system

The system addresses the inadequacy of existing technologies by integrating email content analysis and URL checks, using natural language processing and real-time threat intelligence to effectively detect and notify users of phishing and malware risks.

JP2026037327APending Publication Date: 2026-03-06SOFTBANK GROUP CORP
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-08-21
Publication Date
2026-03-06

AI Technical Summary

Technical Problem

Existing technologies are inadequate in responding to new and sophisticated phishing and malware threats via email, failing to integrate email content analysis and URL destination checks effectively, leading to potential security breaches.

Method used

A system that receives email data, converts it into text data, analyzes it using natural language processing, assesses risk, compares sender addresses with a database, extracts and checks URLs against safety databases, and notifies users of potential threats in real time.

Benefits of technology

Enables rapid and accurate detection of both known and new threats, providing users with timely warnings to enhance email security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026037327000001_ABST
    Figure 2026037327000001_ABST
Patent Text Reader

Abstract

Provide a system. [Solution] A means for receiving email data; A means for converting received email data into text data; a means for transmitting the text data to a server and analyzing the data on the server side using natural language processing technology; means for performing risk assessment of emails based on the analysis results; means for transmitting the risk assessment result to a terminal and notifying the user; A system including:
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The technology of the present disclosure relates to a system. [Background technology]

[0002] Patent document 1 discloses a persona chatbot control method performed by at least one processor, the method including the steps of receiving a user utterance, adding the user utterance to a prompt including an instruction sentence related to a description of the chatbot character, encoding the prompt, and inputting the encoded prompt into a language model to generate a chatbot utterance in response to the user utterance. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Publication No. 2022-180282 Summary of the Invention [Problem to be solved by the invention]

[0004] In recent years, the spread of phishing scams and malware via email has been increasing, and there is a growing need to detect these threats before they occur and warn users. While existing technologies can respond to known threats, they are unable to adequately respond to new threats and increasingly sophisticated attacks. Furthermore, there is a need to effectively integrate email content analysis and URL destination checks into a single system. [Means for solving the problem]

[0005] To solve this problem, the present invention provides the following means. The system includes a means for receiving email data, a means for converting the received email data into text data, and a means for transmitting the text data to a server and analyzing it using natural language processing technology on the server side. The system also includes a means for performing a risk assessment of the email based on the analysis results, and a means for transmitting the risk assessment results to a terminal and notifying the user. The system further includes a means for comparing the sender address with a database to assess the trustworthiness of the email, a means for extracting URLs from the email and comparing them with a safety database, and a means for actually checking the URL destinations and evaluating them for signs of fraud. The system also provides a means for updating the risk assessment based on threat information collected in real time and immediately displaying a warning to the user. This enables rapid and effective response to known and new threats and protects users.

[0006] "Mail Data" refers to data including the content, metadata, and related information of emails sent and received by Users.

[0007] "Text data" refers to data containing character information extracted from email data.

[0008] "Server" refers to a remote computer system that analyzes received data and returns the results to the terminal.

[0009] "Natural language processing technology" refers to technology that enables computer systems to understand, analyze, and generate human language.

[0010] "Risk assessment" refers to the process of assessing the risk of a particular email or URL based on the results of analysis.

[0011] "Terminal" refers to a device such as a computer or smartphone that is directly used by a user.

[0012] "Source address" refers to the address information of the sender of the email.

[0013] A "database" refers to a system that systematically collects, stores, and quickly searches for specific information.

[0014] A "URL" is a string of characters that identifies a specific web page or resource on the Internet.

[0015] A "safe database" refers to a database that classifies and stores known safe and dangerous URLs.

[0016] "Real-time threat information" refers to the process of instantly collecting and updating information on the latest cyber threats.

[0017] "User" refers to an individual or organization that uses this system.

[0018] "Phishing" refers to a type of forged email or web scam designed to steal users' personal information.

[0019] "Malware" refers to malicious software that harms computers and networks.

[0020] "Warning Message" refers to a notification message that is displayed to a user when a particular risk is detected. [Brief explanation of the drawings]

[0021] [Figure 1] 1 is a conceptual diagram showing an example of the configuration of a data processing system according to a first embodiment. [Figure 2] 1 is a conceptual diagram showing an example of main functions of a data processing device and a smart device according to a first embodiment. [Figure 3] FIG. 10 is a conceptual diagram showing an example of the configuration of a data processing system according to a second embodiment. [Figure 4] FIG. 10 is a conceptual diagram showing an example of main functions of a data processing device and smart glasses according to a second embodiment. [Figure 5]FIG. 10 is a conceptual diagram showing an example of the configuration of a data processing system according to a third embodiment. [Figure 6] FIG. 11 is a conceptual diagram showing an example of main functions of a data processing device and a headset-type terminal according to a third embodiment. [Figure 7] FIG. 10 is a conceptual diagram showing an example of the configuration of a data processing system according to a fourth embodiment. [Figure 8] FIG. 10 is a conceptual diagram showing an example of main functions of a data processing device and a robot according to a fourth embodiment. [Figure 9] 1 shows an emotion map onto which multiple emotions are mapped. [Figure 10] 1 shows an emotion map onto which multiple emotions are mapped. [Figure 11] FIG. 3 is a sequence diagram showing a processing flow of the data processing system according to the first embodiment. [Figure 12] FIG. 10 is a sequence diagram showing the flow of processing in the data processing system in Application Example 1. [Figure 13] FIG. 10 is a sequence diagram showing the flow of processing in the data processing system according to the second embodiment when an emotion engine is combined. [Figure 14] FIG. 10 is a sequence diagram showing the flow of processing in the data processing system in Application Example 2 when an emotion engine is combined. DETAILED DESCRIPTION OF THE INVENTION

[0022] An example of an embodiment of a system according to the technology of the present disclosure will be described below with reference to the accompanying drawings.

[0023] First, the terms used in the following description will be explained.

[0024] In the following embodiments, a coded processor (hereinafter simply referred to as a "processor") may be a single arithmetic device or a combination of multiple arithmetic devices. Furthermore, a processor may be a single type of arithmetic device or a combination of multiple types of arithmetic devices. Examples of arithmetic devices include a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), a GPGPU (General-Purpose computing on Graphics Processing Units), and an APU (Accelerated Processing Unit).

[0025] In the following embodiments, a coded RAM (Random Access Memory) is a memory in which information is temporarily stored and is used as a working memory by a processor.

[0026] In the following embodiments, the coded storage is one or more non-volatile storage devices that store various programs, various parameters, etc. Examples of non-volatile storage devices include flash memory (SSD (Solid State Drive)), magnetic disks (e.g., hard disks), and magnetic tapes.

[0027] In the following embodiments, a communication I / F (Interface) with a symbol is an interface including a communication processor, an antenna, etc. The communication I / F controls communication between multiple computers. Examples of communication standards applied to the communication I / F include wireless communication standards including 5G (5th Generation Mobile Communication System), Wi-Fi (registered trademark), Bluetooth (registered trademark), etc.

[0028] In the following embodiments, "A and / or B" is synonymous with "at least one of A and B." In other words, "A and / or B" means that it may be only A, only B, or a combination of A and B. Furthermore, in this specification, the same concept as "A and / or B" is also applied when three or more things are expressed connected by "and / or."

[0029] [First embodiment]

[0030] FIG. 1 shows an example of the configuration of a data processing system 10 according to the first embodiment.

[0031] 1, a data processing system 10 includes a data processing device 12 and a smart device 14. An example of the data processing device 12 is a server.

[0032] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[0033] The smart device 14 includes a computer 36, a reception device 38, an output device 40, a camera 42, and a communication I / F 44. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The reception device 38, the output device 40, and the camera 42 are also connected to the bus 52.

[0034] The reception device 38 includes a touch panel 38A, a microphone 38B, and the like, and receives user input. The touch panel 38A detects contact with an indicator (for example, a pen or a finger) to receive user input by the touch of the indicator. The microphone 38B detects the user's voice to receive user input by voice. The control unit 46A transmits data indicating the user input received by the touch panel 38A and the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the data indicating the user input.

[0035] The output device 40 includes a display 40A and a speaker 40B, and presents data to the user 20 by outputting the data in a form of expression that the user 20 can perceive (for example, audio and / or text). The display 40A displays visible information such as text and images in accordance with instructions from the processor 46. The speaker 40B outputs audio in accordance with instructions from the processor 46. The camera 42 is a compact digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor.

[0036] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 control the exchange of various information between the processor 46 and the processor 28 via the network 54.

[0037] FIG. 2 shows an example of the main functions of the data processing device 12 and the smart device 14.

[0038] 2, in the data processing device 12, a specific process is performed by the processor 28. A specific processing program 56 is stored in the storage 32. The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific process is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[0039] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[0040] In the smart device 14, the processor 46 performs the reception output process. The storage 50 stores a reception output program 60. The reception output program 60 is used in conjunction with the specific processing program 56 by the data processing system 10. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.

[0041] Next, a description will be given of the specific processing performed by the specific processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."

[0042] This invention relates to a system that receives email data, analyzes its contents, performs risk assessment, and notifies the user. Specifically, it uses generative AI to analyze the content of conversations and email text, and checks the destination sites of URLs.

[0043] System program and processing description

[0044] 1. Receiving emails

[0045] 1. The user receives an email

[0046] A user opens an email client application and receives new email, which is saved within the client application.

[0047] 2. The device extracts the email data

[0048] The device extracts the necessary information (body, subject, sender, URL, etc.) from the email data stored.

[0049] 2. Email Data Analysis

[0050] 3. The device sends the extracted data to the server

[0051] The extracted email data is sent to a server where a generative AI is placed and analyzes the data.

[0052] 4. The server analyzes the email content using natural language processing

[0053] AI on the server analyzes the email body using natural language processing technology. The purpose of the analysis is to detect signs of fraud, phishing, spam, etc. For example, if the email contains phrases such as "Please update your account information" or "Click the following link," it will determine that it is likely phishing.

[0054] 5. The server checks the sender

[0055] The server checks the sender address against a pre-registered database to assess its trustworthiness, and if it is a known scam or spam source, it is deemed high risk.

[0056] 3. URL Parsing

[0057] 6. The server extracts the URLs from the email

[0058] All URLs are extracted from the email body and the safety of each URL is evaluated.

[0059] 7. The server checks the URL against a secure database

[0060] The extracted URLs are checked against a pre-registered safe database, and if they are known phishing sites or sites hosting malware, they are rated as high risk.

[0061] 8. The server checks the URL destination

[0062] If necessary, the server will actually navigate to the URL and analyze the content of the site, and if it detects any signs of fraud, the risk level will be increased further.

[0063] 4. Risk Assessment and Notification

[0064] 9. The server performs a risk assessment

[0065] The server performs a comprehensive risk assessment based on the analysis of the email body and URLs, and the assessment is classified into three levels: high risk, medium risk, and low risk.

[0066] 10. The server sends the evaluation results to the device.

[0067] The risk assessment results are sent to the device, and include specific risk factors (e.g., "Possibly a phishing email" or "Contains a malicious URL").

[0068] 11. The device notifies the user

[0069] The device will notify the user based on the evaluation results. A warning message will be displayed for high-risk emails, urging the user not to open them. Trusted emails will also be notified that they are "safe."

[0070] Specific examples

[0071] Example 1: Receiving a phishing email

[0072] 1. The user receives a fraudulent email

[0073] The user receives an email with the subject "Your account has been suspended."

[0074] 2. The device analyzes the email and sends the data to the server

[0075] The email body and URL are extracted and sent to the server.

[0076] 3. The server analyzes the email and detects signs of phishing

[0077] The server's generative AI detects the phrase "Click the link below to update your account information."

[0078] Additionally, the sending address is verified as a known fraudulent address.

[0079] 4. The server parses the URL

[0080] The URL turns out to be a known phishing site.

[0081] 5. The server evaluates the risk as high and sends the result to the device.

[0082] The email is rated as high risk and a message is sent to the device saying, "This email may be phishing."

[0083] 6. The device displays a warning to the user

[0084] A warning message is displayed to the user.

[0085] Example 2: Receiving an important email from work

[0086] 1. A user receives an important email from work

[0087] A user receives an email titled "About the next meeting materials."

[0088] 2. The device analyzes the email and sends the data to the server

[0089] The email body and URL are extracted and sent to the server.

[0090] 3. The server analyzes the email and determines it is safe

[0091] The server's generative AI detects no abnormal patterns and verifies that the source address is trustworthy.

[0092] 4. The server parses the URL

[0093] The URL is confirmed to be the official workplace website.

[0094] 5. The server evaluates the risk as low and sends the result to the device.

[0095] It is evaluated as low risk and a message saying "This email is safe" is sent to the device.

[0096] 6. The device notifies the user

[0097] The user will see a notification that "This email is safe."

[0098] This allows users to quickly and accurately determine whether an email they receive is safe or poses a risk. This system can effectively respond to cyber threats that are constantly evolving, improving users' email security.

[0099] The processing flow will be explained below.

[0100] Step 1:

[0101] When a user receives an email, the device stores the email in the email client application in internal storage, along with metadata such as the email content, subject, sender address, and any URLs it contains.

[0102] Step 2:

[0103] The device extracts text data from the email data stored on the device. Specifically, it analyzes the email body, subject, and sender address and organizes it as structured data in a specific format.

[0104] Step 3:

[0105] The device then sends the extracted email data and URL information to the server, using an encrypted communication protocol to ensure security.

[0106] Step 4:

[0107] The server uses natural language processing technology to analyze the email data it receives. An AI model analyzes the email body and detects abnormal patterns and keywords that may indicate fraud or phishing. For example, phrases such as "update your account information" or "important notice" may indicate the possibility of phishing.

[0108] Step 5:

[0109] The server checks the sending address against a database containing known scam addresses and spam sources, and then rates the sending address as trustworthy or dangerous.

[0110] Step 6:

[0111] The server extracts all URLs from the email, detects URLs from the email body, and analyzes which sites each URL leads to.

[0112] Step 7:

[0113] The server checks the URL against a safety database, which contains information about known safe and dangerous sites. If the URL is a known phishing site or hosts malware, it is rated as high risk.

[0114] Step 8:

[0115] If necessary, the server will actually check the destination site of the URL. In this step, the server will access the URL and analyze its content. For example, it will check the page content to detect whether it contains malicious scripts or suspicious elements.

[0116] Step 9:

[0117] The server then assesses the risk of the email based on the analysis results. Risk is classified as high, medium, or low. For example, emails that are likely to be fraudulent or contain URLs that include phishing sites are assessed as high risk.

[0118] Step 10:

[0119] The server sends the risk assessment results to the device, including the type of risk and the reasons for it, in a format that is easy for the user to understand.

[0120] Step 11:

[0121] The device notifies the user based on the risk assessment results. For high-risk emails, a warning message is displayed on the screen, urging the user not to open the email. For trustworthy emails, the device notifies the user that "This email is safe."

[0122] Step 12:

[0123] The user is notified and is given a risk assessment to decide whether to open the email, delete it, or perform further safety checks.

[0124] These steps allow users to quickly and accurately understand the safety of the emails they receive, and by having the server and device work together, we can provide an unprecedentedly strong security environment.

[0125] Example 1

[0126] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."

[0127] In today's cyber environment, the threat of malicious emails such as phishing and spam is increasing, and users need a way to quickly and accurately determine whether the emails they receive are safe. However, existing email security measures are unable to fully analyze the risks of email content and URLs, potentially exposing users to serious risks. For this reason, a system is needed that performs advanced email content analysis and URL safety assessment, and provides accurate risk assessments and notifications to users in real time.

[0128] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.

[0129] In this invention, the server includes a means for comparing the sender address with a database to evaluate the reliability of the email, a means for extracting URLs from the email and comparing them with a safety database, and a means for checking the destination of the URL and evaluating signs of fraud. This makes it possible to evaluate the reliability of the email and the safety of the URL with high accuracy and quickly notify the user of the risk evaluation results.

[0130] "Mail Data" means digital information received and sent as email, including the body, subject, sender address, and associated metadata.

[0131] "Text data" refers to character string data in an analyzable format that includes the email body and related information.

[0132] A "server" is a computer system that provides services over a network, including hardware and software for data analysis and risk assessment.

[0133] "Natural language processing technology" is a general term for technologies that enable computers to understand, interpret, and generate human language.

[0134] "Risk assessment" is the process of assessing the degree of risk an email poses to the user based on the analyzed email, and the assessment results are classified as high risk, medium risk, or low risk.

[0135] "User" refers to the end user who uses this system to check the security of email.

[0136] A "database" is a software system for efficiently storing, managing, and retrieving data, including those in SQL or NoSQL formats.

[0137] A "safe database" is a database that holds information about known safe and dangerous URLs and domains.

[0138] A "headless browser" is a browser without a GUI, used for automation scripts and system testing.

[0139] A "generative AI model" is an artificial intelligence model that learns large amounts of data and generates and analyzes natural language, and is particularly used for natural language processing.

[0140] An "HTTP request" is a protocol request for exchanging information between a client and a server, typically a GET or POST request.

[0141] "Real-time threat intelligence" refers to the latest information on current security threats and attack patterns, which is used to update risk assessments.

[0142] This invention relates to a system that receives email data, analyzes its contents, performs risk assessment, and notifies the user. Specifically, it uses a generative AI model to analyze the contents of emails using natural language processing technology and checks the destination URLs.

[0143] First, the user receives an email using an email client application. The received email is saved on the device. The device then extracts the email body, subject, sender address, and all URLs in the email body from the saved data. This process uses the Python email package and regular expressions (Regex).

[0144] Next, the device sends the extracted email data to the server using an HTTP request (e.g., a POST request). The server is equipped with a generative AI model (e.g., GPT-3 (registered trademark)), which analyzes the email body using natural language processing (NLU). Specifically, it detects phrases that indicate a fraudulent email, such as "Please update your account information."

[0145] The server then compares the sender address of the email with a database (SQL or NoSQL database) to assess its trustworthiness. If the sender address is a known scam email sender, it is assessed as high risk. Next, the server extracts all URLs from the email body and compares them with a safe database (e.g., Google® Safe Browsing API). This assesses whether they are phishing sites or malware hosting sites.

[0146] In addition to this evaluation, the server will actually check the URL destination using a headless browser (for example, Selenium with ChromeDriver) and analyze the content of the site. If there are any signs of fraud or harmful scripts, the risk level will be raised further.

[0147] Once the risk assessment is complete, the server sends the results to the device. The assessment results include detailed information about specific risk factors (for example, "possibly a phishing email" or "contains a malicious URL"). The device uses this information to provide appropriate notifications to the user. For high-risk emails, a warning message is displayed, urging the user not to open the email. For trustworthy emails, the device notifies the user that the email is "safe."

[0148] As a concrete example, if a user receives a phishing email with the title "Your account has been suspended," the device extracts the email's text and URL and sends them to the server. The server's generative AI model detects the phrase "Click the link below to update your account information" and confirms that the sender address is a known scam address. If the URL is determined to be a phishing site, it is rated as high risk and the result is sent to the device. Finally, the device displays a warning to the user saying, "This email may be phishing."

[0149] This system is designed to effectively respond to ever-evolving cyber threats and improve users' email security. It also updates risk assessments based on threat information collected in real time, enabling rapid response to the latest security situations.

[0150] The flow of the identification process in the first embodiment will be described with reference to FIG.

[0151] Step 1: User receives email

[0152] Input: A user receives an email.

[0153] What it does: Opens an email client application (e.g., Gmail, Outlook) and receives a new email.

[0154] Output: Received emails are saved on the device.

[0155] What happens: When a user opens their email client, new emails are downloaded from the server and displayed within the email application.

[0156] Step 2: Your device extracts the email data

[0157] Input: Received email data.

[0158] How it works: Extracts the body, subject, sender address, and all URLs in the body from saved email data. It uses the Python email package and regular expressions (Regex).

[0159] Output: A list of extracted email bodies, subjects, sender addresses, and URLs.

[0160] What it does: The program analyzes the received email data and extracts important information.

[0161] Step 3: The device sends the extracted data to the server

[0162] Input: A list of extracted email bodies, subjects, sender addresses, and URLs.

[0163] What it does: Sends the extracted data to the server using an HTTP request (e.g., a POST request).

[0164] Output: The email data received by the server.

[0165] Specific operation: The device makes an HTTP request and sends data to the server endpoint.

[0166] Step 4: The server analyzes the email content using natural language processing

[0167] Input: The email body sent from the device.

[0168] How it works: It uses generative AI models (e.g., GPT-3) to analyze email content and detect signs of fraud and phishing. It uses natural language processing libraries like NLTK and SpaCy.

[0169] Output: Analysis results, information on indicators of fraud and phishing.

[0170] Specific operation: The server tokenizes the email content and analyzes specific keywords and context to extract dangerous phrases.

[0171] Step 5: The server checks the source

[0172] Input: The source address sent from the device.

[0173] How it works: The source address is checked against a database (e.g., an SQL or NoSQL database) to assess its trustworthiness.

[0174] Output: The reliability evaluation result of the source address.

[0175] What it does: Runs a database query to match the email against a list of known fraudulent email senders.

[0176] Step 6: The server extracts the URLs in the email

[0177] Input: The email body sent from the device.

[0178] What it does: Extracts all URLs from the email body using regular expressions (Regex).

[0179] Output: A list of extracted URLs.

[0180] What it does: Identify and list all possible URL patterns within the email body.

[0181] Step 7: Server checks URL against safety database

[0182] Input: The extracted URL list.

[0183] How it works: Each URL is checked against a safety database (e.g., Google Safe Browsing API) to assess whether it is a phishing or malware-hosting site.

[0184] Output: Safety assessment results for each URL.

[0185] What it does: It uses HTTP requests to check against a safety database to determine the risk level of the URL.

[0186] Step 8: The server checks the URL destination

[0187] Input: The extracted URL list.

[0188] What it does: Uses a headless browser (e.g. Selenium with ChromeDriver) to navigate to a URL and analyze the content of that site.

[0189] Output: Analysis results of the destination site, information on indicators of fraud.

[0190] What it does: It automatically manipulates the browser to access URLs and analyzes the page content to detect dangerous scripts and content.

[0191] Step 9: Server performs risk assessment

[0192] Input: Email body, sender address, and URL analysis results.

[0193] How it works: The results of these analyses are combined to give the email a risk rating, which is then categorized as high, medium, or low risk.

[0194] Output: Risk assessment results.

[0195] Specific operation: Integrates analysis results and performs comprehensive risk assessment based on pre-defined rules and models.

[0196] Step 10: The server sends the evaluation results to the device.

[0197] Input: Risk assessment results.

[0198] Operation: The evaluation result is sent to the terminal as an HTTP response.

[0199] Output: The evaluation results sent to the device.

[0200] Specific behavior: Create an HTTP response and send it along with the evaluation result.

[0201] Step 11: The device notifies the user

[0202] Input: The risk assessment result sent from the server.

[0203] Behavior: Notifies the user based on the evaluation results. High-risk emails are warned, and trusted emails are told "safe."

[0204] Output: Notification to the user.

[0205] Specific operation: The terminal displays an appropriate message on the user interface based on the evaluation results.

[0206] (Application example 1)

[0207] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."

[0208] In recent years, the spread of phishing attacks and malware via email has been increasing, increasing the risk of users suffering serious damage. For this reason, there is a need for a system that automatically analyzes the content of emails when they are received, evaluates potential risks, and notifies users. Conventional systems often perform insufficient email analysis or are slow to notify users of risks, so technology is needed to enable rapid and accurate risk assessment and notification.

[0209] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.

[0210] In this invention, the server includes means for acquiring email data, means for converting the acquired email data into text data, means for transmitting the text data to the server and analyzing it using natural language processing technology on the server side, means for performing a risk assessment of the email based on the analysis result, means for transmitting the risk assessment result to the client device and notifying the user, means for providing the user with specific factors of the risk assessment along with the notification, means for comparing the sender address with a database to evaluate the reliability of the email, means for extracting URLs from the email and comparing them with a safety database, means for actually checking the destination of the URLs and evaluating signs of fraud, means for classifying the email as high risk, medium risk, or low risk based on the risk assessment result, means for updating the risk assessment based on threat information collected in real time, means for displaying an immediate warning to the user based on the risk assessment, and means for providing detailed information simultaneously with the display of the warning message. This enables rapid and accurate risk assessment and notification to the user upon receipt of email.

[0211] "Email data" refers to the entire content of an email received by a user, including the subject, sender address, body, attachments, URLs, etc.

[0212] "Means of acquisition" refers to the technology or devices used to receive email and extract its contents.

[0213] "Text data" refers to the content of an e-mail, etc., converted into data in an analyzable format.

[0214] "Server" refers to the central system for analyzing email data and conducting risk assessments.

[0215] "Natural language processing technology" refers to technology for analyzing human language and understanding and processing its meaning and structure.

[0216] "Means for analyzing" refers to technology or devices for analyzing the content of email using natural language processing technology.

[0217] "Risk assessment" refers to determining whether an email is dangerous to the user based on the information contained in the email.

[0218] A "client device" is a device that a user directly uses, and includes a smartphone, tablet, computer, etc.

[0219] "Means of notification" refers to the technology or device used to notify users of the results of the risk assessment.

[0220] "Specific factors" refers to the individual factors or information provided to elaborate on the results of a risk assessment.

[0221] A "safe database" refers to a database that stores known safe URLs and reliable information.

