system

The system uses generative AI to generate and analyze BEC email signatures, allowing for quick and precise identification and prevention of BEC scams by moving or deleting suspicious emails, thus reducing financial and reputational risks.

JP2026028131APending Publication Date: 2026-02-19SOFTBANK GROUP CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024130429
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-08-06
Publication Date
2026-02-19

AI Technical Summary

Technical Problem

Conventional email filtering technologies struggle to accurately detect Business Email Compromise (BEC) emails, leading to increased financial and reputational risks due to the sophistication of generative AI-generated scams.

Method used

A system utilizing generative AI to generate multiple BEC emails, extract signatures, store them in a database, compare incoming emails against these signatures, and generate warning messages or move/sanitize suspicious emails.

Benefits of technology

Enables rapid and accurate detection of BEC emails, preventing potential harm by moving them to a quarantine folder or deleting them, with user notification and interaction options.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026028131000001_ABST
    Figure 2026028131000001_ABST
Patent Text Reader

Abstract

To provide a system capable of highly accurately and quickly detecting BEC mail.SOLUTION: The system includes means for generating a plurality of business email compromise mails using a generation AI, means for extracting a signature from the generated business email compromise mails, means for storing the extracted signature in a database, means for acquiring a received mail, means for generating a signature from the acquired received mail, means for comparing the generated signature with a signature in the database, means for determining whether the received mail is suspicious of business email compromise based on the comparison result, means for generating a warning message for the corresponding mail, means for transmitting the warning message to a user, and means for moving or deleting the corresponding mail to a quarantine folder.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The technology of the present disclosure relates to a system. [Background technology]

[0002] Patent document 1 discloses a persona chatbot control method performed by at least one processor, the method including the steps of receiving a user utterance, adding the user utterance to a prompt including an instruction sentence related to a description of the chatbot character, encoding the prompt, and inputting the encoded prompt into a language model to generate a chatbot utterance in response to the user utterance. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Publication No. 2022-180282 Summary of the Invention [Problem to be solved by the invention]

[0004] The number of business email compromise (BEC) cases and the resulting losses are steadily increasing, and more effective measures are needed to address this issue. In particular, generative AI can quickly create natural and sophisticated BEC emails, making it difficult to detect BEC emails using conventional email filtering technology. As a result, companies and individuals are at increased risk of falling victim to BEC scams, which could have a significant impact not only on financial losses but also on reputation. Given this background, there is a need for the development of a new system that can overcome the limitations of conventional technology and quickly detect BEC emails with high accuracy. [Means for solving the problem]

[0005] The present invention provides a system that uses generation AI to generate multiple emails for business email compromise (BEC), extracts signatures from them, stores them in a database, and compares them with received emails. Specifically, the problem is solved by the following means.

[0006] 1. Using generative AI to generate multiple BEC emails:

[0007] Periodically, new BEC emails are generated using a generative AI tool and their signatures are added to the database.

[0008] 2. How to extract signatures from generated BEC emails:

[0009] Characteristic signatures are extracted from the generated emails and stored in a database.

[0010] 3. How to get your incoming emails:

[0011] Periodically retrieve new incoming emails from the company's email server.

[0012] 4. How to generate a signature from an incoming email:

[0013] Analyzes the contents of incoming emails and generates signatures.

[0014] 5. A means of comparing the generated signature with signatures in the database:

[0015] The generated signature is compared with signatures in the database to determine if they match.

[0016] 6. How to determine if an incoming email is suspected of being a business email compromise:

[0017] Based on the comparison results, it determines whether the received email is suspected of being a BEC email.

[0018] 7. How to generate a warning message for applicable mail:

[0019] If the signature matches, a warning message is generated to notify the user.

[0020] 8. Means of sending a warning message to the user:

[0021] A warning about the email is sent to the user's device to notify them.

[0022] 9. How to move the affected email to a quarantine folder or delete it:

[0023] Move warning emails to a quarantine folder or delete them automatically.

[0024] Furthermore, by combining a means of displaying a warning message on the user's device so that the user can check and handle the relevant email, and a means of collecting and analyzing past business email compromise emails created by humans in order to train the generation AI, it is possible to provide a system that enables more accurate and faster detection of BEC emails.

[0025] "Generative AI" is an artificial intelligence technology that uses generative models to automatically generate new data (in this case, emails for business email compromise).

[0026] Business Email Compromise (BEC) is a type of email fraud that involves fraudulent means of posing as a business contact such as a company in order to defraud money or important information.

[0027] A "signature" refers to a unique identifying feature or pattern of a particular piece of data (in this case, a business email compromise email) that is used to determine whether it matches other data.

[0028] A "database" is a structured collection of data for efficiently storing, managing, and retrieving information.

[0029] "Received email" refers to email sent to a company's mail server and received by a user.

[0030] A "warning message" is an information message that notifies the user when the system detects a specific risk or abnormality.

[0031] A "quarantine folder" is a special folder separate from regular email folders that is used to temporarily store suspicious emails.

[0032] "Analysis" is the process of examining data in detail to understand its structure and characteristics. [Brief explanation of the drawings]

[0033] [Figure 1] 1 is a conceptual diagram showing an example of the configuration of a data processing system according to a first embodiment. [Figure 2] 1 is a conceptual diagram showing an example of main functions of a data processing device and a smart device according to a first embodiment. [Figure 3] FIG. 10 is a conceptual diagram showing an example of the configuration of a data processing system according to a second embodiment. [Figure 4] FIG. 10 is a conceptual diagram showing an example of main functions of a data processing device and smart glasses according to a second embodiment. [Figure 5] FIG. 10 is a conceptual diagram showing an example of the configuration of a data processing system according to a third embodiment. [Figure 6] FIG. 11 is a conceptual diagram showing an example of main functions of a data processing device and a headset-type terminal according to a third embodiment. [Figure 7] FIG. 10 is a conceptual diagram showing an example of the configuration of a data processing system according to a fourth embodiment. [Figure 8] FIG. 10 is a conceptual diagram showing an example of main functions of a data processing device and a robot according to a fourth embodiment. [Figure 9] 1 shows an emotion map onto which multiple emotions are mapped. [Figure 10] 1 shows an emotion map onto which multiple emotions are mapped. [Figure 11] FIG. 3 is a sequence diagram showing a processing flow of the data processing system according to the first embodiment. [Figure 12] FIG. 10 is a sequence diagram showing the flow of processing in the data processing system in Application Example 1. [Figure 13] FIG. 10 is a sequence diagram showing the flow of processing in the data processing system according to the second embodiment when an emotion engine is combined. [Figure 14] FIG. 10 is a sequence diagram showing the flow of processing in the data processing system in Application Example 2 when an emotion engine is combined. DETAILED DESCRIPTION OF THE INVENTION

[0034] An example of an embodiment of a system according to the technology of the present disclosure will be described below with reference to the accompanying drawings.

[0035] First, the terms used in the following description will be explained.

[0036] In the following embodiments, a coded processor (hereinafter simply referred to as a "processor") may be a single arithmetic device or a combination of multiple arithmetic devices. Furthermore, a processor may be a single type of arithmetic device or a combination of multiple types of arithmetic devices. Examples of arithmetic devices include a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), a GPGPU (General-Purpose computing on Graphics Processing Units), and an APU (Accelerated Processing Unit).

[0037] In the following embodiments, a coded RAM (Random Access Memory) is a memory in which information is temporarily stored and is used as a working memory by a processor.

[0038] In the following embodiments, the coded storage is one or more non-volatile storage devices that store various programs, various parameters, etc. Examples of non-volatile storage devices include flash memory (SSD (Solid State Drive)), magnetic disks (e.g., hard disks), and magnetic tapes.

[0039] In the following embodiments, a communication I / F (Interface) with a symbol is an interface including a communication processor, an antenna, etc. The communication I / F controls communication between multiple computers. Examples of communication standards applied to the communication I / F include wireless communication standards including 5G (5th Generation Mobile Communication System), Wi-Fi (registered trademark), Bluetooth (registered trademark), etc.

[0040] In the following embodiments, "A and / or B" is synonymous with "at least one of A and B." In other words, "A and / or B" means that it may be only A, only B, or a combination of A and B. Furthermore, in this specification, the same concept as "A and / or B" is also applied when three or more things are expressed connected by "and / or."

[0041] [First embodiment]

[0042] FIG. 1 shows an example of the configuration of a data processing system 10 according to the first embodiment.

[0043] 1, a data processing system 10 includes a data processing device 12 and a smart device 14. An example of the data processing device 12 is a server.

[0044] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[0045] The smart device 14 includes a computer 36, a reception device 38, an output device 40, a camera 42, and a communication I / F 44. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The reception device 38, the output device 40, and the camera 42 are also connected to the bus 52.

[0046] The reception device 38 includes a touch panel 38A, a microphone 38B, and the like, and receives user input. The touch panel 38A detects contact with an indicator (for example, a pen or a finger) to receive user input by the touch of the indicator. The microphone 38B detects the user's voice to receive user input by voice. The control unit 46A transmits data indicating the user input received by the touch panel 38A and the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the data indicating the user input.

[0047] The output device 40 includes a display 40A and a speaker 40B, and presents data to the user 20 by outputting the data in a form of expression that the user 20 can perceive (for example, audio and / or text). The display 40A displays visible information such as text and images in accordance with instructions from the processor 46. The speaker 40B outputs audio in accordance with instructions from the processor 46. The camera 42 is a compact digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor.

[0048] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 control the exchange of various information between the processor 46 and the processor 28 via the network 54.

[0049] FIG. 2 shows an example of the main functions of the data processing device 12 and the smart device 14.

[0050] 2, in the data processing device 12, a specific process is performed by the processor 28. A specific processing program 56 is stored in the storage 32. The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific process is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[0051] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[0052] In the smart device 14, the processor 46 performs the reception output process. The storage 50 stores a reception output program 60. The reception output program 60 is used in conjunction with the specific processing program 56 by the data processing system 10. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.

[0053] Next, a description will be given of the specific processing performed by the specific processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."

[0054] The system of this invention uses generative AI to automatically detect business email compromise (BEC) emails and warn users. It also prevents BEC damage by moving the emails to a quarantine folder or deleting them. The details of the system and the program processing are explained below.

[0055] Server Operation

[0056] 1. Generating BEC emails using AI:

[0057] The server automatically generates new BEC emails at the beginning of each month or every few weeks using a generative AI tool, which uses advanced natural language processing techniques to make the emails appear like regular business emails.

[0058] The server stores the content of generated BEC emails in a database and extracts characteristic signatures from those emails.

[0059] 2. Signature Management:

[0060] The server sequentially adds signatures extracted from the generated BEC emails to the database and updates it regularly. It also trains the generation AI to learn from past BEC emails created by humans, strengthening these signatures.

[0061] 3. Acquiring and analyzing incoming emails:

[0062] The server periodically retrieves new incoming emails from the company's email server. For example, you can configure it to retrieve incoming emails every hour.

[0063] The server analyzes the content of the received emails and generates signatures from these emails as well.

[0064] 4. Signature Matching:

[0065] The server compares the generated signature with the signatures in its database to determine if there is a match.

[0066] 5. Generate and send alerts:

[0067] The server generates a warning message for any emails that match the signature. The warning message contains information about the email and indicates that it is suspected of being a BEC scam.

[0068] The server generates a warning message, sends it to the user, and moves the affected email to a quarantine folder or deletes it.

[0069] Device behavior

[0070] 1. Providing the user interface:

[0071] The terminal displays a list of received emails to the user and displays a warning icon based on the results of the system's automatic analysis.

[0072] The terminal displays a warning message so that the user can check the details of the received email.

[0073] 2. Receiving and acting on warning messages:

[0074] The terminal notifies the user of the warning message received from the server together with its contents.

[0075] When a warning message appears on the device, the user is given the option to easily move the email to a quarantine folder or delete it.

[0076] User operations

[0077] 1. Check notifications:

[0078] The user checks the warning icon or notification displayed on the device.

[0079] The user clicks on the warning message to view the details and realizes that it may be a BEC email.

[0080] 2. Email Operations:

[0081] After reviewing the warning message, users can choose to move the email to a quarantine folder, delete it, or re-evaluate it as legitimate.

[0082] Specific examples

[0083] Scenario 1:

[0084] 1. At the beginning of each month, the server generates 20 new BEC emails using the generation AI and stores their signatures in a database.

[0085] 2. Check incoming emails every hour and analyze their contents.

[0086] 3. During a certain period of time, an incoming email is detected that matches the signature of a generated BEC email.

[0087] 4. The server generates a warning message and moves the affected email to a quarantine folder.

[0088] 5. A warning notification will appear on the user's device, and the user will check the email, confirm that it is a scam, and delete it.

[0089] This makes it possible to detect BEC emails quickly and accurately, preventing harm to users before it occurs.

[0090] The processing flow will be explained below.

[0091] Step 1:

[0092] At the beginning of each month, the server launches the AI ​​tool to generate 20 new Business Email Compromise (BEC) emails. The generated emails are written in a natural style and are designed to look like real business emails.

[0093] Step 2:

[0094] The server extracts characteristic signatures from the 20 generated BEC emails and stores them in a database. The signatures represent important characteristics and patterns of each BEC email.

[0095] Step 3:

[0096] The server collects BEC emails created by humans in the past, generates signatures for them, and adds them to the database, further strengthening the signature database.

[0097] Step 4:

[0098] The server retrieves new incoming emails from the company's mail server every hour, for example by connecting to the mail server and finding the latest incoming emails.

[0099] Step 5:

[0100] The server analyzes the content of the received email and generates a signature from it. This signature generation process uses the same method as the signature of the BEC email saved earlier.

[0101] Step 6:

[0102] The server compares the generated signature of the received email with the BEC signatures in the database. The comparison algorithm calculates the degree of match between each signature, and if there is a high degree of match, the email is determined to be suspected of being a BEC scam.

[0103] Step 7:

[0104] If the match is high, the server generates a warning message and sends it to the user's device, including information about the email, such as the sender, subject, and match level.

[0105] Step 8:

[0106] The server will move any incoming email that generates a warning message to a quarantine folder, and can be configured to automatically delete the email if desired.

[0107] Step 9:

[0108] The device displays a list of received emails and notifies the user of any warning messages received from the server. The warning icon allows the user to identify suspicious emails at a glance.

[0109] Step 10:

[0110] The user can click the warning icon displayed on the device to view the details of the warning message. The user can also check the contents of the email and view further details.

[0111] Step 11:

[0112] Users can follow the instructions in the warning message to manually delete the email or move it to a quarantine folder, or if they determine it to be legitimate, they can choose to move it back to a regular folder.

[0113] Step 12:

[0114] The server periodically checks the emails moved to the quarantine folder and deletes them after a certain period of time. The deletion rules and storage period are set by the administrator.

[0115] Example 1

[0116] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."

[0117] In today's business environment, fraud via business email counterfeiting (BEC) has become a major problem. In particular, the risk of companies and individuals suffering financial losses due to users receiving sophisticated forged emails is increasing. Conventional email filtering systems have difficulty effectively detecting and preventing these sophisticated forged emails, and new systems are needed to ensure user safety.

[0118] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.

[0119] In this invention, the server includes means for generating multiple counterfeit business emails using a generation AI, means for extracting characteristic patterns from the generated counterfeit business emails, means for saving the extracted characteristic patterns in a database, means for acquiring received emails, means for generating characteristic patterns from the acquired received emails, means for comparing the generated characteristic patterns with characteristic patterns in the database, means for determining whether the received emails are suspected of being counterfeit business emails based on the comparison results, means for generating a warning message for the corresponding emails, means for sending the warning message to the user, means for moving or deleting the corresponding emails to a quarantine folder, means for generating a warning message including an overview of the corresponding emails and a warning message and notifying the user of the warning message, and means for providing operation options for quarantining, deleting, or reevaluating the emails as legitimate, thereby enabling rapid and highly accurate detection and prevention of BEC emails.

[0120] "Generative AI" is a system that uses artificial intelligence technology to automatically generate new content (in this case, counterfeit business emails).

[0121] "Forged business email" is a forged email disguised as a normal business email sent with the intent to defraud.

[0122] A "characteristic pattern" is a specific pattern contained in elements such as email content, subject, sender address, and destination URL, and is used to identify counterfeit business emails.

[0123] A "database" is a structured information storage system for effectively storing and managing the generated characteristic patterns.

[0124] "Incoming email" refers to all emails received by a company or user.

[0125] The "warning message" is a warning message that notifies the user that the received email may be a forged business email.

[0126] A "quarantine folder" is a specific email folder that temporarily stores suspicious emails and keeps them separate from other regular emails.

[0127] "Action options" are the choices provided to a user to take action on a suspicious email (e.g., quarantine, delete, reassess).

[0128] The system of this invention uses generative AI to automatically detect forged emails intended for business email compromise (BEC) and warn users. It also prevents BEC damage by moving or deleting the forged emails in question to a quarantine folder.

[0129] Server Operation

[0130] Generating BEC emails using generative AI

[0131] The server automatically generates new BEC emails periodically using a generative AI tool (e.g., GPT-4). This allows emails based on the latest fraud techniques to be constantly added to the database. The server inputs prompt phrases such as "invoice from a customer" or "urgent payment request" into the generative AI, and saves the generated email content in the database.

[0132] Extracting and saving signatures

[0133] The server extracts characteristic patterns (signatures) from the generated BEC emails and stores them in a database using a natural language processing (NLP) algorithm to extract distinctive patterns from the email body, subject, sender address, destination URL, etc.

[0134] Acquiring and analyzing received emails

[0135] The server periodically retrieves new incoming emails from the company's mail server using IMAP or POP3 protocols, analyzes the emails using NLP algorithms, and generates signatures.

[0136] Signature Matching

[0137] The server analyzes the signature of the incoming email and compares it with the signatures in its existing database using fast search algorithms (e.g. hash functions or binary searches). If a match is found, the email is marked as suspected BEC.

[0138] Generate and send alerts

[0139] The server generates a warning message for any emails suspected of being BEC. This message includes a summary of the email and a warning. The warning message is sent to the user, and the email is moved to a quarantine folder or deleted.

[0140] Device behavior

[0141] Providing a user interface

[0142] The terminal displays a list of received emails and a warning icon to the user. If an abnormality is detected in an email, a warning icon will be displayed, and clicking the icon will display a detailed warning message in a pop-up.

[0143] Receiving and acting on warning messages

[0144] The terminal notifies the user of warning messages from the server and provides action options (quarantine, delete, or reassess as legitimate email), allowing the user to handle the email quickly and accurately.

[0145] User operations

[0146] Checking notifications

[0147] Users can check the warning icon or notification displayed on their device and click to open the details of the warning message to get a detailed understanding of whether the email is suspected to be a BEC scam.

[0148] Email Operations

[0149] After reviewing the warning message, users can choose to move the email to a quarantine folder, delete it, or re-evaluate it as legitimate.

[0150] Specific examples

[0151] Scenario 1:

[0152] 1. At the beginning of each month, the server generates 20 new BEC emails using the generation AI and stores their signatures in a database. An example prompt is "Generate an email proposing a new invoice format."

[0153] 2. Check incoming emails every hour and analyze their contents using natural language processing algorithms.

[0154] 3. During a certain period of time, the server detects that an incoming email matches the signature of a generated BEC email and records this as a flag.

[0155] 4. The server generates a warning message and moves the affected email to a quarantine folder.

[0156] 5. A warning notification will appear on the user's device, and the user will check the email, determine that it is a scam, and delete it.

[0157] This makes it possible to detect and prevent BEC emails quickly and accurately, preventing harm to users before it occurs.

[0158] The flow of the identification process in the first embodiment will be described with reference to FIG.

[0159] Step 1:

[0160] Generating BEC emails using generative AI

[0161] The server generates BEC emails using a generative AI model (e.g., GPT-4) and inputs a prompt such as "Generate an email proposing a new invoice format."

[0162] Input: Prompt text "Generate an email proposing a new invoice format."

[0163] Data processing: The generative AI model uses natural language processing based on the prompt text to generate fraudulent business emails.

[0164] Output: The generated BEC email.

[0165] Specific operation: The server saves the automatically generated email as a file and converts its content into a text format for analysis.

[0166] Step 2:

[0167] Extracting and saving signatures

[0168] The server extracts characteristic patterns (signatures) from the content of the generated BEC email.

[0169] Input: The generated BEC email.

[0170] Data processing: Using natural language processing algorithms, characteristic patterns are extracted from elements such as the email body, subject, sender address, and destination URL.

[0171] Output: The extracted signature.

[0172] Specific operation: The server adds the extracted signature to a database and creates an index to match and classify it with existing signatures.

[0173] Step 3:

[0174] Acquiring and analyzing received emails

[0175] The server periodically retrieves new incoming emails from the company's mail server.

[0176] Input: Incoming emails stored on your company's email server.

[0177] Data processing: Received emails are imported to the server using the IMAP or POP3 protocol, and the email content is analyzed using natural language processing algorithms.

[0178] Output: Parsed signature of the incoming email.

[0179] How it works: The server communicates with the mail server every hour, downloads new emails, and analyzes them using techniques such as tokenization and feature extraction.

[0180] Step 4:

[0181] Signature Matching

[0182] The server analyzes the signature of the incoming email and compares it with the signatures in its existing database.

[0183] Input: Parsed signatures from incoming emails and signatures in the database.

[0184] Data processing: Using a fast search algorithm (e.g. hash function or binary search) to match the signature.

[0185] Output: A list of matching signatures.

[0186] What it does: The server goes through a matching process, lists matching signatures, and flags emails that are suspected to be BEC.

[0187] Step 5:

[0188] Generate and send alerts

[0189] The server generates a warning message for emails suspected of being BEC and sends it to the user.

[0190] Input: Incoming email where a matching signature was found.

[0191] Data processing: Generate a warning message that includes a summary of the email and a warning.

[0192] Output: A warning message.

[0193] Specific actions: The server will send a warning message to the user's email address and simultaneously move the email to a quarantine folder or delete it.

[0194] Step 6:

[0195] Providing a user interface

[0196] The terminal displays a list of received emails and a warning icon to the user.

[0197] Input: Incoming emails and warning messages from the server.

[0198] Data Processing: Added warning icon and popup warning message.

[0199] Output: The email list and warning messages displayed in the user interface.

[0200] Specific operation: The terminal displays a list of received emails to the user through the email client software and provides an interface including a warning icon.

[0201] Step 7:

[0202] Receiving and acting on warning messages

[0203] Users can review the warning message and quarantine, delete, or reevaluate the email as legitimate.

[0204] Input: Warning messages and action options displayed on the terminal.

[0205] Data manipulation: Moves the email to a quarantine folder, deletes it, or re-evaluates it based on the user's choice.

[0206] Output: Change the state of the email depending on the user's selection.

[0207] Specific actions: The user checks the warning icon displayed on the device, clicks it to open a detailed warning message, and then performs the action on the relevant email.

[0208] (Application example 1)

[0209] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."

[0210] Conventional business email compromise (BEC) countermeasure systems rely on static rule-based analysis, making it difficult to respond quickly to new and changing fraudulent methods. Furthermore, users have few ways to know in real time whether an email they receive is fraudulent, making it difficult to take appropriate action immediately and preventing damage before it occurs. Furthermore, the user interface when a fraudulent email is detected is inadequate, making it difficult for users to easily and quickly handle the email.

[0211] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.

[0212] In this invention, the server includes: means for generating multiple business email fraud emails using a generation AI; means for extracting signatures from the generated business email fraud emails; means for storing the extracted signatures in a database; means for acquiring received emails; means for generating signatures from the acquired received emails; means for comparing the generated signatures with signatures in the database; means for determining whether the received emails are suspected of being business email fraud based on the comparison results; means for generating a warning message for the suspected emails; means for sending the warning message to a user; means for moving the suspected emails to a quarantine folder or deleting them; means for notifying the user of the warning message in real time on a mobile device of the user and providing a user interface that allows the user to move the suspected emails to a quarantine folder, delete them, or reassess them as legitimate; and means for the user to review and manipulate the suspected fraud emails. This enables advanced fraud email detection and real-time notification using the generation AI, as well as a user-friendly operation interface, thereby preventing fraud damage before it occurs.

[0213] "Generative AI" refers to a model that uses artificial intelligence technology to generate artificial content.

[0214] "Business email compromise" refers to a method of committing forgery or fraud by disguising emails as business-related.

[0215] A "signature" refers to a characteristic pattern or identifier contained in the content of an email.

[0216] "Database" refers to a system that collects and manages signatures and important data in one place.

[0217] "Mobile device" refers to a portable electronic device such as a smartphone or tablet.

[0218] "User interface" refers to the display screen and operating means through which a user interacts with a system.

[0219] A "quarantine folder" is a folder that stores suspicious or fraudulent emails received separately from other emails.

[0220] "Real-time notification" refers to a function that notifies the user of information immediately at the moment a relevant event occurs.

[0221] "Reevaluating as legitimate" refers to the user manually reconfirming an email as legitimate when the email has been mistakenly determined to be fraudulent.

[0222] "User" refers to an individual or company that uses this system.

