system

The system uses generative AI for real-time threat prediction and automated responses to enhance cyber security in high-impact industries, addressing the inadequacies of conventional measures by quickly detecting and mitigating cyberattacks.

JP2026062237APending Publication Date: 2026-04-09SOFTBANK GROUP CORP
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-09-30
Publication Date
2026-04-09

AI Technical Summary

Technical Problem

Conventional cyber security measures are inadequate in responding quickly to sophisticated cyberattacks, lacking automated means for immediate threat detection and countermeasures, especially in industries with high information density and economic impact.

Method used

A system utilizing generative AI for real-time data analysis, anomaly detection, threat prediction, and automated response, including data collection from terminals, machine learning for normal pattern generation, and automated countermeasures such as firewall adjustments and IP blocking.

Benefits of technology

Enables rapid and effective protection against cyber threats by predicting future attacks and executing countermeasures, ensuring quick response and minimizing damage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026062237000001_ABST
    Figure 2026062237000001_ABST
Patent Text Reader

Abstract

We provide the system. [Solution] A means for collecting data from multiple terminals within a distributed network in order to detect abnormal patterns in real time, A data analysis means for generating normal activity patterns and creating a reference pattern based on the aforementioned data, A threat prediction method using generative AI that detects anomalies that deviate from the aforementioned standard pattern and predicts future attack patterns, An automated response means that automatically generates and executes countermeasures in response to anomalies detected by the threat prediction means, Alert sending means for notifying the administrator of the results of the response by the automated response means. A system that includes this.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0004] , , , ,

[0005] , , , ,

[0001] The technology of the present disclosure relates to a system.

Background Art

[0002] Patent Document 1 discloses a method for controlling a persona chatbot, which is performed by at least one processor, including steps of receiving a user utterance, adding the user utterance to a prompt including an instruction sentence related to an explanation of the chatbot's character, encoding the prompt, and inputting the encoded prompt into a language model to generate a chatbot utterance in response to the user utterance.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] Modern digital crimes are becoming more sophisticated and frequent. In particular, cyberattacks against industries with high information density and significant economic impact (such as government, finance, and communication) pose serious risks. Conventional cyber security measures cannot quickly respond to newly emerging complex attack methods and may cause significant damage. In addition, there is a lack of automated means to immediately take countermeasures, and the delay in threat response has become a problem. The purpose of the present invention is to solve these problems by predicting future attacks, detecting anomalies in real time, and automatically executing countermeasures.

Means for Solving the Problems

[0005] The present invention solves the above problem with a system that includes means for collecting data from multiple terminals in a distributed network in order to detect abnormal patterns in real time; data analysis means for generating normal activity patterns and creating a reference pattern based on the data; threat prediction means using generative AI to detect abnormalities that deviate from the reference pattern and predict future attack patterns; automated response means for automatically generating and executing countermeasures against abnormalities detected by the threat prediction means; and alert sending means for notifying the administrator of the results of the response by the automated response means. In particular, the data analysis means detects abnormalities using a machine learning algorithm, and the automated response means realizes rapid and effective countermeasures by automatically changing firewall settings, disconnecting specific terminals from the network, and blocking harmful IP addresses.

[0006] "Data collection" is the process of gathering information such as log data, traffic information, and user activity in real time from multiple terminals within a distributed network.

[0007] "Data analysis" is the process of using machine learning algorithms and other analytical methods to generate normal activity patterns and create baseline patterns based on collected data.

[0008] A "reference pattern" is a model or pattern that is generated based on normal activity data and serves as a standard for detecting anomalies.

[0009] "Threat prediction" is a process that uses generative AI to detect data that deviates from a set pattern and predicts future cyberattack patterns based on that data.

[0010] "Generative AI" refers to an automated learning system that combines machine learning algorithms and other artificial intelligence technologies, used for threat prediction.

[0011] "Automated response" refers to the process of automatically generating and executing recommended countermeasures based on detected anomalies and threats, using a generative AI.

[0012] "Alert generation" is the process of notifying administrators in real time of the results and status of an automated response to an anomaly or threat.

[0013] "Firewall settings" refer to the process of configuring settings such as allowing or blocking communications in order to ensure network security.

[0014] "IP address blocking" is a security measure that restricts or blocks access from harmful IP addresses.

[0015] "Real-time analysis" is a process that monitors and analyzes current data in real time to detect anomalies immediately.

[0016] "Risk level" is an index used to evaluate the severity of detected anomalies and threats based on the results of threat prediction.

[0017] "Administrator notification" is the process of notifying system administrators and relevant parties of details about anomalies detected within a system or network, and the automated responses taken. [Brief explanation of the drawing]

[0018] [Figure 1] This is a conceptual diagram showing an example of the configuration of a data processing system according to the first embodiment. [Figure 2] This is a conceptual diagram showing an example of the essential functions of a data processing device and a smart device according to the first embodiment. [Figure 3] This is a conceptual diagram showing an example of the configuration of a data processing system according to the second embodiment. [Figure 4] This is a conceptual diagram showing an example of the main functions of a data processing device and smart glasses according to the second embodiment. [Figure 5]It is a conceptual diagram showing an example of the configuration of a data processing system according to the third embodiment. [Figure 6] It is a conceptual diagram showing an example of the main functions of a data processing device and a headset-type terminal according to the third embodiment. [Figure 7] It is a conceptual diagram showing an example of the configuration of a data processing system according to the fourth embodiment. [Figure 8] It is a conceptual diagram showing an example of the main functions of a data processing device and a robot according to the fourth embodiment. [Figure 9] It shows an emotion map to which a plurality of emotions are mapped. [Figure 10] It shows an emotion map to which a plurality of emotions are mapped. [Figure 11] It is a sequence diagram showing the processing flow of the data processing system in Example 1. [Figure 12] It is a sequence diagram showing the processing flow of the data processing system in Application Example 1. [Figure 13] It is a sequence diagram showing the processing flow of the data processing system in Example 2 when an emotion engine is combined. [Figure 14] It is a sequence diagram showing the processing flow of the data processing system in Application Example 2 when an emotion engine is combined.

Embodiments for Carrying Out the Invention

[0019] Hereinafter, an example of an embodiment of a system according to the technology of the present disclosure will be described with reference to the accompanying drawings.

[0020] First, the terms used in the following description will be explained.

[0021] In the following embodiments, the signed processor (hereinafter simply referred to as "processor") may be a single arithmetic unit or a combination of multiple arithmetic units. Furthermore, the processor may be a single type of arithmetic unit or a combination of multiple types of arithmetic units. Examples of arithmetic units include CPU (Central Processing Unit), GPU (Graphics Processing Unit), GPGPU (General-Purpose computing on Graphics Processing Units), and APU (Accelerated Processing Unit).

[0022] In the following embodiments, signed RAM (Random Access Memory) is a memory that temporarily stores information and is used as work memory by the processor.

[0023] In the following embodiments, the signed storage is one or more non-volatile storage devices that store various programs and various parameters. Examples of non-volatile storage devices include flash memory (SSD (Solid State Drive)), magnetic disks (e.g., hard disks), or magnetic tapes.

[0024] In the following embodiments, the signed communication interface (I / F) is an interface that includes a communication processor and an antenna, etc. The communication interface manages communication between multiple computers. Examples of communication standards applicable to the communication interface include wireless communication standards such as 5G (5th Generation Mobile Communication System), Wi-Fi (registered trademark), or Bluetooth (registered trademark).

[0025] In the following embodiments, "A and / or B" is synonymous with "at least one of A and B." That is, "A and / or B" means that it may be A alone, or B alone, or a combination of A and B. Furthermore, in this specification, the same concept as "A and / or B" applies when expressing three or more things linked by "and / or."

[0026] [First Embodiment]

[0027] Figure 1 shows an example of the configuration of the data processing system 10 according to the first embodiment.

[0028] As shown in Figure 1, the data processing system 10 includes a data processing device 12 and a smart device 14. An example of the data processing device 12 is a server.

[0029] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[0030] The smart device 14 comprises a computer 36, a reception device 38, an output device 40, a camera 42, and a communication interface 44. The computer 36 comprises a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The reception device 38, output device 40, and camera 42 are also connected to the bus 52.

[0031] The reception device 38 is equipped with a touch panel 38A and a microphone 38B, etc., and receives user input. The touch panel 38A receives user input by detecting contact with an object (e.g., a pen or finger). The microphone 38B receives user input by detecting the user's voice. The control unit 46A transmits data indicating the user input received by the touch panel 38A and microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the data indicating the user input.

[0032] The output device 40 includes a display 40A and a speaker 40B, and presents data to the user 20 by outputting the data in a form perceptible to the user 20 (e.g., audio and / or text). The display 40A displays visible information such as text and images according to instructions from the processor 46. The speaker 40B outputs audio according to instructions from the processor 46. The camera 42 is a small digital camera equipped with an optical system such as a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor.

[0033] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various types of information between processor 46 and processor 28 via network 54.

[0034] Figure 2 shows an example of the main functions of the data processing device 12 and the smart device 14.

[0035] As shown in Figure 2, in the data processing device 12, a specific processing is performed by the processor 28. A specific processing program 56 is stored in the storage 32. The specific processing program 56 is an example of a "program" related to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 according to the specific processing program 56 executed on the RAM 30.

[0036] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[0037] In the smart device 14, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The reception output program 60 is used in conjunction with a specific processing program 56 by the data processing system 10. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.

[0038] Next, the specific processing performed by the specific processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the smart device 14 as the "terminal".

[0039] The present invention will now describe specific embodiments for carrying out the invention. The present invention is a system for preventing digital crime against industries with high information density and significant economic impact (e.g., government, finance, telecommunications, etc.). This system has multiple functions, including detection of abnormal patterns, threat prediction, automated response, and administrator notification.

[0040] 1. Data Collection

[0041] Subject: Server

[0042] First, the server continuously collects log data and traffic information in real time from multiple terminals within the network. The server stores this data in a central database and prepares it for analysis. APIs and log analysis tools are used during this process.

[0043] 2. Data Analysis and Reference Pattern Generation

[0044] Subject: Server

[0045] Next, the server uses a data analysis module to analyze the large amount of data it has collected. This analysis employs machine learning algorithms to generate normal activity patterns (reference patterns). Based on these reference patterns, abnormal data is detected.

[0046] 3. Real-time analysis and anomaly detection

[0047] Subject: Generative AI

[0048] Generative AI scans data in real time to detect unusual activity and traffic patterns. This AI compares historical data with baseline patterns to quickly identify anomalies. In this process, for example, sudden large-scale data transfers or unusual login attempts may be detected.

[0049] 4. Threat prediction and risk assessment

[0050] Subject: Generative AI

[0051] Generative AI predicts future attack patterns based on detected anomalies. This prediction utilizes known threat databases and simulation methods. Based on the prediction results, the risk level is assessed. Risk levels are categorized into low, medium, and high, and the priority of response is determined accordingly.

[0052] 5. Generation and execution of automated responses

[0053] Subject: Generative AI

[0054] The generative AI generates automated response scenarios based on the risk level. For example, if a high risk is detected, the AI ​​automatically modifies firewall settings, blocks harmful IP addresses, and disconnects specific devices from the network. In the case of medium risk, it enhances system log monitoring and issues warnings for specific actions.

[0055] 6. Alert generation and administrator notifications

[0056] Subject: Generative AI

[0057] Finally, after the generative AI completes automated response measures, it sends a real-time notification to the administrator, including the results. This notification is delivered via email, SMS, dashboard, etc. Furthermore, a detailed report is generated and provided for administrator review. This report includes detected anomalies, implemented countermeasures, and risk assessments.

[0058] Specific example

[0059] Specific example 1: Suspicious transactions at financial institutions

[0060] Subject: Server

[0061] A server monitors financial institutions' transaction data in real time, and the server then uses a generative AI to analyze the transaction data. The generative AI detects unusually high-value transactions, compares them to past fraud patterns, and determines that there is a high probability of fraud.

[0062] Subject: Generative AI

[0063] The generation AI automatically implements a temporary freeze measure and sends an alert to the administrator. The administrator reviews the detailed report provided and conducts further investigation.

[0064] Specific example 2: Cyberattacks on government agencies

[0065] Subject: Server

[0066] A server monitors government agency communication traffic 24 hours a day. The server detects unusual large-scale file transfers, and a generative AI analyzes them.

[0067] Subject: Generative AI

[0068] The generating AI identifies a high-risk situation and automatically modifies firewall settings and blocks suspicious IP addresses. It also disconnects the affected devices from the network and sends an emergency alert to the administrator. The administrator reviews the generated detailed report and takes further action.

[0069] As described above, this system, with its advanced AI technology and automated security measures, can quickly and effectively protect critical industries from digital crime.

[0070] The following describes the processing flow.

[0071] Step 1: Data Collection

[0072] Subject: Server

[0073] The server collects data in real time from multiple terminals within a distributed network. Specifically, it retrieves log data, user activity information, network traffic, etc., from each terminal using APIs and stores them in a central database. The collected data is recorded and stored in a consistent manner.

[0074] Step 2: Data analysis and reference pattern generation

[0075] Subject: Server

[0076] The server starts the data analysis module and begins analyzing the collected data. It applies machine learning algorithms to learn normal activity patterns and generate baseline patterns. These baseline patterns are used as templates for anomaly detection.

[0077] Step 3: Real-time analysis and anomaly detection

[0078] Subject: Generative AI

[0079] Generative AI scans new data in real time to detect any anomalous patterns that deviate from the baseline. If an anomaly is found, it analyzes its details to identify the type of anomaly. For example, large-scale data transfers or unusual login attempts might be detected here.

[0080] Step 4: Threat prediction and risk assessment

[0081] Subject: Generative AI

[0082] The generative AI predicts future attack patterns based on detected anomalies. It compares these predictions with existing threat intelligence stored in a database to assess the risk level of new attacks. The risk level is classified as low, medium, or high, and countermeasures are determined.

[0083] Step 5: Generate automated responses

[0084] Subject: Generative AI

[0085] The generation AI automatically generates response scenarios based on the risk level. For example, if a high risk is detected, specific countermeasures such as blocking IP addresses, disconnecting specific devices from the network, and changing firewall settings are generated.

[0086] Step 6: Execute automated response

[0087] Subject: Generative AI

[0088] Based on automated response scenarios generated by a generative AI, security measures are executed sequentially. For example, harmful IP addresses are immediately blocked, and specific devices are isolated from the network.

[0089] Step 7: Alert generation and administrator notification

[0090] Subject: Generative AI

[0091] The generative AI notifies administrators of the results of its automated response. Notifications are sent in real time via email, SMS, dashboards, etc. A detailed report is also generated for administrator review. This report includes detected anomalies, implemented countermeasures, and risk assessments.

[0092] By following these steps, it is possible to effectively prevent digital crimes against industries with high information confidentiality and to respond quickly.

[0093] (Example 1)

[0094] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server," and the smart device 14 will be referred to as the "terminal."

[0095] In today's advanced information society, industries with high information density and significant economic impact (e.g., government, finance, telecommunications) are particularly vulnerable to cyberattacks. Advanced security measures are necessary to prevent digital crime against these industries. However, conventional systems struggle with rapid and effective anomaly detection, threat prediction, and automated response.

[0096] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.

[0097] In this invention, the server includes means for collecting data from multiple terminals in a distributed network in order to detect abnormal patterns in real time; data analysis means for generating normal activity patterns and creating a baseline pattern based on the data; threat prediction means using generative AI to detect anomalies that deviate from the baseline pattern and predict future attack patterns; automated response means for automatically generating and executing countermeasures against anomalies detected by the threat prediction means; and alert issuing means for notifying the administrator of the results of the response by the automated response means. This enables rapid and effective prevention of digital crime and makes it possible to protect critical industries more securely.

[0098] An "abnormal pattern" refers to data or behavior that deviates from normal activity patterns.

[0099] "Data collection method" refers to a system that collects log data, traffic information, and other data from multiple terminals within a distributed network.

[0100] "Data analysis methods" refer to technologies and algorithms that analyze collected data, generate normal activity patterns, and create baseline patterns.

[0101] A "reference pattern" is a definition of a normal activity pattern generated by data analysis methods, and serves as a criterion for detecting abnormal patterns.

[0102] "Generative AI" refers to technologies that use machine learning and artificial intelligence to detect anomalies and perform threat prediction and risk assessment.

[0103] "Threat prediction methods" refer to technologies that use generative AI to detect anomalies that deviate from standard patterns and predict future attack patterns.

[0104] "Automated response measures" refer to technologies that automatically generate and execute appropriate countermeasures in response to anomalies detected by threat prediction measures.

[0105] "Alert notification method" refers to technology used to notify administrators of the results of responses by automated response methods.

[0106] A "machine learning algorithm" refers to an algorithm used in data analysis, specifically a statistical method or model used for anomaly detection.

[0107] "Automatic firewall settings change" refers to a function that automatically changes the settings of the system's protective barrier.

[0108] "Disconnecting a specific device from the network" refers to a function that isolates devices exhibiting abnormal behavior from the network.

[0109] "Blocking harmful IP addresses" refers to a function that blocks IP addresses that may be used for malicious communication.

[0110] This invention is a system for preventing digital crime against industries with high information sensitivity and significant economic impact. This system has multiple functions, including detection of anomalous patterns, threat prediction, automated response, and administrator notification. The specific implementation method of this system is described below.

[0111] Data collection

[0112] Subject: Server

[0113] The server continuously collects log data and traffic information in real time from multiple terminals within a distributed network. Data is efficiently acquired using log analysis tools such as the syslog protocol, NetFlow, and sFlow. The collected data is stored in a NoSQL database (e.g., MongoDB) and organized for later analysis.

[0114] Data analysis and reference pattern generation

[0115] Subject: Server

[0116] Next, the server analyzes the collected data and generates normal activity patterns. Using Python and Scikit-learn, the data is preprocessed, and then a clustering algorithm (e.g., K-means) is executed to create a baseline pattern. This generated baseline pattern forms the basis for anomaly detection.

[0117] Real-time analysis and anomaly detection

[0118] Subject: Generative AI

[0119] Generative AI scans data in real time and uses deep learning frameworks such as TENSORFLOW® to compare generated baseline patterns with historical data. Anomaly detection algorithms such as autoencoders are used to quickly identify anomalous traffic and activity.

[0120] Threat prediction and risk assessment

[0121] Subject: Generative AI

[0122] Generative AI predicts threats and performs risk assessments based on detected anomalies. This is done using the MITRE ATT&CK framework and LSTM models. For predicted attack patterns, it evaluates the risk level as low, medium, or high and determines the priority of response.

[0123] Generation and execution of automated responses

[0124] Subject: Generative AI

[0125] The generative AI generates and executes automated response scenarios based on risk levels. In high-risk cases, it automatically modifies firewall settings using iptables commands to block harmful IP addresses. It also automatically disconnects devices exhibiting abnormal activity from the network.

[0126] Alert generation and administrator notifications

[0127] Subject: Generative AI

[0128] The generative AI notifies administrators of the results of its automated responses. These notifications are sent via email APIs and SMS gateways, and the results are also displayed on a dedicated web dashboard. Furthermore, a detailed report is generated and provided to administrators.

[0129] Specific example

[0130] Specific example 1: Suspicious transactions at financial institutions

[0131] Subject: Server

[0132] The server monitors financial institutions' transaction data in real time, and a generative AI analyzes that data. The generative AI detects unusually high-value transactions and determines that they are highly likely to be fraudulent.

[0133] Subject: Generative AI

[0134] The generation AI automatically implements a temporary freeze measure and sends an alert to the administrator. The administrator reviews a detailed report and conducts further investigation.

