzes the administrator's voice to estimate their emotional state. For example, voice analysis technology can be used to analyze the tone and speed of the administrator's voice to detect signs of fatigue. The real-time analysis unit can also analyze the administrator's biometric data (heart rate and electrodermal activity) to estimate their emotional state. For example, it can detect signs of fatigue based on fluctuations in heart rate. This allows the system to analyze the server administrator's emotional state and automatically suggest taking a break if the administrator feels fatigued, thereby supporting their health.
[0095] When analyzing server behavior, the real-time analysis unit simultaneously analyzes the server's software status, enabling it to detect abnormal software behavior. For example, it can identify cases where specific software is consuming an abnormally large number of resources. The real-time analysis unit also analyzes software version information to identify cases where an old version of software is being used. Furthermore, the real-time analysis unit analyzes software error logs to detect abnormal error occurrences. For example, it can identify cases where errors occur frequently during specific time periods. This makes it possible to detect abnormal software behavior by analyzing the server's software status and take prompt action.
[0096] The real-time analysis unit uses an emotion estimation function to analyze the emotional state of the server user and provide positive feedback when the user is satisfied. For example, the generation AI analyzes the user's facial expressions to estimate their emotional state in real time. For example, a camera can be used to monitor the user's facial expressions and detect signs of satisfaction. The real-time analysis unit also analyzes the user's voice to estimate their emotional state. For example, voice analysis technology can be used to analyze the tone and speed of the user's voice to detect signs of satisfaction. The real-time analysis unit also analyzes the user's biometric data (heart rate and electrodermal activity) to estimate their emotional state. For example, it can detect signs of satisfaction based on fluctuations in heart rate. This allows the server user's emotional state to be analyzed and positive feedback provided when the user is satisfied, thereby improving user satisfaction.
[0097] When detecting suspicious activity, the suspicious activity detection unit analyzes the server's physical location information and can detect access from an abnormal location. For example, it can identify access from a location away from the normal location during a specific time period. The suspicious activity detection unit can also analyze location history and detect access from an abnormal location that differs from normal access patterns. For example, it can identify cases where a specific IP address is accessing from an abnormal location. Furthermore, the suspicious activity detection unit can make suggestions to strengthen the server's security measures based on the location information. For example, it can suggest blocking access from an abnormal location. In this way, by analyzing the server's physical location information, it is possible to detect access from an abnormal location and strengthen security measures.
[0098] The suspicious activity detection unit uses an emotion estimation function to analyze the emotional state of the server administrator and can perform additional security checks if the administrator feels anxious. For example, the generative AI analyzes the server administrator's facial expressions and estimates their emotional state in real time. For example, a camera can be used to monitor the administrator's facial expressions and detect signs of anxiety. The suspicious activity detection unit also analyzes the administrator's voice to estimate their emotional state. For example, voice analysis technology can be used to analyze the tone and speed of the administrator's voice to detect signs of anxiety. The suspicious activity detection unit also analyzes the administrator's biometric data (heart rate and electrodermal activity) to estimate their emotional state. For example, it can detect signs of anxiety based on fluctuations in heart rate. This allows for the server administrator's emotional state to be analyzed and additional security checks to be performed if the administrator feels anxious, thereby strengthening security.
[0099] When detecting suspicious activity, the suspicious activity detection unit can also detect anomalies in the server's communication protocols. For example, it can identify cases where an unusual protocol is being used during a specific time period. The suspicious activity detection unit also analyzes communication protocol patterns and detects anomalous protocol usage that differs from the normal pattern. For example, it can identify cases where a specific IP address is using an abnormal protocol. Furthermore, the suspicious activity detection unit can make suggestions to strengthen server security measures based on communication protocol anomalies. For example, it can suggest blocking the use of an abnormal protocol. This makes it possible to detect anomalies in the server's communication protocols and strengthen security measures.
[0100] The suspicious activity detection unit uses an emotion estimation function to analyze the emotional state of the server user and can suggest security enhancements if the user feels anxious. For example, the generative AI analyzes the server user's facial expressions and estimates their emotional state in real time. For example, a camera can be used to monitor the user's facial expressions and detect signs of anxiety. The suspicious activity detection unit also analyzes the user's voice to estimate their emotional state. For example, voice analysis technology can be used to analyze the tone and speed of the user's voice to detect signs of anxiety. The suspicious activity detection unit also analyzes the user's biometric data (heart rate and electrodermal activity) to estimate their emotional state. For example, it can detect signs of anxiety based on fluctuations in heart rate. This allows the server user's emotional state to be analyzed and security enhancements can be suggested if the user feels anxious, improving the user's sense of security.