[0223] The system of this invention uses a generative AI model to automatically detect fraudulent emails and send warning notifications to users in order to prevent damage caused by business email compromise (BEC). The operation of the server and terminal is described in detail below.

[0224] Server Operation

[0225] 1. Generating BEC emails using AI:

[0226] The server periodically generates new BEC emails using a generative AI model, which uses advanced natural language processing techniques to make the emails appear like regular business emails.

[0227] The content of the generated BEC emails is stored in a database and characteristic signatures are extracted from those emails.

[0228] 2. Signature Management:

[0229] The server sequentially adds the signatures extracted from the generated BEC emails to the database and updates it periodically.

[0230] The generation AI also learns from past artificially created BEC emails to strengthen the signature.

[0231] 3. Acquiring and analyzing incoming emails:

[0232] The server connects to the company's mail server and periodically (for example, every hour) retrieves new incoming emails.

[0233] It analyzes the emails it receives and generates signatures from them.

[0234] 4. Signature Matching:

[0235] The server compares the generated signature with the signatures in its database to determine if there is a match.

[0236] 5. Generate and send alerts:

[0237] If a signature matches an incoming email, a warning message will be generated containing information about the email.

[0238] The server sends the generated warning message to the user's mobile device and moves or deletes the relevant email in a quarantine folder.

[0239] Device behavior

[0240] 1. Providing the user interface:

[0241] The user interface displays a list of received emails to the user and displays a warning icon based on the results of automatic analysis by the system.

[0242] A warning message will be displayed, allowing the user to view details of the affected received email.

[0243] 2. Receiving and acting on warning messages:

[0244] The terminal notifies the user of the warning message received from the server together with its contents.

[0245] When a warning message appears, users are given the option to move the email to a quarantine folder or delete it.

[0246] User operations

[0247] 1. Check notifications:

[0248] The user checks the warning icon or notification displayed on the device.

[0249] Click on the warning message to see more details and understand that it may be a BEC email.

[0250] 2. Email Operations:

[0251] After checking the contents of the warning message, the user can choose to move the email to a quarantine folder, delete it, or re-evaluate it as legitimate.

[0252] Specific examples

[0253] If a user receives an email during a certain time period saying, "Please change the transfer destination to this address," the server analyzes the email and detects that it matches the signature of a previous BEC email. The server then sends a warning notification to the user's mobile device in real time and moves the email to a quarantine folder. The user who receives this notification can click on the warning message to check the details of the email and, if necessary, delete it as a fraudulent email.

[0254] Prompt Sentence Examples

[0255] "Email body: 'Thank you for your hard work. Your bank transfer details have changed, so we are sending you the new account details. Please confirm and confirm...'"

[0256] The above system enables advanced fraudulent email detection using generative AI, real-time notification, and a user-friendly operation interface, making it possible to prevent fraudulent incidents before they occur.

[0257] The flow of the specific processing in the application example 1 will be described with reference to FIG.

[0258] Step 1:

[0259] The server uses AI to generate multiple business email compromise emails.

[0260] Input: Enter a prompt for the generative AI model. "Email body: 'Thank you for your hard work. Your bank transfer details have changed, so we are sending you the new account details. Please confirm and confirm...'"

[0261] How it works: It uses a generative AI model (e.g., GPT-2) to generate BEC emails based on prompts.

[0262] Output: The generated BEC email.

[0263] Step 2:

[0264] The server extracts the signature from the generated BEC email.

[0265] Input: The generated BEC email.

[0266] How it works: Analyzes email content and extracts signatures (characteristic patterns or identifiers).

[0267] Output: The extracted signature.

[0268] Step 3:

[0269] The server stores the extracted signatures in a database.

[0270] Input: The extracted signature.

[0271] Behavior: Saves the signature to the database and updates the existing signature list.

[0272] Output: The updated database.

[0273] Step 4:

[0274] The server retrieves the incoming email.

[0275] Input: Your mail server login and connection information.

[0276] What it does: It connects to your company's mail server using the IMAP protocol and retrieves new incoming emails.

[0277] Output: The received emails retrieved.

[0278] Step 5:

[0279] The server generates a signature from the received email.

[0280] Input: The received emails retrieved.

[0281] How it works: Analyzes incoming emails and generates a new signature from their contents.

[0282] Output: The new signature.

[0283] Step 6:

[0284] The server compares the newly generated signature with the signatures in its database.

[0285] Input: New signatures and existing signatures in the database.

[0286] How it works: It runs an algorithm that compares the new signature with signatures in the database to determine if there is a match.

[0287] Output: Comparison result (match / not match).

[0288] Step 7:

[0289] The server generates a warning message for the affected email.

[0290] Input: Comparison result (if the signatures match).

[0291] Behavior: Generates a warning message containing the contents of the email.

[0292] Output: The warning message generated.

[0293] Step 8:

[0294] The server sends a warning message to the user's mobile device.

[0295] Input: The generated warning message and the user's mobile device information.

[0296] What it does: Sends a warning message to the user's mobile device.

[0297] Output: The warning message displayed on the user's mobile device.

[0298] Step 9:

[0299] The server moves the email to a quarantine folder or deletes it.

[0300] Input: Comparison result (if signature matches) and corresponding received email.

[0301] Action: The email will be moved from the inbox to a quarantine folder or deleted.

[0302] Output: Emails moved to quarantine folder or deleted.

[0303] Step 10:

[0304] The device will notify the user of a warning message and allow them to check and handle the relevant email.

[0305] Input: The warning message sent by the server.

[0306] What it does: Displays a warning message to the user, offering further details and options to delete the email or move it to a quarantine folder.

[0307] Output: User interaction to manage emails.

[0308] Step 11:

[0309] The user checks the relevant email and takes action.

[0310] Input: The warning message displayed on the terminal and detailed information about the email in question.

[0311] Action: The user reviews the email details and takes action to move it to quarantine, delete it, or reassess it as legitimate.

[0312] Output: Operation result (quarantine, delete, or re-evaluate the email).

[0313] Furthermore, an emotion engine that estimates the user's emotion may be combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59 and perform identification processing using the user's emotion.

[0314] Overall overview

[0315] This invention provides a system that uses generative AI to automatically detect business email compromise (BEC) emails and warn users, as well as a system that combines an emotion engine that recognizes the user's emotions. This system has functions to reduce the psychological burden on users, such as adjusting and customizing warning messages based on their emotional state and managing emotional data history.

[0316] Server Operation

[0317] 1. Generating BEC emails using AI:

[0318] At the beginning of each month, the server uses a generative AI tool to generate new Business Email Compromise (BEC) emails, which are then stored in a database and characteristic signatures are extracted from the emails.

[0319] 2. Signature Management:

[0320] The server stores the signatures extracted from the generated emails in a database and updates it regularly. It also collects BEC emails created by humans in the past and trains the generation AI on them. This strengthens the signature database and enables highly accurate detection.

[0321] 3. Acquiring and analyzing incoming emails:

[0322] The server retrieves new incoming emails from the company's mail server every hour and analyzes their contents, generating a signature from the incoming email.

[0323] 4. Signature Matching:

[0324] The server compares the signature generated from the received email with the BEC signatures in its database to determine if there is a match.

[0325] 5. Generate and send alerts:

[0326] The server generates a warning message for any incoming emails suspected of being BEC scams based on the signature matching results. The generated warning message is sent to the user's device, and the email is then moved to a quarantine folder or deleted.

[0327] Emotion Engine Operation

[0328] 1. Emotion recognition:

[0329] The device analyzes the user's facial expressions, voice, and input data, and recognizes the user's emotional state using an emotion engine. The recognized emotional data is then sent to the server.

[0330] 2. Customize the warning message:

[0331] The server customizes the content and presentation of the warning message based on the user's emotional state, for example, if the user is stressed, the warning message will be displayed in a more understandable and gentle tone.

[0332] 3. Emotion data history management:

[0333] The server stores the user's emotional state as historical data, which allows for optimization of warning messages based on past emotional data.

[0334] Device behavior

[0335] 1. Displaying a warning message:

[0336] The device displays a list of received emails to the user, and displays a warning icon for emails suspected of being BEC. The warning message is displayed with customized content based on the emotion engine.

[0337] 2. Emotion Recognition and Feedback:

[0338] The device uses an emotion engine to recognize the user's face and analyze their voice, and sends the results to a server, enabling it to respond appropriately to the user's emotional state.

[0339] User operations

[0340] 1. Check notifications:

[0341] Users can check the warning icon or notification displayed on their device and click on the warning message to view detailed information about the suspected BEC email.

[0342] 2. Email Operations:

[0343] Based on the warning message and the identified emotional state, users have the option to manually delete the email, move it to a quarantine folder, or reassess it as legitimate.

[0344] Specific examples

[0345] Scenario: A user is experiencing stress

[0346] 1. At the beginning of the month, the server generates a new BEC email using the generation AI and stores its signature in the database.

[0347] 2. The server retrieves new incoming emails from the company's email server every hour and determines that one of them is suspected to be a BEC scam.

[0348] 3. The server generates a warning message and sends it to the user.

[0349] 4. The device checks the user's emotional state using an emotion engine and recognizes that they are feeling stressed.

[0350] 5. The server changes the warning message to a softer tone based on the user's emotional state and sends it to the user.

[0351] 6. The user checks the warning notice displayed on the device and moves the relevant email to the quarantine folder.

[0352] This will reduce the psychological burden on users and realize a system that enables rapid and highly accurate detection of BEC emails.

[0353] The processing flow will be explained below.

[0354] Step 1:

[0355] At the beginning of each month, the server generates 20 new Business Email Compromise (BEC) emails using a generative AI tool, which stores the emails in a database and extracts their distinctive signatures.

[0356] Step 2:

[0357] The server sequentially adds and updates the database with signatures extracted from the 20 generated BEC emails. These signatures represent important characteristics and patterns of each BEC email.

[0358] Step 3:

[0359] The server collects BEC emails created by humans in the past, generates signatures for them, and adds them to the database, further strengthening the signature database and enabling high accuracy in detecting BEC emails.

[0360] Step 4:

[0361] The server retrieves new incoming emails from the company's mail server every hour, for example by connecting to the mail server using the IMAP or POP3 protocol to detect new incoming emails.

[0362] Step 5:

[0363] The server analyzes the content of the received emails and generates a signature for each email. The signature generation process uses the same method as for signatures extracted from BEC emails.

[0364] Step 6:

[0365] The server compares the generated signature of the received email with the BEC signatures in the database. The comparison algorithm calculates the degree of match between each signature, and if the degree of match is high, the email is determined to be suspected of being a BEC scam.

[0366] Step 7:

[0367] The server generates a warning message for any incoming emails suspected of being BEC emails, including information such as the sender, subject, and degree of similarity of the email.

[0368] Step 8:

[0369] The server activates an emotion engine to recognize the user's emotional state and receives emotion data from each user's device, including information based on facial recognition and voice analysis.

[0370] Step 9:

[0371] The server customizes the content and format of the warning message based on the user's emotional state as recognized by the emotion engine. For example, if the user is highly stressed, the message will be displayed in a gentle tone.

[0372] Step 10:

[0373] The server sends a customized warning message to the user's terminal, which helps the user to understand and respond to the warning appropriately.

[0374] Step 11:

[0375] The device will display a list of received emails and notify the user with a warning message. A warning icon will be displayed, allowing the user to identify emails that are suspected to be BEC.

[0376] Step 12:

[0377] The user clicks on the warning icon displayed on the device to check detailed information, reads the warning message adjusted by the emotion engine, and understands its content.

[0378] Step 13:

[0379] Users can follow the instructions in the warning message to move the affected email to a quarantine folder, delete it, or re-evaluate it as legitimate.

[0380] Step 14:

[0381] The server periodically checks the emails moved to the quarantine folder and automatically deletes them after a certain period of time, based on deletion rules set by the system administrator.

[0382] Step 15:

[0383] The server stores the emotion data collected by the emotion engine as a history and uses it to display future warning messages. This history data is used to display optimal warning messages that take into account the user's emotional state.

[0384] Example 2

[0385] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."

[0386] Business email compromise (BEC) is a major threat to companies, and its detection and response are extremely important. However, conventional systems not only have low accuracy in detecting BEC emails, but also often make it difficult for recipients to properly understand the warning messages. Furthermore, warning messages that do not take into account the recipient's emotional state can increase the psychological burden on users. Furthermore, there is a lack of countermeasures that utilize user emotional data, making it difficult to provide customized warning messages.

[0387] The specific processing by the specific processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means.

[0388] In this invention, the server includes means for generating multiple business email fraud emails using a generation AI, means for extracting signatures from the generated business email fraud emails, means for saving the extracted signatures in a database, means for acquiring received emails, means for generating signatures from the acquired received emails, means for comparing the generated signatures with signatures in the database, means for determining whether the received emails are suspected of being business email fraud based on the comparison results, means for generating a warning message for the relevant emails, means for sending the warning message to a user, means for moving or deleting the relevant emails to a quarantine folder, means for acquiring user emotion data using an emotion engine that recognizes the user's emotional state, means for customizing the warning message based on the acquired emotion data, and means for saving the user emotion data as a history in the database. This enables highly accurate detection of BEC emails and provision of appropriate warning messages, thereby reducing the psychological burden on users.

[0389] "Generative AI" refers to systems or algorithms that use artificial intelligence technology to automatically generate emails intended for business email compromise.

[0390] Business Email Compromise (BEC) refers to a fraudulent activity that targets corporate executives and employees by sending emails containing fraudulent instructions or requests in an attempt to defraud them of money or information.

[0391] A "signature" refers to a specific identifier used to identify and detect business email compromise emails, such as a characteristic phrase or link pattern.

[0392] A "database" is a data storage system that organizes and stores information so that it can be quickly searched and retrieved when needed.

[0393] An "emotion engine" refers to software or algorithms that analyze a user's facial expressions, voice, input data, etc. to recognize their emotional state.

[0394] "Warning messages" refer to notifications or alerts that warn users about emails that may be business email compromises.

[0395] A "quarantine folder" refers to a specific email folder that stores fraudulent or suspicious emails separately from other legitimate emails.

[0396] "Customization" refers to adjusting or changing content or presentation format based on the user's emotional state or specific conditions.

[0397] "History" refers to information that records events and data that occurred in the past and organizes them in chronological order.

[0398] MODE FOR CARRYING OUT THE INVENTION

[0399] This invention provides a system that uses generative AI to automatically detect business email compromise (BEC) emails and warn users, as well as a system that combines an emotion engine that recognizes user emotions. This system reduces the psychological burden on users and enables rapid and accurate detection of BEC emails.

[0400] Server Operation

[0401] At the beginning of each month, the server generates new BEC emails using a generative AI tool (such as OpenAI's GPT-4). An example prompt for generating emails is, "Generate a new business email compromise (BEC) scenario. The target is an executive at a midstream company who receives emails during the afternoon workday." The generated emails are stored in a database, and characteristic signatures are extracted from the emails.

[0402] The server stores the extracted signatures in a database and updates it regularly. It also collects BEC emails created by humans in the past and trains the AI ​​to improve the accuracy of the signature database. The server also retrieves newly received emails from the company's email server every hour and analyzes their contents. New signatures are generated from the analyzed emails.

[0403] The server compares the generated signature with existing BEC signatures in its database to determine whether they match. For emails suspected of being BEC, a warning message is generated and sent to the user's device. The warning message includes the characteristics of BEC emails and the steps the user should take, and the email is then moved to a quarantine folder or deleted.

[0404] Emotion Engine Operation

[0405] The device uses a built-in camera and microphone to capture the user's facial expressions, voice, and input data, which are then analyzed by an emotion engine (such as Microsoft's Azure Cognitive Services). The emotion data recognized through the analysis is then sent to a server.

[0406] The server adjusts the content and display format of the warning message based on the received emotional data. For example, if the user is feeling stressed, the warning message can be softened. For example, "Warning! This email may be fraudulent" can be changed to "Please be careful. This email may be fraudulent, so please check it."

[0407] Emotional data is stored in a database as a history, and warning messages are optimized using past emotional data, allowing for more appropriate and friendly warning messages to be provided to users.

[0408] Device behavior

[0409] The device will display a warning icon and a pop-up warning message on any emails suspected of being BEC emails in the user's email list. The user can click on the message to view detailed information about the BEC email.

[0410] The emotion engine allows the device to continuously analyze the user's facial expressions and voice and transmits the results to the server in real time, enabling it to respond appropriately to the user's emotional state.

[0411] User operations

[0412] Users can check the warning icon or notification displayed on their device and click to view detailed information about the suspected BEC email. Based on the warning message, they can manually delete the email, move it to a quarantine folder, or reevaluate it as legitimate.

[0413] This system takes into account the user's emotional state, detects BEC emails with high accuracy, and provides effective measures to reduce the psychological burden.

[0414] The flow of the identification process in the second embodiment will be described with reference to FIG.

[0415] Step 1: Generating BEC emails using generative AI

[0416] At the beginning of each month, the server uses the generative AI model to generate BEC emails. The prompt text is entered as "Generate a new business email compromise (BEC) scenario. The target is an executive at a mid-stream company, and the scenario is set to receive emails during work hours in the afternoon." Based on the entered prompt text, the generative AI model generates a BEC email, and its content is stored in a database. Characteristic signatures are extracted from the generated email and added to the database.

[0417] Input: prompt statement

[0418] Data processing: Generating BEC emails using AI and extracting signatures

[0419] Output: Generated BEC email, extracted signature

[0420] Step 2: Managing Signatures

[0421] The server stores the extracted signatures in a database and updates it regularly. It also collects BEC emails created by humans in the past and trains the AI ​​to improve the accuracy of the database. This process improves the accuracy of detecting BEC emails.

[0422] Input: Previous BEC emails, generated signatures

[0423] Data processing: Signature storage and learning

[0424] Output: Updated signature database

[0425] Step 3: Capture and analyze incoming emails

[0426] The server retrieves new incoming emails from the company's mail server every hour, analyzes them immediately, and generates new signatures from the email body and header information.

[0427] Input: Newly received email

[0428] Data processing: Email analysis, signature generation

[0429] Output: Generated signature

[0430] Step 4: Signature Matching

[0431] The server compares the generated signature with existing BEC signatures in its database. If the signatures match, the email is deemed to be a suspected BEC scam. Specifically, text mining technology is used to analyze the email content and match it with existing BEC signatures.

[0432] Input: Generated signature

[0433] Data processing: Signature comparison

[0434] Output: Comparison result (match / mismatch)

[0435] Step 5: Generate and send an alert

[0436] The server generates a warning message for emails suspected of being BEC scams and sends it to the user's device. The generated warning message includes the characteristics of BEC emails and the measures the user should take. The server also automatically moves the email to a quarantine folder or deletes it.

[0437] Input: Comparison result (if match)

[0438] Data processing: Generate warning messages, move / delete emails

[0439] Output: Warning message, email moved to quarantine / deleted email

[0440] Step 6: Emotion Recognition

[0441] The device uses a built-in camera and microphone to capture the user's facial expressions and voice, and analyzes the input data with an emotion engine. The user's emotional data recognized through the analysis is then sent to the server.

[0442] Input: User's facial expression and voice data

[0443] Data processing: Emotion analysis using an emotion engine

[0444] Output: User emotion data

[0445] Step 7: Customizing the warning message

[0446] The server customizes the content and display format of the warning message based on the user's emotional data. For example, if the user is feeling stressed, the server changes the tone of the warning message to a gentler tone. This customization information is also stored in the database.

[0447] Input: User emotion data

[0448] Data Processing: Customizing warning messages

[0449] Output: Customized warning message

[0450] Step 8: Displaying warning messages

[0451] The device will display a warning icon next to suspected BEC emails in the user's email list, and when the user clicks on the icon, a customized warning message will pop up.

[0452] Input: Customized warning message

[0453] Data processing: Display warning message

[0454] Output: Warning icon, popup message

[0455] Step 9: User interaction

[0456] Users can check the warning icons and notifications displayed on their devices, click on them to view detailed information about the suspected BEC email, and then manually delete the email, move it to a quarantine folder, or reassess it as legitimate.

[0457] Input: Warning notification, more information

[0458] Data processing: Email operations (manual deletion, movement, re-evaluation)

[0459] Output: Updated email status (delete, quarantine, reevaluate)

[0460] In this way, the entire system works together to detect BEC emails with high accuracy while reducing the psychological burden on users, and provides appropriate warnings and quick responses.

[0461] (Application example 2)

[0462] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."

[0463] When sending or receiving business emails, there is a need for a system that can automatically detect business email compromise (BEC) emails with high accuracy and issue appropriate warnings to users. However, conventional systems use uniform warning messages, making it difficult to respond flexibly to the user's emotional state. This increases the user's psychological burden, and can lead to delayed responses or oversight of messages. To solve these issues, a flexible warning system that takes into account the user's emotional state as well as highly accurate detection of BEC emails is required.

[0464] The identification process by the identification processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means. In this invention, the server includes: means for generating multiple business email fraud emails using a generation AI; means for extracting signatures from the generated business email fraud emails; means for saving the extracted signatures in a database; means for acquiring received emails; means for generating signatures from the acquired received emails; means for comparing the generated signatures with signatures in the database; means for determining whether the received emails are suspected of being business email fraud based on the comparison results; means for generating a warning message for the relevant emails; means for sending the warning message to a user; means for moving or deleting the relevant emails to a quarantine folder; means for recognizing a user's emotional state and acquiring emotional data; means for customizing the warning message based on the acquired emotional data; and means for saving and managing the emotional data history in a database. This enables highly accurate detection of BEC emails and flexible display of warning messages according to the user's emotional state.

[0465] "Generative AI" is an artificial intelligence system that uses machine learning and neural network techniques to automatically generate new data patterns and text.

[0466] "Business email compromise" refers to fraudulent emails sent to businesses or organizations with the intent of fraudulently obtaining financial or other sensitive information.

[0467] A "signature" is data that indicates characteristics specific to fraudulent emails, extracted based on the content and structure of the email.

[0468] A "database" is a system or software for storing and managing data efficiently and systematically.

[0469] "Emotion recognition" is the technology of identifying a person's emotional state through the analysis of facial expressions, voice tone, and text.

[0470] A "warning message" is a message that contains information to notify a user of a particular situation or condition and to call their attention.

[0471] A "quarantine folder" is an email folder that stores suspicious or malicious emails separately from your regular inbox.

[0472] "History management" is a system or process that stores records of past data or events so that they can be analyzed and referenced.

[0473] This invention relates to a system that uses a generative AI system to detect business email compromise (BEC) emails with high accuracy, warn users, and understand the user's emotional state and customize the warning message based on that.

[0474] Server Operation Overview

[0475] The server system is constructed using the following hardware and software: The hardware is a server computer equipped with a high-performance processor, memory, and storage. The software uses a generative AI tool, a database system (MySQL), an email analysis library (Apache James), an emotion recognition engine (Microsoft's Azure Emotional Analysis API), and a backend framework (Node.js, Express).

[0476] At the beginning of the month, the server uses the generative AI model to generate new BEC emails, extracts characteristic signatures from these emails, and stores them in a database.

[0477] The server retrieves new incoming emails from the company's email server every hour and analyzes their contents using an email analysis library. The analyzed email signatures are compared with the BEC signatures in the existing database. If a suspicious email is found, a warning message is generated for that email.

[0478] The server uses Microsoft's Azure Emotional Analysis API to obtain user emotional data and determine the emotional state the user was in when receiving the email. This emotional data is then stored in a database as a history.

[0479] About device operation

[0480] The system operates using the following technologies on user devices, which can be smartphones, tablets, or desktop computers. The devices use Google ML Kit to analyze facial expressions and voice tones to obtain emotion data.

[0481] When a user receives an email on their device, the emotion recognition system captures their facial expressions and voice and analyzes their emotional state in real time, and this data is sent to the server.

[0482] The warning message sent from the server is customized according to the user's emotional state and displayed on the device. For example, if the user is determined to be in a stressful state, the warning message will be displayed in a soft tone.

[0483] User operations

[0484] The user can check the warning message displayed on the terminal and check the detailed information of the email.

[0485] You can choose to move the email to a quarantine folder, delete it, or re-evaluate it as legitimate.

[0486] Examples of concrete examples and prompts

[0487] Specific examples

[0488] While a user is checking work emails on their smartphone while out and about, the server determines that they have received a BEC email. If the emotion engine determines that the user is under stress, it changes the usual stiff warning message to a softer tone, saying, "Thank you for your hard work. An email requiring your attention has been found. Please remain calm and take appropriate action."

[0489] Prompt Sentence Examples

[0490] Generate customized warning messages when the user's emotional state is stressed.

[0491] Original warning message:

[0492] "Warning! Suspicious email found. Please review immediately."

[0493] Customized warning message:

[0494] "Thank you for your hard work. We've found an email that needs your attention. Please stay calm and take care of it."

[0495] In this way, we provide a system that reduces the psychological burden on users and strengthens security through BEC email detection and emotion-customized warning messages.

[0496] The flow of the specific processing in the application example 2 will be described with reference to FIG.