[0135] Specific example 2: Cyberattacks on government agencies

[0136] Subject: Server

[0137] The server monitors government agency communication traffic 24 hours a day. The server detects unusual large-scale file transfers, and generative AI analyzes them.

[0138] Subject: Generative AI

[0139] The generation AI identifies a high-risk situation and automatically takes action such as changing firewall settings and blocking suspicious IP addresses. It also disconnects the relevant devices from the network and sends an emergency alert to the administrator. The administrator reviews the generated detailed report and takes further action.

[0140] Example of a prompt

[0141] "Detect anomalous patterns from the given traffic data, compare them to relevant past attack patterns to perform a risk assessment, and then generate appropriate automated countermeasures."

[0142] This invention combines advanced AI technology with automated security measures to quickly and effectively protect critical industries from digital crime.

[0143] The flow of the specific processing in Example 1 will be explained using Figure 11.

[0144] Step 1: Data Collection

[0145] Subject: Server

[0146] Input: Log data and traffic information sent from multiple terminals within a distributed network.

[0147] Specific operation: The server uses the syslog protocol, NetFlow, and sFlow to retrieve log data and traffic information from each terminal. The server uses ping to verify connectivity with each terminal, then starts the syslog daemon to collect log data. It also uses a NetFlow collector to collect traffic information. The collected data is stored in a NoSQL database (e.g., MongoDB).

[0148] Output: Log data and traffic information stored in the database

[0149] Step 2: Data analysis and reference pattern generation

[0150] Subject: Server

[0151] Input: Log data and traffic information stored in the database

[0152] Specific operation: The server analyzes log data and traffic information using Python and Scikit-learn. Data preprocessing includes denoising and data standardization. Then, a clustering algorithm (e.g., K-means) is executed to create a baseline pattern. The generated baseline pattern is then saved back into the database.

[0153] Output: Database where the reference pattern is stored.

[0154] Step 3: Real-time analysis and anomaly detection

[0155] Subject: Generative AI

[0156] Input: Real-time acquired log data and traffic information, baseline patterns

[0157] Specific operation: Generative AI scans data in real time and compares it with historical data and baseline patterns. TensorFlow is used to perform anomaly detection with an Autoencoder algorithm. When abnormal traffic or activity is detected, an alert is generated.

[0158] Output: Anomaly detection results and alerts

[0159] Step 4: Threat prediction and risk assessment

[0160] Subject: Generative AI

[0161] Input: Data on detected anomalies, baseline patterns, and known threat databases.

[0162] Specific operation: Generative AI analyzes detected anomalies using the MITRE ATT&CK framework and LSTM models. It compares them with a known threat database to predict future attack patterns. Risk is assessed in three stages: "low," "medium," and "high," and the priority of response is determined.

[0163] Output: Risk assessment and predicted threat patterns

[0164] Step 5: Generate and execute automated responses

[0165] Subject: Generative AI

[0166] Input: Risk assessment results, anomaly detection results

[0167] Specific operation: The generative AI generates automated response scenarios based on the risk level. In high-risk cases, it modifies firewall settings using iptables commands to block harmful IP addresses. It also automatically disconnects devices exhibiting abnormal activity from the network.

[0168] Output: Automated countermeasures taken and their results

[0169] Step 6: Alert generation and administrator notification

[0170] Subject: Generative AI

[0171] Input: Automated response results, anomaly detection results, risk assessment

[0172] Specific operation: The generative AI notifies the administrator of the results of its automated response. Communication is conducted via email API and SMS gateway, and the results are displayed on a web dashboard. A detailed report is generated for the administrator to review.

[0173] Output: Notification to administrator and detailed report

[0174] (Application Example 1)

[0175] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server," and the smart device 14 will be referred to as the "terminal."

[0176] Current security systems often lack sufficient capabilities to detect anomalies in real time and respond immediately. Furthermore, even when an anomaly is detected, there is a lack of systems that efficiently notify administrators and quickly implement countermeasures. In addition, few systems have reporting capabilities that allow administrators to easily understand the details of anomalies. To address these issues, there is a need for security systems with more advanced anomaly detection, prediction, notification, and reporting capabilities.

[0177] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.

[0178] In this invention, the server includes means for collecting data from multiple terminals in a distributed network in order to detect abnormal patterns in real time; data analysis means for generating normal activity patterns and creating a baseline pattern based on the data; threat prediction means using generative AI to detect abnormalities that deviate from the baseline pattern and predict future attack patterns; automated response means for automatically generating and executing countermeasures against abnormalities detected by the threat prediction means; notification means for sending alerts to an administrator from a specific device and creating a detailed report when a high-risk abnormality is detected; and a notification application that monitors network traffic in real time and reports to the administrator in real time when an abnormality is detected. This makes it possible to quickly detect abnormal patterns and respond immediately, thereby realizing advanced security measures.

[0179] An "anomalous pattern" refers to data on unusual activity or traffic that deviates from the generated baseline pattern.

[0180] A "distributed network" is a network structure in which multiple terminals are connected to each other and exchange data.

[0181] "Data analysis" is the process of using collected data to generate typical activity patterns and baseline patterns.

[0182] A "reference pattern" is an indicator of normal activity patterns generated through data analysis, and serves as a criterion for detecting anomalies.

[0183] "Generative AI" refers to artificial intelligence technology used to predict threats and detect anomalies based on data analysis.

[0184] "Threat prediction" is the process of predicting future attack patterns and risks using generative AI.

[0185] An "automated response mechanism" is a function that automatically generates and executes countermeasures in response to detected anomalies.

[0186] "Notification means" refers to a function that informs administrators of the results of automated response measures and details of any anomalies.

[0187] "Network traffic" refers to data that flows over a network.

[0188] A "notification application" is software that monitors network traffic in real time and reports any anomalies to the administrator.

[0189] A "detailed report" is a document that provides administrators with detailed information about any anomalies that occurred and the countermeasures taken.

[0190] This invention is a security system for preventing digital crime against industries with high information sensitivity and significant economic impact. The specific implementation of this system is described below.

[0191] 1. Data Collection

[0192] Subject: Server

[0193] The server continuously collects log data and traffic information in real time from multiple terminals within a distributed network. This data is stored in a central database and prepared for later analysis. APIs and log analysis tools are used in this process.

[0194] 2. Data Analysis and Reference Pattern Generation

[0195] Subject: Server

[0196] The server analyzes large amounts of data collected using data analysis tools to generate normal activity patterns (reference patterns). Machine learning algorithms (e.g., Python machine learning libraries) are used for this analysis. Based on the generated reference patterns, anomalous data is later detected.

[0197] 3. Real-time analysis and anomaly detection

[0198] Subject: Generative AI

[0199] Generative AI scans data in real time to detect unusual activity and traffic patterns. It compares historical data with baseline patterns to quickly identify anomalies. This process can, for example, detect sudden large-scale data transfers or unusual login attempts.

[0200] 4. Threat prediction and risk assessment

[0201] Subject: Generative AI

[0202] Generative AI predicts future attack patterns based on detected anomalies. This prediction utilizes known threat databases and simulation methods. Based on the prediction results, the risk level is assessed and assigned to a low, medium, or high level. This determines the priority of the response.

[0203] 5. Generation and execution of automated responses

[0204] Subject: Generative AI

[0205] The generative AI generates automated response scenarios based on the risk level. For example, if a high risk is detected, the AI ​​automatically modifies firewall settings, blocks harmful IP addresses, and disconnects specific devices from the network. In the case of medium risk, it enhances system log monitoring and issues warnings for specific actions.

[0206] 6. Alert generation and administrator notifications

[0207] Subject: Generative AI

[0208] After the generation AI completes automated response measures, it sends a real-time notification to the administrator including the results. The notification is delivered via email, SMS, dashboard, etc., and a detailed report is provided to the administrator. This report includes detected anomalies, implemented countermeasures, and risk assessments.

[0209] Specific example

[0210] Example 1: Advanced financial transaction security

[0211] Subject: Server

[0212] A server monitors financial institutions' transaction data in real time, and the server then uses a generative AI to analyze the transaction data. The generative AI detects unusually high-value transactions, compares them to past fraud patterns, and determines that there is a high probability of fraud.

[0213] Subject: Generative AI

[0214] The generation AI automatically implements a temporary freeze measure and sends an alert to the administrator. The administrator reviews the detailed report provided and conducts further investigation.

[0215] Specific example 2: Defending against cyberattacks on government agencies

[0216] Subject: Server

[0217] A server monitors government agency communication traffic 24 hours a day. The server detects unusual large-scale file transfers, and a generative AI analyzes them.

[0218] Subject: Generative AI

[0219] The generating AI identifies a high-risk situation and automatically modifies firewall settings and blocks suspicious IP addresses. It also disconnects the affected devices from the network and sends an emergency alert to the administrator. The administrator reviews the generated detailed report and takes further action.

[0220] Example of a prompt

[0221] "Design a smartphone app with real-time monitoring and anomaly detection capabilities to predict and prevent cyberattacks. This app will use Scapy to analyze network traffic and send email alerts if anomalies are detected."

[0222] The flow of a specific process in Application Example 1 will be explained using Figure 12.

[0223] Step 1:

[0224] Data collection

[0225] Subject: Server

[0226] The server collects log data and network traffic information in real time from multiple terminals within a distributed network. The input consists of communication logs and network traffic data transmitted from each terminal. The server collects this data using APIs and log analysis tools and stores it in a central database. The output is the collected data stored in the central database, prepared for analysis.

[0227] Step 2:

[0228] Data analysis and reference pattern generation

[0229] Subject: Server

[0230] The server analyzes data stored in a central database using data analysis tools (e.g., Python machine learning libraries). Input includes collected log data and network traffic information. The server analyzes this data and generates normal activity patterns (reference patterns). The generated reference patterns are stored in the database as output, forming the basis for anomaly detection.

[0231] Step 3:

[0232] Real-time analysis and anomaly detection

[0233] Subject: Generative AI

[0234] Generative AI scans newly collected data (traffic information and log data) in real time and detects deviations from baseline patterns. Its input includes data collected in real time and baseline patterns. The generative AI identifies anomalies by comparing them to historical data. This often detects abnormal traffic patterns or sudden large-scale data transfers. The output is the generated data of the detected anomalies.

[0235] Step 4:

[0236] Threat prediction and risk assessment

[0237] Subject: Generative AI

[0238] Generative AI predicts future attack patterns based on detected anomalous data. Its inputs include anomalous data and a database of known threats. The generative AI runs simulations and outputs prediction results. These predictions allow for a risk level assessment, categorized into low, medium, and high.

[0239] Step 5:

[0240] Generation and execution of automated responses

[0241] Subject: Generative AI

[0242] The generative AI generates and executes automated response scenarios based on the risk level. Its inputs include risk assessment results and response scenario templates. For example, in high-risk cases, it might automatically modify firewall settings, block harmful IP addresses, or disconnect specific devices from the network. The output records the implemented countermeasures.

[0243] Step 6:

[0244] Alert generation and administrator notifications

[0245] Subject: Generative AI

[0246] The generation AI automatically handles the situation and then sends a real-time notification to the administrator, including the results. Inputs include the automated response results and the administrator's contact information. Notifications are sent via email, SMS, dashboards, etc. Outputs include the notification sent to the administrator and a detailed report. This report includes detected anomalies, implemented countermeasures, and risk assessments.

[0247] The above outlines the specific processing flow within this system.

[0248] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.

[0249] This invention is a system for preventing digital crime in industries with high information density and significant economic impact. The system combines abnormal pattern detection, threat prediction, automated response, administrator notification, and an emotion engine that recognizes user emotions.

[0250] 1. Data Collection

[0251] Subject: Server

[0252] The server continuously collects log data, user activity information, network traffic, and user sentiment data in real time from multiple terminals within the network. The server stores this data in a central database and prepares it for analysis. APIs and log analysis tools are used in this process.

[0253] 2. Data Analysis and Reference Pattern Generation

[0254] Subject: Server

[0255] The server activates a data analysis module and analyzes the large amount of collected data. This analysis uses machine learning algorithms to generate normal activity patterns (reference patterns). Based on these reference patterns, abnormal data is detected.

[0256] 3. Real-time analysis and anomaly detection

[0257] Subject: Generative AI

[0258] Generative AI scans new data in real time to detect any anomalous patterns that deviate from the baseline. If an anomaly is found, it analyzes its details to identify the type of anomaly. For example, large-scale data transfers or unusual login attempts might be detected here.

[0259] 4. Analysis using an emotion engine

[0260] Subject: Generative AI

[0261] Generative AI analyzes user emotional data in real time to detect abnormal emotional patterns. Specifically, the emotion engine uses emotion recognition algorithms to track changes in the user's emotions and identify anomalies that deviate from the normal range. This allows for an assessment of whether the user's stress or anxiety is related to a cyberattack.

[0262] 5. Threat Prediction and Risk Assessment

[0263] Subject: Generative AI

[0264] Generative AI predicts future attack patterns based on detected anomaly and sentiment data. This prediction utilizes a database of known threats and simulation methods to assess risk levels. Risk levels are classified as low, medium, or high, and the priority of response is determined accordingly.

[0265] 6. Generation and execution of automated responses

[0266] Subject: Generative AI

[0267] The generative AI automatically generates response scenarios based on the risk level. For example, if a high risk is detected, specific countermeasures are generated, such as changing firewall settings, blocking harmful IP addresses, disconnecting specific devices from the network, and sending emotional care notifications to users.

[0268] 7. Execute automated response

[0269] Subject: Generative AI

[0270] Based on automated response scenarios generated by a generative AI, security measures are implemented sequentially. For example, it sends emotional care notifications to users and suggests psychological counseling as needed.

[0271] 8. Alert generation and administrator notifications

[0272] Subject: Generative AI

[0273] The generative AI notifies administrators of the results of its automated response. Notifications are sent in real time via email, SMS, dashboards, etc. A detailed report is also generated for administrator review. This report includes information on detected anomalies, implemented countermeasures, risk assessments, and user sentiment.

[0274] Specific example

[0275] Specific example 1: Suspicious transactions at financial institutions

[0276] Subject: Server

[0277] A server monitors financial institution transaction data and user sentiment data in real time. The server then uses a generative AI to analyze the transaction and sentiment data. If the generative AI detects an unusually high-value transaction and the user's sentiment data also shows abnormalities, it indicates a potential fraud.

[0278] Subject: Generative AI

[0279] The generative AI automatically implements temporary suspension measures and sends emotional care notifications to the user. An alert is sent to the administrator, and a detailed report is provided, allowing for further investigation and corrective action.

[0280] Specific example 2: Cyberattacks on government agencies

[0281] Subject: Server

[0282] The server monitors government agency communication traffic and employee sentiment data 24 hours a day. The server detects unusual large-scale file transfers, and generative AI analyzes them.

[0283] Subject: Generative AI

[0284] The generative AI determines that it is a high risk, and the AI automatically implements changes to the firewall settings and blocks suspicious IP addresses. It also disconnects the relevant terminal from the network and sends an emotional care notification to the user. An emergency alert is sent to the administrator, and a detailed report is provided. The administrator checks the report and takes further action.

[0285] As described above, by combining the emotion engine, this system enables more accurate anomaly detection and rapid countermeasures, and can effectively protect industries with high information confidentiality.

[0286] The processing flow will be described below.

[0287] Step 1: Data collection

[0288] Subject: Server

[0289] The server collects real-time log data, user activity information, network traffic, and user emotion data from multiple terminals within the network. The server stores these data in a central database. In the collection process, APIs and log analysis tools are used to obtain and record the data in a consistent format.

[0290] Step 2: Data analysis and generation of reference patterns

[0291] Subject: Server

[0292] The server activates the data analysis module and analyzes the collected data. Machine learning algorithms are applied to learn and generate normal activity patterns (reference patterns) and emotion patterns. Based on this reference pattern, abnormal data is detected.

[0293] Step 3: Analysis of user emotion data

[0294] Subject: Generative AI

[0295] Generative AI analyzes user emotional data in real time to detect abnormal emotional fluctuations. The emotion engine uses emotion recognition algorithms to monitor the user's emotional state and identify changes that deviate from the normal range. If the user is experiencing excessive stress or anxiety, this information is recorded.

[0296] Step 4: Real-time analysis and anomaly detection

[0297] Subject: Generative AI

[0298] Generative AI scans new data in real time and detects anomalous patterns that deviate from the baseline. For example, it can detect large-scale data transfers or fraudulent login attempts. Furthermore, if anomalies in emotional data are associated with technical anomalies, that information is also analyzed.

[0299] Step 5: Threat prediction and risk assessment

[0300] Subject: Generative AI

[0301] Generative AI predicts future attack patterns based on detected anomalies. It compares these anomalies against a database of known threats to predict how they will develop. Simultaneously, it considers user sentiment data to assess the risk level, which is categorized as low, medium, or high.

[0302] Step 6: Generate automated responses

[0303] Subject: Generative AI

[0304] The generative AI generates automated response scenarios based on the risk level. For example, if the risk is high, it will automatically change firewall settings, block harmful IP addresses, disconnect specific devices from the network, and send emotional care notifications to users.

[0305] Step 7: Execute automated response

[0306] Subject: Generative AI

[0307] Based on the automated response scenarios generated by the generative AI, security measures are sequentially executed. As a specific example, the firewall settings are changed in real time, the relevant IP addresses are blocked, and specific terminals are disconnected from the network. Also, notifications for emotional care are sent to the user, and responses such as psychological counseling are proposed.

[0308] Step 8: Alert Transmission and Administrator Notification

[0309] Subject: Generative AI

[0310] The generative AI notifies the administrator of the results of the automated response. The notification is carried out in real time and is sent through email, SMS, dashboard, etc. A detailed report is generated and provided to the administrator. This report includes information on the detected anomalies, the implemented countermeasures, the risk assessment, and the emotional status of the user.

[0311] Through the above steps, the prevention of digital crimes in industries with high information confidentiality is effectively carried out, and a rapid response is realized. By combining the emotion engine, the relevance between technical anomalies and the emotional state of the user is enhanced, enabling more accurate anomaly detection and countermeasures.

[0312] (Example 2)

[0313] Next, Example 2 will be described. In the following description, the data processing device 12 is referred to as the "server", and the smart device 14 is referred to as the "terminal".

[0314] To prevent digital crime in industries with high information density and significant economic impact, it is necessary to perform complex analysis that considers not only the detection of abnormal data patterns but also the emotional state of users. However, conventional systems do not provide a consistent solution that includes the analysis of emotional data, the detection of its anomalies, and the generation and execution of automated countermeasures. As a result, the accuracy of anomaly detection and threat prediction is insufficient, making it difficult to respond quickly and appropriately. Furthermore, there is a lack of functionality to notify administrators of the results of the response after an anomaly is detected in real time and to provide detailed reports.

[0315] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.

[0316] In this invention, the server includes means for continuously collecting log data, user activity information, network traffic, and sentiment data from multiple terminals in a distributed network in order to prevent digital crime; data analysis means for generating normal activity patterns and creating a baseline pattern based on the data; real-time analysis means for detecting anomalies that deviate from the baseline pattern and performing detailed analysis to identify the type of anomaly; sentiment analysis means for analyzing user sentiment data and detecting anomalies that deviate from the normal range; threat prediction means for predicting future attack patterns and evaluating risk levels based on the anomaly data and sentiment data; automated response means for generating automated response scenarios according to the risk level evaluated by the threat prediction means and automatically executing security measures when the risk is high; and alert issuing means for notifying the administrator of the results of the response by the automated response means and generating a detailed report. This improves the accuracy of anomaly detection in information-sensitive industries and enables quick and appropriate responses.