[0222] "Indicators of fraud" refer to evidence or patterns that indicate possible malicious activity, such as phishing sites or malware.

[0223] "High risk, medium risk, low risk" are classifications of different levels of potential danger for email.

[0224] "Threat intelligence" refers to information about the latest threats and attack methods, including data collected in real time.

[0225] A "warning message" refers to a message that displays warning information to notify the user of a danger.

[0226] "Detailed information" refers to information provided to the user, including background and specific explanations of the risk assessment.

[0227] In order to put the present invention into practice, it is necessary to build a system that acquires email data, analyzes it, performs risk assessment, and notifies the user.

[0228] The system uses the following hardware and software:

[0229] Hardware

[0230] server

[0231] Client devices (smartphones, tablets, computers)

[0232] software

[0233] Email client applications

[0234] Natural language processing libraries (e.g. NLTK, SpaCy)

[0235] Generative AI models (e.g., GPT-3 by OpenAI®)

[0236] Security databases (e.g., lists of known phishing sites)

[0237] Database systems (e.g. PostgreSQL, MongoDB)

[0238] Server platform (e.g., AWS (registered trademark), GCP, Azure (registered trademark))

[0239] The server first obtains the email data received by the user. The obtained email data is converted into text data. The server receives the text data and analyzes it using natural language processing technology. Based on the analysis results, a risk assessment of the email is performed.

[0240] For risk assessment, the server uses the following methods:

[0241] 1. Check the sender address against a database to assess the authenticity of the email.

[0242] 2. Extract URLs from emails and check them against a secure database.

[0243] 3. Check the destination of the URL and evaluate for signs of fraud.

[0244] The risk assessment results are classified as high risk, medium risk, or low risk, and the results are sent to the client device, which receives the results and notifies the user, including the specific risk factors.

[0245] For example, the following prompt sentences are sent to the generative AI model for analysis:

[0246] Please analyze the body of the following email and assess it for signs of phishing:

[0247] ---

[0248] Subject: Your account has been suspended

[0249] Body: "Your account has been suspended due to unauthorized access. Please click the link below to update your account information: http: / / example.com / phishing"

[0250] From: "support@example.com"

[0251] Classify your results as "high risk," "medium risk," or "low risk," and explain why.

[0252] The generative AI model analyzes the email body based on this prompt and returns the analysis results to the server. Based on the results, the email is assessed for risk and notified to the user.

[0253] For example, if a user receives an email with the subject line "Your account has been suspended," the server analyzes the email and detects signs of phishing. As a result, the user is warned that "This email may be phishing" and is provided with more information.

[0254] As described above, the present invention automates the process of risk assessment and user notification when an email is received, thereby realizing accurate security measures in real time.

[0255] The flow of the specific processing in the application example 1 will be described with reference to FIG.

[0256] Step 1:

[0257] The terminal acquires the email data received by the user. It parses the new email data received through the email client application into necessary elements such as subject, sender address, body, attachments, and URLs. The acquired data becomes the input for the next processing step.

[0258] Step 2:

[0259] The terminal converts the acquired email data into text data. The text data is then formatted into an analyzable format and sent to the server. In this data conversion process, the email body and URL are unified into a string format.

[0260] Step 3:

[0261] The server receives the received text data and analyzes the email content using natural language processing technology. The input for analysis is the text data and extracted URLs. During the analysis process, a generative AI model (e.g., GPT-3) is used to identify signs of phishing and anomalous expressions in the text. The output is the analysis results.

[0262] Step 4:

[0263] The server performs a risk assessment based on the analysis results. The input is the analysis results obtained in step 3. The server compares the sender address with a database to assess its trustworthiness, and compares the URL in the email with a safety database. Furthermore, if necessary, it actually checks the destination of the URL and assesses signs of fraud. This classifies the risk level of the email into three categories: high risk, medium risk, and low risk. This risk assessment is the output.

[0264] Step 5:

[0265] The server sends the risk assessment result to the client device. The input is the risk assessment result, and the output is a notification message sent to the client device. The notification message includes the risk level and specific factors (e.g., the likelihood of phishing or the presence of a malicious URL).

[0266] Step 6:

[0267] The terminal displays a notification to the user based on the evaluation results. The input is the received notification message, and the output is a warning message or detailed information presented to the user. This allows the user to immediately recognize the safety of their email and take any necessary action.

[0268] The above processing steps enable rapid and accurate risk assessment and user notification upon receipt of email.

[0269] Furthermore, an emotion engine that estimates the user's emotion may be combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59 and perform identification processing using the user's emotion.

[0270] This invention relates to a system that receives email data, analyzes its contents, performs risk assessment, and notifies the user. It also combines an emotion engine that recognizes the user's emotions and dynamically adjusts the risk assessment and notification method accordingly.

[0271] System program and processing description

[0272] 1. Receiving emails and extracting data

[0273] 1. The user receives an email

[0274] A user opens an email client application and receives a new email, which is then saved in the device's storage.

[0275] 2. The device extracts the email data

[0276] The device extracts the body of the email, subject, sender address, and any URLs contained in it from the email data stored on the device.

[0277] 2. Email Data Analysis

[0278] 3. The device sends the extracted data to the server

[0279] The extracted email data is sent to a server, where a generative AI with natural language processing technology is placed to analyze the data.

[0280] 4. The server analyzes the email content using natural language processing

[0281] The server's AI analyzes the email body and detects abnormal patterns that may indicate fraud or phishing, such as the phrase "Click on the link to update your account information."

[0282] 5. The server checks the sender

[0283] The server checks the email sender address against a secure database to assess its trustworthiness. If it's a known fraudulent sender on the list, it's rated as high risk.

[0284] 3. URL Parsing

[0285] 6. The server extracts the URLs from the email

[0286] The server extracts URLs from the email body and analyzes which sites each URL leads to.

[0287] 7. The server checks the URL against a secure database

[0288] It checks the URL against a database and warns you if it is a known phishing site or a dangerous site.

[0289] 8. The server actually checks the URL destination if necessary

[0290] The server actually accesses the URL and analyzes its contents to check whether it contains any invalid elements.

[0291] 4. Risk Assessment and Notification

[0292] 9. The server performs a risk assessment

[0293] The server performs a risk assessment based on the analysis of the email body and URL, and classifies the risk as high, medium, or low.

[0294] 10. The server sends the evaluation results to the device.

[0295] The risk assessment results are sent to the device, along with detailed reasons for the assessment.

[0296] 11. The device notifies the user

[0297] The device will notify the user based on the risk assessment results. If the email is high risk, a warning message will be displayed, urging the user not to open the email. If the email is trustworthy, the device will notify the user that it is "safe."

[0298] 5. Emotion engine integration

[0299] 12. The device will recognize the user's emotions

[0300] The emotion engine built into the device uses a camera and microphone to detect emotions from the user's facial expressions and voice, and the emotion data is analyzed in real time.

[0301] 13. The server analyzes the emotional data and reflects it in risk assessment

[0302] The server can then use emotional data to provide flexibility in risk assessment, for example, making a more conservative risk assessment if the user is in an unstable emotional state.

[0303] 14. The server selects the notification method according to the emotion

[0304] The server adjusts the notification method depending on the detected emotion, for example, displaying a strong warning message if the user is unstable, and a light warning if the user is stable.

[0305] Specific examples

[0306] Example 1: A user receives a phishing email

[0307] 1. A user receives a phishing email

[0308] A user receives a phishing email with the subject "Your account information has been suspended."

[0309] 2. The device extracts the email data and sends it to the server

[0310] The email body, subject, sender, and URL are extracted and sent to the server.

[0311] 3. The server detects signs of fraud

[0312] The server's AI analyzes the email content to detect signs of fraud and also checks that the sender is on a fraud list.

[0313] 4. The server analyzes the URL and checks if it is a phishing site

[0314] Verify that the URL matches a known phishing site and also contains malicious scripts.

[0315] 5. The server evaluates the risk as high and sends the result to the device.

[0316] The server evaluates the email as high risk and sends the result to the device.

[0317] 6. Emotion engine detects user's unstable emotions

[0318] The emotion engine detects when a user expresses uneasy emotions about a phishing email.

[0319] 7. The server displays a strong warning

[0320] The server displays a strong warning message on the terminal based on the user's emotional state.

[0321] Example 2: Receiving important emails from work and checking safety

[0322] 1. A user receives an important email from work

[0323] A user receives a secure email with the subject "Next Meeting Materials."

[0324] 2. The device extracts the email data and sends it to the server

[0325] The email body and URL are extracted and sent to the server.

[0326] 3. The server performs analysis and does not detect any abnormalities.

[0327] The server's AI analyzes the email content and verifies that there are no abnormal patterns.

[0328] 4. The server analyzes the URL and verifies that it is a secure site.

[0329] The URL is confirmed to be the official workplace website.

[0330] 5. The server evaluates the risk as low and sends the result to the device.

[0331] The email is assessed as low risk and the result is sent to the device.

[0332] 6. The emotion engine detects the user's calm emotion

[0333] The emotion engine ensures that the user is in a normal emotional state.

[0334] 7. Server displays a light notification

[0335] The server responds to the user's sentiment and displays a simple notification saying, "This email is safe."

[0336] As described above, the present invention goes beyond the conventional technology of analyzing email content and assessing risk by providing a system that dynamically adjusts risk assessment and notification methods taking into account the user's emotional state, allowing users to receive flexible support tailored to their emotions while improving email security.

[0337] The processing flow will be explained below.

[0338] Step 1:

[0339] When a user receives an email, the device stores the email in the email client application in internal storage, along with metadata such as the email content, subject, sender address, and any URLs it contains.

[0340] Step 2:

[0341] The device extracts text data from the email data stored on the device. Specifically, it analyzes the email body, subject, and sender address and organizes it as structured data in a specific format.

[0342] Step 3:

[0343] The device sends the extracted email data and URL information to the server, using an encrypted communication protocol to ensure security.

[0344] Step 4:

[0345] The server uses natural language processing technology to analyze the email data it receives. An AI model analyzes the email body and detects abnormal patterns and keywords that may indicate fraud or phishing. For example, phrases such as "update your account information" or "important notice" may indicate the possibility of phishing.

[0346] Step 5:

[0347] The server checks the sending address against a database containing known scam addresses and spam sources, and then rates the sending address as trustworthy or risky.

[0348] Step 6:

[0349] The server extracts all URLs from the email, detects URLs from the email body, and analyzes which sites each URL leads to.

[0350] Step 7:

[0351] The server checks the URL against a safety database, which contains information about known safe and dangerous sites. If the URL is a known phishing site or hosts malware, it is rated as high risk.

[0352] Step 8:

[0353] If necessary, the server will actually check the destination site of the URL. In this step, the server will access the URL and analyze its content. For example, it will check the page content to detect whether it contains malicious scripts or suspicious elements.

[0354] Step 9:

[0355] The server then assesses the risk of the email based on the analysis results. Risk is classified as high, medium, or low. For example, emails that are likely to be fraudulent or contain URLs that include phishing sites are assessed as high risk.

[0356] Step 10:

[0357] The server sends the risk assessment results to the device, including the type of risk and the reasons for it, in a format that is easy for the user to understand.

[0358] Step 11:

[0359] The device notifies the user based on the risk assessment results. For high-risk emails, a warning message is displayed on the screen, urging the user not to open the email. For trustworthy emails, the device notifies the user that "This email is safe."

[0360] Step 12:

[0361] The device recognizes the user's emotions. The emotion engine built into the device uses the camera and microphone to detect emotions from the user's facial expressions and voice. Emotional data is analyzed in real time.

[0362] Step 13:

[0363] The server analyzes the emotional data and reflects it in the risk assessment. The server makes the risk assessment flexible based on the emotional data. For example, if the user is in an unstable emotional state, the server makes a more cautious risk assessment.

[0364] Step 14:

[0365] The server selects the notification method according to the emotion. The server adjusts the notification method according to the emotion detected. For example, if the user is in an unstable state, a strong warning message is displayed, and conversely, if the user is stable, a light warning is displayed.

[0366] Step 15:

[0367] The user is notified and can decide whether to open the email, delete it, or conduct further safety checks based on the risk assessment provided. This process allows the user to quickly and accurately understand the safety of the email they received, and also provides appropriate support based on their emotional state.

[0368] Example 2

[0369] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."

[0370] While conventional email risk assessment systems are technically effective, such as by analyzing email text and checking sender addresses, they ignore the user's emotional state and do not take into account the user's mental burden. Furthermore, because the risk notification method is uniform, they have the problem of being unable to respond adequately in situations where flexible responses according to the user's state are required.

[0371] The specific processing by the specific processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means.

[0372] In this invention, the server includes means for analyzing email data, means for verifying sender addresses and URLs, and means for adjusting risk assessment and notification methods based on user emotional data, thereby enabling flexible risk assessment and notification according to the user's emotional state.

[0373] "Email data" refers to all data received as the content of an email, including the body of the email, the subject line, the sender's address, and URLs.

[0374] "Text data" refers to character information extracted from email data, such as the body of the email and the subject line that are the subject of analysis.

[0375] "Server" refers to a computer system for analyzing email data, assessing risk, and processing emotional data.

[0376] "Natural language processing technology" refers to technology that allows computers to understand, interpret, and generate human language, and is used as a means of detecting signs of fraud in email text.

[0377] "Risk assessment" refers to the process of assessing the degree of risk an email poses based on the content of the analyzed email data, the sender address, and the safety of the URL.

[0378] "Notification" refers to the act of communicating the results of a risk assessment to the user, including warning messages and safety notifications.

[0379] An "emotion engine" is a system that uses a camera or microphone to recognize a user's emotions, analyzes the data, and reflects it in risk assessments and notification methods.

[0380] A "safe database" is a database containing information such as known fraudulent sites and unsafe source addresses, and is used to match URLs and source addresses.

[0381] "Real-time" refers to the timing in which data is processed and analyzed the moment it is generated, meaning that results are reflected immediately.

[0382] "Threat information" means information that indicates potential dangers to networks and systems, including data on malware, phishing sites, and fraudulent activities.

[0383] This invention relates to a system that receives email data, analyzes its contents, performs risk assessment, and notifies the user. It also combines an emotion engine that recognizes the user's emotions and dynamically adjusts the risk assessment and notification method accordingly.

[0384] Hardware and software used

[0385] This system is primarily comprised of terminals and servers. An email client application (e.g., commonly referred to as an "email client") is installed on the terminal, which receives and manages email data. The server is equipped with a generative AI model (e.g., natural language processing technology such as OpenAI GPT-3) that analyzes email data and assesses risk. Furthermore, an emotion engine (e.g., Microsoft® Azure's emotion recognition API) is used to analyze user emotions.

[0386] Data processing and calculation

[0387] 1. Email reception and data extraction

[0388] The user opens an email client and receives a new email. The email data is stored in the device's storage.

[0389] The device extracts the body, subject, sender address, and URL from the email data stored on the device. This process is performed using a Python email parser library.

[0390] 2. Email Data Analysis

[0391] The terminal sends the extracted email data to the server, where it is converted into JSON format and sent via the HTTPS protocol.

[0392] The server-generated AI model analyzes the email body and detects signs of fraud or phishing.

[0393] The server checks the sender address against a safety database (e.g., Spamhaus or PhishTank) to assess trustworthiness.

[0394] 3. URL Parsing

[0395] The server extracts the URL from the email body and checks its safety against a safety database (e.g., Google Safe Browsing API).

[0396] If necessary, the server will actually visit the URL and scrape the website content to detect malicious scripts.

[0397] 4. Risk Assessment and Notification

[0398] The server performs a risk assessment based on the analysis of the email body, sender, and URL, and classifies the email as high risk, medium risk, or low risk.

[0399] The evaluation results are sent to the device in JSON format, and the device notifies the user. If the risk is high, a warning message is displayed, and if the risk is low, a message stating "it's safe" is displayed.

[0400] 5. Emotion engine integration

[0401] The emotion engine built into the device uses the camera and microphone to analyze the user's emotions in real time.

[0402] The server dynamically adjusts risk assessment and notification methods based on emotional data, displaying a strong warning if the user is in an unstable state and a light warning if the user is in a stable state.

[0403] Specific examples

[0404] Example 1: Detecting phishing emails and notifying users

[0405] 1. The user receives a phishing email with the subject "Your account information has been suspended."

[0406] 2. The device extracts the email data and sends it to the server.

[0407] 3. The server's generative AI model detects signs of fraud and verifies that the sender is on the fraud list.

[0408] 4. The server parses the URL and verifies that it matches a phishing site.

[0409] 5. Evaluate it as high risk and send the result to the device.

[0410] 6. The emotion engine detects the user's unstable emotions and displays a strong warning message.

[0411] Example 2: Checking important emails from work

[0412] 1. A user receives a secure email with the subject "Next Meeting Materials."

[0413] 2. The device extracts the email data and sends it to the server.

[0414] 3. The server-generated AI model analyzes the email content and verifies that there are no abnormal patterns.

[0415] 4. The server parses the URL and verifies that it is a secure site.

[0416] 5. Evaluate it as low risk and send the result to the device.

[0417] 6. The emotion engine checks the user's stable emotions and displays a gentle notification saying, "This email is safe."

[0418] Examples of prompt statements

[0419] Phishing email risk assessment prompt:

[0420] Analyze the body of the following emails for signs of fraud and categorize them as high, medium, or low risk.

[0421] Email body: "Your account information has been suspended. Click the link below to update it: http: / / example.com"

[0422] Prompts that adjust notification methods based on the user's emotions:

[0423] Based on the following emotional data, select the appropriate notification method according to the risk assessment results: If the user is unstable, give a strong warning, and if the user is stable, give a light warning.

[0424] Emotion data: { "emotion": "anxious", "confidence": 0.85}

[0425] The above is an embodiment of the present invention. This system allows users to enhance email security and receive flexible support according to their emotions.

[0426] The flow of the identification process in the second embodiment will be described with reference to FIG.

[0427] Step 1:

[0428] The user receives the email.

[0429] Input: Data from the mail server, including emails

[0430] What happens: The user opens their email client and receives a new email.

[0431] Output: Email data stored in the device's storage (body, subject, sender address, URL, etc.)

[0432] Step 2:

[0433] The device extracts the email data.

[0434] Input: Email data stored in the device's storage

[0435] What it does: The device uses a Python email parser library (e.g., the email package) to extract the body, subject, sender address, and URL from the email data stored on the device.

[0436] Output: Extracted text data (body, subject, sender address, URL)

[0437] Step 3:

[0438] The terminal transmits the extracted data to the server.

[0439] Input: Extracted text data

[0440] Specific operation: The terminal converts the extracted email data into JSON format and sends it to the server using the HTTPS protocol.

[0441] Output: Text data sent to the server

[0442] Step 4:

[0443] The server analyzes the email content using natural language processing.

[0444] Input: Text data sent to the server

[0445] How it works: The server-generated AI model analyzes the body of received emails and detects anomalous patterns that may indicate fraud or phishing, such as the phrase "Click on the link to update your account information."

[0446] Output: Analysis results (presence or absence of signs of fraud, detection of abnormal patterns)

[0447] Step 5:

[0448] The server verifies the sender.

[0449] Input: Source address and analysis result from the previous step

[0450] What it does: The server checks the sender address of the email against a secure database (e.g., Spamhaus or PhishTank) to assess its trustworthiness. If it is a known fraudulent sender, it is rated as high risk.

[0451] Output: Sender evaluation result (sender reliability evaluation)

[0452] Step 6:

[0453] The server extracts the URLs in the email.

[0454] Input: Email body

[0455] Specific operation: The server uses regular expressions to extract URLs from the email body and stores them in a list.

[0456] Output: Extracted URL list

[0457] Step 7:

[0458] The server checks the URL against a secure database.

[0459] Input: Extracted URL list

[0460] How it works: The server checks the URL against a safety database (e.g., Google Safe Browsing API) to verify its safety. If the site is fraudulent, it immediately issues a warning.

[0461] Output: URL safety assessment results

[0462] Step 8:

[0463] The server will actually check the URL destination if necessary.

[0464] Input: Suspected dangerous URL

[0465] Specific operation: The server actually accesses the URL and uses BeautifulSoup or Selenium to scrape the HTML content of the destination website to detect whether or not there is any malicious script.

[0466] Output: URL check result (whether malicious script is included or not)

[0467] Step 9:

[0468] The server performs the risk assessment.

[0469] Input: Email body analysis results, sender evaluation results, URL evaluation results

[0470] Specific operation: The server evaluates these results comprehensively and calculates a risk score, which is then classified as high risk, medium risk, or low risk.

[0471] Output: Risk assessment results (risk score and classification)

[0472] Step 10:

[0473] The server transmits the evaluation results to the terminal.

[0474] Input: Risk assessment results

[0475] Specific operation: The server converts the risk assessment results and detailed assessment reasons into JSON format and sends them to the terminal using the HTTPS protocol.

[0476] Output: Risk assessment results sent to the device

[0477] Step 11:

[0478] The terminal notifies the user.

[0479] Input: Risk assessment results

[0480] Specific operation: Based on the risk assessment results received by the device, the notification API is used to notify the user. If the risk is high, a warning message will be displayed in a pop-up window stating "This is a high-risk email. Do not open it."

[0481] Output: User notification (warning message)

[0482] Step 12:

[0483] The device recognizes the user's emotions.

[0484] Input: User facial and voice data

[0485] Specific operation: The emotion engine (e.g., emotion recognition API) built into the device uses the camera and microphone to analyze the user's facial expressions and voice in real time.

[0486] Output: Parsed emotion data

[0487] Step 13:

[0488] The server analyzes the emotional data and reflects it in risk assessment.

[0489] Input: Emotion data and risk assessment results

[0490] Specific operation: The server flexibly adjusts the risk assessment based on the analyzed emotional data. For example, if the user is in an unstable emotional state, the risk score will be adjusted upward.

[0491] Output: Adjusted risk assessment results

[0492] Step 14:

[0493] The server selects the notification method according to the emotion.

[0494] Input: Adjusted risk assessment results and sentiment data

[0495] Specific operation: The server selects the notification method based on the detected emotion. For example, if the user is unstable, a strong warning message is displayed, and conversely, if the user is stable, a light warning is displayed.

[0496] Output: Emotion-based notification (strong or mild warning message)

[0497] (Application example 2)

[0498] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."

[0499] Conventional email security systems analyze received email data to perform risk assessment, but are indifferent to the user's emotional state, resulting in a lack of accuracy and flexibility in risk assessment and notification. Furthermore, to address the increase in fraudulent emails, including phishing and scams, real-time risk assessment and advanced warning systems are necessary, but the current situation is one in which these are not fully realized. Therefore, there is a need for a method of personalized risk assessment notification that responds to the user's emotional state.

[0500] The identification process by the identification processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means. In this invention, the server includes means for receiving email data, means for converting the received email data into text data, means for transmitting the text data to the server and analyzing it using natural language processing technology on the server side, means for assessing the risk of the email based on the analysis results, means for recognizing the user's emotions, means for adaptively adjusting the risk assessment based on the detection results of the emotion engine, and means for transmitting the risk assessment results to the terminal and notifying the user. This enables dynamic and flexible risk assessment and notification according to the user's emotional state. Furthermore, by updating the risk assessment based on threat information collected in real time and displaying a strong warning if the user is in an unstable emotional state, more effective and personalized security measures are realized.

[0501] "Email data" refers to the content and metadata of an email, including the body, subject, sender address, URL, etc.

[0502] A "server" refers to a computer system that performs processes such as receiving, transmitting, analyzing, and storing data on a network.

[0503] "Natural language processing technology" refers to technology that mechanically analyzes, understands, and generates human language, and analyzes email text and other text data to extract meaning.

[0504] "Risk assessment" refers to the process of determining whether an email contains risks such as phishing, fraud, or malware based on the results of analyzing email data.

[0505] "User" refers to a general user who uses an email client, checks received emails, and receives security notifications.

[0506] An "emotion engine" is a technology that detects the user's current emotions from their facial expressions, voice, etc., and adjusts the system's operation based on that.

[0507] "Risk assessment result" refers to the final risk assessment result issued by the server after analyzing the email data.

[0508] "Terminal" refers to a computer device (smartphone, PC, tablet, etc.) that is directly operated by a user and that receives notification of risk assessment results.

[0509] "Notification means" refers to methods and techniques for informing users of risk assessment results, including alert messages, pop-up notifications, and audio notifications.

[0510] A "database" refers to a storage system that systematically stores specific data and allows it to be quickly searched, collated, and updated.

[0511] "Indicators of fraud" refer to abnormal behavior or content that differs from normal operations or data patterns, and may include phishing sites or malware.

[0512] The system for implementing this invention integrates email data reception, analysis, risk assessment, emotion recognition, and notification. The present invention exchanges data between a server and a terminal, provides security notifications to users in real time, and dynamically adjusts the content of notifications according to the user's emotional state.

[0513] System configuration

[0514] Server: A computer system that receives, analyzes, and assesses risk of data, and is equipped with generative AI with natural language processing technology. When specific email data is received, it analyzes the data and assesses the risk of fraud, phishing, malware, etc. It also incorporates user emotional data to dynamically adjust risk assessment and notifications.

[0515] Terminal: A computing device that is directly operated by the user and receives and displays emails using an email client application. The terminal is equipped with an emotion engine with emotion recognition capabilities, and detects the user's emotions in real time using a camera and microphone.

