System

The system addresses the challenge of identifying and remediating server vulnerabilities by using a scanning, analyzing, and learning unit with generative AI to provide real-time, customized remediation measures, enhancing security efficiency.

JP2026018850APending Publication Date: 2026-02-05SOFTBANK GROUP CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024120178
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-07-25
Publication Date
2026-02-05

AI Technical Summary

Technical Problem

Conventional technologies face challenges in quickly and accurately identifying server vulnerabilities and proposing optimal remediation measures.

Method used

A system utilizing a scanning unit, analyzing unit, and learning unit to automatically scan, analyze, and propose remediation measures for server vulnerabilities, with a notification unit to inform administrators, leveraging generative AI for real-time updates and customization.

Benefits of technology

The system efficiently identifies and addresses server vulnerabilities by providing real-time, customized remediation measures, reducing administrative workload and enhancing overall security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026018850000001_ABST
    Figure 2026018850000001_ABST
Patent Text Reader

Abstract

An object of a system according to an embodiment is to quickly and accurately identify vulnerability of a server and propose an optimal repair measure.SOLUTION: A system includes a scan unit, an analysis unit, a learning unit, and a notification unit. The scanning unit scans vulnerability of a server. The analysis unit analyzes the scan result acquired by the scan unit. The learning unit proposes an optimal repair measure for the vulnerability specified by the analysis unit. The notification unit notifies a diagnosis result based on the new vulnerability information learned by the learning unit.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The technology of the present disclosure relates to a system. [Background technology]

[0002] Patent document 1 discloses a persona chatbot control method performed by at least one processor, the method including the steps of receiving a user utterance, adding the user utterance to a prompt including an instruction sentence related to a description of the chatbot character, encoding the prompt, and inputting the encoded prompt into a language model to generate a chatbot utterance in response to the user utterance. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Publication No. 2022-180282 Summary of the Invention [Problem to be solved by the invention]

[0004] Conventional technologies have faced the challenge of making it difficult to quickly and accurately identify server vulnerabilities and propose optimal remediation measures.

[0005] The system according to the embodiment aims to quickly and accurately identify server vulnerabilities and propose optimal remediation measures. [Means for solving the problem]

[0006] The system according to the embodiment includes a scanning unit, an analyzing unit, a learning unit, and a notifying unit. The scanning unit scans a server for vulnerabilities. The analyzing unit analyzes the scan results obtained by the scanning unit. The learning unit proposes optimal repair measures for vulnerabilities identified by the analyzing unit. The notifying unit notifies the diagnosis results based on new vulnerability information learned by the learning unit. [Effects of the Invention]

[0007] The system according to the embodiment can quickly and accurately identify server vulnerabilities and propose optimal remediation measures. [Brief explanation of the drawings]

[0008] [Figure 1] 1 is a conceptual diagram showing an example of the configuration of a data processing system according to a first embodiment. [Figure 2] 1 is a conceptual diagram showing an example of main functions of a data processing device and a smart device according to a first embodiment. [Figure 3] FIG. 10 is a conceptual diagram showing an example of the configuration of a data processing system according to a second embodiment. [Figure 4] FIG. 10 is a conceptual diagram showing an example of main functions of a data processing device and smart glasses according to a second embodiment. [Figure 5] FIG. 10 is a conceptual diagram showing an example of the configuration of a data processing system according to a third embodiment. [Figure 6] FIG. 11 is a conceptual diagram showing an example of main functions of a data processing device and a headset-type terminal according to a third embodiment. [Figure 7] FIG. 10 is a conceptual diagram showing an example of the configuration of a data processing system according to a fourth embodiment. [Figure 8] FIG. 10 is a conceptual diagram showing an example of main functions of a data processing device and a robot according to a fourth embodiment. [Figure 9] 1 shows an emotion map onto which multiple emotions are mapped. [Figure 10] 1 shows an emotion map onto which multiple emotions are mapped. DETAILED DESCRIPTION OF THE INVENTION

[0009] An example of an embodiment of a system according to the technology of the present disclosure will be described below with reference to the accompanying drawings.

[0010] First, the terms used in the following description will be explained.

[0011] In the following embodiments, a coded processor (hereinafter simply referred to as a "processor") may be a single arithmetic device or a combination of multiple arithmetic devices. Furthermore, the processor may be a single type of arithmetic device or a combination of multiple types of arithmetic devices. Examples of arithmetic devices include a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), a GPGPU (General-Purpose computing on Graphics Processing Units), an APU (Accelerated Processing Unit), or a TPU (Tensor Processing Unit).

[0012] In the following embodiments, a coded RAM (Random Access Memory) is a memory in which information is temporarily stored and is used as a working memory by a processor.

[0013] In the following embodiments, the coded storage is one or more nonvolatile storage devices that store various programs, various parameters, etc. Examples of nonvolatile storage devices include flash memory (SSD (Solid State Drive)), magnetic disks (e.g., hard disks), and magnetic tapes.

[0014] In the following embodiments, a communication I / F (Interface) with a symbol is an interface including a communication processor, an antenna, etc. The communication I / F controls communication between multiple computers. Examples of communication standards applied to the communication I / F include wireless communication standards including 5G (5th Generation Mobile Communication System), Wi-Fi (registered trademark), and Bluetooth (registered trademark).

[0015] In the following embodiments, "A and / or B" is synonymous with "at least one of A and B." In other words, "A and / or B" means that it may be only A, only B, or a combination of A and B. Furthermore, in this specification, the same concept as "A and / or B" is also applied when three or more things are expressed connected by "and / or."

[0016] [First embodiment] FIG. 1 shows an example of the configuration of a data processing system 10 according to the first embodiment.

[0017] 1, a data processing system 10 includes a data processing device 12 and a smart device 14. An example of the data processing device 12 is a server.

[0018] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[0019] The smart device 14 includes a computer 36, a reception device 38, an output device 40, a camera 42, and a communication I / F 44. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The reception device 38, the output device 40, and the camera 42 are also connected to the bus 52.

[0020] The reception device 38 includes a touch panel 38A and a microphone 38B, and receives user input. The touch panel 38A detects contact with a pointer (for example, a pen or a finger) to receive user input by the touch of the pointer. The microphone 38B detects the user's voice to receive user input by voice. The control unit 46A transmits data indicating the user input received by the touch panel 38A and the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 (see FIG. 2) acquires the data indicating the user input.

[0021] Output device 40 includes a display 40A and a speaker 40B, and presents data to a user by outputting the data in a form of expression that the user can perceive (e.g., audio and / or text). Display 40A displays visible information such as text and images in accordance with instructions from processor 46. Speaker 40B outputs audio in accordance with instructions from processor 46. Camera 42 is a compact digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor.

[0022] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 control the exchange of various information between the processor 46 and the processor 28 via the network 54.

[0023] FIG. 2 shows an example of the main functions of the data processing device 12 and the smart device 14.

[0024] 2, in the data processing device 12, a specific process is performed by the processor 28. A specific processing program 56 is stored in the storage 32. The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific process is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[0025] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290. The identification processing unit 290 can estimate the user's emotion using the emotion identification model 59 and perform identification processing using the user's emotion.

[0026] In the smart device 14, the specific processing is performed by the processor 46. The storage 50 stores a specific processing program 60. The specific processing program 60 is used together with the specific processing program 56 by the data processing system 10. The processor 46 reads the specific processing program 60 from the storage 50 and executes the read specific processing program 60 on the RAM 48. The specific processing is realized by the processor 46 operating as the control unit 46A in accordance with the specific processing program 60 executed on the RAM 48. Note that the smart device 14 may have a data generation model and an emotion identification model similar to the data generation model 58 and the emotion identification model 59.

[0027] Note that a device other than the data processing device 12 may have the data generation model 58. For example, a server device (e.g., a generation server) may have the data generation model 58. In this case, the data processing device 12 obtains a processing result (prediction result, etc.) using the data generation model 58 by communicating with the server device having the data generation model 58. Furthermore, the data processing device 12 may be a server device, or may be a terminal device owned by a user (e.g., a mobile phone, a robot, a home appliance, etc.). Next, an example of processing by the data processing system 10 according to the first embodiment will be described.

[0028] (Example 1) A security solution system according to an embodiment of the present invention is a system that automatically scans and repairs server vulnerabilities using generative AI, thereby enabling the security solution system to efficiently identify server vulnerabilities, propose repair measures, and quickly address them.