[0101] The processing flow of the second embodiment will be briefly explained below.
[0102] Step 1: The real-time analysis unit uses generative AI to analyze server behavior in real time, for example, analyzing server access logs, communication data, file change history, etc., to detect suspicious activity that deviates from normal behavior. Step 2: The suspicious activity detection unit detects suspicious activity from the data analyzed by the real-time analysis unit, such as a large number of accesses that differ from normal access patterns or unauthorized access to specific files. Step 3: The threat response unit identifies and responds to threats based on the suspicious activity detected by the suspicious activity detection unit. For example, if an attack from a specific IP address is detected, that IP address will be blocked. Also, if a specific file has been illegally modified, the file will be restored to its original state. Step 4: The report generation unit generates a security report based on information about the threats dealt with by the threat response unit. For example, based on information about detected suspicious activity and dealt with threats, the unit generates a report to be provided to the company's security personnel. Step 5: The automatic learning unit automatically learns and improves security measures based on the reports generated by the report generation unit. For example, it automatically learns countermeasures to deal with new attack methods based on data on detected suspicious activity and countermeasures against threats.
[0103] The specific processing unit 290 transmits the result of the specific processing to the smart device 14. In the smart device 14, the control unit 46A causes the output device 40 to output the result of the specific processing. The microphone 38B acquires audio indicating a user input regarding the result of the specific processing. The control unit 46A transmits audio data indicating the user input acquired by the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.
[0104] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> Examples of generative AIs include the data generation model 58, such as a neural network model (e.g., a neural network model), and a neural network model (e.g., a neural network model). The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating speech, text data indicating text, and image data indicating an image is also input to the data generation model 58. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization. The specification processing unit 290 performs the above-mentioned specification processing using the data generation model 58. The data generation model 58 may be a fine-tuned model so as to output an inference result from a prompt that does not include an instruction. In this case, the data generation model 58 can output an inference result from a prompt that does not include an instruction. The data processing device 12 and the like include multiple types of data generation models 58, and the data generation model 58 includes AIs other than the generative AI. The AI other than the generative AI may be, for example, linear regression, logistic regression, decision tree, random forest, support vector machine (SVM), k-means clustering, convolutional neural network (CNN), recurrent neural network (RNN), generative adversarial network (GAN), or naive Bayes, and can perform various processes, but is not limited to these examples. The AI may also be an AI agent. When the processes of each of the above-mentioned parts are performed by AI, the processes may be performed in part or entirely by AI, but are not limited to these examples. The processes performed by AI, including the generative AI, may be replaced with rule-based processes.
[0105] Furthermore, the processing by the data processing system 10 described above is executed by the specific processing unit 290 of the data processing device 12 or the control unit 46A of the smart device 14, but may also be executed by the specific processing unit 290 of the data processing device 12 and the control unit 46A of the smart device 14. Furthermore, the specific processing unit 290 of the data processing device 12 acquires or collects information necessary for processing from the smart device 14 or an external device, and the smart device 14 acquires or collects information necessary for processing from the data processing device 12 or an external device.
[0106] [Second embodiment] FIG. 3 shows an example of the configuration of a data processing system 210 according to the second embodiment.
[0107] 3, the data processing system 210 includes a data processing device 12 and smart glasses 214. An example of the data processing device 12 is a server.
[0108] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN and / or a LAN.
[0109] The smart glasses 214 include a computer 36, a microphone 238, a speaker 240, a camera 42, and a communication I / F 44. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The microphone 238, the speaker 240, and the camera 42 are also connected to the bus 52.
[0110] The microphone 238 receives instructions and the like from the user by receiving voice uttered by the user. The microphone 238 captures the voice uttered by the user, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to instructions from the processor 46.
[0111] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the user's surroundings (for example, an imaging range defined by an angle of view equivalent to the field of vision of a typical healthy person).
[0112] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 are responsible for the exchange of various information between the processor 46 and the processor 28 via the network 54. The exchange of various information between the processor 46 and the processor 28 using the communication I / Fs 44 and 26 is carried out in a secure state.