[0497] Step 1:

[0498] The server uses the generative AI model to generate new BEC emails at the beginning of each month. It extracts characteristic signatures from the generated emails and stores them in a database. The input is the email data generated by the generative AI model, and the output is the extracted signature data. New signature information is added to the database.

[0499] Step 2:

[0500] The server retrieves new incoming emails from the company's email server every hour. It uses an email analysis library (Apache James) to analyze the content of the retrieved emails and generate a signature from them. The input is new email data retrieved from the company's email server, and the output is the generated signature data. The signature is obtained by analyzing the email content.

[0501] Step 3:

[0502] The server compares the generated signature with existing BEC signatures in the database. Based on the comparison results, it determines whether the received email is suspected of being a business email compromise. The input is the newly generated signature and existing signatures in the database, and the output is the determination result of whether or not there is suspicion of BEC. The signature is matched by referring to the information in the database.

[0503] Step 4:

[0504] The server generates a warning message for emails that are suspected of being BEC attacks. The input is the email data that is suspected of being BEC attacks, and the output is the warning message. The generated warning message is created based on a template.

[0505] Step 5:

[0506] The server sends the generated warning message to the user's terminal. The input is the generated warning message, and the output is the successful transmission of the warning message to the user's terminal. The message is sent to the user's terminal via the network.

[0507] Step 6:

[0508] When receiving a warning message, the device captures facial expressions and voice to obtain emotional data in order to recognize the user's emotional state. Analysis is performed using Google ML Kit. The input is the user's facial expression data and voice data, and the output is the recognized emotional data. The emotional state is analyzed in real time and sent to the server.

[0509] Step 7:

[0510] The server customizes the warning message based on the acquired emotion data. The input is the recognized emotion data and the original warning message, and the output is the customized warning message. The message content is adjusted based on the emotion data.

[0511] Step 8:

[0512] The terminal displays a customized warning message to the user. The input is the customized warning message, and the output is the warning message displayed on the terminal screen. The message is presented to the user visually and audibly.

[0513] Step 9:

[0514] The user checks the warning icon or notification displayed on the device and views the details of the received email. The input is the warning notification displayed on the device, and the output is the detailed information of the email viewed by the user. The user clicks on the warning message to view the details.

[0515] Step 10:

[0516] The user can move the email to a quarantine folder, delete it, or reassess it as legitimate. The input is the user's choice of action, and the output is the quarantine, new assessment, or deletion of the email. The user selects the appropriate action, and the system processes the email according to that choice.

[0517] The specific processing unit 290 transmits the result of the specific processing to the smart device 14. In the smart device 14, the control unit 46A causes the output device 40 to output the result of the specific processing. The microphone 38B acquires audio indicating a user input regarding the result of the specific processing. The control unit 46A transmits audio data indicating the user input acquired by the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.

[0518] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search<url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[0519] In the above embodiment, an example in which the specific process is performed by the data processing device 12 has been given, but the technology of the present disclosure is not limited to this, and the specific process may be performed by the smart device 14.

[0520] [Second embodiment]

[0521] FIG. 3 shows an example of the configuration of a data processing system 210 according to the second embodiment.

[0522] 3, the data processing system 210 includes the data processing device 12 and smart glasses 214. An example of the data processing device 12 is a server.

[0523] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[0524] The smart glasses 214 include a computer 36, a microphone 238, a speaker 240, a camera 42, and a communication I / F 44. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The microphone 238, the speaker 240, and the camera 42 are also connected to the bus 52.

[0525] The microphone 238 receives instructions and the like from the user 20 by receiving voice uttered by the user 20. The microphone 238 captures the voice uttered by the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio in accordance with instructions from the processor 46.

[0526] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the surroundings of user 20 (for example, an imaging range defined by an angle of view equivalent to the field of vision of a typical healthy person).

[0527] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 are responsible for the exchange of various information between the processor 46 and the processor 28 via the network 54. The exchange of various information between the processor 46 and the processor 28 using the communication I / Fs 44 and 26 is carried out in a secure state.

[0528] Fig. 4 shows an example of the main functions of the data processing device 12 and the smart glasses 214. As shown in Fig. 4, in the data processing device 12, a specific process is performed by the processor 28. A specific process program 56 is stored in the storage 32.

[0529] The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[0530] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[0531] In the smart glasses 214, the reception output process is performed by the processor 46. A reception output program 60 is stored in the storage 50. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.

[0532] Next, a description will be given of the identification process performed by the identification processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as the "server" and the smart glasses 214 will be referred to as the "terminal."

[0533] The system of this invention uses generative AI to automatically detect business email compromise (BEC) emails and warn users. It also prevents BEC damage by moving the emails to a quarantine folder or deleting them. The details of the system and the program processing are explained below.

[0534] Server Operation

[0535] 1. Generating BEC emails using AI:

[0536] The server automatically generates new BEC emails at the beginning of each month or every few weeks using a generative AI tool, which uses advanced natural language processing techniques to make the emails appear like regular business emails.

[0537] The server stores the content of generated BEC emails in a database and extracts characteristic signatures from those emails.

[0538] 2. Signature Management:

[0539] The server sequentially adds signatures extracted from the generated BEC emails to the database and updates it regularly. It also trains the generation AI to learn from past BEC emails created by humans, strengthening these signatures.

[0540] 3. Acquiring and analyzing incoming emails:

[0541] The server periodically retrieves new incoming emails from the company's email server. For example, you can configure it to retrieve incoming emails every hour.

[0542] The server analyzes the content of the received emails and generates signatures from these emails as well.

[0543] 4. Signature Matching:

[0544] The server compares the generated signature with the signatures in its database to determine if there is a match.

[0545] 5. Generate and send alerts:

[0546] The server generates a warning message for any emails that match the signature. The warning message contains information about the email and indicates that it is suspected of being a BEC scam.

[0547] The server generates a warning message, sends it to the user, and moves the affected email to a quarantine folder or deletes it.

[0548] Device behavior

[0549] 1. Providing the user interface:

[0550] The terminal displays a list of received emails to the user and displays a warning icon based on the results of the system's automatic analysis.

[0551] The terminal displays a warning message so that the user can check the details of the received email.

[0552] 2. Receiving and acting on warning messages:

[0553] The terminal notifies the user of the warning message received from the server together with its contents.

[0554] When a warning message appears on the device, the user is given the option to easily move the email to a quarantine folder or delete it.

[0555] User operations

[0556] 1. Check notifications:

[0557] The user checks the warning icon or notification displayed on the device.

[0558] The user clicks on the warning message to view the details and realizes that it may be a BEC email.

[0559] 2. Email Operations:

[0560] After reviewing the warning message, users can choose to move the email to a quarantine folder, delete it, or re-evaluate it as legitimate.

[0561] Specific examples

[0562] Scenario 1:

[0563] 1. At the beginning of each month, the server generates 20 new BEC emails using the generation AI and stores their signatures in a database.

[0564] 2. Check incoming emails every hour and analyze their contents.

[0565] 3. During a certain period of time, an incoming email is detected that matches the signature of a generated BEC email.

[0566] 4. The server generates a warning message and moves the affected email to a quarantine folder.

[0567] 5. A warning notification will appear on the user's device, and the user will check the email, confirm that it is a scam, and delete it.

[0568] This makes it possible to detect BEC emails quickly and accurately, preventing harm to users before it occurs.

[0569] The processing flow will be explained below.

[0570] Step 1:

[0571] At the beginning of each month, the server launches the AI ​​tool to generate 20 new Business Email Compromise (BEC) emails. The generated emails are written in a natural style and are designed to look like real business emails.

[0572] Step 2:

[0573] The server extracts characteristic signatures from the 20 generated BEC emails and stores them in a database. The signatures represent important characteristics and patterns of each BEC email.

[0574] Step 3:

[0575] The server collects BEC emails created by humans in the past, generates signatures for them, and adds them to the database, further strengthening the signature database.

[0576] Step 4:

[0577] The server retrieves new incoming emails from the company's mail server every hour, for example by connecting to the mail server and finding the latest incoming emails.

[0578] Step 5:

[0579] The server analyzes the content of the received email and generates a signature from it. This signature generation process uses the same method as the signature of the BEC email saved earlier.

[0580] Step 6:

[0581] The server compares the generated signature of the received email with the BEC signatures in the database. The comparison algorithm calculates the degree of match between each signature, and if there is a high degree of match, the email is determined to be suspected of being a BEC scam.

[0582] Step 7:

[0583] If the match is high, the server generates a warning message and sends it to the user's device, including information about the email, such as the sender, subject, and match level.

[0584] Step 8:

[0585] The server will move any incoming email that generates a warning message to a quarantine folder, and can be configured to automatically delete the email if desired.

[0586] Step 9:

[0587] The device displays a list of received emails and notifies the user of any warning messages received from the server. The warning icon allows the user to identify suspicious emails at a glance.

[0588] Step 10:

[0589] The user can click the warning icon displayed on the device to view the details of the warning message. The user can also check the contents of the email and view further details.

[0590] Step 11:

[0591] Users can follow the instructions in the warning message to manually delete the email or move it to a quarantine folder, or if they determine it to be legitimate, they can choose to move it back to a regular folder.

[0592] Step 12:

[0593] The server periodically checks the emails moved to the quarantine folder and deletes them after a certain period of time. The deletion rules and storage period are set by the administrator.

[0594] Example 1

[0595] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."

[0596] In today's business environment, fraud via business email counterfeiting (BEC) has become a major problem. In particular, the risk of companies and individuals suffering financial losses due to users receiving sophisticated forged emails is increasing. Conventional email filtering systems have difficulty effectively detecting and preventing these sophisticated forged emails, and new systems are needed to ensure user safety.

[0597] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.

[0598] In this invention, the server includes means for generating multiple counterfeit business emails using a generation AI, means for extracting characteristic patterns from the generated counterfeit business emails, means for saving the extracted characteristic patterns in a database, means for acquiring received emails, means for generating characteristic patterns from the acquired received emails, means for comparing the generated characteristic patterns with characteristic patterns in the database, means for determining whether the received emails are suspected of being counterfeit business emails based on the comparison results, means for generating a warning message for the corresponding emails, means for sending the warning message to the user, means for moving or deleting the corresponding emails to a quarantine folder, means for generating a warning message including an overview of the corresponding emails and a warning message and notifying the user of the warning message, and means for providing operation options for quarantining, deleting, or reevaluating the emails as legitimate, thereby enabling rapid and highly accurate detection and prevention of BEC emails.

[0599] "Generative AI" is a system that uses artificial intelligence technology to automatically generate new content (in this case, counterfeit business emails).

[0600] "Forged business email" is a forged email disguised as a normal business email sent with the intent to defraud.

[0601] A "characteristic pattern" is a specific pattern contained in elements such as email content, subject, sender address, and destination URL, and is used to identify counterfeit business emails.

[0602] A "database" is a structured information storage system for effectively storing and managing the generated characteristic patterns.

[0603] "Incoming email" refers to all emails received by a company or user.

[0604] The "warning message" is a warning message that notifies the user that the received email may be a forged business email.

[0605] A "quarantine folder" is a specific email folder that temporarily stores suspicious emails and keeps them separate from other regular emails.

[0606] "Action options" are the choices provided to a user to take action on a suspicious email (e.g., quarantine, delete, reassess).

[0607] The system of this invention uses generative AI to automatically detect forged emails intended for business email compromise (BEC) and warn users. It also prevents BEC damage by moving or deleting the forged emails in question to a quarantine folder.

[0608] Server Operation

[0609] Generating BEC emails using generative AI

[0610] The server automatically generates new BEC emails periodically using a generative AI tool (e.g., GPT-4). This allows emails based on the latest fraud techniques to be constantly added to the database. The server inputs prompt phrases such as "invoice from a customer" or "urgent payment request" into the generative AI, and saves the generated email content in the database.

[0611] Extracting and saving signatures

[0612] The server extracts characteristic patterns (signatures) from the generated BEC emails and stores them in a database using a natural language processing (NLP) algorithm to extract distinctive patterns from the email body, subject, sender address, destination URL, etc.

[0613] Acquiring and analyzing received emails

[0614] The server periodically retrieves new incoming emails from the company's mail server using IMAP or POP3 protocols, analyzes the emails using NLP algorithms, and generates signatures.

[0615] Signature Matching

[0616] The server analyzes the signature of the incoming email and compares it with the signatures in its existing database using fast search algorithms (e.g. hash functions or binary searches). If a match is found, the email is marked as suspected BEC.

[0617] Generate and send alerts

[0618] The server generates a warning message for any emails suspected of being BEC. This message includes a summary of the email and a warning. The warning message is sent to the user, and the email is moved to a quarantine folder or deleted.

[0619] Device behavior

[0620] Providing a user interface

[0621] The terminal displays a list of received emails and a warning icon to the user. If an abnormality is detected in an email, a warning icon will be displayed, and clicking the icon will display a detailed warning message in a pop-up.

[0622] Receiving and acting on warning messages

[0623] The terminal notifies the user of warning messages from the server and provides action options (quarantine, delete, or reassess as legitimate email), allowing the user to handle the email quickly and accurately.

[0624] User operations

[0625] Checking notifications

[0626] Users can check the warning icon or notification displayed on their device and click to open the details of the warning message to get a detailed understanding of whether the email is suspected to be a BEC scam.

[0627] Email Operations

[0628] After reviewing the warning message, users can choose to move the email to a quarantine folder, delete it, or re-evaluate it as legitimate.

[0629] Specific examples

[0630] Scenario 1:

[0631] 1. At the beginning of each month, the server generates 20 new BEC emails using the generation AI and stores their signatures in a database. An example prompt is "Generate an email proposing a new invoice format."

[0632] 2. Check incoming emails every hour and analyze their contents using natural language processing algorithms.

[0633] 3. During a certain period of time, the server detects that an incoming email matches the signature of a generated BEC email and records this as a flag.

[0634] 4. The server generates a warning message and moves the affected email to a quarantine folder.

[0635] 5. A warning notification will appear on the user's device, and the user will check the email, determine that it is a scam, and delete it.

[0636] This makes it possible to detect and prevent BEC emails quickly and accurately, preventing harm to users before it occurs.

[0637] The flow of the identification process in the first embodiment will be described with reference to FIG.

[0638] Step 1:

[0639] Generating BEC emails using generative AI

[0640] The server generates BEC emails using a generative AI model (e.g., GPT-4) and inputs a prompt such as "Generate an email proposing a new invoice format."

[0641] Input: Prompt text "Generate an email proposing a new invoice format."

[0642] Data processing: The generative AI model uses natural language processing based on the prompt text to generate fraudulent business emails.

[0643] Output: The generated BEC email.

[0644] Specific operation: The server saves the automatically generated email as a file and converts its content into a text format for analysis.

[0645] Step 2:

[0646] Extracting and saving signatures

[0647] The server extracts characteristic patterns (signatures) from the content of the generated BEC email.

[0648] Input: The generated BEC email.

[0649] Data processing: Using natural language processing algorithms, characteristic patterns are extracted from elements such as the email body, subject, sender address, and destination URL.

[0650] Output: The extracted signature.

[0651] Specific operation: The server adds the extracted signature to a database and creates an index to match and classify it with existing signatures.

[0652] Step 3:

[0653] Acquiring and analyzing received emails

[0654] The server periodically retrieves new incoming emails from the company's mail server.

[0655] Input: Incoming emails stored on your company's email server.

[0656] Data processing: Received emails are imported to the server using the IMAP or POP3 protocol, and the email content is analyzed using natural language processing algorithms.

[0657] Output: Parsed signature of the incoming email.

[0658] How it works: The server communicates with the mail server every hour, downloads new emails, and analyzes them using techniques such as tokenization and feature extraction.

[0659] Step 4:

[0660] Signature Matching

[0661] The server analyzes the signature of the incoming email and compares it with the signatures in its existing database.

[0662] Input: Parsed signatures from incoming emails and signatures in the database.

[0663] Data processing: Using a fast search algorithm (e.g. hash function or binary search) to match the signature.

[0664] Output: A list of matching signatures.

[0665] What it does: The server goes through a matching process, lists matching signatures, and flags emails that are suspected to be BEC.

[0666] Step 5:

[0667] Generate and send alerts

[0668] The server generates a warning message for emails suspected of being BEC and sends it to the user.

[0669] Input: Incoming email where a matching signature was found.

[0670] Data processing: Generate a warning message that includes a summary of the email and a warning.

[0671] Output: A warning message.

[0672] Specific actions: The server will send a warning message to the user's email address and simultaneously move the email to a quarantine folder or delete it.

[0673] Step 6:

[0674] Providing a user interface

[0675] The terminal displays a list of received emails and a warning icon to the user.

[0676] Input: Incoming emails and warning messages from the server.

[0677] Data Processing: Added warning icon and popup warning message.

[0678] Output: The email list and warning messages displayed in the user interface.

[0679] Specific operation: The terminal displays a list of received emails to the user through the email client software and provides an interface including a warning icon.

[0680] Step 7:

[0681] Receiving and acting on warning messages

[0682] Users can review the warning message and quarantine, delete, or reevaluate the email as legitimate.

[0683] Input: Warning messages and action options displayed on the terminal.

[0684] Data manipulation: Moves the email to a quarantine folder, deletes it, or re-evaluates it based on the user's choice.

[0685] Output: Change the state of the email depending on the user's selection.

[0686] Specific actions: The user checks the warning icon displayed on the device, clicks it to open a detailed warning message, and then performs the action on the relevant email.

[0687] (Application example 1)

[0688] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."

[0689] Conventional business email compromise (BEC) countermeasure systems rely on static rule-based analysis, making it difficult to respond quickly to new and changing fraudulent methods. Furthermore, users have few ways to know in real time whether an email they receive is fraudulent, making it difficult to take appropriate action immediately and preventing damage before it occurs. Furthermore, the user interface when a fraudulent email is detected is inadequate, making it difficult for users to easily and quickly handle the email.

[0690] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.

[0691] In this invention, the server includes: means for generating multiple business email fraud emails using a generation AI; means for extracting signatures from the generated business email fraud emails; means for storing the extracted signatures in a database; means for acquiring received emails; means for generating signatures from the acquired received emails; means for comparing the generated signatures with signatures in the database; means for determining whether the received emails are suspected of being business email fraud based on the comparison results; means for generating a warning message for the suspected emails; means for sending the warning message to a user; means for moving the suspected emails to a quarantine folder or deleting them; means for notifying the user of the warning message in real time on a mobile device of the user and providing a user interface that allows the user to move the suspected emails to a quarantine folder, delete them, or reassess them as legitimate; and means for the user to review and manipulate the suspected fraud emails. This enables advanced fraud email detection and real-time notification using the generation AI, as well as a user-friendly operation interface, thereby preventing fraud damage before it occurs.

[0692] "Generative AI" refers to a model that uses artificial intelligence technology to generate artificial content.

[0693] "Business email compromise" refers to a method of committing forgery or fraud by disguising emails as business-related.

[0694] A "signature" refers to a characteristic pattern or identifier contained in the content of an email.

[0695] "Database" refers to a system that collects and manages signatures and important data in one place.

[0696] "Mobile device" refers to a portable electronic device such as a smartphone or tablet.

[0697] "User interface" refers to the display screen and operating means through which a user interacts with a system.

[0698] A "quarantine folder" is a folder that stores suspicious or fraudulent emails received separately from other emails.

[0699] "Real-time notification" refers to a function that notifies the user of information immediately at the moment a relevant event occurs.

[0700] "Reevaluating as legitimate" refers to the user manually reconfirming an email as legitimate when the email has been mistakenly determined to be fraudulent.

[0701] "User" refers to an individual or company that uses this system.

[0702] The system of this invention uses a generative AI model to automatically detect fraudulent emails and send warning notifications to users in order to prevent damage caused by business email compromise (BEC). The operation of the server and terminal is described in detail below.

[0703] Server Operation

[0704] 1. Generating BEC emails using AI:

[0705] The server periodically generates new BEC emails using a generative AI model, which uses advanced natural language processing techniques to make the emails appear like regular business emails.

[0706] The content of the generated BEC emails is stored in a database and characteristic signatures are extracted from those emails.

[0707] 2. Signature Management:

[0708] The server sequentially adds the signatures extracted from the generated BEC emails to the database and updates it periodically.

[0709] The generation AI also learns from past artificially created BEC emails to strengthen the signature.

[0710] 3. Acquiring and analyzing incoming emails:

[0711] The server connects to the company's mail server and periodically (for example, every hour) retrieves new incoming emails.

[0712] It analyzes the emails it receives and generates signatures from them.

[0713] 4. Signature Matching:

[0714] The server compares the generated signature with the signatures in its database to determine if there is a match.

[0715] 5. Generate and send alerts:

[0716] If a signature matches an incoming email, a warning message will be generated containing information about the email.

[0717] The server sends the generated warning message to the user's mobile device and moves or deletes the relevant email in a quarantine folder.

[0718] Device behavior

[0719] 1. Providing the user interface:

[0720] The user interface displays a list of received emails to the user and displays a warning icon based on the results of automatic analysis by the system.

[0721] A warning message will be displayed, allowing the user to view details of the affected received email.

[0722] 2. Receiving and acting on warning messages:

[0723] The terminal notifies the user of the warning message received from the server together with its contents.

[0724] When a warning message appears, users are given the option to move the email to a quarantine folder or delete it.

[0725] User operations

[0726] 1. Check notifications:

[0727] The user checks the warning icon or notification displayed on the device.

[0728] Click on the warning message to see more details and understand that it may be a BEC email.

[0729] 2. Email Operations:

[0730] After checking the contents of the warning message, the user can choose to move the email to a quarantine folder, delete it, or re-evaluate it as legitimate.

[0731] Specific examples

[0732] If a user receives an email during a certain time period saying, "Please change the transfer destination to this address," the server analyzes the email and detects that it matches the signature of a previous BEC email. The server then sends a warning notification to the user's mobile device in real time and moves the email to a quarantine folder. The user who receives this notification can click on the warning message to check the details of the email and, if necessary, delete it as a fraudulent email.

[0733] Prompt Sentence Examples

[0734] "Email body: 'Thank you for your hard work. Your bank transfer details have changed, so we are sending you the new account details. Please confirm and confirm...'"

[0735] The above system enables advanced fraudulent email detection using generative AI, real-time notification, and a user-friendly operation interface, making it possible to prevent fraudulent incidents before they occur.

[0736] The flow of the specific processing in the application example 1 will be described with reference to FIG.

[0737] Step 1:

[0738] The server uses AI to generate multiple business email compromise emails.

[0739] Input: Enter a prompt for the generative AI model. "Email body: 'Thank you for your hard work. Your bank transfer details have changed, so we are sending you the new account details. Please confirm and confirm...'"

[0740] How it works: It uses a generative AI model (e.g., GPT-2) to generate BEC emails based on prompts.

[0741] Output: The generated BEC email.

[0742] Step 2:

[0743] The server extracts the signature from the generated BEC email.

[0744] Input: The generated BEC email.

[0745] How it works: Analyzes email content and extracts signatures (characteristic patterns or identifiers).

[0746] Output: The extracted signature.

[0747] Step 3:

[0748] The server stores the extracted signatures in a database.

[0749] Input: The extracted signature.

[0750] Behavior: Saves the signature to the database and updates the existing signature list.

[0751] Output: The updated database.

[0752] Step 4:

[0753] The server retrieves the incoming email.

[0754] Input: Your mail server login and connection information.

[0755] What it does: It connects to your company's mail server using the IMAP protocol and retrieves new incoming emails.

[0756] Output: The received emails retrieved.

[0757] Step 5:

[0758] The server generates a signature from the received email.

[0759] Input: The received emails retrieved.

[0760] How it works: Analyzes incoming emails and generates a new signature from their contents.

[0761] Output: The new signature.

[0762] Step 6:

[0763] The server compares the newly generated signature with the signatures in its database.

[0764] Input: New signatures and existing signatures in the database.

[0765] How it works: It runs an algorithm that compares the new signature with signatures in the database to determine if there is a match.

[0766] Output: Comparison result (match / not match).

[0767] Step 7:

[0768] The server generates a warning message for the affected email.

[0769] Input: Comparison result (if the signatures match).

[0770] Behavior: Generates a warning message containing the contents of the email.

[0771] Output: The warning message generated.

[0772] Step 8:

[0773] The server sends a warning message to the user's mobile device.

[0774] Input: The generated warning message and the user's mobile device information.

[0775] What it does: Sends a warning message to the user's mobile device.

[0776] Output: The warning message displayed on the user's mobile device.

[0777] Step 9:

[0778] The server moves the email to a quarantine folder or deletes it.

[0779] Input: Comparison result (if signature matches) and corresponding received email.

[0780] Action: The email will be moved from the inbox to a quarantine folder or deleted.

[0781] Output: Emails moved to quarantine folder or deleted.

[0782] Step 10:

[0783] The device will notify the user of a warning message and allow them to check and handle the relevant email.

[0784] Input: The warning message sent by the server.

[0785] What it does: Displays a warning message to the user, offering further details and options to delete the email or move it to a quarantine folder.

[0786] Output: User interaction to manage emails.

[0787] Step 11:

[0788] The user checks the relevant email and takes action.

[0789] Input: The warning message displayed on the terminal and detailed information about the email in question.