[0029] A security solution system according to an embodiment includes a scanning unit, an analysis unit, a learning unit, and a notification unit. The scanning unit scans a server for vulnerabilities. For example, the scanning unit analyzes the server's log files and configuration files to detect known and potential vulnerabilities. The scanning unit can also periodically scan the entire server to keep its security status up to date. The analysis unit analyzes the scan results obtained by the scanning unit. For example, the analysis unit can propose optimal remediation measures for vulnerabilities identified based on the scan results. The analysis unit can also propose patch application or configuration changes for specific vulnerabilities. When new vulnerabilities are disclosed, the learning unit incorporates the information and reflects it in scans and proposed remediation measures. For example, the learning unit collects new vulnerability information in real time, and the generation AI instantly learns and updates countermeasures. The notification unit notifies the administrator of the diagnosis results based on the new vulnerability information learned by the learning unit. For example, the notification unit notifies the administrator in the form of, "A vulnerability has been found on the server. Please perform the following steps as a remediation measure." As a result, the security solution system according to the embodiment can efficiently maintain security by automatically scanning servers for vulnerabilities, proposing remediation measures, and notifying users of the results of the diagnosis. For example, administrators can grasp the vulnerability status in real time and take appropriate measures.

[0030] The scanning unit can analyze log files and configuration files to detect known and potential vulnerabilities. For example, the scanning unit analyzes log files to detect vulnerabilities from access logs and error logs. The scanning unit also analyzes configuration files to detect server configuration errors and security holes. For example, the scanning unit analyzes server configuration files to detect security configuration deficiencies. The scanning unit also analyzes log files and configuration files in combination to provide more detailed vulnerability information. This makes it possible to detect known and potential vulnerabilities by analyzing server log files and configuration files.

[0031] The analysis unit can propose applying a patch or changing settings for a specific vulnerability. For example, the analysis unit proposes applying a patch for a specific vulnerability. For example, the analysis unit proposes applying a security patch for a specific vulnerability. The analysis unit can also propose changing settings for a specific vulnerability. For example, the analysis unit proposes strengthening security settings for a specific vulnerability. The analysis unit can also propose updating software for a specific vulnerability. For example, the analysis unit proposes updating to the latest software version for a specific vulnerability. This makes it possible to propose appropriate repair measures for a specific vulnerability.

[0032] When a new vulnerability is made public, the learning unit can incorporate that information and reflect it in its scan and remediation proposals. For example, when a new vulnerability is made public, the learning unit can incorporate that information and reflect it in its scan and remediation proposals. For example, the learning unit collects new vulnerability information from security forums and vulnerability databases, and the generation AI immediately learns and updates countermeasures. The learning unit can also have the generation AI automatically propose preventative security measures based on new vulnerability information. For example, the learning unit can propose pre-emptive changes to settings that are prone to vulnerabilities based on new vulnerability information. This allows for rapid response to new vulnerabilities.

[0033] The notification unit can notify the administrator in the form of, for example, "A vulnerability has been found on the server. Please perform the following steps as a remediation measure." The notification unit can, for example, notify the administrator in the form of, "A vulnerability has been found on the server. Please perform the following steps as a remediation measure." For example, the notification unit can send a notification to the administrator that includes detailed information about the vulnerability and recommended remediation measures. The notification unit can also customize the content of notifications to provide information according to the administrator's role and skill level. For example, the notification unit can provide detailed technical information to system administrators and an overview to management. This allows for appropriate notification to administrators and promotes rapid response.

[0034] The scanning unit can dynamically adjust the depth and scope of the scan depending on the type of vulnerability detected during the scan. For example, the scanning unit dynamically adjusts the depth of the scan depending on the type of vulnerability detected during the scan. For example, if a serious vulnerability is detected, the scanning depth is increased and a more detailed analysis is performed. The scanning unit also dynamically adjusts the scope of the scan depending on the type of vulnerability detected during the scan. For example, if a specific vulnerability is detected, the entire system related to that vulnerability is scanned. This makes it possible to dynamically adjust the depth and scope of the scan depending on the type of vulnerability detected during the scan.

[0035] The scanning unit automatically optimizes the server configuration and settings based on the scan results, making it possible to prevent future vulnerabilities from occurring. The scanning unit automatically optimizes the server configuration based on the scan results, for example, by stopping unnecessary services and strengthening security settings. The scanning unit also automatically optimizes the server settings based on the scan results, for example, by strengthening security settings and optimizing network settings. In this way, the server configuration and settings can be automatically optimized based on the scan results, making it possible to prevent future vulnerabilities from occurring.

[0036] The scanning unit can expand the scan target beyond servers to include entire networks and cloud infrastructure, thereby achieving comprehensive security scanning. For example, the scanning unit can scan the entire network, not just servers. For example, network devices such as routers and switches can also be included. The scanning unit can also expand the scan target to cloud infrastructure. For example, cloud service provider infrastructure and virtual machines on the cloud can also be included as scan targets. This allows the scan target to be expanded beyond servers to include entire networks and cloud infrastructure, thereby achieving comprehensive security scanning.

[0037] The scanning unit can link the scan results with other security tools to perform integrated security management. The scanning unit, for example, links the scan results with other security tools. For example, it can link with a firewall or IDS / IPS to automatically repair vulnerabilities. The scanning unit can also link the scan results with other security tools to build a system for integrated security management. For example, it can integrate the scan results with a security information and event management (SIEM) system to perform overall security management. This allows the scan results to be linked with other security tools to perform integrated security management.

[0038] The analysis unit can select the optimal repair measure for the proposed repair based on past repair history and success rate. For example, the analysis unit refers to past repair history to select the optimal repair measure for the proposed repair measure. For example, the analysis unit preferentially proposes repair measures that have been successful in the past for similar vulnerabilities. The analysis unit can also select the optimal repair measure for the proposed repair measure based on the success rate. For example, the analysis unit evaluates the success rate of repair work and proposes the repair measure with the highest success rate. This allows the optimal repair measure to be selected for the proposed repair measure based on past repair history and success rate.

[0039] The analysis unit can perform a simulation of the proposed repair measure to evaluate the effectiveness of the proposed repair measure in advance. The analysis unit, for example, performs a simulation of the proposed repair measure to evaluate the effectiveness in advance. For example, it simulates the operation of the system when the repair measure is applied. The analysis unit can also modify the proposed repair measure based on the simulation results. For example, it optimizes the effectiveness of the repair measure based on the simulation results. In this way, the proposed repair measure can be simulated to evaluate the effectiveness in advance.

[0040] The analysis unit can provide the proposed repair measures as generic repair measures that can be applied to other servers and systems. For example, the analysis unit can provide the proposed repair measures as generic repair measures that can be applied to other servers and systems. For example, the analysis unit can propose repair measures that are compatible with different operating systems or platforms. The analysis unit can also provide the proposed repair measures in a format that can be applied to other servers and systems. For example, the analysis unit can provide the repair measures as scripts or templates. This allows the proposed repair measures to be provided as generic repair measures that can be applied to other servers and systems.

[0041] The analysis unit can add a function to automatically execute the proposed repair measures, thereby reducing the workload of the administrator. The analysis unit, for example, adds a function to automatically execute the proposed repair measures. For example, automatically applying patches or changing settings. The analysis unit can also reduce the workload of the administrator by automatically executing the proposed repair measures. For example, automating repair work reduces the workload of the administrator. This allows the proposed repair measures to be executed automatically, thereby reducing the workload of the administrator.

[0042] The learning unit collects new vulnerability information in real time, allowing the generation AI to instantly learn and update countermeasures. The learning unit, for example, collects new vulnerability information in real time, allowing the generation AI to instantly learn and update countermeasures. For example, it obtains the latest information from security forums and vulnerability databases. The learning unit can also allow the generation AI to automatically suggest preventive security measures based on new vulnerability information. For example, it can suggest changing settings that are prone to vulnerabilities in advance. This allows new vulnerability information to be collected in real time, allowing the generation AI to instantly learn and update countermeasures.

[0043] The learning unit allows the generation AI to automatically propose preventative security measures based on the vulnerability information it has learned. The learning unit, for example, allows the generation AI to automatically propose preventative security measures based on the vulnerability information it has learned. For example, it may suggest changing settings that are prone to vulnerabilities in advance. The learning unit also allows the generation AI to automatically update security policies based on the vulnerability information it has learned. For example, it may add policies to address new vulnerabilities. This allows the generation AI to automatically propose preventative security measures based on the vulnerability information it has learned.

[0044] The learning unit can share new vulnerability information with other security systems to improve the overall security level. The learning unit, for example, shares new vulnerability information with other security systems. For example, it can send the vulnerability information to a firewall or IDS / IPS to improve the overall security level. The learning unit can also work with other security systems to take countermeasures based on the new vulnerability information. For example, it can integrate the vulnerability information into a security information and event management (SIEM) system to perform overall security management. This allows the new vulnerability information to be shared with other security systems to improve the overall security level.

