Information processing device, information processing method, and program
The information processing device uses generative AI and prompts to efficiently collect and identify security incidents and organizations, addressing the inefficiencies of existing systems by automating the process.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-08-27
- Publication Date
- 2026-03-11
AI Technical Summary
Existing systems, such as that described in Patent Document 1, do not efficiently collect information related to security incidents using generative AI and prompts, requiring significant manpower and time to identify organizations and types of security incidents.
An information processing device and method that utilizes a collection unit to input instructions into a generative AI model to collect information about security incidents, and an extraction unit to identify the incident and responsible organizations, employing prompts and format information to streamline the process.
Efficiently collects and presents information related to security incidents, enabling rapid identification of organizations involved and the type of incidents, reducing manual effort and time.
Smart Images

Figure 2026042455000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to an information processing device, an information processing method, and a program used for cybersecurity. [Background technology]
[0002] Identifying the organizations (e.g., companies, organizations, etc.) involved in a security incident and the type of security incident requires a lot of manpower and time. Therefore, there is a need for a system that can automatically identify the organizations and types of security incidents involved.
[0003] As a related technology, Patent Document 1 discloses a system that extracts multiple security events from source data natural language text such as news articles, blogs, tweets, etc. The system in Patent Document 1 also uses machine learning techniques to extract security entities such as malware, cybercriminals, and IoCs (Indicators of compromise). [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Special Publication No. 2022-527511 Summary of the Invention [Problem to be solved by the invention]
[0005] However, the system of Patent Document 1 does not use generative AI (artificial intelligence) to efficiently collect information related to security incidents. Specifically, it does not use prompts to collect information related to security incidents.
[0006] One example of a purpose of the present disclosure is to efficiently collect information related to security incidents. [Means for solving the problem]
[0007] In order to achieve the above object, an information processing device according to one aspect of the present disclosure includes: a collection unit that inputs instruction information for collecting information related to a security incident into a model that generates and outputs an answer based on an input instruction, and collects answer information related to the security incident into the model; an extraction unit that extracts information indicating the security incident and information indicating the organization that is the subject of the security incident based on the response information; The present invention is characterized by having the following.
[0008] In order to achieve the above object, an information processing method according to one aspect of the present disclosure includes: The information processing device inputting instruction information for collecting information related to a security incident into a model that generates and outputs a response based on an input instruction, and causing the model to collect response information related to the security incident; extracting information indicating the security incident and information indicating the organization responsible for the security incident based on the response information; It is characterized by:
[0009] Furthermore, in order to achieve the above object, a program according to one aspect of the present disclosure comprises: On the computer, inputting instruction information for collecting information related to a security incident into a model that generates and outputs a response based on an input instruction, and causing the model to collect response information related to the security incident; extracting information indicating the security incident and information indicating the organization responsible for the security incident based on the response information; It is characterized by: [Effects of the Invention]
[0010] As described above, according to the present disclosure, information related to security incidents can be collected efficiently. [Brief explanation of the drawings]
[0011] [Figure 1] FIG. 1 is a diagram illustrating an example of an information processing device. [Figure 2] FIG. 2 is a diagram illustrating an example of a system including an information processing device. [Figure 3] FIG. 3 is a diagram illustrating an example of the content of the instruction information. [Figure 4] FIG. 4 is a diagram illustrating an example of a user interface. [Figure 5] FIG. 5 is a diagram for explaining the filter screen, keyword search screen, word appearance frequency screen, and transition screen. [Figure 6] FIG. 6 is a diagram for explaining the news display screen. [Figure 7] FIG. 7 is a diagram for explaining the security incident type screen and the news media display screen. [Figure 8] FIG. 8 is a diagram for explaining the news details display screen. [Figure 9] FIG. 9 is a diagram illustrating the operation of the information processing device. [Figure 10] FIG. 10 is a diagram illustrating an example of a computer that realizes the information processing device according to the embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0012] Hereinafter, embodiments will be described with reference to the drawings. In the drawings described below, elements having the same or corresponding functions are denoted by the same reference numerals, and repeated description thereof may be omitted.
[0013] (Embodiment) The configuration of an information processing device 10 according to an embodiment will be described with reference to Fig. 1. Fig. 1 is a diagram illustrating an example of an information processing device.
[0014] [Device configuration] 1 is a device that efficiently collects information related to security incidents and presents it to a user (a device that collects information related to security incidents: a security incident collection device, or a device that collects and presents information related to security incidents: a security incident presentation device). Also, as shown in FIG. 1, the information processing device 10 has a collection unit (collection means) 11 and an extraction unit (extraction means) 12.
[0015] The collection unit 11 inputs instruction information for collecting information related to a security incident to a model that generates and outputs an answer based on the input instructions, and causes the model to collect answer information related to the security incident. The extraction unit 12 extracts information indicating the security incident and information indicating the organization that is the subject of the security incident, based on the response information.