[0790] Action: The user reviews the email details and takes action to move it to quarantine, delete it, or reassess it as legitimate.

[0791] Output: Operation result (quarantine, delete, or re-evaluate the email).

[0792] Furthermore, an emotion engine that estimates the user's emotion may be further combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59, and perform identification processing using the user's emotion.

[0793] Overall overview

[0794] This invention provides a system that uses generative AI to automatically detect business email compromise (BEC) emails and warn users, as well as a system that combines an emotion engine that recognizes the user's emotions. This system has functions to reduce the psychological burden on users, such as adjusting and customizing warning messages based on their emotional state and managing emotional data history.

[0795] Server Operation

[0796] 1. Generating BEC emails using AI:

[0797] At the beginning of each month, the server uses a generative AI tool to generate new Business Email Compromise (BEC) emails, which are then stored in a database and characteristic signatures are extracted from the emails.

[0798] 2. Signature Management:

[0799] The server stores the signatures extracted from the generated emails in a database and updates it regularly. It also collects BEC emails created by humans in the past and trains the generation AI on them. This strengthens the signature database and enables highly accurate detection.

[0800] 3. Acquiring and analyzing incoming emails:

[0801] The server retrieves new incoming emails from the company's mail server every hour and analyzes their contents, generating a signature from the incoming email.

[0802] 4. Signature Matching:

[0803] The server compares the signature generated from the received email with the BEC signatures in its database to determine if there is a match.

[0804] 5. Generate and send alerts:

[0805] The server generates a warning message for any incoming emails suspected of being BEC scams based on the signature matching results. The generated warning message is sent to the user's device, and the email is then moved to a quarantine folder or deleted.

[0806] Emotion Engine Operation

[0807] 1. Emotion recognition:

[0808] The device analyzes the user's facial expressions, voice, and input data, and recognizes the user's emotional state using an emotion engine. The recognized emotional data is then sent to the server.

[0809] 2. Customize the warning message:

[0810] The server customizes the content and presentation of the warning message based on the user's emotional state, for example, if the user is stressed, the warning message will be displayed in a more understandable and gentle tone.

[0811] 3. Emotion data history management:

[0812] The server stores the user's emotional state as historical data, which allows for optimization of warning messages based on past emotional data.

[0813] Device behavior

[0814] 1. Displaying a warning message:

[0815] The device displays a list of received emails to the user, and displays a warning icon for emails suspected of being BEC. The warning message is displayed with customized content based on the emotion engine.

[0816] 2. Emotion Recognition and Feedback:

[0817] The device uses an emotion engine to recognize the user's face and analyze their voice, and sends the results to a server, enabling it to respond appropriately to the user's emotional state.

[0818] User operations

[0819] 1. Check notifications:

[0820] Users can check the warning icon or notification displayed on their device and click on the warning message to view detailed information about the suspected BEC email.

[0821] 2. Email Operations:

[0822] Based on the warning message and the identified emotional state, users have the option to manually delete the email, move it to a quarantine folder, or reassess it as legitimate.

[0823] Specific examples

[0824] Scenario: A user is experiencing stress

[0825] 1. At the beginning of the month, the server generates a new BEC email using the generation AI and stores its signature in the database.

[0826] 2. The server retrieves new incoming emails from the company's email server every hour and determines that one of them is suspected to be a BEC scam.

[0827] 3. The server generates a warning message and sends it to the user.

[0828] 4. The device checks the user's emotional state using an emotion engine and recognizes that they are feeling stressed.

[0829] 5. The server changes the warning message to a softer tone based on the user's emotional state and sends it to the user.

[0830] 6. The user checks the warning notice displayed on the device and moves the relevant email to the quarantine folder.

[0831] This will reduce the psychological burden on users and realize a system that enables rapid and highly accurate detection of BEC emails.

[0832] The processing flow will be explained below.

[0833] Step 1:

[0834] At the beginning of each month, the server generates 20 new Business Email Compromise (BEC) emails using a generative AI tool, which stores the emails in a database and extracts their distinctive signatures.

[0835] Step 2:

[0836] The server sequentially adds and updates the database with signatures extracted from the 20 generated BEC emails. These signatures represent important characteristics and patterns of each BEC email.

[0837] Step 3:

[0838] The server collects BEC emails created by humans in the past, generates signatures for them, and adds them to the database, further strengthening the signature database and enabling high accuracy in detecting BEC emails.

[0839] Step 4:

[0840] The server retrieves new incoming emails from the company's mail server every hour, for example by connecting to the mail server using the IMAP or POP3 protocol to detect new incoming emails.

[0841] Step 5:

[0842] The server analyzes the content of the received emails and generates a signature for each email. The signature generation process uses the same method as for signatures extracted from BEC emails.

[0843] Step 6:

[0844] The server compares the generated signature of the received email with the BEC signatures in the database. The comparison algorithm calculates the degree of match between each signature, and if the degree of match is high, the email is determined to be suspected of being a BEC scam.

[0845] Step 7:

[0846] The server generates a warning message for any incoming emails suspected of being BEC emails, including information such as the sender, subject, and degree of similarity of the email.

[0847] Step 8:

[0848] The server activates an emotion engine to recognize the user's emotional state and receives emotion data from each user's device, including information based on facial recognition and voice analysis.

[0849] Step 9:

[0850] The server customizes the content and format of the warning message based on the user's emotional state as recognized by the emotion engine. For example, if the user is highly stressed, the message will be displayed in a gentle tone.

[0851] Step 10:

[0852] The server sends a customized warning message to the user's terminal, which helps the user to understand and respond to the warning appropriately.

[0853] Step 11:

[0854] The device will display a list of received emails and notify the user with a warning message. A warning icon will be displayed, allowing the user to identify emails that are suspected to be BEC.

[0855] Step 12:

[0856] The user clicks on the warning icon displayed on the device to check detailed information, reads the warning message adjusted by the emotion engine, and understands its content.

[0857] Step 13:

[0858] Users can follow the instructions in the warning message to move the affected email to a quarantine folder, delete it, or re-evaluate it as legitimate.

[0859] Step 14:

[0860] The server periodically checks the emails moved to the quarantine folder and automatically deletes them after a certain period of time, based on deletion rules set by the system administrator.

[0861] Step 15:

[0862] The server stores the emotion data collected by the emotion engine as a history and uses it to display future warning messages. This history data is used to display optimal warning messages that take into account the user's emotional state.

[0863] Example 2

[0864] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."

[0865] Business email compromise (BEC) is a major threat to companies, and its detection and response are extremely important. However, conventional systems not only have low accuracy in detecting BEC emails, but also often make it difficult for recipients to properly understand the warning messages. Furthermore, warning messages that do not take into account the recipient's emotional state can increase the psychological burden on users. Furthermore, there is a lack of countermeasures that utilize user emotional data, making it difficult to provide customized warning messages.

[0866] The specific processing by the specific processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means.

[0867] In this invention, the server includes means for generating multiple business email fraud emails using a generation AI, means for extracting signatures from the generated business email fraud emails, means for saving the extracted signatures in a database, means for acquiring received emails, means for generating signatures from the acquired received emails, means for comparing the generated signatures with signatures in the database, means for determining whether the received emails are suspected of being business email fraud based on the comparison results, means for generating a warning message for the relevant emails, means for sending the warning message to a user, means for moving or deleting the relevant emails to a quarantine folder, means for acquiring user emotion data using an emotion engine that recognizes the user's emotional state, means for customizing the warning message based on the acquired emotion data, and means for saving the user emotion data as a history in the database. This enables highly accurate detection of BEC emails and provision of appropriate warning messages, thereby reducing the psychological burden on users.

[0868] "Generative AI" refers to systems or algorithms that use artificial intelligence technology to automatically generate emails intended for business email compromise.

[0869] Business Email Compromise (BEC) refers to a fraudulent activity that targets corporate executives and employees by sending emails containing fraudulent instructions or requests in an attempt to defraud them of money or information.

[0870] A "signature" refers to a specific identifier used to identify and detect business email compromise emails, such as a characteristic phrase or link pattern.

[0871] A "database" is a data storage system that organizes and stores information so that it can be quickly searched and retrieved when needed.

[0872] An "emotion engine" refers to software or algorithms that analyze a user's facial expressions, voice, input data, etc. to recognize their emotional state.

[0873] "Warning messages" refer to notifications or alerts that warn users about emails that may be business email compromises.

[0874] A "quarantine folder" refers to a specific email folder that stores fraudulent or suspicious emails separately from other legitimate emails.

[0875] "Customization" refers to adjusting or changing content or presentation format based on the user's emotional state or specific conditions.

[0876] "History" refers to information that records events and data that occurred in the past and organizes them in chronological order.

[0877] MODE FOR CARRYING OUT THE INVENTION

[0878] This invention provides a system that uses generative AI to automatically detect business email compromise (BEC) emails and warn users, as well as a system that combines an emotion engine that recognizes user emotions. This system reduces the psychological burden on users and enables rapid and accurate detection of BEC emails.

[0879] Server Operation

[0880] At the beginning of each month, the server generates new BEC emails using a generative AI tool (such as OpenAI's GPT-4). An example prompt for generating emails is, "Generate a new business email compromise (BEC) scenario. The target is an executive at a midstream company who receives emails during the afternoon workday." The generated emails are stored in a database, and characteristic signatures are extracted from the emails.

[0881] The server stores the extracted signatures in a database and updates it regularly. It also collects BEC emails created by humans in the past and trains the AI ​​to improve the accuracy of the signature database. The server also retrieves newly received emails from the company's email server every hour and analyzes their contents. New signatures are generated from the analyzed emails.

[0882] The server compares the generated signature with existing BEC signatures in its database to determine whether they match. For emails suspected of being BEC, a warning message is generated and sent to the user's device. The warning message includes the characteristics of BEC emails and the steps the user should take, and the email is then moved to a quarantine folder or deleted.

[0883] Emotion Engine Operation

[0884] The device uses a built-in camera and microphone to capture the user's facial expressions, voice, and input data, which are then analyzed by an emotion engine (such as Microsoft's Azure Cognitive Services). The emotion data recognized through the analysis is then sent to a server.

[0885] The server adjusts the content and display format of the warning message based on the received emotional data. For example, if the user is feeling stressed, the warning message can be softened. For example, "Warning! This email may be fraudulent" can be changed to "Please be careful. This email may be fraudulent, so please check it."

[0886] Emotional data is stored in a database as a history, and warning messages are optimized using past emotional data, allowing for more appropriate and friendly warning messages to be provided to users.

[0887] Device behavior

[0888] The device will display a warning icon and a pop-up warning message on any emails suspected of being BEC emails in the user's email list. The user can click on the message to view detailed information about the BEC email.

[0889] The emotion engine allows the device to continuously analyze the user's facial expressions and voice and transmits the results to the server in real time, enabling it to respond appropriately to the user's emotional state.

[0890] User operations

[0891] Users can check the warning icon or notification displayed on their device and click to view detailed information about the suspected BEC email. Based on the warning message, they can manually delete the email, move it to a quarantine folder, or reevaluate it as legitimate.

[0892] This system takes into account the user's emotional state, detects BEC emails with high accuracy, and provides effective measures to reduce the psychological burden.

[0893] The flow of the identification process in the second embodiment will be described with reference to FIG.

[0894] Step 1: Generating BEC emails using generative AI

[0895] At the beginning of each month, the server uses the generative AI model to generate BEC emails. The prompt text is entered as "Generate a new business email compromise (BEC) scenario. The target is an executive at a mid-stream company, and the scenario is set to receive emails during work hours in the afternoon." Based on the entered prompt text, the generative AI model generates a BEC email, and its content is stored in a database. Characteristic signatures are extracted from the generated email and added to the database.

[0896] Input: prompt statement

[0897] Data processing: Generating BEC emails using AI and extracting signatures

[0898] Output: Generated BEC email, extracted signature

[0899] Step 2: Managing Signatures

[0900] The server stores the extracted signatures in a database and updates it regularly. It also collects BEC emails created by humans in the past and trains the AI ​​to improve the accuracy of the database. This process improves the accuracy of detecting BEC emails.

[0901] Input: Previous BEC emails, generated signatures

[0902] Data processing: Signature storage and learning

[0903] Output: Updated signature database

[0904] Step 3: Capture and analyze incoming emails

[0905] The server retrieves new incoming emails from the company's mail server every hour, analyzes them immediately, and generates new signatures from the email body and header information.

[0906] Input: Newly received email

[0907] Data processing: Email analysis, signature generation

[0908] Output: Generated signature

[0909] Step 4: Signature Matching

[0910] The server compares the generated signature with existing BEC signatures in its database. If the signatures match, the email is deemed to be a suspected BEC scam. Specifically, text mining technology is used to analyze the email content and match it with existing BEC signatures.

[0911] Input: Generated signature

[0912] Data processing: Signature comparison

[0913] Output: Comparison result (match / mismatch)

[0914] Step 5: Generate and send an alert

[0915] The server generates a warning message for emails suspected of being BEC scams and sends it to the user's device. The generated warning message includes the characteristics of BEC emails and the measures the user should take. The server also automatically moves the email to a quarantine folder or deletes it.

[0916] Input: Comparison result (if match)

[0917] Data processing: Generate warning messages, move / delete emails

[0918] Output: Warning message, email moved to quarantine / deleted email

[0919] Step 6: Emotion Recognition

[0920] The device uses a built-in camera and microphone to capture the user's facial expressions and voice, and analyzes the input data with an emotion engine. The user's emotional data recognized through the analysis is then sent to the server.

[0921] Input: User's facial expression and voice data

[0922] Data processing: Emotion analysis using an emotion engine

[0923] Output: User emotion data

[0924] Step 7: Customizing the warning message

[0925] The server customizes the content and display format of the warning message based on the user's emotional data. For example, if the user is feeling stressed, the server changes the tone of the warning message to a gentler tone. This customization information is also stored in the database.

[0926] Input: User emotion data

[0927] Data Processing: Customizing warning messages

[0928] Output: Customized warning message

[0929] Step 8: Displaying warning messages

[0930] The device will display a warning icon next to suspected BEC emails in the user's email list, and when the user clicks on the icon, a customized warning message will pop up.

[0931] Input: Customized warning message

[0932] Data processing: Display warning message

[0933] Output: Warning icon, popup message

[0934] Step 9: User interaction

[0935] Users can check the warning icons and notifications displayed on their devices, click on them to view detailed information about the suspected BEC email, and then manually delete the email, move it to a quarantine folder, or reassess it as legitimate.

[0936] Input: Warning notification, more information

[0937] Data processing: Email operations (manual deletion, movement, re-evaluation)

[0938] Output: Updated email status (delete, quarantine, reevaluate)

[0939] In this way, the entire system works together to detect BEC emails with high accuracy while reducing the psychological burden on users, and provides appropriate warnings and quick responses.

[0940] (Application example 2)

[0941] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."

[0942] When sending or receiving business emails, there is a need for a system that can automatically detect business email compromise (BEC) emails with high accuracy and issue appropriate warnings to users. However, conventional systems use uniform warning messages, making it difficult to respond flexibly to the user's emotional state. This increases the user's psychological burden, and can lead to delayed responses or oversight of messages. To solve these issues, a flexible warning system that takes into account the user's emotional state as well as highly accurate detection of BEC emails is required.

[0943] The identification process by the identification processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means. In this invention, the server includes: means for generating multiple business email fraud emails using a generation AI; means for extracting signatures from the generated business email fraud emails; means for saving the extracted signatures in a database; means for acquiring received emails; means for generating signatures from the acquired received emails; means for comparing the generated signatures with signatures in the database; means for determining whether the received emails are suspected of being business email fraud based on the comparison results; means for generating a warning message for the relevant emails; means for sending the warning message to a user; means for moving or deleting the relevant emails to a quarantine folder; means for recognizing a user's emotional state and acquiring emotional data; means for customizing the warning message based on the acquired emotional data; and means for saving and managing the emotional data history in a database. This enables highly accurate detection of BEC emails and flexible display of warning messages according to the user's emotional state.

[0944] "Generative AI" is an artificial intelligence system that uses machine learning and neural network techniques to automatically generate new data patterns and text.

[0945] "Business email compromise" refers to fraudulent emails sent to businesses or organizations with the intent of fraudulently obtaining financial or other sensitive information.

[0946] A "signature" is data that indicates characteristics specific to fraudulent emails, extracted based on the content and structure of the email.

[0947] A "database" is a system or software for storing and managing data efficiently and systematically.

[0948] "Emotion recognition" is the technology of identifying a person's emotional state through the analysis of facial expressions, voice tone, and text.

[0949] A "warning message" is a message that contains information to notify a user of a particular situation or condition and to call their attention.

[0950] A "quarantine folder" is an email folder that stores suspicious or malicious emails separately from your regular inbox.

[0951] "History management" is a system or process that stores records of past data or events so that they can be analyzed and referenced.

[0952] This invention relates to a system that uses a generative AI system to detect business email compromise (BEC) emails with high accuracy, warn users, and understand the user's emotional state and customize the warning message based on that.

[0953] Server Operation Overview

[0954] The server system is constructed using the following hardware and software: The hardware is a server computer equipped with a high-performance processor, memory, and storage. The software uses a generative AI tool, a database system (MySQL), an email analysis library (Apache James), an emotion recognition engine (Microsoft's Azure Emotional Analysis API), and a backend framework (Node.js, Express).

[0955] At the beginning of the month, the server uses the generative AI model to generate new BEC emails, extracts characteristic signatures from these emails, and stores them in a database.

[0956] The server retrieves new incoming emails from the company's email server every hour and analyzes their contents using an email analysis library. The analyzed email signatures are compared with the BEC signatures in the existing database. If a suspicious email is found, a warning message is generated for that email.

[0957] The server uses Microsoft's Azure Emotional Analysis API to obtain user emotional data and determine the emotional state the user was in when receiving the email. This emotional data is then stored in a database as a history.

[0958] About device operation

[0959] The system operates using the following technologies on user devices, which can be smartphones, tablets, or desktop computers. The devices use Google ML Kit to analyze facial expressions and voice tones to obtain emotion data.

[0960] When a user receives an email on their device, the emotion recognition system captures their facial expressions and voice and analyzes their emotional state in real time, and this data is sent to the server.

[0961] The warning message sent from the server is customized according to the user's emotional state and displayed on the device. For example, if the user is determined to be in a stressful state, the warning message will be displayed in a soft tone.

[0962] User operations

[0963] The user can check the warning message displayed on the terminal and check the detailed information of the email.

[0964] You can choose to move the email to a quarantine folder, delete it, or re-evaluate it as legitimate.

[0965] Examples of concrete examples and prompts

[0966] Specific examples

[0967] While a user is checking work emails on their smartphone while out and about, the server determines that they have received a BEC email. If the emotion engine determines that the user is under stress, it changes the usual stiff warning message to a softer tone, saying, "Thank you for your hard work. An email requiring your attention has been found. Please remain calm and take appropriate action."

[0968] Prompt Sentence Examples

[0969] Generate customized warning messages when the user's emotional state is stressed.

[0970] Original warning message:

[0971] "Warning! Suspicious email found. Please review immediately."

[0972] Customized warning message:

[0973] "Thank you for your hard work. We've found an email that needs your attention. Please stay calm and take care of it."

[0974] In this way, we provide a system that reduces the psychological burden on users and strengthens security through BEC email detection and emotion-customized warning messages.

[0975] The flow of the specific processing in the application example 2 will be described with reference to FIG.

[0976] Step 1:

[0977] The server uses the generative AI model to generate new BEC emails at the beginning of each month. It extracts characteristic signatures from the generated emails and stores them in a database. The input is the email data generated by the generative AI model, and the output is the extracted signature data. New signature information is added to the database.

[0978] Step 2:

[0979] The server retrieves new incoming emails from the company's email server every hour. It uses an email analysis library (Apache James) to analyze the content of the retrieved emails and generate a signature from them. The input is new email data retrieved from the company's email server, and the output is the generated signature data. The signature is obtained by analyzing the email content.

[0980] Step 3:

[0981] The server compares the generated signature with existing BEC signatures in the database. Based on the comparison results, it determines whether the received email is suspected of being a business email compromise. The input is the newly generated signature and existing signatures in the database, and the output is the determination result of whether or not there is suspicion of BEC. The signature is matched by referring to the information in the database.

[0982] Step 4:

[0983] The server generates a warning message for emails that are suspected of being BEC attacks. The input is the email data that is suspected of being BEC attacks, and the output is the warning message. The generated warning message is created based on a template.

[0984] Step 5:

[0985] The server sends the generated warning message to the user's terminal. The input is the generated warning message, and the output is the successful transmission of the warning message to the user's terminal. The message is sent to the user's terminal via the network.

[0986] Step 6:

[0987] When receiving a warning message, the device captures facial expressions and voice to obtain emotional data in order to recognize the user's emotional state. Analysis is performed using Google ML Kit. The input is the user's facial expression data and voice data, and the output is the recognized emotional data. The emotional state is analyzed in real time and sent to the server.

[0988] Step 7:

[0989] The server customizes the warning message based on the acquired emotion data. The input is the recognized emotion data and the original warning message, and the output is the customized warning message. The message content is adjusted based on the emotion data.

[0990] Step 8:

[0991] The terminal displays a customized warning message to the user. The input is the customized warning message, and the output is the warning message displayed on the terminal screen. The message is presented to the user visually and audibly.

[0992] Step 9:

[0993] The user checks the warning icon or notification displayed on the device and views the details of the received email. The input is the warning notification displayed on the device, and the output is the detailed information of the email viewed by the user. The user clicks on the warning message to view the details.

[0994] Step 10:

[0995] The user can move the email to a quarantine folder, delete it, or reassess it as legitimate. The input is the user's choice of action, and the output is the quarantine, new assessment, or deletion of the email. The user selects the appropriate action, and the system processes the email according to that choice.

[0996] The specific processing unit 290 transmits the result of the specific processing to the smart glasses 214. In the smart glasses 214, the control unit 46A causes the speaker 240 to output the result of the specific processing. The microphone 238 acquires audio indicating a user input regarding the result of the specific processing. The control unit 46A transmits audio data indicating the user input acquired by the microphone 238 to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.

[0997] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[0998] In the above embodiment, an example in which the specific processing is performed by the data processing device 12 has been given, but the technology of the present disclosure is not limited to this, and the specific processing may be performed by the smart glasses 214.

[0999] [Third embodiment]

[1000] FIG. 5 shows an example of the configuration of a data processing system 310 according to the third embodiment.

[1001] 5, the data processing system 310 includes the data processing device 12 and a headset type terminal 314. An example of the data processing device 12 is a server.

[1002] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[1003] The headset type terminal 314 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication I / F 44, and a display 343. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The microphone 238, the speaker 240, the camera 42, and the display 343 are also connected to the bus 52.

[1004] The microphone 238 receives instructions and the like from the user 20 by receiving voice uttered by the user 20. The microphone 238 captures the voice uttered by the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio in accordance with instructions from the processor 46.

[1005] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the surroundings of user 20 (for example, an imaging range defined by an angle of view equivalent to the field of vision of a typical healthy person).

[1006] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 are responsible for the exchange of various information between the processor 46 and the processor 28 via the network 54. The exchange of various information between the processor 46 and the processor 28 using the communication I / Fs 44 and 26 is carried out in a secure state.

[1007] Fig. 6 shows an example of the main functions of the data processing device 12 and the headset type terminal 314. As shown in Fig. 6, in the data processing device 12, a specific process is performed by the processor 28. A specific process program 56 is stored in the storage 32.

[1008] The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[1009] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[1010] In the headset type terminal 314, a reception output process is performed by the processor 46. A reception output program 60 is stored in the storage 50. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.

[1011] Next, a description will be given of the identification process performed by the identification processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as the "server" and the headset type terminal 314 will be referred to as the "terminal."

[1012] The system of this invention uses generative AI to automatically detect business email compromise (BEC) emails and warn users. It also prevents BEC damage by moving the emails to a quarantine folder or deleting them. The details of the system and the program processing are explained below.

[1013] Server Operation

[1014] 1. Generating BEC emails using AI:

[1015] The server automatically generates new BEC emails at the beginning of each month or every few weeks using a generative AI tool, which uses advanced natural language processing techniques to make the emails appear like regular business emails.

[1016] The server stores the content of generated BEC emails in a database and extracts characteristic signatures from those emails.

[1017] 2. Signature Management:

[1018] The server sequentially adds signatures extracted from the generated BEC emails to the database and updates it regularly. It also trains the generation AI to learn from past BEC emails created by humans, strengthening these signatures.

[1019] 3. Acquiring and analyzing incoming emails:

[1020] The server periodically retrieves new incoming emails from the company's email server. For example, you can configure it to retrieve incoming emails every hour.

[1021] The server analyzes the content of the received emails and generates signatures from these emails as well.

[1022] 4. Signature Matching:

[1023] The server compares the generated signature with the signatures in its database to determine if there is a match.

[1024] 5. Generate and send alerts:

[1025] The server generates a warning message for any emails that match the signature. The warning message contains information about the email and indicates that it is suspected of being a BEC scam.