[0113] Fig. 4 shows an example of the main functions of the data processing device 12 and the smart glasses 214. As shown in Fig. 4, in the data processing device 12, a specific process is performed by the processor 28. A specific process program 56 is stored in the storage 32.
[0114] The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[0115] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290. The identification processing unit 290 can estimate the user's emotion using the emotion identification model 59 and perform identification processing using the user's emotion.
[0116] In the smart glasses 214, the specific processing is performed by the processor 46. A specific processing program 60 is stored in the storage 50. The processor 46 reads the specific processing program 60 from the storage 50 and executes the read specific processing program 60 on the RAM 48. The specific processing is realized by the processor 46 operating as the control unit 46A in accordance with the specific processing program 60 executed on the RAM 48. Note that the smart glasses 214 may have a data generation model and an emotion identification model similar to the data generation model 58 and the emotion identification model 59.
[0117] Note that a device other than the data processing device 12 may have the data generation model 58. For example, a server device may have the data generation model 58. In this case, the data processing device 12 communicates with the server device having the data generation model 58 to obtain a processing result (such as a prediction result) using the data generation model 58. Furthermore, the data processing device 12 may be a server device, or may be a terminal device (for example, a mobile phone, a robot, a home appliance, etc.) owned by a user.
[0118] The specific processing unit 290 transmits the result of the specific processing to the smart glasses 214. In the smart glasses 214, the control unit 46A causes the speaker 240 to output the result of the specific processing. The microphone 238 acquires audio indicating a user input regarding the result of the specific processing. The control unit 46A transmits audio data indicating the user input acquired by the microphone 238 to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.
[0119] The data generation model 58 is a so-called generative AI. An example of the data generation model 58 is a generative AI such as ChatGPT. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 receives a prompt containing an instruction, as well as inference data such as voice data representing speech, text data representing text, and image data representing an image. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization. The identification processing unit 290 performs the above-mentioned identification processing using the data generation model 58. The data generation model 58 may be a fine-tuned model so as to output an inference result from a prompt that does not include an instruction. In this case, the data generation model 58 can output an inference result from a prompt that does not include an instruction. The data processing device 12 and the like include multiple types of data generation models 58, and the data generation model 58 includes AIs other than the generative AI. The AI other than the generative AI may be, for example, linear regression, logistic regression, decision tree, random forest, support vector machine (SVM), k-means clustering, convolutional neural network (CNN), recurrent neural network (RNN), generative adversarial network (GAN), or naive Bayes, and can perform various processes, but is not limited to these examples. The AI may also be an AI agent. When the processes of each of the above-mentioned parts are performed by AI, the processes may be performed in part or entirely by AI, but are not limited to these examples. The processes performed by AI, including the generative AI, may be replaced with rule-based processes.
[0120] The data processing system 210 according to the second embodiment performs the same processing as the data processing system 10 according to the first embodiment. The processing by the data processing system 210 is executed by the specific processing unit 290 of the data processing device 12 or the control unit 46A of the smart glasses 214, but may also be executed by the specific processing unit 290 of the data processing device 12 and the control unit 46A of the smart glasses 214. Furthermore, the specific processing unit 290 of the data processing device 12 acquires or collects information required for processing from the smart glasses 214 or an external device, etc., and the smart glasses 214 acquires or collects information required for processing from the data processing device 12 or an external device, etc.
[0121] [Third embodiment] FIG. 5 shows an example of the configuration of a data processing system 310 according to the third embodiment.
[0122] 5, the data processing system 310 includes the data processing device 12 and a headset terminal 314. An example of the data processing device 12 is a server.
[0123] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN and / or a LAN.
[0124] The headset type terminal 314 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication I / F 44, and a display 343. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The microphone 238, the speaker 240, the camera 42, and the display 343 are also connected to the bus 52.
[0125] The microphone 238 receives instructions and the like from the user by receiving voice uttered by the user. The microphone 238 captures the voice uttered by the user, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to instructions from the processor 46.
[0126] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the user's surroundings (for example, an imaging range defined by an angle of view equivalent to the field of vision of a typical healthy person).