[0317] A "distributed network" is a network in which multiple terminals and servers are distributed and communicate with each other to share data.

[0318] "Log data" refers to records of operations generated by systems and applications, and includes access logs, authentication logs, error logs, etc.

[0319] "User activity information" refers to the history of operations and actions performed by a user within a system or application, and includes operation logs, browsing history, and other similar information.

[0320] "Network traffic" refers to the flow of data sent and received through a network, and includes the volume of packets sent and received, as well as the timing of communication.

[0321] "Emotional data" refers to data that indicates a user's emotional state, and includes facial expression data and biosignals acquired from emotion recognition systems and biometric sensors.

[0322] "Data analysis methods" refer to means for analyzing collected data and generating normal activity patterns or baseline patterns, and include machine learning algorithms and data mining techniques.

[0323] A "reference pattern" is a standard data pattern that represents normal activity and serves as a comparison criterion for identifying abnormal data.

[0324] "Real-time analysis means" refers to a method for analyzing new data in real time, detecting anomalies that deviate from the standard pattern, and identifying their type.

[0325] "Emotional analysis means" refers to methods for analyzing a user's emotional data and detecting anomalies that deviate from the normal range, and includes emotional recognition algorithms and biosignal analysis technologies.

[0326] "Threat prediction tools" refer to methods for predicting future attack patterns and assessing risk levels based on anomalous data and sentiment data.

[0327] "Automated response measures" refer to methods that automatically generate security measures based on risk assessments using threat prediction and execute them when the risk is high, and include changing firewall settings and disconnecting from the network.

[0328] "Alert generation method" refers to a method for notifying administrators of the results of responses by automated response methods and generating and providing detailed reports.

[0329] This invention is a system for preventing digital crime in industries with high information density and significant economic impact. The system combines abnormal pattern detection, threat prediction, automated response, administrator notification, and an emotion engine that recognizes user emotions.

[0330] Data collection

[0331] Subject: Server

[0332] The server continuously collects data from multiple terminals within the corporate network. This data includes log data (access logs, authentication logs, error logs, etc.), user activity information (operation logs, browsing history, etc.), network traffic, and sentiment data (facial expression data from sentiment recognition systems and biometric sensor data, etc.). To collect this data, the server uses APIs and log analysis tools (e.g., Elasticsearch®, Splunk). The collected data is stored in a central database and prepared for analysis.

[0333] Data Analysis

[0334] Subject: Server

[0335] The server starts the data analysis module and analyzes the collected data. Specifically, the process proceeds as follows:

[0336] Machine learning algorithms (e.g., TensorFlow and Scikit-learn) are used to learn typical activity patterns from past data.

[0337] Clustering and anomaly detection techniques are used to generate normal activity patterns (reference patterns).

[0338] Real-time analysis

[0339] Subject: Generative AI

[0340] The generative AI retrieves new data from a central database in real time and compares it against a baseline pattern. This allows for the detection of abnormal patterns in real time. The stream processing engine used (e.g., Apache® Kafka, Apache Storm) monitors the new data in real time and detects abnormal patterns that deviate from the baseline pattern.

[0341] Analysis using an emotion engine

[0342] Subject: Generative AI

[0343] Generative AI analyzes user emotional data in real time. Specifically, it uses emotion recognition algorithms (e.g., face detection using Haar-like features, deep learning emotion classification models) to analyze the user's real-time facial expressions and biometric information. If the emotional data deviates from the normal range, the generative AI identifies the anomaly.

[0344] Threat prediction

[0345] Subject: Generative AI

[0346] Generative AI predicts future attack patterns based on anomalous and sentiment data. By cross-referencing with known threat databases (e.g., CVE databases) and using simulation methods, it constructs risk scenarios and assesses risk levels. Risk levels are classified into three stages: low, medium, and high.

[0347] Automated response scenarios

[0348] Subject: Generative AI

[0349] The generative AI generates automated response scenarios based on risk assessments. Specific countermeasures include modifying firewall settings, blocking harmful IP addresses, and disconnecting specific devices from the network. It also provides emotional care notifications and suggests psychological counseling as countermeasures against emotional disturbances.

[0350] Execute automated response

[0351] Subject: Generative AI

[0352] The generative AI will perform the following security measures based on the generated automated response scenarios:

[0353] You will need to use a network management tool (e.g., Cisco ASA, pfSense) to change firewall settings.

[0354] Update the access control list to block suspicious IP addresses.

[0355] Disconnect the terminal experiencing the malfunction from the network.

[0356] Additionally, the system sends emotional care notifications to users and suggests psychological counseling as needed.

[0357] Alert generation and administrator notifications

[0358] Subject: Generative AI

[0359] The generative AI notifies administrators of the results of its automated responses. These notifications are delivered in real time via email, SMS, or a dashboard. Furthermore, a detailed report is generated for administrator review. This report includes information on detected anomalies, actions taken, risk assessments, and user sentiment.

[0360] Specific example

[0361] Specific example 1: Suspicious transactions at financial institutions

[0362] Subject: Server

[0363] A server monitors financial institution transaction data and user sentiment data in real time. The server then uses generative AI to analyze the transaction and sentiment data. If the generative AI detects an unusually high-value transaction and the user sentiment data also shows abnormalities, it indicates a potential fraud.

[0364] Subject: Generative AI

[0365] The generative AI automatically implements temporary suspension measures and sends emotional care notifications to the user. It also sends alerts to administrators and provides detailed reports to facilitate further investigation and countermeasures.

[0366] Specific example 2: Cyberattacks on government agencies

[0367] Subject: Server

[0368] The server monitors government agency communication traffic and employee sentiment data 24 hours a day. The server detects unusual large-scale file transfers, which are then analyzed by generative AI.

[0369] Subject: Generative AI

[0370] The generation AI identifies the situation as high-risk and automatically modifies firewall settings and blocks suspicious IP addresses. It also disconnects the relevant devices from the network and sends emotional care notifications to users. An emergency alert is sent to the administrator, providing a detailed report. The administrator reviews the report and takes further action.

[0371] Example of a prompt

[0372] "Based on the analysis of the new data, an abnormal pattern has been detected. The sentiment data also shows abnormalities, so please generate specific countermeasures."

[0373] The flow of the specific processing in Example 2 will be explained using Figure 13.

[0374] Step 1:

[0375] Inputs: Log data, user activity information, network traffic, sentiment data

[0376] Specific operation: The server collects this data in real time from multiple terminals within the corporate network.

[0377] Data processing: Collect data using APIs and log analysis tools (e.g., Elasticsearch, Splunk) and store it in a central database.

[0378] Output: Collected data stored in the central database

[0379] Step 2:

[0380] Input: Collected data stored in the central database

[0381] Specific operation: The server starts the data analysis module and begins analyzing the stored data.

[0382] Data processing: Machine learning algorithms (e.g., TensorFlow or Scikit-learn) are used to learn normal activity patterns from past data and generate normal activity patterns (reference patterns). Clustering and anomaly detection methods are employed.

[0383] Output: Generated reference pattern

[0384] Step 3:

[0385] Input: Newly collected data, reference pattern

[0386] Specific operation: The generative AI retrieves new data from a central database in real time and compares it against a reference pattern.

[0387] Data processing: Using stream processing engines (e.g., Apache Kafka, Apache Storm), new data is monitored in real time, and abnormal patterns that deviate from the baseline pattern are detected.

[0388] Output: List of detected anomaly patterns

[0389] Step 4:

[0390] Input: Collected emotional data

[0391] Specific operation: Generative AI analyzes emotional data in real time.

[0392] Data processing: We analyze user facial expressions and biometric information using emotion recognition algorithms (e.g., face detection using Haar-like features, deep learning emotion classification models).

[0393] Output: List of abnormal emotional patterns

[0394] Step 5:

[0395] Input: Abnormal data, sentiment data

[0396] Specific operation: Generative AI predicts future attack patterns based on anomaly data and emotional data.

[0397] Data processing: The data is compared with known threat databases (e.g., CVE databases), and risk scenarios are constructed using simulation methods to evaluate risk levels.

[0398] Output: Risk Assessment Report

[0399] Step 6:

[0400] Input: Risk assessment report

[0401] Specific operation: The generative AI generates automated response scenarios based on risk assessment.

[0402] Data processing: As automated response scenarios, this includes changing firewall settings, blocking harmful IP addresses, disconnecting specific devices from the network, and generating emotional care notifications.

[0403] Output: Automated response scenario

[0404] Step 7:

[0405] Input: Automated response scenario

[0406] Specific operation: The generative AI executes security measures based on the scenarios it generates.

[0407] Data processing: Use network management tools (e.g., Cisco ASA, pfSense) to modify firewall settings, block IP addresses to prevent unauthorized access, and disconnect terminals that have experienced problems. Also, send emotional care notifications to users and suggest psychological counseling as needed.

[0408] Output: Security measures taken

[0409] Step 8:

[0410] Input: Results of security measures taken

[0411] Specific operation: The generative AI notifies the administrator of the results of its response.

[0412] Data processing: Generate detailed reports and send real-time notifications to administrators via email, SMS, and dashboards.

[0413] Output: Notification to administrator and detailed report

[0414] (Application Example 2)

[0415] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server," and the smart device 14 will be referred to as the "terminal."

[0416] Traditional security systems focus on detecting and countering unusual patterns of digital crime, but they fail to consider the emotional state of users. This shortcoming can lead to reduced accuracy in predicting potential threats and delays in optimal responses, especially in industries with high information sensitivity and significant economic impact. Furthermore, there is a lack of emotional support for users who experience psychological stress as a result of cyberattacks. This increases the risk of data breaches and cyberattacks, which is a significant challenge.

[0417] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means.

[0418] In this invention, the server includes means for collecting data from multiple terminals in a distributed network in order to detect abnormal patterns in real time; data analysis means for generating normal activity patterns and creating a reference pattern based on the data; threat prediction means using generative AI to detect abnormalities that deviate from the reference pattern and predict future attack patterns; automated response means for automatically generating and executing countermeasures against abnormalities detected by the threat prediction means; emotion analysis means for the automated response means to monitor the user's emotional state in real time and detect abnormal emotional patterns; means for generating an emotional care notification when an abnormality is detected; and alert issuing means. This enables rapid and accurate detection of abnormalities, execution of appropriate countermeasures, and care that takes into account the user's emotional state.

[0419] An "abnormal pattern" refers to data or behavioral tendencies that deviate from the standard pattern and are not typically observed.

[0420] A "distributed network" refers to a network in which multiple terminals are interconnected and data is exchanged in a distributed manner.

[0421] "Data collection means" refers to methods and devices for collecting log data, user activity information, network traffic, and user sentiment data from terminals within a network.

[0422] "Data analysis means" refers to methods and devices for analyzing collected data, generating normal activity patterns, and creating reference patterns.

[0423] "Generative AI" refers to artificial intelligence systems that use machine learning and deep learning technologies to analyze data in real time and detect anomalies.

[0424] "Threat prediction means" refers to methods and devices that use generative AI to predict future attack patterns based on detected anomaly data.

[0425] "Automated response means" refers to methods or devices for automatically generating and executing countermeasures in response to detected anomalies.

[0426] "Emotional analysis means" refers to methods and devices for monitoring a user's emotional state in real time and detecting abnormal emotional patterns.

[0427] "Emotional care notifications" refer to relaxation notifications and support suggestions sent to a user when their emotional state is abnormal.

[0428] "Alert notification means" refers to methods or devices for notifying administrators of the results of responses by automated response means.

[0429] The system that implements this application has the following configuration.

[0430] 1. Data acquisition module

[0431] The server collects log data, user activity information, network traffic, and user sentiment data in real time from multiple terminals within a distributed network. APIs and log analysis tools (e.g., Splunk, Prometheus) are used for this purpose. The collected data is stored in a central database and prepared for subsequent analysis.

[0432] 2. Data Analysis Module

[0433] The server analyzes the large amount of collected data using machine learning algorithms (e.g., Scikit-learn, TensorFlow). As a result of the analysis, normal activity patterns (reference patterns) are generated, which serve as criteria for detecting anomalies. These reference patterns are stored in the server's central database and form the basis for real-time analysis.

[0434] 3. Real-time analysis module

[0435] Generative AI scans new data in real time and detects anomalous patterns that deviate from the baseline pattern. This process uses AI models (e.g., YOLO, RNN) to perform data calculations. If an anomaly is found, its details are analyzed to identify the type of anomaly (e.g., large-scale data transfer, abnormal login attempt).

[0436] 4. Emotion Analysis Module

[0437] Generative AI analyzes user emotional data in real time and detects abnormal emotional patterns. Emotional analysis uses emotion recognition algorithms (e.g., OpenCV, IBM Watson®) to track changes in the user's emotions. This identifies emotional anomalies that deviate from the normal range and evaluates whether the user's stress or anxiety is related to cyberattacks.

[0438] 5. Threat Prediction Module

[0439] Generative AI predicts future attack patterns based on detected anomaly and sentiment data. Threat prediction utilizes known threat databases and simulation methods, and risk levels are assessed. Risk levels are classified as low, medium, or high, and response priorities are determined.

[0440] 6. Automated response module

[0441] The generative AI generates automated response scenarios based on the risk level. If a high risk is detected, firewall settings are modified, harmful IP addresses are blocked, specific devices are disconnected from the network, and emotional care notifications are generated for the user. These countermeasures are executed sequentially, with the server coordinating the entire process.

[0442] 7. Alert generation module

[0443] The generative AI notifies administrators of the results of automated responses in real time. Notifications are sent via email, SMS, and dashboards (e.g., Grafana). A detailed report is also generated for administrator review. This report includes information on detected anomalies, actions taken, risk assessment, and user sentiment.

[0444] For example, a server might detect a combination of abnormal network traffic and a sudden increase in user stress. In this case, the system automatically isolates the network segment and sends a relaxation notification to the user.

[0445] Examples of prompt statements are as follows:

[0446] Monitor network traffic for sudden increases and user stress levels, and implement automated countermeasures if anomalies are detected.

[0447] The above describes the embodiments for carrying out this invention.

[0448] The flow of a specific process in Application Example 2 will be explained using Figure 14.

[0449] Step 1: Data Collection

[0450] The server collects log data, user activity information, network traffic, and user sentiment data in real time from multiple terminals within the network. APIs (e.g., RESTful APIs) and log analysis tools (e.g., Splunk, Prometheus) are used for this collection. The collected data is sent to and stored in a central database. Inputs include terminal log data, network traffic data, and sentiment data, while output is the integration of this data into the central database.

[0451] Step 2: Data Analysis

[0452] The server launches a data analysis module and analyzes the large amount of collected data using machine learning algorithms (e.g., Scikit-learn, TensorFlow). The goal of the analysis is to generate normal activity patterns and create a baseline pattern. The input includes data stored in a central database, and the output is a baseline pattern. This baseline pattern serves as the basis for subsequent real-time analysis.

[0453] Step 3: Real-time analysis

[0454] Generative AI scans new data in real time to check for anomalous patterns that deviate from the baseline pattern. An AI model (e.g., YOLO, RNN) is used for this scan. Input includes newly collected real-time data and the baseline pattern, and output is details of any detected anomalies. If an anomaly is found, its details are passed on to the next analysis step.

[0455] Step 4: Emotion Analysis

[0456] The generative AI uses an emotion analysis module to analyze user emotion data in real time. The input includes emotion data acquired in real time, and the output detects abnormal emotion patterns. Emotion recognition algorithms (e.g., OpenCV, IBM Watson) are used to track changes in the user's emotions and identify anomalies that deviate from the normal range.

[0457] Step 5: Threat Prediction

[0458] Generative AI predicts future attack patterns based on anomalies detected through real-time analysis and sentiment analysis. This prediction utilizes a database of known threats and simulation methods, and the risk level is assessed. Input includes detected anomaly data and sentiment data, and output is a prediction result categorized by risk level. The risk level is classified as either low, medium, or high.

[0459] Step 6: Generate and execute automated responses

[0460] The generative AI generates automated response scenarios based on the risk level. If a high risk is detected, it will take actions such as changing firewall settings, blocking harmful IP addresses, disconnecting specific devices from the network, and generating emotional care notifications for users. The input includes prediction results categorized by risk level, and the output is the execution of specific countermeasures.

[0461] Step 7: Issue an alert

[0462] The generative AI notifies administrators of the results of automated responses. Notifications are sent in real time via email, SMS, and dashboards (e.g., Grafana). Inputs include the results of automated responses, and outputs generate alerts for administrators. A detailed report is also generated, which includes information on detected anomalies, implemented countermeasures, risk assessments, and user sentiment.

[0463] The specific processing unit 290 transmits the result of the specific processing to the smart device 14. In the smart device 14, the control unit 46A causes the output device 40 to output the result of the specific processing. The microphone 38B acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.

[0464] Data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of data generation model 58 is ChatGPT (registered trademark) (Internet search).<URL: https: / / openai.com / blog / chatgpt> ), Gemini (registered trademark) (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[0465] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and the specific processing may also be performed by the smart device 14.

[0466] [Second Embodiment]

[0467] Figure 3 shows an example of the configuration of the data processing system 210 according to the second embodiment.

[0468] As shown in Figure 3, the data processing system 210 includes a data processing device 12 and smart glasses 214. An example of the data processing device 12 is a server.

[0469] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[0470] The smart glasses 214 include a computer 36, a microphone 238, a speaker 240, a camera 42, and a communication interface 44. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, and camera 42 are also connected to the bus 52.

[0471] The microphone 238 receives voice signals from the user 20 and receives instructions from the user 20. The microphone 238 captures the voice signals from the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.

[0472] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the area around the user 20 (for example, an imaging range defined by a field of view equivalent to the width of a typical healthy person's field of vision).

[0473] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.

[0474] Figure 4 shows an example of the main functions of the data processing device 12 and the smart glasses 214. As shown in Figure 4, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.

[0475] The specific processing program 56 is an example of a "program" relating to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[0476] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[0477] In the smart glasses 214, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.

[0478] Next, the identification processing performed by the identification processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the smart glasses 214 will be referred to as the "terminal".

[0479] The present invention will now describe specific embodiments for carrying out the invention. The present invention is a system for preventing digital crime against industries with high information density and significant economic impact (e.g., government, finance, telecommunications, etc.). This system has multiple functions, including detection of abnormal patterns, threat prediction, automated response, and administrator notification.

[0480] 1. Data Collection

[0481] Subject: Server

[0482] First, the server continuously collects log data and traffic information in real time from multiple terminals within the network. The server stores this data in a central database and prepares it for analysis. APIs and log analysis tools are used during this process.

[0483] 2. Data Analysis and Reference Pattern Generation

[0484] Subject: Server

[0485] Next, the server uses a data analysis module to analyze the large amount of data it has collected. This analysis employs machine learning algorithms to generate normal activity patterns (reference patterns). Based on these reference patterns, abnormal data is detected.

[0486] 3. Real-time analysis and anomaly detection

[0487] Subject: Generative AI

[0488] Generative AI scans data in real time to detect unusual activity and traffic patterns. This AI compares historical data with baseline patterns to quickly identify anomalies. In this process, for example, sudden large-scale data transfers or unusual login attempts may be detected.

[0489] 4. Threat prediction and risk assessment

[0490] Subject: Generative AI

[0491] Generative AI predicts future attack patterns based on detected anomalies. This prediction utilizes known threat databases and simulation methods. Based on the prediction results, the risk level is assessed. Risk levels are categorized into low, medium, and high, and the priority of response is determined accordingly.