[1026] The server generates a warning message, sends it to the user, and moves the affected email to a quarantine folder or deletes it.

[1027] Device behavior

[1028] 1. Providing the user interface:

[1029] The terminal displays a list of received emails to the user and displays a warning icon based on the results of the system's automatic analysis.

[1030] The terminal displays a warning message so that the user can check the details of the received email.

[1031] 2. Receiving and acting on warning messages:

[1032] The terminal notifies the user of the warning message received from the server together with its contents.

[1033] When a warning message appears on the device, the user is given the option to easily move the email to a quarantine folder or delete it.

[1034] User operations

[1035] 1. Check notifications:

[1036] The user checks the warning icon or notification displayed on the device.

[1037] The user clicks on the warning message to view the details and realizes that it may be a BEC email.

[1038] 2. Email Operations:

[1039] After reviewing the warning message, users can choose to move the email to a quarantine folder, delete it, or re-evaluate it as legitimate.

[1040] Specific examples

[1041] Scenario 1:

[1042] 1. At the beginning of each month, the server generates 20 new BEC emails using the generation AI and stores their signatures in a database.

[1043] 2. Check incoming emails every hour and analyze their contents.

[1044] 3. During a certain period of time, an incoming email is detected that matches the signature of a generated BEC email.

[1045] 4. The server generates a warning message and moves the affected email to a quarantine folder.

[1046] 5. A warning notification will appear on the user's device, and the user will check the email, confirm that it is a scam, and delete it.

[1047] This makes it possible to detect BEC emails quickly and accurately, preventing harm to users before it occurs.

[1048] The processing flow will be explained below.

[1049] Step 1:

[1050] At the beginning of each month, the server launches the AI ​​tool to generate 20 new Business Email Compromise (BEC) emails. The generated emails are written in a natural style and are designed to look like real business emails.

[1051] Step 2:

[1052] The server extracts characteristic signatures from the 20 generated BEC emails and stores them in a database. The signatures represent important characteristics and patterns of each BEC email.

[1053] Step 3:

[1054] The server collects BEC emails created by humans in the past, generates signatures for them, and adds them to the database, further strengthening the signature database.

[1055] Step 4:

[1056] The server retrieves new incoming emails from the company's mail server every hour, for example by connecting to the mail server and finding the latest incoming emails.

[1057] Step 5:

[1058] The server analyzes the content of the received email and generates a signature from it. This signature generation process uses the same method as the signature of the BEC email saved earlier.

[1059] Step 6:

[1060] The server compares the generated signature of the received email with the BEC signatures in the database. The comparison algorithm calculates the degree of match between each signature, and if there is a high degree of match, the email is determined to be suspected of being a BEC scam.

[1061] Step 7:

[1062] If the match is high, the server generates a warning message and sends it to the user's device, including information about the email, such as the sender, subject, and match level.

[1063] Step 8:

[1064] The server will move any incoming email that generates a warning message to a quarantine folder, and can be configured to automatically delete the email if desired.

[1065] Step 9:

[1066] The device displays a list of received emails and notifies the user of any warning messages received from the server. The warning icon allows the user to identify suspicious emails at a glance.

[1067] Step 10:

[1068] The user can click the warning icon displayed on the device to view the details of the warning message. The user can also check the contents of the email and view further details.

[1069] Step 11:

[1070] Users can follow the instructions in the warning message to manually delete the email or move it to a quarantine folder, or if they determine it to be legitimate, they can choose to move it back to a regular folder.

[1071] Step 12:

[1072] The server periodically checks the emails moved to the quarantine folder and deletes them after a certain period of time. The deletion rules and storage period are set by the administrator.

[1073] Example 1

[1074] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."

[1075] In today's business environment, fraud via business email counterfeiting (BEC) has become a major problem. In particular, the risk of companies and individuals suffering financial losses due to users receiving sophisticated forged emails is increasing. Conventional email filtering systems have difficulty effectively detecting and preventing these sophisticated forged emails, and new systems are needed to ensure user safety.

[1076] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.

[1077] In this invention, the server includes means for generating multiple counterfeit business emails using a generation AI, means for extracting characteristic patterns from the generated counterfeit business emails, means for saving the extracted characteristic patterns in a database, means for acquiring received emails, means for generating characteristic patterns from the acquired received emails, means for comparing the generated characteristic patterns with characteristic patterns in the database, means for determining whether the received emails are suspected of being counterfeit business emails based on the comparison results, means for generating a warning message for the corresponding emails, means for sending the warning message to the user, means for moving or deleting the corresponding emails to a quarantine folder, means for generating a warning message including an overview of the corresponding emails and a warning message and notifying the user of the warning message, and means for providing operation options for quarantining, deleting, or reevaluating the emails as legitimate, thereby enabling rapid and highly accurate detection and prevention of BEC emails.

[1078] "Generative AI" is a system that uses artificial intelligence technology to automatically generate new content (in this case, counterfeit business emails).

[1079] "Forged business email" is a forged email disguised as a normal business email sent with the intent to defraud.

[1080] A "characteristic pattern" is a specific pattern contained in elements such as email content, subject, sender address, and destination URL, and is used to identify counterfeit business emails.

[1081] A "database" is a structured information storage system for effectively storing and managing the generated characteristic patterns.

[1082] "Incoming email" refers to all emails received by a company or user.

[1083] The "warning message" is a warning message that notifies the user that the received email may be a forged business email.

[1084] A "quarantine folder" is a specific email folder that temporarily stores suspicious emails and keeps them separate from other regular emails.

[1085] "Action options" are the choices provided to a user to take action on a suspicious email (e.g., quarantine, delete, reassess).

[1086] The system of this invention uses generative AI to automatically detect forged emails intended for business email compromise (BEC) and warn users. It also prevents BEC damage by moving or deleting the forged emails in question to a quarantine folder.

[1087] Server Operation

[1088] Generating BEC emails using generative AI

[1089] The server automatically generates new BEC emails periodically using a generative AI tool (e.g., GPT-4). This allows emails based on the latest fraud techniques to be constantly added to the database. The server inputs prompt phrases such as "invoice from a customer" or "urgent payment request" into the generative AI, and saves the generated email content in the database.

[1090] Extracting and saving signatures

[1091] The server extracts characteristic patterns (signatures) from the generated BEC emails and stores them in a database using a natural language processing (NLP) algorithm to extract distinctive patterns from the email body, subject, sender address, destination URL, etc.

[1092] Acquiring and analyzing received emails

[1093] The server periodically retrieves new incoming emails from the company's mail server using IMAP or POP3 protocols, analyzes the emails using NLP algorithms, and generates signatures.

[1094] Signature Matching

[1095] The server analyzes the signature of the incoming email and compares it with the signatures in its existing database using fast search algorithms (e.g. hash functions or binary searches). If a match is found, the email is marked as suspected BEC.

[1096] Generate and send alerts

[1097] The server generates a warning message for any emails suspected of being BEC. This message includes a summary of the email and a warning. The warning message is sent to the user, and the email is moved to a quarantine folder or deleted.

[1098] Device behavior

[1099] Providing a user interface

[1100] The terminal displays a list of received emails and a warning icon to the user. If an abnormality is detected in an email, a warning icon will be displayed, and clicking the icon will display a detailed warning message in a pop-up.

[1101] Receiving and acting on warning messages

[1102] The terminal notifies the user of warning messages from the server and provides action options (quarantine, delete, or reassess as legitimate email), allowing the user to handle the email quickly and accurately.

[1103] User operations

[1104] Checking notifications

[1105] Users can check the warning icon or notification displayed on their device and click to open the details of the warning message to get a detailed understanding of whether the email is suspected to be a BEC scam.

[1106] Email Operations

[1107] After reviewing the warning message, users can choose to move the email to a quarantine folder, delete it, or re-evaluate it as legitimate.

[1108] Specific examples

[1109] Scenario 1:

[1110] 1. At the beginning of each month, the server generates 20 new BEC emails using the generation AI and stores their signatures in a database. An example prompt is "Generate an email proposing a new invoice format."

[1111] 2. Check incoming emails every hour and analyze their contents using natural language processing algorithms.

[1112] 3. During a certain period of time, the server detects that an incoming email matches the signature of a generated BEC email and records this as a flag.

[1113] 4. The server generates a warning message and moves the affected email to a quarantine folder.

[1114] 5. A warning notification will appear on the user's device, and the user will check the email, determine that it is a scam, and delete it.

[1115] This makes it possible to detect and prevent BEC emails quickly and accurately, preventing harm to users before it occurs.

[1116] The flow of the identification process in the first embodiment will be described with reference to FIG.

[1117] Step 1:

[1118] Generating BEC emails using generative AI

[1119] The server generates BEC emails using a generative AI model (e.g., GPT-4) and inputs a prompt such as "Generate an email proposing a new invoice format."

[1120] Input: Prompt text "Generate an email proposing a new invoice format."

[1121] Data processing: The generative AI model uses natural language processing based on the prompt text to generate fraudulent business emails.

[1122] Output: The generated BEC email.

[1123] Specific operation: The server saves the automatically generated email as a file and converts its content into a text format for analysis.

[1124] Step 2:

[1125] Extracting and saving signatures

[1126] The server extracts characteristic patterns (signatures) from the content of the generated BEC email.

[1127] Input: The generated BEC email.

[1128] Data processing: Using natural language processing algorithms, characteristic patterns are extracted from elements such as the email body, subject, sender address, and destination URL.

[1129] Output: The extracted signature.

[1130] Specific operation: The server adds the extracted signature to a database and creates an index to match and classify it with existing signatures.

[1131] Step 3:

[1132] Acquiring and analyzing received emails

[1133] The server periodically retrieves new incoming emails from the company's mail server.

[1134] Input: Incoming emails stored on your company's email server.

[1135] Data processing: Received emails are imported to the server using the IMAP or POP3 protocol, and the email content is analyzed using natural language processing algorithms.

[1136] Output: Parsed signature of the incoming email.

[1137] How it works: The server communicates with the mail server every hour, downloads new emails, and analyzes them using techniques such as tokenization and feature extraction.

[1138] Step 4:

[1139] Signature Matching

[1140] The server analyzes the signature of the incoming email and compares it with the signatures in its existing database.

[1141] Input: Parsed signatures from incoming emails and signatures in the database.

[1142] Data processing: Using a fast search algorithm (e.g. hash function or binary search) to match the signature.

[1143] Output: A list of matching signatures.

[1144] What it does: The server goes through a matching process, lists matching signatures, and flags emails that are suspected to be BEC.

[1145] Step 5:

[1146] Generate and send alerts

[1147] The server generates a warning message for emails suspected of being BEC and sends it to the user.

[1148] Input: Incoming email where a matching signature was found.

[1149] Data processing: Generate a warning message that includes a summary of the email and a warning.

[1150] Output: A warning message.

[1151] Specific actions: The server will send a warning message to the user's email address and simultaneously move the email to a quarantine folder or delete it.

[1152] Step 6:

[1153] Providing a user interface

[1154] The terminal displays a list of received emails and a warning icon to the user.

[1155] Input: Incoming emails and warning messages from the server.

[1156] Data Processing: Added warning icon and popup warning message.

[1157] Output: The email list and warning messages displayed in the user interface.

[1158] Specific operation: The terminal displays a list of received emails to the user through the email client software and provides an interface including a warning icon.

[1159] Step 7:

[1160] Receiving and acting on warning messages

[1161] Users can review the warning message and quarantine, delete, or reevaluate the email as legitimate.

[1162] Input: Warning messages and action options displayed on the terminal.

[1163] Data manipulation: Moves the email to a quarantine folder, deletes it, or re-evaluates it based on the user's choice.

[1164] Output: Change the state of the email depending on the user's selection.

[1165] Specific actions: The user checks the warning icon displayed on the device, clicks it to open a detailed warning message, and then performs the action on the relevant email.

[1166] (Application example 1)

[1167] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."

[1168] Conventional business email compromise (BEC) countermeasure systems rely on static rule-based analysis, making it difficult to respond quickly to new and changing fraudulent methods. Furthermore, users have few ways to know in real time whether an email they receive is fraudulent, making it difficult to take appropriate action immediately and preventing damage before it occurs. Furthermore, the user interface when a fraudulent email is detected is inadequate, making it difficult for users to easily and quickly handle the email.

[1169] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.

[1170] In this invention, the server includes: means for generating multiple business email fraud emails using a generation AI; means for extracting signatures from the generated business email fraud emails; means for storing the extracted signatures in a database; means for acquiring received emails; means for generating signatures from the acquired received emails; means for comparing the generated signatures with signatures in the database; means for determining whether the received emails are suspected of being business email fraud based on the comparison results; means for generating a warning message for the suspected emails; means for sending the warning message to a user; means for moving the suspected emails to a quarantine folder or deleting them; means for notifying the user of the warning message in real time on a mobile device of the user and providing a user interface that allows the user to move the suspected emails to a quarantine folder, delete them, or reassess them as legitimate; and means for the user to review and manipulate the suspected fraud emails. This enables advanced fraud email detection and real-time notification using the generation AI, as well as a user-friendly operation interface, thereby preventing fraud damage before it occurs.

[1171] "Generative AI" refers to a model that uses artificial intelligence technology to generate artificial content.

[1172] "Business email compromise" refers to a method of committing forgery or fraud by disguising emails as business-related.

[1173] A "signature" refers to a characteristic pattern or identifier contained in the content of an email.

[1174] "Database" refers to a system that collects and manages signatures and important data in one place.

[1175] "Mobile device" refers to a portable electronic device such as a smartphone or tablet.

[1176] "User interface" refers to the display screen and operating means through which a user interacts with a system.

[1177] A "quarantine folder" is a folder that stores suspicious or fraudulent emails received separately from other emails.

[1178] "Real-time notification" refers to a function that notifies the user of information immediately at the moment a relevant event occurs.

[1179] "Reevaluating as legitimate" refers to the user manually reconfirming an email as legitimate when the email has been mistakenly determined to be fraudulent.

[1180] "User" refers to an individual or company that uses this system.

[1181] The system of this invention uses a generative AI model to automatically detect fraudulent emails and send warning notifications to users in order to prevent damage caused by business email compromise (BEC). The operation of the server and terminal is described in detail below.

[1182] Server Operation

[1183] 1. Generating BEC emails using AI:

[1184] The server periodically generates new BEC emails using a generative AI model, which uses advanced natural language processing techniques to make the emails appear like regular business emails.

[1185] The content of the generated BEC emails is stored in a database and characteristic signatures are extracted from those emails.

[1186] 2. Signature Management:

[1187] The server sequentially adds the signatures extracted from the generated BEC emails to the database and updates it periodically.

[1188] The generation AI also learns from past artificially created BEC emails to strengthen the signature.

[1189] 3. Acquiring and analyzing incoming emails:

[1190] The server connects to the company's mail server and periodically (for example, every hour) retrieves new incoming emails.

[1191] It analyzes the emails it receives and generates signatures from them.

[1192] 4. Signature Matching:

[1193] The server compares the generated signature with the signatures in its database to determine if there is a match.

[1194] 5. Generate and send alerts:

[1195] If a signature matches an incoming email, a warning message will be generated containing information about the email.

[1196] The server sends the generated warning message to the user's mobile device and moves or deletes the relevant email in a quarantine folder.

[1197] Device behavior

[1198] 1. Providing the user interface:

[1199] The user interface displays a list of received emails to the user and displays a warning icon based on the results of automatic analysis by the system.

[1200] A warning message will be displayed, allowing the user to view details of the affected received email.

[1201] 2. Receiving and acting on warning messages:

[1202] The terminal notifies the user of the warning message received from the server together with its contents.

[1203] When a warning message appears, users are given the option to move the email to a quarantine folder or delete it.

[1204] User operations

[1205] 1. Check notifications:

[1206] The user checks the warning icon or notification displayed on the device.

[1207] Click on the warning message to see more details and understand that it may be a BEC email.

[1208] 2. Email Operations:

[1209] After checking the contents of the warning message, the user can choose to move the email to a quarantine folder, delete it, or re-evaluate it as legitimate.

[1210] Specific examples

[1211] If a user receives an email during a certain time period saying, "Please change the transfer destination to this address," the server analyzes the email and detects that it matches the signature of a previous BEC email. The server then sends a warning notification to the user's mobile device in real time and moves the email to a quarantine folder. The user who receives this notification can click on the warning message to check the details of the email and, if necessary, delete it as a fraudulent email.

[1212] Prompt Sentence Examples

[1213] "Email body: 'Thank you for your hard work. Your bank transfer details have changed, so we are sending you the new account details. Please confirm and confirm...'"

[1214] The above system enables advanced fraudulent email detection using generative AI, real-time notification, and a user-friendly operation interface, making it possible to prevent fraudulent incidents before they occur.

[1215] The flow of the specific processing in the application example 1 will be described with reference to FIG.

[1216] Step 1:

[1217] The server uses AI to generate multiple business email compromise emails.

[1218] Input: Enter a prompt for the generative AI model. "Email body: 'Thank you for your hard work. Your bank transfer details have changed, so we are sending you the new account details. Please confirm and confirm...'"

[1219] How it works: It uses a generative AI model (e.g., GPT-2) to generate BEC emails based on prompts.

[1220] Output: The generated BEC email.

[1221] Step 2:

[1222] The server extracts the signature from the generated BEC email.

[1223] Input: The generated BEC email.

[1224] How it works: Analyzes email content and extracts signatures (characteristic patterns or identifiers).

[1225] Output: The extracted signature.

[1226] Step 3:

[1227] The server stores the extracted signatures in a database.

[1228] Input: The extracted signature.

[1229] Behavior: Saves the signature to the database and updates the existing signature list.

[1230] Output: The updated database.

[1231] Step 4:

[1232] The server retrieves the incoming email.

[1233] Input: Your mail server login and connection information.

[1234] What it does: It connects to your company's mail server using the IMAP protocol and retrieves new incoming emails.

[1235] Output: The received emails retrieved.

[1236] Step 5:

[1237] The server generates a signature from the received email.

[1238] Input: The received emails retrieved.

[1239] How it works: Analyzes incoming emails and generates a new signature from their contents.

[1240] Output: The new signature.

[1241] Step 6:

[1242] The server compares the newly generated signature with the signatures in its database.

[1243] Input: New signatures and existing signatures in the database.

[1244] How it works: It runs an algorithm that compares the new signature with signatures in the database to determine if there is a match.

[1245] Output: Comparison result (match / not match).

[1246] Step 7:

[1247] The server generates a warning message for the affected email.

[1248] Input: Comparison result (if the signatures match).

[1249] Behavior: Generates a warning message containing the contents of the email.

[1250] Output: The warning message generated.

[1251] Step 8:

[1252] The server sends a warning message to the user's mobile device.

[1253] Input: The generated warning message and the user's mobile device information.

[1254] What it does: Sends a warning message to the user's mobile device.

[1255] Output: The warning message displayed on the user's mobile device.

[1256] Step 9:

[1257] The server moves the email to a quarantine folder or deletes it.

[1258] Input: Comparison result (if signature matches) and corresponding received email.

[1259] Action: The email will be moved from the inbox to a quarantine folder or deleted.

[1260] Output: Emails moved to quarantine folder or deleted.

[1261] Step 10:

[1262] The device will notify the user of a warning message and allow them to check and handle the relevant email.

[1263] Input: The warning message sent by the server.

[1264] What it does: Displays a warning message to the user, offering further details and options to delete the email or move it to a quarantine folder.

[1265] Output: User interaction to manage emails.

[1266] Step 11:

[1267] The user checks the relevant email and takes action.

[1268] Input: The warning message displayed on the terminal and detailed information about the email in question.

[1269] Action: The user reviews the email details and takes action to move it to quarantine, delete it, or reassess it as legitimate.

[1270] Output: Operation result (quarantine, delete, or re-evaluate the email).

[1271] Furthermore, an emotion engine that estimates the user's emotion may be further combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59, and perform identification processing using the user's emotion.

[1272] Overall overview

[1273] This invention provides a system that uses generative AI to automatically detect business email compromise (BEC) emails and warn users, as well as a system that combines an emotion engine that recognizes the user's emotions. This system has functions to reduce the psychological burden on users, such as adjusting and customizing warning messages based on their emotional state and managing emotional data history.

[1274] Server Operation

[1275] 1. Generating BEC emails using AI:

[1276] At the beginning of each month, the server uses a generative AI tool to generate new Business Email Compromise (BEC) emails, which are then stored in a database and characteristic signatures are extracted from the emails.

[1277] 2. Signature Management:

[1278] The server stores the signatures extracted from the generated emails in a database and updates it regularly. It also collects BEC emails created by humans in the past and trains the generation AI on them. This strengthens the signature database and enables highly accurate detection.

[1279] 3. Acquiring and analyzing incoming emails:

[1280] The server retrieves new incoming emails from the company's mail server every hour and analyzes their contents, generating a signature from the incoming email.

[1281] 4. Signature Matching:

[1282] The server compares the signature generated from the received email with the BEC signatures in its database to determine if there is a match.

[1283] 5. Generate and send alerts:

[1284] The server generates a warning message for any incoming emails suspected of being BEC scams based on the signature matching results. The generated warning message is sent to the user's device, and the email is then moved to a quarantine folder or deleted.

[1285] Emotion Engine Operation

[1286] 1. Emotion recognition:

[1287] The device analyzes the user's facial expressions, voice, and input data, and recognizes the user's emotional state using an emotion engine. The recognized emotional data is then sent to the server.

[1288] 2. Customize the warning message:

[1289] The server customizes the content and presentation of the warning message based on the user's emotional state, for example, if the user is stressed, the warning message will be displayed in a more understandable and gentle tone.

[1290] 3. Emotion data history management:

[1291] The server stores the user's emotional state as historical data, which allows for optimization of warning messages based on past emotional data.

[1292] Device behavior

[1293] 1. Displaying a warning message:

[1294] The device displays a list of received emails to the user, and displays a warning icon for emails suspected of being BEC. The warning message is displayed with customized content based on the emotion engine.

[1295] 2. Emotion Recognition and Feedback:

[1296] The device uses an emotion engine to recognize the user's face and analyze their voice, and sends the results to a server, enabling it to respond appropriately to the user's emotional state.

[1297] User operations

[1298] 1. Check notifications:

[1299] Users can check the warning icon or notification displayed on their device and click on the warning message to view detailed information about the suspected BEC email.

[1300] 2. Email Operations:

[1301] Based on the warning message and the identified emotional state, users have the option to manually delete the email, move it to a quarantine folder, or reassess it as legitimate.

[1302] Specific examples

[1303] Scenario: A user is experiencing stress

[1304] 1. At the beginning of the month, the server generates a new BEC email using the generation AI and stores its signature in the database.

[1305] 2. The server retrieves new incoming emails from the company's email server every hour and determines that one of them is suspected to be a BEC scam.

[1306] 3. The server generates a warning message and sends it to the user.

[1307] 4. The device checks the user's emotional state using an emotion engine and recognizes that they are feeling stressed.

[1308] 5. The server changes the warning message to a softer tone based on the user's emotional state and sends it to the user.

[1309] 6. The user checks the warning notice displayed on the device and moves the relevant email to the quarantine folder.

[1310] This will reduce the psychological burden on users and realize a system that enables rapid and highly accurate detection of BEC emails.

[1311] The processing flow will be explained below.

[1312] Step 1:

[1313] At the beginning of each month, the server generates 20 new Business Email Compromise (BEC) emails using a generative AI tool, which stores the emails in a database and extracts their distinctive signatures.

[1314] Step 2:

[1315] The server sequentially adds and updates the database with signatures extracted from the 20 generated BEC emails. These signatures represent important characteristics and patterns of each BEC email.

[1316] Step 3:

[1317] The server collects BEC emails created by humans in the past, generates signatures for them, and adds them to the database, further strengthening the signature database and enabling high accuracy in detecting BEC emails.

[1318] Step 4:

[1319] The server retrieves new incoming emails from the company's mail server every hour, for example by connecting to the mail server using the IMAP or POP3 protocol to detect new incoming emails.

[1320] Step 5:

[1321] The server analyzes the content of the received emails and generates a signature for each email. The signature generation process uses the same method as for signatures extracted from BEC emails.

[1322] Step 6:

[1323] The server compares the generated signature of the received email with the BEC signatures in the database. The comparison algorithm calculates the degree of match between each signature, and if the degree of match is high, the email is determined to be suspected of being a BEC scam.

[1324] Step 7:

[1325] The server generates a warning message for any incoming emails suspected of being BEC emails, including information such as the sender, subject, and degree of similarity of the email.

[1326] Step 8:

[1327] The server activates an emotion engine to recognize the user's emotional state and receives emotion data from each user's device, including information based on facial recognition and voice analysis.

[1328] Step 9:

[1329] The server customizes the content and format of the warning message based on the user's emotional state as recognized by the emotion engine. For example, if the user is highly stressed, the message will be displayed in a gentle tone.

[1330] Step 10:

[1331] The server sends a customized warning message to the user's terminal, which helps the user to understand and respond to the warning appropriately.

[1332] Step 11:

[1333] The device will display a list of received emails and notify the user with a warning message. A warning icon will be displayed, allowing the user to identify emails that are suspected to be BEC.