[0016] In this manner, in the embodiment, the model is made to collect information related to security incidents, so that information related to security incidents can be collected efficiently.
[0017] [System Configuration] Next, the configuration of the information processing device 10 in the embodiment will be described in more detail with reference to Fig. 2. Fig. 2 is a diagram showing an example of a system including an information processing device.
[0018] As shown in FIG. 2, the system 100 in the embodiment includes an information processing device 10, a storage device 20, an information processing device 30, and an output device 40, which are communicably connected via a network 50.
[0019] The information processing device 10 is, for example, a CPU (Central Processing Unit), a programmable device such as an FPGA (Field-Programmable Gate Array), a GPU (Graphics Processing Unit), or a circuit equipped with one or more of these, a server computer, a personal computer, a mobile terminal, etc.
[0020] The storage device 20 is a database, a server computer, a circuit having a memory, etc. The storage device 20 stores various information (at least instruction information, response information, analysis results, etc.) described later. In the example of Fig. 2, the storage device 20 is provided outside the information processing device 10, but it may also be provided inside the information processing device 10.
[0021] The information processing device 30 is, for example, a CPU equipped with a model such as the generation AI 31, a programmable device such as an FPGA, a GPU, or a circuit equipped with one or more of them, a server computer, a personal computer, etc. However, although the information processing device 30 is provided outside the information processing device 10 in the example of Fig. 2, it may also be provided inside the information processing device 10.
[0022] The generation AI 31 is an artificial intelligence system that generates and outputs new information such as text, images, and audio based on input information. Examples of the generation AI include ChatGPT, Gemini, Claude, and Llama.
[0023] The output device 40 displays at least a user interface 41 that the user uses to perform analysis. The output device 40 acquires output information (described later) converted into an outputtable format, and outputs generated images, sounds, and the like based on the output information. The output device 40 is, for example, an image display device using a liquid crystal, an organic electroluminescence (EL) display, or a cathode ray tube (CRT). The image display device may also include an audio output device such as a speaker. The output device 40 may also be a printing device such as a printer. Although the output device 40 is provided externally to the information processing device 10 in the example of FIG. 2, it may also be provided internally to the information processing device 10.
[0024] Network 50 is a general network constructed using communication lines such as the Internet, a LAN (Local Area Network), a dedicated line, a telephone line, an in-house network, a mobile communication network, Bluetooth (registered trademark), or Wi-Fi (Wireless Fidelity) (registered trademark).
[0025] ●The information processing device will be explained in detail. The information processing device 10 includes a generating unit 13 , a collecting unit 11 , an extracting unit 12 , an analyzing unit 14 , and an output information generating unit 15 .
[0026] The generator 13 generates instruction information for collecting information related to a security incident. The instruction information includes, for example, a system message and a prompt. Note that the instruction information may also be generated by a user.
[0027] The system message is information that represents the context, commands, etc. related to the use case and is used to preprocess the model. The prompt has judgment condition information, subject extraction information, and type judgment information as information to be input to the generation AI 31.
[0028] The judgment condition information is information for determining whether or not a target incident corresponds to a security incident. The subject extraction information is information for extracting the organization that is the subject of the security incident. The type judgment information is information for determining the type of security incident.
[0029] Types of security incidents include, for example, information leaks, ransomware damage, DoS (Denial of Service) attack damage, and unauthorized access.
[0030] Furthermore, the prompt includes, as information to be input into generation AI31, information for extracting the date and time when the security incident occurred (occurrence date and time information) and information for extracting the date and time when the security incident was announced (announcement date and time information).
[0031] Furthermore, the prompt includes format information to be input to the generation AI 31, which is used to make the answer of the generation AI 31 follow a preset format.
[0032] Fig. 3 is a diagram for explaining an example of the content of instruction information. In the example of Fig. 3, the "System Message" reads, "As a member of a security response organization, you are collecting and analyzing news related to cybersecurity."
[0033] In addition, in the example in Figure 3, the "prompt" is written as "Please tell us the name of the company that caused the accident and the date the incident occurred based on the following sentence and input conditions."
[0034] Furthermore, the "prompt" contains input conditions (determination condition information, subject extraction information, type determination information, occurrence date and time information, and announcement date and time information) to specifically indicate the content of the answer. In the example of Figure 3, the following is written as the "input conditions."