[0045] The learning unit allows the generation AI to automatically update the security policy based on the vulnerability information it has learned. The learning unit, for example, allows the generation AI to automatically update the security policy based on the vulnerability information it has learned. For example, it adds a policy to deal with new vulnerabilities. The learning unit also allows the generation AI to automatically optimize the security policy based on the vulnerability information it has learned. For example, it strengthens the security policy settings and prevents vulnerabilities from occurring. This allows the generation AI to automatically update the security policy based on the vulnerability information it has learned.

[0046] When notifying the diagnostic results, the generation AI can provide detailed explanations and background information, deepening the administrator's understanding. When notifying the diagnostic results, the generation AI can provide detailed explanations. For example, it can specifically explain the cause of the vulnerability and the scope of its impact. In addition, when notifying the diagnostic results, the generation AI can also provide background information. For example, it can provide the cause of the vulnerability and past examples. In this way, when notifying the diagnostic results, the generation AI can provide detailed explanations and background information, deepening the administrator's understanding.

[0047] The notification unit can customize the notification content and provide information according to the role and skill level of the administrator. The notification unit, for example, customizes the notification content and provides information according to the role of the administrator. For example, detailed technical information is provided to a system administrator, and an overview is provided to a manager. The notification unit can also customize the notification content and provide information according to the skill level of the administrator. For example, basic information is provided to beginners, and detailed technical information is provided to advanced users. In this way, the notification content can be customized and information according to the role and skill level of the administrator can be provided.

[0048] The notification unit can link the notification of the diagnosis result with other communication tools to promote a prompt response. The notification unit, for example, links the notification of the diagnosis result with email. For example, the diagnosis result can be sent to an administrator by email to promote a prompt response. The notification unit can also link the notification of the diagnosis result with SMS. For example, the diagnosis result can be sent to an administrator by SMS to promote a prompt response. In this way, the notification of the diagnosis result can be linked with other communication tools to promote a prompt response.

[0049] The notification unit can add a function for sharing the notification content with other administrators or team members and working together to take measures. The notification unit adds, for example, a function for sharing the notification content with other administrators or team members. For example, a dedicated portal for sharing diagnostic results is provided. The notification unit can also provide a chat function for sharing the notification content with other administrators or team members and working together to take measures. For example, a chat room is provided for discussing measures in real time based on the diagnostic results. This allows the addition of a function for sharing the notification content with other administrators or team members and working together to take measures.

[0050] The system according to the embodiment is not limited to the above-described example, and various modifications are possible, for example, as follows.

[0051] The security solution system further includes a prediction unit. The prediction unit can predict vulnerabilities that may occur in the future based on past vulnerability data and the current system state. For example, the prediction unit can analyze past vulnerability data and find specific patterns. The prediction unit can also monitor the current system state and detect abnormal behavior or configuration changes. Furthermore, the prediction unit can also propose preventive measures for vulnerabilities that may occur in the future. This allows the security solution system to predict future vulnerabilities and take measures in advance.

[0052] The security solution system further includes a reporting unit. The reporting unit can periodically generate reports based on scan results and analysis results and provide them to the administrator. For example, the reporting unit can generate a report summarizing weekly scan results. The reporting unit can also report the status of vulnerability repairs and unresolved vulnerabilities based on the analysis results. Furthermore, the reporting unit can compare reports with past reports to evaluate the status of security improvements. This allows the administrator to periodically understand the security status of the system and take appropriate measures.

[0053] The security solution system further includes an education department. The education department can provide security-related educational content to administrators and users. For example, the education department can provide online courses on types of vulnerabilities and countermeasures. The education department can also regularly hold security-related webinars to share the latest vulnerability information and countermeasures. The education department can also provide quizzes and simulations to raise administrators' and users' security awareness. This allows administrators and users to deepen their security knowledge and take more effective countermeasures.

[0054] The security solution system further includes a backup unit. The backup unit can periodically create backups of the system, enabling rapid recovery if a vulnerability is discovered. For example, the backup unit can create a backup of the entire system every day. The backup unit can also periodically back up important data and configuration files. Furthermore, the backup unit can store the backup data in a safe location and quickly restore it as needed. This allows the system to be quickly restored and damage minimized even if a vulnerability is discovered.

[0055] The security solution system further includes a monitoring unit. The monitoring unit monitors the system in real time and can detect abnormal behavior or unauthorized access. For example, the monitoring unit monitors network traffic and detects abnormal patterns. The monitoring unit can also analyze system logs and detect signs of unauthorized access. Furthermore, the monitoring unit can send an alert to an administrator when an abnormality is detected, urging them to take a prompt response. This allows for real-time monitoring of the system, rapid detection of abnormal behavior or unauthorized access, and the implementation of countermeasures.

[0056] The processing flow of the first embodiment will be briefly explained below.

[0057] Step 1: The scanning unit scans the server for vulnerabilities. For example, the scanning unit analyzes the server's log files and configuration files to detect known and potential vulnerabilities. The scanning unit can also periodically scan the entire server to keep its security status up to date. Step 2: The analysis unit analyzes the scan results obtained by the scanning unit. For example, the analysis unit can propose optimal remediation measures for vulnerabilities identified based on the scan results. The analysis unit can also suggest patch application or configuration changes for specific vulnerabilities. Step 3: When new vulnerabilities are disclosed, the learning unit incorporates that information and reflects it in scans and remediation proposals. For example, the learning unit collects new vulnerability information in real time, and the generating AI immediately learns and updates countermeasures. Step 4: The notification unit notifies the administrator of the diagnosis results based on the new vulnerability information learned by the learning unit. For example, the notification unit may notify the administrator in the form of, "A vulnerability has been found on the server. Please perform the following steps as a remediation measure."

[0058] (Example 2) A security solution system according to an embodiment of the present invention is a system that automatically scans and repairs server vulnerabilities using generative AI, thereby enabling the security solution system to efficiently identify server vulnerabilities, propose repair measures, and quickly address them.

[0059] A security solution system according to an embodiment includes a scanning unit, an analysis unit, a learning unit, and a notification unit. The scanning unit scans a server for vulnerabilities. For example, the scanning unit analyzes the server's log files and configuration files to detect known and potential vulnerabilities. The scanning unit can also periodically scan the entire server to keep its security status up to date. The analysis unit analyzes the scan results obtained by the scanning unit. For example, the analysis unit can propose optimal remediation measures for vulnerabilities identified based on the scan results. The analysis unit can also propose patch application or configuration changes for specific vulnerabilities. When new vulnerabilities are disclosed, the learning unit incorporates the information and reflects it in scans and proposed remediation measures. For example, the learning unit collects new vulnerability information in real time, and the generation AI instantly learns and updates countermeasures. The notification unit notifies the administrator of the diagnosis results based on the new vulnerability information learned by the learning unit. For example, the notification unit notifies the administrator in the form of, "A vulnerability has been found on the server. Please perform the following steps as a remediation measure." As a result, the security solution system according to the embodiment can efficiently maintain security by automatically scanning servers for vulnerabilities, proposing remediation measures, and notifying users of the results of the diagnosis. For example, administrators can grasp the vulnerability status in real time and take appropriate measures.

[0060] The scanning unit can analyze log files and configuration files to detect known and potential vulnerabilities. For example, the scanning unit analyzes log files to detect vulnerabilities from access logs and error logs. The scanning unit also analyzes configuration files to detect server configuration errors and security holes. For example, the scanning unit analyzes server configuration files to detect security configuration deficiencies. The scanning unit also analyzes log files and configuration files in combination to provide more detailed vulnerability information. This makes it possible to detect known and potential vulnerabilities by analyzing server log files and configuration files.

[0061] The analysis unit can propose applying a patch or changing settings for a specific vulnerability. For example, the analysis unit proposes applying a patch for a specific vulnerability. For example, the analysis unit proposes applying a security patch for a specific vulnerability. The analysis unit can also propose changing settings for a specific vulnerability. For example, the analysis unit proposes strengthening security settings for a specific vulnerability. The analysis unit can also propose updating software for a specific vulnerability. For example, the analysis unit proposes updating to the latest software version for a specific vulnerability. This makes it possible to propose appropriate repair measures for a specific vulnerability.