[1334] Step 12:

[1335] The user clicks on the warning icon displayed on the device to check detailed information, reads the warning message adjusted by the emotion engine, and understands its content.

[1336] Step 13:

[1337] Users can follow the instructions in the warning message to move the affected email to a quarantine folder, delete it, or re-evaluate it as legitimate.

[1338] Step 14:

[1339] The server periodically checks the emails moved to the quarantine folder and automatically deletes them after a certain period of time, based on deletion rules set by the system administrator.

[1340] Step 15:

[1341] The server stores the emotion data collected by the emotion engine as a history and uses it to display future warning messages. This history data is used to display optimal warning messages that take into account the user's emotional state.

[1342] Example 2

[1343] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."

[1344] Business email compromise (BEC) is a major threat to companies, and its detection and response are extremely important. However, conventional systems not only have low accuracy in detecting BEC emails, but also often make it difficult for recipients to properly understand the warning messages. Furthermore, warning messages that do not take into account the recipient's emotional state can increase the psychological burden on users. Furthermore, there is a lack of countermeasures that utilize user emotional data, making it difficult to provide customized warning messages.

[1345] The specific processing by the specific processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means.

[1346] In this invention, the server includes means for generating multiple business email fraud emails using a generation AI, means for extracting signatures from the generated business email fraud emails, means for saving the extracted signatures in a database, means for acquiring received emails, means for generating signatures from the acquired received emails, means for comparing the generated signatures with signatures in the database, means for determining whether the received emails are suspected of being business email fraud based on the comparison results, means for generating a warning message for the relevant emails, means for sending the warning message to a user, means for moving or deleting the relevant emails to a quarantine folder, means for acquiring user emotion data using an emotion engine that recognizes the user's emotional state, means for customizing the warning message based on the acquired emotion data, and means for saving the user emotion data as a history in the database. This enables highly accurate detection of BEC emails and provision of appropriate warning messages, thereby reducing the psychological burden on users.

[1347] "Generative AI" refers to systems or algorithms that use artificial intelligence technology to automatically generate emails intended for business email compromise.

[1348] Business Email Compromise (BEC) refers to a fraudulent activity that targets corporate executives and employees by sending emails containing fraudulent instructions or requests in an attempt to defraud them of money or information.

[1349] A "signature" refers to a specific identifier used to identify and detect business email compromise emails, such as a characteristic phrase or link pattern.

[1350] A "database" is a data storage system that organizes and stores information so that it can be quickly searched and retrieved when needed.

[1351] An "emotion engine" refers to software or algorithms that analyze a user's facial expressions, voice, input data, etc. to recognize their emotional state.

[1352] "Warning messages" refer to notifications or alerts that warn users about emails that may be business email compromises.

[1353] A "quarantine folder" refers to a specific email folder that stores fraudulent or suspicious emails separately from other legitimate emails.

[1354] "Customization" refers to adjusting or changing content or presentation format based on the user's emotional state or specific conditions.

[1355] "History" refers to information that records events and data that occurred in the past and organizes them in chronological order.

[1356] MODE FOR CARRYING OUT THE INVENTION

[1357] This invention provides a system that uses generative AI to automatically detect business email compromise (BEC) emails and warn users, as well as a system that combines an emotion engine that recognizes user emotions. This system reduces the psychological burden on users and enables rapid and accurate detection of BEC emails.

[1358] Server Operation

[1359] At the beginning of each month, the server generates new BEC emails using a generative AI tool (such as OpenAI's GPT-4). An example prompt for generating emails is, "Generate a new business email compromise (BEC) scenario. The target is an executive at a midstream company who receives emails during the afternoon workday." The generated emails are stored in a database, and characteristic signatures are extracted from the emails.

[1360] The server stores the extracted signatures in a database and updates it regularly. It also collects BEC emails created by humans in the past and trains the AI ​​to improve the accuracy of the signature database. The server also retrieves newly received emails from the company's email server every hour and analyzes their contents. New signatures are generated from the analyzed emails.

[1361] The server compares the generated signature with existing BEC signatures in its database to determine whether they match. For emails suspected of being BEC, a warning message is generated and sent to the user's device. The warning message includes the characteristics of BEC emails and the steps the user should take, and the email is then moved to a quarantine folder or deleted.

[1362] Emotion Engine Operation

[1363] The device uses a built-in camera and microphone to capture the user's facial expressions, voice, and input data, which are then analyzed by an emotion engine (such as Microsoft's Azure Cognitive Services). The emotion data recognized through the analysis is then sent to a server.

[1364] The server adjusts the content and display format of the warning message based on the received emotional data. For example, if the user is feeling stressed, the warning message can be softened. For example, "Warning! This email may be fraudulent" can be changed to "Please be careful. This email may be fraudulent, so please check it."

[1365] Emotional data is stored in a database as a history, and warning messages are optimized using past emotional data, allowing for more appropriate and friendly warning messages to be provided to users.

[1366] Device behavior

[1367] The device will display a warning icon and a pop-up warning message on any emails suspected of being BEC emails in the user's email list. The user can click on the message to view detailed information about the BEC email.

[1368] The emotion engine allows the device to continuously analyze the user's facial expressions and voice and transmits the results to the server in real time, enabling it to respond appropriately to the user's emotional state.

[1369] User operations

[1370] Users can check the warning icon or notification displayed on their device and click to view detailed information about the suspected BEC email. Based on the warning message, they can manually delete the email, move it to a quarantine folder, or reevaluate it as legitimate.

[1371] This system takes into account the user's emotional state, detects BEC emails with high accuracy, and provides effective measures to reduce the psychological burden.

[1372] The flow of the identification process in the second embodiment will be described with reference to FIG.

[1373] Step 1: Generating BEC emails using generative AI

[1374] At the beginning of each month, the server uses the generative AI model to generate BEC emails. The prompt text is entered as "Generate a new business email compromise (BEC) scenario. The target is an executive at a mid-stream company, and the scenario is set to receive emails during work hours in the afternoon." Based on the entered prompt text, the generative AI model generates a BEC email, and its content is stored in a database. Characteristic signatures are extracted from the generated email and added to the database.

[1375] Input: prompt statement

[1376] Data processing: Generating BEC emails using AI and extracting signatures

[1377] Output: Generated BEC email, extracted signature

[1378] Step 2: Managing Signatures

[1379] The server stores the extracted signatures in a database and updates it regularly. It also collects BEC emails created by humans in the past and trains the AI ​​to improve the accuracy of the database. This process improves the accuracy of detecting BEC emails.

[1380] Input: Previous BEC emails, generated signatures

[1381] Data processing: Signature storage and learning

[1382] Output: Updated signature database

[1383] Step 3: Capture and analyze incoming emails

[1384] The server retrieves new incoming emails from the company's mail server every hour, analyzes them immediately, and generates new signatures from the email body and header information.

[1385] Input: Newly received email

[1386] Data processing: Email analysis, signature generation

[1387] Output: Generated signature

[1388] Step 4: Signature Matching

[1389] The server compares the generated signature with existing BEC signatures in its database. If the signatures match, the email is deemed to be a suspected BEC scam. Specifically, text mining technology is used to analyze the email content and match it with existing BEC signatures.

[1390] Input: Generated signature

[1391] Data processing: Signature comparison

[1392] Output: Comparison result (match / mismatch)

[1393] Step 5: Generate and send an alert

[1394] The server generates a warning message for emails suspected of being BEC scams and sends it to the user's device. The generated warning message includes the characteristics of BEC emails and the measures the user should take. The server also automatically moves the email to a quarantine folder or deletes it.

[1395] Input: Comparison result (if match)

[1396] Data processing: Generate warning messages, move / delete emails

[1397] Output: Warning message, email moved to quarantine / deleted email

[1398] Step 6: Emotion Recognition

[1399] The device uses a built-in camera and microphone to capture the user's facial expressions and voice, and analyzes the input data with an emotion engine. The user's emotional data recognized through the analysis is then sent to the server.

[1400] Input: User's facial expression and voice data

[1401] Data processing: Emotion analysis using an emotion engine

[1402] Output: User emotion data

[1403] Step 7: Customizing the warning message

[1404] The server customizes the content and display format of the warning message based on the user's emotional data. For example, if the user is feeling stressed, the server changes the tone of the warning message to a gentler tone. This customization information is also stored in the database.

[1405] Input: User emotion data

[1406] Data Processing: Customizing warning messages

[1407] Output: Customized warning message

[1408] Step 8: Displaying warning messages

[1409] The device will display a warning icon next to suspected BEC emails in the user's email list, and when the user clicks on the icon, a customized warning message will pop up.

[1410] Input: Customized warning message

[1411] Data processing: Display warning message

[1412] Output: Warning icon, popup message

[1413] Step 9: User interaction

[1414] Users can check the warning icons and notifications displayed on their devices, click on them to view detailed information about the suspected BEC email, and then manually delete the email, move it to a quarantine folder, or reassess it as legitimate.

[1415] Input: Warning notification, more information

[1416] Data processing: Email operations (manual deletion, movement, re-evaluation)

[1417] Output: Updated email status (delete, quarantine, reevaluate)

[1418] In this way, the entire system works together to detect BEC emails with high accuracy while reducing the psychological burden on users, and provides appropriate warnings and quick responses.

[1419] (Application example 2)

[1420] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."

[1421] When sending or receiving business emails, there is a need for a system that can automatically detect business email compromise (BEC) emails with high accuracy and issue appropriate warnings to users. However, conventional systems use uniform warning messages, making it difficult to respond flexibly to the user's emotional state. This increases the user's psychological burden, and can lead to delayed responses or oversight of messages. To solve these issues, a flexible warning system that takes into account the user's emotional state as well as highly accurate detection of BEC emails is required.

[1422] The identification process by the identification processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means. In this invention, the server includes: means for generating multiple business email fraud emails using a generation AI; means for extracting signatures from the generated business email fraud emails; means for saving the extracted signatures in a database; means for acquiring received emails; means for generating signatures from the acquired received emails; means for comparing the generated signatures with signatures in the database; means for determining whether the received emails are suspected of being business email fraud based on the comparison results; means for generating a warning message for the relevant emails; means for sending the warning message to a user; means for moving or deleting the relevant emails to a quarantine folder; means for recognizing a user's emotional state and acquiring emotional data; means for customizing the warning message based on the acquired emotional data; and means for saving and managing the emotional data history in a database. This enables highly accurate detection of BEC emails and flexible display of warning messages according to the user's emotional state.

[1423] "Generative AI" is an artificial intelligence system that uses machine learning and neural network techniques to automatically generate new data patterns and text.

[1424] "Business email compromise" refers to fraudulent emails sent to businesses or organizations with the intent of fraudulently obtaining financial or other sensitive information.

[1425] A "signature" is data that indicates characteristics specific to fraudulent emails, extracted based on the content and structure of the email.

[1426] A "database" is a system or software for storing and managing data efficiently and systematically.

[1427] "Emotion recognition" is the technology of identifying a person's emotional state through the analysis of facial expressions, voice tone, and text.

[1428] A "warning message" is a message that contains information to notify a user of a particular situation or condition and to call their attention.

[1429] A "quarantine folder" is an email folder that stores suspicious or malicious emails separately from your regular inbox.

[1430] "History management" is a system or process that stores records of past data or events so that they can be analyzed and referenced.

[1431] This invention relates to a system that uses a generative AI system to detect business email compromise (BEC) emails with high accuracy, warn users, and understand the user's emotional state and customize the warning message based on that.

[1432] Server Operation Overview

[1433] The server system is constructed using the following hardware and software: The hardware is a server computer equipped with a high-performance processor, memory, and storage. The software uses a generative AI tool, a database system (MySQL), an email analysis library (Apache James), an emotion recognition engine (Microsoft's Azure Emotional Analysis API), and a backend framework (Node.js, Express).

[1434] At the beginning of the month, the server uses the generative AI model to generate new BEC emails, extracts characteristic signatures from these emails, and stores them in a database.

[1435] The server retrieves new incoming emails from the company's email server every hour and analyzes their contents using an email analysis library. The analyzed email signatures are compared with the BEC signatures in the existing database. If a suspicious email is found, a warning message is generated for that email.

[1436] The server uses Microsoft's Azure Emotional Analysis API to obtain user emotional data and determine the emotional state the user was in when receiving the email. This emotional data is then stored in a database as a history.

[1437] About device operation

[1438] The system operates using the following technologies on user devices, which can be smartphones, tablets, or desktop computers. The devices use Google ML Kit to analyze facial expressions and voice tones to obtain emotion data.

[1439] When a user receives an email on their device, the emotion recognition system captures their facial expressions and voice and analyzes their emotional state in real time, and this data is sent to the server.

[1440] The warning message sent from the server is customized according to the user's emotional state and displayed on the device. For example, if the user is determined to be in a stressful state, the warning message will be displayed in a soft tone.

[1441] User operations

[1442] The user can check the warning message displayed on the terminal and check the detailed information of the email.

[1443] You can choose to move the email to a quarantine folder, delete it, or re-evaluate it as legitimate.

[1444] Examples of concrete examples and prompts

[1445] Specific examples

[1446] While a user is checking work emails on their smartphone while out and about, the server determines that they have received a BEC email. If the emotion engine determines that the user is under stress, it changes the usual stiff warning message to a softer tone, saying, "Thank you for your hard work. An email requiring your attention has been found. Please remain calm and take appropriate action."

[1447] Prompt Sentence Examples

[1448] Generate customized warning messages when the user's emotional state is stressed.

[1449] Original warning message:

[1450] "Warning! Suspicious email found. Please review immediately."

[1451] Customized warning message:

[1452] "Thank you for your hard work. We've found an email that needs your attention. Please stay calm and take care of it."

[1453] In this way, we provide a system that reduces the psychological burden on users and strengthens security through BEC email detection and emotion-customized warning messages.

[1454] The flow of the specific processing in the application example 2 will be described with reference to FIG.

[1455] Step 1:

[1456] The server uses the generative AI model to generate new BEC emails at the beginning of each month. It extracts characteristic signatures from the generated emails and stores them in a database. The input is the email data generated by the generative AI model, and the output is the extracted signature data. New signature information is added to the database.

[1457] Step 2:

[1458] The server retrieves new incoming emails from the company's email server every hour. It uses an email analysis library (Apache James) to analyze the content of the retrieved emails and generate a signature from them. The input is new email data retrieved from the company's email server, and the output is the generated signature data. The signature is obtained by analyzing the email content.

[1459] Step 3:

[1460] The server compares the generated signature with existing BEC signatures in the database. Based on the comparison results, it determines whether the received email is suspected of being a business email compromise. The input is the newly generated signature and existing signatures in the database, and the output is the determination result of whether or not there is suspicion of BEC. The signature is matched by referring to the information in the database.

[1461] Step 4:

[1462] The server generates a warning message for emails that are suspected of being BEC attacks. The input is the email data that is suspected of being BEC attacks, and the output is the warning message. The generated warning message is created based on a template.

[1463] Step 5:

[1464] The server sends the generated warning message to the user's terminal. The input is the generated warning message, and the output is the successful transmission of the warning message to the user's terminal. The message is sent to the user's terminal via the network.

[1465] Step 6:

[1466] When receiving a warning message, the device captures facial expressions and voice to obtain emotional data in order to recognize the user's emotional state. Analysis is performed using Google ML Kit. The input is the user's facial expression data and voice data, and the output is the recognized emotional data. The emotional state is analyzed in real time and sent to the server.

[1467] Step 7:

[1468] The server customizes the warning message based on the acquired emotion data. The input is the recognized emotion data and the original warning message, and the output is the customized warning message. The message content is adjusted based on the emotion data.

[1469] Step 8:

[1470] The terminal displays a customized warning message to the user. The input is the customized warning message, and the output is the warning message displayed on the terminal screen. The message is presented to the user visually and audibly.

[1471] Step 9:

[1472] The user checks the warning icon or notification displayed on the device and views the details of the received email. The input is the warning notification displayed on the device, and the output is the detailed information of the email viewed by the user. The user clicks on the warning message to view the details.

[1473] Step 10:

[1474] The user can move the email to a quarantine folder, delete it, or reassess it as legitimate. The input is the user's choice of action, and the output is the quarantine, new assessment, or deletion of the email. The user selects the appropriate action, and the system processes the email according to that choice.

[1475] The specific processing unit 290 transmits the result of the specific processing to the headset type terminal 314. In the headset type terminal 314, the control unit 46A causes the speaker 240 and the display 343 to output the result of the specific processing. The microphone 238 acquires audio indicating a user input regarding the result of the specific processing. The control unit 46A transmits audio data indicating the user input acquired by the microphone 238 to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.

[1476] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[1477] In the above embodiment, an example was given in which the specific processing is performed by the data processing device 12, but the technology of the present disclosure is not limited to this, and the specific processing may be performed by the headset type terminal 314.

[1478] [Fourth embodiment]

[1479] FIG. 7 shows an example of the configuration of a data processing system 410 according to the fourth embodiment.

[1480] 7, a data processing system 410 includes a data processing device 12 and a robot 414. An example of the data processing device 12 is a server.

[1481] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[1482] The robot 414 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication I / F 44, and a control target 443. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The microphone 238, the speaker 240, the camera 42, and the control target 443 are also connected to the bus 52.

[1483] The microphone 238 receives instructions and the like from the user 20 by receiving voice uttered by the user 20. The microphone 238 captures the voice uttered by the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio in accordance with instructions from the processor 46.

[1484] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the surroundings of user 20 (for example, an imaging range defined by an angle of view equivalent to the field of vision of a typical healthy person).

[1485] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 are responsible for the exchange of various information between the processor 46 and the processor 28 via the network 54. The exchange of various information between the processor 46 and the processor 28 using the communication I / Fs 44 and 26 is carried out in a secure state.

[1486] The control object 443 includes a display device, LEDs in the eyes, and motors for driving the arms, hands, and feet. The posture and gestures of the robot 414 are controlled by controlling the motors of the arms, hands, and feet. Some of the emotions of the robot 414 can be expressed by controlling these motors. In addition, the facial expressions of the robot 414 can also be expressed by controlling the light emission state of the LEDs in the eyes of the robot 414.

[1487] Fig. 8 shows an example of the main functions of the data processing device 12 and the robot 414. As shown in Fig. 8, in the data processing device 12, a specific process is performed by the processor 28. A specific process program 56 is stored in the storage 32.

[1488] The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[1489] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[1490] In the robot 414, the processor 46 performs the reception output process. A reception output program 60 is stored in the storage 50. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.

[1491] Next, a description will be given of the specific processing performed by the specific processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."

[1492] The system of this invention uses generative AI to automatically detect business email compromise (BEC) emails and warn users. It also prevents BEC damage by moving the emails to a quarantine folder or deleting them. The details of the system and the program processing are explained below.

[1493] Server Operation

[1494] 1. Generating BEC emails using AI:

[1495] The server automatically generates new BEC emails at the beginning of each month or every few weeks using a generative AI tool, which uses advanced natural language processing techniques to make the emails appear like regular business emails.

[1496] The server stores the content of generated BEC emails in a database and extracts characteristic signatures from those emails.

[1497] 2. Signature Management:

[1498] The server sequentially adds signatures extracted from the generated BEC emails to the database and updates it regularly. It also trains the generation AI to learn from past BEC emails created by humans, strengthening these signatures.

[1499] 3. Acquiring and analyzing incoming emails:

[1500] The server periodically retrieves new incoming emails from the company's email server. For example, you can configure it to retrieve incoming emails every hour.

[1501] The server analyzes the content of the received emails and generates signatures from these emails as well.

[1502] 4. Signature Matching:

[1503] The server compares the generated signature with the signatures in its database to determine if there is a match.

[1504] 5. Generate and send alerts:

[1505] The server generates a warning message for any emails that match the signature. The warning message contains information about the email and indicates that it is suspected of being a BEC scam.

[1506] The server generates a warning message, sends it to the user, and moves the affected email to a quarantine folder or deletes it.

[1507] Device behavior

[1508] 1. Providing the user interface:

[1509] The terminal displays a list of received emails to the user and displays a warning icon based on the results of the system's automatic analysis.

[1510] The terminal displays a warning message so that the user can check the details of the received email.

[1511] 2. Receiving and acting on warning messages:

[1512] The terminal notifies the user of the warning message received from the server together with its contents.

[1513] When a warning message appears on the device, the user is given the option to easily move the email to a quarantine folder or delete it.

[1514] User operations

[1515] 1. Check notifications:

[1516] The user checks the warning icon or notification displayed on the device.

[1517] The user clicks on the warning message to view the details and realizes that it may be a BEC email.

[1518] 2. Email Operations:

[1519] After reviewing the warning message, users can choose to move the email to a quarantine folder, delete it, or re-evaluate it as legitimate.

[1520] Specific examples

[1521] Scenario 1:

[1522] 1. At the beginning of each month, the server generates 20 new BEC emails using the generation AI and stores their signatures in a database.

[1523] 2. Check incoming emails every hour and analyze their contents.

[1524] 3. During a certain period of time, an incoming email is detected that matches the signature of a generated BEC email.

[1525] 4. The server generates a warning message and moves the affected email to a quarantine folder.

[1526] 5. A warning notification will appear on the user's device, and the user will check the email, confirm that it is a scam, and delete it.

[1527] This makes it possible to detect BEC emails quickly and accurately, preventing harm to users before it occurs.

[1528] The processing flow will be explained below.

[1529] Step 1:

[1530] At the beginning of each month, the server launches the AI ​​tool to generate 20 new Business Email Compromise (BEC) emails. The generated emails are written in a natural style and are designed to look like real business emails.

[1531] Step 2:

[1532] The server extracts characteristic signatures from the 20 generated BEC emails and stores them in a database. The signatures represent important characteristics and patterns of each BEC email.

[1533] Step 3:

[1534] The server collects BEC emails created by humans in the past, generates signatures for them, and adds them to the database, further strengthening the signature database.

[1535] Step 4:

[1536] The server retrieves new incoming emails from the company's mail server every hour, for example by connecting to the mail server and finding the latest incoming emails.

[1537] Step 5:

[1538] The server analyzes the content of the received email and generates a signature from it. This signature generation process uses the same method as the signature of the BEC email saved earlier.

[1539] Step 6:

[1540] The server compares the generated signature of the received email with the BEC signatures in the database. The comparison algorithm calculates the degree of match between each signature, and if there is a high degree of match, the email is determined to be suspected of being a BEC scam.

[1541] Step 7:

[1542] If the match is high, the server generates a warning message and sends it to the user's device, including information about the email, such as the sender, subject, and match level.

[1543] Step 8:

[1544] The server will move any incoming email that generates a warning message to a quarantine folder, and can be configured to automatically delete the email if desired.

[1545] Step 9:

[1546] The device displays a list of received emails and notifies the user of any warning messages received from the server. The warning icon allows the user to identify suspicious emails at a glance.

[1547] Step 10:

[1548] The user can click the warning icon displayed on the device to view the details of the warning message. The user can also check the contents of the email and view further details.

[1549] Step 11:

[1550] Users can follow the instructions in the warning message to manually delete the email or move it to a quarantine folder, or if they determine it to be legitimate, they can choose to move it back to a regular folder.

[1551] Step 12:

[1552] The server periodically checks the emails moved to the quarantine folder and deletes them after a certain period of time. The deletion rules and storage period are set by the administrator.

[1553] Example 1

[1554] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."

[1555] In today's business environment, fraud via business email counterfeiting (BEC) has become a major problem. In particular, the risk of companies and individuals suffering financial losses due to users receiving sophisticated forged emails is increasing. Conventional email filtering systems have difficulty effectively detecting and preventing these sophisticated forged emails, and new systems are needed to ensure user safety.

[1556] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.

[1557] In this invention, the server includes means for generating multiple counterfeit business emails using a generation AI, means for extracting characteristic patterns from the generated counterfeit business emails, means for saving the extracted characteristic patterns in a database, means for acquiring received emails, means for generating characteristic patterns from the acquired received emails, means for comparing the generated characteristic patterns with characteristic patterns in the database, means for determining whether the received emails are suspected of being counterfeit business emails based on the comparison results, means for generating a warning message for the corresponding emails, means for sending the warning message to the user, means for moving or deleting the corresponding emails to a quarantine folder, means for generating a warning message including an overview of the corresponding emails and a warning message and notifying the user of the warning message, and means for providing operation options for quarantining, deleting, or reevaluating the emails as legitimate, thereby enabling rapid and highly accurate detection and prevention of BEC emails.

[1558] "Generative AI" is a system that uses artificial intelligence technology to automatically generate new content (in this case, counterfeit business emails).

[1559] "Forged business email" is a forged email disguised as a normal business email sent with the intent to defraud.

[1560] A "characteristic pattern" is a specific pattern contained in elements such as email content, subject, sender address, and destination URL, and is used to identify counterfeit business emails.

[1561] A "database" is a structured information storage system for effectively storing and managing the generated characteristic patterns.

[1562] "Incoming email" refers to all emails received by a company or user.

[1563] The "warning message" is a warning message that notifies the user that the received email may be a forged business email.