[0516] Program processing

[0517] Receiving emails and extracting data: When a user opens an email client application and receives a new email, the email data is stored on the device and its contents (body, subject, sender address, and included URLs) are extracted. This process is performed using the email client application and the device's storage.

[0518] Data analysis and risk assessment: The extracted email data is sent to a server where it is analyzed using natural language processing technology. A generative AI model is placed on the server to analyze the email body and detect anomalous patterns. In addition, the sender address and URL are compared with a database to assess signs of fraud. The risk assessment is classified as high, medium, or low risk based on the content of the message body, the sender, and the safety of the URL.

[0519] Emotion recognition and risk assessment adjustment: The emotion engine built into the device uses the camera and microphone to recognize the user's emotions in real time. The recognized emotion data is sent to the server and reflected in the risk assessment. For example, if the user is in an unstable emotional state, the server will make a more cautious risk assessment and display a strong warning message.

[0520] Notification of risk assessment results: The server sends the risk assessment results to the terminal and notifies the user based on the results. The terminal displays the risk assessment results and provides the user with information about the safety of the email. If the email is deemed high risk, a warning message is displayed, urging the user not to open the email.

[0521] Specific examples

[0522] Prompt Sentence Examples

[0523] 1. Phishing emails:

[0524] Subject: "Update your account information"

[0525] Body text: "Click the link below to update your account information."

[0526] From: "malicious@example.com"

[0527] URL: "http: / / phishing.example.com"

[0528] 2. Secure Work Email:

[0529] Subject: "Materials for the next meeting"

[0530] Body of text: "I have attached the materials to be used at the next meeting."

[0531] From: "trusted@workplace.com"

[0532] URL: "http: / / workplace.com / document"]

[0533] In this way, the present invention improves email security and the user experience through collaboration between the server and the terminal. In addition, by utilizing an emotion engine, flexible responses according to the user's emotional state become possible.

[0534] The flow of the specific processing in the application example 2 will be described with reference to FIG.

[0535] Step 1:

[0536] The device opens an email client application. The user receives a new email, and the email data (body, subject, sender address, and included URLs) is saved to the device's storage. The input is the email the user received, and the output is the saved email data.

[0537] Step 2:

[0538] The device extracts data such as the body, subject, sender address, and included URLs from the saved email data. This process is performed by an internal routine of the email client application. The input is the email data saved in step 1, and the output is the extracted email data (body, subject, sender address, and URL).

[0539] Step 3:

[0540] The terminal sends the extracted email data to the server. The server analyzes the received email data using natural language processing technology. The input is the extracted email data, and the output is the email data received by the server.

[0541] Step 4:

[0542] The server analyzes the email body received using a generative AI model to detect signs of fraud. In this case, the generative AI model (e.g., DistilBERT) analyzes the meaning of the sentence and determines whether it is a scam or phishing scam, such as "Click the link to update your account information." The input is the email body, and the output is a risk assessment as a result of the analysis.

[0543] Step 5:

[0544] The server checks the sender address of the email against a database to evaluate its trustworthiness. It determines the trustworthiness by checking against a list of trusted sender addresses (e.g., trusted_sources). The input is the sender address, and the output is the result of the trustworthiness evaluation.

[0545] Step 6:

[0546] The server extracts the URL from the email and compares it with a safety database. Furthermore, if necessary, it actually checks the URL's destination and evaluates it for signs of fraud. Specifically, it sends an HTTP request to the URL and obtains the analysis results. The input is the URL, and the output is the URL's safety evaluation result.

[0547] Step 7:

[0548] The server performs a risk assessment based on the email body, the reliability assessment of the sender address, and the safety assessment of the URL. The risk assessment is classified as high risk, medium risk, or low risk. The input is the analysis result up to the previous step, and the output is the risk assessment result.

[0549] Step 8:

[0550] The emotion engine built into the device uses a camera and microphone to detect emotions from the user's facial expressions and voice. Specifically, it analyzes camera footage and audio data in real time. The input is the user's facial expression and voice data, and the output is the emotion recognition results.

[0551] Step 9:

[0552] The server adaptively adjusts the risk assessment based on the emotion recognition results. For example, if the user is in an unstable emotional state, the risk assessment is adjusted to be more cautious. The inputs are the emotion recognition results and the risk assessment results, and the output is the adjusted risk assessment results.

[0553] Step 10:

[0554] The server sends the risk assessment result to the terminal, and the terminal notifies the user. If the risk is high, a warning message is displayed, urging the user not to open the email. The input is the adjusted risk assessment result, and the output is the notification message displayed to the user.

[0555] The specific processing unit 290 transmits the result of the specific processing to the smart device 14. In the smart device 14, the control unit 46A causes the output device 40 to output the result of the specific processing. The microphone 38B acquires audio indicating a user input regarding the result of the specific processing. The control unit 46A transmits audio data indicating the user input acquired by the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.

[0556] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (registered trademark) (Internet search engine).<URL: https: / / openai.com / blog / chatgpt> ), Gemini (registered trademark) (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[0557] In the above embodiment, an example in which the specific process is performed by the data processing device 12 has been given, but the technology of the present disclosure is not limited to this, and the specific process may be performed by the smart device 14.

[0558] [Second embodiment]

[0559] FIG. 3 shows an example of the configuration of a data processing system 210 according to the second embodiment.

[0560] 3, the data processing system 210 includes the data processing device 12 and smart glasses 214. An example of the data processing device 12 is a server.

[0561] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[0562] The smart glasses 214 include a computer 36, a microphone 238, a speaker 240, a camera 42, and a communication I / F 44. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The microphone 238, the speaker 240, and the camera 42 are also connected to the bus 52.

[0563] The microphone 238 receives instructions and the like from the user 20 by receiving voice uttered by the user 20. The microphone 238 captures the voice uttered by the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio in accordance with instructions from the processor 46.

[0564] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the surroundings of user 20 (for example, an imaging range defined by an angle of view equivalent to the field of vision of a typical healthy person).

[0565] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 are responsible for the exchange of various information between the processor 46 and the processor 28 via the network 54. The exchange of various information between the processor 46 and the processor 28 using the communication I / Fs 44 and 26 is carried out in a secure state.

[0566] Fig. 4 shows an example of the main functions of the data processing device 12 and the smart glasses 214. As shown in Fig. 4, in the data processing device 12, a specific process is performed by the processor 28. A specific process program 56 is stored in the storage 32.

[0567] The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[0568] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[0569] In the smart glasses 214, the reception output process is performed by the processor 46. A reception output program 60 is stored in the storage 50. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.

[0570] Next, a description will be given of the identification process performed by the identification processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as the "server" and the smart glasses 214 will be referred to as the "terminal."

[0571] This invention relates to a system that receives email data, analyzes its contents, performs risk assessment, and notifies the user. Specifically, it uses generative AI to analyze the content of conversations and email text, and checks the destination sites of URLs.

[0572] System program and processing description

[0573] 1. Receiving emails

[0574] 1. The user receives an email

[0575] A user opens an email client application and receives new email, which is saved within the client application.

[0576] 2. The device extracts the email data

[0577] The device extracts the necessary information (body, subject, sender, URL, etc.) from the email data stored.

[0578] 2. Email Data Analysis

[0579] 3. The device sends the extracted data to the server

[0580] The extracted email data is sent to a server where a generative AI is placed and analyzes the data.

[0581] 4. The server analyzes the email content using natural language processing

[0582] AI on the server analyzes the email body using natural language processing technology. The purpose of the analysis is to detect signs of fraud, phishing, spam, etc. For example, if the email contains phrases such as "Please update your account information" or "Click the following link," it will determine that it is likely phishing.

[0583] 5. The server checks the sender

[0584] The server checks the sender address against a pre-registered database to assess its trustworthiness, and if it is a known scam or spam source, it is deemed high risk.

[0585] 3. URL Parsing

[0586] 6. The server extracts the URLs from the email

[0587] All URLs are extracted from the email body and the safety of each URL is evaluated.

[0588] 7. The server checks the URL against a secure database

[0589] The extracted URLs are checked against a pre-registered safe database, and if they are known phishing sites or sites hosting malware, they are rated as high risk.

[0590] 8. The server checks the URL destination

[0591] If necessary, the server will actually navigate to the URL and analyze the content of the site, and if it detects any signs of fraud, the risk level will be increased further.

[0592] 4. Risk Assessment and Notification

[0593] 9. The server performs a risk assessment

[0594] The server performs a comprehensive risk assessment based on the analysis of the email body and URLs, and the assessment is classified into three levels: high risk, medium risk, and low risk.

[0595] 10. The server sends the evaluation results to the device.

[0596] The risk assessment results are sent to the device, and include specific risk factors (e.g., "Possibly a phishing email" or "Contains a malicious URL").

[0597] 11. The device notifies the user

[0598] The device will notify the user based on the evaluation results. A warning message will be displayed for high-risk emails, urging the user not to open them. Trusted emails will also be notified that they are "safe."

[0599] Specific examples

[0600] Example 1: Receiving a phishing email

[0601] 1. The user receives a fraudulent email

[0602] The user receives an email with the subject "Your account has been suspended."

[0603] 2. The device analyzes the email and sends the data to the server

[0604] The email body and URL are extracted and sent to the server.

[0605] 3. The server analyzes the email and detects signs of phishing

[0606] The server's generative AI detects the phrase "Click the link below to update your account information."

[0607] Additionally, the sending address is verified as a known fraudulent address.

[0608] 4. The server parses the URL

[0609] The URL turns out to be a known phishing site.

[0610] 5. The server evaluates the risk as high and sends the result to the device.

[0611] The email is rated as high risk and a message is sent to the device saying, "This email may be phishing."

[0612] 6. The device displays a warning to the user

[0613] A warning message is displayed to the user.

[0614] Example 2: Receiving an important email from work

[0615] 1. A user receives an important email from work

[0616] A user receives an email titled "About the next meeting materials."

[0617] 2. The device analyzes the email and sends the data to the server

[0618] The email body and URL are extracted and sent to the server.

[0619] 3. The server analyzes the email and determines it is safe

[0620] The server's generative AI detects no abnormal patterns and verifies that the source address is trustworthy.

[0621] 4. The server parses the URL

[0622] The URL is confirmed to be the official workplace website.

[0623] 5. The server evaluates the risk as low and sends the result to the device.

[0624] It is evaluated as low risk and a message saying "This email is safe" is sent to the device.

[0625] 6. The device notifies the user

[0626] The user will see a notification that "This email is safe."

[0627] This allows users to quickly and accurately determine whether an email they receive is safe or poses a risk. This system can effectively respond to cyber threats that are constantly evolving, improving users' email security.

[0628] The processing flow will be explained below.

[0629] Step 1:

[0630] When a user receives an email, the device stores the email in the email client application in internal storage, along with metadata such as the email content, subject, sender address, and any URLs it contains.

[0631] Step 2:

[0632] The device extracts text data from the email data stored on the device. Specifically, it analyzes the email body, subject, and sender address and organizes it as structured data in a specific format.

[0633] Step 3:

[0634] The device then sends the extracted email data and URL information to the server, using an encrypted communication protocol to ensure security.

[0635] Step 4:

[0636] The server uses natural language processing technology to analyze the email data it receives. An AI model analyzes the email body and detects abnormal patterns and keywords that may indicate fraud or phishing. For example, phrases such as "update your account information" or "important notice" may indicate the possibility of phishing.

[0637] Step 5:

[0638] The server checks the sending address against a database containing known scam addresses and spam sources, and then rates the sending address as trustworthy or dangerous.

[0639] Step 6:

[0640] The server extracts all URLs from the email, detects URLs from the email body, and analyzes which sites each URL leads to.

[0641] Step 7:

[0642] The server checks the URL against a safety database, which contains information about known safe and dangerous sites. If the URL is a known phishing site or hosts malware, it is rated as high risk.

[0643] Step 8:

[0644] If necessary, the server will actually check the destination site of the URL. In this step, the server will access the URL and analyze its content. For example, it will check the page content to detect whether it contains malicious scripts or suspicious elements.

[0645] Step 9:

[0646] The server then assesses the risk of the email based on the analysis results. Risk is classified as high, medium, or low. For example, emails that are likely to be fraudulent or contain URLs that include phishing sites are assessed as high risk.

[0647] Step 10:

[0648] The server sends the risk assessment results to the device, including the type of risk and the reasons for it, in a format that is easy for the user to understand.

[0649] Step 11:

[0650] The device notifies the user based on the risk assessment results. For high-risk emails, a warning message is displayed on the screen, urging the user not to open the email. For trustworthy emails, the device notifies the user that "This email is safe."

[0651] Step 12:

[0652] The user is notified and is given a risk assessment to decide whether to open the email, delete it, or perform further safety checks.

[0653] These steps allow users to quickly and accurately understand the safety of the emails they receive, and by having the server and device work together, we can provide an unprecedentedly strong security environment.

[0654] Example 1

[0655] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."

[0656] In today's cyber environment, the threat of malicious emails such as phishing and spam is increasing, and users need a way to quickly and accurately determine whether the emails they receive are safe. However, existing email security measures are unable to fully analyze the risks of email content and URLs, potentially exposing users to serious risks. For this reason, a system is needed that performs advanced email content analysis and URL safety assessment, and provides accurate risk assessments and notifications to users in real time.

[0657] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.

[0658] In this invention, the server includes a means for comparing the sender address with a database to evaluate the reliability of the email, a means for extracting URLs from the email and comparing them with a safety database, and a means for checking the destination of the URL and evaluating signs of fraud. This makes it possible to evaluate the reliability of the email and the safety of the URL with high accuracy and quickly notify the user of the risk evaluation results.

[0659] "Mail Data" means digital information received and sent as email, including the body, subject, sender address, and associated metadata.

[0660] "Text data" refers to character string data in an analyzable format that includes the email body and related information.

[0661] A "server" is a computer system that provides services over a network, including hardware and software for data analysis and risk assessment.

[0662] "Natural language processing technology" is a general term for technologies that enable computers to understand, interpret, and generate human language.

[0663] "Risk assessment" is the process of assessing the degree of risk an email poses to the user based on the analyzed email, and the assessment results are classified as high risk, medium risk, or low risk.

[0664] "User" refers to the end user who uses this system to check the security of email.

[0665] A "database" is a software system for efficiently storing, managing, and retrieving data, including those in SQL or NoSQL formats.

[0666] A "safe database" is a database that holds information about known safe and dangerous URLs and domains.

[0667] A "headless browser" is a browser without a GUI, used for automation scripts and system testing.

[0668] A "generative AI model" is an artificial intelligence model that learns large amounts of data and generates and analyzes natural language, and is particularly used for natural language processing.

[0669] An "HTTP request" is a protocol request for exchanging information between a client and a server, typically a GET or POST request.

[0670] "Real-time threat intelligence" refers to the latest information on current security threats and attack patterns, which is used to update risk assessments.

[0671] This invention relates to a system that receives email data, analyzes its contents, performs risk assessment, and notifies the user. Specifically, it uses a generative AI model to analyze the contents of emails using natural language processing technology and checks the destination URLs.

[0672] First, the user receives an email using an email client application. The received email is saved on the device. The device then extracts the email body, subject, sender address, and all URLs in the email body from the saved data. This process uses the Python email package and regular expressions (Regex).

[0673] Next, the device sends the extracted email data to a server using an HTTP request (e.g., a POST request). A generative AI model (e.g., GPT-3) is placed on the server, and this AI model analyzes the email body using natural language processing (NLU). Specifically, it detects phrases that indicate a fraudulent email, such as "Please update your account information."

[0674] Additionally, the server compares the sender address of the email with a database (SQL or NoSQL database) to assess its trustworthiness. If it is a sender address of a known fraudulent email, it is assessed as high risk. Next, the server extracts all URLs from the email body and compares them with a safe database (e.g., Google Safe Browsing API). This assesses whether they are phishing sites or malware hosting sites.

[0675] In addition to this evaluation, the server will actually check the URL destination using a headless browser (for example, Selenium with ChromeDriver) and analyze the content of the site. If there are any signs of fraud or harmful scripts, the risk level will be raised further.

[0676] Once the risk assessment is complete, the server sends the results to the device. The assessment results include detailed information about specific risk factors (for example, "possibly a phishing email" or "contains a malicious URL"). The device uses this information to provide appropriate notifications to the user. For high-risk emails, a warning message is displayed, urging the user not to open the email. For trustworthy emails, the device notifies the user that the email is "safe."

[0677] As a concrete example, if a user receives a phishing email with the title "Your account has been suspended," the device extracts the email's text and URL and sends them to the server. The server's generative AI model detects the phrase "Click the link below to update your account information" and confirms that the sender address is a known scam address. If the URL is determined to be a phishing site, it is rated as high risk and the result is sent to the device. Finally, the device displays a warning to the user saying, "This email may be phishing."

[0678] This system is designed to effectively respond to ever-evolving cyber threats and improve users' email security. It also updates risk assessments based on threat information collected in real time, enabling rapid response to the latest security situations.

[0679] The flow of the identification process in the first embodiment will be described with reference to FIG.

[0680] Step 1: User receives email

[0681] Input: A user receives an email.

[0682] What it does: Opens an email client application (e.g., Gmail, Outlook) and receives a new email.

[0683] Output: Received emails are saved on the device.

[0684] What happens: When a user opens their email client, new emails are downloaded from the server and displayed within the email application.

[0685] Step 2: Your device extracts the email data

[0686] Input: Received email data.

[0687] How it works: Extracts the body, subject, sender address, and all URLs in the body from saved email data. It uses the Python email package and regular expressions (Regex).

[0688] Output: A list of extracted email bodies, subjects, sender addresses, and URLs.

[0689] What it does: The program analyzes the received email data and extracts important information.

[0690] Step 3: The device sends the extracted data to the server

[0691] Input: A list of extracted email bodies, subjects, sender addresses, and URLs.

[0692] What it does: Sends the extracted data to the server using an HTTP request (e.g., a POST request).

[0693] Output: The email data received by the server.

[0694] Specific operation: The device makes an HTTP request and sends data to the server endpoint.

[0695] Step 4: The server analyzes the email content using natural language processing

[0696] Input: The email body sent from the device.

[0697] How it works: It uses generative AI models (e.g., GPT-3) to analyze email content and detect signs of fraud and phishing. It uses natural language processing libraries like NLTK and SpaCy.

[0698] Output: Analysis results, information on indicators of fraud and phishing.

[0699] Specific operation: The server tokenizes the email content and analyzes specific keywords and context to extract dangerous phrases.

[0700] Step 5: The server checks the source

[0701] Input: The source address sent from the device.

[0702] How it works: The source address is checked against a database (e.g., an SQL or NoSQL database) to assess its trustworthiness.

[0703] Output: The reliability evaluation result of the source address.

[0704] What it does: Runs a database query to match the email against a list of known fraudulent email senders.

[0705] Step 6: The server extracts the URLs in the email

[0706] Input: The email body sent from the device.

[0707] What it does: Extracts all URLs from the email body using regular expressions (Regex).

[0708] Output: A list of extracted URLs.

[0709] What it does: Identify and list all possible URL patterns within the email body.

[0710] Step 7: Server checks URL against safety database

[0711] Input: The extracted URL list.

[0712] How it works: Each URL is checked against a safety database (e.g., Google Safe Browsing API) to assess whether it is a phishing or malware-hosting site.

[0713] Output: Safety assessment results for each URL.

[0714] What it does: It uses HTTP requests to check against a safety database to determine the risk level of the URL.

[0715] Step 8: The server checks the URL destination

[0716] Input: The extracted URL list.

[0717] What it does: Uses a headless browser (e.g. Selenium with ChromeDriver) to navigate to a URL and analyze the content of that site.

[0718] Output: Analysis results of the destination site, information on indicators of fraud.

[0719] What it does: It automatically manipulates the browser to access URLs and analyzes the page content to detect dangerous scripts and content.

[0720] Step 9: Server performs risk assessment

[0721] Input: Email body, sender address, and URL analysis results.

[0722] How it works: The results of these analyses are combined to give the email a risk rating, which is then categorized as high, medium, or low risk.

[0723] Output: Risk assessment results.

[0724] Specific operation: Integrates analysis results and performs comprehensive risk assessment based on pre-defined rules and models.

[0725] Step 10: The server sends the evaluation results to the device.

[0726] Input: Risk assessment results.

[0727] Operation: The evaluation result is sent to the terminal as an HTTP response.

[0728] Output: The evaluation results sent to the device.

[0729] Specific behavior: Create an HTTP response and send it along with the evaluation result.

[0730] Step 11: The device notifies the user

[0731] Input: The risk assessment result sent from the server.

[0732] Behavior: Notifies the user based on the evaluation results. High-risk emails are warned, and trusted emails are told "safe."

[0733] Output: Notification to the user.

[0734] Specific operation: The terminal displays an appropriate message on the user interface based on the evaluation results.

[0735] (Application example 1)

[0736] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."

[0737] In recent years, the spread of phishing attacks and malware via email has been increasing, increasing the risk of users suffering serious damage. For this reason, there is a need for a system that automatically analyzes the content of emails when they are received, evaluates potential risks, and notifies users. Conventional systems often perform insufficient email analysis or are slow to notify users of risks, so technology is needed to enable rapid and accurate risk assessment and notification.

[0738] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.

[0739] In this invention, the server includes means for acquiring email data, means for converting the acquired email data into text data, means for transmitting the text data to the server and analyzing it using natural language processing technology on the server side, means for performing a risk assessment of the email based on the analysis result, means for transmitting the risk assessment result to the client device and notifying the user, means for providing the user with specific factors of the risk assessment along with the notification, means for comparing the sender address with a database to evaluate the reliability of the email, means for extracting URLs from the email and comparing them with a safety database, means for actually checking the destination of the URLs and evaluating signs of fraud, means for classifying the email as high risk, medium risk, or low risk based on the risk assessment result, means for updating the risk assessment based on threat information collected in real time, means for displaying an immediate warning to the user based on the risk assessment, and means for providing detailed information simultaneously with the display of the warning message. This enables rapid and accurate risk assessment and notification to the user upon receipt of email.

[0740] "Email data" refers to the entire content of an email received by a user, including the subject, sender address, body, attachments, URLs, etc.

[0741] "Means of acquisition" refers to the technology or devices used to receive email and extract its contents.

[0742] "Text data" refers to the content of an e-mail, etc., converted into data in an analyzable format.

[0743] "Server" refers to the central system for analyzing email data and conducting risk assessments.

[0744] "Natural language processing technology" refers to technology for analyzing human language and understanding and processing its meaning and structure.

[0745] "Means for analyzing" refers to technology or devices for analyzing the content of email using natural language processing technology.

[0746] "Risk assessment" refers to determining whether an email is dangerous to the user based on the information contained in the email.

[0747] A "client device" is a device that a user directly uses, and includes a smartphone, tablet, computer, etc.

[0748] "Means of notification" refers to the technology or device used to notify users of the results of the risk assessment.

[0749] "Specific factors" refers to the individual factors or information provided to elaborate on the results of a risk assessment.

[0750] A "safe database" refers to a database that stores known safe URLs and reliable information.

[0751] "Indicators of fraud" refer to evidence or patterns that indicate possible malicious activity, such as phishing sites or malware.

[0752] "High risk, medium risk, low risk" are classifications of different levels of potential danger for email.

[0753] "Threat intelligence" refers to information about the latest threats and attack methods, including data collected in real time.

[0754] A "warning message" refers to a message that displays warning information to notify the user of a danger.

[0755] "Detailed information" refers to information provided to the user, including background and specific explanations of the risk assessment.

[0756] In order to put the present invention into practice, it is necessary to build a system that acquires email data, analyzes it, performs risk assessment, and notifies the user.

[0757] The system uses the following hardware and software:

[0758] Hardware

[0759] server

[0760] Client devices (smartphones, tablets, computers)

[0761] software

[0762] Email client applications

[0763] Natural language processing libraries (e.g. NLTK, SpaCy)

[0764] Generative AI models (e.g., OpenAI's GPT-3)

[0765] Security databases (e.g., lists of known phishing sites)

[0766] Database systems (e.g. PostgreSQL, MongoDB)

[0767] Server platform (e.g. AWS, GCP, Azure)

[0768] The server first obtains the email data received by the user. The obtained email data is converted into text data. The server receives the text data and analyzes it using natural language processing technology. Based on the analysis results, a risk assessment of the email is performed.

[0769] For risk assessment, the server uses the following methods:

[0770] 1. Check the sender address against a database to assess the authenticity of the email.

[0771] 2. Extract URLs from emails and check them against a secure database.

[0772] 3. Check the destination of the URL and evaluate for signs of fraud.

[0773] The risk assessment results are classified as high risk, medium risk, or low risk, and the results are sent to the client device, which receives the results and notifies the user, including the specific risk factors.

[0774] For example, the following prompt sentences are sent to the generative AI model for analysis:

[0775] Please analyze the body of the following email and assess it for signs of phishing:

[0776] ---

[0777] Subject: Your account has been suspended

[0778] Body: "Your account has been suspended due to unauthorized access. Please click the link below to update your account information: http: / / example.com / phishing"

[0779] From: "support@example.com"

[0780] Classify your results as "high risk," "medium risk," or "low risk," and explain why.

[0781] The generative AI model analyzes the email body based on this prompt and returns the analysis results to the server. Based on the results, the email is assessed for risk and notified to the user.

[0782] For example, if a user receives an email with the subject line "Your account has been suspended," the server analyzes the email and detects signs of phishing. As a result, the user is warned that "This email may be phishing" and is provided with more information.