[0492] 5. Generation and execution of automated responses

[0493] Subject: Generative AI

[0494] The generative AI generates automated response scenarios based on the risk level. For example, if a high risk is detected, the AI ​​automatically modifies firewall settings, blocks harmful IP addresses, and disconnects specific devices from the network. In the case of medium risk, it enhances system log monitoring and issues warnings for specific actions.

[0495] 6. Alert generation and administrator notifications

[0496] Subject: Generative AI

[0497] Finally, after the generative AI completes automated response measures, it sends a real-time notification to the administrator, including the results. This notification is delivered via email, SMS, dashboard, etc. Furthermore, a detailed report is generated and provided for administrator review. This report includes detected anomalies, implemented countermeasures, and risk assessments.

[0498] Specific example

[0499] Specific example 1: Suspicious transactions at financial institutions

[0500] Subject: Server

[0501] A server monitors financial institutions' transaction data in real time, and the server then uses a generative AI to analyze the transaction data. The generative AI detects unusually high-value transactions, compares them to past fraud patterns, and determines that there is a high probability of fraud.

[0502] Subject: Generative AI

[0503] The generation AI automatically implements a temporary freeze measure and sends an alert to the administrator. The administrator reviews the detailed report provided and conducts further investigation.

[0504] Specific example 2: Cyberattacks on government agencies

[0505] Subject: Server

[0506] A server monitors government agency communication traffic 24 hours a day. The server detects unusual large-scale file transfers, and a generative AI analyzes them.

[0507] Subject: Generative AI

[0508] The generating AI identifies a high-risk situation and automatically modifies firewall settings and blocks suspicious IP addresses. It also disconnects the affected devices from the network and sends an emergency alert to the administrator. The administrator reviews the generated detailed report and takes further action.

[0509] As described above, this system, with its advanced AI technology and automated security measures, can quickly and effectively protect critical industries from digital crime.

[0510] The following describes the processing flow.

[0511] Step 1: Data Collection

[0512] Subject: Server

[0513] The server collects data in real time from multiple terminals within a distributed network. Specifically, it retrieves log data, user activity information, network traffic, etc., from each terminal using APIs and stores them in a central database. The collected data is recorded and stored in a consistent manner.

[0514] Step 2: Data analysis and reference pattern generation

[0515] Subject: Server

[0516] The server starts the data analysis module and begins analyzing the collected data. It applies machine learning algorithms to learn normal activity patterns and generate baseline patterns. These baseline patterns are used as templates for anomaly detection.

[0517] Step 3: Real-time analysis and anomaly detection

[0518] Subject: Generative AI

[0519] Generative AI scans new data in real time to detect any anomalous patterns that deviate from the baseline. If an anomaly is found, it analyzes its details to identify the type of anomaly. For example, large-scale data transfers or unusual login attempts might be detected here.

[0520] Step 4: Threat prediction and risk assessment

[0521] Subject: Generative AI

[0522] The generative AI predicts future attack patterns based on detected anomalies. It compares these predictions with existing threat intelligence stored in a database to assess the risk level of new attacks. The risk level is classified as low, medium, or high, and countermeasures are determined.

[0523] Step 5: Generate automated responses

[0524] Subject: Generative AI

[0525] The generation AI automatically generates response scenarios based on the risk level. For example, if a high risk is detected, specific countermeasures such as blocking IP addresses, disconnecting specific devices from the network, and changing firewall settings are generated.

[0526] Step 6: Execute automated response

[0527] Subject: Generative AI

[0528] Based on automated response scenarios generated by a generative AI, security measures are executed sequentially. For example, harmful IP addresses are immediately blocked, and specific devices are isolated from the network.

[0529] Step 7: Alert generation and administrator notification

[0530] Subject: Generative AI

[0531] The generative AI notifies administrators of the results of its automated response. Notifications are sent in real time via email, SMS, dashboards, etc. A detailed report is also generated for administrator review. This report includes detected anomalies, implemented countermeasures, and risk assessments.

[0532] By following these steps, it is possible to effectively prevent digital crimes against industries with high information confidentiality and to respond quickly.

[0533] (Example 1)

[0534] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server" and the smart glasses 214 will be referred to as the "terminal".

[0535] In today's advanced information society, industries with high information density and significant economic impact (e.g., government, finance, telecommunications) are particularly vulnerable to cyberattacks. Advanced security measures are necessary to prevent digital crime against these industries. However, conventional systems struggle with rapid and effective anomaly detection, threat prediction, and automated response.

[0536] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.

[0537] In this invention, the server includes means for collecting data from multiple terminals in a distributed network in order to detect abnormal patterns in real time; data analysis means for generating normal activity patterns and creating a baseline pattern based on the data; threat prediction means using generative AI to detect anomalies that deviate from the baseline pattern and predict future attack patterns; automated response means for automatically generating and executing countermeasures against anomalies detected by the threat prediction means; and alert issuing means for notifying the administrator of the results of the response by the automated response means. This enables rapid and effective prevention of digital crime and makes it possible to protect critical industries more securely.

[0538] An "abnormal pattern" refers to data or behavior that deviates from normal activity patterns.

[0539] "Data collection method" refers to a system that collects log data, traffic information, and other data from multiple terminals within a distributed network.

[0540] "Data analysis methods" refer to technologies and algorithms that analyze collected data, generate normal activity patterns, and create baseline patterns.

[0541] A "reference pattern" is a definition of a normal activity pattern generated by data analysis methods, and serves as a criterion for detecting abnormal patterns.

[0542] "Generative AI" refers to technologies that use machine learning and artificial intelligence to detect anomalies and perform threat prediction and risk assessment.

[0543] "Threat prediction methods" refer to technologies that use generative AI to detect anomalies that deviate from standard patterns and predict future attack patterns.

[0544] "Automated response measures" refer to technologies that automatically generate and execute appropriate countermeasures in response to anomalies detected by threat prediction measures.

[0545] "Alert notification method" refers to technology used to notify administrators of the results of responses by automated response methods.

[0546] A "machine learning algorithm" refers to an algorithm used in data analysis, specifically a statistical method or model used for anomaly detection.

[0547] "Automatic firewall settings change" refers to a function that automatically changes the settings of the system's protective barrier.

[0548] "Disconnecting a specific device from the network" refers to a function that isolates devices exhibiting abnormal behavior from the network.

[0549] "Blocking harmful IP addresses" refers to a function that blocks IP addresses that may be used for malicious communication.

[0550] This invention is a system for preventing digital crime against industries with high information sensitivity and significant economic impact. This system has multiple functions, including detection of anomalous patterns, threat prediction, automated response, and administrator notification. The specific implementation method of this system is described below.

[0551] Data collection

[0552] Subject: Server

[0553] The server continuously collects log data and traffic information in real time from multiple terminals within a distributed network. Data is efficiently acquired using log analysis tools such as the syslog protocol, NetFlow, and sFlow. The collected data is stored in a NoSQL database (e.g., MongoDB) and organized for later analysis.

[0554] Data analysis and reference pattern generation

[0555] Subject: Server

[0556] Next, the server analyzes the collected data and generates normal activity patterns. Using Python and Scikit-learn, the data is preprocessed, and then a clustering algorithm (e.g., K-means) is executed to create a baseline pattern. This generated baseline pattern forms the basis for anomaly detection.

[0557] Real-time analysis and anomaly detection

[0558] Subject: Generative AI

[0559] Generative AI scans data in real time and uses deep learning frameworks such as TensorFlow to compare generated baseline patterns with historical data. Anomaly detection algorithms such as autoencoders are used to quickly identify anomalous traffic and activity.

[0560] Threat prediction and risk assessment

[0561] Subject: Generative AI

[0562] Generative AI predicts threats and performs risk assessments based on detected anomalies. This is done using the MITRE ATT&CK framework and LSTM models. For predicted attack patterns, it evaluates the risk level as low, medium, or high and determines the priority of response.

[0563] Generation and execution of automated responses

[0564] Subject: Generative AI

[0565] The generative AI generates and executes automated response scenarios based on risk levels. In high-risk cases, it automatically modifies firewall settings using iptables commands to block harmful IP addresses. It also automatically disconnects devices exhibiting abnormal activity from the network.

[0566] Alert generation and administrator notifications

[0567] Subject: Generative AI

[0568] The generative AI notifies administrators of the results of its automated responses. These notifications are sent via email APIs and SMS gateways, and the results are also displayed on a dedicated web dashboard. Furthermore, a detailed report is generated and provided to administrators.

[0569] Specific example

[0570] Specific example 1: Suspicious transactions at financial institutions

[0571] Subject: Server

[0572] The server monitors financial institutions' transaction data in real time, and a generative AI analyzes that data. The generative AI detects unusually high-value transactions and determines that they are highly likely to be fraudulent.

[0573] Subject: Generative AI

[0574] The generation AI automatically implements a temporary freeze measure and sends an alert to the administrator. The administrator reviews a detailed report and conducts further investigation.

[0575] Specific example 2: Cyberattacks on government agencies

[0576] Subject: Server

[0577] The server monitors government agency communication traffic 24 hours a day. The server detects unusual large-scale file transfers, and generative AI analyzes them.

[0578] Subject: Generative AI

[0579] The generation AI identifies a high-risk situation and automatically takes action such as changing firewall settings and blocking suspicious IP addresses. It also disconnects the relevant devices from the network and sends an emergency alert to the administrator. The administrator reviews the generated detailed report and takes further action.

[0580] Example of a prompt

[0581] "Detect anomalous patterns from the given traffic data, compare them to relevant past attack patterns to perform a risk assessment, and then generate appropriate automated countermeasures."

[0582] This invention combines advanced AI technology with automated security measures to quickly and effectively protect critical industries from digital crime.

[0583] The flow of the specific processing in Example 1 will be explained using Figure 11.

[0584] Step 1: Data Collection

[0585] Subject: Server

[0586] Input: Log data and traffic information sent from multiple terminals within a distributed network.

[0587] Specific operation: The server uses the syslog protocol, NetFlow, and sFlow to retrieve log data and traffic information from each terminal. The server uses ping to verify connectivity with each terminal, then starts the syslog daemon to collect log data. It also uses a NetFlow collector to collect traffic information. The collected data is stored in a NoSQL database (e.g., MongoDB).

[0588] Output: Log data and traffic information stored in the database

[0589] Step 2: Data analysis and reference pattern generation

[0590] Subject: Server

[0591] Input: Log data and traffic information stored in the database

[0592] Specific operation: The server analyzes log data and traffic information using Python and Scikit-learn. Data preprocessing includes denoising and data standardization. Then, a clustering algorithm (e.g., K-means) is executed to create a baseline pattern. The generated baseline pattern is then saved back into the database.

[0593] Output: Database where the reference pattern is stored.

[0594] Step 3: Real-time analysis and anomaly detection

[0595] Subject: Generative AI

[0596] Input: Real-time acquired log data and traffic information, baseline patterns

[0597] Specific operation: Generative AI scans data in real time and compares it with historical data and baseline patterns. TensorFlow is used to perform anomaly detection with an Autoencoder algorithm. When abnormal traffic or activity is detected, an alert is generated.

[0598] Output: Anomaly detection results and alerts

[0599] Step 4: Threat prediction and risk assessment

[0600] Subject: Generative AI

[0601] Input: Data on detected anomalies, baseline patterns, and known threat databases.

[0602] Specific operation: Generative AI analyzes detected anomalies using the MITRE ATT&CK framework and LSTM models. It compares them with a known threat database to predict future attack patterns. Risk is assessed in three stages: "low," "medium," and "high," and the priority of response is determined.

[0603] Output: Risk assessment and predicted threat patterns

[0604] Step 5: Generate and execute automated responses

[0605] Subject: Generative AI

[0606] Input: Risk assessment results, anomaly detection results

[0607] Specific operation: The generative AI generates automated response scenarios based on the risk level. In high-risk cases, it modifies firewall settings using iptables commands to block harmful IP addresses. It also automatically disconnects devices exhibiting abnormal activity from the network.

[0608] Output: Automated countermeasures taken and their results

[0609] Step 6: Alert generation and administrator notification

[0610] Subject: Generative AI

[0611] Input: Automated response results, anomaly detection results, risk assessment

[0612] Specific operation: The generative AI notifies the administrator of the results of its automated response. Communication is conducted via email API and SMS gateway, and the results are displayed on a web dashboard. A detailed report is generated for the administrator to review.

[0613] Output: Notification to administrator and detailed report

[0614] (Application Example 1)

[0615] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server," and the smart glasses 214 will be referred to as the "terminal."

[0616] Current security systems often lack sufficient capabilities to detect anomalies in real time and respond immediately. Furthermore, even when an anomaly is detected, there is a lack of systems that efficiently notify administrators and quickly implement countermeasures. In addition, few systems have reporting capabilities that allow administrators to easily understand the details of anomalies. To address these issues, there is a need for security systems with more advanced anomaly detection, prediction, notification, and reporting capabilities.

[0617] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.

[0618] In this invention, the server includes means for collecting data from multiple terminals in a distributed network in order to detect abnormal patterns in real time; data analysis means for generating normal activity patterns and creating a baseline pattern based on the data; threat prediction means using generative AI to detect abnormalities that deviate from the baseline pattern and predict future attack patterns; automated response means for automatically generating and executing countermeasures against abnormalities detected by the threat prediction means; notification means for sending alerts to an administrator from a specific device and creating a detailed report when a high-risk abnormality is detected; and a notification application that monitors network traffic in real time and reports to the administrator in real time when an abnormality is detected. This makes it possible to quickly detect abnormal patterns and respond immediately, thereby realizing advanced security measures.

[0619] An "anomalous pattern" refers to data on unusual activity or traffic that deviates from the generated baseline pattern.

[0620] A "distributed network" is a network structure in which multiple terminals are connected to each other and exchange data.

[0621] "Data analysis" is the process of using collected data to generate typical activity patterns and baseline patterns.

[0622] A "reference pattern" is an indicator of normal activity patterns generated through data analysis, and serves as a criterion for detecting anomalies.

[0623] "Generative AI" refers to artificial intelligence technology used to predict threats and detect anomalies based on data analysis.

[0624] "Threat prediction" is the process of predicting future attack patterns and risks using generative AI.

[0625] An "automated response mechanism" is a function that automatically generates and executes countermeasures in response to detected anomalies.

[0626] "Notification means" refers to a function that informs administrators of the results of automated response measures and details of any anomalies.

[0627] "Network traffic" refers to data that flows over a network.

[0628] A "notification application" is software that monitors network traffic in real time and reports any anomalies to the administrator.

[0629] A "detailed report" is a document that provides administrators with detailed information about any anomalies that occurred and the countermeasures taken.

[0630] This invention is a security system for preventing digital crime against industries with high information sensitivity and significant economic impact. The specific implementation of this system is described below.

[0631] 1. Data Collection

[0632] Subject: Server

[0633] The server continuously collects log data and traffic information in real time from multiple terminals within a distributed network. This data is stored in a central database and prepared for later analysis. APIs and log analysis tools are used in this process.

[0634] 2. Data Analysis and Reference Pattern Generation

[0635] Subject: Server

[0636] The server analyzes large amounts of data collected using data analysis tools to generate normal activity patterns (reference patterns). Machine learning algorithms (e.g., Python machine learning libraries) are used for this analysis. Based on the generated reference patterns, anomalous data is later detected.

[0637] 3. Real-time analysis and anomaly detection

[0638] Subject: Generative AI

[0639] Generative AI scans data in real time to detect unusual activity and traffic patterns. It compares historical data with baseline patterns to quickly identify anomalies. This process can, for example, detect sudden large-scale data transfers or unusual login attempts.

[0640] 4. Threat prediction and risk assessment

[0641] Subject: Generative AI

[0642] Generative AI predicts future attack patterns based on detected anomalies. This prediction utilizes known threat databases and simulation methods. Based on the prediction results, the risk level is assessed and assigned to a low, medium, or high level. This determines the priority of the response.

[0643] 5. Generation and execution of automated responses

[0644] Subject: Generative AI

[0645] The generative AI generates automated response scenarios based on the risk level. For example, if a high risk is detected, the AI ​​automatically modifies firewall settings, blocks harmful IP addresses, and disconnects specific devices from the network. In the case of medium risk, it enhances system log monitoring and issues warnings for specific actions.

[0646] 6. Alert generation and administrator notifications

[0647] Subject: Generative AI

[0648] After the generation AI completes automated response measures, it sends a real-time notification to the administrator including the results. The notification is delivered via email, SMS, dashboard, etc., and a detailed report is provided to the administrator. This report includes detected anomalies, implemented countermeasures, and risk assessments.

[0649] Specific example

[0650] Example 1: Advanced financial transaction security

[0651] Subject: Server

[0652] A server monitors financial institutions' transaction data in real time, and the server then uses a generative AI to analyze the transaction data. The generative AI detects unusually high-value transactions, compares them to past fraud patterns, and determines that there is a high probability of fraud.

[0653] Subject: Generative AI

[0654] The generation AI automatically implements a temporary freeze measure and sends an alert to the administrator. The administrator reviews the detailed report provided and conducts further investigation.

[0655] Specific example 2: Defending against cyberattacks on government agencies

[0656] Subject: Server

[0657] A server monitors government agency communication traffic 24 hours a day. The server detects unusual large-scale file transfers, and a generative AI analyzes them.

[0658] Subject: Generative AI

[0659] The generating AI identifies a high-risk situation and automatically modifies firewall settings and blocks suspicious IP addresses. It also disconnects the affected devices from the network and sends an emergency alert to the administrator. The administrator reviews the generated detailed report and takes further action.

[0660] Example of a prompt

[0661] "Design a smartphone app with real-time monitoring and anomaly detection capabilities to predict and prevent cyberattacks. This app will use Scapy to analyze network traffic and send email alerts if anomalies are detected."

[0662] The flow of a specific process in Application Example 1 will be explained using Figure 12.

[0663] Step 1:

[0664] Data collection

[0665] Subject: Server

[0666] The server collects log data and network traffic information in real time from multiple terminals within a distributed network. The input consists of communication logs and network traffic data transmitted from each terminal. The server collects this data using APIs and log analysis tools and stores it in a central database. The output is the collected data stored in the central database, prepared for analysis.

[0667] Step 2:

[0668] Data analysis and reference pattern generation

[0669] Subject: Server

[0670] The server analyzes data stored in a central database using data analysis tools (e.g., Python machine learning libraries). Input includes collected log data and network traffic information. The server analyzes this data and generates normal activity patterns (reference patterns). The generated reference patterns are stored in the database as output, forming the basis for anomaly detection.

[0671] Step 3:

[0672] Real-time analysis and anomaly detection

[0673] Subject: Generative AI

[0674] Generative AI scans newly collected data (traffic information and log data) in real time and detects deviations from baseline patterns. Its input includes data collected in real time and baseline patterns. The generative AI identifies anomalies by comparing them to historical data. This often detects abnormal traffic patterns or sudden large-scale data transfers. The output is the generated data of the detected anomalies.

[0675] Step 4:

[0676] Threat prediction and risk assessment

[0677] Subject: Generative AI

[0678] Generative AI predicts future attack patterns based on detected anomalous data. Its inputs include anomalous data and a database of known threats. The generative AI runs simulations and outputs prediction results. These predictions allow for a risk level assessment, categorized into low, medium, and high.

[0679] Step 5:

[0680] Generation and execution of automated responses

[0681] Subject: Generative AI

[0682] The generative AI generates and executes automated response scenarios based on the risk level. Its inputs include risk assessment results and response scenario templates. For example, in high-risk cases, it might automatically modify firewall settings, block harmful IP addresses, or disconnect specific devices from the network. The output records the implemented countermeasures.