[1564] A "quarantine folder" is a specific email folder that temporarily stores suspicious emails and keeps them separate from other regular emails.

[1565] "Action options" are the choices provided to a user to take action on a suspicious email (e.g., quarantine, delete, reassess).

[1566] The system of this invention uses generative AI to automatically detect forged emails intended for business email compromise (BEC) and warn users. It also prevents BEC damage by moving or deleting the forged emails in question to a quarantine folder.

[1567] Server Operation

[1568] Generating BEC emails using generative AI

[1569] The server automatically generates new BEC emails periodically using a generative AI tool (e.g., GPT-4). This allows emails based on the latest fraud techniques to be constantly added to the database. The server inputs prompt phrases such as "invoice from a customer" or "urgent payment request" into the generative AI, and saves the generated email content in the database.

[1570] Extracting and saving signatures

[1571] The server extracts characteristic patterns (signatures) from the generated BEC emails and stores them in a database using a natural language processing (NLP) algorithm to extract distinctive patterns from the email body, subject, sender address, destination URL, etc.

[1572] Acquiring and analyzing received emails

[1573] The server periodically retrieves new incoming emails from the company's mail server using IMAP or POP3 protocols, analyzes the emails using NLP algorithms, and generates signatures.

[1574] Signature Matching

[1575] The server analyzes the signature of the incoming email and compares it with the signatures in its existing database using fast search algorithms (e.g. hash functions or binary searches). If a match is found, the email is marked as suspected BEC.

[1576] Generate and send alerts

[1577] The server generates a warning message for any emails suspected of being BEC. This message includes a summary of the email and a warning. The warning message is sent to the user, and the email is moved to a quarantine folder or deleted.

[1578] Device behavior

[1579] Providing a user interface

[1580] The terminal displays a list of received emails and a warning icon to the user. If an abnormality is detected in an email, a warning icon will be displayed, and clicking the icon will display a detailed warning message in a pop-up.

[1581] Receiving and acting on warning messages

[1582] The terminal notifies the user of warning messages from the server and provides action options (quarantine, delete, or reassess as legitimate email), allowing the user to handle the email quickly and accurately.

[1583] User operations

[1584] Checking notifications

[1585] Users can check the warning icon or notification displayed on their device and click to open the details of the warning message to get a detailed understanding of whether the email is suspected to be a BEC scam.

[1586] Email Operations

[1587] After reviewing the warning message, users can choose to move the email to a quarantine folder, delete it, or re-evaluate it as legitimate.

[1588] Specific examples

[1589] Scenario 1:

[1590] 1. At the beginning of each month, the server generates 20 new BEC emails using the generation AI and stores their signatures in a database. An example prompt is "Generate an email proposing a new invoice format."

[1591] 2. Check incoming emails every hour and analyze their contents using natural language processing algorithms.

[1592] 3. During a certain period of time, the server detects that an incoming email matches the signature of a generated BEC email and records this as a flag.

[1593] 4. The server generates a warning message and moves the affected email to a quarantine folder.

[1594] 5. A warning notification will appear on the user's device, and the user will check the email, determine that it is a scam, and delete it.

[1595] This makes it possible to detect and prevent BEC emails quickly and accurately, preventing harm to users before it occurs.

[1596] The flow of the identification process in the first embodiment will be described with reference to FIG.

[1597] Step 1:

[1598] Generating BEC emails using generative AI

[1599] The server generates BEC emails using a generative AI model (e.g., GPT-4) and inputs a prompt such as "Generate an email proposing a new invoice format."

[1600] Input: Prompt text "Generate an email proposing a new invoice format."

[1601] Data processing: The generative AI model uses natural language processing based on the prompt text to generate fraudulent business emails.

[1602] Output: The generated BEC email.

[1603] Specific operation: The server saves the automatically generated email as a file and converts its content into a text format for analysis.

[1604] Step 2:

[1605] Extracting and saving signatures

[1606] The server extracts characteristic patterns (signatures) from the content of the generated BEC email.

[1607] Input: The generated BEC email.

[1608] Data processing: Using natural language processing algorithms, characteristic patterns are extracted from elements such as the email body, subject, sender address, and destination URL.

[1609] Output: The extracted signature.

[1610] Specific operation: The server adds the extracted signature to a database and creates an index to match and classify it with existing signatures.

[1611] Step 3:

[1612] Acquiring and analyzing received emails

[1613] The server periodically retrieves new incoming emails from the company's mail server.

[1614] Input: Incoming emails stored on your company's email server.

[1615] Data processing: Received emails are imported to the server using the IMAP or POP3 protocol, and the email content is analyzed using natural language processing algorithms.

[1616] Output: Parsed signature of the incoming email.

[1617] How it works: The server communicates with the mail server every hour, downloads new emails, and analyzes them using techniques such as tokenization and feature extraction.

[1618] Step 4:

[1619] Signature Matching

[1620] The server analyzes the signature of the incoming email and compares it with the signatures in its existing database.

[1621] Input: Parsed signatures from incoming emails and signatures in the database.

[1622] Data processing: Using a fast search algorithm (e.g. hash function or binary search) to match the signature.

[1623] Output: A list of matching signatures.

[1624] What it does: The server goes through a matching process, lists matching signatures, and flags emails that are suspected to be BEC.

[1625] Step 5:

[1626] Generate and send alerts

[1627] The server generates a warning message for emails suspected of being BEC and sends it to the user.

[1628] Input: Incoming email where a matching signature was found.

[1629] Data processing: Generate a warning message that includes a summary of the email and a warning.

[1630] Output: A warning message.

[1631] Specific actions: The server will send a warning message to the user's email address and simultaneously move the email to a quarantine folder or delete it.

[1632] Step 6:

[1633] Providing a user interface

[1634] The terminal displays a list of received emails and a warning icon to the user.

[1635] Input: Incoming emails and warning messages from the server.

[1636] Data Processing: Added warning icon and popup warning message.

[1637] Output: The email list and warning messages displayed in the user interface.

[1638] Specific operation: The terminal displays a list of received emails to the user through the email client software and provides an interface including a warning icon.

[1639] Step 7:

[1640] Receiving and acting on warning messages

[1641] Users can review the warning message and quarantine, delete, or reevaluate the email as legitimate.

[1642] Input: Warning messages and action options displayed on the terminal.

[1643] Data manipulation: Moves the email to a quarantine folder, deletes it, or re-evaluates it based on the user's choice.

[1644] Output: Change the state of the email depending on the user's selection.

[1645] Specific actions: The user checks the warning icon displayed on the device, clicks it to open a detailed warning message, and then performs the action on the relevant email.

[1646] (Application example 1)

[1647] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."

[1648] Conventional business email compromise (BEC) countermeasure systems rely on static rule-based analysis, making it difficult to respond quickly to new and changing fraudulent methods. Furthermore, users have few ways to know in real time whether an email they receive is fraudulent, making it difficult to take appropriate action immediately and preventing damage before it occurs. Furthermore, the user interface when a fraudulent email is detected is inadequate, making it difficult for users to easily and quickly handle the email.

[1649] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.

[1650] In this invention, the server includes: means for generating multiple business email fraud emails using a generation AI; means for extracting signatures from the generated business email fraud emails; means for storing the extracted signatures in a database; means for acquiring received emails; means for generating signatures from the acquired received emails; means for comparing the generated signatures with signatures in the database; means for determining whether the received emails are suspected of being business email fraud based on the comparison results; means for generating a warning message for the suspected emails; means for sending the warning message to a user; means for moving the suspected emails to a quarantine folder or deleting them; means for notifying the user of the warning message in real time on a mobile device of the user and providing a user interface that allows the user to move the suspected emails to a quarantine folder, delete them, or reassess them as legitimate; and means for the user to review and manipulate the suspected fraud emails. This enables advanced fraud email detection and real-time notification using the generation AI, as well as a user-friendly operation interface, thereby preventing fraud damage before it occurs.

[1651] "Generative AI" refers to a model that uses artificial intelligence technology to generate artificial content.

[1652] "Business email compromise" refers to a method of committing forgery or fraud by disguising emails as business-related.

[1653] A "signature" refers to a characteristic pattern or identifier contained in the content of an email.

[1654] "Database" refers to a system that collects and manages signatures and important data in one place.

[1655] "Mobile device" refers to a portable electronic device such as a smartphone or tablet.

[1656] "User interface" refers to the display screen and operating means through which a user interacts with a system.

[1657] A "quarantine folder" is a folder that stores suspicious or fraudulent emails received separately from other emails.

[1658] "Real-time notification" refers to a function that notifies the user of information immediately at the moment a relevant event occurs.

[1659] "Reevaluating as legitimate" refers to the user manually reconfirming an email as legitimate when the email has been mistakenly determined to be fraudulent.

[1660] "User" refers to an individual or company that uses this system.

[1661] The system of this invention uses a generative AI model to automatically detect fraudulent emails and send warning notifications to users in order to prevent damage caused by business email compromise (BEC). The operation of the server and terminal is described in detail below.

[1662] Server Operation

[1663] 1. Generating BEC emails using AI:

[1664] The server periodically generates new BEC emails using a generative AI model, which uses advanced natural language processing techniques to make the emails appear like regular business emails.

[1665] The content of the generated BEC emails is stored in a database and characteristic signatures are extracted from those emails.

[1666] 2. Signature Management:

[1667] The server sequentially adds the signatures extracted from the generated BEC emails to the database and updates it periodically.

[1668] The generation AI also learns from past artificially created BEC emails to strengthen the signature.

[1669] 3. Acquiring and analyzing incoming emails:

[1670] The server connects to the company's mail server and periodically (for example, every hour) retrieves new incoming emails.

[1671] It analyzes the emails it receives and generates signatures from them.

[1672] 4. Signature Matching:

[1673] The server compares the generated signature with the signatures in its database to determine if there is a match.

[1674] 5. Generate and send alerts:

[1675] If a signature matches an incoming email, a warning message will be generated containing information about the email.

[1676] The server sends the generated warning message to the user's mobile device and moves or deletes the relevant email in a quarantine folder.

[1677] Device behavior

[1678] 1. Providing the user interface:

[1679] The user interface displays a list of received emails to the user and displays a warning icon based on the results of automatic analysis by the system.

[1680] A warning message will be displayed, allowing the user to view details of the affected received email.

[1681] 2. Receiving and acting on warning messages:

[1682] The terminal notifies the user of the warning message received from the server together with its contents.

[1683] When a warning message appears, users are given the option to move the email to a quarantine folder or delete it.

[1684] User operations

[1685] 1. Check notifications:

[1686] The user checks the warning icon or notification displayed on the device.

[1687] Click on the warning message to see more details and understand that it may be a BEC email.

[1688] 2. Email Operations:

[1689] After checking the contents of the warning message, the user can choose to move the email to a quarantine folder, delete it, or re-evaluate it as legitimate.

[1690] Specific examples

[1691] If a user receives an email during a certain time period saying, "Please change the transfer destination to this address," the server analyzes the email and detects that it matches the signature of a previous BEC email. The server then sends a warning notification to the user's mobile device in real time and moves the email to a quarantine folder. The user who receives this notification can click on the warning message to check the details of the email and, if necessary, delete it as a fraudulent email.

[1692] Prompt Sentence Examples

[1693] "Email body: 'Thank you for your hard work. Your bank transfer details have changed, so we are sending you the new account details. Please confirm and confirm...'"

[1694] The above system enables advanced fraudulent email detection using generative AI, real-time notification, and a user-friendly operation interface, making it possible to prevent fraudulent incidents before they occur.

[1695] The flow of the specific processing in the application example 1 will be described with reference to FIG.

[1696] Step 1:

[1697] The server uses AI to generate multiple business email compromise emails.

[1698] Input: Enter a prompt for the generative AI model. "Email body: 'Thank you for your hard work. Your bank transfer details have changed, so we are sending you the new account details. Please confirm and confirm...'"

[1699] How it works: It uses a generative AI model (e.g., GPT-2) to generate BEC emails based on prompts.

[1700] Output: The generated BEC email.

[1701] Step 2:

[1702] The server extracts the signature from the generated BEC email.

[1703] Input: The generated BEC email.

[1704] How it works: Analyzes email content and extracts signatures (characteristic patterns or identifiers).

[1705] Output: The extracted signature.

[1706] Step 3:

[1707] The server stores the extracted signatures in a database.

[1708] Input: The extracted signature.

[1709] Behavior: Saves the signature to the database and updates the existing signature list.

[1710] Output: The updated database.

[1711] Step 4:

[1712] The server retrieves the incoming email.

[1713] Input: Your mail server login and connection information.

[1714] What it does: It connects to your company's mail server using the IMAP protocol and retrieves new incoming emails.

[1715] Output: The received emails retrieved.

[1716] Step 5:

[1717] The server generates a signature from the received email.

[1718] Input: The received emails retrieved.

[1719] How it works: Analyzes incoming emails and generates a new signature from their contents.

[1720] Output: The new signature.

[1721] Step 6:

[1722] The server compares the newly generated signature with the signatures in its database.

[1723] Input: New signatures and existing signatures in the database.

[1724] How it works: It runs an algorithm that compares the new signature with signatures in the database to determine if there is a match.

[1725] Output: Comparison result (match / not match).

[1726] Step 7:

[1727] The server generates a warning message for the affected email.

[1728] Input: Comparison result (if the signatures match).

[1729] Behavior: Generates a warning message containing the contents of the email.

[1730] Output: The warning message generated.

[1731] Step 8:

[1732] The server sends a warning message to the user's mobile device.

[1733] Input: The generated warning message and the user's mobile device information.

[1734] What it does: Sends a warning message to the user's mobile device.

[1735] Output: The warning message displayed on the user's mobile device.

[1736] Step 9:

[1737] The server moves the email to a quarantine folder or deletes it.

[1738] Input: Comparison result (if signature matches) and corresponding received email.

[1739] Action: The email will be moved from the inbox to a quarantine folder or deleted.

[1740] Output: Emails moved to quarantine folder or deleted.

[1741] Step 10:

[1742] The device will notify the user of a warning message and allow them to check and handle the relevant email.

[1743] Input: The warning message sent by the server.

[1744] What it does: Displays a warning message to the user, offering further details and options to delete the email or move it to a quarantine folder.

[1745] Output: User interaction to manage emails.

[1746] Step 11:

[1747] The user checks the relevant email and takes action.

[1748] Input: The warning message displayed on the terminal and detailed information about the email in question.

[1749] Action: The user reviews the email details and takes action to move it to quarantine, delete it, or reassess it as legitimate.

[1750] Output: Operation result (quarantine, delete, or re-evaluate the email).

[1751] Furthermore, an emotion engine that estimates the user's emotion may be further combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59, and perform identification processing using the user's emotion.

[1752] Overall overview

[1753] This invention provides a system that uses generative AI to automatically detect business email compromise (BEC) emails and warn users, as well as a system that combines an emotion engine that recognizes the user's emotions. This system has functions to reduce the psychological burden on users, such as adjusting and customizing warning messages based on their emotional state and managing emotional data history.

[1754] Server Operation

[1755] 1. Generating BEC emails using AI:

[1756] At the beginning of each month, the server uses a generative AI tool to generate new Business Email Compromise (BEC) emails, which are then stored in a database and characteristic signatures are extracted from the emails.

[1757] 2. Signature Management:

[1758] The server stores the signatures extracted from the generated emails in a database and updates it regularly. It also collects BEC emails created by humans in the past and trains the generation AI on them. This strengthens the signature database and enables highly accurate detection.

[1759] 3. Acquiring and analyzing incoming emails:

[1760] The server retrieves new incoming emails from the company's mail server every hour and analyzes their contents, generating a signature from the incoming email.

[1761] 4. Signature Matching:

[1762] The server compares the signature generated from the received email with the BEC signatures in its database to determine if there is a match.

[1763] 5. Generate and send alerts:

[1764] The server generates a warning message for any incoming emails suspected of being BEC scams based on the signature matching results. The generated warning message is sent to the user's device, and the email is then moved to a quarantine folder or deleted.

[1765] Emotion Engine Operation

[1766] 1. Emotion recognition:

[1767] The device analyzes the user's facial expressions, voice, and input data, and recognizes the user's emotional state using an emotion engine. The recognized emotional data is then sent to the server.

[1768] 2. Customize the warning message:

[1769] The server customizes the content and presentation of the warning message based on the user's emotional state, for example, if the user is stressed, the warning message will be displayed in a more understandable and gentle tone.

[1770] 3. Emotion data history management:

[1771] The server stores the user's emotional state as historical data, which allows for optimization of warning messages based on past emotional data.

[1772] Device behavior

[1773] 1. Displaying a warning message:

[1774] The device displays a list of received emails to the user, and displays a warning icon for emails suspected of being BEC. The warning message is displayed with customized content based on the emotion engine.

[1775] 2. Emotion Recognition and Feedback:

[1776] The device uses an emotion engine to recognize the user's face and analyze their voice, and sends the results to a server, enabling it to respond appropriately to the user's emotional state.

[1777] User operations

[1778] 1. Check notifications:

[1779] Users can check the warning icon or notification displayed on their device and click on the warning message to view detailed information about the suspected BEC email.

[1780] 2. Email Operations:

[1781] Based on the warning message and the identified emotional state, users have the option to manually delete the email, move it to a quarantine folder, or reassess it as legitimate.

[1782] Specific examples

[1783] Scenario: A user is experiencing stress

[1784] 1. At the beginning of the month, the server generates a new BEC email using the generation AI and stores its signature in the database.

[1785] 2. The server retrieves new incoming emails from the company's email server every hour and determines that one of them is suspected to be a BEC scam.

[1786] 3. The server generates a warning message and sends it to the user.

[1787] 4. The device checks the user's emotional state using an emotion engine and recognizes that they are feeling stressed.

[1788] 5. The server changes the warning message to a softer tone based on the user's emotional state and sends it to the user.

[1789] 6. The user checks the warning notice displayed on the device and moves the relevant email to the quarantine folder.

[1790] This will reduce the psychological burden on users and realize a system that enables rapid and highly accurate detection of BEC emails.

[1791] The processing flow will be explained below.

[1792] Step 1:

[1793] At the beginning of each month, the server generates 20 new Business Email Compromise (BEC) emails using a generative AI tool, which stores the emails in a database and extracts their distinctive signatures.

[1794] Step 2:

[1795] The server sequentially adds and updates the database with signatures extracted from the 20 generated BEC emails. These signatures represent important characteristics and patterns of each BEC email.

[1796] Step 3:

[1797] The server collects BEC emails created by humans in the past, generates signatures for them, and adds them to the database, further strengthening the signature database and enabling high accuracy in detecting BEC emails.

[1798] Step 4:

[1799] The server retrieves new incoming emails from the company's mail server every hour, for example by connecting to the mail server using the IMAP or POP3 protocol to detect new incoming emails.

[1800] Step 5:

[1801] The server analyzes the content of the received emails and generates a signature for each email. The signature generation process uses the same method as for signatures extracted from BEC emails.

[1802] Step 6:

[1803] The server compares the generated signature of the received email with the BEC signatures in the database. The comparison algorithm calculates the degree of match between each signature, and if the degree of match is high, the email is determined to be suspected of being a BEC scam.

[1804] Step 7:

[1805] The server generates a warning message for any incoming emails suspected of being BEC emails, including information such as the sender, subject, and degree of similarity of the email.

[1806] Step 8:

[1807] The server activates an emotion engine to recognize the user's emotional state and receives emotion data from each user's device, including information based on facial recognition and voice analysis.

[1808] Step 9:

[1809] The server customizes the content and format of the warning message based on the user's emotional state as recognized by the emotion engine. For example, if the user is highly stressed, the message will be displayed in a gentle tone.

[1810] Step 10:

[1811] The server sends a customized warning message to the user's terminal, which helps the user to understand and respond to the warning appropriately.

[1812] Step 11:

[1813] The device will display a list of received emails and notify the user with a warning message. A warning icon will be displayed, allowing the user to identify emails that are suspected to be BEC.

[1814] Step 12:

[1815] The user clicks on the warning icon displayed on the device to check detailed information, reads the warning message adjusted by the emotion engine, and understands its content.

[1816] Step 13:

[1817] Users can follow the instructions in the warning message to move the affected email to a quarantine folder, delete it, or re-evaluate it as legitimate.

[1818] Step 14:

[1819] The server periodically checks the emails moved to the quarantine folder and automatically deletes them after a certain period of time, based on deletion rules set by the system administrator.

[1820] Step 15:

[1821] The server stores the emotion data collected by the emotion engine as a history and uses it to display future warning messages. This history data is used to display optimal warning messages that take into account the user's emotional state.

[1822] Example 2

[1823] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."

[1824] Business email compromise (BEC) is a major threat to companies, and its detection and response are extremely important. However, conventional systems not only have low accuracy in detecting BEC emails, but also often make it difficult for recipients to properly understand the warning messages. Furthermore, warning messages that do not take into account the recipient's emotional state can increase the psychological burden on users. Furthermore, there is a lack of countermeasures that utilize user emotional data, making it difficult to provide customized warning messages.

[1825] The specific processing by the specific processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means.

[1826] In this invention, the server includes means for generating multiple business email fraud emails using a generation AI, means for extracting signatures from the generated business email fraud emails, means for saving the extracted signatures in a database, means for acquiring received emails, means for generating signatures from the acquired received emails, means for comparing the generated signatures with signatures in the database, means for determining whether the received emails are suspected of being business email fraud based on the comparison results, means for generating a warning message for the relevant emails, means for sending the warning message to a user, means for moving or deleting the relevant emails to a quarantine folder, means for acquiring user emotion data using an emotion engine that recognizes the user's emotional state, means for customizing the warning message based on the acquired emotion data, and means for saving the user emotion data as a history in the database. This enables highly accurate detection of BEC emails and provision of appropriate warning messages, thereby reducing the psychological burden on users.

[1827] "Generative AI" refers to systems or algorithms that use artificial intelligence technology to automatically generate emails intended for business email compromise.

[1828] Business Email Compromise (BEC) refers to a fraudulent activity that targets corporate executives and employees by sending emails containing fraudulent instructions or requests in an attempt to defraud them of money or information.

[1829] A "signature" refers to a specific identifier used to identify and detect business email compromise emails, such as a characteristic phrase or link pattern.

[1830] A "database" is a data storage system that organizes and stores information so that it can be quickly searched and retrieved when needed.

[1831] An "emotion engine" refers to software or algorithms that analyze a user's facial expressions, voice, input data, etc. to recognize their emotional state.

[1832] "Warning messages" refer to notifications or alerts that warn users about emails that may be business email compromises.

[1833] A "quarantine folder" refers to a specific email folder that stores fraudulent or suspicious emails separately from other legitimate emails.

[1834] "Customization" refers to adjusting or changing content or presentation format based on the user's emotional state or specific conditions.

[1835] "History" refers to information that records events and data that occurred in the past and organizes them in chronological order.

[1836] MODE FOR CARRYING OUT THE INVENTION

[1837] This invention provides a system that uses generative AI to automatically detect business email compromise (BEC) emails and warn users, as well as a system that combines an emotion engine that recognizes user emotions. This system reduces the psychological burden on users and enables rapid and accurate detection of BEC emails.

[1838] Server Operation

[1839] At the beginning of each month, the server generates new BEC emails using a generative AI tool (such as OpenAI's GPT-4). An example prompt for generating emails is, "Generate a new business email compromise (BEC) scenario. The target is an executive at a midstream company who receives emails during the afternoon workday." The generated emails are stored in a database, and characteristic signatures are extracted from the emails.

[1840] The server stores the extracted signatures in a database and updates it regularly. It also collects BEC emails created by humans in the past and trains the AI ​​to improve the accuracy of the signature database. The server also retrieves newly received emails from the company's email server every hour and analyzes their contents. New signatures are generated from the analyzed emails.

[1841] The server compares the generated signature with existing BEC signatures in its database to determine whether they match. For emails suspected of being BEC, a warning message is generated and sent to the user's device. The warning message includes the characteristics of BEC emails and the steps the user should take, and the email is then moved to a quarantine folder or deleted.

[1842] Emotion Engine Operation

[1843] The device uses a built-in camera and microphone to capture the user's facial expressions, voice, and input data, which are then analyzed by an emotion engine (such as Microsoft's Azure Cognitive Services). The emotion data recognized through the analysis is then sent to a server.

[1844] The server adjusts the content and display format of the warning message based on the received emotional data. For example, if the user is feeling stressed, the warning message can be softened. For example, "Warning! This email may be fraudulent" can be changed to "Please be careful. This email may be fraudulent, so please check it."

[1845] Emotional data is stored in a database as a history, and warning messages are optimized using past emotional data, allowing for more appropriate and friendly warning messages to be provided to users.

[1846] Device behavior

[1847] The device will display a warning icon and a pop-up warning message on any emails suspected of being BEC emails in the user's email list. The user can click on the message to view detailed information about the BEC email.

[1848] The emotion engine allows the device to continuously analyze the user's facial expressions and voice and transmits the results to the server in real time, enabling it to respond appropriately to the user's emotional state.

[1849] User operations

[1850] Users can check the warning icon or notification displayed on their device and click to view detailed information about the suspected BEC email. Based on the warning message, they can manually delete the email, move it to a quarantine folder, or reevaluate it as legitimate.