[0783] As described above, the present invention automates the process of risk assessment and user notification when an email is received, thereby realizing accurate security measures in real time.

[0784] The flow of the specific processing in the application example 1 will be described with reference to FIG.

[0785] Step 1:

[0786] The terminal acquires the email data received by the user. It parses the new email data received through the email client application into necessary elements such as subject, sender address, body, attachments, and URLs. The acquired data becomes the input for the next processing step.

[0787] Step 2:

[0788] The terminal converts the acquired email data into text data. The text data is then formatted into an analyzable format and sent to the server. In this data conversion process, the email body and URL are unified into a string format.

[0789] Step 3:

[0790] The server receives the received text data and analyzes the email content using natural language processing technology. The input for analysis is the text data and extracted URLs. During the analysis process, a generative AI model (e.g., GPT-3) is used to identify signs of phishing and anomalous expressions in the text. The output is the analysis results.

[0791] Step 4:

[0792] The server performs a risk assessment based on the analysis results. The input is the analysis results obtained in step 3. The server compares the sender address with a database to assess its trustworthiness, and compares the URL in the email with a safety database. Furthermore, if necessary, it actually checks the destination of the URL and assesses signs of fraud. This classifies the risk level of the email into three categories: high risk, medium risk, and low risk. This risk assessment is the output.

[0793] Step 5:

[0794] The server sends the risk assessment result to the client device. The input is the risk assessment result, and the output is a notification message sent to the client device. The notification message includes the risk level and specific factors (e.g., the likelihood of phishing or the presence of a malicious URL).

[0795] Step 6:

[0796] The terminal displays a notification to the user based on the evaluation results. The input is the received notification message, and the output is a warning message or detailed information presented to the user. This allows the user to immediately recognize the safety of their email and take any necessary action.

[0797] The above processing steps enable rapid and accurate risk assessment and user notification upon receipt of email.

[0798] Furthermore, an emotion engine that estimates the user's emotion may be further combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59, and perform identification processing using the user's emotion.

[0799] This invention relates to a system that receives email data, analyzes its contents, performs risk assessment, and notifies the user. It also combines an emotion engine that recognizes the user's emotions and dynamically adjusts the risk assessment and notification method accordingly.

[0800] System program and processing description

[0801] 1. Receiving emails and extracting data

[0802] 1. The user receives an email

[0803] A user opens an email client application and receives a new email, which is then saved in the device's storage.

[0804] 2. The device extracts the email data

[0805] The device extracts the body of the email, subject, sender address, and any URLs contained in it from the email data stored on the device.

[0806] 2. Email Data Analysis

[0807] 3. The device sends the extracted data to the server

[0808] The extracted email data is sent to a server, where a generative AI with natural language processing technology is placed to analyze the data.

[0809] 4. The server analyzes the email content using natural language processing

[0810] The server's AI analyzes the email body and detects abnormal patterns that may indicate fraud or phishing, such as the phrase "Click on the link to update your account information."

[0811] 5. The server checks the sender

[0812] The server checks the email sender address against a secure database to assess its trustworthiness. If it's a known fraudulent sender on the list, it's rated as high risk.

[0813] 3. URL Parsing

[0814] 6. The server extracts the URLs from the email

[0815] The server extracts URLs from the email body and analyzes which sites each URL leads to.

[0816] 7. The server checks the URL against a secure database

[0817] It checks the URL against a database and warns you if it is a known phishing site or a dangerous site.

[0818] 8. The server actually checks the URL destination if necessary

[0819] The server actually accesses the URL and analyzes its contents to check whether it contains any invalid elements.

[0820] 4. Risk Assessment and Notification

[0821] 9. The server performs a risk assessment

[0822] The server performs a risk assessment based on the analysis of the email body and URL, and classifies the risk as high, medium, or low.

[0823] 10. The server sends the evaluation results to the device.

[0824] The risk assessment results are sent to the device, along with detailed reasons for the assessment.

[0825] 11. The device notifies the user

[0826] The device will notify the user based on the risk assessment results. If the email is high risk, a warning message will be displayed, urging the user not to open the email. If the email is trustworthy, the device will notify the user that it is "safe."

[0827] 5. Emotion engine integration

[0828] 12. The device will recognize the user's emotions

[0829] The emotion engine built into the device uses a camera and microphone to detect emotions from the user's facial expressions and voice, and the emotion data is analyzed in real time.

[0830] 13. The server analyzes the emotional data and reflects it in risk assessment

[0831] The server can then use emotional data to provide flexibility in risk assessment, for example, making a more conservative risk assessment if the user is in an unstable emotional state.

[0832] 14. The server selects the notification method according to the emotion

[0833] The server adjusts the notification method depending on the detected emotion, for example, displaying a strong warning message if the user is unstable, and a light warning if the user is stable.

[0834] Specific examples

[0835] Example 1: A user receives a phishing email

[0836] 1. A user receives a phishing email

[0837] A user receives a phishing email with the subject "Your account information has been suspended."

[0838] 2. The device extracts the email data and sends it to the server

[0839] The email body, subject, sender, and URL are extracted and sent to the server.

[0840] 3. The server detects signs of fraud

[0841] The server's AI analyzes the email content to detect signs of fraud and also checks that the sender is on a fraud list.

[0842] 4. The server analyzes the URL and checks if it is a phishing site

[0843] Verify that the URL matches a known phishing site and also contains malicious scripts.

[0844] 5. The server evaluates the risk as high and sends the result to the device.

[0845] The server evaluates the email as high risk and sends the result to the device.

[0846] 6. Emotion engine detects user's unstable emotions

[0847] The emotion engine detects when a user expresses uneasy emotions about a phishing email.

[0848] 7. The server displays a strong warning

[0849] The server displays a strong warning message on the terminal based on the user's emotional state.

[0850] Example 2: Receiving important emails from work and checking safety

[0851] 1. A user receives an important email from work

[0852] A user receives a secure email with the subject "Next Meeting Materials."

[0853] 2. The device extracts the email data and sends it to the server

[0854] The email body and URL are extracted and sent to the server.

[0855] 3. The server performs analysis and does not detect any abnormalities.

[0856] The server's AI analyzes the email content and verifies that there are no abnormal patterns.

[0857] 4. The server analyzes the URL and verifies that it is a secure site.

[0858] The URL is confirmed to be the official workplace website.

[0859] 5. The server evaluates the risk as low and sends the result to the device.

[0860] The email is assessed as low risk and the result is sent to the device.

[0861] 6. The emotion engine detects the user's calm emotion

[0862] The emotion engine ensures that the user is in a normal emotional state.

[0863] 7. Server displays a light notification

[0864] The server responds to the user's sentiment and displays a simple notification saying, "This email is safe."

[0865] As described above, the present invention goes beyond the conventional technology of analyzing email content and assessing risk by providing a system that dynamically adjusts risk assessment and notification methods taking into account the user's emotional state, allowing users to receive flexible support tailored to their emotions while improving email security.

[0866] The processing flow will be explained below.

[0867] Step 1:

[0868] When a user receives an email, the device stores the email in the email client application in internal storage, along with metadata such as the email content, subject, sender address, and any URLs it contains.

[0869] Step 2:

[0870] The device extracts text data from the email data stored on the device. Specifically, it analyzes the email body, subject, and sender address and organizes it as structured data in a specific format.

[0871] Step 3:

[0872] The device sends the extracted email data and URL information to the server, using an encrypted communication protocol to ensure security.

[0873] Step 4:

[0874] The server uses natural language processing technology to analyze the email data it receives. An AI model analyzes the email body and detects abnormal patterns and keywords that may indicate fraud or phishing. For example, phrases such as "update your account information" or "important notice" may indicate the possibility of phishing.

[0875] Step 5:

[0876] The server checks the sending address against a database containing known scam addresses and spam sources, and then rates the sending address as trustworthy or risky.

[0877] Step 6:

[0878] The server extracts all URLs from the email, detects URLs from the email body, and analyzes which sites each URL leads to.

[0879] Step 7:

[0880] The server checks the URL against a safety database, which contains information about known safe and dangerous sites. If the URL is a known phishing site or hosts malware, it is rated as high risk.

[0881] Step 8:

[0882] If necessary, the server will actually check the destination site of the URL. In this step, the server will access the URL and analyze its content. For example, it will check the page content to detect whether it contains malicious scripts or suspicious elements.

[0883] Step 9:

[0884] The server then assesses the risk of the email based on the analysis results. Risk is classified as high, medium, or low. For example, emails that are likely to be fraudulent or contain URLs that include phishing sites are assessed as high risk.

[0885] Step 10:

[0886] The server sends the risk assessment results to the device, including the type of risk and the reasons for it, in a format that is easy for the user to understand.

[0887] Step 11:

[0888] The device notifies the user based on the risk assessment results. For high-risk emails, a warning message is displayed on the screen, urging the user not to open the email. For trustworthy emails, the device notifies the user that "This email is safe."

[0889] Step 12:

[0890] The device recognizes the user's emotions. The emotion engine built into the device uses the camera and microphone to detect emotions from the user's facial expressions and voice. Emotional data is analyzed in real time.

[0891] Step 13:

[0892] The server analyzes the emotional data and reflects it in the risk assessment. The server makes the risk assessment flexible based on the emotional data. For example, if the user is in an unstable emotional state, the server makes a more cautious risk assessment.

[0893] Step 14:

[0894] The server selects the notification method according to the emotion. The server adjusts the notification method according to the emotion detected. For example, if the user is in an unstable state, a strong warning message is displayed, and conversely, if the user is stable, a light warning is displayed.

[0895] Step 15:

[0896] The user is notified and can decide whether to open the email, delete it, or conduct further safety checks based on the risk assessment provided. This process allows the user to quickly and accurately understand the safety of the email they received, and also provides appropriate support based on their emotional state.

[0897] Example 2

[0898] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."

[0899] While conventional email risk assessment systems are technically effective, such as by analyzing email text and checking sender addresses, they ignore the user's emotional state and do not take into account the user's mental burden. Furthermore, because the risk notification method is uniform, they have the problem of being unable to respond adequately in situations where flexible responses according to the user's state are required.

[0900] The specific processing by the specific processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means.

[0901] In this invention, the server includes means for analyzing email data, means for verifying sender addresses and URLs, and means for adjusting risk assessment and notification methods based on user emotional data, thereby enabling flexible risk assessment and notification according to the user's emotional state.

[0902] "Email data" refers to all data received as the content of an email, including the body of the email, the subject line, the sender's address, and URLs.

[0903] "Text data" refers to character information extracted from email data, such as the body of the email and the subject line that are the subject of analysis.

[0904] "Server" refers to a computer system for analyzing email data, assessing risk, and processing emotional data.

[0905] "Natural language processing technology" refers to technology that allows computers to understand, interpret, and generate human language, and is used as a means of detecting signs of fraud in email text.

[0906] "Risk assessment" refers to the process of assessing the degree of risk an email poses based on the content of the analyzed email data, the sender address, and the safety of the URL.

[0907] "Notification" refers to the act of communicating the results of a risk assessment to the user, including warning messages and safety notifications.

[0908] An "emotion engine" is a system that uses a camera or microphone to recognize a user's emotions, analyzes the data, and reflects it in risk assessments and notification methods.

[0909] A "safe database" is a database containing information such as known fraudulent sites and unsafe source addresses, and is used to match URLs and source addresses.

[0910] "Real-time" refers to the timing in which data is processed and analyzed the moment it is generated, meaning that results are reflected immediately.

[0911] "Threat information" means information that indicates potential dangers to networks and systems, including data on malware, phishing sites, and fraudulent activities.

[0912] This invention relates to a system that receives email data, analyzes its contents, performs risk assessment, and notifies the user. It also combines an emotion engine that recognizes the user's emotions and dynamically adjusts the risk assessment and notification method accordingly.

[0913] Hardware and software used

[0914] This system is primarily comprised of terminals and servers. An email client application (e.g., commonly referred to as an "email client") is installed on the terminal, which receives and manages email data. The server is equipped with a generative AI model (e.g., natural language processing technology such as OpenAI GPT-3) that analyzes email data and assesses risk. In addition, an emotion engine (e.g., Microsoft Azure's emotion recognition API) is used to analyze user emotions.

[0915] Data processing and calculation

[0916] 1. Email reception and data extraction

[0917] The user opens an email client and receives a new email. The email data is stored in the device's storage.

[0918] The device extracts the body, subject, sender address, and URL from the email data stored on the device. This process is performed using a Python email parser library.

[0919] 2. Email Data Analysis

[0920] The terminal sends the extracted email data to the server, where it is converted into JSON format and sent via the HTTPS protocol.

[0921] The server-generated AI model analyzes the email body and detects signs of fraud or phishing.

[0922] The server checks the sender address against a safety database (e.g., Spamhaus or PhishTank) to assess trustworthiness.

[0923] 3. URL Parsing

[0924] The server extracts the URL from the email body and checks its safety against a safety database (e.g., Google Safe Browsing API).

[0925] If necessary, the server will actually visit the URL and scrape the website content to detect malicious scripts.

[0926] 4. Risk Assessment and Notification

[0927] The server performs a risk assessment based on the analysis of the email body, sender, and URL, and classifies the email as high risk, medium risk, or low risk.

[0928] The evaluation results are sent to the device in JSON format, and the device notifies the user. If the risk is high, a warning message is displayed, and if the risk is low, a message stating "it's safe" is displayed.

[0929] 5. Emotion engine integration

[0930] The emotion engine built into the device uses the camera and microphone to analyze the user's emotions in real time.

[0931] The server dynamically adjusts risk assessment and notification methods based on emotional data, displaying a strong warning if the user is in an unstable state and a light warning if the user is in a stable state.

[0932] Specific examples

[0933] Example 1: Detecting phishing emails and notifying users

[0934] 1. The user receives a phishing email with the subject "Your account information has been suspended."

[0935] 2. The device extracts the email data and sends it to the server.

[0936] 3. The server's generative AI model detects signs of fraud and verifies that the sender is on the fraud list.

[0937] 4. The server parses the URL and verifies that it matches a phishing site.

[0938] 5. Evaluate it as high risk and send the result to the device.

[0939] 6. The emotion engine detects the user's unstable emotions and displays a strong warning message.

[0940] Example 2: Checking important emails from work

[0941] 1. A user receives a secure email with the subject "Next Meeting Materials."

[0942] 2. The device extracts the email data and sends it to the server.

[0943] 3. The server-generated AI model analyzes the email content and verifies that there are no abnormal patterns.

[0944] 4. The server parses the URL and verifies that it is a secure site.

[0945] 5. Evaluate it as low risk and send the result to the device.

[0946] 6. The emotion engine checks the user's stable emotions and displays a gentle notification saying, "This email is safe."

[0947] Examples of prompt statements

[0948] Phishing email risk assessment prompt:

[0949] Analyze the body of the following emails for signs of fraud and categorize them as high, medium, or low risk.

[0950] Email body: "Your account information has been suspended. Click the link below to update it: http: / / example.com"

[0951] Prompts that adjust notification methods based on the user's emotions:

[0952] Based on the following emotional data, select the appropriate notification method according to the risk assessment results: If the user is unstable, give a strong warning, and if the user is stable, give a light warning.

[0953] Emotion data: { "emotion": "anxious", "confidence": 0.85}

[0954] The above is an embodiment of the present invention. This system allows users to enhance email security and receive flexible support according to their emotions.

[0955] The flow of the identification process in the second embodiment will be described with reference to FIG.

[0956] Step 1:

[0957] The user receives the email.

[0958] Input: Data from the mail server, including emails

[0959] What happens: The user opens their email client and receives a new email.

[0960] Output: Email data stored in the device's storage (body, subject, sender address, URL, etc.)

[0961] Step 2:

[0962] The device extracts the email data.

[0963] Input: Email data stored in the device's storage

[0964] What it does: The device uses a Python email parser library (e.g., the email package) to extract the body, subject, sender address, and URL from the email data stored on the device.

[0965] Output: Extracted text data (body, subject, sender address, URL)

[0966] Step 3:

[0967] The terminal transmits the extracted data to the server.

[0968] Input: Extracted text data

[0969] Specific operation: The terminal converts the extracted email data into JSON format and sends it to the server using the HTTPS protocol.

[0970] Output: Text data sent to the server

[0971] Step 4:

[0972] The server analyzes the email content using natural language processing.

[0973] Input: Text data sent to the server

[0974] How it works: The server-generated AI model analyzes the body of received emails and detects anomalous patterns that may indicate fraud or phishing, such as the phrase "Click on the link to update your account information."

[0975] Output: Analysis results (presence or absence of signs of fraud, detection of abnormal patterns)

[0976] Step 5:

[0977] The server verifies the sender.

[0978] Input: Source address and analysis result from the previous step

[0979] What it does: The server checks the sender address of the email against a secure database (e.g., Spamhaus or PhishTank) to assess its trustworthiness. If it is a known fraudulent sender, it is rated as high risk.

[0980] Output: Sender evaluation result (sender reliability evaluation)

[0981] Step 6:

[0982] The server extracts the URLs in the email.

[0983] Input: Email body

[0984] Specific operation: The server uses regular expressions to extract URLs from the email body and stores them in a list.

[0985] Output: Extracted URL list

[0986] Step 7:

[0987] The server checks the URL against a secure database.

[0988] Input: Extracted URL list

[0989] How it works: The server checks the URL against a safety database (e.g., Google Safe Browsing API) to verify its safety. If the site is fraudulent, it immediately issues a warning.

[0990] Output: URL safety assessment results

[0991] Step 8:

[0992] The server will actually check the URL destination if necessary.

[0993] Input: Suspected dangerous URL

[0994] Specific operation: The server actually accesses the URL and uses BeautifulSoup or Selenium to scrape the HTML content of the destination website to detect whether or not there is any malicious script.

[0995] Output: URL check result (whether malicious script is included or not)

[0996] Step 9:

[0997] The server performs the risk assessment.

[0998] Input: Email body analysis results, sender evaluation results, URL evaluation results

[0999] Specific operation: The server evaluates these results comprehensively and calculates a risk score, which is then classified as high risk, medium risk, or low risk.

[1000] Output: Risk assessment results (risk score and classification)

[1001] Step 10:

[1002] The server transmits the evaluation results to the terminal.

[1003] Input: Risk assessment results

[1004] Specific operation: The server converts the risk assessment results and detailed assessment reasons into JSON format and sends them to the terminal using the HTTPS protocol.

[1005] Output: Risk assessment results sent to the device

[1006] Step 11:

[1007] The terminal notifies the user.

[1008] Input: Risk assessment results

[1009] Specific operation: Based on the risk assessment results received by the device, the notification API is used to notify the user. If the risk is high, a warning message will be displayed in a pop-up window stating "This is a high-risk email. Do not open it."

[1010] Output: User notification (warning message)

[1011] Step 12:

[1012] The device recognizes the user's emotions.

[1013] Input: User facial and voice data

[1014] Specific operation: The emotion engine (e.g., emotion recognition API) built into the device uses the camera and microphone to analyze the user's facial expressions and voice in real time.

[1015] Output: Parsed emotion data

[1016] Step 13:

[1017] The server analyzes the emotional data and reflects it in risk assessment.

[1018] Input: Emotion data and risk assessment results

[1019] Specific operation: The server flexibly adjusts the risk assessment based on the analyzed emotional data. For example, if the user is in an unstable emotional state, the risk score will be adjusted upward.

[1020] Output: Adjusted risk assessment results

[1021] Step 14:

[1022] The server selects the notification method according to the emotion.

[1023] Input: Adjusted risk assessment results and sentiment data

[1024] Specific operation: The server selects the notification method based on the detected emotion. For example, if the user is unstable, a strong warning message is displayed, and conversely, if the user is stable, a light warning is displayed.

[1025] Output: Emotion-based notification (strong or mild warning message)

[1026] (Application example 2)

[1027] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."

[1028] Conventional email security systems analyze received email data to perform risk assessment, but are indifferent to the user's emotional state, resulting in a lack of accuracy and flexibility in risk assessment and notification. Furthermore, to address the increase in fraudulent emails, including phishing and scams, real-time risk assessment and advanced warning systems are necessary, but the current situation is one in which these are not fully realized. Therefore, there is a need for a method of personalized risk assessment notification that responds to the user's emotional state.

[1029] The identification process by the identification processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means. In this invention, the server includes means for receiving email data, means for converting the received email data into text data, means for transmitting the text data to the server and analyzing it using natural language processing technology on the server side, means for assessing the risk of the email based on the analysis results, means for recognizing the user's emotions, means for adaptively adjusting the risk assessment based on the detection results of the emotion engine, and means for transmitting the risk assessment results to the terminal and notifying the user. This enables dynamic and flexible risk assessment and notification according to the user's emotional state. Furthermore, by updating the risk assessment based on threat information collected in real time and displaying a strong warning if the user is in an unstable emotional state, more effective and personalized security measures are realized.

[1030] "Email data" refers to the content and metadata of an email, including the body, subject, sender address, URL, etc.

[1031] A "server" refers to a computer system that performs processes such as receiving, transmitting, analyzing, and storing data on a network.

[1032] "Natural language processing technology" refers to technology that mechanically analyzes, understands, and generates human language, and analyzes email text and other text data to extract meaning.

[1033] "Risk assessment" refers to the process of determining whether an email contains risks such as phishing, fraud, or malware based on the results of analyzing email data.

[1034] "User" refers to a general user who uses an email client, checks received emails, and receives security notifications.

[1035] An "emotion engine" is a technology that detects the user's current emotions from their facial expressions, voice, etc., and adjusts the system's operation based on that.

[1036] "Risk assessment result" refers to the final risk assessment result issued by the server after analyzing the email data.

[1037] "Terminal" refers to a computer device (smartphone, PC, tablet, etc.) that is directly operated by a user and that receives notification of risk assessment results.

[1038] "Notification means" refers to methods and techniques for informing users of risk assessment results, including alert messages, pop-up notifications, and audio notifications.

[1039] A "database" refers to a storage system that systematically stores specific data and allows it to be quickly searched, collated, and updated.

[1040] "Indicators of fraud" refer to abnormal behavior or content that differs from normal operations or data patterns, and may include phishing sites or malware.

[1041] The system for implementing this invention integrates email data reception, analysis, risk assessment, emotion recognition, and notification. The present invention exchanges data between a server and a terminal, provides security notifications to users in real time, and dynamically adjusts the content of notifications according to the user's emotional state.

[1042] System configuration

[1043] Server: A computer system that receives, analyzes, and assesses risk of data, and is equipped with generative AI with natural language processing technology. When specific email data is received, it analyzes the data and assesses the risk of fraud, phishing, malware, etc. It also incorporates user emotional data to dynamically adjust risk assessment and notifications.

[1044] Terminal: A computing device that is directly operated by the user and receives and displays emails using an email client application. The terminal is equipped with an emotion engine with emotion recognition capabilities, and detects the user's emotions in real time using a camera and microphone.

[1045] Program processing

[1046] Receiving emails and extracting data: When a user opens an email client application and receives a new email, the email data is stored on the device and its contents (body, subject, sender address, and included URLs) are extracted. This process is performed using the email client application and the device's storage.

[1047] Data analysis and risk assessment: The extracted email data is sent to a server where it is analyzed using natural language processing technology. A generative AI model is placed on the server to analyze the email body and detect anomalous patterns. In addition, the sender address and URL are compared with a database to assess signs of fraud. The risk assessment is classified as high, medium, or low risk based on the content of the message body, the sender, and the safety of the URL.

[1048] Emotion recognition and risk assessment adjustment: The emotion engine built into the device uses the camera and microphone to recognize the user's emotions in real time. The recognized emotion data is sent to the server and reflected in the risk assessment. For example, if the user is in an unstable emotional state, the server will make a more cautious risk assessment and display a strong warning message.

[1049] Notification of risk assessment results: The server sends the risk assessment results to the terminal and notifies the user based on the results. The terminal displays the risk assessment results and provides the user with information about the safety of the email. If the email is deemed high risk, a warning message is displayed, urging the user not to open the email.

[1050] Specific examples

[1051] Prompt Sentence Examples

[1052] 1. Phishing emails:

[1053] Subject: "Update your account information"

[1054] Body text: "Click the link below to update your account information."

[1055] From: "malicious@example.com"

[1056] URL: "http: / / phishing.example.com"

[1057] 2. Secure Work Email:

[1058] Subject: "Materials for the next meeting"

[1059] Body of text: "I have attached the materials to be used at the next meeting."

[1060] From: "trusted@workplace.com"

[1061] URL: "http: / / workplace.com / document"]

[1062] In this way, the present invention improves email security and the user experience through collaboration between the server and the terminal. In addition, by utilizing an emotion engine, flexible responses according to the user's emotional state become possible.

[1063] The flow of the specific processing in the application example 2 will be described with reference to FIG.

[1064] Step 1:

[1065] The device opens an email client application. The user receives a new email, and the email data (body, subject, sender address, and included URLs) is saved to the device's storage. The input is the email the user received, and the output is the saved email data.

[1066] Step 2:

[1067] The device extracts data such as the body, subject, sender address, and included URLs from the saved email data. This process is performed by an internal routine of the email client application. The input is the email data saved in step 1, and the output is the extracted email data (body, subject, sender address, and URL).

[1068] Step 3:

[1069] The terminal sends the extracted email data to the server. The server analyzes the received email data using natural language processing technology. The input is the extracted email data, and the output is the email data received by the server.