[0062] When a new vulnerability is made public, the learning unit can incorporate that information and reflect it in its scan and remediation proposals. For example, when a new vulnerability is made public, the learning unit can incorporate that information and reflect it in its scan and remediation proposals. For example, the learning unit collects new vulnerability information from security forums and vulnerability databases, and the generation AI immediately learns and updates countermeasures. The learning unit can also have the generation AI automatically propose preventative security measures based on new vulnerability information. For example, the learning unit can propose pre-emptive changes to settings that are prone to vulnerabilities based on new vulnerability information. This allows for rapid response to new vulnerabilities.

[0063] The notification unit can notify the administrator in the form of, for example, "A vulnerability has been found on the server. Please perform the following steps as a remediation measure." The notification unit can, for example, notify the administrator in the form of, "A vulnerability has been found on the server. Please perform the following steps as a remediation measure." For example, the notification unit can send a notification to the administrator that includes detailed information about the vulnerability and recommended remediation measures. The notification unit can also customize the content of notifications to provide information according to the administrator's role and skill level. For example, the notification unit can provide detailed technical information to system administrators and an overview to management. This allows for appropriate notification to administrators and promotes rapid response.

[0064] The scanning unit can dynamically adjust the depth and scope of the scan depending on the type of vulnerability detected during the scan. For example, the scanning unit dynamically adjusts the depth of the scan depending on the type of vulnerability detected during the scan. For example, if a serious vulnerability is detected, the scanning depth is increased and a more detailed analysis is performed. The scanning unit also dynamically adjusts the scope of the scan depending on the type of vulnerability detected during the scan. For example, if a specific vulnerability is detected, the entire system related to that vulnerability is scanned. This makes it possible to dynamically adjust the depth and scope of the scan depending on the type of vulnerability detected during the scan.

[0065] The scanning unit automatically optimizes the server configuration and settings based on the scan results, making it possible to prevent future vulnerabilities from occurring. The scanning unit automatically optimizes the server configuration based on the scan results, for example, by stopping unnecessary services and strengthening security settings. The scanning unit also automatically optimizes the server settings based on the scan results, for example, by strengthening security settings and optimizing network settings. In this way, the server configuration and settings can be automatically optimized based on the scan results, making it possible to prevent future vulnerabilities from occurring.

[0066] The scanning unit can use the emotion estimation function to analyze the manager's emotions regarding the scan results and provide an interface for reducing stress. The scanning unit, for example, uses the emotion estimation function to analyze the manager's emotions regarding the scan results in real time. For example, if the manager is feeling stressed, it provides an interface that helps the manager relax. The scanning unit can also use the emotion estimation function to analyze the manager's emotions regarding the scan results and provide support for reducing stress. For example, if the manager is feeling anxious, it provides information that gives the manager a sense of security. In this way, it is possible to analyze the manager's emotions regarding the scan results and provide an interface for reducing stress.

[0067] The scanning unit can expand the scan target beyond servers to include entire networks and cloud infrastructure, thereby achieving comprehensive security scanning. For example, the scanning unit can scan the entire network, not just servers. For example, network devices such as routers and switches can also be included. The scanning unit can also expand the scan target to cloud infrastructure. For example, cloud service provider infrastructure and virtual machines on the cloud can also be included as scan targets. This allows the scan target to be expanded beyond servers to include entire networks and cloud infrastructure, thereby achieving comprehensive security scanning.

[0068] The scanning unit can link the scan results with other security tools to perform integrated security management. The scanning unit, for example, links the scan results with other security tools. For example, it can link with a firewall or IDS / IPS to automatically repair vulnerabilities. The scanning unit can also link the scan results with other security tools to build a system for integrated security management. For example, it can integrate the scan results with a security information and event management (SIEM) system to perform overall security management. This allows the scan results to be linked with other security tools to perform integrated security management.

[0069] The scanning unit can use the emotion estimation function to monitor the user's emotions regarding the scan results in real time and promote positive feedback. The scanning unit, for example, uses the emotion estimation function to monitor the user's emotions regarding the scan results in real time. For example, if the user is feeling anxious, a message that provides reassurance can be displayed. The scanning unit can also use the emotion estimation function to analyze the user's emotions regarding the scan results and provide positive feedback. For example, if the user has positive emotions, feedback that reinforces those emotions can be provided. In this way, the user's emotions regarding the scan results can be monitored in real time and positive feedback can be promoted.

[0070] The analysis unit can select the optimal repair measure for the proposed repair based on past repair history and success rate. For example, the analysis unit refers to past repair history to select the optimal repair measure for the proposed repair measure. For example, the analysis unit preferentially proposes repair measures that have been successful in the past for similar vulnerabilities. The analysis unit can also select the optimal repair measure for the proposed repair measure based on the success rate. For example, the analysis unit evaluates the success rate of repair work and proposes the repair measure with the highest success rate. This allows the optimal repair measure to be selected for the proposed repair measure based on past repair history and success rate.

[0071] The analysis unit can perform a simulation of the proposed repair measure to evaluate the effectiveness of the proposed repair measure in advance. The analysis unit, for example, performs a simulation of the proposed repair measure to evaluate the effectiveness in advance. For example, it simulates the operation of the system when the repair measure is applied. The analysis unit can also modify the proposed repair measure based on the simulation results. For example, it optimizes the effectiveness of the repair measure based on the simulation results. In this way, the proposed repair measure can be simulated to evaluate the effectiveness in advance.

[0072] The analysis unit can use the emotion estimation function to analyze the administrator's emotions regarding the proposed repair measures and present the most acceptable repair measures. The analysis unit, for example, uses the emotion estimation function to analyze the administrator's emotions regarding the proposed repair measures in real time. For example, if the administrator is feeling anxious, the analysis unit presents a repair measure that gives the administrator a sense of security. The analysis unit can also use the emotion estimation function to analyze the administrator's emotions regarding the proposed repair measures and select the most acceptable repair measure. For example, if the administrator has positive emotions, the analysis unit presents a repair measure that reinforces those emotions. In this way, the analysis unit can analyze the administrator's emotions regarding the proposed repair measures and present the most acceptable repair measure.

[0073] The analysis unit can provide the proposed repair measures as generic repair measures that can be applied to other servers and systems. For example, the analysis unit can provide the proposed repair measures as generic repair measures that can be applied to other servers and systems. For example, the analysis unit can propose repair measures that are compatible with different operating systems or platforms. The analysis unit can also provide the proposed repair measures in a format that can be applied to other servers and systems. For example, the analysis unit can provide the repair measures as scripts or templates. This allows the proposed repair measures to be provided as generic repair measures that can be applied to other servers and systems.

[0074] The analysis unit can add a function to automatically execute the proposed repair measures, thereby reducing the workload of the administrator. The analysis unit, for example, adds a function to automatically execute the proposed repair measures. For example, automatically applying patches or changing settings. The analysis unit can also reduce the workload of the administrator by automatically executing the proposed repair measures. For example, automating repair work reduces the workload of the administrator. This allows the proposed repair measures to be executed automatically, thereby reducing the workload of the administrator.

[0075] The analysis unit can use the emotion estimation function to provide real-time feedback on the user's emotions regarding the proposed repair measures, thereby improving the proposed content. For example, the analysis unit can use the emotion estimation function to provide real-time feedback on the user's emotions regarding the proposed repair measures. For example, if the user feels anxious, the analysis unit can add a detailed explanation of the repair measures. The analysis unit can also use the emotion estimation function to analyze the user's emotions regarding the proposed repair measures and improve the proposed content. For example, if the user has positive emotions, the analysis unit can provide a proposed content that reinforces those emotions. This allows real-time feedback on the user's emotions regarding the proposed repair measures, thereby improving the proposed content.

[0076] The learning unit collects new vulnerability information in real time, allowing the generation AI to instantly learn and update countermeasures. The learning unit, for example, collects new vulnerability information in real time, allowing the generation AI to instantly learn and update countermeasures. For example, it obtains the latest information from security forums and vulnerability databases. The learning unit can also allow the generation AI to automatically suggest preventive security measures based on new vulnerability information. For example, it can suggest changing settings that are prone to vulnerabilities in advance. This allows new vulnerability information to be collected in real time, allowing the generation AI to instantly learn and update countermeasures.

[0077] The learning unit allows the generation AI to automatically propose preventative security measures based on the vulnerability information it has learned. The learning unit, for example, allows the generation AI to automatically propose preventative security measures based on the vulnerability information it has learned. For example, it may suggest changing settings that are prone to vulnerabilities in advance. The learning unit also allows the generation AI to automatically update security policies based on the vulnerability information it has learned. For example, it may add policies to address new vulnerabilities. This allows the generation AI to automatically propose preventative security measures based on the vulnerability information it has learned.