[0127] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 are responsible for the exchange of various information between the processor 46 and the processor 28 via the network 54. The exchange of various information between the processor 46 and the processor 28 using the communication I / Fs 44 and 26 is carried out in a secure state.
[0128] Fig. 6 shows an example of the main functions of the data processing device 12 and the headset terminal 314. As shown in Fig. 6, in the data processing device 12, a specific process is performed by the processor 28. A specific process program 56 is stored in the storage 32.
[0129] The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[0130] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290. The identification processing unit 290 can estimate the user's emotion using the emotion identification model 59 and perform identification processing using the user's emotion.
[0131] In the headset type terminal 314, the identification process is performed by the processor 46. A identification program 60 is stored in the storage 50. The processor 46 reads the identification program 60 from the storage 50 and executes the read identification program 60 on the RAM 48. The identification process is realized by the processor 46 operating as a control unit 46A in accordance with the identification program 60 executed on the RAM 48. Note that the headset type terminal 314 may also have a data generation model and an emotion identification model similar to the data generation model 58 and the emotion identification model 59.
[0132] Note that a device other than the data processing device 12 may have the data generation model 58. For example, a server device may have the data generation model 58. In this case, the data processing device 12 communicates with the server device having the data generation model 58 to obtain a processing result (such as a prediction result) using the data generation model 58. Furthermore, the data processing device 12 may be a server device, or may be a terminal device (for example, a mobile phone, a robot, a home appliance, etc.) owned by a user.
[0133] The specific processing unit 290 transmits the result of the specific processing to the headset type terminal 314. In the headset type terminal 314, the control unit 46A causes the speaker 240 and the display 343 to output the result of the specific processing. The microphone 238 acquires audio indicating a user input regarding the result of the specific processing. The control unit 46A transmits audio data indicating the user input acquired by the microphone 238 to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.
[0134] The data generation model 58 is a so-called generative AI. An example of the data generation model 58 is a generative AI such as ChatGPT. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 receives a prompt containing an instruction, as well as inference data such as voice data representing speech, text data representing text, and image data representing an image. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization. The identification processing unit 290 performs the above-mentioned identification processing using the data generation model 58. The data generation model 58 may be a fine-tuned model so as to output an inference result from a prompt that does not include an instruction. In this case, the data generation model 58 can output an inference result from a prompt that does not include an instruction. The data processing device 12 and the like include multiple types of data generation models 58, and the data generation model 58 includes AIs other than the generative AI. The AI other than the generative AI may be, for example, linear regression, logistic regression, decision tree, random forest, support vector machine (SVM), k-means clustering, convolutional neural network (CNN), recurrent neural network (RNN), generative adversarial network (GAN), or naive Bayes, and can perform various processes, but is not limited to these examples. The AI may also be an AI agent. When the processes of each of the above-mentioned parts are performed by AI, the processes may be performed in part or entirely by AI, but are not limited to these examples. The processes performed by AI, including the generative AI, may be replaced with rule-based processes.
[0135] The data processing system 310 according to the third embodiment performs the same processing as the data processing system 10 according to the first embodiment. The processing by the data processing system 310 is executed by the specific processing unit 290 of the data processing device 12 or the control unit 46A of the headset type terminal 314, but may also be executed by the specific processing unit 290 of the data processing device 12 and the control unit 46A of the headset type terminal 314. Furthermore, the specific processing unit 290 of the data processing device 12 acquires or collects information required for processing from the headset type terminal 314 or an external device, etc., and the headset type terminal 314 acquires or collects information required for processing from the data processing device 12 or an external device, etc.
[0136] [Fourth embodiment] FIG. 7 shows an example of the configuration of a data processing system 410 according to the fourth embodiment.
[0137] 7, the data processing system 410 includes a data processing device 12 and a robot 414. An example of the data processing device 12 is a server.
[0138] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN and / or a LAN.
[0139] The robot 414 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication I / F 44, and a control target 443. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The microphone 238, the speaker 240, the camera 42, and the control target 443 are also connected to the bus 52.
[0140] The microphone 238 receives instructions and the like from the user by receiving voice uttered by the user. The microphone 238 captures the voice uttered by the user, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to instructions from the processor 46.
[0141] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS image sensor or a CCD image sensor, and captures images of the user's surroundings (for example, an imaging range defined by an angle of view equivalent to the field of vision of a typical healthy person).