[1070] Step 4:

[1071] The server analyzes the email body received using a generative AI model to detect signs of fraud. In this case, the generative AI model (e.g., DistilBERT) analyzes the meaning of the sentence and determines whether it is a scam or phishing scam, such as "Click the link to update your account information." The input is the email body, and the output is a risk assessment as a result of the analysis.

[1072] Step 5:

[1073] The server checks the sender address of the email against a database to evaluate its trustworthiness. It determines the trustworthiness by checking against a list of trusted sender addresses (e.g., trusted_sources). The input is the sender address, and the output is the result of the trustworthiness evaluation.

[1074] Step 6:

[1075] The server extracts the URL from the email and compares it with a safety database. Furthermore, if necessary, it actually checks the URL's destination and evaluates it for signs of fraud. Specifically, it sends an HTTP request to the URL and obtains the analysis results. The input is the URL, and the output is the URL's safety evaluation result.

[1076] Step 7:

[1077] The server performs a risk assessment based on the email body, the reliability assessment of the sender address, and the safety assessment of the URL. The risk assessment is classified as high risk, medium risk, or low risk. The input is the analysis result up to the previous step, and the output is the risk assessment result.

[1078] Step 8:

[1079] The emotion engine built into the device uses a camera and microphone to detect emotions from the user's facial expressions and voice. Specifically, it analyzes camera footage and audio data in real time. The input is the user's facial expression and voice data, and the output is the emotion recognition results.

[1080] Step 9:

[1081] The server adaptively adjusts the risk assessment based on the emotion recognition results. For example, if the user is in an unstable emotional state, the risk assessment is adjusted to be more cautious. The inputs are the emotion recognition results and the risk assessment results, and the output is the adjusted risk assessment results.

[1082] Step 10:

[1083] The server sends the risk assessment result to the terminal, and the terminal notifies the user. If the risk is high, a warning message is displayed, urging the user not to open the email. The input is the adjusted risk assessment result, and the output is the notification message displayed to the user.

[1084] The specific processing unit 290 transmits the result of the specific processing to the smart glasses 214. In the smart glasses 214, the control unit 46A causes the speaker 240 to output the result of the specific processing. The microphone 238 acquires audio indicating a user input regarding the result of the specific processing. The control unit 46A transmits audio data indicating the user input acquired by the microphone 238 to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.

[1085] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[1086] In the above embodiment, an example in which the specific processing is performed by the data processing device 12 has been given, but the technology of the present disclosure is not limited to this, and the specific processing may be performed by the smart glasses 214.

[1087] [Third embodiment]

[1088] FIG. 5 shows an example of the configuration of a data processing system 310 according to the third embodiment.

[1089] 5, the data processing system 310 includes the data processing device 12 and a headset terminal 314. An example of the data processing device 12 is a server.

[1090] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[1091] The headset type terminal 314 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication I / F 44, and a display 343. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The microphone 238, the speaker 240, the camera 42, and the display 343 are also connected to the bus 52.

[1092] The microphone 238 receives instructions and the like from the user 20 by receiving voice uttered by the user 20. The microphone 238 captures the voice uttered by the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio in accordance with instructions from the processor 46.

[1093] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the surroundings of user 20 (for example, an imaging range defined by an angle of view equivalent to the field of vision of a typical healthy person).

[1094] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 are responsible for the exchange of various information between the processor 46 and the processor 28 via the network 54. The exchange of various information between the processor 46 and the processor 28 using the communication I / Fs 44 and 26 is carried out in a secure state.

[1095] Fig. 6 shows an example of the main functions of the data processing device 12 and the headset type terminal 314. As shown in Fig. 6, in the data processing device 12, a specific process is performed by the processor 28. A specific process program 56 is stored in the storage 32.

[1096] The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[1097] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[1098] In the headset type terminal 314, a reception output process is performed by the processor 46. A reception output program 60 is stored in the storage 50. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.

[1099] Next, a description will be given of the identification process performed by the identification processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as the "server" and the headset type terminal 314 will be referred to as the "terminal."

[1100] This invention relates to a system that receives email data, analyzes its contents, performs risk assessment, and notifies the user. Specifically, it uses generative AI to analyze the content of conversations and email text, and checks the destination sites of URLs.

[1101] System program and processing description

[1102] 1. Receiving emails

[1103] 1. The user receives an email

[1104] A user opens an email client application and receives new email, which is saved within the client application.

[1105] 2. The device extracts the email data

[1106] The device extracts the necessary information (body, subject, sender, URL, etc.) from the email data stored.

[1107] 2. Email Data Analysis

[1108] 3. The device sends the extracted data to the server

[1109] The extracted email data is sent to a server where a generative AI is placed and analyzes the data.

[1110] 4. The server analyzes the email content using natural language processing

[1111] AI on the server analyzes the email body using natural language processing technology. The purpose of the analysis is to detect signs of fraud, phishing, spam, etc. For example, if the email contains phrases such as "Please update your account information" or "Click the following link," it will determine that it is likely phishing.

[1112] 5. The server checks the sender

[1113] The server checks the sender address against a pre-registered database to assess its trustworthiness, and if it is a known scam or spam source, it is deemed high risk.

[1114] 3. URL Parsing

[1115] 6. The server extracts the URLs from the email

[1116] All URLs are extracted from the email body and the safety of each URL is evaluated.

[1117] 7. The server checks the URL against a secure database

[1118] The extracted URLs are checked against a pre-registered safe database, and if they are known phishing sites or sites hosting malware, they are rated as high risk.

[1119] 8. The server checks the URL destination

[1120] If necessary, the server will actually navigate to the URL and analyze the content of the site, and if it detects any signs of fraud, the risk level will be increased further.

[1121] 4. Risk Assessment and Notification

[1122] 9. The server performs a risk assessment

[1123] The server performs a comprehensive risk assessment based on the analysis of the email body and URLs, and the assessment is classified into three levels: high risk, medium risk, and low risk.

[1124] 10. The server sends the evaluation results to the device.

[1125] The risk assessment results are sent to the device, and include specific risk factors (e.g., "Possibly a phishing email" or "Contains a malicious URL").

[1126] 11. The device notifies the user

[1127] The device will notify the user based on the evaluation results. A warning message will be displayed for high-risk emails, urging the user not to open them. Trusted emails will also be notified that they are "safe."

[1128] Specific examples

[1129] Example 1: Receiving a phishing email

[1130] 1. The user receives a fraudulent email

[1131] The user receives an email with the subject "Your account has been suspended."

[1132] 2. The device analyzes the email and sends the data to the server

[1133] The email body and URL are extracted and sent to the server.

[1134] 3. The server analyzes the email and detects signs of phishing

[1135] The server's generative AI detects the phrase "Click the link below to update your account information."

[1136] Additionally, the sending address is verified as a known fraudulent address.

[1137] 4. The server parses the URL

[1138] The URL turns out to be a known phishing site.

[1139] 5. The server evaluates the risk as high and sends the result to the device.

[1140] The email is rated as high risk and a message is sent to the device saying, "This email may be phishing."

[1141] 6. The device displays a warning to the user

[1142] A warning message is displayed to the user.

[1143] Example 2: Receiving an important email from work

[1144] 1. A user receives an important email from work

[1145] A user receives an email titled "About the next meeting materials."

[1146] 2. The device analyzes the email and sends the data to the server

[1147] The email body and URL are extracted and sent to the server.

[1148] 3. The server analyzes the email and determines it is safe

[1149] The server's generative AI detects no abnormal patterns and verifies that the source address is trustworthy.

[1150] 4. The server parses the URL

[1151] The URL is confirmed to be the official workplace website.

[1152] 5. The server evaluates the risk as low and sends the result to the device.

[1153] It is evaluated as low risk and a message saying "This email is safe" is sent to the device.

[1154] 6. The device notifies the user

[1155] The user will see a notification that "This email is safe."

[1156] This allows users to quickly and accurately determine whether an email they receive is safe or poses a risk. This system can effectively respond to cyber threats that are constantly evolving, improving users' email security.

[1157] The processing flow will be explained below.

[1158] Step 1:

[1159] When a user receives an email, the device stores the email in the email client application in internal storage, along with metadata such as the email content, subject, sender address, and any URLs it contains.

[1160] Step 2:

[1161] The device extracts text data from the email data stored on the device. Specifically, it analyzes the email body, subject, and sender address and organizes it as structured data in a specific format.

[1162] Step 3:

[1163] The device then sends the extracted email data and URL information to the server, using an encrypted communication protocol to ensure security.

[1164] Step 4:

[1165] The server uses natural language processing technology to analyze the email data it receives. An AI model analyzes the email body and detects abnormal patterns and keywords that may indicate fraud or phishing. For example, phrases such as "update your account information" or "important notice" may indicate the possibility of phishing.

[1166] Step 5:

[1167] The server checks the sending address against a database containing known scam addresses and spam sources, and then rates the sending address as trustworthy or dangerous.

[1168] Step 6:

[1169] The server extracts all URLs from the email, detects URLs from the email body, and analyzes which sites each URL leads to.

[1170] Step 7:

[1171] The server checks the URL against a safety database, which contains information about known safe and dangerous sites. If the URL is a known phishing site or hosts malware, it is rated as high risk.

[1172] Step 8:

[1173] If necessary, the server will actually check the destination site of the URL. In this step, the server will access the URL and analyze its content. For example, it will check the page content to detect whether it contains malicious scripts or suspicious elements.

[1174] Step 9:

[1175] The server then assesses the risk of the email based on the analysis results. Risk is classified as high, medium, or low. For example, emails that are likely to be fraudulent or contain URLs that include phishing sites are assessed as high risk.

[1176] Step 10:

[1177] The server sends the risk assessment results to the device, including the type of risk and the reasons for it, in a format that is easy for the user to understand.

[1178] Step 11:

[1179] The device notifies the user based on the risk assessment results. For high-risk emails, a warning message is displayed on the screen, urging the user not to open the email. For trustworthy emails, the device notifies the user that "This email is safe."

[1180] Step 12:

[1181] The user is notified and is given a risk assessment to decide whether to open the email, delete it, or perform further safety checks.

[1182] These steps allow users to quickly and accurately understand the safety of the emails they receive, and by having the server and device work together, we can provide an unprecedentedly strong security environment.

[1183] Example 1

[1184] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."

[1185] In today's cyber environment, the threat of malicious emails such as phishing and spam is increasing, and users need a way to quickly and accurately determine whether the emails they receive are safe. However, existing email security measures are unable to fully analyze the risks of email content and URLs, potentially exposing users to serious risks. For this reason, a system is needed that performs advanced email content analysis and URL safety assessment, and provides accurate risk assessments and notifications to users in real time.

[1186] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.

[1187] In this invention, the server includes a means for comparing the sender address with a database to evaluate the reliability of the email, a means for extracting URLs from the email and comparing them with a safety database, and a means for checking the destination of the URL and evaluating signs of fraud. This makes it possible to evaluate the reliability of the email and the safety of the URL with high accuracy and quickly notify the user of the risk evaluation results.

[1188] "Mail Data" means digital information received and sent as email, including the body, subject, sender address, and associated metadata.

[1189] "Text data" refers to character string data in an analyzable format that includes the email body and related information.

[1190] A "server" is a computer system that provides services over a network, including hardware and software for data analysis and risk assessment.

[1191] "Natural language processing technology" is a general term for technologies that enable computers to understand, interpret, and generate human language.

[1192] "Risk assessment" is the process of assessing the degree of risk an email poses to the user based on the analyzed email, and the assessment results are classified as high risk, medium risk, or low risk.

[1193] "User" refers to the end user who uses this system to check the security of email.

[1194] A "database" is a software system for efficiently storing, managing, and retrieving data, including those in SQL or NoSQL formats.

[1195] A "safe database" is a database that holds information about known safe and dangerous URLs and domains.

[1196] A "headless browser" is a browser without a GUI, used for automation scripts and system testing.

[1197] A "generative AI model" is an artificial intelligence model that learns large amounts of data and generates and analyzes natural language, and is particularly used for natural language processing.

[1198] An "HTTP request" is a protocol request for exchanging information between a client and a server, typically a GET or POST request.

[1199] "Real-time threat intelligence" refers to the latest information on current security threats and attack patterns, which is used to update risk assessments.

[1200] This invention relates to a system that receives email data, analyzes its contents, performs risk assessment, and notifies the user. Specifically, it uses a generative AI model to analyze the contents of emails using natural language processing technology and checks the destination URLs.

[1201] First, the user receives an email using an email client application. The received email is saved on the device. The device then extracts the email body, subject, sender address, and all URLs in the email body from the saved data. This process uses the Python email package and regular expressions (Regex).

[1202] Next, the device sends the extracted email data to a server using an HTTP request (e.g., a POST request). A generative AI model (e.g., GPT-3) is placed on the server, and this AI model analyzes the email body using natural language processing (NLU). Specifically, it detects phrases that indicate a fraudulent email, such as "Please update your account information."

[1203] Additionally, the server compares the sender address of the email with a database (SQL or NoSQL database) to assess its trustworthiness. If it is a sender address of a known fraudulent email, it is assessed as high risk. Next, the server extracts all URLs from the email body and compares them with a safe database (e.g., Google Safe Browsing API). This assesses whether they are phishing sites or malware hosting sites.

[1204] In addition to this evaluation, the server will actually check the URL destination using a headless browser (for example, Selenium with ChromeDriver) and analyze the content of the site. If there are any signs of fraud or harmful scripts, the risk level will be raised further.

[1205] Once the risk assessment is complete, the server sends the results to the device. The assessment results include detailed information about specific risk factors (for example, "possibly a phishing email" or "contains a malicious URL"). The device uses this information to provide appropriate notifications to the user. For high-risk emails, a warning message is displayed, urging the user not to open the email. For trustworthy emails, the device notifies the user that the email is "safe."

[1206] As a concrete example, if a user receives a phishing email with the title "Your account has been suspended," the device extracts the email's text and URL and sends them to the server. The server's generative AI model detects the phrase "Click the link below to update your account information" and confirms that the sender address is a known scam address. If the URL is determined to be a phishing site, it is rated as high risk and the result is sent to the device. Finally, the device displays a warning to the user saying, "This email may be phishing."

[1207] This system is designed to effectively respond to ever-evolving cyber threats and improve users' email security. It also updates risk assessments based on threat information collected in real time, enabling rapid response to the latest security situations.

[1208] The flow of the identification process in the first embodiment will be described with reference to FIG.

[1209] Step 1: User receives email

[1210] Input: A user receives an email.

[1211] What it does: Opens an email client application (e.g., Gmail, Outlook) and receives a new email.

[1212] Output: Received emails are saved on the device.

[1213] What happens: When a user opens their email client, new emails are downloaded from the server and displayed within the email application.

[1214] Step 2: Your device extracts the email data

[1215] Input: Received email data.

[1216] How it works: Extracts the body, subject, sender address, and all URLs in the body from saved email data. It uses the Python email package and regular expressions (Regex).

[1217] Output: A list of extracted email bodies, subjects, sender addresses, and URLs.

[1218] What it does: The program analyzes the received email data and extracts important information.

[1219] Step 3: The device sends the extracted data to the server

[1220] Input: A list of extracted email bodies, subjects, sender addresses, and URLs.

[1221] What it does: Sends the extracted data to the server using an HTTP request (e.g., a POST request).

[1222] Output: The email data received by the server.

[1223] Specific operation: The device makes an HTTP request and sends data to the server endpoint.

[1224] Step 4: The server analyzes the email content using natural language processing

[1225] Input: The email body sent from the device.

[1226] How it works: It uses generative AI models (e.g., GPT-3) to analyze email content and detect signs of fraud and phishing. It uses natural language processing libraries like NLTK and SpaCy.

[1227] Output: Analysis results, information on indicators of fraud and phishing.

[1228] Specific operation: The server tokenizes the email content and analyzes specific keywords and context to extract dangerous phrases.

[1229] Step 5: The server checks the source

[1230] Input: The source address sent from the device.

[1231] How it works: The source address is checked against a database (e.g., an SQL or NoSQL database) to assess its trustworthiness.

[1232] Output: The reliability evaluation result of the source address.

[1233] What it does: Runs a database query to match the email against a list of known fraudulent email senders.

[1234] Step 6: The server extracts the URLs in the email

[1235] Input: The email body sent from the device.

[1236] What it does: Extracts all URLs from the email body using regular expressions (Regex).

[1237] Output: A list of extracted URLs.

[1238] What it does: Identify and list all possible URL patterns within the email body.

[1239] Step 7: Server checks URL against safety database

[1240] Input: The extracted URL list.

[1241] How it works: Each URL is checked against a safety database (e.g., Google Safe Browsing API) to assess whether it is a phishing or malware-hosting site.

[1242] Output: Safety assessment results for each URL.

[1243] What it does: It uses HTTP requests to check against a safety database to determine the risk level of the URL.

[1244] Step 8: The server checks the URL destination

[1245] Input: The extracted URL list.

[1246] What it does: Uses a headless browser (e.g. Selenium with ChromeDriver) to navigate to a URL and analyze the content of that site.

[1247] Output: Analysis results of the destination site, information on indicators of fraud.

[1248] What it does: It automatically manipulates the browser to access URLs and analyzes the page content to detect dangerous scripts and content.

[1249] Step 9: Server performs risk assessment

[1250] Input: Email body, sender address, and URL analysis results.

[1251] How it works: The results of these analyses are combined to give the email a risk rating, which is then categorized as high, medium, or low risk.

[1252] Output: Risk assessment results.

[1253] Specific operation: Integrates analysis results and performs comprehensive risk assessment based on pre-defined rules and models.

[1254] Step 10: The server sends the evaluation results to the device.

[1255] Input: Risk assessment results.

[1256] Operation: The evaluation result is sent to the terminal as an HTTP response.

[1257] Output: The evaluation results sent to the device.

[1258] Specific behavior: Create an HTTP response and send it along with the evaluation result.

[1259] Step 11: The device notifies the user

[1260] Input: The risk assessment result sent from the server.

[1261] Behavior: Notifies the user based on the evaluation results. High-risk emails are warned, and trusted emails are told "safe."

[1262] Output: Notification to the user.

[1263] Specific operation: The terminal displays an appropriate message on the user interface based on the evaluation results.

[1264] (Application example 1)

[1265] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."

[1266] In recent years, the spread of phishing attacks and malware via email has been increasing, increasing the risk of users suffering serious damage. For this reason, there is a need for a system that automatically analyzes the content of emails when they are received, evaluates potential risks, and notifies users. Conventional systems often perform insufficient email analysis or are slow to notify users of risks, so technology is needed to enable rapid and accurate risk assessment and notification.

[1267] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.

[1268] In this invention, the server includes means for acquiring email data, means for converting the acquired email data into text data, means for transmitting the text data to the server and analyzing it using natural language processing technology on the server side, means for performing a risk assessment of the email based on the analysis result, means for transmitting the risk assessment result to the client device and notifying the user, means for providing the user with specific factors of the risk assessment along with the notification, means for comparing the sender address with a database to evaluate the reliability of the email, means for extracting URLs from the email and comparing them with a safety database, means for actually checking the destination of the URLs and evaluating signs of fraud, means for classifying the email as high risk, medium risk, or low risk based on the risk assessment result, means for updating the risk assessment based on threat information collected in real time, means for displaying an immediate warning to the user based on the risk assessment, and means for providing detailed information simultaneously with the display of the warning message. This enables rapid and accurate risk assessment and notification to the user upon receipt of email.

[1269] "Email data" refers to the entire content of an email received by a user, including the subject, sender address, body, attachments, URLs, etc.

[1270] "Means of acquisition" refers to the technology or devices used to receive email and extract its contents.

[1271] "Text data" refers to the content of an e-mail, etc., converted into data in an analyzable format.

[1272] "Server" refers to the central system for analyzing email data and conducting risk assessments.

[1273] "Natural language processing technology" refers to technology for analyzing human language and understanding and processing its meaning and structure.

[1274] "Means for analyzing" refers to technology or devices for analyzing the content of email using natural language processing technology.

[1275] "Risk assessment" refers to determining whether an email is dangerous to the user based on the information contained in the email.

[1276] A "client device" is a device that a user directly uses, and includes a smartphone, tablet, computer, etc.

[1277] "Means of notification" refers to the technology or device used to notify users of the results of the risk assessment.

[1278] "Specific factors" refers to the individual factors or information provided to elaborate on the results of a risk assessment.

[1279] A "safe database" refers to a database that stores known safe URLs and reliable information.

[1280] "Indicators of fraud" refer to evidence or patterns that indicate possible malicious activity, such as phishing sites or malware.

[1281] "High risk, medium risk, low risk" are classifications of different levels of potential danger for email.

[1282] "Threat intelligence" refers to information about the latest threats and attack methods, including data collected in real time.

[1283] A "warning message" refers to a message that displays warning information to notify the user of a danger.

[1284] "Detailed information" refers to information provided to the user, including background and specific explanations of the risk assessment.

[1285] In order to put the present invention into practice, it is necessary to build a system that acquires email data, analyzes it, performs risk assessment, and notifies the user.

[1286] The system uses the following hardware and software:

[1287] Hardware

[1288] server

[1289] Client devices (smartphones, tablets, computers)

[1290] software

[1291] Email client applications

[1292] Natural language processing libraries (e.g. NLTK, SpaCy)

[1293] Generative AI models (e.g., OpenAI's GPT-3)

[1294] Security databases (e.g., lists of known phishing sites)

[1295] Database systems (e.g. PostgreSQL, MongoDB)

[1296] Server platform (e.g. AWS, GCP, Azure)

[1297] The server first obtains the email data received by the user. The obtained email data is converted into text data. The server receives the text data and analyzes it using natural language processing technology. Based on the analysis results, a risk assessment of the email is performed.

[1298] For risk assessment, the server uses the following methods:

[1299] 1. Check the sender address against a database to assess the authenticity of the email.

[1300] 2. Extract URLs from emails and check them against a secure database.

[1301] 3. Check the destination of the URL and evaluate for signs of fraud.

[1302] The risk assessment results are classified as high risk, medium risk, or low risk, and the results are sent to the client device, which receives the results and notifies the user, including the specific risk factors.

[1303] For example, the following prompt sentences are sent to the generative AI model for analysis:

[1304] Please analyze the body of the following email and assess it for signs of phishing:

[1305] ---

[1306] Subject: Your account has been suspended

[1307] Body: "Your account has been suspended due to unauthorized access. Please click the link below to update your account information: http: / / example.com / phishing"

[1308] From: "support@example.com"

[1309] Classify your results as "high risk," "medium risk," or "low risk," and explain why.

[1310] The generative AI model analyzes the email body based on this prompt and returns the analysis results to the server. Based on the results, the email is assessed for risk and notified to the user.

[1311] For example, if a user receives an email with the subject line "Your account has been suspended," the server analyzes the email and detects signs of phishing. As a result, the user is warned that "This email may be phishing" and is provided with more information.

[1312] As described above, the present invention automates the process of risk assessment and user notification when an email is received, thereby realizing accurate security measures in real time.

[1313] The flow of the specific processing in the application example 1 will be described with reference to FIG.

[1314] Step 1:

[1315] The terminal acquires the email data received by the user. It parses the new email data received through the email client application into necessary elements such as subject, sender address, body, attachments, and URLs. The acquired data becomes the input for the next processing step.

[1316] Step 2:

[1317] The terminal converts the acquired email data into text data. The text data is then formatted into an analyzable format and sent to the server. In this data conversion process, the email body and URL are unified into a string format.

[1318] Step 3:

[1319] The server receives the received text data and analyzes the email content using natural language processing technology. The input for analysis is the text data and extracted URLs. During the analysis process, a generative AI model (e.g., GPT-3) is used to identify signs of phishing and anomalous expressions in the text. The output is the analysis results.

[1320] Step 4:

[1321] The server performs a risk assessment based on the analysis results. The input is the analysis results obtained in step 3. The server compares the sender address with a database to assess its trustworthiness, and compares the URL in the email with a safety database. Furthermore, if necessary, it actually checks the destination of the URL and assesses signs of fraud. This classifies the risk level of the email into three categories: high risk, medium risk, and low risk. This risk assessment is the output.

[1322] Step 5:

[1323] The server sends the risk assessment result to the client device. The input is the risk assessment result, and the output is a notification message sent to the client device. The notification message includes the risk level and specific factors (e.g., the likelihood of phishing or the presence of a malicious URL).

[1324] Step 6:

[1325] The terminal displays a notification to the user based on the evaluation results. The input is the received notification message, and the output is a warning message or detailed information presented to the user. This allows the user to immediately recognize the safety of their email and take any necessary action.

[1326] The above processing steps enable rapid and accurate risk assessment and user notification upon receipt of email.

[1327] Furthermore, an emotion engine that estimates the user's emotion may be further combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59, and perform identification processing using the user's emotion.

[1328] This invention relates to a system that receives email data, analyzes its contents, performs risk assessment, and notifies the user. It also combines an emotion engine that recognizes the user's emotions and dynamically adjusts the risk assessment and notification method accordingly.

[1329] System program and processing description

[1330] 1. Receiving emails and extracting data

[1331] 1. The user receives an email

[1332] A user opens an email client application and receives a new email, which is then saved in the device's storage.

[1333] 2. The device extracts the email data

[1334] The device extracts the body of the email, subject, sender address, and any URLs contained in it from the email data stored on the device.

[1335] 2. Email Data Analysis

[1336] 3. The device sends the extracted data to the server

[1337] The extracted email data is sent to a server, where a generative AI with natural language processing technology is placed to analyze the data.