[0035] #Input conditions -Answer whether it is a security incident by one of the following: yes no Extract the name of the organization that caused the security incident If the name of the organization that caused the security incident is not stated in the document, answer "unknown." Extract security incident occurrence dates If the date of the security incident is not stated in the document, answer "unknown." Extract security incident announcement dates If the security incident announcement date is not stated in the document, answer "unknown." -Please answer the following questions regarding the type of security incident: Information leakage Ransomware damage DoS attack damage Unauthorized access
[0036] Furthermore, the "prompt" contains information (format information) that specifies the format of the answer to reduce variations in the answers of the generation AI 31. In the example of Figure 3, the "format information" is written as follows. Note that variations in answers occur depending on whether or not there are items ("#" and ":"), whether or not values are entered on the same line, etc.
[0037] #Determining if it's a security incident: #Name of organization that caused the security incident: #Date of security incident: #SecurityIncidentAnnouncementDate: #Type of security incident:
[0038] In addition, information that is the basis for determining the input condition, such as the main text of the news or a summary of the main text of the news, is input in {input1}.
[0039] The collection unit 11 first inputs instruction information for collecting information related to a security incident to a model such as the generation AI 31. When the instruction information is input, the generation AI 31 generates answer information from information such as the main text of the news and a summary of the main text of the news.
[0040] Next, the collection unit 11 collects answer information related to the security incident generated by the model from a model such as the generation AI 31. Specifically, the collection unit 11 acquires answer information generated based on the format of the answer sentence from the generation AI 31, and stores the answer information in the storage device 20.
[0041] The extraction unit 12 first acquires answer information from the collection unit 11 or the storage device 20. Next, the extraction unit 12 extracts answers to each item from the acquired answer information. The extraction unit 12 stores the extracted answers (extracted information) in the storage device 20.
[0042] When using the format information in Figure 3, answers are extracted for each of the following response information items: "#Determining whether it is a security incident:", "#Name of the organization that caused the security incident:", "#Date the security incident occurred:", "#Date the security incident was announced:", and "#Type of security incident:".
[0043] Furthermore, the extraction unit 12 performs a morphological analysis process on the extracted answer (extracted information), dividing it into the smallest meaningful units (morphemes) in language, and classifying the morphemes by part of speech.The extraction unit 12 then creates a list of noun morphemes from the classified morphemes.The extraction unit 12 stores the list (extracted information) in the storage device 20.Specifically, the extraction unit 12 breaks down each of the organization names and news titles from the extracted answer (extracted information) into nouns, and generates a noun list by breaking down each noun.
[0044] When a user performs an analysis using the user interface 41, the analysis unit 14 first executes various analysis functions using the extracted information (extracted answers and list) extracted based on the answer information to obtain the analysis results. Next, the analysis unit 14 stores the analysis results in the storage device 20.
[0045] The analysis functions include, for example, a filter function, a keyword search function, a word frequency display function, a trend display function, a news display function, a news organization display function, a security incident type display function, and a news detail display function.
[0046] The filter function allows you to, for example, narrow down the organization that caused the security incident, narrow down the type of security incident, or narrow down the year / month to be analyzed.
[0047] The keyword search function performs a keyword search using, for example, the name of an organization, the title of a news item, or a summary of the news item, and presents the relevant news item to the user. The function may also display a list of frequently searched keywords and present the user with news items that are attracting attention.
[0048] The word frequency display function, for example, visualizes the frequency of words contained in the organization (word cloud). By breaking down the organization name into nouns and highlighting the most frequently used words, it can absorb variations in the spelling of the organization name.
[0049] The trend display function displays the trend in the number of security incidents by type. For example, the horizontal axis shows time series, and the vertical axis shows the number of incident types in a bar graph. This allows users to understand when and what types of security incidents were occurring most frequently.
[0050] The news display function displays a list of news. For example, news from the same organization is collected and displayed in chronological order. If the news spans multiple days, it is displayed for that period. The displayed information may be exportable.
[0051] The news organization display function displays a list of news organizations. For example, it visualizes the breakdown of news organizations in a compact horizontal bar graph.
[0052] The security incident type display function displays the types of security incidents. For example, it visualizes the breakdown of security incidents by type in a compact horizontal bar graph.
[0053] The news detail display function displays more detailed information about the displayed news. The detailed information may be exported by attaching a URL, for example.
[0054] The various analysis functions described above are performed by a user using a user interface 41 displayed on the output device 40. The user operates the user interface 41 using an input device (not shown). The input device is, for example, a touch panel, a mouse, a keyboard, or the like.
[0055] Based on the analysis results of the analysis unit 14, the output information generation unit 15 generates output information to be output to the user interface 41. Thereafter, the output information generation unit 15 outputs the output information to the output device 40.
[0056] ●Explain the user interface in detail. Fig. 4 is a diagram illustrating an example of a user interface. In the example of Fig. 4, the user interface displays at least one of a filter screen 41a for executing the filter function, a keyword search screen 41b for executing the keyword search function, a word occurrence frequency screen 41c for executing the word occurrence frequency function, a transition screen 41d for executing the transition display function, a news display screen 41e for executing the news display function, a news organization display screen 41f for executing the news organization display function, a security incident type screen 41g for executing the security incident type display function, and a news detail display screen 41h for executing the news detail display function.