[0683] Step 6:

[0684] Alert generation and administrator notifications

[0685] Subject: Generative AI

[0686] The generation AI automatically handles the situation and then sends a real-time notification to the administrator, including the results. Inputs include the automated response results and the administrator's contact information. Notifications are sent via email, SMS, dashboards, etc. Outputs include the notification sent to the administrator and a detailed report. This report includes detected anomalies, implemented countermeasures, and risk assessments.

[0687] The above outlines the specific processing flow within this system.

[0688] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.

[0689] This invention is a system for preventing digital crime in industries with high information density and significant economic impact. The system combines abnormal pattern detection, threat prediction, automated response, administrator notification, and an emotion engine that recognizes user emotions.

[0690] 1. Data Collection

[0691] Subject: Server

[0692] The server continuously collects log data, user activity information, network traffic, and user sentiment data in real time from multiple terminals within the network. The server stores this data in a central database and prepares it for analysis. APIs and log analysis tools are used in this process.

[0693] 2. Data Analysis and Reference Pattern Generation

[0694] Subject: Server

[0695] The server activates a data analysis module and analyzes the large amount of collected data. This analysis uses machine learning algorithms to generate normal activity patterns (reference patterns). Based on these reference patterns, abnormal data is detected.

[0696] 3. Real-time analysis and anomaly detection

[0697] Subject: Generative AI

[0698] Generative AI scans new data in real time to detect any anomalous patterns that deviate from the baseline. If an anomaly is found, it analyzes its details to identify the type of anomaly. For example, large-scale data transfers or unusual login attempts might be detected here.

[0699] 4. Analysis using an emotion engine

[0700] Subject: Generative AI

[0701] Generative AI analyzes user emotional data in real time to detect abnormal emotional patterns. Specifically, the emotion engine uses emotion recognition algorithms to track changes in the user's emotions and identify anomalies that deviate from the normal range. This allows for an assessment of whether the user's stress or anxiety is related to a cyberattack.

[0702] 5. Threat Prediction and Risk Assessment

[0703] Subject: Generative AI

[0704] Generative AI predicts future attack patterns based on detected anomaly and sentiment data. This prediction utilizes a database of known threats and simulation methods to assess risk levels. Risk levels are classified as low, medium, or high, and the priority of response is determined accordingly.

[0705] 6. Generation and execution of automated responses

[0706] Subject: Generative AI

[0707] The generative AI automatically generates response scenarios based on the risk level. For example, if a high risk is detected, specific countermeasures are generated, such as changing firewall settings, blocking harmful IP addresses, disconnecting specific devices from the network, and sending emotional care notifications to users.

[0708] 7. Execute automated response

[0709] Subject: Generative AI

[0710] Based on automated response scenarios generated by a generative AI, security measures are implemented sequentially. For example, it sends emotional care notifications to users and suggests psychological counseling as needed.

[0711] 8. Alert generation and administrator notifications

[0712] Subject: Generative AI

[0713] The generative AI notifies administrators of the results of its automated response. Notifications are sent in real time via email, SMS, dashboards, etc. A detailed report is also generated for administrator review. This report includes information on detected anomalies, implemented countermeasures, risk assessments, and user sentiment.

[0714] Specific example

[0715] Specific example 1: Suspicious transactions at financial institutions

[0716] Subject: Server

[0717] A server monitors financial institution transaction data and user sentiment data in real time. The server then uses a generative AI to analyze the transaction and sentiment data. If the generative AI detects an unusually high-value transaction and the user's sentiment data also shows abnormalities, it indicates a potential fraud.

[0718] Subject: Generative AI

[0719] The generative AI automatically implements temporary suspension measures and sends emotional care notifications to the user. An alert is sent to the administrator, and a detailed report is provided, allowing for further investigation and corrective action.

[0720] Specific example 2: Cyberattacks on government agencies

[0721] Subject: Server

[0722] The server monitors government agency communication traffic and employee sentiment data 24 hours a day. The server detects unusual large-scale file transfers, and generative AI analyzes them.

[0723] Subject: Generative AI

[0724] The generative AI identifies a high-risk situation and automatically modifies firewall settings and blocks suspicious IP addresses. It also disconnects the relevant devices from the network and sends emotional care notifications to users. An emergency alert is sent to the administrator, along with a detailed report. The administrator reviews the report and takes further action.

[0725] As described above, by combining this system with an emotion engine, it enables more accurate anomaly detection and rapid response, effectively protecting industries with high information confidentiality.

[0726] The following describes the processing flow.

[0727] Step 1: Data Collection

[0728] Subject: Server

[0729] The server collects log data, user activity information, network traffic, and user sentiment data in real time from multiple terminals within the network. The server stores this data in a central database. The collection process uses APIs and log analysis tools to retrieve and record data in a consistent format.

[0730] Step 2: Data analysis and reference pattern generation

[0731] Subject: Server

[0732] The server activates a data analysis module and analyzes the collected data. It applies machine learning algorithms to learn and generate normal activity patterns (reference patterns) and emotional patterns. Based on these reference patterns, abnormal data is detected.

[0733] Step 3: Analyzing user sentiment data

[0734] Subject: Generative AI

[0735] Generative AI analyzes user emotional data in real time to detect abnormal emotional fluctuations. The emotion engine uses emotion recognition algorithms to monitor the user's emotional state and identify changes that deviate from the normal range. If the user is experiencing excessive stress or anxiety, this information is recorded.

[0736] Step 4: Real-time analysis and anomaly detection

[0737] Subject: Generative AI

[0738] Generative AI scans new data in real time and detects anomalous patterns that deviate from the baseline. For example, it can detect large-scale data transfers or fraudulent login attempts. Furthermore, if anomalies in emotional data are associated with technical anomalies, that information is also analyzed.

[0739] Step 5: Threat prediction and risk assessment

[0740] Subject: Generative AI

[0741] Generative AI predicts future attack patterns based on detected anomalies. It compares these anomalies against a database of known threats to predict how they will develop. Simultaneously, it considers user sentiment data to assess the risk level, which is categorized as low, medium, or high.

[0742] Step 6: Generate automated responses

[0743] Subject: Generative AI

[0744] The generative AI generates automated response scenarios based on the risk level. For example, if the risk is high, it will automatically change firewall settings, block harmful IP addresses, disconnect specific devices from the network, and send emotional care notifications to users.

[0745] Step 7: Execute automated response

[0746] Subject: Generative AI

[0747] Based on automated response scenarios generated by a generative AI, security measures are executed sequentially. For example, firewall settings are changed in real time, related IP addresses are blocked, and specific devices are disconnected from the network. Additionally, emotional support notifications are sent to users, suggesting responses such as psychological counseling.

[0748] Step 8: Alert generation and administrator notification

[0749] Subject: Generative AI

[0750] The generative AI notifies administrators of the results of its automated response. Notifications are sent in real time via email, SMS, dashboards, etc. A detailed report is generated and provided to administrators. This report includes information on detected anomalies, actions taken, risk assessments, and user sentiment.

[0751] The above steps enable effective prevention of digital crime in industries with high information confidentiality, and allow for rapid response. By combining this with an emotion engine, the correlation between technical anomalies and users' emotional states is enhanced, enabling more accurate anomaly detection and countermeasures.

[0752] (Example 2)

[0753] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server" and the smart glasses 214 will be referred to as the "terminal".

[0754] To prevent digital crime in industries with high information density and significant economic impact, it is necessary to perform complex analysis that considers not only the detection of abnormal data patterns but also the emotional state of users. However, conventional systems do not provide a consistent solution that includes the analysis of emotional data, the detection of its anomalies, and the generation and execution of automated countermeasures. As a result, the accuracy of anomaly detection and threat prediction is insufficient, making it difficult to respond quickly and appropriately. Furthermore, there is a lack of functionality to notify administrators of the results of the response after an anomaly is detected in real time and to provide detailed reports.

[0755] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.

[0756] In this invention, the server includes means for continuously collecting log data, user activity information, network traffic, and sentiment data from multiple terminals in a distributed network in order to prevent digital crime; data analysis means for generating normal activity patterns and creating a baseline pattern based on the data; real-time analysis means for detecting anomalies that deviate from the baseline pattern and performing detailed analysis to identify the type of anomaly; sentiment analysis means for analyzing user sentiment data and detecting anomalies that deviate from the normal range; threat prediction means for predicting future attack patterns and evaluating risk levels based on the anomaly data and sentiment data; automated response means for generating automated response scenarios according to the risk level evaluated by the threat prediction means and automatically executing security measures when the risk is high; and alert issuing means for notifying the administrator of the results of the response by the automated response means and generating a detailed report. This improves the accuracy of anomaly detection in information-sensitive industries and enables quick and appropriate responses.

[0757] A "distributed network" is a network in which multiple terminals and servers are distributed and communicate with each other to share data.

[0758] "Log data" refers to records of operations generated by systems and applications, and includes access logs, authentication logs, error logs, etc.

[0759] "User activity information" refers to the history of operations and actions performed by a user within a system or application, and includes operation logs, browsing history, and other similar information.

[0760] "Network traffic" refers to the flow of data sent and received through a network, and includes the volume of packets sent and received, as well as the timing of communication.

[0761] "Emotional data" refers to data that indicates a user's emotional state, and includes facial expression data and biosignals acquired from emotion recognition systems and biometric sensors.

[0762] "Data analysis methods" refer to means for analyzing collected data and generating normal activity patterns or baseline patterns, and include machine learning algorithms and data mining techniques.

[0763] A "reference pattern" is a standard data pattern that represents normal activity and serves as a comparison criterion for identifying abnormal data.

[0764] "Real-time analysis means" refers to a method for analyzing new data in real time, detecting anomalies that deviate from the standard pattern, and identifying their type.

[0765] "Emotional analysis means" refers to methods for analyzing a user's emotional data and detecting anomalies that deviate from the normal range, and includes emotional recognition algorithms and biosignal analysis technologies.

[0766] "Threat prediction tools" refer to methods for predicting future attack patterns and assessing risk levels based on anomalous data and sentiment data.

[0767] "Automated response measures" refer to methods that automatically generate security measures based on risk assessments using threat prediction and execute them when the risk is high, and include changing firewall settings and disconnecting from the network.

[0768] "Alert generation method" refers to a method for notifying administrators of the results of responses by automated response methods and generating and providing detailed reports.

[0769] This invention is a system for preventing digital crime in industries with high information density and significant economic impact. The system combines abnormal pattern detection, threat prediction, automated response, administrator notification, and an emotion engine that recognizes user emotions.

[0770] Data collection

[0771] Subject: Server

[0772] The server continuously collects data from multiple terminals within the corporate network. This data includes log data (access logs, authentication logs, error logs, etc.), user activity information (operation logs, browsing history, etc.), network traffic, and sentiment data (facial expression data from sentiment recognition systems and biometric sensors, etc.). To collect this data, the server uses APIs and log analysis tools (e.g., Elasticsearch, Splunk). The collected data is stored in a central database and prepared for analysis.

[0773] Data Analysis

[0774] Subject: Server

[0775] The server starts the data analysis module and analyzes the collected data. Specifically, the process proceeds as follows:

[0776] Machine learning algorithms (e.g., TensorFlow and Scikit-learn) are used to learn typical activity patterns from past data.

[0777] Clustering and anomaly detection techniques are used to generate normal activity patterns (reference patterns).

[0778] Real-time analysis

[0779] Subject: Generative AI

[0780] The generative AI retrieves new data from a central database in real time and compares it against a baseline pattern. This allows for the detection of anomalous patterns in real time. The stream processing engine used (e.g., Apache Kafka, Apache Storm) monitors the new data in real time and detects anomalous patterns that deviate from the baseline pattern.

[0781] Analysis using an emotion engine

[0782] Subject: Generative AI

[0783] Generative AI analyzes user emotional data in real time. Specifically, it uses emotion recognition algorithms (e.g., face detection using Haar-like features, deep learning emotion classification models) to analyze the user's real-time facial expressions and biometric information. If the emotional data deviates from the normal range, the generative AI identifies the anomaly.

[0784] Threat prediction

[0785] Subject: Generative AI

[0786] Generative AI predicts future attack patterns based on anomalous and sentiment data. By cross-referencing with known threat databases (e.g., CVE databases) and using simulation methods, it constructs risk scenarios and assesses risk levels. Risk levels are classified into three stages: low, medium, and high.

[0787] Automated response scenarios

[0788] Subject: Generative AI

[0789] The generative AI generates automated response scenarios based on risk assessments. Specific countermeasures include modifying firewall settings, blocking harmful IP addresses, and disconnecting specific devices from the network. It also provides emotional care notifications and suggests psychological counseling as countermeasures against emotional disturbances.

[0790] Execute automated response

[0791] Subject: Generative AI

[0792] The generative AI will perform the following security measures based on the generated automated response scenarios:

[0793] You will need to use a network management tool (e.g., Cisco ASA, pfSense) to change firewall settings.

[0794] Update the access control list to block suspicious IP addresses.

[0795] Disconnect the terminal experiencing the malfunction from the network.

[0796] Additionally, the system sends emotional care notifications to users and suggests psychological counseling as needed.

[0797] Alert generation and administrator notifications

[0798] Subject: Generative AI

[0799] The generative AI notifies administrators of the results of its automated responses. These notifications are delivered in real time via email, SMS, or a dashboard. Furthermore, a detailed report is generated for administrator review. This report includes information on detected anomalies, implemented actions, risk assessments, and user sentiment.

[0800] Specific example

[0801] Specific example 1: Suspicious transactions at financial institutions

[0802] Subject: Server

[0803] A server monitors financial institution transaction data and user sentiment data in real time. The server then uses generative AI to analyze the transaction and sentiment data. If the generative AI detects an unusually high-value transaction and the user sentiment data also shows abnormalities, it indicates a potential fraud.

[0804] Subject: Generative AI

[0805] The generative AI automatically implements temporary suspension measures and sends emotional care notifications to the user. It also sends alerts to administrators and provides detailed reports to facilitate further investigation and countermeasures.

[0806] Specific example 2: Cyberattacks on government agencies

[0807] Subject: Server

[0808] The server monitors government agency communication traffic and employee sentiment data 24 hours a day. The server detects unusual large-scale file transfers, which are then analyzed by generative AI.

[0809] Subject: Generative AI

[0810] The generation AI identifies the situation as high-risk and automatically modifies firewall settings and blocks suspicious IP addresses. It also disconnects the relevant devices from the network and sends emotional care notifications to users. An emergency alert is sent to the administrator, providing a detailed report. The administrator reviews the report and takes further action.

[0811] Example of a prompt

[0812] "Based on the analysis of the new data, an abnormal pattern has been detected. The sentiment data also shows abnormalities, so please generate specific countermeasures."

[0813] The flow of the specific processing in Example 2 will be explained using Figure 13.

[0814] Step 1:

[0815] Inputs: Log data, user activity information, network traffic, sentiment data

[0816] Specific operation: The server collects this data in real time from multiple terminals within the corporate network.

[0817] Data processing: Collect data using APIs and log analysis tools (e.g., Elasticsearch, Splunk) and store it in a central database.

[0818] Output: Collected data stored in the central database

[0819] Step 2:

[0820] Input: Collected data stored in the central database

[0821] Specific operation: The server starts the data analysis module and begins analyzing the stored data.

[0822] Data processing: Machine learning algorithms (e.g., TensorFlow or Scikit-learn) are used to learn normal activity patterns from past data and generate normal activity patterns (reference patterns). Clustering and anomaly detection methods are employed.

[0823] Output: Generated reference pattern

[0824] Step 3:

[0825] Input: Newly collected data, reference pattern

[0826] Specific operation: The generative AI retrieves new data from a central database in real time and compares it against a reference pattern.

[0827] Data processing: Using stream processing engines (e.g., Apache Kafka, Apache Storm), new data is monitored in real time, and abnormal patterns that deviate from the baseline pattern are detected.

[0828] Output: List of detected anomaly patterns

[0829] Step 4:

[0830] Input: Collected emotional data

[0831] Specific operation: A generative AI analyzes emotional data in real time.

[0832] Data processing: We analyze user facial expressions and biometric information using emotion recognition algorithms (e.g., face detection using Haar-like features, deep learning emotion classification models).

[0833] Output: List of abnormal emotional patterns

[0834] Step 5:

[0835] Input: Abnormal data, sentiment data

[0836] Specific operation: Generative AI predicts future attack patterns based on anomaly data and emotional data.

[0837] Data processing: The data is compared with known threat databases (e.g., CVE databases), and risk scenarios are constructed using simulation methods to evaluate risk levels.

[0838] Output: Risk Assessment Report

[0839] Step 6:

[0840] Input: Risk assessment report

[0841] Specific operation: The generative AI generates automated response scenarios based on risk assessment.

[0842] Data processing: As automated response scenarios, it performs actions such as changing firewall settings, blocking harmful IP addresses, disconnecting specific devices from the network, and generating emotional care notifications.

[0843] Output: Automated response scenario

[0844] Step 7:

[0845] Input: Automated response scenario

[0846] Specific operation: The generative AI executes security measures based on the scenarios it generates.

[0847] Data processing: Use network management tools (e.g., Cisco ASA, pfSense) to modify firewall settings, block IP addresses to prevent unauthorized access, and disconnect terminals that have experienced problems. Also, send emotional care notifications to users and suggest psychological counseling as needed.

[0848] Output: Security measures taken

[0849] Step 8:

[0850] Input: Results of security measures taken

[0851] Specific operation: The generative AI notifies the administrator of the results of its response.

[0852] Data processing: Generate detailed reports and send real-time notifications to administrators via email, SMS, and dashboards.

[0853] Output: Notification to administrator and detailed report

[0854] (Application Example 2)

[0855] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server," and the smart glasses 214 will be referred to as the "terminal."

[0856] Traditional security systems focus on detecting and countering unusual patterns of digital crime, but they fail to consider the emotional state of users. This shortcoming can lead to reduced accuracy in predicting potential threats and delays in optimal responses, especially in industries with high information sensitivity and significant economic impact. Furthermore, there is a lack of emotional support for users who experience psychological stress as a result of cyberattacks. This increases the risk of data breaches and cyberattacks, which is a significant challenge.

[0857] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means.

[0858] In this invention, the server includes means for collecting data from multiple terminals in a distributed network in order to detect abnormal patterns in real time; data analysis means for generating normal activity patterns and creating a reference pattern based on the data; threat prediction means using generative AI to detect abnormalities that deviate from the reference pattern and predict future attack patterns; automated response means for automatically generating and executing countermeasures against abnormalities detected by the threat prediction means; emotion analysis means for the automated response means to monitor the user's emotional state in real time and detect abnormal emotional patterns; means for generating an emotional care notification when an abnormality is detected; and alert issuing means. This enables rapid and accurate detection of abnormalities, execution of appropriate countermeasures, and care that takes into account the user's emotional state.

[0859] An "abnormal pattern" refers to data or behavioral tendencies that deviate from the standard pattern and are not typically observed.

[0860] A "distributed network" refers to a network in which multiple terminals are interconnected and data is exchanged in a distributed manner.

[0861] "Data collection means" refers to methods and devices for collecting log data, user activity information, network traffic, and user sentiment data from terminals within a network.

[0862] "Data analysis means" refers to methods and devices for analyzing collected data, generating normal activity patterns, and creating reference patterns.

[0863] "Generative AI" refers to artificial intelligence systems that use machine learning and deep learning technologies to analyze data in real time and detect anomalies.

[0864] "Threat prediction means" refers to methods and devices that use generative AI to predict future attack patterns based on detected anomaly data.

[0865] "Automated response means" refers to methods or devices for automatically generating and executing countermeasures in response to detected anomalies.

[0866] "Emotional analysis means" refers to methods and devices for monitoring a user's emotional state in real time and detecting abnormal emotional patterns.