[0078] The learning unit can use the emotion estimation function to analyze the administrator's emotions regarding new vulnerabilities and add information to provide a sense of security. The learning unit, for example, uses the emotion estimation function to analyze the administrator's emotions regarding new vulnerabilities in real time. For example, if the administrator is feeling anxious, the learning unit provides information that provides a sense of security. The learning unit can also use the emotion estimation function to analyze the administrator's emotions regarding new vulnerabilities and add information to provide a sense of security. For example, if the administrator has positive emotions, the learning unit provides information that reinforces those emotions. This makes it possible to analyze the administrator's emotions regarding new vulnerabilities and add information to provide a sense of security.

[0079] The learning unit can share new vulnerability information with other security systems to improve the overall security level. The learning unit, for example, shares new vulnerability information with other security systems. For example, it can send the vulnerability information to a firewall or IDS / IPS to improve the overall security level. The learning unit can also work with other security systems to take countermeasures based on the new vulnerability information. For example, it can integrate the vulnerability information into a security information and event management (SIEM) system to perform overall security management. This allows the new vulnerability information to be shared with other security systems to improve the overall security level.

[0080] The learning unit allows the generation AI to automatically update the security policy based on the vulnerability information it has learned. The learning unit, for example, allows the generation AI to automatically update the security policy based on the vulnerability information it has learned. For example, it adds a policy to deal with new vulnerabilities. The learning unit also allows the generation AI to automatically optimize the security policy based on the vulnerability information it has learned. For example, it strengthens the security policy settings and prevents vulnerabilities from occurring. This allows the generation AI to automatically update the security policy based on the vulnerability information it has learned.

[0081] The learning unit can use the emotion estimation function to monitor user emotions regarding new vulnerabilities in real time and quickly provide appropriate countermeasures. The learning unit, for example, uses the emotion estimation function to monitor user emotions regarding new vulnerabilities in real time. For example, if the user is feeling anxious, the learning unit can provide countermeasures that give the user a sense of security. The learning unit can also use the emotion estimation function to analyze user emotions regarding new vulnerabilities and quickly provide appropriate countermeasures. For example, if the user has positive emotions, the learning unit can provide countermeasures that reinforce those emotions. In this way, the learning unit can monitor user emotions regarding new vulnerabilities in real time and quickly provide appropriate countermeasures.

[0082] When notifying the diagnostic results, the generation AI can provide detailed explanations and background information, deepening the administrator's understanding. When notifying the diagnostic results, the generation AI can provide detailed explanations. For example, it can specifically explain the cause of the vulnerability and the scope of its impact. In addition, when notifying the diagnostic results, the generation AI can also provide background information. For example, it can provide the cause of the vulnerability and past examples. In this way, when notifying the diagnostic results, the generation AI can provide detailed explanations and background information, deepening the administrator's understanding.

[0083] The notification unit can customize the notification content and provide information according to the role and skill level of the administrator. The notification unit, for example, customizes the notification content and provides information according to the role of the administrator. For example, detailed technical information is provided to a system administrator, and an overview is provided to a manager. The notification unit can also customize the notification content and provide information according to the skill level of the administrator. For example, basic information is provided to beginners, and detailed technical information is provided to advanced users. In this way, the notification content can be customized and information according to the role and skill level of the administrator can be provided.

[0084] The notification unit can use the emotion estimation function to analyze the manager's emotion regarding the notification content and provide support to reduce stress. The notification unit, for example, uses the emotion estimation function to analyze the manager's emotion regarding the notification content in real time. For example, if the manager is feeling stressed, support to help the manager relax is provided. The notification unit can also use the emotion estimation function to analyze the manager's emotion regarding the notification content and provide information to reduce stress. For example, if the manager is feeling anxious, information that gives a sense of security is provided. This makes it possible to analyze the manager's emotion regarding the notification content and provide support to reduce stress.

[0085] The notification unit can link the notification of the diagnosis result with other communication tools to promote a prompt response. The notification unit, for example, links the notification of the diagnosis result with email. For example, the diagnosis result can be sent to an administrator by email to promote a prompt response. The notification unit can also link the notification of the diagnosis result with SMS. For example, the diagnosis result can be sent to an administrator by SMS to promote a prompt response. In this way, the notification of the diagnosis result can be linked with other communication tools to promote a prompt response.

[0086] The notification unit can add a function for sharing the notification content with other administrators or team members and working together to take measures. The notification unit adds, for example, a function for sharing the notification content with other administrators or team members. For example, a dedicated portal for sharing diagnostic results is provided. The notification unit can also provide a chat function for sharing the notification content with other administrators or team members and working together to take measures. For example, a chat room is provided for discussing measures in real time based on the diagnostic results. This allows the addition of a function for sharing the notification content with other administrators or team members and working together to take measures.

[0087] The notification unit can use the emotion estimation function to monitor the user's emotion regarding the notification content in real time and provide appropriate feedback. The notification unit, for example, uses the emotion estimation function to monitor the user's emotion regarding the notification content in real time. For example, if the user is feeling anxious, the notification unit can provide feedback that gives a sense of security. The notification unit can also use the emotion estimation function to analyze the user's emotion regarding the notification content and provide appropriate feedback. For example, if the user has positive emotions, the notification unit can provide feedback that reinforces those emotions. In this way, the user's emotion regarding the notification content can be monitored in real time and appropriate feedback can be provided.

[0088] The system according to the embodiment is not limited to the above-described example, and various modifications are possible, for example, as follows.

[0089] The security solution system further includes a prediction unit. The prediction unit can predict vulnerabilities that may occur in the future based on past vulnerability data and the current system state. For example, the prediction unit can analyze past vulnerability data and find specific patterns. The prediction unit can also monitor the current system state and detect abnormal behavior or configuration changes. Furthermore, the prediction unit can also propose preventive measures for vulnerabilities that may occur in the future. This allows the security solution system to predict future vulnerabilities and take measures in advance.

[0090] The security solution system further includes a reporting unit. The reporting unit can periodically generate reports based on scan results and analysis results and provide them to the administrator. For example, the reporting unit can generate a report summarizing weekly scan results. The reporting unit can also report the status of vulnerability repairs and unresolved vulnerabilities based on the analysis results. Furthermore, the reporting unit can compare reports with past reports to evaluate the status of security improvements. This allows the administrator to periodically understand the security status of the system and take appropriate measures.

[0091] The security solution system further includes an education department. The education department can provide security-related educational content to administrators and users. For example, the education department can provide online courses on types of vulnerabilities and countermeasures. The education department can also regularly hold security-related webinars to share the latest vulnerability information and countermeasures. The education department can also provide quizzes and simulations to raise administrators' and users' security awareness. This allows administrators and users to deepen their security knowledge and take more effective countermeasures.

[0092] The security solution system further includes a backup unit. The backup unit can periodically create backups of the system, enabling rapid recovery if a vulnerability is discovered. For example, the backup unit can create a backup of the entire system every day. The backup unit can also periodically back up important data and configuration files. Furthermore, the backup unit can store the backup data in a safe location and quickly restore it as needed. This allows the system to be quickly restored and damage minimized even if a vulnerability is discovered.

[0093] The security solution system further includes a monitoring unit. The monitoring unit monitors the system in real time and can detect abnormal behavior or unauthorized access. For example, the monitoring unit monitors network traffic and detects abnormal patterns. The monitoring unit can also analyze system logs and detect signs of unauthorized access. Furthermore, the monitoring unit can send an alert to an administrator when an abnormality is detected, urging them to take a prompt response. This allows for real-time monitoring of the system, rapid detection of abnormal behavior or unauthorized access, and the implementation of countermeasures.

[0094] The analysis unit can estimate the user's emotions and customize suggested repair measures based on the estimated user emotions. For example, if the user feels anxious, detailed explanations and support can be provided. Also, if the user feels stressed, simple and quick repair measures can be suggested. Furthermore, if the user has positive emotions, feedback can be provided to reinforce those emotions. This allows the system to customize suggested repair measures based on the user's emotions and provide more effective support.

[0095] The notification unit can estimate the user's emotions and customize the notification content based on the estimated user emotions. For example, if the user is feeling anxious, a message that gives a sense of security can be provided. Also, if the user is feeling stressed, information that helps the user relax can be provided. Furthermore, if the user is feeling positive, feedback to reinforce that emotion can be provided. This allows the notification content to be customized based on the user's emotions, enabling more effective communication.