[0057] The user interface displays two or more of a filter screen 41a, a keyword search screen 41b, a word frequency screen 41c, a transition screen 41d, a news display screen 41e, a news organization display screen 41f, a security incident type screen 41g, and a news detail display screen 41h side by side. The layout of each screen is not limited to the example in FIG. 4.
[0058] 5 is a diagram for explaining the filter screen, keyword search screen, word appearance frequency screen, and transition screen. Note that the layout of each screen is not limited to the example in FIG.
[0059] The filter screen 41a is a screen for displaying filters for narrowing down the displayed content. In the example of Fig. 5, pull-down menus (combo boxes) are arranged to group by organization, narrow down by type of security incident (case category), narrow down by year (fiscal year), and narrow down by month (month).
[0060] In grouping organizations, the organizations designated by the security management department are grouped based on the noun list of organization names created by the extraction unit 12. For example, if the company name, abbreviation, and names of subsidiaries of Company A all contain "A," the organizations that contain "A" in the noun list are grouped as Company A.
[0061] In the menu for filtering by type of security incident, you can select "All," "DoS attack damage," "Ransomware damage," "Unauthorized access," or "Information leak." "All" indicates that the filtering will target "DoS attack damage," "Ransomware damage," "Unauthorized access," and "Information leak."
[0062] The type of security incident is determined by analyzing the news corresponding to the security incident in question and the summary of that news using generative AI, etc.
[0063] If the type of security incident is "information leak," the news title and summary are checked to see if they contain any words that suggest they are news about personal or customer information, and the news is then judged to be "news about a leak of personal or customer information" or "news about an information leak where the leak of personal or customer information cannot be confirmed." For example, the judgment is made based on whether personal information, customer information, user information, etc. is included in the news title. If personal or customer information is included, the results can be further narrowed down to "leak of personal or customer information" and "information leaks not including personal or customer information."
[0064] In the menu for narrowing down by year and month, you can select "year," "month," "quarter," "first half," or "second half." The year and month are determined based on the date and time of the occurrence of the security incident in question.
[0065] The keyword search screen 41b is used to display a keyword search. In the example of Fig. 5, a free search and frequently searched keywords are displayed.
[0066] In the free search, the information stored in the storage device 20 (organizations related to the security incident, the main text of the news, the title of the news, and the summary of the news) is referenced using the entered keywords, and the organization, the main text of the news, the title of the news, and the summary of the news are searched for.
[0067] Frequently searched keywords are calculated by the number of searches performed in free search and displayed in order of the most frequently searched keywords. This allows you to understand what security incidents other employees within your organization are interested in and to learn about security incidents that are attracting attention. You can also click on each keyword to perform a free search for that keyword.
[0068] Since newness is required for news, the number of keyword searches may be adjusted so that the most recently searched keywords are ranked higher. The number of keyword searches KWn may be adjusted as shown in Equation 1.
[0069] (Number 1) KWn = RKWn - (RKWn × SPN / Cn) KWn: Number of keyword searches RKWn: Actual keyword search count SPN: Number of days since search date Cn: constant, e.g. 7 days
[0070] The word appearance frequency screen 41c is used to display the appearance frequency of words. In the example of Fig. 5, frequently appearing words in organization names and frequently appearing words in news titles are displayed in frequency visualization (word cloud).
[0071] Frequently occurring words in organization names can be called differently depending on the news outlet, so when the AI is used to extract them, variations in the spelling of the organization name occur. For example, the National Center of Incident Readiness and Strategy for Cybersecurity (NCSC) can be spelled differently, such as "National Center of Incident Readiness and Strategy for Cybersecurity (NISC)" or "NISC."
[0072] To automatically identify organizations with the most frequently reported security incidents, frequently occurring words in organization names are calculated by breaking down organization names into nouns and sorting them by frequency, based on information filtered using the filter and keyword search functions. For example, frequently occurring words in organization names are analyzed within a range filtered by year and month, or within a range limited by keywords such as ransomware. In addition, frequently occurring words in organization names highlight nouns that are frequently reported, allowing users to identify nouns commonly used in organization names. As a result, users can quickly identify which organizations are receiving the most coverage for security incidents (i.e., which organizations are attracting the most public attention).
[0073] Specifically, in Figure 5, the frequently occurring words in the organization names are "KADOKADO" and "Nihongo," which are highlighted, suggesting that security incidents involving "KADOKADO" and "Nihongo" are being reported.
[0074] As with organization names, frequently occurring words in news titles are highlighted in order of frequency from data that breaks down the words in news titles into nouns, based on information filtered using the filter function and keyword search function. As a result, you can quickly understand what security incidents are attracting the public's attention.