[0867] "Emotional care notifications" refer to relaxation notifications and support suggestions sent to a user when their emotional state is abnormal.

[0868] "Alert notification means" refers to methods or devices for notifying administrators of the results of responses by automated response means.

[0869] The system that implements this application has the following configuration.

[0870] 1. Data acquisition module

[0871] The server collects log data, user activity information, network traffic, and user sentiment data in real time from multiple terminals within a distributed network. APIs and log analysis tools (e.g., Splunk, Prometheus) are used for this purpose. The collected data is stored in a central database and prepared for subsequent analysis.

[0872] 2. Data Analysis Module

[0873] The server analyzes the large amount of collected data using machine learning algorithms (e.g., Scikit-learn, TensorFlow). As a result of the analysis, normal activity patterns (reference patterns) are generated, which serve as criteria for detecting anomalies. These reference patterns are stored in the server's central database and form the basis for real-time analysis.

[0874] 3. Real-time analysis module

[0875] Generative AI scans new data in real time and detects anomalous patterns that deviate from the baseline pattern. This process uses AI models (e.g., YOLO, RNN) to perform data calculations. If an anomaly is found, its details are analyzed to identify the type of anomaly (e.g., large-scale data transfer, abnormal login attempt).

[0876] 4. Emotion Analysis Module

[0877] Generative AI analyzes user emotional data in real time to detect abnormal emotional patterns. Emotional analysis uses emotion recognition algorithms (e.g., OpenCV, IBM Watson) to track changes in the user's emotions. This identifies emotional anomalies that deviate from the normal range and allows for evaluation of whether the user's stress or anxiety is related to cyberattacks.

[0878] 5. Threat Prediction Module

[0879] Generative AI predicts future attack patterns based on detected anomaly and sentiment data. Threat prediction utilizes known threat databases and simulation methods, and risk levels are assessed. Risk levels are classified as low, medium, or high, and response priorities are determined.

[0880] 6. Automated response module

[0881] The generative AI generates automated response scenarios based on the risk level. If a high risk is detected, firewall settings are modified, harmful IP addresses are blocked, specific devices are disconnected from the network, and emotional care notifications are generated for the user. These countermeasures are executed sequentially, with the server coordinating the entire process.

[0882] 7. Alert generation module

[0883] The generative AI notifies administrators of the results of automated responses in real time. Notifications are sent via email, SMS, and dashboards (e.g., Grafana). A detailed report is also generated for administrator review. This report includes information on detected anomalies, actions taken, risk assessment, and user sentiment.

[0884] For example, a server might detect a combination of abnormal network traffic and a sudden increase in user stress. In this case, the system automatically isolates the network segment and sends a relaxation notification to the user.

[0885] Examples of prompt statements are as follows:

[0886] Monitor network traffic for sudden increases and user stress levels, and implement automated countermeasures if anomalies are detected.

[0887] The above describes the embodiments for carrying out this invention.

[0888] The flow of a specific process in Application Example 2 will be explained using Figure 14.

[0889] Step 1: Data Collection

[0890] The server collects log data, user activity information, network traffic, and user sentiment data in real time from multiple terminals within the network. APIs (e.g., RESTful APIs) and log analysis tools (e.g., Splunk, Prometheus) are used for this collection. The collected data is sent to and stored in a central database. Inputs include terminal log data, network traffic data, and sentiment data, while output is the integration of this data into the central database.

[0891] Step 2: Data Analysis

[0892] The server launches a data analysis module and analyzes the large amount of collected data using machine learning algorithms (e.g., Scikit-learn, TensorFlow). The goal of the analysis is to generate normal activity patterns and create a baseline pattern. The input includes data stored in a central database, and the output is a baseline pattern. This baseline pattern serves as the basis for subsequent real-time analysis.

[0893] Step 3: Real-time analysis

[0894] Generative AI scans new data in real time to check for anomalous patterns that deviate from the baseline pattern. An AI model (e.g., YOLO, RNN) is used for this scan. Input includes newly collected real-time data and the baseline pattern, and output is details of any detected anomalies. If an anomaly is found, its details are passed on to the next analysis step.

[0895] Step 4: Emotion Analysis

[0896] The generative AI uses an emotion analysis module to analyze user emotion data in real time. The input includes emotion data acquired in real time, and the output detects abnormal emotion patterns. Emotion recognition algorithms (e.g., OpenCV, IBM Watson) are used to track changes in the user's emotions and identify anomalies that deviate from the normal range.

[0897] Step 5: Threat Prediction

[0898] Generative AI predicts future attack patterns based on anomalies detected through real-time analysis and sentiment analysis. This prediction utilizes a database of known threats and simulation methods, and the risk level is assessed. Input includes detected anomaly data and sentiment data, and output is a prediction result categorized by risk level. The risk level is classified as either low, medium, or high.

[0899] Step 6: Generate and execute automated responses

[0900] The generative AI generates automated response scenarios based on the risk level. If a high risk is detected, it will take actions such as changing firewall settings, blocking harmful IP addresses, disconnecting specific devices from the network, and generating emotional care notifications for users. The input includes prediction results categorized by risk level, and the output is the execution of specific countermeasures.

[0901] Step 7: Issue an alert

[0902] The generative AI notifies administrators of the results of automated responses. Notifications are sent in real time via email, SMS, and dashboards (e.g., Grafana). Inputs include the results of automated responses, and outputs generate alerts for administrators. A detailed report is also generated, which includes information on detected anomalies, implemented countermeasures, risk assessments, and user sentiment.

[0903] The specific processing unit 290 transmits the result of the specific processing to the smart glasses 214. In the smart glasses 214, the control unit 46A causes the speaker 240 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.

[0904] Data generation model 58 is a type of so-called generative AI (Artificial Intelligence). One example of data generation model 58 is ChatGPT (Internet search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[0905] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and the specific processing may also be performed by the smart glasses 214.

[0906] [Third Embodiment]

[0907] Figure 5 shows an example of the configuration of the data processing system 310 according to the third embodiment.

[0908] As shown in Figure 5, the data processing system 310 includes a data processing device 12 and a headset terminal 314. An example of the data processing device 12 is a server.

[0909] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[0910] The headset terminal 314 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication interface 44, and a display 343. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, camera 42, and display 343 are also connected to the bus 52.

[0911] The microphone 238 receives voice signals from the user 20 and receives instructions from the user 20. The microphone 238 captures the voice signals from the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.

[0912] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the area around the user 20 (for example, an imaging range defined by a field of view equivalent to the width of a typical healthy person's field of vision).

[0913] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.

[0914] Figure 6 shows an example of the main functions of the data processing device 12 and the headset terminal 314. As shown in Figure 6, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.

[0915] The specific processing program 56 is an example of a "program" relating to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[0916] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[0917] In the headset terminal 314, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.

[0918] Next, the specific processing performed by the specific processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the headset terminal 314 will be referred to as the "terminal".

[0919] The present invention will now describe specific embodiments for carrying out the invention. The present invention is a system for preventing digital crime against industries with high information density and significant economic impact (e.g., government, finance, telecommunications, etc.). This system has multiple functions, including detection of abnormal patterns, threat prediction, automated response, and administrator notification.

[0920] 1. Data Collection

[0921] Subject: Server

[0922] First, the server continuously collects log data and traffic information in real time from multiple terminals within the network. The server stores this data in a central database and prepares it for analysis. APIs and log analysis tools are used during this process.

[0923] 2. Data Analysis and Reference Pattern Generation

[0924] Subject: Server

[0925] Next, the server uses a data analysis module to analyze the large amount of data it has collected. This analysis employs machine learning algorithms to generate normal activity patterns (reference patterns). Based on these reference patterns, abnormal data is detected.

[0926] 3. Real-time analysis and anomaly detection

[0927] Subject: Generative AI

[0928] Generative AI scans data in real time to detect unusual activity and traffic patterns. This AI compares historical data with baseline patterns to quickly identify anomalies. In this process, for example, sudden large-scale data transfers or unusual login attempts may be detected.

[0929] 4. Threat prediction and risk assessment

[0930] Subject: Generative AI

[0931] Generative AI predicts future attack patterns based on detected anomalies. This prediction utilizes known threat databases and simulation methods. Based on the prediction results, the risk level is assessed. Risk levels are categorized into low, medium, and high, and the priority of response is determined accordingly.

[0932] 5. Generation and execution of automated responses

[0933] Subject: Generative AI

[0934] The generative AI generates automated response scenarios based on the risk level. For example, if a high risk is detected, the AI ​​automatically modifies firewall settings, blocks harmful IP addresses, and disconnects specific devices from the network. In the case of medium risk, it enhances system log monitoring and issues warnings for specific actions.

[0935] 6. Alert generation and administrator notifications

[0936] Subject: Generative AI

[0937] Finally, after the generative AI completes automated response measures, it sends a real-time notification to the administrator, including the results. This notification is delivered via email, SMS, dashboard, etc. Furthermore, a detailed report is generated and provided for administrator review. This report includes detected anomalies, implemented countermeasures, and risk assessments.

[0938] Specific example

[0939] Specific example 1: Suspicious transactions at financial institutions

[0940] Subject: Server

[0941] A server monitors financial institutions' transaction data in real time, and the server then uses a generative AI to analyze the transaction data. The generative AI detects unusually high-value transactions, compares them to past fraud patterns, and determines that there is a high probability of fraud.

[0942] Subject: Generative AI

[0943] The generation AI automatically implements a temporary freeze measure and sends an alert to the administrator. The administrator reviews the detailed report provided and conducts further investigation.

[0944] Specific example 2: Cyberattacks on government agencies

[0945] Subject: Server

[0946] A server monitors government agency communication traffic 24 hours a day. The server detects unusual large-scale file transfers, and a generative AI analyzes them.

[0947] Subject: Generative AI

[0948] The generating AI identifies a high-risk situation and automatically modifies firewall settings and blocks suspicious IP addresses. It also disconnects the affected devices from the network and sends an emergency alert to the administrator. The administrator reviews the generated detailed report and takes further action.

[0949] As described above, this system, with its advanced AI technology and automated security measures, can quickly and effectively protect critical industries from digital crime.

[0950] The following describes the processing flow.

[0951] Step 1: Data Collection

[0952] Subject: Server

[0953] The server collects data in real time from multiple terminals within a distributed network. Specifically, it retrieves log data, user activity information, network traffic, etc., from each terminal using APIs and stores them in a central database. The collected data is recorded and stored in a consistent manner.

[0954] Step 2: Data analysis and reference pattern generation

[0955] Subject: Server

[0956] The server starts the data analysis module and begins analyzing the collected data. It applies machine learning algorithms to learn normal activity patterns and generate baseline patterns. These baseline patterns are used as templates for anomaly detection.

[0957] Step 3: Real-time analysis and anomaly detection

[0958] Subject: Generative AI

[0959] Generative AI scans new data in real time to detect any anomalous patterns that deviate from the baseline. If an anomaly is found, it analyzes its details to identify the type of anomaly. For example, large-scale data transfers or unusual login attempts might be detected here.

[0960] Step 4: Threat prediction and risk assessment

[0961] Subject: Generative AI

[0962] The generative AI predicts future attack patterns based on detected anomalies. It compares these predictions with existing threat intelligence stored in a database to assess the risk level of new attacks. The risk level is classified as low, medium, or high, and countermeasures are determined.

[0963] Step 5: Generate automated responses

[0964] Subject: Generative AI

[0965] The generation AI automatically generates response scenarios based on the risk level. For example, if a high risk is detected, specific countermeasures such as blocking IP addresses, disconnecting specific devices from the network, and changing firewall settings are generated.

[0966] Step 6: Execute automated response

[0967] Subject: Generative AI

[0968] Based on automated response scenarios generated by a generative AI, security measures are executed sequentially. For example, harmful IP addresses are immediately blocked, and specific devices are isolated from the network.

[0969] Step 7: Alert generation and administrator notification

[0970] Subject: Generative AI

[0971] The generative AI notifies administrators of the results of its automated response. Notifications are sent in real time via email, SMS, dashboards, etc. A detailed report is also generated for administrator review. This report includes detected anomalies, implemented countermeasures, and risk assessments.

[0972] By following these steps, it is possible to effectively prevent digital crimes against industries with high information confidentiality and to respond quickly.

[0973] (Example 1)

[0974] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."

[0975] In today's advanced information society, industries with high information density and significant economic impact (e.g., government, finance, telecommunications) are particularly vulnerable to cyberattacks. Advanced security measures are necessary to prevent digital crime against these industries. However, conventional systems struggle with rapid and effective anomaly detection, threat prediction, and automated response.

[0976] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.

[0977] In this invention, the server includes means for collecting data from multiple terminals in a distributed network in order to detect abnormal patterns in real time; data analysis means for generating normal activity patterns and creating a baseline pattern based on the data; threat prediction means using generative AI to detect anomalies that deviate from the baseline pattern and predict future attack patterns; automated response means for automatically generating and executing countermeasures against anomalies detected by the threat prediction means; and alert issuing means for notifying the administrator of the results of the response by the automated response means. This enables rapid and effective prevention of digital crime and makes it possible to protect critical industries more securely.

[0978] An "abnormal pattern" refers to data or behavior that deviates from normal activity patterns.

[0979] "Data collection method" refers to a system that collects log data, traffic information, and other data from multiple terminals within a distributed network.

[0980] "Data analysis methods" refer to technologies and algorithms that analyze collected data, generate normal activity patterns, and create baseline patterns.

[0981] A "reference pattern" is a definition of a normal activity pattern generated by data analysis methods, and serves as a criterion for detecting abnormal patterns.

[0982] "Generative AI" refers to technologies that use machine learning and artificial intelligence to detect anomalies and perform threat prediction and risk assessment.

[0983] "Threat prediction methods" refer to technologies that use generative AI to detect anomalies that deviate from standard patterns and predict future attack patterns.

[0984] "Automated response measures" refer to technologies that automatically generate and execute appropriate countermeasures in response to anomalies detected by threat prediction measures.

[0985] "Alert notification method" refers to technology used to notify administrators of the results of responses by automated response methods.

[0986] A "machine learning algorithm" refers to an algorithm used in data analysis, specifically a statistical method or model used for anomaly detection.

[0987] "Automatic firewall settings change" refers to a function that automatically changes the settings of the system's protective barrier.

[0988] "Disconnecting a specific device from the network" refers to a function that isolates devices exhibiting abnormal behavior from the network.

[0989] "Blocking harmful IP addresses" refers to a function that blocks IP addresses that may be used for malicious communication.

[0990] This invention is a system for preventing digital crime against industries with high information sensitivity and significant economic impact. This system has multiple functions, including detection of anomalous patterns, threat prediction, automated response, and administrator notification. The specific implementation method of this system is described below.

[0991] Data collection

[0992] Subject: Server

[0993] The server continuously collects log data and traffic information in real time from multiple terminals within a distributed network. Data is efficiently acquired using log analysis tools such as the syslog protocol, NetFlow, and sFlow. The collected data is stored in a NoSQL database (e.g., MongoDB) and organized for later analysis.

[0994] Data analysis and reference pattern generation

[0995] Subject: Server

[0996] Next, the server analyzes the collected data and generates normal activity patterns. Using Python and Scikit-learn, the data is preprocessed, and then a clustering algorithm (e.g., K-means) is executed to create a baseline pattern. This generated baseline pattern forms the basis for anomaly detection.

[0997] Real-time analysis and anomaly detection

[0998] Subject: Generative AI

[0999] Generative AI scans data in real time and uses deep learning frameworks such as TensorFlow to compare generated baseline patterns with historical data. Anomaly detection algorithms such as autoencoders are used to quickly identify anomalous traffic and activity.

[1000] Threat prediction and risk assessment

[1001] Subject: Generative AI

[1002] Generative AI predicts threats and performs risk assessments based on detected anomalies. This is done using the MITRE ATT&CK framework and LSTM models. For predicted attack patterns, it evaluates the risk level as low, medium, or high and determines the priority of response.

[1003] Generation and execution of automated responses

[1004] Subject: Generative AI

[1005] The generative AI generates and executes automated response scenarios based on risk levels. In high-risk cases, it automatically modifies firewall settings using iptables commands to block harmful IP addresses. It also automatically disconnects devices exhibiting abnormal activity from the network.

[1006] Alert generation and administrator notifications

[1007] Subject: Generative AI

[1008] The generative AI notifies administrators of the results of its automated responses. These notifications are sent via email APIs and SMS gateways, and the results are also displayed on a dedicated web dashboard. Furthermore, a detailed report is generated and provided to administrators.

[1009] Specific example

[1010] Specific example 1: Suspicious transactions at financial institutions

[1011] Subject: Server

[1012] The server monitors financial institutions' transaction data in real time, and a generative AI analyzes that data. The generative AI detects unusually high-value transactions and determines that they are highly likely to be fraudulent.

[1013] Subject: Generative AI

[1014] The generation AI automatically implements a temporary freeze measure and sends an alert to the administrator. The administrator reviews a detailed report and conducts further investigation.

[1015] Specific example 2: Cyberattacks on government agencies

[1016] Subject: Server

[1017] The server monitors government agency communication traffic 24 hours a day. The server detects unusual large-scale file transfers, and generative AI analyzes them.

[1018] Subject: Generative AI

[1019] The generation AI identifies a high-risk situation and automatically takes action such as changing firewall settings and blocking suspicious IP addresses. It also disconnects the relevant devices from the network and sends an emergency alert to the administrator. The administrator reviews the generated detailed report and takes further action.

[1020] Example of a prompt

[1021] "Detect anomalous patterns from the given traffic data, compare them to relevant past attack patterns to perform a risk assessment, and then generate appropriate automated countermeasures."

[1022] This invention combines advanced AI technology with automated security measures to quickly and effectively protect critical industries from digital crime.

[1023] The flow of the specific processing in Example 1 will be explained using Figure 11.

[1024] Step 1: Data Collection

[1025] Subject: Server

[1026] Input: Log data and traffic information sent from multiple terminals within a distributed network.

[1027] Specific operation: The server uses the syslog protocol, NetFlow, and sFlow to retrieve log data and traffic information from each terminal. The server uses ping to verify connectivity with each terminal, then starts the syslog daemon to collect log data. It also uses a NetFlow collector to collect traffic information. The collected data is stored in a NoSQL database (e.g., MongoDB).

[1028] Output: Log data and traffic information stored in the database

[1029] Step 2: Data analysis and reference pattern generation

[1030] Subject: Server

[1031] Input: Log data and traffic information stored in the database

[1032] Specific operation: The server analyzes log data and traffic information using Python and Scikit-learn. Data preprocessing includes denoising and data standardization. Then, a clustering algorithm (e.g., K-means) is executed to create a baseline pattern. The generated baseline pattern is then saved back into the database.

[1033] Output: Database where the reference pattern is stored.

[1034] Step 3: Real-time analysis and anomaly detection

[1035] Subject: Generative AI

[1036] Input: Real-time acquired log data and traffic information, baseline patterns

[1037] Specific operation: Generative AI scans data in real time and compares it with historical data and baseline patterns. TensorFlow is used to perform anomaly detection with an Autoencoder algorithm. When abnormal traffic or activity is detected, an alert is generated.

[1038] Output: Anomaly detection results and alerts

[1039] Step 4: Threat prediction and risk assessment

[1040] Subject: Generative AI

[1041] Input: Data on detected anomalies, baseline patterns, and known threat databases.

[1042] Specific operation: Generative AI analyzes detected anomalies using the MITRE ATT&CK framework and LSTM models. It compares them with a known threat database to predict future attack patterns. Risk is assessed in three stages: "low," "medium," and "high," and the priority of response is determined.