[1338] 4. The server analyzes the email content using natural language processing

[1339] The server's AI analyzes the email body and detects abnormal patterns that may indicate fraud or phishing, such as the phrase "Click on the link to update your account information."

[1340] 5. The server checks the sender

[1341] The server checks the email sender address against a secure database to assess its trustworthiness. If it's a known fraudulent sender on the list, it's rated as high risk.

[1342] 3. URL Parsing

[1343] 6. The server extracts the URLs from the email

[1344] The server extracts URLs from the email body and analyzes which sites each URL leads to.

[1345] 7. The server checks the URL against a secure database

[1346] It checks the URL against a database and warns you if it is a known phishing site or a dangerous site.

[1347] 8. The server actually checks the URL destination if necessary

[1348] The server actually accesses the URL and analyzes its contents to check whether it contains any invalid elements.

[1349] 4. Risk Assessment and Notification

[1350] 9. The server performs a risk assessment

[1351] The server performs a risk assessment based on the analysis of the email body and URL, and classifies the risk as high, medium, or low.

[1352] 10. The server sends the evaluation results to the device.

[1353] The risk assessment results are sent to the device, along with detailed reasons for the assessment.

[1354] 11. The device notifies the user

[1355] The device will notify the user based on the risk assessment results. If the email is high risk, a warning message will be displayed, urging the user not to open the email. If the email is trustworthy, the device will notify the user that it is "safe."

[1356] 5. Emotion engine integration

[1357] 12. The device will recognize the user's emotions

[1358] The emotion engine built into the device uses a camera and microphone to detect emotions from the user's facial expressions and voice, and the emotion data is analyzed in real time.

[1359] 13. The server analyzes the emotional data and reflects it in risk assessment

[1360] The server can then use emotional data to provide flexibility in risk assessment, for example, making a more conservative risk assessment if the user is in an unstable emotional state.

[1361] 14. The server selects the notification method according to the emotion

[1362] The server adjusts the notification method depending on the detected emotion, for example, displaying a strong warning message if the user is unstable, and a light warning if the user is stable.

[1363] Specific examples

[1364] Example 1: A user receives a phishing email

[1365] 1. A user receives a phishing email

[1366] A user receives a phishing email with the subject "Your account information has been suspended."

[1367] 2. The device extracts the email data and sends it to the server

[1368] The email body, subject, sender, and URL are extracted and sent to the server.

[1369] 3. The server detects signs of fraud

[1370] The server's AI analyzes the email content to detect signs of fraud and also checks that the sender is on a fraud list.

[1371] 4. The server analyzes the URL and checks if it is a phishing site

[1372] Verify that the URL matches a known phishing site and also contains malicious scripts.

[1373] 5. The server evaluates the risk as high and sends the result to the device.

[1374] The server evaluates the email as high risk and sends the result to the device.

[1375] 6. Emotion engine detects user's unstable emotions

[1376] The emotion engine detects when a user expresses uneasy emotions about a phishing email.

[1377] 7. The server displays a strong warning

[1378] The server displays a strong warning message on the terminal based on the user's emotional state.

[1379] Example 2: Receiving important emails from work and checking safety

[1380] 1. A user receives an important email from work

[1381] A user receives a secure email with the subject "Next Meeting Materials."

[1382] 2. The device extracts the email data and sends it to the server

[1383] The email body and URL are extracted and sent to the server.

[1384] 3. The server performs analysis and does not detect any abnormalities.

[1385] The server's AI analyzes the email content and verifies that there are no abnormal patterns.

[1386] 4. The server analyzes the URL and verifies that it is a secure site.

[1387] The URL is confirmed to be the official workplace website.

[1388] 5. The server evaluates the risk as low and sends the result to the device.

[1389] The email is assessed as low risk and the result is sent to the device.

[1390] 6. The emotion engine detects the user's calm emotion

[1391] The emotion engine ensures that the user is in a normal emotional state.

[1392] 7. Server displays a light notification

[1393] The server responds to the user's sentiment and displays a simple notification saying, "This email is safe."

[1394] As described above, the present invention goes beyond the conventional technology of analyzing email content and assessing risk by providing a system that dynamically adjusts risk assessment and notification methods taking into account the user's emotional state, allowing users to receive flexible support tailored to their emotions while improving email security.

[1395] The processing flow will be explained below.

[1396] Step 1:

[1397] When a user receives an email, the device stores the email in the email client application in internal storage, along with metadata such as the email content, subject, sender address, and any URLs it contains.

[1398] Step 2:

[1399] The device extracts text data from the email data stored on the device. Specifically, it analyzes the email body, subject, and sender address and organizes it as structured data in a specific format.

[1400] Step 3:

[1401] The device sends the extracted email data and URL information to the server, using an encrypted communication protocol to ensure security.

[1402] Step 4:

[1403] The server uses natural language processing technology to analyze the email data it receives. An AI model analyzes the email body and detects abnormal patterns and keywords that may indicate fraud or phishing. For example, phrases such as "update your account information" or "important notice" may indicate the possibility of phishing.

[1404] Step 5:

[1405] The server checks the sending address against a database containing known scam addresses and spam sources, and then rates the sending address as trustworthy or risky.

[1406] Step 6:

[1407] The server extracts all URLs from the email, detects URLs from the email body, and analyzes which sites each URL leads to.

[1408] Step 7:

[1409] The server checks the URL against a safety database, which contains information about known safe and dangerous sites. If the URL is a known phishing site or hosts malware, it is rated as high risk.

[1410] Step 8:

[1411] If necessary, the server will actually check the destination site of the URL. In this step, the server will access the URL and analyze its content. For example, it will check the page content to detect whether it contains malicious scripts or suspicious elements.

[1412] Step 9:

[1413] The server then assesses the risk of the email based on the analysis results. Risk is classified as high, medium, or low. For example, emails that are likely to be fraudulent or contain URLs that include phishing sites are assessed as high risk.

[1414] Step 10:

[1415] The server sends the risk assessment results to the device, including the type of risk and the reasons for it, in a format that is easy for the user to understand.

[1416] Step 11:

[1417] The device notifies the user based on the risk assessment results. For high-risk emails, a warning message is displayed on the screen, urging the user not to open the email. For trustworthy emails, the device notifies the user that "This email is safe."

[1418] Step 12:

[1419] The device recognizes the user's emotions. The emotion engine built into the device uses the camera and microphone to detect emotions from the user's facial expressions and voice. Emotional data is analyzed in real time.

[1420] Step 13:

[1421] The server analyzes the emotional data and reflects it in the risk assessment. The server makes the risk assessment flexible based on the emotional data. For example, if the user is in an unstable emotional state, the server makes a more cautious risk assessment.

[1422] Step 14:

[1423] The server selects the notification method according to the emotion. The server adjusts the notification method according to the emotion detected. For example, if the user is in an unstable state, a strong warning message is displayed, and conversely, if the user is stable, a light warning is displayed.

[1424] Step 15:

[1425] The user is notified and can decide whether to open the email, delete it, or conduct further safety checks based on the risk assessment provided. This process allows the user to quickly and accurately understand the safety of the email they received, and also provides appropriate support based on their emotional state.

[1426] Example 2

[1427] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."

[1428] While conventional email risk assessment systems are technically effective, such as by analyzing email text and checking sender addresses, they ignore the user's emotional state and do not take into account the user's mental burden. Furthermore, because the risk notification method is uniform, they have the problem of being unable to respond adequately in situations where flexible responses according to the user's state are required.

[1429] The specific processing by the specific processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means.

[1430] In this invention, the server includes means for analyzing email data, means for verifying sender addresses and URLs, and means for adjusting risk assessment and notification methods based on user emotional data, thereby enabling flexible risk assessment and notification according to the user's emotional state.

[1431] "Email data" refers to all data received as the content of an email, including the body of the email, the subject line, the sender's address, and URLs.

[1432] "Text data" refers to character information extracted from email data, such as the body of the email and the subject line that are the subject of analysis.

[1433] "Server" refers to a computer system for analyzing email data, assessing risk, and processing emotional data.

[1434] "Natural language processing technology" refers to technology that allows computers to understand, interpret, and generate human language, and is used as a means of detecting signs of fraud in email text.

[1435] "Risk assessment" refers to the process of assessing the degree of risk an email poses based on the content of the analyzed email data, the sender address, and the safety of the URL.

[1436] "Notification" refers to the act of communicating the results of a risk assessment to the user, including warning messages and safety notifications.

[1437] An "emotion engine" is a system that uses a camera or microphone to recognize a user's emotions, analyzes the data, and reflects it in risk assessments and notification methods.

[1438] A "safe database" is a database containing information such as known fraudulent sites and unsafe source addresses, and is used to match URLs and source addresses.

[1439] "Real-time" refers to the timing in which data is processed and analyzed the moment it is generated, meaning that results are reflected immediately.

[1440] "Threat information" means information that indicates potential dangers to networks and systems, including data on malware, phishing sites, and fraudulent activities.

[1441] This invention relates to a system that receives email data, analyzes its contents, performs risk assessment, and notifies the user. It also combines an emotion engine that recognizes the user's emotions and dynamically adjusts the risk assessment and notification method accordingly.

[1442] Hardware and software used

[1443] This system is primarily comprised of terminals and servers. An email client application (e.g., commonly referred to as an "email client") is installed on the terminal, which receives and manages email data. The server is equipped with a generative AI model (e.g., natural language processing technology such as OpenAI GPT-3) that analyzes email data and assesses risk. In addition, an emotion engine (e.g., Microsoft Azure's emotion recognition API) is used to analyze user emotions.

[1444] Data processing and calculation

[1445] 1. Email reception and data extraction

[1446] The user opens an email client and receives a new email. The email data is stored in the device's storage.

[1447] The device extracts the body, subject, sender address, and URL from the email data stored on the device. This process is performed using a Python email parser library.

[1448] 2. Email Data Analysis

[1449] The terminal sends the extracted email data to the server, where it is converted into JSON format and sent via the HTTPS protocol.

[1450] The server-generated AI model analyzes the email body and detects signs of fraud or phishing.

[1451] The server checks the sender address against a safety database (e.g., Spamhaus or PhishTank) to assess trustworthiness.

[1452] 3. URL Parsing

[1453] The server extracts the URL from the email body and checks its safety against a safety database (e.g., Google Safe Browsing API).

[1454] If necessary, the server will actually visit the URL and scrape the website content to detect malicious scripts.

[1455] 4. Risk Assessment and Notification

[1456] The server performs a risk assessment based on the analysis of the email body, sender, and URL, and classifies the email as high risk, medium risk, or low risk.

[1457] The evaluation results are sent to the device in JSON format, and the device notifies the user. If the risk is high, a warning message is displayed, and if the risk is low, a message stating "it's safe" is displayed.

[1458] 5. Emotion engine integration

[1459] The emotion engine built into the device uses the camera and microphone to analyze the user's emotions in real time.

[1460] The server dynamically adjusts risk assessment and notification methods based on emotional data, displaying a strong warning if the user is in an unstable state and a light warning if the user is in a stable state.

[1461] Specific examples

[1462] Example 1: Detecting phishing emails and notifying users

[1463] 1. The user receives a phishing email with the subject "Your account information has been suspended."

[1464] 2. The device extracts the email data and sends it to the server.

[1465] 3. The server's generative AI model detects signs of fraud and verifies that the sender is on the fraud list.

[1466] 4. The server parses the URL and verifies that it matches a phishing site.

[1467] 5. Evaluate it as high risk and send the result to the device.

[1468] 6. The emotion engine detects the user's unstable emotions and displays a strong warning message.

[1469] Example 2: Checking important emails from work

[1470] 1. A user receives a secure email with the subject "Next Meeting Materials."

[1471] 2. The device extracts the email data and sends it to the server.

[1472] 3. The server-generated AI model analyzes the email content and verifies that there are no abnormal patterns.

[1473] 4. The server parses the URL and verifies that it is a secure site.

[1474] 5. Evaluate it as low risk and send the result to the device.

[1475] 6. The emotion engine checks the user's stable emotions and displays a gentle notification saying, "This email is safe."

[1476] Examples of prompt statements

[1477] Phishing email risk assessment prompt:

[1478] Analyze the body of the following emails for signs of fraud and categorize them as high, medium, or low risk.

[1479] Email body: "Your account information has been suspended. Click the link below to update it: http: / / example.com"

[1480] Prompts that adjust notification methods based on the user's emotions:

[1481] Based on the following emotional data, select the appropriate notification method according to the risk assessment results: If the user is unstable, give a strong warning, and if the user is stable, give a light warning.

[1482] Emotion data: { "emotion": "anxious", "confidence": 0.85}

[1483] The above is an embodiment of the present invention. This system allows users to enhance email security and receive flexible support according to their emotions.

[1484] The flow of the identification process in the second embodiment will be described with reference to FIG.

[1485] Step 1:

[1486] The user receives the email.

[1487] Input: Data from the mail server, including emails

[1488] What happens: The user opens their email client and receives a new email.

[1489] Output: Email data stored in the device's storage (body, subject, sender address, URL, etc.)

[1490] Step 2:

[1491] The device extracts the email data.

[1492] Input: Email data stored in the device's storage

[1493] What it does: The device uses a Python email parser library (e.g., the email package) to extract the body, subject, sender address, and URL from the email data stored on the device.

[1494] Output: Extracted text data (body, subject, sender address, URL)

[1495] Step 3:

[1496] The terminal transmits the extracted data to the server.

[1497] Input: Extracted text data

[1498] Specific operation: The terminal converts the extracted email data into JSON format and sends it to the server using the HTTPS protocol.

[1499] Output: Text data sent to the server

[1500] Step 4:

[1501] The server analyzes the email content using natural language processing.

[1502] Input: Text data sent to the server

[1503] How it works: The server-generated AI model analyzes the body of received emails and detects anomalous patterns that may indicate fraud or phishing, such as the phrase "Click on the link to update your account information."

[1504] Output: Analysis results (presence or absence of signs of fraud, detection of abnormal patterns)

[1505] Step 5:

[1506] The server verifies the sender.

[1507] Input: Source address and analysis result from the previous step

[1508] What it does: The server checks the sender address of the email against a secure database (e.g., Spamhaus or PhishTank) to assess its trustworthiness. If it is a known fraudulent sender, it is rated as high risk.

[1509] Output: Sender evaluation result (sender reliability evaluation)

[1510] Step 6:

[1511] The server extracts the URLs in the email.

[1512] Input: Email body

[1513] Specific operation: The server uses regular expressions to extract URLs from the email body and stores them in a list.

[1514] Output: Extracted URL list

[1515] Step 7:

[1516] The server checks the URL against a secure database.

[1517] Input: Extracted URL list

[1518] How it works: The server checks the URL against a safety database (e.g., Google Safe Browsing API) to verify its safety. If the site is fraudulent, it immediately issues a warning.

[1519] Output: URL safety assessment results

[1520] Step 8:

[1521] The server will actually check the URL destination if necessary.

[1522] Input: Suspected dangerous URL

[1523] Specific operation: The server actually accesses the URL and uses BeautifulSoup or Selenium to scrape the HTML content of the destination website to detect whether or not there is any malicious script.

[1524] Output: URL check result (whether malicious script is included or not)

[1525] Step 9:

[1526] The server performs the risk assessment.

[1527] Input: Email body analysis results, sender evaluation results, URL evaluation results

[1528] Specific operation: The server evaluates these results comprehensively and calculates a risk score, which is then classified as high risk, medium risk, or low risk.

[1529] Output: Risk assessment results (risk score and classification)

[1530] Step 10:

[1531] The server transmits the evaluation results to the terminal.

[1532] Input: Risk assessment results

[1533] Specific operation: The server converts the risk assessment results and detailed assessment reasons into JSON format and sends them to the terminal using the HTTPS protocol.

[1534] Output: Risk assessment results sent to the device

[1535] Step 11:

[1536] The terminal notifies the user.

[1537] Input: Risk assessment results

[1538] Specific operation: Based on the risk assessment results received by the device, the notification API is used to notify the user. If the risk is high, a warning message will be displayed in a pop-up window stating "This is a high-risk email. Do not open it."

[1539] Output: User notification (warning message)

[1540] Step 12:

[1541] The device recognizes the user's emotions.

[1542] Input: User facial and voice data

[1543] Specific operation: The emotion engine (e.g., emotion recognition API) built into the device uses the camera and microphone to analyze the user's facial expressions and voice in real time.

[1544] Output: Parsed emotion data

[1545] Step 13:

[1546] The server analyzes the emotional data and reflects it in risk assessment.

[1547] Input: Emotion data and risk assessment results

[1548] Specific operation: The server flexibly adjusts the risk assessment based on the analyzed emotional data. For example, if the user is in an unstable emotional state, the risk score will be adjusted upward.

[1549] Output: Adjusted risk assessment results

[1550] Step 14:

[1551] The server selects the notification method according to the emotion.

[1552] Input: Adjusted risk assessment results and sentiment data

[1553] Specific operation: The server selects the notification method based on the detected emotion. For example, if the user is unstable, a strong warning message is displayed, and conversely, if the user is stable, a light warning is displayed.

[1554] Output: Emotion-based notification (strong or mild warning message)

[1555] (Application example 2)

[1556] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."

[1557] Conventional email security systems analyze received email data to perform risk assessment, but are indifferent to the user's emotional state, resulting in a lack of accuracy and flexibility in risk assessment and notification. Furthermore, to address the increase in fraudulent emails, including phishing and scams, real-time risk assessment and advanced warning systems are necessary, but the current situation is one in which these are not fully realized. Therefore, there is a need for a method of personalized risk assessment notification that responds to the user's emotional state.

[1558] The identification process by the identification processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means. In this invention, the server includes means for receiving email data, means for converting the received email data into text data, means for transmitting the text data to the server and analyzing it using natural language processing technology on the server side, means for assessing the risk of the email based on the analysis results, means for recognizing the user's emotions, means for adaptively adjusting the risk assessment based on the detection results of the emotion engine, and means for transmitting the risk assessment results to the terminal and notifying the user. This enables dynamic and flexible risk assessment and notification according to the user's emotional state. Furthermore, by updating the risk assessment based on threat information collected in real time and displaying a strong warning if the user is in an unstable emotional state, more effective and personalized security measures are realized.

[1559] "Email data" refers to the content and metadata of an email, including the body, subject, sender address, URL, etc.

[1560] A "server" refers to a computer system that performs processes such as receiving, transmitting, analyzing, and storing data on a network.

[1561] "Natural language processing technology" refers to technology that mechanically analyzes, understands, and generates human language, and analyzes email text and other text data to extract meaning.

[1562] "Risk assessment" refers to the process of determining whether an email contains risks such as phishing, fraud, or malware based on the results of analyzing email data.

[1563] "User" refers to a general user who uses an email client, checks received emails, and receives security notifications.

[1564] An "emotion engine" is a technology that detects the user's current emotions from their facial expressions, voice, etc., and adjusts the system's operation based on that.

[1565] "Risk assessment result" refers to the final risk assessment result issued by the server after analyzing the email data.

[1566] "Terminal" refers to a computer device (smartphone, PC, tablet, etc.) that is directly operated by a user and that receives notification of risk assessment results.

[1567] "Notification means" refers to methods and techniques for informing users of risk assessment results, including alert messages, pop-up notifications, and audio notifications.

[1568] A "database" refers to a storage system that systematically stores specific data and allows it to be quickly searched, collated, and updated.

[1569] "Indicators of fraud" refer to abnormal behavior or content that differs from normal operations or data patterns, and may include phishing sites or malware.

[1570] The system for implementing this invention integrates email data reception, analysis, risk assessment, emotion recognition, and notification. The present invention exchanges data between a server and a terminal, provides security notifications to users in real time, and dynamically adjusts the content of notifications according to the user's emotional state.

[1571] System configuration

[1572] Server: A computer system that receives, analyzes, and assesses risk of data, and is equipped with generative AI with natural language processing technology. When specific email data is received, it analyzes the data and assesses the risk of fraud, phishing, malware, etc. It also incorporates user emotional data to dynamically adjust risk assessment and notifications.

[1573] Terminal: A computing device that is directly operated by the user and receives and displays emails using an email client application. The terminal is equipped with an emotion engine with emotion recognition capabilities, and detects the user's emotions in real time using a camera and microphone.

[1574] Program processing

[1575] Receiving emails and extracting data: When a user opens an email client application and receives a new email, the email data is stored on the device and its contents (body, subject, sender address, and included URLs) are extracted. This process is performed using the email client application and the device's storage.

[1576] Data analysis and risk assessment: The extracted email data is sent to a server where it is analyzed using natural language processing technology. A generative AI model is placed on the server to analyze the email body and detect anomalous patterns. In addition, the sender address and URL are compared with a database to assess signs of fraud. The risk assessment is classified as high, medium, or low risk based on the content of the message body, the sender, and the safety of the URL.

[1577] Emotion recognition and risk assessment adjustment: The emotion engine built into the device uses the camera and microphone to recognize the user's emotions in real time. The recognized emotion data is sent to the server and reflected in the risk assessment. For example, if the user is in an unstable emotional state, the server will make a more cautious risk assessment and display a strong warning message.

[1578] Notification of risk assessment results: The server sends the risk assessment results to the terminal and notifies the user based on the results. The terminal displays the risk assessment results and provides the user with information about the safety of the email. If the email is deemed high risk, a warning message is displayed, urging the user not to open the email.

[1579] Specific examples

[1580] Prompt Sentence Examples

[1581] 1. Phishing emails:

[1582] Subject: "Update your account information"

[1583] Body text: "Click the link below to update your account information."

[1584] From: "malicious@example.com"

[1585] URL: "http: / / phishing.example.com"

[1586] 2. Secure Work Email:

[1587] Subject: "Materials for the next meeting"

[1588] Body of text: "I have attached the materials to be used at the next meeting."

[1589] From: "trusted@workplace.com"

[1590] URL: "http: / / workplace.com / document"]

[1591] In this way, the present invention improves email security and the user experience through collaboration between the server and the terminal. In addition, by utilizing an emotion engine, flexible responses according to the user's emotional state become possible.

[1592] The flow of the specific processing in the application example 2 will be described with reference to FIG.

[1593] Step 1:

[1594] The device opens an email client application. The user receives a new email, and the email data (body, subject, sender address, and included URLs) is saved to the device's storage. The input is the email the user received, and the output is the saved email data.

[1595] Step 2:

[1596] The device extracts data such as the body, subject, sender address, and included URLs from the saved email data. This process is performed by an internal routine of the email client application. The input is the email data saved in step 1, and the output is the extracted email data (body, subject, sender address, and URL).

[1597] Step 3:

[1598] The terminal sends the extracted email data to the server. The server analyzes the received email data using natural language processing technology. The input is the extracted email data, and the output is the email data received by the server.

[1599] Step 4:

[1600] The server analyzes the email body received using a generative AI model to detect signs of fraud. In this case, the generative AI model (e.g., DistilBERT) analyzes the meaning of the sentence and determines whether it is a scam or phishing scam, such as "Click the link to update your account information." The input is the email body, and the output is a risk assessment as a result of the analysis.

[1601] Step 5:

[1602] The server checks the sender address of the email against a database to evaluate its trustworthiness. It determines the trustworthiness by checking against a list of trusted sender addresses (e.g., trusted_sources). The input is the sender address, and the output is the result of the trustworthiness evaluation.

[1603] Step 6:

[1604] The server extracts the URL from the email and compares it with a safety database. Furthermore, if necessary, it actually checks the URL's destination and evaluates it for signs of fraud. Specifically, it sends an HTTP request to the URL and obtains the analysis results. The input is the URL, and the output is the URL's safety evaluation result.

[1605] Step 7:

[1606] The server performs a risk assessment based on the email body, the reliability assessment of the sender address, and the safety assessment of the URL. The risk assessment is classified as high risk, medium risk, or low risk. The input is the analysis result up to the previous step, and the output is the risk assessment result.

[1607] Step 8:

[1608] The emotion engine built into the device uses a camera and microphone to detect emotions from the user's facial expressions and voice. Specifically, it analyzes camera footage and audio data in real time. The input is the user's facial expression and voice data, and the output is the emotion recognition results.

[1609] Step 9:

[1610] The server adaptively adjusts the risk assessment based on the emotion recognition results. For example, if the user is in an unstable emotional state, the risk assessment is adjusted to be more cautious. The inputs are the emotion recognition results and the risk assessment results, and the output is the adjusted risk assessment results.

[1611] Step 10:

[1612] The server sends the risk assessment result to the terminal, and the terminal notifies the user. If the risk is high, a warning message is displayed, urging the user not to open the email. The input is the adjusted risk assessment result, and the output is the notification message displayed to the user.

[1613] The specific processing unit 290 transmits the result of the specific processing to the headset type terminal 314. In the headset type terminal 314, the control unit 46A causes the speaker 240 and the display 343 to output the result of the specific processing. The microphone 238 acquires audio indicating a user input regarding the result of the specific processing. The control unit 46A transmits audio data indicating the user input acquired by the microphone 238 to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.

[1614] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[1615] In the above embodiment, an example was given in which the specific processing is performed by the data processing device 12, but the technology of the present disclosure is not limited to this, and the specific processing may be performed by the headset type terminal 314.

[1616] [Fourth embodiment]

[1617] FIG. 7 shows an example of the configuration of a data processing system 410 according to the fourth embodiment.