[0142] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 are responsible for the exchange of various information between the processor 46 and the processor 28 via the network 54. The exchange of various information between the processor 46 and the processor 28 using the communication I / Fs 44 and 26 is carried out in a secure state.
[0143] The control object 443 includes a display device, LEDs in the eyes, and motors that drive the arms, hands, and feet. The posture and gestures of the robot 414 are controlled by controlling the motors of the arms, hands, and feet. Some of the emotions of the robot 414 can be expressed by controlling these motors. In addition, the facial expressions of the robot 414 can also be expressed by controlling the light emission state of the LEDs in the eyes of the robot 414.
[0144] Fig. 8 shows an example of the main functions of the data processing device 12 and the robot 414. As shown in Fig. 8, in the data processing device 12, a specific process is performed by the processor 28. A specific process program 56 is stored in the storage 32.
[0145] The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[0146] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290. The identification processing unit 290 can estimate the user's emotion using the emotion identification model 59 and perform identification processing using the user's emotion.
[0147] In the robot 414, the processor 46 performs the identification process. A identification program 60 is stored in the storage 50. The processor 46 reads the identification program 60 from the storage 50 and executes the read identification program 60 on the RAM 48. The identification process is realized by the processor 46 operating as a control unit 46A in accordance with the identification program 60 executed on the RAM 48. The robot 414 may have a data generation model and an emotion identification model similar to the data generation model 58 and the emotion identification model 59.
[0148] Note that a device other than the data processing device 12 may have the data generation model 58. For example, a server device may have the data generation model 58. In this case, the data processing device 12 communicates with the server device having the data generation model 58 to obtain a processing result (such as a prediction result) using the data generation model 58. Furthermore, the data processing device 12 may be a server device, or may be a terminal device (for example, a mobile phone, a robot, a home appliance, etc.) owned by a user.
[0149] The specific processing unit 290 transmits the result of the specific processing to the robot 414. In the robot 414, the control unit 46A causes the speaker 240 and the control target 443 to output the result of the specific processing. The microphone 238 acquires voice indicating a user input regarding the result of the specific processing. The control unit 46A transmits voice data indicating the user input acquired by the microphone 238 to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the voice data.
[0150] The data generation model 58 is a so-called generative AI. An example of the data generation model 58 is a generative AI such as ChatGPT. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 receives a prompt containing an instruction, as well as inference data such as voice data representing speech, text data representing text, and image data representing an image. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization. The identification processing unit 290 performs the above-mentioned identification processing using the data generation model 58. The data generation model 58 may be a fine-tuned model so as to output an inference result from a prompt that does not include an instruction. In this case, the data generation model 58 can output an inference result from a prompt that does not include an instruction. The data processing device 12 and the like include multiple types of data generation models 58, and the data generation model 58 includes AIs other than the generative AI. The AI other than the generative AI may be, for example, linear regression, logistic regression, decision tree, random forest, support vector machine (SVM), k-means clustering, convolutional neural network (CNN), recurrent neural network (RNN), generative adversarial network (GAN), or naive Bayes, and can perform various processes, but is not limited to these examples. The AI may also be an AI agent. When the processes of each of the above-mentioned parts are performed by AI, the processes may be performed in part or entirely by AI, but are not limited to these examples. The processes performed by AI, including the generative AI, may be replaced with rule-based processes.
[0151] The data processing system 410 according to the fourth embodiment performs the same processing as the data processing system 10 according to the first embodiment. The processing by the data processing system 410 is executed by the specific processing unit 290 of the data processing device 12 or the control unit 46A of the robot 414, but may also be executed by the specific processing unit 290 of the data processing device 12 and the control unit 46A of the robot 414. Furthermore, the specific processing unit 290 of the data processing device 12 acquires or collects information required for processing from the robot 414 or an external device, etc., and the robot 414 acquires or collects information required for processing from the data processing device 12 or an external device, etc.
[0152] The emotion identification model 59 as an emotion engine may determine the user's emotion according to a specific mapping. Specifically, the emotion identification model 59 may determine the user's emotion according to an emotion map (see FIG. 9), which is a specific mapping. Similarly, the emotion identification model 59 may determine the robot's emotion, and the identification processing unit 290 may perform identification processing using the robot's emotion.