[1851] This system takes into account the user's emotional state, detects BEC emails with high accuracy, and provides effective measures to reduce the psychological burden.

[1852] The flow of the identification process in the second embodiment will be described with reference to FIG.

[1853] Step 1: Generating BEC emails using generative AI

[1854] At the beginning of each month, the server uses the generative AI model to generate BEC emails. The prompt text is entered as "Generate a new business email compromise (BEC) scenario. The target is an executive at a mid-stream company, and the scenario is set to receive emails during work hours in the afternoon." Based on the entered prompt text, the generative AI model generates a BEC email, and its content is stored in a database. Characteristic signatures are extracted from the generated email and added to the database.

[1855] Input: prompt statement

[1856] Data processing: Generating BEC emails using AI and extracting signatures

[1857] Output: Generated BEC email, extracted signature

[1858] Step 2: Managing Signatures

[1859] The server stores the extracted signatures in a database and updates it regularly. It also collects BEC emails created by humans in the past and trains the AI ​​to improve the accuracy of the database. This process improves the accuracy of detecting BEC emails.

[1860] Input: Previous BEC emails, generated signatures

[1861] Data processing: Signature storage and learning

[1862] Output: Updated signature database

[1863] Step 3: Capture and analyze incoming emails

[1864] The server retrieves new incoming emails from the company's mail server every hour, analyzes them immediately, and generates new signatures from the email body and header information.

[1865] Input: Newly received email

[1866] Data processing: Email analysis, signature generation

[1867] Output: Generated signature

[1868] Step 4: Signature Matching

[1869] The server compares the generated signature with existing BEC signatures in its database. If the signatures match, the email is deemed to be a suspected BEC scam. Specifically, text mining technology is used to analyze the email content and match it with existing BEC signatures.

[1870] Input: Generated signature

[1871] Data processing: Signature comparison

[1872] Output: Comparison result (match / mismatch)

[1873] Step 5: Generate and send an alert

[1874] The server generates a warning message for emails suspected of being BEC scams and sends it to the user's device. The generated warning message includes the characteristics of BEC emails and the measures the user should take. The server also automatically moves the email to a quarantine folder or deletes it.

[1875] Input: Comparison result (if match)

[1876] Data processing: Generate warning messages, move / delete emails

[1877] Output: Warning message, email moved to quarantine / deleted email

[1878] Step 6: Emotion Recognition

[1879] The device uses a built-in camera and microphone to capture the user's facial expressions and voice, and analyzes the input data with an emotion engine. The user's emotional data recognized through the analysis is then sent to the server.

[1880] Input: User's facial expression and voice data

[1881] Data processing: Emotion analysis using an emotion engine

[1882] Output: User emotion data

[1883] Step 7: Customizing the warning message

[1884] The server customizes the content and display format of the warning message based on the user's emotional data. For example, if the user is feeling stressed, the server changes the tone of the warning message to a gentler tone. This customization information is also stored in the database.

[1885] Input: User emotion data

[1886] Data Processing: Customizing warning messages

[1887] Output: Customized warning message

[1888] Step 8: Displaying warning messages

[1889] The device will display a warning icon next to suspected BEC emails in the user's email list, and when the user clicks on the icon, a customized warning message will pop up.

[1890] Input: Customized warning message

[1891] Data processing: Display warning message

[1892] Output: Warning icon, popup message

[1893] Step 9: User interaction

[1894] Users can check the warning icons and notifications displayed on their devices, click on them to view detailed information about the suspected BEC email, and then manually delete the email, move it to a quarantine folder, or reassess it as legitimate.

[1895] Input: Warning notification, more information

[1896] Data processing: Email operations (manual deletion, movement, re-evaluation)

[1897] Output: Updated email status (delete, quarantine, reevaluate)

[1898] In this way, the entire system works together to detect BEC emails with high accuracy while reducing the psychological burden on users, and provides appropriate warnings and quick responses.

[1899] (Application example 2)

[1900] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."

[1901] When sending or receiving business emails, there is a need for a system that can automatically detect business email compromise (BEC) emails with high accuracy and issue appropriate warnings to users. However, conventional systems use uniform warning messages, making it difficult to respond flexibly to the user's emotional state. This increases the user's psychological burden, and can lead to delayed responses or oversight of messages. To solve these issues, a flexible warning system that takes into account the user's emotional state as well as highly accurate detection of BEC emails is required.

[1902] The identification process by the identification processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means. In this invention, the server includes: means for generating multiple business email fraud emails using a generation AI; means for extracting signatures from the generated business email fraud emails; means for saving the extracted signatures in a database; means for acquiring received emails; means for generating signatures from the acquired received emails; means for comparing the generated signatures with signatures in the database; means for determining whether the received emails are suspected of being business email fraud based on the comparison results; means for generating a warning message for the relevant emails; means for sending the warning message to a user; means for moving or deleting the relevant emails to a quarantine folder; means for recognizing a user's emotional state and acquiring emotional data; means for customizing the warning message based on the acquired emotional data; and means for saving and managing the emotional data history in a database. This enables highly accurate detection of BEC emails and flexible display of warning messages according to the user's emotional state.

[1903] "Generative AI" is an artificial intelligence system that uses machine learning and neural network techniques to automatically generate new data patterns and text.

[1904] "Business email compromise" refers to fraudulent emails sent to businesses or organizations with the intent of fraudulently obtaining financial or other sensitive information.

[1905] A "signature" is data that indicates characteristics specific to fraudulent emails, extracted based on the content and structure of the email.

[1906] A "database" is a system or software for storing and managing data efficiently and systematically.

[1907] "Emotion recognition" is the technology of identifying a person's emotional state through the analysis of facial expressions, voice tone, and text.

[1908] A "warning message" is a message that contains information to notify a user of a particular situation or condition and to call their attention.

[1909] A "quarantine folder" is an email folder that stores suspicious or malicious emails separately from your regular inbox.

[1910] "History management" is a system or process that stores records of past data or events so that they can be analyzed and referenced.

[1911] This invention relates to a system that uses a generative AI system to detect business email compromise (BEC) emails with high accuracy, warn users, and understand the user's emotional state and customize the warning message based on that.

[1912] Server Operation Overview

[1913] The server system is constructed using the following hardware and software: The hardware is a server computer equipped with a high-performance processor, memory, and storage. The software uses a generative AI tool, a database system (MySQL), an email analysis library (Apache James), an emotion recognition engine (Microsoft's Azure Emotional Analysis API), and a backend framework (Node.js, Express).

[1914] At the beginning of the month, the server uses the generative AI model to generate new BEC emails, extracts characteristic signatures from these emails, and stores them in a database.

[1915] The server retrieves new incoming emails from the company's email server every hour and analyzes their contents using an email analysis library. The analyzed email signatures are compared with the BEC signatures in the existing database. If a suspicious email is found, a warning message is generated for that email.

[1916] The server uses Microsoft's Azure Emotional Analysis API to obtain user emotional data and determine the emotional state the user was in when receiving the email. This emotional data is then stored in a database as a history.

[1917] About device operation

[1918] The system operates using the following technologies on user devices, which can be smartphones, tablets, or desktop computers. The devices use Google ML Kit to analyze facial expressions and voice tones to obtain emotion data.

[1919] When a user receives an email on their device, the emotion recognition system captures their facial expressions and voice and analyzes their emotional state in real time, and this data is sent to the server.

[1920] The warning message sent from the server is customized according to the user's emotional state and displayed on the device. For example, if the user is determined to be in a stressful state, the warning message will be displayed in a soft tone.

[1921] User operations

[1922] The user can check the warning message displayed on the terminal and check the detailed information of the email.

[1923] You can choose to move the email to a quarantine folder, delete it, or re-evaluate it as legitimate.

[1924] Examples of concrete examples and prompts

[1925] Specific examples

[1926] While a user is checking work emails on their smartphone while out and about, the server determines that they have received a BEC email. If the emotion engine determines that the user is under stress, it changes the usual stiff warning message to a softer tone, saying, "Thank you for your hard work. An email requiring your attention has been found. Please remain calm and take appropriate action."

[1927] Prompt Sentence Examples

[1928] Generate customized warning messages when the user's emotional state is stressed.

[1929] Original warning message:

[1930] "Warning! Suspicious email found. Please review immediately."

[1931] Customized warning message:

[1932] "Thank you for your hard work. We've found an email that needs your attention. Please stay calm and take care of it."

[1933] In this way, we provide a system that reduces the psychological burden on users and strengthens security through BEC email detection and emotion-customized warning messages.

[1934] The flow of the specific processing in the application example 2 will be described with reference to FIG.

[1935] Step 1:

[1936] The server uses the generative AI model to generate new BEC emails at the beginning of each month. It extracts characteristic signatures from the generated emails and stores them in a database. The input is the email data generated by the generative AI model, and the output is the extracted signature data. New signature information is added to the database.

[1937] Step 2:

[1938] The server retrieves new incoming emails from the company's email server every hour. It uses an email analysis library (Apache James) to analyze the content of the retrieved emails and generate a signature from them. The input is new email data retrieved from the company's email server, and the output is the generated signature data. The signature is obtained by analyzing the email content.

[1939] Step 3:

[1940] The server compares the generated signature with existing BEC signatures in the database. Based on the comparison results, it determines whether the received email is suspected of being a business email compromise. The input is the newly generated signature and existing signatures in the database, and the output is the determination result of whether or not there is suspicion of BEC. The signature is matched by referring to the information in the database.

[1941] Step 4:

[1942] The server generates a warning message for emails that are suspected of being BEC attacks. The input is the email data that is suspected of being BEC attacks, and the output is the warning message. The generated warning message is created based on a template.

[1943] Step 5:

[1944] The server sends the generated warning message to the user's terminal. The input is the generated warning message, and the output is the successful transmission of the warning message to the user's terminal. The message is sent to the user's terminal via the network.

[1945] Step 6:

[1946] When receiving a warning message, the device captures facial expressions and voice to obtain emotional data in order to recognize the user's emotional state. Analysis is performed using Google ML Kit. The input is the user's facial expression data and voice data, and the output is the recognized emotional data. The emotional state is analyzed in real time and sent to the server.

[1947] Step 7:

[1948] The server customizes the warning message based on the acquired emotion data. The input is the recognized emotion data and the original warning message, and the output is the customized warning message. The message content is adjusted based on the emotion data.

[1949] Step 8:

[1950] The terminal displays a customized warning message to the user. The input is the customized warning message, and the output is the warning message displayed on the terminal screen. The message is presented to the user visually and audibly.

[1951] Step 9:

[1952] The user checks the warning icon or notification displayed on the device and views the details of the received email. The input is the warning notification displayed on the device, and the output is the detailed information of the email viewed by the user. The user clicks on the warning message to view the details.

[1953] Step 10:

[1954] The user can move the email to a quarantine folder, delete it, or reassess it as legitimate. The input is the user's choice of action, and the output is the quarantine, new assessment, or deletion of the email. The user selects the appropriate action, and the system processes the email according to that choice.

[1955] The specific processing unit 290 transmits the result of the specific processing to the robot 414. In the robot 414, the control unit 46A causes the speaker 240 and the control target 443 to output the result of the specific processing. The microphone 238 acquires voice indicating a user input regarding the result of the specific processing. The control unit 46A transmits voice data indicating the user input acquired by the microphone 238 to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the voice data.

[1956] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[1957] In the above embodiment, an example was given in which the specific processing is performed by the data processing device 12, but the technology of the present disclosure is not limited to this, and the specific processing may be performed by the robot 414.

[1958] The emotion identification model 59 as an emotion engine may determine the user's emotion according to a specific mapping. Specifically, the emotion identification model 59 may determine the user's emotion according to an emotion map (see FIG. 9), which is a specific mapping. Similarly, the emotion identification model 59 may determine the robot's emotion, and the identification processing unit 290 may perform identification processing using the robot's emotion.

[1959] FIG. 9 is a diagram illustrating an emotion map 400 on which multiple emotions are mapped. In the emotion map 400, emotions are arranged in concentric circles radiating from the center. Emotions closer to the center of the concentric circles are more primitive. Emotions representing states and actions arising from a state of mind are arranged on the outer edges of the concentric circles. The concept of emotion includes both affect and mental states. Emotions generally generated from reactions occurring in the brain are arranged on the left side of the concentric circles. Emotions generally induced by situational judgment are arranged on the right side of the concentric circles. Emotions generally generated from reactions occurring in the brain and induced by situational judgment are arranged on the upper and lower sides of the concentric circles. Furthermore, the emotion of "pleasure" is arranged on the upper side of the concentric circles, and the emotion of "discomfort" is arranged on the lower side. In this way, in the emotion map 400, multiple emotions are mapped based on the structure by which emotions are generated, and emotions that tend to occur simultaneously are mapped close to each other.

[1960] These emotions are distributed in the 3 o'clock direction on emotion map 400, and typically fluctuate between relief and anxiety. In the right half of emotion map 400, situational awareness dominates over internal sensations, resulting in a sense of calm.

[1961] The inside of emotion map 400 represents what is going on in the mind, and the outside of emotion map 400 represents behavior, so the further you go outside emotion map 400, the more visible the emotions become (the more they are expressed in behavior).

[1962] Human emotions are based on various balances, such as posture and blood sugar levels. When these balances deviate from the ideal, a state of discomfort is indicated, and when they approach the ideal, a state of pleasure is indicated. Emotions can also be created for robots, automobiles, and motorcycles, based on various balances, such as posture and remaining battery life. When these balances deviate from the ideal, a state of discomfort is indicated, and when they approach the ideal, a state of pleasure is indicated. An emotion map can be generated, for example, based on Dr. Mitsuyoshi's emotion map (Research on Voice Emotion Recognition and Emotional Brain Physiological Signal Analysis Systems, Tokushima University, Doctoral Dissertation: https: / / ci.nii.ac.jp / naid / 500000375379). The left half of the emotion map lists emotions belonging to the "reaction" domain, where sensation is dominant. The right half of the emotion map lists emotions belonging to the "situation" domain, where situational awareness is dominant.

[1963] The emotion map defines two emotions that promote learning. One is a negative emotion on the situation side, around the middle of "repentance" or "reflection." In other words, this occurs when the robot experiences negative emotions such as "I never want to feel this way again" or "I don't want to be scolded again." The other is a positive emotion on the response side, around "desire." In other words, this occurs when the robot experiences positive feelings such as "I want more" or "I want to know more."

[1964] The emotion identification model 59 inputs user input into a pre-trained neural network, obtains emotion values ​​indicating each emotion shown in the emotion map 400, and determines the user's emotion. This neural network is pre-trained based on multiple pieces of training data that are combinations of user input and emotion values ​​indicating each emotion shown in the emotion map 400. Furthermore, this neural network is trained so that emotions that are located close to each other have similar values, as in the emotion map 900 shown in FIG. 10. FIG. 10 shows an example in which multiple emotions, "relieved," "calm," and "reassuring," have similar emotion values.

[1965] The system according to the present disclosure has been described above mainly with respect to the functions of the data processing device 12, but the system according to the present disclosure is not necessarily implemented on a server. The system according to the present disclosure may be implemented as a general information processing system. The present disclosure may be implemented, for example, as a software program running on a personal computer or an application running on a smartphone, etc. The method according to the present disclosure may be provided to users in the form of SaaS (Software as a Service).

[1966] In the above embodiment, an example was given in which the specific processing is performed by one computer 22, but the technology of the present disclosure is not limited to this, and the specific processing may be distributed and performed by a plurality of computers including the computer 22. For example, the data generation model 58 may be provided in an external device of the data processing device 12, and data may be generated in the external device in accordance with input data.

[1967] In the above embodiment, an example in which the specific processing program 56 is stored in the storage 32 has been described, but the technology of the present disclosure is not limited to this. For example, the specific processing program 56 may be stored in a portable, computer-readable, non-transitory storage medium such as a USB (Universal Serial Bus) memory. The specific processing program 56 stored in the non-transitory storage medium is installed in the computer 22 of the data processing device 12. The processor 28 executes the specific processing in accordance with the specific processing program 56.

[1968] Alternatively, the specific processing program 56 may be stored in a storage device such as a server connected to the data processing device 12 via the network 54, and the specific processing program 56 may be downloaded and installed on the computer 22 in response to a request from the data processing device 12.

[1969] It is not necessary to store all of the specific processing program 56 in a storage device such as a server connected to the data processing device 12 via the network 54, or to store all of the specific processing program 56 in the storage 32; only a portion of the specific processing program 56 may be stored.

[1970] The hardware resource for executing a specific process can be any of the following processors: An example of a processor is a CPU, which is a general-purpose processor that functions as a hardware resource for executing a specific process by executing software, i.e., a program. Another example of a processor is a dedicated electrical circuit, such as an FPGA (Field-Programmable Gate Array), a PLD (Programmable Logic Device), or an ASIC (Application Specific Integrated Circuit), which is a processor with a circuit configuration designed specifically for executing a specific process. Each processor has built-in or connected memory, and each processor uses the memory to execute the specific process.

[1971] The hardware resource that executes the specific processing may be configured with one of these various processors, or may be configured with a combination of two or more processors of the same or different types (for example, a combination of multiple FPGAs, or a combination of a CPU and an FPGA). Also, the hardware resource that executes the specific processing may be a single processor.

[1972] As an example of a system configured with a single processor, first, one processor is configured by combining one or more CPUs and software, and this processor functions as a hardware resource that executes a specific process. Second, there is a system that uses a processor that realizes the functions of an entire system including multiple hardware resources that execute a specific process on a single IC chip, as typified by SoC (System-on-a-chip). In this way, a specific process is realized using one or more of the above-mentioned various processors as hardware resources.

[1973] Furthermore, the hardware structure of these various processors can be, more specifically, an electric circuit that combines circuit elements such as semiconductor devices. The specific processing described above is merely an example. Therefore, it goes without saying that unnecessary steps may be deleted, new steps may be added, or the processing order may be rearranged, without departing from the spirit of the invention.

[1974] The above-described description and illustrations are a detailed explanation of the parts related to the technology of the present disclosure and are merely an example of the technology of the present disclosure. For example, the above description of the configuration, functions, actions, and effects is an explanation of an example of the configuration, functions, actions, and effects of the parts related to the technology of the present disclosure. Therefore, it goes without saying that unnecessary parts may be deleted, new elements may be added, or replacements may be made to the above-described description and illustrations within the scope of the gist of the technology of the present disclosure. Furthermore, to avoid confusion and facilitate understanding of the parts related to the technology of the present disclosure, the above-described description and illustrations omit explanations of common technical knowledge that do not require particular explanation to enable the implementation of the technology of the present disclosure.

[1975] All publications, patent applications, and technical standards mentioned in this specification are herein incorporated by reference to the same extent as if each individual publication, patent application, or technical standard was specifically and individually indicated to be incorporated by reference.

[1976] The following is further disclosed regarding the above embodiment.

[1977] (Claim 1)

[1978] A method for generating multiple business email compromise emails using generative AI;

[1979] a means for extracting a signature from the generated business email compromise email;

[1980] a means for storing the extracted signatures in a database;

[1981] a means for retrieving received email;

[1982] A means for generating a signature from the retrieved received email;

[1983] means for comparing the generated signature with signatures in a database;

[1984] A means for determining whether the received email is suspected of being a business email compromise based on the comparison result;

[1985] a means for generating a warning message for the affected email;

[1986] means for sending a warning message to a user;

[1987] How to move or delete the email in question to a quarantine folder

[1988] A system including:

[1989] (Claim 2)

[1990] 2. The system according to claim 1, further comprising means for displaying a warning message on a user's terminal, allowing the user to check and handle the relevant email.

[1991] (Claim 3)

[1992] 2. The system of claim 1, further comprising means for collecting and analyzing past human-created business email compromise emails for training the generation AI.

[1993] "Example 1"

[1994] (Claim 1)

[1995] A method for generating multiple counterfeit business emails using a generative AI;

[1996] A means for extracting characteristic patterns from the generated forged business email;

[1997] means for storing the extracted characteristic patterns in a database;

[1998] a means for retrieving received email;

[1999] A means for generating a characteristic pattern from the acquired received email;

[2000] means for comparing the generated characteristic pattern with characteristic patterns in a database;

[2001] A means for determining whether the received email is suspected to be a forged business email based on the comparison result;

[2002] a means for generating a warning message for the affected email;

[2003] means for sending a warning message to a user;

[2004] How to move or delete the affected emails to a quarantine folder;

[2005] a means for generating a warning message including a summary of the relevant email and a warning message and notifying the user of the message;

[2006] A means to provide operational options to quarantine, delete, or re-evaluate email as legitimate

[2007] A system including:

[2008] (Claim 2)

[2009] 2. The system according to claim 1, further comprising means for displaying a warning message on a user's terminal, allowing the user to check and handle the relevant email.

[2010] (Claim 3)

[2011] The system of claim 1, further comprising means for collecting and analyzing past forged business emails created by humans for training the generation AI.

[2012] "Application Example 1"

[2013] (Claim 1)

[2014] A method for generating multiple business email compromise emails using generative AI;

[2015] a means for extracting a signature from the generated business email compromise email;

[2016] a means for storing the extracted signatures in a database;

[2017] a means for retrieving received email;

[2018] A means for generating a signature from the retrieved received email;

[2019] means for comparing the generated signature with signatures in a database;

[2020] A means for determining whether the received email is suspected of being a business email compromise based on the comparison result;

[2021] a means for generating a warning message for the affected email;

[2022] means for sending a warning message to a user;

[2023] How to move or delete the affected emails to a quarantine folder;

[2024] A means for notifying a user of a warning message in real time on a mobile device of the user and providing a user interface that allows the user to move the email to a quarantine folder, delete it, or reassess it as legitimate;

[2025] How users can view and interact with suspected fraudulent emails

[2026] A system including:

[2027] (Claim 2)

[2028] 10. The system of claim 1, further comprising means for collecting and analyzing various business email compromise emails for training the generation AI.

[2029] (Claim 3)

[2030] 10. The system of claim 1, further comprising means for connecting to a mail server to periodically retrieve incoming emails and copy emails suspected of being fraudulent to a quarantine folder.

[2031] "Example 2: Combining Emotion Engines"

[2032] (Claim 1)

[2033] A method for generating multiple business email compromise emails using generative AI;

[2034] a means for extracting a signature from the generated business email compromise email;

[2035] a means for storing the extracted signatures in a database;

[2036] a means for retrieving received email;

[2037] A means for generating a signature from the retrieved received email;

[2038] means for comparing the generated signature with signatures in a database;

[2039] A means for determining whether the received email is suspected of being a business email compromise based on the comparison result;

[2040] a means for generating a warning message for the affected email;

[2041] means for sending a warning message to a user;

[2042] How to move or delete the affected emails to a quarantine folder;

[2043] means for acquiring user emotion data using an emotion engine that recognizes the user's emotional state;

[2044] means for customizing a warning message based on the acquired emotion data;

[2045] A means of storing user emotion data as history in a database

[2046] A system including:

[2047] (Claim 2)

[2048] 2. The system according to claim 1, further comprising means for displaying a warning message on a user's terminal, allowing the user to check and handle the relevant email.

[2049] (Claim 3)

[2050] 2. The system of claim 1, further comprising means for collecting and analyzing past human-created business email compromise emails for training the generation AI.

[2051] "Application example 2 when combining emotion engines"

[2052] (Claim 1)

[2053] A method for generating multiple business email compromise emails using generative AI;

[2054] a means for extracting a signature from the generated business email compromise email;

[2055] a means for storing the extracted signatures in a database;

[2056] a means for retrieving received email;

[2057] A means for generating a signature from the retrieved received email;

[2058] means for comparing the generated signature with signatures in a database;

[2059] A means for determining whether the received email is suspected of being a business email compromise based on the comparison result;

[2060] a means for generating a warning message for the affected email;

[2061] means for sending a warning message to a user;

[2062] How to move or delete the affected emails to a quarantine folder;

[2063] means for recognizing a user's emotional state and acquiring emotional data;

[2064] means for customizing a warning message based on the acquired emotion data;

[2065] a means for storing and managing the history of emotion data in a database;

[2066] A system including:

[2067] (Claim 2)

[2068] 2. The system according to claim 1, further comprising means for displaying a warning message on a user's terminal, allowing the user to...

Claims

1. A method for generating multiple business email compromise emails using generative AI; a means for extracting a signature from the generated business email compromise email; a means for storing the extracted signatures in a database; a means for retrieving received email; A means for generating a signature from the retrieved received email; means for comparing the generated signature with signatures in a database; A means for determining whether the received email is suspected of being a business email compromise based on the comparison result; a means for generating a warning message for the affected email; means for sending a warning message to a user; How to move or delete the email in question to a quarantine folder A system including:

2. 2. The system according to claim 1, further comprising means for displaying a warning message on a user's terminal, allowing the user to check and handle the relevant email.

3. The system of claim 1, further comprising means for collecting and analyzing past human-created business email compromise emails for training the generation AI.

Citation Information

Patent Citations

  • Persona chatbot control method and system

    JP2022180282A