[0075] Specifically, in the frequently occurring words in the titles of Figure 5, "exciting videos" and "cyber attacks" are highlighted, so it can be inferred that many security incidents related to "exciting videos" and "cyber attacks" are being reported.
[0076] The transition screen 41d is used to display the transition in the number of reported security incidents by type. In the example of Fig. 5, a time chart showing the transition in the number of reported security incidents (cases) is arranged in chronological order.
[0077] The trend of reported security incidents (cases) displays classified security incident types (categories) in a time chart based on information filtered using the filter function and keyword search function. This allows you to understand which security incidents are receiving the most coverage and whether there are security incidents that are being reported in a concentrated manner during a specific period. As a result, you can understand the long-term trends of security incidents.
[0078] The news display screen 41e is used to display a list of news. Fig. 6 is a diagram for explaining the news display screen. In the example of Fig. 6, a list of one or more rows is arranged (displayed) as display items on the news display screen 41e, in which "period of coverage," "name of company / organization," "number of coverage items," and "title" are associated.
[0079] When a report is made over multiple days, if the list is sorted by the date of the report only, security incidents (cases) with the same organization name (company / organization name) but on different report dates will be displayed on separate lines, making it difficult to identify security incidents with the same organization name.
[0080] Visibility is improved by summarizing by the period of coverage (the period from the first to the last report of the same organization). Also, since the period of coverage can be monotonous if it is simply a list of security incidents (cases), summarizing by month (separating each month by headline) makes it easier to find the information you need for a specific period.
[0081] In the example of Figure 6, security incidents (incidents) in June 2024 are displayed. In addition, the date and time when the security incidents occurred in June 2024 ("Reported Period"), the names of organizations related to the KADOKADO Group ("Company / Organization Name"), the number of cases reported ("Number of Reported Cases"), and the titles of the news ("Title") are displayed in association with each other.
[0082] Additionally, by clicking on a line in Figure 6, you can perform a free search using the organization name (company or organization name) of the line you clicked on (drill-down function (deep search function)). For example, in the case of "KADOKADO Nihongo," click on the line for "KADOKADO Nihongo" to perform a free search (automatic execution). This drill-down function is used when investigating security incidents (cases) over a long period of time.
[0083] Users can also broaden the scope of their search by adjusting the free search keywords. For example, if you search for "KADOKADO Nihongo," you can remove "Nihongo" and broaden the scope to just "KADOKADO."
[0084] Furthermore, the news display screen has a function that allows users to export news related to a title by clicking on the title. News data is downloaded in a format such as CSV (comma separated values). As a result, users can efficiently use the downloaded data to create reports and analytical data.
[0085] The security incident type screen 41g is used to display the percentage of incident categories. The news organization display screen 41f is used to display a breakdown of news organizations. Figure 7 is a diagram for explaining the security incident type screen and the news organization display screen. In the example of Figure 7, the percentage of incident categories (security incident types) and the percentage of distribution sites are displayed.
[0086] The percentage of incident categories (security incident types) is used to display the types of security incidents. Based on information filtered using the filter function and keyword search function, the percentage of security incident types (incident categories) is displayed in a bar graph. As a result, users can easily understand which security incidents are occurring most frequently.
[0087] The distribution site ratio is used to display the ratio of distribution sites, etc. It displays the ratio of distribution sites, etc. in a bar graph based on the information narrowed down using the filter function and keyword search function. When using the distribution site ratio to narrow down security incident news to a specific organization (company or group) or specific incident category using the filter function, users can see which media outlets are reporting the most on the filtered subject. After viewing the site ratio, users can also see which media outlets are most likely to provide the information they need.
[0088] However, the display of percentages is not limited to bar graphs. For example, pie charts may be used. The advantage of using bar graphs is that pie charts create a lot of white space and require height, resulting in a lot of wasted white space on the dashboard, whereas bar graphs can be displayed at a lower height and require less white space.
[0089] The news details display screen 41h is used to display news details. Fig. 8 is a diagram for explaining the news details display screen. In the example of Fig. 8, a list of one or more rows is arranged (displayed) as display items on the news details display screen 41h, each associated with "publication date and time," "article category," "distribution site," "title," and "main text (AI summary)."
[0090] The input summary is text data without line breaks and therefore lacks readability. Therefore, the news detail display screen 41h automatically inserts a line break when a period (.) and a comma (,) appear after a certain number of characters, thereby improving the readability of the summary for the user.
[0091] Additionally, clicking on a line in Figure 8 will open the news item in a separate window (drill-down function (deep search function)). There is also a function to export news items related to the title. News items can be downloaded in formats such as CSV (comma separated values). Downloaded data may also be generated with a URL added. As a result, users can efficiently use the downloaded data to create reports and analytical data.