[0153] FIG. 9 illustrates an emotion map 400 on which multiple emotions are mapped. In the emotion map 400, emotions are arranged in concentric circles radiating from the center. Emotions closer to the center of the concentric circles are more primitive. Emotions representing states and behaviors arising from a state of mind are arranged on the outer edges of the concentric circles. The concept of emotion encompasses both emotions and mental states. Emotions generally generated from reactions occurring in the brain are arranged on the left side of the concentric circles. Emotions generally induced by situational judgment are arranged on the right side of the concentric circles. Emotions generally generated from reactions occurring in the brain and induced by situational judgment are arranged on the upper and lower sides of the concentric circles. Furthermore, the emotion of "pleasure" is arranged on the upper side of the concentric circles, and the emotion of "discomfort" is arranged on the lower side. In this way, in the emotion map 400, multiple emotions are mapped based on the structure by which emotions are generated, and emotions that tend to occur simultaneously are mapped close to each other.
[0154] These emotions are distributed in the 3 o'clock direction on emotion map 400, and typically fluctuate between relief and anxiety. In the right half of emotion map 400, situational awareness dominates over internal sensations, resulting in a sense of calm.
[0155] The inside of emotion map 400 represents what is going on in the mind, and the outside of emotion map 400 represents behavior, so the further you go outside emotion map 400, the more visible the emotions become (the more they are expressed in behavior).
[0156] Human emotions are based on various balances, such as posture and blood sugar levels. When these balances deviate from the ideal, a state of discomfort is expressed, and when they approach the ideal, a state of pleasure is expressed. Emotions can also be created for robots, cars, and motorcycles, based on various balances, such as posture and remaining battery life. When these balances deviate from the ideal, a state of discomfort is expressed, and when they approach the ideal, a state of pleasure is expressed. An emotion map can be generated, for example, based on Dr. Mitsuyoshi's emotion map (Research on speech emotion recognition and brain physiological signal analysis systems for emotions, Tokushima University, doctoral dissertation: https: / / ci.nii.ac.jp / naid / 500000375379). The left half of the emotion map lists emotions belonging to the area called "reaction," where sensation is dominant. The right half of the emotion map lists emotions belonging to the area called "situation," where situational awareness is dominant.
[0157] The emotion map defines two emotions that promote learning. One is a negative emotion on the situation side, around the middle of "repentance" or "reflection." In other words, this occurs when the robot experiences negative emotions such as "I never want to feel this way again" or "I don't want to be scolded again." The other is a positive emotion on the response side, around "desire." In other words, this occurs when the robot experiences positive feelings such as "I want more" or "I want to know more."
[0158] The emotion identification model 59 inputs user input into a pre-trained neural network, obtains emotion values indicating each emotion shown in the emotion map 400, and determines the user's emotion. This neural network is pre-trained based on multiple pieces of training data that are combinations of user input and emotion values indicating each emotion shown in the emotion map 400. Furthermore, this neural network is trained so that emotions that are located close to each other have similar values, as in the emotion map 900 shown in FIG. 10. FIG. 10 shows an example in which multiple emotions, "relieved," "calm," and "reassuring," have similar emotion values.
[0159] In the above embodiment, an example was given in which a specific process is performed by one computer 22, but the technology disclosed herein is not limited to this, and distributed processing of the specific process may be performed by multiple computers including computer 22.
[0160] In the above embodiment, an example in which the specific processing program 56 is stored in the storage 32 has been described, but the technology of the present disclosure is not limited to this. For example, the specific processing program 56 may be stored in a portable, computer-readable, non-transitory storage medium such as a USB (Universal Serial Bus) memory. The specific processing program 56 stored in the non-transitory storage medium is installed in the computer 22 of the data processing device 12. The processor 28 executes the specific processing in accordance with the specific processing program 56.
[0161] Alternatively, the specific processing program 56 may be stored in a storage device such as a server connected to the data processing device 12 via the network 54, and the specific processing program 56 may be downloaded and installed on the computer 22 in response to a request from the data processing device 12.
[0162] It is not necessary to store all of the specific processing program 56 in a storage device such as a server connected to the data processing device 12 via the network 54, or to store all of the specific processing program 56 in the storage 32; only a portion of the specific processing program 56 may be stored.