[1043] Output: Risk assessment and predicted threat patterns

[1044] Step 5: Generate and execute automated responses

[1045] Subject: Generative AI

[1046] Input: Risk assessment results, anomaly detection results

[1047] Specific operation: The generative AI generates automated response scenarios based on the risk level. In high-risk cases, it modifies firewall settings using iptables commands to block harmful IP addresses. It also automatically disconnects devices exhibiting abnormal activity from the network.

[1048] Output: Automated countermeasures taken and their results

[1049] Step 6: Alert generation and administrator notification

[1050] Subject: Generative AI

[1051] Input: Automated response results, anomaly detection results, risk assessment

[1052] Specific operation: The generative AI notifies the administrator of the results of its automated response. Communication is conducted via email API and SMS gateway, and the results are displayed on a web dashboard. A detailed report is generated for the administrator to review.

[1053] Output: Notification to administrator and detailed report

[1054] (Application Example 1)

[1055] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."

[1056] Current security systems often lack sufficient capabilities to detect anomalies in real time and respond immediately. Furthermore, even when an anomaly is detected, there is a lack of systems that efficiently notify administrators and quickly implement countermeasures. In addition, few systems have reporting capabilities that allow administrators to easily understand the details of anomalies. To address these issues, there is a need for security systems with more advanced anomaly detection, prediction, notification, and reporting capabilities.

[1057] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.

[1058] In this invention, the server includes means for collecting data from multiple terminals in a distributed network in order to detect abnormal patterns in real time; data analysis means for generating normal activity patterns and creating a baseline pattern based on the data; threat prediction means using generative AI to detect abnormalities that deviate from the baseline pattern and predict future attack patterns; automated response means for automatically generating and executing countermeasures against abnormalities detected by the threat prediction means; notification means for sending alerts to an administrator from a specific device and creating a detailed report when a high-risk abnormality is detected; and a notification application that monitors network traffic in real time and reports to the administrator in real time when an abnormality is detected. This makes it possible to quickly detect abnormal patterns and respond immediately, thereby realizing advanced security measures.

[1059] An "anomalous pattern" refers to data on unusual activity or traffic that deviates from the generated baseline pattern.

[1060] A "distributed network" is a network structure in which multiple terminals are connected to each other and exchange data.

[1061] "Data analysis" is the process of using collected data to generate typical activity patterns and baseline patterns.

[1062] A "reference pattern" is an indicator of normal activity patterns generated through data analysis, and serves as a criterion for detecting anomalies.

[1063] "Generative AI" refers to artificial intelligence technology used to predict threats and detect anomalies based on data analysis.

[1064] "Threat prediction" is the process of predicting future attack patterns and risks using generative AI.

[1065] An "automated response mechanism" is a function that automatically generates and executes countermeasures in response to detected anomalies.

[1066] "Notification means" refers to a function that informs administrators of the results of automated response measures and details of any anomalies.

[1067] "Network traffic" refers to data that flows over a network.

[1068] A "notification application" is software that monitors network traffic in real time and reports any anomalies to the administrator.

[1069] A "detailed report" is a document that provides administrators with detailed information about any anomalies that occurred and the countermeasures taken.

[1070] This invention is a security system for preventing digital crime against industries with high information sensitivity and significant economic impact. The specific implementation of this system is described below.

[1071] 1. Data Collection

[1072] Subject: Server

[1073] The server continuously collects log data and traffic information in real time from multiple terminals within a distributed network. This data is stored in a central database and prepared for later analysis. APIs and log analysis tools are used in this process.

[1074] 2. Data Analysis and Reference Pattern Generation

[1075] Subject: Server

[1076] The server analyzes large amounts of data collected using data analysis tools to generate normal activity patterns (reference patterns). Machine learning algorithms (e.g., Python machine learning libraries) are used for this analysis. Based on the generated reference patterns, anomalous data is later detected.

[1077] 3. Real-time analysis and anomaly detection

[1078] Subject: Generative AI

[1079] Generative AI scans data in real time to detect unusual activity and traffic patterns. It compares historical data with baseline patterns to quickly identify anomalies. This process can, for example, detect sudden large-scale data transfers or unusual login attempts.

[1080] 4. Threat prediction and risk assessment

[1081] Subject: Generative AI

[1082] Generative AI predicts future attack patterns based on detected anomalies. This prediction utilizes known threat databases and simulation methods. Based on the prediction results, the risk level is assessed and assigned to a low, medium, or high level. This determines the priority of the response.

[1083] 5. Generation and execution of automated responses

[1084] Subject: Generative AI

[1085] The generative AI generates automated response scenarios based on the risk level. For example, if a high risk is detected, the AI ​​automatically modifies firewall settings, blocks harmful IP addresses, and disconnects specific devices from the network. In the case of medium risk, it enhances system log monitoring and issues warnings for specific actions.

[1086] 6. Alert generation and administrator notifications

[1087] Subject: Generative AI

[1088] After the generation AI completes automated response measures, it sends a real-time notification to the administrator including the results. The notification is delivered via email, SMS, dashboard, etc., and a detailed report is provided to the administrator. This report includes detected anomalies, implemented countermeasures, and risk assessments.

[1089] Specific example

[1090] Example 1: Advanced financial transaction security

[1091] Subject: Server

[1092] A server monitors financial institutions' transaction data in real time, and the server then uses a generative AI to analyze the transaction data. The generative AI detects unusually high-value transactions, compares them to past fraud patterns, and determines that there is a high probability of fraud.

[1093] Subject: Generative AI

[1094] The generation AI automatically implements a temporary freeze measure and sends an alert to the administrator. The administrator reviews the detailed report provided and conducts further investigation.

[1095] Specific example 2: Defending against cyberattacks on government agencies

[1096] Subject: Server

[1097] A server monitors government agency communication traffic 24 hours a day. The server detects unusual large-scale file transfers, and a generative AI analyzes them.

[1098] Subject: Generative AI

[1099] The generating AI identifies a high-risk situation and automatically modifies firewall settings and blocks suspicious IP addresses. It also disconnects the affected devices from the network and sends an emergency alert to the administrator. The administrator reviews the generated detailed report and takes further action.

[1100] Example of a prompt

[1101] "Design a smartphone app with real-time monitoring and anomaly detection capabilities to predict and prevent cyberattacks. This app will use Scapy to analyze network traffic and send email alerts if anomalies are detected."

[1102] The flow of a specific process in Application Example 1 will be explained using Figure 12.

[1103] Step 1:

[1104] Data collection

[1105] Subject: Server

[1106] The server collects log data and network traffic information in real time from multiple terminals within a distributed network. The input consists of communication logs and network traffic data transmitted from each terminal. The server collects this data using APIs and log analysis tools and stores it in a central database. The output is the collected data stored in the central database, prepared for analysis.

[1107] Step 2:

[1108] Data analysis and reference pattern generation

[1109] Subject: Server

[1110] The server analyzes data stored in a central database using data analysis tools (e.g., Python machine learning libraries). Input includes collected log data and network traffic information. The server analyzes this data and generates normal activity patterns (reference patterns). The generated reference patterns are stored in the database as output, forming the basis for anomaly detection.

[1111] Step 3:

[1112] Real-time analysis and anomaly detection

[1113] Subject: Generative AI

[1114] Generative AI scans newly collected data (traffic information and log data) in real time and detects deviations from baseline patterns. Its input includes data collected in real time and baseline patterns. The generative AI identifies anomalies by comparing them to historical data. This often detects abnormal traffic patterns or sudden large-scale data transfers. The output is the generated data of the detected anomalies.

[1115] Step 4:

[1116] Threat prediction and risk assessment

[1117] Subject: Generative AI

[1118] Generative AI predicts future attack patterns based on detected anomalous data. Its inputs include anomalous data and a database of known threats. The generative AI runs simulations and outputs prediction results. These predictions allow for a risk level assessment, categorized into low, medium, and high.

[1119] Step 5:

[1120] Generation and execution of automated responses

[1121] Subject: Generative AI

[1122] The generative AI generates and executes automated response scenarios based on the risk level. Its inputs include risk assessment results and response scenario templates. For example, in high-risk cases, it might automatically modify firewall settings, block harmful IP addresses, or disconnect specific devices from the network. The output records the implemented countermeasures.

[1123] Step 6:

[1124] Alert generation and administrator notifications

[1125] Subject: Generative AI

[1126] The generation AI automatically handles the situation and then sends a real-time notification to the administrator, including the results. Inputs include the automated response results and the administrator's contact information. Notifications are sent via email, SMS, dashboards, etc. Outputs include the notification sent to the administrator and a detailed report. This report includes detected anomalies, implemented countermeasures, and risk assessments.

[1127] The above outlines the specific processing flow within this system.

[1128] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.

[1129] This invention is a system for preventing digital crime in industries with high information density and significant economic impact. The system combines abnormal pattern detection, threat prediction, automated response, administrator notification, and an emotion engine that recognizes user emotions.

[1130] 1. Data Collection

[1131] Subject: Server

[1132] The server continuously collects log data, user activity information, network traffic, and user sentiment data in real time from multiple terminals within the network. The server stores this data in a central database and prepares it for analysis. APIs and log analysis tools are used in this process.

[1133] 2. Data Analysis and Reference Pattern Generation

[1134] Subject: Server

[1135] The server activates a data analysis module and analyzes the large amount of collected data. This analysis uses machine learning algorithms to generate normal activity patterns (reference patterns). Based on these reference patterns, abnormal data is detected.

[1136] 3. Real-time analysis and anomaly detection

[1137] Subject: Generative AI

[1138] Generative AI scans new data in real time to detect any anomalous patterns that deviate from the baseline. If an anomaly is found, it analyzes its details to identify the type of anomaly. For example, large-scale data transfers or unusual login attempts might be detected here.

[1139] 4. Analysis using an emotion engine

[1140] Subject: Generative AI

[1141] Generative AI analyzes user emotional data in real time to detect abnormal emotional patterns. Specifically, the emotion engine uses emotion recognition algorithms to track changes in the user's emotions and identify anomalies that deviate from the normal range. This allows for an assessment of whether the user's stress or anxiety is related to a cyberattack.

[1142] 5. Threat Prediction and Risk Assessment

[1143] Subject: Generative AI

[1144] Generative AI predicts future attack patterns based on detected anomaly and sentiment data. This prediction utilizes a database of known threats and simulation methods to assess risk levels. Risk levels are classified as low, medium, or high, and the priority of response is determined accordingly.

[1145] 6. Generation and execution of automated responses

[1146] Subject: Generative AI

[1147] The generative AI automatically generates response scenarios based on the risk level. For example, if a high risk is detected, specific countermeasures are generated, such as changing firewall settings, blocking harmful IP addresses, disconnecting specific devices from the network, and sending emotional care notifications to users.

[1148] 7. Execute automated response

[1149] Subject: Generative AI

[1150] Based on automated response scenarios generated by a generative AI, security measures are implemented sequentially. For example, it sends emotional care notifications to users and suggests psychological counseling as needed.

[1151] 8. Alert generation and administrator notifications

[1152] Subject: Generative AI

[1153] The generative AI notifies administrators of the results of its automated response. Notifications are sent in real time via email, SMS, dashboards, etc. A detailed report is also generated for administrator review. This report includes information on detected anomalies, implemented countermeasures, risk assessments, and user sentiment.

[1154] Specific example

[1155] Specific example 1: Suspicious transactions at financial institutions

[1156] Subject: Server

[1157] A server monitors financial institution transaction data and user sentiment data in real time. The server then uses a generative AI to analyze the transaction and sentiment data. If the generative AI detects an unusually high-value transaction and the user's sentiment data also shows abnormalities, it indicates a potential fraud.

[1158] Subject: Generative AI

[1159] The generative AI automatically implements temporary suspension measures and sends emotional care notifications to the user. An alert is sent to the administrator, and a detailed report is provided, allowing for further investigation and corrective action.

[1160] Specific example 2: Cyberattacks on government agencies

[1161] Subject: Server

[1162] The server monitors government agency communication traffic and employee sentiment data 24 hours a day. The server detects unusual large-scale file transfers, and generative AI analyzes them.

[1163] Subject: Generative AI

[1164] The generative AI identifies a high-risk situation and automatically modifies firewall settings and blocks suspicious IP addresses. It also disconnects the relevant devices from the network and sends emotional care notifications to users. An emergency alert is sent to the administrator, along with a detailed report. The administrator reviews the report and takes further action.

[1165] As described above, by combining this system with an emotion engine, it enables more accurate anomaly detection and rapid response, effectively protecting industries with high information confidentiality.

[1166] The following describes the processing flow.

[1167] Step 1: Data Collection

[1168] Subject: Server

[1169] The server collects log data, user activity information, network traffic, and user sentiment data in real time from multiple terminals within the network. The server stores this data in a central database. The collection process uses APIs and log analysis tools to retrieve and record data in a consistent format.

[1170] Step 2: Data analysis and reference pattern generation

[1171] Subject: Server

[1172] The server activates a data analysis module and analyzes the collected data. It applies machine learning algorithms to learn and generate normal activity patterns (reference patterns) and emotional patterns. Based on these reference patterns, abnormal data is detected.

[1173] Step 3: Analyzing user sentiment data

[1174] Subject: Generative AI

[1175] Generative AI analyzes user emotional data in real time to detect abnormal emotional fluctuations. The emotion engine uses emotion recognition algorithms to monitor the user's emotional state and identify changes that deviate from the normal range. If the user is experiencing excessive stress or anxiety, this information is recorded.

[1176] Step 4: Real-time analysis and anomaly detection

[1177] Subject: Generative AI

[1178] Generative AI scans new data in real time and detects anomalous patterns that deviate from the baseline. For example, it can detect large-scale data transfers or fraudulent login attempts. Furthermore, if anomalies in emotional data are associated with technical anomalies, that information is also analyzed.

[1179] Step 5: Threat prediction and risk assessment

[1180] Subject: Generative AI

[1181] Generative AI predicts future attack patterns based on detected anomalies. It compares these anomalies against a database of known threats to predict how they will develop. Simultaneously, it considers user sentiment data to assess the risk level, which is categorized as low, medium, or high.

[1182] Step 6: Generate automated responses

[1183] Subject: Generative AI

[1184] The generative AI generates automated response scenarios based on the risk level. For example, if the risk is high, it will automatically change firewall settings, block harmful IP addresses, disconnect specific devices from the network, and send emotional care notifications to users.

[1185] Step 7: Execute automated response

[1186] Subject: Generative AI

[1187] Based on automated response scenarios generated by a generative AI, security measures are executed sequentially. For example, firewall settings are changed in real time, related IP addresses are blocked, and specific devices are disconnected from the network. Additionally, emotional support notifications are sent to users, suggesting responses such as psychological counseling.

[1188] Step 8: Alert generation and administrator notification

[1189] Subject: Generative AI

[1190] The generative AI notifies administrators of the results of its automated response. Notifications are sent in real time via email, SMS, dashboards, etc. A detailed report is generated and provided to administrators. This report includes information on detected anomalies, actions taken, risk assessments, and user sentiment.

[1191] The above steps enable effective prevention of digital crime in industries with high information confidentiality, and allow for rapid response. By combining this with an emotion engine, the correlation between technical anomalies and users' emotional states is enhanced, enabling more accurate anomaly detection and countermeasures.

[1192] (Example 2)

[1193] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."

[1194] To prevent digital crime in industries with high information density and significant economic impact, it is necessary to perform complex analysis that considers not only the detection of abnormal data patterns but also the emotional state of users. However, conventional systems do not provide a consistent solution that includes the analysis of emotional data, the detection of its anomalies, and the generation and execution of automated countermeasures. As a result, the accuracy of anomaly detection and threat prediction is insufficient, making it difficult to respond quickly and appropriately. Furthermore, there is a lack of functionality to notify administrators of the results of the response after an anomaly is detected in real time and to provide detailed reports.

[1195] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.

[1196] In this invention, the server includes means for continuously collecting log data, user activity information, network traffic, and sentiment data from multiple terminals in a distributed network in order to prevent digital crime; data analysis means for generating normal activity patterns and creating a baseline pattern based on the data; real-time analysis means for detecting anomalies that deviate from the baseline pattern and performing detailed analysis to identify the type of anomaly; sentiment analysis means for analyzing user sentiment data and detecting anomalies that deviate from the normal range; threat prediction means for predicting future attack patterns and evaluating risk levels based on the anomaly data and sentiment data; automated response means for generating automated response scenarios according to the risk level evaluated by the threat prediction means and automatically executing security measures when the risk is high; and alert issuing means for notifying the administrator of the results of the response by the automated response means and generating a detailed report. This improves the accuracy of anomaly detection in information-sensitive industries and enables quick and appropriate responses.

[1197] A "distributed network" is a network in which multiple terminals and servers are distributed and communicate with each other to share data.

[1198] "Log data" refers to records of operations generated by systems and applications, and includes access logs, authentication logs, error logs, etc.

[1199] "User activity information" refers to the history of operations and actions performed by a user within a system or application, and includes operation logs, browsing history, and other similar information.

[1200] "Network traffic" refers to the flow of data sent and received through a network, and includes the volume of packets sent and received, as well as the timing of communication.

[1201] "Emotional data" refers to data that indicates a user's emotional state, and includes facial expression data and biosignals acquired from emotion recognition systems and biometric sensors.

[1202] "Data analysis methods" refer to means for analyzing collected data and generating normal activity patterns or baseline patterns, and include machine learning algorithms and data mining techniques.

[1203] A "reference pattern" is a standard data pattern that represents normal activity and serves as a comparison criterion for identifying abnormal data.

[1204] "Real-time analysis means" refers to a method for analyzing new data in real time, detecting anomalies that deviate from the standard pattern, and identifying their type.

[1205] "Emotional analysis means" refers to methods for analyzing a user's emotional data and detecting anomalies that deviate from the normal range, and includes emotional recognition algorithms and biosignal analysis technologies.

[1206] "Threat prediction tools" refer to methods for predicting future attack patterns and assessing risk levels based on anomalous data and sentiment data.

[1207] "Automated response measures" refer to methods that automatically generate security measures based on risk assessments using threat prediction and execute them when the risk is high, and include changing firewall settings and disconnecting from the network.

[1208] "Alert generation method" refers to a method for notifying administrators of the results of responses by automated response methods and generating and providing detailed reports.

[1209] This invention is a system for preventing digital crime in industries with high information density and significant economic impact. The system combines abnormal pattern detection, threat prediction, automated response, administrator notification, and an emotion engine that recognizes user emotions.

[1210] Data collection

[1211] Subject: Server

[1212] The server continuously collects data from multiple terminals within the corporate network. This data includes log data (access logs, authentication logs, error logs, etc.), user activity information (operation logs, browsing history, etc.), network traffic, and sentiment data (facial expression data from sentiment recognition systems and biometric sensors, etc.). To collect this data, the server uses APIs and log analysis tools (e.g., Elasticsearch, Splunk). The collected data is stored in a central database and prepared for analysis.

[1213] Data Analysis

[1214] Subject: Server

[1215] The server starts the data analysis module and analyzes the collected data. Specifically, the process proceeds as follows:

[1216] Machine learning algorithms (e.g., TensorFlow and Scikit-learn) are used to learn typical activity patterns from past data.

[1217] Clustering and anomaly detection techniques are used to generate normal activity patterns (reference patterns).

[1218] Real-time analysis

[1219] Subject: Generative AI

[1220] The generative AI retrieves new data from a central database in real time and compares it against a baseline pattern. This allows for the detection of anomalous patterns in real time. The stream processing engine used (e.g., Apache Kafka, Apache Storm) monitors the new data in real time and detects anomalous patterns that deviate from the baseline pattern.