[0092] [Device operation] Next, the operation of the information processing device in the embodiment will be described with reference to FIG. 9. FIG. 9 is a diagram for explaining the operation of the information processing device. In the following description, the diagram will be referenced as appropriate. Furthermore, in the embodiment, an information processing method is implemented by operating the information processing device. Therefore, the description of the information processing method in the embodiment will be replaced with the description of the operation of the information processing device below.
[0093] As shown in FIG. 9, first, the generating unit 13 generates instruction information for collecting information related to a security incident (step A1).
[0094] Next, the collection unit 11 inputs instruction information for collecting information related to the security incident to a model such as the generation AI 31 (step A2).
[0095] Next, the collection unit 11 collects, from a model such as the generation AI 31, response information related to the security incident generated by the model (step A3).
[0096] Next, the extraction unit 12 acquires the answer information from the collection unit 11 or the storage device 20, and extracts answers (extracted information) for each item from the acquired answer information (step A4). Furthermore, in step A4, the extraction unit 12 generates a list (extracted information).
[0097] Next, when the user performs an analysis using the user interface 41, the analysis unit 14 executes various analysis functions (filter function, keyword search function, word occurrence frequency display function, trend display function, news display function, news organization display function, security incident type display function, and news detail display function) using the extracted information (extracted answers and list) extracted based on the answer information to obtain the analysis results (step A5).
[0098] Furthermore, the various analysis functions are performed by a user using a user interface 41 displayed on the output device 40. The user operates the user interface 41 using an input device (not shown).
[0099] Next, the output information generation unit 15 generates output information to be output to the user interface 41 based on the analysis result of the analysis unit 14. Thereafter, the output information generation unit 15 outputs the output information to the output device 40 (step A6).
[0100] [Effects of the embodiment] As described above, according to the embodiment, since the model collects information related to security incidents, the information related to security incidents can be collected efficiently. Furthermore, the information related to security incidents can be presented to the user.
[0101] [program] The program in the embodiment may be any program that causes a computer to execute steps A1 to A6 shown in Fig. 9. By installing and executing this program on a computer, the information processing device and information processing method in the embodiment can be realized. In this case, the processor of the computer functions as a generation unit 13, a collection unit 11, an extraction unit 12, an analysis unit 14, and an output information generation unit 15, and performs processing.
[0102] The program in the embodiment may be executed by a computer system constructed by a plurality of computers, in which case, for example, each computer may function as one of the generating unit 13, collecting unit 11, extracting unit 12, analyzing unit 14, and output information generating unit 15.
[0103] [Physical configuration] A computer that realizes an information processing device by executing a program in the embodiment will now be described with reference to Fig. 10. Fig. 10 is a diagram illustrating an example of a computer that realizes an information processing device in the embodiment.
[0104] 10, the computer 110 includes a CPU (Central Processing Unit) 111, a main memory 112, a storage device 113, an input interface 114, a display controller 115, a data reader / writer 116, and a communication interface 117. These components are connected to each other via a bus 121 so as to be able to communicate data with each other. Note that the computer 110 may include a GPU or an FPGA in addition to or instead of the CPU 111.
[0105] The CPU 111 loads a program in the embodiment, which is composed of a group of codes and stored in the storage device 113, into the main memory 112 and executes each code in a predetermined order to perform various calculations. The main memory 112 is typically a volatile storage device such as a DRAM (Dynamic Random Access Memory).
[0106] The program in the embodiment is provided in a state stored in a computer-readable recording medium 120. The program in the embodiment may be distributed over the Internet connected via the communication interface 117.
[0107] Specific examples of the storage device 113 include a hard disk drive and a semiconductor storage device such as a flash memory. The input interface 114 mediates data transmission between the CPU 111 and input devices 118 such as a keyboard and a mouse. The display controller 115 is connected to a display device 119 and controls the display on the display device 119.
[0108] The data reader / writer 116 mediates data transmission between the CPU 111 and the recording medium 120, reads programs from the recording medium 120, and writes processing results from the computer 110 to the recording medium 120. The communication interface 117 mediates data transmission between the CPU 111 and other computers.
[0109] Specific examples of the recording medium 120 include general-purpose semiconductor storage devices such as CF (Compact Flash (registered trademark)) and SD (Secure Digital), magnetic recording media such as flexible disks, or optical recording media such as CD-ROMs (Compact Disk Read Only Memory).
[0110] The information processing device 10 in the embodiment can be realized not by a computer on which a program is installed, but by hardware corresponding to each unit, for example, an electronic circuit. Furthermore, the information processing device 10 may be partially realized by a program and the remaining unit by hardware. In the embodiment, the computer is not limited to the computer shown in FIG. 10.
[0111] [Note] The following supplementary notes are further provided with respect to the above-described embodiments. Some or all of the above-described embodiments can be expressed by (Supplementary Note 1) to (Supplementary Note 24) described below, but are not limited to the following descriptions.