[0096] The learning unit can estimate the user's emotions and customize the learning content based on the estimated user emotions. For example, if the user is feeling anxious, it can provide information that gives a sense of security. Also, if the user is feeling stressed, it can provide learning content that helps the user relax. Furthermore, if the user is feeling positive, it can provide feedback to reinforce those emotions. This allows the learning content to be customized based on the user's emotions, making learning more effective.

[0097] The scanning unit can estimate the user's emotions and customize the display method of the scan results based on the estimated user emotions. For example, if the user is feeling anxious, an interface that gives a sense of security can be provided. Also, if the user is feeling stressed, a display method that helps the user relax can be provided. Furthermore, if the user is feeling positive, feedback can be provided to reinforce that emotion. This allows the display method of the scan results to be customized based on the user's emotions, making it possible to provide information more effectively.

[0098] The analysis unit can estimate the user's emotions and customize the display method of the analysis results based on the estimated user emotions. For example, if the user is feeling anxious, an interface that gives a sense of security can be provided. Also, if the user is feeling stressed, a display method that helps the user relax can be provided. Furthermore, if the user has positive emotions, feedback can be provided to reinforce those emotions. This allows the display method of the analysis results to be customized based on the user's emotions, making it possible to provide information more effectively.

[0099] The processing flow of the second embodiment will be briefly explained below.

[0100] Step 1: The scanning unit scans the server for vulnerabilities. For example, the scanning unit analyzes the server's log files and configuration files to detect known and potential vulnerabilities. The scanning unit can also periodically scan the entire server to keep its security status up to date. Step 2: The analysis unit analyzes the scan results obtained by the scanning unit. For example, the analysis unit can propose optimal remediation measures for vulnerabilities identified based on the scan results. The analysis unit can also suggest patch application or configuration changes for specific vulnerabilities. Step 3: When new vulnerabilities are disclosed, the learning unit incorporates that information and reflects it in scans and remediation proposals. For example, the learning unit collects new vulnerability information in real time, and the generating AI immediately learns and updates countermeasures. Step 4: The notification unit notifies the administrator of the diagnosis results based on the new vulnerability information learned by the learning unit. For example, the notification unit may notify the administrator in the form of, "A vulnerability has been found on the server. Please perform the following steps as a remediation measure."

[0101] The specific processing unit 290 transmits the result of the specific processing to the smart device 14. In the smart device 14, the control unit 46A causes the output device 40 to output the result of the specific processing. The microphone 38B acquires audio indicating a user input regarding the result of the specific processing. The control unit 46A transmits audio data indicating the user input acquired by the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.

[0102] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> Examples of generative AIs include the data generation model 58, such as a neural network model (e.g., a neural network model), and a neural network model (e.g., a neural network model). The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating speech, text data indicating text, and image data indicating an image is also input to the data generation model 58. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization. The specification processing unit 290 performs the above-mentioned specification processing using the data generation model 58. The data generation model 58 may be a fine-tuned model so as to output an inference result from a prompt that does not include an instruction. In this case, the data generation model 58 can output an inference result from a prompt that does not include an instruction. The data processing device 12 and the like include multiple types of data generation models 58, and the data generation model 58 includes AIs other than the generative AI. The AI ​​other than the generative AI may be, for example, linear regression, logistic regression, decision tree, random forest, support vector machine (SVM), k-means clustering, convolutional neural network (CNN), recurrent neural network (RNN), generative adversarial network (GAN), or naive Bayes, and can perform various processes, but is not limited to these examples. The AI ​​may also be an AI agent. When the processes of each of the above-mentioned parts are performed by AI, the processes may be performed in part or entirely by AI, but are not limited to these examples. The processes performed by AI, including the generative AI, may be replaced with rule-based processes.

[0103] Furthermore, the processing by the data processing system 10 described above is executed by the specific processing unit 290 of the data processing device 12 or the control unit 46A of the smart device 14, but may also be executed by the specific processing unit 290 of the data processing device 12 and the control unit 46A of the smart device 14. Furthermore, the specific processing unit 290 of the data processing device 12 acquires or collects information necessary for processing from the smart device 14 or an external device, and the smart device 14 acquires or collects information necessary for processing from the data processing device 12 or an external device.

[0104] [Second embodiment] FIG. 3 shows an example of the configuration of a data processing system 210 according to the second embodiment.

[0105] 3, the data processing system 210 includes a data processing device 12 and smart glasses 214. An example of the data processing device 12 is a server.

[0106] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN and / or a LAN.

[0107] The smart glasses 214 include a computer 36, a microphone 238, a speaker 240, a camera 42, and a communication I / F 44. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The microphone 238, the speaker 240, and the camera 42 are also connected to the bus 52.

[0108] The microphone 238 receives instructions and the like from the user by receiving voice uttered by the user. The microphone 238 captures the voice uttered by the user, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to instructions from the processor 46.

[0109] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the user's surroundings (for example, an imaging range defined by an angle of view equivalent to the field of vision of a typical healthy person).

[0110] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 are responsible for the exchange of various information between the processor 46 and the processor 28 via the network 54. The exchange of various information between the processor 46 and the processor 28 using the communication I / Fs 44 and 26 is carried out in a secure state.

[0111] Fig. 4 shows an example of the main functions of the data processing device 12 and the smart glasses 214. As shown in Fig. 4, in the data processing device 12, a specific process is performed by the processor 28. A specific process program 56 is stored in the storage 32.

[0112] The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[0113] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290. The identification processing unit 290 can estimate the user's emotion using the emotion identification model 59 and perform identification processing using the user's emotion.

[0114] In the smart glasses 214, the specific processing is performed by the processor 46. A specific processing program 60 is stored in the storage 50. The processor 46 reads the specific processing program 60 from the storage 50 and executes the read specific processing program 60 on the RAM 48. The specific processing is realized by the processor 46 operating as the control unit 46A in accordance with the specific processing program 60 executed on the RAM 48. Note that the smart glasses 214 may have a data generation model and an emotion identification model similar to the data generation model 58 and the emotion identification model 59.

[0115] Note that a device other than the data processing device 12 may have the data generation model 58. For example, a server device may have the data generation model 58. In this case, the data processing device 12 communicates with the server device having the data generation model 58 to obtain a processing result (such as a prediction result) using the data generation model 58. Furthermore, the data processing device 12 may be a server device, or may be a terminal device (for example, a mobile phone, a robot, a home appliance, etc.) owned by a user.

[0116] The specific processing unit 290 transmits the result of the specific processing to the smart glasses 214. In the smart glasses 214, the control unit 46A causes the speaker 240 to output the result of the specific processing. The microphone 238 acquires audio indicating a user input regarding the result of the specific processing. The control unit 46A transmits audio data indicating the user input acquired by the microphone 238 to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.

[0117] The data generation model 58 is a so-called generative AI. An example of the data generation model 58 is a generative AI such as ChatGPT. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 receives a prompt containing an instruction, as well as inference data such as voice data representing speech, text data representing text, and image data representing an image. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization. The identification processing unit 290 performs the above-mentioned identification processing using the data generation model 58. The data generation model 58 may be a fine-tuned model so as to output an inference result from a prompt that does not include an instruction. In this case, the data generation model 58 can output an inference result from a prompt that does not include an instruction. The data processing device 12 and the like include multiple types of data generation models 58, and the data generation model 58 includes AIs other than the generative AI. The AI ​​other than the generative AI may be, for example, linear regression, logistic regression, decision tree, random forest, support vector machine (SVM), k-means clustering, convolutional neural network (CNN), recurrent neural network (RNN), generative adversarial network (GAN), or naive Bayes, and can perform various processes, but is not limited to these examples. The AI ​​may also be an AI agent. When the processes of each of the above-mentioned parts are performed by AI, the processes may be performed in part or entirely by AI, but are not limited to these examples. The processes performed by AI, including the generative AI, may be replaced with rule-based processes.

[0118] The data processing system 210 according to the second embodiment performs the same processing as the data processing system 10 according to the first embodiment. The processing by the data processing system 210 is executed by the specific processing unit 290 of the data processing device 12 or the control unit 46A of the smart glasses 214, but may also be executed by the specific processing unit 290 of the data processing device 12 and the control unit 46A of the smart glasses 214. Furthermore, the specific processing unit 290 of the data processing device 12 acquires or collects information required for processing from the smart glasses 214 or an external device, etc., and the smart glasses 214 acquires or collects information required for processing from the data processing device 12 or an external device, etc.

[0119] [Third embodiment] FIG. 5 shows an example of the configuration of a data processing system 310 according to the third embodiment.

[0120] 5, the data processing system 310 includes the data processing device 12 and a headset terminal 314. An example of the data processing device 12 is a server.