[0163] The hardware resource for executing a specific process can be any of the following processors: A CPU is a general-purpose processor that functions as a hardware resource for executing a specific process by executing software, i.e., a program. A dedicated electrical circuit, such as a field-programmable gate array (FPGA), a programmable logic device (PLD), or an application-specific integrated circuit (ASIC), is a processor with a circuit configuration specifically designed to execute a specific process. Each processor has built-in or connected memory, and uses the memory to execute the specific process.
[0164] The hardware resource that executes the specific process may be configured with one of these various processors, or may be configured with a combination of two or more processors of the same or different types (for example, a combination of multiple FPGAs, or a combination of a CPU and an FPGA). Also, the hardware resource that executes the specific process may be a single processor.
[0165] As an example of a system configured with a single processor, first, one processor is configured by combining one or more CPUs and software, and this processor functions as a hardware resource that executes a specific process. Second, there is a system that uses a processor that realizes the functions of an entire system including multiple hardware resources that execute a specific process on a single IC chip, as typified by SoC (System-on-a-chip). In this way, a specific process is realized using one or more of the above-mentioned various processors as hardware resources.
[0166] Furthermore, the hardware structure of these various processors can be, more specifically, an electric circuit that combines circuit elements such as semiconductor devices. The specific processing described above is merely an example. Therefore, it goes without saying that unnecessary steps may be deleted, new steps may be added, or the processing order may be rearranged, without departing from the spirit of the invention.
[0167] In the above example, the first to fourth embodiments have been described separately, but some or all of these embodiments may be combined. The smart device 14, smart glasses 214, headset terminal 314, and robot 414 are merely examples, and they may be combined, or other devices may be used. In the above example, the first and second embodiments have been described separately, but they may be combined.
[0168] The above-described description and illustrations are a detailed explanation of the parts related to the technology of the present disclosure and are merely an example of the technology of the present disclosure. For example, the above description of the configuration, functions, actions, and effects is an explanation of an example of the configuration, functions, actions, and effects of the parts related to the technology of the present disclosure. Therefore, it goes without saying that unnecessary parts may be deleted, new elements may be added, or replacements may be made to the above-described description and illustrations within the scope of the gist of the technology of the present disclosure. Furthermore, to avoid confusion and facilitate understanding of the parts related to the technology of the present disclosure, the above-described description and illustrations omit explanations of common technical knowledge that do not require particular explanation to enable the implementation of the technology of the present disclosure.
[0169] All publications, patent applications, and technical standards mentioned in this specification are herein incorporated by reference to the same extent as if each individual publication, patent application, or technical standard was specifically and individually indicated to be incorporated by reference. [Explanation of symbols]
[0170] 10, 210, 310, 410 Data Processing Systems 12 Data Processing Device 14 Smart Devices 214 Smart Glasses 314 Headset-type terminal 414 Robot
Claims
1. A real-time analysis section that uses generative AI to analyze server behavior in real time, a suspicious activity detection unit that detects suspicious activity from the data analyzed by the real-time analysis unit; a threat countermeasure unit that identifies and counters threats based on the suspicious activity detected by the suspicious activity detection unit; a report generation unit that generates a security report based on information about threats dealt with by the threat dealt with unit; an automatic learning unit that automatically learns based on the report generated by the report generating unit and improves security measures; A system characterized by:
2. The suspicious activity detection unit When detecting the suspicious activity, it learns past attack patterns and can respond to unknown attack methods. The system of claim 1 .
3. The threat countermeasure unit When identifying the threat, predict the attacker's behavioral patterns and prevent the next attack. The system of claim 1 .
4. The report generation unit When generating the security report, comparative analysis is performed with past reports to clearly indicate changes in the security situation. The system of claim 1 .
5. The automatic learning unit When performing automatic learning, it will collaborate with other AI systems and share learning data with each other. The system of claim 1 .
6. The real-time analysis unit Using emotion estimation, the system monitors the emotional state of server administrators in real time and issues alerts when stress or fatigue increases. The system of claim 1 .
7. The suspicious activity detection unit Using emotion estimation, the system analyzes the emotional state of server administrators and performs additional security checks if the administrator feels uneasy. The system of claim 1 .
8. The threat countermeasure unit Using emotion estimation function, we analyze the emotional state of server users and suggest ways to deal with anxiety when users feel anxious. The system of claim 1 .
Citation Information
Patent Citations
Persona chatbot control method and system
JP2022180282A