[0112] (Appendix 1) a collection unit that inputs instruction information for collecting information related to a security incident into a model that generates and outputs a response based on an input instruction, and causes the model to collect response information related to the security incident; an extraction unit that extracts information indicating the security incident and information indicating the organization that is the subject of the security incident based on the response information; An information processing device having the above.
[0113] (Appendix 2) The instruction information includes determination condition information for determining whether the security incident corresponds to a security incident, subject extraction information for extracting an organization that is a subject of the security incident, and type determination information for determining the type of the security incident. 2. The information processing device according to claim 1.
[0114] (Appendix 3) The types of security incidents are information leaks, ransomware damage, DoS (Denial of Service) attack damage, and unauthorized access. 3. The information processing device according to claim 2.
[0115] (Appendix 4) The instruction information further includes information for extracting the date and time when the security incident occurred, and information for extracting the date and time when an announcement was made regarding the security incident. 4. The information processing device according to claim 2 or 3.
[0116] (Appendix 5) The instruction information further includes format information for causing the model to respond in accordance with a preset format. 5. An information processing device according to any one of appendices 2 to 4.
[0117] (Appendix 6) Furthermore, an analysis means for analyzing information extracted based on the response information; an output information generating means for generating output information to be output to a user interface based on the analysis result of the analyzing means; 6. An information processing device according to any one of appendices 1 to 5.
[0118] (Appendix 7) The user interface displays at least one of a filter screen for displaying a filter for narrowing down the display content, a keyword search screen for displaying a keyword search, a word occurrence frequency screen for displaying the frequency of occurrence of words, a transition screen for displaying the transition in the number of reported security incidents by type, a news display screen for displaying a list of news, a news organization display screen for displaying a breakdown of news organizations, a security incident type screen for displaying the type of security incident, and a news detail display screen for displaying news details. 7. The information processing device according to claim 6.
[0119] (Appendix 8) two or more of the filter screen, the keyword search screen, the word appearance frequency screen, the transition screen, the news display screen, the news organization display screen, the security incident type screen, and the news detail display screen are displayed side by side on the user interface; 8. The information processing device according to claim 7.
[0120] (Appendix 9) The information processing device inputting instruction information for collecting information related to a security incident into a model that generates and outputs a response based on an input instruction, and causing the model to collect response information related to the security incident; extracting information indicating the security incident and information indicating the organization responsible for the security incident based on the response information; Information processing methods.
[0121] (Appendix 10) The instruction information includes determination condition information for determining whether the security incident corresponds to a security incident, subject extraction information for extracting an organization that is a subject of the security incident, and type determination information for determining the type of the security incident. 10. The information processing method according to claim 9.
[0122] (Appendix 11) The types of security incidents are information leaks, ransomware damage, DoS (Denial of Service) attack damage, and unauthorized access. 11. The information processing method according to claim 10.
[0123] (Appendix 12) The instruction information further includes information for extracting the date and time when the security incident occurred, and information for extracting the date and time when an announcement was made regarding the security incident. 12. The information processing method according to claim 10 or 11.
[0124] (Appendix 13) The instruction information further includes format information for causing the model to respond in accordance with a preset format. 13. An information processing method according to any one of appendices 10 to 12.
[0125] (Appendix 14) Furthermore, the information processing device Analyzing information extracted based on the response information; generating output information based on the analysis results for use in outputting the user interface; 14. An information processing method according to any one of appendices 9 to 13.
[0126] (Appendix 15) The user interface displays at least one of a filter screen for displaying a filter for narrowing down the display content, a keyword search screen for displaying a keyword search, a word occurrence frequency screen for displaying the frequency of occurrence of words, a transition screen for displaying the transition in the number of reported security incidents by type, a news display screen for displaying a list of news, a news organization display screen for displaying a breakdown of news organizations, a security incident type screen for displaying the type of security incident, and a news detail display screen for displaying news details. 15. The information processing method according to claim 14.
[0127] (Appendix 16) two or more of the filter screen, the keyword search screen, the word appearance frequency screen, the transition screen, the news display screen, the news organization display screen, the security incident type screen, and the news detail display screen are displayed side by side on the user interface; 16. The information processing method according to claim 15.
[0128] (Appendix 17) On the computer, inputting instruction information for collecting information related to a security incident into a model that generates and outputs a response based on an input instruction, and causing the model to collect response information related to the security incident; extracting information indicating the security incident and information indicating the organization responsible for the security incident based on the response information; program.
[0129] (Appendix 18) The instruction information includes determination condition information for determining whether the security incident corresponds to a security incident, subject extraction information for extracting an organization that is a subject of the security incident, and type determination information for determining the type of the security incident. 17. The program described in Appendix 17.