[1618] 7, a data processing system 410 includes a data processing device 12 and a robot 414. An example of the data processing device 12 is a server.

[1619] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[1620] The robot 414 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication I / F 44, and a control target 443. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The microphone 238, the speaker 240, the camera 42, and the control target 443 are also connected to the bus 52.

[1621] The microphone 238 receives instructions and the like from the user 20 by receiving voice uttered by the user 20. The microphone 238 captures the voice uttered by the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio in accordance with instructions from the processor 46.

[1622] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the surroundings of user 20 (for example, an imaging range defined by an angle of view equivalent to the field of vision of a typical healthy person).

[1623] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 are responsible for the exchange of various information between the processor 46 and the processor 28 via the network 54. The exchange of various information between the processor 46 and the processor 28 using the communication I / Fs 44 and 26 is carried out in a secure state.

[1624] The control object 443 includes a display device, LEDs in the eyes, and motors for driving the arms, hands, and feet. The posture and gestures of the robot 414 are controlled by controlling the motors of the arms, hands, and feet. Some of the emotions of the robot 414 can be expressed by controlling these motors. In addition, the facial expressions of the robot 414 can also be expressed by controlling the light emission state of the LEDs in the eyes of the robot 414.

[1625] Fig. 8 shows an example of the main functions of the data processing device 12 and the robot 414. As shown in Fig. 8, in the data processing device 12, a specific process is performed by the processor 28. A specific process program 56 is stored in the storage 32.

[1626] The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[1627] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[1628] In the robot 414, the processor 46 performs the reception output process. A reception output program 60 is stored in the storage 50. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.

[1629] Next, a description will be given of the specific processing performed by the specific processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."

[1630] This invention relates to a system that receives email data, analyzes its contents, performs risk assessment, and notifies the user. Specifically, it uses generative AI to analyze the content of conversations and email text, and checks the destination sites of URLs.

[1631] System program and processing description

[1632] 1. Receiving emails

[1633] 1. The user receives an email

[1634] A user opens an email client application and receives new email, which is saved within the client application.

[1635] 2. The device extracts the email data

[1636] The device extracts the necessary information (body, subject, sender, URL, etc.) from the email data stored.

[1637] 2. Email Data Analysis

[1638] 3. The device sends the extracted data to the server

[1639] The extracted email data is sent to a server where a generative AI is placed and analyzes the data.

[1640] 4. The server analyzes the email content using natural language processing

[1641] AI on the server analyzes the email body using natural language processing technology. The purpose of the analysis is to detect signs of fraud, phishing, spam, etc. For example, if the email contains phrases such as "Please update your account information" or "Click the following link," it will determine that it is likely phishing.

[1642] 5. The server checks the sender

[1643] The server checks the sender address against a pre-registered database to assess its trustworthiness, and if it is a known scam or spam source, it is deemed high risk.

[1644] 3. URL Parsing

[1645] 6. The server extracts the URLs from the email

[1646] All URLs are extracted from the email body and the safety of each URL is evaluated.

[1647] 7. The server checks the URL against a secure database

[1648] The extracted URLs are checked against a pre-registered safe database, and if they are known phishing sites or sites hosting malware, they are rated as high risk.

[1649] 8. The server checks the URL destination

[1650] If necessary, the server will actually navigate to the URL and analyze the content of the site, and if it detects any signs of fraud, the risk level will be increased further.

[1651] 4. Risk Assessment and Notification

[1652] 9. The server performs a risk assessment

[1653] The server performs a comprehensive risk assessment based on the analysis of the email body and URLs, and the assessment is classified into three levels: high risk, medium risk, and low risk.

[1654] 10. The server sends the evaluation results to the device.

[1655] The risk assessment results are sent to the device, and include specific risk factors (e.g., "Possibly a phishing email" or "Contains a malicious URL").

[1656] 11. The device notifies the user

[1657] The device will notify the user based on the evaluation results. A warning message will be displayed for high-risk emails, urging the user not to open them. Trusted emails will also be notified that they are "safe."

[1658] Specific examples

[1659] Example 1: Receiving a phishing email

[1660] 1. The user receives a fraudulent email

[1661] The user receives an email with the subject "Your account has been suspended."

[1662] 2. The device analyzes the email and sends the data to the server

[1663] The email body and URL are extracted and sent to the server.

[1664] 3. The server analyzes the email and detects signs of phishing

[1665] The server's generative AI detects the phrase "Click the link below to update your account information."

[1666] Additionally, the sending address is verified as a known fraudulent address.

[1667] 4. The server parses the URL

[1668] The URL turns out to be a known phishing site.

[1669] 5. The server evaluates the risk as high and sends the result to the device.

[1670] The email is rated as high risk and a message is sent to the device saying, "This email may be phishing."

[1671] 6. The device displays a warning to the user

[1672] A warning message is displayed to the user.

[1673] Example 2: Receiving an important email from work

[1674] 1. A user receives an important email from work

[1675] A user receives an email titled "About the next meeting materials."

[1676] 2. The device analyzes the email and sends the data to the server

[1677] The email body and URL are extracted and sent to the server.

[1678] 3. The server analyzes the email and determines it is safe

[1679] The server's generative AI detects no abnormal patterns and verifies that the source address is trustworthy.

[1680] 4. The server parses the URL

[1681] The URL is confirmed to be the official workplace website.

[1682] 5. The server evaluates the risk as low and sends the result to the device.

[1683] It is evaluated as low risk and a message saying "This email is safe" is sent to the device.

[1684] 6. The device notifies the user

[1685] The user will see a notification that "This email is safe."

[1686] This allows users to quickly and accurately determine whether an email they receive is safe or poses a risk. This system can effectively respond to cyber threats that are constantly evolving, improving users' email security.

[1687] The processing flow will be explained below.

[1688] Step 1:

[1689] When a user receives an email, the device stores the email in the email client application in internal storage, along with metadata such as the email content, subject, sender address, and any URLs it contains.

[1690] Step 2:

[1691] The device extracts text data from the email data stored on the device. Specifically, it analyzes the email body, subject, and sender address and organizes it as structured data in a specific format.

[1692] Step 3:

[1693] The device then sends the extracted email data and URL information to the server, using an encrypted communication protocol to ensure security.

[1694] Step 4:

[1695] The server uses natural language processing technology to analyze the email data it receives. An AI model analyzes the email body and detects abnormal patterns and keywords that may indicate fraud or phishing. For example, phrases such as "update your account information" or "important notice" may indicate the possibility of phishing.

[1696] Step 5:

[1697] The server checks the sending address against a database containing known scam addresses and spam sources, and then rates the sending address as trustworthy or dangerous.

[1698] Step 6:

[1699] The server extracts all URLs from the email, detects URLs from the email body, and analyzes which sites each URL leads to.

[1700] Step 7:

[1701] The server checks the URL against a safety database, which contains information about known safe and dangerous sites. If the URL is a known phishing site or hosts malware, it is rated as high risk.

[1702] Step 8:

[1703] If necessary, the server will actually check the destination site of the URL. In this step, the server will access the URL and analyze its content. For example, it will check the page content to detect whether it contains malicious scripts or suspicious elements.

[1704] Step 9:

[1705] The server then assesses the risk of the email based on the analysis results. Risk is classified as high, medium, or low. For example, emails that are likely to be fraudulent or contain URLs that include phishing sites are assessed as high risk.

[1706] Step 10:

[1707] The server sends the risk assessment results to the device, including the type of risk and the reasons for it, in a format that is easy for the user to understand.

[1708] Step 11:

[1709] The device notifies the user based on the risk assessment results. For high-risk emails, a warning message is displayed on the screen, urging the user not to open the email. For trustworthy emails, the device notifies the user that "This email is safe."

[1710] Step 12:

[1711] The user is notified and is given a risk assessment to decide whether to open the email, delete it, or perform further safety checks.

[1712] These steps allow users to quickly and accurately understand the safety of the emails they receive, and by having the server and device work together, we can provide an unprecedentedly strong security environment.

[1713] Example 1

[1714] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."

[1715] In today's cyber environment, the threat of malicious emails such as phishing and spam is increasing, and users need a way to quickly and accurately determine whether the emails they receive are safe. However, existing email security measures are unable to fully analyze the risks of email content and URLs, potentially exposing users to serious risks. For this reason, a system is needed that performs advanced email content analysis and URL safety assessment, and provides accurate risk assessments and notifications to users in real time.

[1716] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.

[1717] In this invention, the server includes a means for comparing the sender address with a database to evaluate the reliability of the email, a means for extracting URLs from the email and comparing them with a safety database, and a means for checking the destination of the URL and evaluating signs of fraud. This makes it possible to evaluate the reliability of the email and the safety of the URL with high accuracy and quickly notify the user of the risk evaluation results.

[1718] "Mail Data" means digital information received and sent as email, including the body, subject, sender address, and associated metadata.

[1719] "Text data" refers to character string data in an analyzable format that includes the email body and related information.

[1720] A "server" is a computer system that provides services over a network, including hardware and software for data analysis and risk assessment.

[1721] "Natural language processing technology" is a general term for technologies that enable computers to understand, interpret, and generate human language.

[1722] "Risk assessment" is the process of assessing the degree of risk an email poses to the user based on the analyzed email, and the assessment results are classified as high risk, medium risk, or low risk.

[1723] "User" refers to the end user who uses this system to check the security of email.

[1724] A "database" is a software system for efficiently storing, managing, and retrieving data, including those in SQL or NoSQL formats.

[1725] A "safe database" is a database that holds information about known safe and dangerous URLs and domains.

[1726] A "headless browser" is a browser without a GUI, used for automation scripts and system testing.

[1727] A "generative AI model" is an artificial intelligence model that learns large amounts of data and generates and analyzes natural language, and is particularly used for natural language processing.

[1728] An "HTTP request" is a protocol request for exchanging information between a client and a server, typically a GET or POST request.

[1729] "Real-time threat intelligence" refers to the latest information on current security threats and attack patterns, which is used to update risk assessments.

[1730] This invention relates to a system that receives email data, analyzes its contents, performs risk assessment, and notifies the user. Specifically, it uses a generative AI model to analyze the contents of emails using natural language processing technology and checks the destination URLs.

[1731] First, the user receives an email using an email client application. The received email is saved on the device. The device then extracts the email body, subject, sender address, and all URLs in the email body from the saved data. This process uses the Python email package and regular expressions (Regex).

[1732] Next, the device sends the extracted email data to a server using an HTTP request (e.g., a POST request). A generative AI model (e.g., GPT-3) is placed on the server, and this AI model analyzes the email body using natural language processing (NLU). Specifically, it detects phrases that indicate a fraudulent email, such as "Please update your account information."

[1733] Additionally, the server compares the sender address of the email with a database (SQL or NoSQL database) to assess its trustworthiness. If it is a sender address of a known fraudulent email, it is assessed as high risk. Next, the server extracts all URLs from the email body and compares them with a safe database (e.g., Google Safe Browsing API). This assesses whether they are phishing sites or malware hosting sites.

[1734] In addition to this evaluation, the server will actually check the URL destination using a headless browser (for example, Selenium with ChromeDriver) and analyze the content of the site. If there are any signs of fraud or harmful scripts, the risk level will be raised further.

[1735] Once the risk assessment is complete, the server sends the results to the device. The assessment results include detailed information about specific risk factors (for example, "possibly a phishing email" or "contains a malicious URL"). The device uses this information to provide appropriate notifications to the user. For high-risk emails, a warning message is displayed, urging the user not to open the email. For trustworthy emails, the device notifies the user that the email is "safe."

[1736] As a concrete example, if a user receives a phishing email with the title "Your account has been suspended," the device extracts the email's text and URL and sends them to the server. The server's generative AI model detects the phrase "Click the link below to update your account information" and confirms that the sender address is a known scam address. If the URL is determined to be a phishing site, it is rated as high risk and the result is sent to the device. Finally, the device displays a warning to the user saying, "This email may be phishing."

[1737] This system is designed to effectively respond to ever-evolving cyber threats and improve users' email security. It also updates risk assessments based on threat information collected in real time, enabling rapid response to the latest security situations.

[1738] The flow of the identification process in the first embodiment will be described with reference to FIG.

[1739] Step 1: User receives email

[1740] Input: A user receives an email.

[1741] What it does: Opens an email client application (e.g., Gmail, Outlook) and receives a new email.

[1742] Output: Received emails are saved on the device.

[1743] What happens: When a user opens their email client, new emails are downloaded from the server and displayed within the email application.

[1744] Step 2: Your device extracts the email data

[1745] Input: Received email data.

[1746] How it works: Extracts the body, subject, sender address, and all URLs in the body from saved email data. It uses the Python email package and regular expressions (Regex).

[1747] Output: A list of extracted email bodies, subjects, sender addresses, and URLs.

[1748] What it does: The program analyzes the received email data and extracts important information.

[1749] Step 3: The device sends the extracted data to the server

[1750] Input: A list of extracted email bodies, subjects, sender addresses, and URLs.

[1751] What it does: Sends the extracted data to the server using an HTTP request (e.g., a POST request).

[1752] Output: The email data received by the server.

[1753] Specific operation: The device makes an HTTP request and sends data to the server endpoint.

[1754] Step 4: The server analyzes the email content using natural language processing

[1755] Input: The email body sent from the device.

[1756] How it works: It uses generative AI models (e.g., GPT-3) to analyze email content and detect signs of fraud and phishing. It uses natural language processing libraries like NLTK and SpaCy.

[1757] Output: Analysis results, information on indicators of fraud and phishing.

[1758] Specific operation: The server tokenizes the email content and analyzes specific keywords and context to extract dangerous phrases.

[1759] Step 5: The server checks the source

[1760] Input: The source address sent from the device.

[1761] How it works: The source address is checked against a database (e.g., an SQL or NoSQL database) to assess its trustworthiness.

[1762] Output: The reliability evaluation result of the source address.

[1763] What it does: Runs a database query to match the email against a list of known fraudulent email senders.

[1764] Step 6: The server extracts the URLs in the email

[1765] Input: The email body sent from the device.

[1766] What it does: Extracts all URLs from the email body using regular expressions (Regex).

[1767] Output: A list of extracted URLs.

[1768] What it does: Identify and list all possible URL patterns within the email body.

[1769] Step 7: Server checks URL against safety database

[1770] Input: The extracted URL list.

[1771] How it works: Each URL is checked against a safety database (e.g., Google Safe Browsing API) to assess whether it is a phishing or malware-hosting site.

[1772] Output: Safety assessment results for each URL.

[1773] What it does: It uses HTTP requests to check against a safety database to determine the risk level of the URL.

[1774] Step 8: The server checks the URL destination

[1775] Input: The extracted URL list.

[1776] What it does: Uses a headless browser (e.g. Selenium with ChromeDriver) to navigate to a URL and analyze the content of that site.

[1777] Output: Analysis results of the destination site, information on indicators of fraud.

[1778] What it does: It automatically manipulates the browser to access URLs and analyzes the page content to detect dangerous scripts and content.

[1779] Step 9: Server performs risk assessment

[1780] Input: Email body, sender address, and URL analysis results.

[1781] How it works: The results of these analyses are combined to give the email a risk rating, which is then categorized as high, medium, or low risk.

[1782] Output: Risk assessment results.

[1783] Specific operation: Integrates analysis results and performs comprehensive risk assessment based on pre-defined rules and models.

[1784] Step 10: The server sends the evaluation results to the device.

[1785] Input: Risk assessment results.

[1786] Operation: The evaluation result is sent to the terminal as an HTTP response.

[1787] Output: The evaluation results sent to the device.

[1788] Specific behavior: Create an HTTP response and send it along with the evaluation result.

[1789] Step 11: The device notifies the user

[1790] Input: The risk assessment result sent from the server.

[1791] Behavior: Notifies the user based on the evaluation results. High-risk emails are warned, and trusted emails are told "safe."

[1792] Output: Notification to the user.

[1793] Specific operation: The terminal displays an appropriate message on the user interface based on the evaluation results.

[1794] (Application example 1)

[1795] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."

[1796] In recent years, the spread of phishing attacks and malware via email has been increasing, increasing the risk of users suffering serious damage. For this reason, there is a need for a system that automatically analyzes the content of emails when they are received, evaluates potential risks, and notifies users. Conventional systems often perform insufficient email analysis or are slow to notify users of risks, so technology is needed to enable rapid and accurate risk assessment and notification.

[1797] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.

[1798] In this invention, the server includes means for acquiring email data, means for converting the acquired email data into text data, means for transmitting the text data to the server and analyzing it using natural language processing technology on the server side, means for performing a risk assessment of the email based on the analysis result, means for transmitting the risk assessment result to the client device and notifying the user, means for providing the user with specific factors of the risk assessment along with the notification, means for comparing the sender address with a database to evaluate the reliability of the email, means for extracting URLs from the email and comparing them with a safety database, means for actually checking the destination of the URLs and evaluating signs of fraud, means for classifying the email as high risk, medium risk, or low risk based on the risk assessment result, means for updating the risk assessment based on threat information collected in real time, means for displaying an immediate warning to the user based on the risk assessment, and means for providing detailed information simultaneously with the display of the warning message. This enables rapid and accurate risk assessment and notification to the user upon receipt of email.

[1799] "Email data" refers to the entire content of an email received by a user, including the subject, sender address, body, attachments, URLs, etc.

[1800] "Means of acquisition" refers to the technology or devices used to receive email and extract its contents.

[1801] "Text data" refers to the content of an e-mail, etc., converted into data in an analyzable format.

[1802] "Server" refers to the central system for analyzing email data and conducting risk assessments.

[1803] "Natural language processing technology" refers to technology for analyzing human language and understanding and processing its meaning and structure.

[1804] "Means for analyzing" refers to technology or devices for analyzing the content of email using natural language processing technology.

[1805] "Risk assessment" refers to determining whether an email is dangerous to the user based on the information contained in the email.

[1806] A "client device" is a device that a user directly uses, and includes a smartphone, tablet, computer, etc.

[1807] "Means of notification" refers to the technology or device used to notify users of the results of the risk assessment.

[1808] "Specific factors" refers to the individual factors or information provided to elaborate on the results of a risk assessment.

[1809] A "safe database" refers to a database that stores known safe URLs and reliable information.

[1810] "Indicators of fraud" refer to evidence or patterns that indicate possible malicious activity, such as phishing sites or malware.

[1811] "High risk, medium risk, low risk" are classifications of different levels of potential danger for email.

[1812] "Threat intelligence" refers to information about the latest threats and attack methods, including data collected in real time.

[1813] A "warning message" refers to a message that displays warning information to notify the user of a danger.

[1814] "Detailed information" refers to information provided to the user, including background and specific explanations of the risk assessment.

[1815] In order to put the present invention into practice, it is necessary to build a system that acquires email data, analyzes it, performs risk assessment, and notifies the user.

[1816] The system uses the following hardware and software:

[1817] Hardware

[1818] server

[1819] Client devices (smartphones, tablets, computers)

[1820] software

[1821] Email client applications

[1822] Natural language processing libraries (e.g. NLTK, SpaCy)

[1823] Generative AI models (e.g., OpenAI's GPT-3)

[1824] Security databases (e.g., lists of known phishing sites)

[1825] Database systems (e.g. PostgreSQL, MongoDB)

[1826] Server platform (e.g. AWS, GCP, Azure)

[1827] The server first obtains the email data received by the user. The obtained email data is converted into text data. The server receives the text data and analyzes it using natural language processing technology. Based on the analysis results, a risk assessment of the email is performed.

[1828] For risk assessment, the server uses the following methods:

[1829] 1. Check the sender address against a database to assess the authenticity of the email.

[1830] 2. Extract URLs from emails and check them against a secure database.

[1831] 3. Check the destination of the URL and evaluate for signs of fraud.

[1832] The risk assessment results are classified as high risk, medium risk, or low risk, and the results are sent to the client device, which receives the results and notifies the user, including the specific risk factors.

[1833] For example, the following prompt sentences are sent to the generative AI model for analysis:

[1834] Please analyze the body of the following email and assess it for signs of phishing:

[1835] ---

[1836] Subject: Your account has been suspended

[1837] Body: "Your account has been suspended due to unauthorized access. Please click the link below to update your account information: http: / / example.com / phishing"

[1838] From: "support@example.com"

[1839] Classify your results as "high risk," "medium risk," or "low risk," and explain why.

[1840] The generative AI model analyzes the email body based on this prompt and returns the analysis results to the server. Based on the results, the email is assessed for risk and notified to the user.

[1841] For example, if a user receives an email with the subject line "Your account has been suspended," the server analyzes the email and detects signs of phishing. As a result, the user is warned that "This email may be phishing" and is provided with more information.

[1842] As described above, the present invention automates the process of risk assessment and user notification when an email is received, thereby realizing accurate security measures in real time.

[1843] The flow of the specific processing in the application example 1 will be described with reference to FIG.

[1844] Step 1:

[1845] The terminal acquires the email data received by the user. It parses the new email data received through the email client application into necessary elements such as subject, sender address, body, attachments, and URLs. The acquired data becomes the input for the next processing step.

[1846] Step 2:

[1847] The terminal converts the acquired email data into text data. The text data is then formatted into an analyzable format and sent to the server. In this data conversion process, the email body and URL are unified into a string format.

[1848] Step 3:

[1849] The server receives the received text data and analyzes the email content using natural language processing technology. The input for analysis is the text data and extracted URLs. During the analysis process, a generative AI model (e.g., GPT-3) is used to identify signs of phishing and anomalous expressions in the text. The output is the analysis results.

[1850] Step 4:

[1851] The server performs a risk assessment based on the analysis results. The input is the analysis results obtained in step 3. The server compares the sender address with a database to assess its trustworthiness, and compares the URL in the email with a safety database. Furthermore, if necessary, it actually checks the destination of the URL and assesses signs of fraud. This classifies the risk level of the email into three categories: high risk, medium risk, and low risk. This risk assessment is the output.

[1852] Step 5:

[1853] The server sends the risk assessment result to the client device. The input is the risk assessment result, and the output is a notification message sent to the client device. The notification message includes the risk level and specific factors (e.g., the likelihood of phishing or the presence of a malicious URL).

[1854] Step 6:

[1855] The terminal displays a notification to the user based on the evaluation results. The input is the received notification message, and the output is a warning message or detailed information presented to the user. This allows the user to immediately recognize the safety of their email and take any necessary action.

[1856] The above processing steps enable rapid and accurate risk assessment and user notification upon receipt of email.

[1857] Furthermore, an emotion engine that estimates the user's emotion may be further combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59, and perform identification processing using the user's emotion.

[1858] This invention relates to a system that receives email data, analyzes its contents, performs risk assessment, and notifies the user. It also combines an emotion engine that recognizes the user's emotions and dynamically adjusts the risk assessment and notification method accordingly.

[1859] System program and processing description

[1860] 1. Receiving emails and extracting data

[1861] 1. The user receives an email

[1862] A user opens an email client application and receives a new email, which is then saved in the device's storage.

[1863] 2. The device extracts the email data

[1864] The device extracts the body of the email, subject, sender address, and any URLs contained in it from the email data stored on the device.

[1865] 2. Email Data Analysis

[1866] 3. The device sends the extracted data to the server

[1867] The extracted email data is sent to a server, where a generative AI with natural language processing technology is placed to analyze the data.

[1868] 4. The server analyzes the email content using natural language processing

[1869] The server's AI analyzes the email body and detects abnormal patterns that may indicate fraud or phishing, such as the phrase "Click on the link to update your account information."

[1870] 5. The server checks the sender

[1871] The server checks the email sender address against a secure database to assess its trustworthiness. If it's a known fraudulent sender on the list, it's rated as high risk.

[1872] 3. URL Parsing

[1873] 6. The server extracts the URLs from the email

[1874] The server extracts URLs from the email body and analyzes which sites each URL leads to.

[1875] 7. The server checks the URL against a secure database

[1876] It checks the URL against a database and warns you if it is a known phishing site or a dangerous site.

[1877] 8. The server actually checks the URL destination if necessary

[1878] The server actually accesses the URL and analyzes its contents to check whether it contains any invalid elements.

[1879] 4. Risk Assessment and Notification

[1880] 9. The server performs a risk assessment

[1881] The server performs a risk assessment based on the analysis of the email body and URL, and classifies the risk as high, medium, or low.

[1882] 10. The server sends the evaluation results to the device.

[1883] The risk assessment results are sent to the device, along with detailed reasons for the assessment.

[1884] 11. The device notifies the user

[1885] The device will notify the user based on the risk assessment results. If the email is high risk, a warning message will be displayed, urging the user not to open the email. If the email is trustworthy, the device will notify the user that it is "safe."

[1886] 5. Emotion engine integration

[1887] 12. The device will recognize the user's emotions

[1888] The emotion engine built into the device uses a camera and microphone to detect emotions from the user's facial expressions and voice, and the emotion data is analyzed in real time.

[1889] 13. The server analyzes the emotional data and reflects it in risk assessment

[1890] The server can then use emotional data to provide flexibility in risk assessment, for example, making a more conservative risk assessment if the user is in an unstable emotional state.

[1891] 14. The server selects the notification method according to the emotion

[1892] The server adjusts the notification method depending on the detected emotion, for example, displaying a strong warning message if the user is unstable, and a light warning if the user is stable.

[1893] Specific examples

[1894] Example 1: A user receives a phishing email

[1895] 1. A user receives a phishing email

[1896] A user receives a phishing email with the subject "Your account information has been suspended."