[0121] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN and / or a LAN.

[0122] The headset type terminal 314 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication I / F 44, and a display 343. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The microphone 238, the speaker 240, the camera 42, and the display 343 are also connected to the bus 52.

[0123] The microphone 238 receives instructions and the like from the user by receiving voice uttered by the user. The microphone 238 captures the voice uttered by the user, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to instructions from the processor 46.

[0124] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the user's surroundings (for example, an imaging range defined by an angle of view equivalent to the field of vision of a typical healthy person).

[0125] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 are responsible for the exchange of various information between the processor 46 and the processor 28 via the network 54. The exchange of various information between the processor 46 and the processor 28 using the communication I / Fs 44 and 26 is carried out in a secure state.

[0126] Fig. 6 shows an example of the main functions of the data processing device 12 and the headset terminal 314. As shown in Fig. 6, in the data processing device 12, a specific process is performed by the processor 28. A specific process program 56 is stored in the storage 32.

[0127] The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[0128] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290. The identification processing unit 290 can estimate the user's emotion using the emotion identification model 59 and perform identification processing using the user's emotion.

[0129] In the headset type terminal 314, the identification process is performed by the processor 46. A identification program 60 is stored in the storage 50. The processor 46 reads the identification program 60 from the storage 50 and executes the read identification program 60 on the RAM 48. The identification process is realized by the processor 46 operating as a control unit 46A in accordance with the identification program 60 executed on the RAM 48. Note that the headset type terminal 314 may also have a data generation model and an emotion identification model similar to the data generation model 58 and the emotion identification model 59.

[0130] Note that a device other than the data processing device 12 may have the data generation model 58. For example, a server device may have the data generation model 58. In this case, the data processing device 12 communicates with the server device having the data generation model 58 to obtain a processing result (such as a prediction result) using the data generation model 58. Furthermore, the data processing device 12 may be a server device, or may be a terminal device (for example, a mobile phone, a robot, a home appliance, etc.) owned by a user.

[0131] The specific processing unit 290 transmits the result of the specific processing to the headset type terminal 314. In the headset type terminal 314, the control unit 46A causes the speaker 240 and the display 343 to output the result of the specific processing. The microphone 238 acquires audio indicating a user input regarding the result of the specific processing. The control unit 46A transmits audio data indicating the user input acquired by the microphone 238 to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.

[0132] The data generation model 58 is a so-called generative AI. An example of the data generation model 58 is a generative AI such as ChatGPT. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 receives a prompt containing an instruction, as well as inference data such as voice data representing speech, text data representing text, and image data representing an image. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization. The identification processing unit 290 performs the above-mentioned identification processing using the data generation model 58. The data generation model 58 may be a fine-tuned model so as to output an inference result from a prompt that does not include an instruction. In this case, the data generation model 58 can output an inference result from a prompt that does not include an instruction. The data processing device 12 and the like include multiple types of data generation models 58, and the data generation model 58 includes AIs other than the generative AI. The AI ​​other than the generative AI may be, for example, linear regression, logistic regression, decision tree, random forest, support vector machine (SVM), k-means clustering, convolutional neural network (CNN), recurrent neural network (RNN), generative adversarial network (GAN), or naive Bayes, and can perform various processes, but is not limited to these examples. The AI ​​may also be an AI agent. When the processes of each of the above-mentioned parts are performed by AI, the processes may be performed in part or entirely by AI, but are not limited to these examples. The processes performed by AI, including the generative AI, may be replaced with rule-based processes.

[0133] The data processing system 310 according to the third embodiment performs the same processing as the data processing system 10 according to the first embodiment. The processing by the data processing system 310 is executed by the specific processing unit 290 of the data processing device 12 or the control unit 46A of the headset type terminal 314, but may also be executed by the specific processing unit 290 of the data processing device 12 and the control unit 46A of the headset type terminal 314. Furthermore, the specific processing unit 290 of the data processing device 12 acquires or collects information required for processing from the headset type terminal 314 or an external device, etc., and the headset type terminal 314 acquires or collects information required for processing from the data processing device 12 or an external device, etc.

[0134] [Fourth embodiment] FIG. 7 shows an example of the configuration of a data processing system 410 according to the fourth embodiment.

[0135] 7, the data processing system 410 includes a data processing device 12 and a robot 414. An example of the data processing device 12 is a server.

[0136] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN and / or a LAN.

[0137] The robot 414 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication I / F 44, and a control target 443. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The microphone 238, the speaker 240, the camera 42, and the control target 443 are also connected to the bus 52.

[0138] The microphone 238 receives instructions and the like from the user by receiving voice uttered by the user. The microphone 238 captures the voice uttered by the user, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to instructions from the processor 46.

[0139] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS image sensor or a CCD image sensor, and captures images of the user's surroundings (for example, an imaging range defined by an angle of view equivalent to the field of vision of a typical healthy person).

[0140] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 are responsible for the exchange of various information between the processor 46 and the processor 28 via the network 54. The exchange of various information between the processor 46 and the processor 28 using the communication I / Fs 44 and 26 is carried out in a secure state.

[0141] The control object 443 includes a display device, LEDs in the eyes, and motors that drive the arms, hands, and feet. The posture and gestures of the robot 414 are controlled by controlling the motors of the arms, hands, and feet. Some of the emotions of the robot 414 can be expressed by controlling these motors. In addition, the facial expressions of the robot 414 can also be expressed by controlling the light emission state of the LEDs in the eyes of the robot 414.

[0142] Fig. 8 shows an example of the main functions of the data processing device 12 and the robot 414. As shown in Fig. 8, in the data processing device 12, a specific process is performed by the processor 28. A specific process program 56 is stored in the storage 32.

[0143] The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[0144] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290. The identification processing unit 290 can estimate the user's emotion using the emotion identification model 59 and perform identification processing using the user's emotion.

[0145] In the robot 414, the processor 46 performs the identification process. A identification program 60 is stored in the storage 50. The processor 46 reads the identification program 60 from the storage 50 and executes the read identification program 60 on the RAM 48. The identification process is realized by the processor 46 operating as a control unit 46A in accordance with the identification program 60 executed on the RAM 48. The robot 414 may have a data generation model and an emotion identification model similar to the data generation model 58 and the emotion identification model 59.

[0146] Note that a device other than the data processing device 12 may have the data generation model 58. For example, a server device may have the data generation model 58. In this case, the data processing device 12 communicates with the server device having the data generation model 58 to obtain a processing result (such as a prediction result) using the data generation model 58. Furthermore, the data processing device 12 may be a server device, or may be a terminal device (for example, a mobile phone, a robot, a home appliance, etc.) owned by a user.

[0147] The specific processing unit 290 transmits the result of the specific processing to the robot 414. In the robot 414, the control unit 46A causes the speaker 240 and the control target 443 to output the result of the specific processing. The microphone 238 acquires voice indicating a user input regarding the result of the specific processing. The control unit 46A transmits voice data indicating the user input acquired by the microphone 238 to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the voice data.

[0148] The data generation model 58 is a so-called generative AI. An example of the data generation model 58 is a generative AI such as ChatGPT. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 receives a prompt containing an instruction, as well as inference data such as voice data representing speech, text data representing text, and image data representing an image. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization. The identification processing unit 290 performs the above-mentioned identification processing using the data generation model 58. The data generation model 58 may be a fine-tuned model so as to output an inference result from a prompt that does not include an instruction. In this case, the data generation model 58 can output an inference result from a prompt that does not include an instruction. The data processing device 12 and the like include multiple types of data generation models 58, and the data generation model 58 includes AIs other than the generative AI. The AI ​​other than the generative AI may be, for example, linear regression, logistic regression, decision tree, random forest, support vector machine (SVM), k-means clustering, convolutional neural network (CNN), recurrent neural network (RNN), generative adversarial network (GAN), or naive Bayes, and can perform various processes, but is not limited to these examples. The AI ​​may also be an AI agent. When the processes of each of the above-mentioned parts are performed by AI, the processes may be performed in part or entirely by AI, but are not limited to these examples. The processes performed by AI, including the generative AI, may be replaced with rule-based processes.

[0149] The data processing system 410 according to the fourth embodiment performs the same processing as the data processing system 10 according to the first embodiment. The processing by the data processing system 410 is executed by the specific processing unit 290 of the data processing device 12 or the control unit 46A of the robot 414, but may also be executed by the specific processing unit 290 of the data processing device 12 and the control unit 46A of the robot 414. Furthermore, the specific processing unit 290 of the data processing device 12 acquires or collects information required for processing from the robot 414 or an external device, etc., and the robot 414 acquires or collects information required for processing from the data processing device 12 or an external device, etc.