[0130] (Appendix 19) The types of security incidents are information leaks, ransomware damage, DoS (Denial of Service) attack damage, and unauthorized access. 18. The program described in Appendix 18.
[0131] (Appendix 20) The instruction information further includes information for extracting the date and time when the security incident occurred, and information for extracting the date and time when an announcement was made regarding the security incident. 19. The program according to claim 18 or 19.
[0132] (Appendix 21) The instruction information further includes format information for causing the model to respond in accordance with a preset format. 21. The program of any one of appendices 18 to 20.
[0133] (Appendix 22) Furthermore, the information processing device Analyzing information extracted based on the response information; generating output information based on the analysis results for use in outputting the user interface; 22. The program of any one of appendices 17 to 21.
[0134] (Appendix 23) The user interface displays at least one of a filter screen for displaying a filter for narrowing down the display content, a keyword search screen for displaying a keyword search, a word occurrence frequency screen for displaying the frequency of occurrence of words, a transition screen for displaying the transition in the number of reported security incidents by type, a news display screen for displaying a list of news, a news organization display screen for displaying a breakdown of news organizations, a security incident type screen for displaying the type of security incident, and a news detail display screen for displaying news details. 22. The program of claim 1.
[0135] (Appendix 24) two or more of the filter screen, the keyword search screen, the word appearance frequency screen, the transition screen, the news display screen, the news organization display screen, the security incident type screen, and the news detail display screen are displayed side by side on the user interface; 23. The program described in Appendix 23.
[0136] Although the present invention has been described above with reference to the embodiments, the present invention is not limited to the above-described embodiments. Various modifications that can be understood by those skilled in the art can be made to the configuration and details of the present invention within the scope of the present invention. [Industrial Applicability]
[0137] According to the above description, information related to security incidents can be collected efficiently, and is useful in fields where security incident analysis is required. [Explanation of symbols]
[0138] 10. Information processing equipment 11 Collection Department 12 Extraction part 13 Generation part 14 Analysis Department 15 Output information generation unit 20 Storage device 30 Information processing equipment 40 Output Devices 41 User Interface 50 Network 100 systems 110 Computer 111 CPU 112 main memory 113 Storage device 114 Input Interface 115 Display Controller 116 Data Reader / Writer 117 Communication Interface 118 Input Devices 119 Display Device 120 Recording Media 121 Bus
Claims
1. a collection means for inputting instruction information for collecting information related to a security incident into a model that generates and outputs a response based on an input instruction, and causing the model to collect response information related to the security incident; an extraction means for extracting information indicating the security incident and information indicating the organization responsible for the security incident based on the response information; An information processing device having the above.
2. The instruction information includes determination condition information for determining whether the security incident corresponds to a security incident, subject extraction information for extracting an organization that is a subject of the security incident, and type determination information for determining the type of the security incident. The information processing device according to claim 1 .
3. The types of security incidents are information leakage, ransomware damage, DoS (Denial of Service) attack damage, and unauthorized access. The information processing device according to claim 2 .
4. The instruction information further includes information for extracting the date and time when the security incident occurred, and information for extracting the date and time when an announcement was made regarding the security incident. The information processing device according to claim 2 .
5. The instruction information further includes format information for causing the model to respond in accordance with a preset format. The information processing device according to claim 2 .
6. Furthermore, an analysis means for analyzing information extracted based on the response information; an output information generating means for generating output information to be output to a user interface based on the analysis result of the analyzing means; The information processing device according to claim 1 .
7. The user interface displays at least one of a filter screen for displaying a filter for narrowing down the display content, a keyword search screen for displaying a keyword search, a word occurrence frequency screen for displaying the frequency of occurrence of words, a transition screen for displaying the transition in the number of reported security incidents by type, a news display screen for displaying a list of news, a news organization display screen for displaying a breakdown of news organizations, a security incident type screen for displaying the type of security incident, and a news detail display screen for displaying news details. The information processing device according to claim 6 .
8. two or more of the filter screen, the keyword search screen, the word appearance frequency screen, the transition screen, the news display screen, the news organization display screen, the security incident type screen, and the news detail display screen are displayed side by side on the user interface; The information processing device according to claim 7 .
9. The information processing device inputting instruction information for collecting information related to a security incident into a model that generates and outputs a response based on an input instruction, and causing the model to collect response information related to the security incident; extracting information indicating the security incident and information indicating the organization responsible for the security incident based on the response information; Information processing methods.
10. On the computer, inputting instruction information for collecting information related to a security incident into a model that generates and outputs a response based on an input instruction, and causing the model to collect response information related to the security incident; extracting information indicating the security incident and information indicating the organization responsible for the security incident based on the response information; program.
Citation Information
Patent Citations
Inferring temporal relationships about cybersecurity events
JP2022527511A