[1897] 2. The device extracts the email data and sends it to the server

[1898] The email body, subject, sender, and URL are extracted and sent to the server.

[1899] 3. The server detects signs of fraud

[1900] The server's AI analyzes the email content to detect signs of fraud and also checks that the sender is on a fraud list.

[1901] 4. The server analyzes the URL and checks if it is a phishing site

[1902] Verify that the URL matches a known phishing site and also contains malicious scripts.

[1903] 5. The server evaluates the risk as high and sends the result to the device.

[1904] The server evaluates the email as high risk and sends the result to the device.

[1905] 6. Emotion engine detects user's unstable emotions

[1906] The emotion engine detects when a user expresses uneasy emotions about a phishing email.

[1907] 7. The server displays a strong warning

[1908] The server displays a strong warning message on the terminal based on the user's emotional state.

[1909] Example 2: Receiving important emails from work and checking safety

[1910] 1. A user receives an important email from work

[1911] A user receives a secure email with the subject "Next Meeting Materials."

[1912] 2. The device extracts the email data and sends it to the server

[1913] The email body and URL are extracted and sent to the server.

[1914] 3. The server performs analysis and does not detect any abnormalities.

[1915] The server's AI analyzes the email content and verifies that there are no abnormal patterns.

[1916] 4. The server analyzes the URL and verifies that it is a secure site.

[1917] The URL is confirmed to be the official workplace website.

[1918] 5. The server evaluates the risk as low and sends the result to the device.

[1919] The email is assessed as low risk and the result is sent to the device.

[1920] 6. The emotion engine detects the user's calm emotion

[1921] The emotion engine ensures that the user is in a normal emotional state.

[1922] 7. Server displays a light notification

[1923] The server responds to the user's sentiment and displays a simple notification saying, "This email is safe."

[1924] As described above, the present invention goes beyond the conventional technology of analyzing email content and assessing risk by providing a system that dynamically adjusts risk assessment and notification methods taking into account the user's emotional state, allowing users to receive flexible support tailored to their emotions while improving email security.

[1925] The processing flow will be explained below.

[1926] Step 1:

[1927] When a user receives an email, the device stores the email in the email client application in internal storage, along with metadata such as the email content, subject, sender address, and any URLs it contains.

[1928] Step 2:

[1929] The device extracts text data from the email data stored on the device. Specifically, it analyzes the email body, subject, and sender address and organizes it as structured data in a specific format.

[1930] Step 3:

[1931] The device sends the extracted email data and URL information to the server, using an encrypted communication protocol to ensure security.

[1932] Step 4:

[1933] The server uses natural language processing technology to analyze the email data it receives. An AI model analyzes the email body and detects abnormal patterns and keywords that may indicate fraud or phishing. For example, phrases such as "update your account information" or "important notice" may indicate the possibility of phishing.

[1934] Step 5:

[1935] The server checks the sending address against a database containing known scam addresses and spam sources, and then rates the sending address as trustworthy or risky.

[1936] Step 6:

[1937] The server extracts all URLs from the email, detects URLs from the email body, and analyzes which sites each URL leads to.

[1938] Step 7:

[1939] The server checks the URL against a safety database, which contains information about known safe and dangerous sites. If the URL is a known phishing site or hosts malware, it is rated as high risk.

[1940] Step 8:

[1941] If necessary, the server will actually check the destination site of the URL. In this step, the server will access the URL and analyze its content. For example, it will check the page content to detect whether it contains malicious scripts or suspicious elements.

[1942] Step 9:

[1943] The server then assesses the risk of the email based on the analysis results. Risk is classified as high, medium, or low. For example, emails that are likely to be fraudulent or contain URLs that include phishing sites are assessed as high risk.

[1944] Step 10:

[1945] The server sends the risk assessment results to the device, including the type of risk and the reasons for it, in a format that is easy for the user to understand.

[1946] Step 11:

[1947] The device notifies the user based on the risk assessment results. For high-risk emails, a warning message is displayed on the screen, urging the user not to open the email. For trustworthy emails, the device notifies the user that "This email is safe."

[1948] Step 12:

[1949] The device recognizes the user's emotions. The emotion engine built into the device uses the camera and microphone to detect emotions from the user's facial expressions and voice. Emotional data is analyzed in real time.

[1950] Step 13:

[1951] The server analyzes the emotional data and reflects it in the risk assessment. The server makes the risk assessment flexible based on the emotional data. For example, if the user is in an unstable emotional state, the server makes a more cautious risk assessment.

[1952] Step 14:

[1953] The server selects the notification method according to the emotion. The server adjusts the notification method according to the emotion detected. For example, if the user is in an unstable state, a strong warning message is displayed, and conversely, if the user is stable, a light warning is displayed.

[1954] Step 15:

[1955] The user is notified and can decide whether to open the email, delete it, or conduct further safety checks based on the risk assessment provided. This process allows the user to quickly and accurately understand the safety of the email they received, and also provides appropriate support based on their emotional state.

[1956] Example 2

[1957] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."

[1958] While conventional email risk assessment systems are technically effective, such as by analyzing email text and checking sender addresses, they ignore the user's emotional state and do not take into account the user's mental burden. Furthermore, because the risk notification method is uniform, they have the problem of being unable to respond adequately in situations where flexible responses according to the user's state are required.

[1959] The specific processing by the specific processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means.

[1960] In this invention, the server includes means for analyzing email data, means for verifying sender addresses and URLs, and means for adjusting risk assessment and notification methods based on user emotional data, thereby enabling flexible risk assessment and notification according to the user's emotional state.

[1961] "Email data" refers to all data received as the content of an email, including the body of the email, the subject line, the sender's address, and URLs.

[1962] "Text data" refers to character information extracted from email data, such as the body of the email and the subject line that are the subject of analysis.

[1963] "Server" refers to a computer system for analyzing email data, assessing risk, and processing emotional data.

[1964] "Natural language processing technology" refers to technology that allows computers to understand, interpret, and generate human language, and is used as a means of detecting signs of fraud in email text.

[1965] "Risk assessment" refers to the process of assessing the degree of risk an email poses based on the content of the analyzed email data, the sender address, and the safety of the URL.

[1966] "Notification" refers to the act of communicating the results of a risk assessment to the user, including warning messages and safety notifications.

[1967] An "emotion engine" is a system that uses a camera or microphone to recognize a user's emotions, analyzes the data, and reflects it in risk assessments and notification methods.

[1968] A "safe database" is a database containing information such as known fraudulent sites and unsafe source addresses, and is used to match URLs and source addresses.

[1969] "Real-time" refers to the timing in which data is processed and analyzed the moment it is generated, meaning that results are reflected immediately.

[1970] "Threat information" means information that indicates potential dangers to networks and systems, including data on malware, phishing sites, and fraudulent activities.

[1971] This invention relates to a system that receives email data, analyzes its contents, performs risk assessment, and notifies the user. It also combines an emotion engine that recognizes the user's emotions and dynamically adjusts the risk assessment and notification method accordingly.

[1972] Hardware and software used

[1973] This system is primarily comprised of terminals and servers. An email client application (e.g., commonly referred to as an "email client") is installed on the terminal, which receives and manages email data. The server is equipped with a generative AI model (e.g., natural language processing technology such as OpenAI GPT-3) that analyzes email data and assesses risk. In addition, an emotion engine (e.g., Microsoft Azure's emotion recognition API) is used to analyze user emotions.

[1974] Data processing and calculation

[1975] 1. Email reception and data extraction

[1976] The user opens an email client and receives a new email. The email data is stored in the device's storage.

[1977] The device extracts the body, subject, sender address, and URL from the email data stored on the device. This process is performed using a Python email parser library.

[1978] 2. Email Data Analysis

[1979] The terminal sends the extracted email data to the server, where it is converted into JSON format and sent via the HTTPS protocol.

[1980] The server-generated AI model analyzes the email body and detects signs of fraud or phishing.

[1981] The server checks the sender address against a safety database (e.g., Spamhaus or PhishTank) to assess trustworthiness.

[1982] 3. URL Parsing

[1983] The server extracts the URL from the email body and checks its safety against a safety database (e.g., Google Safe Browsing API).

[1984] If necessary, the server will actually visit the URL and scrape the website content to detect malicious scripts.

[1985] 4. Risk Assessment and Notification

[1986] The server performs a risk assessment based on the analysis of the email body, sender, and URL, and classifies the email as high risk, medium risk, or low risk.

[1987] The evaluation results are sent to the device in JSON format, and the device notifies the user. If the risk is high, a warning message is displayed, and if the risk is low, a message stating "it's safe" is displayed.

[1988] 5. Emotion engine integration

[1989] The emotion engine built into the device uses the camera and microphone to analyze the user's emotions in real time.

[1990] The server dynamically adjusts risk assessment and notification methods based on emotional data, displaying a strong warning if the user is in an unstable state and a light warning if the user is in a stable state.

[1991] Specific examples

[1992] Example 1: Detecting phishing emails and notifying users

[1993] 1. The user receives a phishing email with the subject "Your account information has been suspended."

[1994] 2. The device extracts the email data and sends it to the server.

[1995] 3. The server's generative AI model detects signs of fraud and verifies that the sender is on the fraud list.

[1996] 4. The server parses the URL and verifies that it matches a phishing site.

[1997] 5. Evaluate it as high risk and send the result to the device.

[1998] 6. The emotion engine detects the user's unstable emotions and displays a strong warning message.

[1999] Example 2: Checking important emails from work

[2000] 1. A user receives a secure email with the subject "Next Meeting Materials."

[2001] 2. The device extracts the email data and sends it to the server.

[2002] 3. The server-generated AI model analyzes the email content and verifies that there are no abnormal patterns.

[2003] 4. The server parses the URL and verifies that it is a secure site.

[2004] 5. Evaluate it as low risk and send the result to the device.

[2005] 6. The emotion engine checks the user's stable emotions and displays a gentle notification saying, "This email is safe."

[2006] Examples of prompt statements

[2007] Phishing email risk assessment prompt:

[2008] Analyze the body of the following emails for signs of fraud and categorize them as high, medium, or low risk.

[2009] Email body: "Your account information has been suspended. Click the link below to update it: http: / / example.com"

[2010] Prompts that adjust notification methods based on the user's emotions:

[2011] Based on the following emotional data, select the appropriate notification method according to the risk assessment results: If the user is unstable, give a strong warning, and if the user is stable, give a light warning.

[2012] Emotion data: { "emotion": "anxious", "confidence": 0.85}

[2013] The above is an embodiment of the present invention. This system allows users to enhance email security and receive flexible support according to their emotions.

[2014] The flow of the identification process in the second embodiment will be described with reference to FIG.

[2015] Step 1:

[2016] The user receives the email.

[2017] Input: Data from the mail server, including emails

[2018] What happens: The user opens their email client and receives a new email.

[2019] Output: Email data stored in the device's storage (body, subject, sender address, URL, etc.)

[2020] Step 2:

[2021] The device extracts the email data.

[2022] Input: Email data stored in the device's storage

[2023] What it does: The device uses a Python email parser library (e.g., the email package) to extract the body, subject, sender address, and URL from the email data stored on the device.

[2024] Output: Extracted text data (body, subject, sender address, URL)

[2025] Step 3:

[2026] The terminal transmits the extracted data to the server.

[2027] Input: Extracted text data

[2028] Specific operation: The terminal converts the extracted email data into JSON format and sends it to the server using the HTTPS protocol.

[2029] Output: Text data sent to the server

[2030] Step 4:

[2031] The server analyzes the email content using natural language processing.

[2032] Input: Text data sent to the server

[2033] How it works: The server-generated AI model analyzes the body of received emails and detects anomalous patterns that may indicate fraud or phishing, such as the phrase "Click on the link to update your account information."

[2034] Output: Analysis results (presence or absence of signs of fraud, detection of abnormal patterns)

[2035] Step 5:

[2036] The server verifies the sender.

[2037] Input: Source address and analysis result from the previous step

[2038] What it does: The server checks the sender address of the email against a secure database (e.g., Spamhaus or PhishTank) to assess its trustworthiness. If it is a known fraudulent sender, it is rated as high risk.

[2039] Output: Sender evaluation result (sender reliability evaluation)

[2040] Step 6:

[2041] The server extracts the URLs in the email.

[2042] Input: Email body

[2043] Specific operation: The server uses regular expressions to extract URLs from the email body and stores them in a list.

[2044] Output: Extracted URL list

[2045] Step 7:

[2046] The server checks the URL against a secure database.

[2047] Input: Extracted URL list

[2048] How it works: The server checks the URL against a safety database (e.g., Google Safe Browsing API) to verify its safety. If the site is fraudulent, it immediately issues a warning.

[2049] Output: URL safety assessment results

[2050] Step 8:

[2051] The server will actually check the URL destination if necessary.

[2052] Input: Suspected dangerous URL

[2053] Specific operation: The server actually accesses the URL and uses BeautifulSoup or Selenium to scrape the HTML content of the destination website to detect whether or not there is any malicious script.

[2054] Output: URL check result (whether malicious script is included or not)

[2055] Step 9:

[2056] The server performs the risk assessment.

[2057] Input: Email body analysis results, sender evaluation results, URL evaluation results

[2058] Specific operation: The server evaluates these results comprehensively and calculates a risk score, which is then classified as high risk, medium risk, or low risk.

[2059] Output: Risk assessment results (risk score and classification)

[2060] Step 10:

[2061] The server transmits the evaluation results to the terminal.

[2062] Input: Risk assessment results

[2063] Specific operation: The server converts the risk assessment results and detailed assessment reasons into JSON format and sends them to the terminal using the HTTPS protocol.

[2064] Output: Risk assessment results sent to the device

[2065] Step 11:

[2066] The terminal notifies the user.

[2067] Input: Risk assessment results

[2068] Specific operation: Based on the risk assessment results received by the device, the notification API is used to notify the user. If the risk is high, a warning message will be displayed in a pop-up window stating "This is a high-risk email. Do not open it."

[2069] Output: User notification (warning message)

[2070] Step 12:

[2071] The device recognizes the user's emotions.

[2072] Input: User facial and voice data

[2073] Specific operation: The emotion engine (e.g., emotion recognition API) built into the device uses the camera and microphone to analyze the user's facial expressions and voice in real time.

[2074] Output: Parsed emotion data

[2075] Step 13:

[2076] The server analyzes the emotional data and reflects it in risk assessment.

[2077] Input: Emotion data and risk assessment results

[2078] Specific operation: The server flexibly adjusts the risk assessment based on the analyzed emotional data. For example, if the user is in an unstable emotional state, the risk score will be adjusted upward.

[2079] Output: Adjusted risk assessment results

[2080] Step 14:

[2081] The server selects the notification method according to the emotion.

[2082] Input: Adjusted risk assessment results and sentiment data

[2083] Specific operation: The server selects the notification method based on the detected emotion. For example, if the user is unstable, a strong warning message is displayed, and conversely, if the user is stable, a light warning is displayed.

[2084] Output: Emotion-based notification (strong or mild warning message)

[2085] (Application example 2)

[2086] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."

[2087] Conventional email security systems analyze received email data to perform risk assessment, but are indifferent to the user's emotional state, resulting in a lack of accuracy and flexibility in risk assessment and notification. Furthermore, to address the increase in fraudulent emails, including phishing and scams, real-time risk assessment and advanced warning systems are necessary, but the current situation is one in which these are not fully realized. Therefore, there is a need for a method of personalized risk assessment notification that responds to the user's emotional state.

[2088] The identification process by the identification processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means. In this invention, the server includes means for receiving email data, means for converting the received email data into text data, means for transmitting the text data to the server and analyzing it using natural language processing technology on the server side, means for assessing the risk of the email based on the analysis results, means for recognizing the user's emotions, means for adaptively adjusting the risk assessment based on the detection results of the emotion engine, and means for transmitting the risk assessment results to the terminal and notifying the user. This enables dynamic and flexible risk assessment and notification according to the user's emotional state. Furthermore, by updating the risk assessment based on threat information collected in real time and displaying a strong warning if the user is in an unstable emotional state, more effective and personalized security measures are realized.

[2089] "Email data" refers to the content and metadata of an email, including the body, subject, sender address, URL, etc.

[2090] A "server" refers to a computer system that performs processes such as receiving, transmitting, analyzing, and storing data on a network.

[2091] "Natural language processing technology" refers to technology that mechanically analyzes, understands, and generates human language, and analyzes email text and other text data to extract meaning.

[2092] "Risk assessment" refers to the process of determining whether an email contains risks such as phishing, fraud, or malware based on the results of analyzing email data.

[2093] "User" refers to a general user who uses an email client, checks received emails, and receives security notifications.

[2094] An "emotion engine" is a technology that detects the user's current emotions from their facial expressions, voice, etc., and adjusts the system's operation based on that.

[2095] "Risk assessment result" refers to the final risk assessment result issued by the server after analyzing the email data.

[2096] "Terminal" refers to a computer device (smartphone, PC, tablet, etc.) that is directly operated by a user and that receives notification of risk assessment results.

[2097] "Notification means" refers to methods and techniques for informing users of risk assessment results, including alert messages, pop-up notifications, and audio notifications.

[2098] A "database" refers to a storage system that systematically stores specific data and allows it to be quickly searched, collated, and updated.

[2099] "Indicators of fraud" refer to abnormal behavior or content that differs from normal operations or data patterns, and may include phishing sites or malware.

[2100] The system for implementing this invention integrates email data reception, analysis, risk assessment, emotion recognition, and notification. The present invention exchanges data between a server and a terminal, provides security notifications to users in real time, and dynamically adjusts the content of notifications according to the user's emotional state.

[2101] System configuration

[2102] Server: A computer system that receives, analyzes, and assesses risk of data, and is equipped with generative AI with natural language processing technology. When specific email data is received, it analyzes the data and assesses the risk of fraud, phishing, malware, etc. It also incorporates user emotional data to dynamically adjust risk assessment and notifications.

[2103] Terminal: A computing device that is directly operated by the user and receives and displays emails using an email client application. The terminal is equipped with an emotion engine with emotion recognition capabilities, and detects the user's emotions in real time using a camera and microphone.

[2104] Program processing

[2105] Receiving emails and extracting data: When a user opens an email client application and receives a new email, the email data is stored on the device and its contents (body, subject, sender address, and included URLs) are extracted. This process is performed using the email client application and the device's storage.

[2106] Data analysis and risk assessment: The extracted email data is sent to a server where it is analyzed using natural language processing technology. A generative AI model is placed on the server to analyze the email body and detect anomalous patterns. In addition, the sender address and URL are compared with a database to assess signs of fraud. The risk assessment is classified as high, medium, or low risk based on the content of the message body, the sender, and the safety of the URL.

[2107] Emotion recognition and risk assessment adjustment: The emotion engine built into the device uses the camera and microphone to recognize the user's emotions in real time. The recognized emotion data is sent to the server and reflected in the risk assessment. For example, if the user is in an unstable emotional state, the server will make a more cautious risk assessment and display a strong warning message.

[2108] Notification of risk assessment results: The server sends the risk assessment results to the terminal and notifies the user based on the results. The terminal displays the risk assessment results and provides the user with information about the safety of the email. If the email is deemed high risk, a warning message is displayed, urging the user not to open the email.

[2109] Specific examples

[2110] Prompt Sentence Examples

[2111] 1. Phishing emails:

[2112] Subject: "Update your account information"

[2113] Body text: "Click the link below to update your account information."

[2114] From: "malicious@example.com"

[2115] URL: "http: / / phishing.example.com"

[2116] 2. Secure Work Email:

[2117] Subject: "Materials for the next meeting"

[2118] Body of text: "I have attached the materials to be used at the next meeting."

[2119] From: "trusted@workplace.com"

[2120] URL: "http: / / workplace.com / document"]

[2121] In this way, the present invention improves email security and the user experience through collaboration between the server and the terminal. In addition, by utilizing an emotion engine, flexible responses according to the user's emotional state become possible.

[2122] The flow of the specific processing in the application example 2 will be described with reference to FIG.

[2123] Step 1:

[2124] The device opens an email client application. The user receives a new email, and the email data (body, subject, sender address, and included URLs) is saved to the device's storage. The input is the email the user received, and the output is the saved email data.

[2125] Step 2:

[2126] The device extracts data such as the body, subject, sender address, and included URLs from the saved email data. This process is performed by an internal routine of the email client application. The input is the email data saved in step 1, and the output is the extracted email data (body, subject, sender address, and URL).

[2127] Step 3:

[2128] The terminal sends the extracted email data to the server. The server analyzes the received email data using natural language processing technology. The input is the extracted email data, and the output is the email data received by the server.

[2129] Step 4:

[2130] The server analyzes the email body received using a generative AI model to detect signs of fraud. In this case, the generative AI model (e.g., DistilBERT) analyzes the meaning of the sentence and determines whether it is a scam or phishing scam, such as "Click the link to update your account information." The input is the email body, and the output is a risk assessment as a result of the analysis.

[2131] Step 5:

[2132] The server checks the sender address of the email against a database to evaluate its trustworthiness. It determines the trustworthiness by checking against a list of trusted sender addresses (e.g., trusted_sources). The input is the sender address, and the output is the result of the trustworthiness evaluation.

[2133] Step 6:

[2134] The server extracts the URL from the email and compares it with a safety database. Furthermore, if necessary, it actually checks the URL's destination and evaluates it for signs of fraud. Specifically, it sends an HTTP request to the URL and obtains the analysis results. The input is the URL, and the output is the URL's safety evaluation result.

[2135] Step 7:

[2136] The server performs a risk assessment based on the email body, the reliability assessment of the sender address, and the safety assessment of the URL. The risk assessment is classified as high risk, medium risk, or low risk. The input is the analysis result up to the previous step, and the output is the risk assessment result.

[2137] Step 8:

[2138] The emotion engine built into the device uses a camera and microphone to detect emotions from the user's facial expressions and voice. Specifically, it analyzes camera footage and audio data in real time. The input is the user's facial expression and voice data, and the output is the emotion recognition results.

[2139] Step 9:

[2140] The server adaptively adjusts the risk assessment based on the emotion recognition results. For example, if the user is in an unstable emotional state, the risk assessment is adjusted to be more cautious. The inputs are the emotion recognition results and the risk assessment results, and the output is the adjusted risk assessment results.

[2141] Step 10:

[2142] The server sends the risk assessment result to the terminal, and the terminal notifies the user. If the risk is high, a warning message is displayed, urging the user not to open the email. The input is the adjusted risk assessment result, and the output is the notification message displayed to the user.

[2143] The specific processing unit 290 transmits the result of the specific processing to the robot 414. In the robot 414, the control unit 46A causes the speaker 240 and the control target 443 to output the result of the specific processing. The microphone 238 acquires voice indicating a user input regarding the result of the specific processing. The control unit 46A transmits voice data indicating the user input acquired by the microphone 238 to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the voice data.

[2144] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[2145] In the above embodiment, an example was given in which the specific processing is performed by the data processing device 12, but the technology of the present disclosure is not limited to this, and the specific processing may be performed by the robot 414.

[2146] The emotion identification model 59 as an emotion engine may determine the user's emotion according to a specific mapping. Specifically, the emotion identification model 59 may determine the user's emotion according to an emotion map (see FIG. 9), which is a specific mapping. Similarly, the emotion identification model 59 may determine the robot's emotion, and the identification processing unit 290 may perform identification processing using the robot's emotion.

[2147] FIG. 9 is a diagram illustrating an emotion map 400 on which multiple emotions are mapped. In the emotion map 400, emotions are arranged in concentric circles radiating from the center. Emotions closer to the center of the concentric circles are more primitive. Emotions representing states and actions arising from a state of mind are arranged on the outer edges of the concentric circles. The concept of emotion includes both affect and mental states. Emotions generally generated from reactions occurring in the brain are arranged on the left side of the concentric circles. Emotions generally induced by situational judgment are arranged on the right side of the concentric circles. Emotions generally generated from reactions occurring in the brain and induced by situational judgment are arranged on the upper and lower sides of the concentric circles. Furthermore, the emotion of "pleasure" is arranged on the upper side of the concentric circles, and the emotion of "discomfort" is arranged on the lower side. In this way, in the emotion map 400, multiple emotions are mapped based on the structure by which emotions are generated, and emotions that tend to occur simultaneously are mapped close to each other.

[2148] These emotions are distributed in the 3 o'clock direction on emotion map 400, and typically fluctuate between relief and anxiety. In the right half of emotion map 400, situational awareness dominates over internal sensations, resulting in a sense of calm.

[2149] The inside of emotion map 400 represents what is going on in the mind, and the outside of emotion map 400 represents behavior, so the further you go outside emotion map 400, the more visible the emotions become (the more they are expressed in behavior).

[2150] Human emotions are based on va...

Claims

1. A means for receiving email data; A means for converting received email data into text data; a means for transmitting the text data to a server and analyzing the data on the server side using natural language processing technology; means for performing risk assessment of emails based on the analysis results; means for transmitting the risk assessment result to a terminal and notifying the user; A system including:

2. A means for comparing the sender address with a database to evaluate the reliability of the email, a means for extracting URLs from the email and comparing them with a safety database, A means for actually checking the destination of the URL and evaluating signs of fraud; The system of claim 1 further comprising:

3. A means to update risk assessments based on threat information collected in real time; and means for displaying an immediate warning to a user based on said risk assessment; The system of claim 1 further comprising:

Citation Information

Patent Citations

  • Persona chatbot control method and system

    JP2022180282A