[0150] The emotion identification model 59 as an emotion engine may determine the user's emotion according to a specific mapping. Specifically, the emotion identification model 59 may determine the user's emotion according to an emotion map (see FIG. 9), which is a specific mapping. Similarly, the emotion identification model 59 may determine the robot's emotion, and the identification processing unit 290 may perform identification processing using the robot's emotion.

[0151] FIG. 9 illustrates an emotion map 400 on which multiple emotions are mapped. In the emotion map 400, emotions are arranged in concentric circles radiating from the center. Emotions closer to the center of the concentric circles are more primitive. Emotions representing states and behaviors arising from a state of mind are arranged on the outer edges of the concentric circles. The concept of emotion encompasses both emotions and mental states. Emotions generally generated from reactions occurring in the brain are arranged on the left side of the concentric circles. Emotions generally induced by situational judgment are arranged on the right side of the concentric circles. Emotions generally generated from reactions occurring in the brain and induced by situational judgment are arranged on the upper and lower sides of the concentric circles. Furthermore, the emotion of "pleasure" is arranged on the upper side of the concentric circles, and the emotion of "discomfort" is arranged on the lower side. In this way, in the emotion map 400, multiple emotions are mapped based on the structure by which emotions are generated, and emotions that tend to occur simultaneously are mapped close to each other.

[0152] These emotions are distributed in the 3 o'clock direction on emotion map 400, and typically fluctuate between relief and anxiety. In the right half of emotion map 400, situational awareness dominates over internal sensations, resulting in a sense of calm.

[0153] The inside of emotion map 400 represents what is going on in the mind, and the outside of emotion map 400 represents behavior, so the further you go outside emotion map 400, the more visible the emotions become (the more they are expressed in behavior).

[0154] Human emotions are based on various balances, such as posture and blood sugar levels. When these balances deviate from the ideal, a state of discomfort is expressed, and when they approach the ideal, a state of pleasure is expressed. Emotions can also be created for robots, cars, and motorcycles, based on various balances, such as posture and remaining battery life. When these balances deviate from the ideal, a state of discomfort is expressed, and when they approach the ideal, a state of pleasure is expressed. An emotion map can be generated, for example, based on Dr. Mitsuyoshi's emotion map (Research on speech emotion recognition and brain physiological signal analysis systems for emotions, Tokushima University, doctoral dissertation: https: / / ci.nii.ac.jp / naid / 500000375379). The left half of the emotion map lists emotions belonging to the area called "reaction," where sensation is dominant. The right half of the emotion map lists emotions belonging to the area called "situation," where situational awareness is dominant.

[0155] The emotion map defines two emotions that promote learning. One is a negative emotion on the situation side, around the middle of "repentance" or "reflection." In other words, this occurs when the robot experiences negative emotions such as "I never want to feel this way again" or "I don't want to be scolded again." The other is a positive emotion on the response side, around "desire." In other words, this occurs when the robot experiences positive feelings such as "I want more" or "I want to know more."

[0156] The emotion identification model 59 inputs user input into a pre-trained neural network, obtains emotion values ​​indicating each emotion shown in the emotion map 400, and determines the user's emotion. This neural network is pre-trained based on multiple pieces of training data that are combinations of user input and emotion values ​​indicating each emotion shown in the emotion map 400. Furthermore, this neural network is trained so that emotions that are located close to each other have similar values, as in the emotion map 900 shown in FIG. 10. FIG. 10 shows an example in which multiple emotions, "relieved," "calm," and "reassuring," have similar emotion values.

[0157] In the above embodiment, an example was given in which a specific process is performed by one computer 22, but the technology disclosed herein is not limited to this, and distributed processing of the specific process may be performed by multiple computers including computer 22.

[0158] In the above embodiment, an example in which the specific processing program 56 is stored in the storage 32 has been described, but the technology of the present disclosure is not limited to this. For example, the specific processing program 56 may be stored in a portable, computer-readable, non-transitory storage medium such as a USB (Universal Serial Bus) memory. The specific processing program 56 stored in the non-transitory storage medium is installed in the computer 22 of the data processing device 12. The processor 28 executes the specific processing in accordance with the specific processing program 56.

[0159] Alternatively, the specific processing program 56 may be stored in a storage device such as a server connected to the data processing device 12 via the network 54, and the specific processing program 56 may be downloaded and installed on the computer 22 in response to a request from the data processing device 12.

[0160] It is not necessary to store all of the specific processing program 56 in a storage device such as a server connected to the data processing device 12 via the network 54, or to store all of the specific processing program 56 in the storage 32; only a portion of the specific processing program 56 may be stored.

[0161] The hardware resource for executing a specific process can be any of the following processors: A CPU is a general-purpose processor that functions as a hardware resource for executing a specific process by executing software, i.e., a program. A dedicated electrical circuit, such as a field-programmable gate array (FPGA), a programmable logic device (PLD), or an application-specific integrated circuit (ASIC), is a processor with a circuit configuration specifically designed to execute a specific process. Each processor has built-in or connected memory, and uses the memory to execute the specific process.

[0162] The hardware resource that executes the specific process may be configured with one of these various processors, or may be configured with a combination of two or more processors of the same or different types (for example, a combination of multiple FPGAs, or a combination of a CPU and an FPGA). Also, the hardware resource that executes the specific process may be a single processor.

[0163] As an example of a system configured with a single processor, first, one processor is configured by combining one or more CPUs and software, and this processor functions as a hardware resource that executes a specific process. Second, there is a system that uses a processor that realizes the functions of an entire system including multiple hardware resources that execute a specific process on a single IC chip, as typified by SoC (System-on-a-chip). In this way, a specific process is realized using one or more of the above-mentioned various processors as hardware resources.

[0164] Furthermore, the hardware structure of these various processors can be, more specifically, an electric circuit that combines circuit elements such as semiconductor devices. The specific processing described above is merely an example. Therefore, it goes without saying that unnecessary steps may be deleted, new steps may be added, or the processing order may be rearranged, without departing from the spirit of the invention.

[0165] In the above example, the first to fourth embodiments have been described separately, but some or all of these embodiments may be combined. The smart device 14, smart glasses 214, headset terminal 314, and robot 414 are merely examples, and they may be combined, or other devices may be used. In the above example, the first and second embodiments have been described separately, but they may be combined.

[0166] The above-described description and illustrations are a detailed explanation of the parts related to the technology of the present disclosure and are merely an example of the technology of the present disclosure. For example, the above description of the configuration, functions, actions, and effects is an explanation of an example of the configuration, functions, actions, and effects of the parts related to the technology of the present disclosure. Therefore, it goes without saying that unnecessary parts may be deleted, new elements may be added, or replacements may be made to the above-described description and illustrations within the scope of the gist of the technology of the present disclosure. Furthermore, to avoid confusion and facilitate understanding of the parts related to the technology of the present disclosure, the above-described description and illustrations omit explanations of common technical knowledge that do not require particular explanation to enable the implementation of the technology of the present disclosure.

[0167] All publications, patent applications, and technical standards mentioned in this specification are herein incorporated by reference to the same extent as if each individual publication, patent application, or technical standard was specifically and individually indicated to be incorporated by reference. [Explanation of symbols]

[0168] 10, 210, 310, 410 Data Processing Systems 12 Data Processing Device 14 Smart Devices 214 Smart Glasses 314 Headset-type terminal 414 Robot

Claims

1. A scanning section that scans the server for vulnerabilities, an analysis unit that analyzes the scan results obtained by the scanning unit; a learning unit that proposes optimal repair measures for the vulnerabilities identified by the analysis unit; a notification unit that notifies the diagnosis result based on the new vulnerability information learned by the learning unit. A system characterized by:

2. The scanning unit Extend the scanning scope beyond the server to the entire network and cloud infrastructure for comprehensive security scanning.

2. The system of claim 1.

3. The analysis unit Selecting the most suitable repair plan from the proposed repair plans based on past repair history and success rate 2. The system of claim 1.

4. The learning unit New vulnerability information is collected in real time, and the generating AI immediately learns and updates countermeasures.

2. The system of claim 1.

5. The notification unit When notifying the administrator of the diagnostic results, the generating AI provides detailed explanations and background information to deepen the administrator's understanding.

2. The system of claim 1.

6. The scanning unit Using an emotion estimation function, the emotion of the administrator regarding the scan results is analyzed, and an interface for reducing stress is provided.

2. The system of claim 1.

Citation Information

Patent Citations

  • Persona chatbot control method and system

    JP2022180282A