[1221] Analysis using an emotion engine

[1222] Subject: Generative AI

[1223] Generative AI analyzes user emotional data in real time. Specifically, it uses emotion recognition algorithms (e.g., face detection using Haar-like features, deep learning emotion classification models) to analyze the user's real-time facial expressions and biometric information. If the emotional data deviates from the normal range, the generative AI identifies the anomaly.

[1224] Threat prediction

[1225] Subject: Generative AI

[1226] Generative AI predicts future attack patterns based on anomalous and sentiment data. By cross-referencing with known threat databases (e.g., CVE databases) and using simulation methods, it constructs risk scenarios and assesses risk levels. Risk levels are classified into three stages: low, medium, and high.

[1227] Automated response scenarios

[1228] Subject: Generative AI

[1229] The generative AI generates automated response scenarios based on risk assessments. Specific countermeasures include modifying firewall settings, blocking harmful IP addresses, and disconnecting specific devices from the network. It also provides emotional care notifications and suggests psychological counseling as countermeasures against emotional disturbances.

[1230] Execute automated response

[1231] Subject: Generative AI

[1232] The generative AI will perform the following security measures based on the generated automated response scenarios:

[1233] You will need to use a network management tool (e.g., Cisco ASA, pfSense) to change firewall settings.

[1234] Update the access control list to block suspicious IP addresses.

[1235] Disconnect the terminal experiencing the malfunction from the network.

[1236] Additionally, the system sends emotional care notifications to users and suggests psychological counseling as needed.

[1237] Alert generation and administrator notifications

[1238] Subject: Generative AI

[1239] The generative AI notifies administrators of the results of its automated responses. These notifications are delivered in real time via email, SMS, or a dashboard. Furthermore, a detailed report is generated for administrator review. This report includes information on detected anomalies, implemented actions, risk assessments, and user sentiment.

[1240] Specific example

[1241] Specific example 1: Suspicious transactions at financial institutions

[1242] Subject: Server

[1243] A server monitors financial institution transaction data and user sentiment data in real time. The server then uses generative AI to analyze the transaction and sentiment data. If the generative AI detects an unusually high-value transaction and the user sentiment data also shows abnormalities, it indicates a potential fraud.

[1244] Subject: Generative AI

[1245] The generative AI automatically implements temporary suspension measures and sends emotional care notifications to the user. It also sends alerts to administrators and provides detailed reports to facilitate further investigation and countermeasures.

[1246] Specific example 2: Cyberattacks on government agencies

[1247] Subject: Server

[1248] The server monitors government agency communication traffic and employee sentiment data 24 hours a day. The server detects unusual large-scale file transfers, which are then analyzed by generative AI.

[1249] Subject: Generative AI

[1250] The generation AI identifies the situation as high-risk and automatically modifies firewall settings and blocks suspicious IP addresses. It also disconnects the relevant devices from the network and sends emotional care notifications to users. An emergency alert is sent to the administrator, providing a detailed report. The administrator reviews the report and takes further action.

[1251] Example of a prompt

[1252] "Based on the analysis of the new data, an abnormal pattern has been detected. The sentiment data also shows abnormalities, so please generate specific countermeasures."

[1253] The flow of the specific processing in Example 2 will be explained using Figure 13.

[1254] Step 1:

[1255] Inputs: Log data, user activity information, network traffic, sentiment data

[1256] Specific operation: The server collects this data in real time from multiple terminals within the corporate network.

[1257] Data processing: Collect data using APIs and log analysis tools (e.g., Elasticsearch, Splunk) and store it in a central database.

[1258] Output: Collected data stored in the central database

[1259] Step 2:

[1260] Input: Collected data stored in the central database

[1261] Specific operation: The server starts the data analysis module and begins analyzing the stored data.

[1262] Data processing: Machine learning algorithms (e.g., TensorFlow or Scikit-learn) are used to learn normal activity patterns from past data and generate normal activity patterns (reference patterns). Clustering and anomaly detection methods are employed.

[1263] Output: Generated reference pattern

[1264] Step 3:

[1265] Input: Newly collected data, reference pattern

[1266] Specific operation: The generative AI retrieves new data from a central database in real time and compares it against a reference pattern.

[1267] Data processing: Using stream processing engines (e.g., Apache Kafka, Apache Storm), new data is monitored in real time, and abnormal patterns that deviate from the baseline pattern are detected.

[1268] Output: List of detected anomaly patterns

[1269] Step 4:

[1270] Input: Collected emotional data

[1271] Specific operation: A generative AI analyzes emotional data in real time.

[1272] Data processing: We analyze user facial expressions and biometric information using emotion recognition algorithms (e.g., face detection using Haar-like features, deep learning emotion classification models).

[1273] Output: List of abnormal emotional patterns

[1274] Step 5:

[1275] Input: Abnormal data, sentiment data

[1276] Specific operation: Generative AI predicts future attack patterns based on anomaly data and emotional data.

[1277] Data processing: The data is compared with known threat databases (e.g., CVE databases), and risk scenarios are constructed using simulation methods to evaluate risk levels.

[1278] Output: Risk Assessment Report

[1279] Step 6:

[1280] Input: Risk assessment report

[1281] Specific operation: The generative AI generates automated response scenarios based on risk assessment.

[1282] Data processing: As automated response scenarios, it performs actions such as changing firewall settings, blocking harmful IP addresses, disconnecting specific devices from the network, and generating emotional care notifications.

[1283] Output: Automated response scenario

[1284] Step 7:

[1285] Input: Automated response scenario

[1286] Specific operation: The generative AI executes security measures based on the scenarios it generates.

[1287] Data processing: Use network management tools (e.g., Cisco ASA, pfSense) to modify firewall settings, block IP addresses to prevent unauthorized access, and disconnect terminals that have experienced problems. Also, send emotional care notifications to users and suggest psychological counseling as needed.

[1288] Output: Security measures taken

[1289] Step 8:

[1290] Input: Results of security measures taken

[1291] Specific operation: The generative AI notifies the administrator of the results of its response.

[1292] Data processing: Generate detailed reports and send real-time notifications to administrators via email, SMS, and dashboards.

[1293] Output: Notification to administrator and detailed report

[1294] (Application Example 2)

[1295] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."

[1296] Traditional security systems focus on detecting and countering unusual patterns of digital crime, but they fail to consider the emotional state of users. This shortcoming can lead to reduced accuracy in predicting potential threats and delays in optimal responses, especially in industries with high information sensitivity and significant economic impact. Furthermore, there is a lack of emotional support for users who experience psychological stress as a result of cyberattacks. This increases the risk of data breaches and cyberattacks, which is a significant challenge.

[1297] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means.

[1298] In this invention, the server includes means for collecting data from multiple terminals in a distributed network in order to detect abnormal patterns in real time; data analysis means for generating normal activity patterns and creating a reference pattern based on the data; threat prediction means using generative AI to detect abnormalities that deviate from the reference pattern and predict future attack patterns; automated response means for automatically generating and executing countermeasures against abnormalities detected by the threat prediction means; emotion analysis means for the automated response means to monitor the user's emotional state in real time and detect abnormal emotional patterns; means for generating an emotional care notification when an abnormality is detected; and alert issuing means. This enables rapid and accurate detection of abnormalities, execution of appropriate countermeasures, and care that takes into account the user's emotional state.

[1299] An "abnormal pattern" refers to data or behavioral tendencies that deviate from the standard pattern and are not typically observed.

[1300] A "distributed network" refers to a network in which multiple terminals are interconnected and data is exchanged in a distributed manner.

[1301] "Data collection means" refers to methods and devices for collecting log data, user activity information, network traffic, and user sentiment data from terminals within a network.

[1302] "Data analysis means" refers to methods and devices for analyzing collected data, generating normal activity patterns, and creating reference patterns.

[1303] "Generative AI" refers to artificial intelligence systems that use machine learning and deep learning technologies to analyze data in real time and detect anomalies.

[1304] "Threat prediction means" refers to methods and devices that use generative AI to predict future attack patterns based on detected anomaly data.

[1305] "Automated response means" refers to methods or devices for automatically generating and executing countermeasures in response to detected anomalies.

[1306] "Emotional analysis means" refers to methods and devices for monitoring a user's emotional state in real time and detecting abnormal emotional patterns.

[1307] "Emotional care notifications" refer to relaxation notifications and support suggestions sent to a user when their emotional state is abnormal.

[1308] "Alert notification means" refers to methods or devices for notifying administrators of the results of responses by automated response means.

[1309] The system that implements this application has the following configuration.

[1310] 1. Data acquisition module

[1311] The server collects log data, user activity information, network traffic, and user sentiment data in real time from multiple terminals within a distributed network. APIs and log analysis tools (e.g., Splunk, Prometheus) are used for this purpose. The collected data is stored in a central database and prepared for subsequent analysis.

[1312] 2. Data Analysis Module

[1313] The server analyzes the large amount of collected data using machine learning algorithms (e.g., Scikit-learn, TensorFlow). As a result of the analysis, normal activity patterns (reference patterns) are generated, which serve as criteria for detecting anomalies. These reference patterns are stored in the server's central database and form the basis for real-time analysis.

[1314] 3. Real-time analysis module

[1315] Generative AI scans new data in real time and detects anomalous patterns that deviate from the baseline pattern. This process uses AI models (e.g., YOLO, RNN) to perform data calculations. If an anomaly is found, its details are analyzed to identify the type of anomaly (e.g., large-scale data transfer, abnormal login attempt).

[1316] 4. Emotion Analysis Module

[1317] Generative AI analyzes user emotional data in real time to detect abnormal emotional patterns. Emotional analysis uses emotion recognition algorithms (e.g., OpenCV, IBM Watson) to track changes in the user's emotions. This identifies emotional anomalies that deviate from the normal range and allows for evaluation of whether the user's stress or anxiety is related to cyberattacks.

[1318] 5. Threat Prediction Module

[1319] Generative AI predicts future attack patterns based on detected anomaly and sentiment data. Threat prediction utilizes known threat databases and simulation methods, and risk levels are assessed. Risk levels are classified as low, medium, or high, and response priorities are determined.

[1320] 6. Automated response module

[1321] The generative AI generates automated response scenarios based on the risk level. If a high risk is detected, firewall settings are modified, harmful IP addresses are blocked, specific devices are disconnected from the network, and emotional care notifications are generated for the user. These countermeasures are executed sequentially, with the server coordinating the entire process.

[1322] 7. Alert generation module

[1323] The generative AI notifies administrators of the results of automated responses in real time. Notifications are sent via email, SMS, and dashboards (e.g., Grafana). A detailed report is also generated for administrator review. This report includes information on detected anomalies, actions taken, risk assessment, and user sentiment.

[1324] For example, a server might detect a combination of abnormal network traffic and a sudden increase in user stress. In this case, the system automatically isolates the network segment and sends a relaxation notification to the user.

[1325] Examples of prompt statements are as follows:

[1326] Monitor network traffic for sudden increases and user stress levels, and implement automated countermeasures if anomalies are detected.

[1327] The above describes the embodiments for carrying out this invention.

[1328] The flow of a specific process in Application Example 2 will be explained using Figure 14.

[1329] Step 1: Data Collection

[1330] The server collects log data, user activity information, network traffic, and user sentiment data in real time from multiple terminals within the network. APIs (e.g., RESTful APIs) and log analysis tools (e.g., Splunk, Prometheus) are used for this collection. The collected data is sent to and stored in a central database. Inputs include terminal log data, network traffic data, and sentiment data, while output is the integration of this data into the central database.

[1331] Step 2: Data Analysis

[1332] The server launches a data analysis module and analyzes the large amount of collected data using machine learning algorithms (e.g., Scikit-learn, TensorFlow). The goal of the analysis is to generate normal activity patterns and create a baseline pattern. The input includes data stored in a central database, and the output is a baseline pattern. This baseline pattern serves as the basis for subsequent real-time analysis.

[1333] Step 3: Real-time analysis

[1334] Generative AI scans new data in real time to check for anomalous patterns that deviate from the baseline pattern. An AI model (e.g., YOLO, RNN) is used for this scan. Input includes newly collected real-time data and the baseline pattern, and output is details of any detected anomalies. If an anomaly is found, its details are passed on to the next analysis step.

[1335] Step 4: Emotion Analysis

[1336] The generative AI uses an emotion analysis module to analyze user emotion data in real time. The input includes emotion data acquired in real time, and the output detects abnormal emotion patterns. Emotion recognition algorithms (e.g., OpenCV, IBM Watson) are used to track changes in the user's emotions and identify anomalies that deviate from the normal range.

[1337] Step 5: Threat Prediction

[1338] Generative AI predicts future attack patterns based on anomalies detected through real-time analysis and sentiment analysis. This prediction utilizes a database of known threats and simulation methods, and the risk level is assessed. Input includes detected anomaly data and sentiment data, and output is a prediction result categorized by risk level. The risk level is classified as either low, medium, or high.

[1339] Step 6: Generate and execute automated responses

[1340] The generative AI generates automated response scenarios based on the risk level. If a high risk is detected, it will take actions such as changing firewall settings, blocking harmful IP addresses, disconnecting specific devices from the network, and generating emotional care notifications for users. The input includes prediction results categorized by risk level, and the output is the execution of specific countermeasures.

[1341] Step 7: Issue an alert

[1342] The generative AI notifies administrators of the results of automated responses. Notifications are sent in real time via email, SMS, and dashboards (e.g., Grafana). Inputs include the results of automated responses, and outputs generate alerts for administrators. A detailed report is also generated, which includes information on detected anomalies, implemented countermeasures, risk assessments, and user sentiment.

[1343] The specific processing unit 290 transmits the result of the specific processing to the headset terminal 314. In the headset terminal 314, the control unit 46A causes the speaker 240 and display 343 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.

[1344] Data generation model 58 is a type of so-called generative AI (Artificial Intelligence). One example of data generation model 58 is ChatGPT (Internet search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[1345] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and specific processing may also be performed by the headset terminal 314.

[1346] [Fourth Embodiment]

[1347] Figure 7 shows an example of the configuration of the data processing system 410 according to the fourth embodiment.

[1348] As shown in Figure 7, the data processing system 410 includes a data processing device 12 and a robot 414. An example of the data processing device 12 is a server.

[1349] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[1350] The robot 414 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication interface 44, and a controlled object 443. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, camera 42, and controlled object 443 are also connected to the bus 52.

[1351] The microphone 238 receives voice signals from the user 20 and receives instructions from the user 20. The microphone 238 captures the voice signals from the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.

[1352] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the area around the user 20 (for example, an imaging range defined by a field of view equivalent to the width of a typical healthy person's field of vision).

[1353] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.

[1354] The controlled object 443 includes a display device, LEDs in the eyes, and motors that drive the arms, hands, and feet. The posture and gestures of the robot 414 are controlled by controlling the motors of the arms, hands, and feet. Some of the robot 414's emotions can be expressed by controlling these motors. Furthermore, the robot 414's facial expressions can also be expressed by controlling the illumination state of the LEDs in its eyes.

[1355] Figure 8 shows an example of the main functions of the data processing device 12 and the robot 414. As shown in Figure 8, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.

[1356] The specific processing program 56 is an example of a "program" relating to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[1357] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[1358] In robot 414, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.

[1359] Next, the specific processing performed by the specific processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".

[1360] The present invention will now describe specific embodiments for carrying out the invention. The present invention is a system for preventing digital crime against industries with high information density and significant economic impact (e.g., government, finance, telecommunications, etc.). This system has multiple functions, including detection of abnormal patterns, threat prediction, automated response, and administrator notification.

[1361] 1. Data Collection

[1362] Subject: Server

[1363] First, the server continuously collects log data and traffic information in real time from multiple terminals within the network. The server stores this data in a central database and prepares it for analysis. APIs and log analysis tools are used during this process.

[1364] 2. Data Analysis and Reference Pattern Generation

[1365] Subject: Server

[1366] Next, the server uses a data analysis module to analyze the large amount of data it has collected. This analysis employs machine learning algorithms to generate normal activity patterns (reference patterns). Based on these reference patterns, abnormal data is detected.

[1367] 3. Real-time analysis and anomaly detection

[1368] Subject: Generative AI

[1369] Generative AI scans data in real time to detect unusual activity and traffic patterns. This AI compares historical data with baseline patterns to quickly identify anomalies. In this process, for example, sudden large-scale data transfers or unusual login attempts may be detected.

[1370] 4. Threat prediction and risk assessment

[1371] Subject: Generative AI

[1372] Generative AI predicts future attack patterns based on detected anomalies. This prediction utilizes known threat databases and simulation methods. Based on the prediction results, the risk level is assessed. Risk levels are categorized into low, medium, and high, and the priority of response is determined accordingly.

[1373] 5. Generation and execution of automated responses

[1374] Subject: Generative AI

[1375] The generative AI generates automated response scenarios based on the risk level. For example, if a high risk is detected, the AI ​​automatically modifies firewall settings, blocks harmful IP addresses, and disconnects specific devices from the network. In the case of medium risk, it enhances system log monitoring and issues warnings for specific actions.

[1376] 6. Alert generation and administrator notifications

[1377] Subject: Generative AI

[1378] Finally, after the generative AI completes automated response measures, it sends a real-time notification to the administrator, including the results. This notification is delivered via email, SMS, dashboard, etc. Furthermore, a detailed report is generated and provided for administrator review. This report includes detected anomalies, implemented countermeasures, and risk assessments.

[1379] Specific example

[1380] Specific example 1: Suspicious transactions at financial institutions

[1381] Subject: Server

[1382] A server monitors financial institutions' transaction data in real time, and the server then uses a generative AI to analyze the transaction data. The generative AI detects unusually high-value transactions, compares them to past fraud patterns, and determines that there is a high probability of fraud.

[1383] Subject: Generative AI

[1384] The generation AI automatically implements a temporary freeze measure and sends an alert to the administrator. The administrator reviews the detailed report provided and conducts further investigation.

[1385] Specific example 2: Cyberattacks on government agencies

[1386] Subject: Server

[1387] A server monitors government agency communication traffic 24 hours a day. The server detects unusual large-scale file transfers, and a generative AI analyzes them.

[1388] Subject: Generative AI

[1389] The generating AI identifies a high-risk situation and automatically modifies firewall settings and blocks suspicious IP addresses. It also disconnects the affected devices from the network and sends an emergency alert to the administrator. The administrator reviews the generated detailed report and takes further action.

[1390] As described above, this system, with its advanced AI technology and automated security measures, can quickly and effectively protect critical industries from digital crime.

[1391] The following describes the processing flow.

[1392] Step 1: Data Collection

[1393] Subject: Server

[1394] The server collects data in real time from multiple terminals within a distributed network. Specifically, it retrieves log data, user activity information, network traffic, etc., from each terminal using APIs and stores them in a central database. The collected data is recorded and stored in a consistent manner.

[1395] Step 2: Data analysis and reference pattern generation

[1396] Subject: Server

[1397] The server starts the data analysis module and begins analyzing the collected data. It applies machine learning algorithms to learn normal activity patterns and generate baseline patterns. These baseline patterns are used as templates for anomaly detection.

[1398] Step 3: Real-time analysis and anomaly detection

[1399] Subject: Generative AI

[1400] Generative AI scans new data in real time to detect any anomalous patterns that deviate from the baseline. If an anomaly is found, it analyzes its details to identify the type of anomaly. For example, large-scale data transfers or unusual login attempts might be detected here.

[1401] Step 4: Threat prediction and risk assessment

[1402] Subject: Generative AI

[1403] The generative AI predicts future attack patterns based on detected anomalies. It compares these predictions with existing threat intelligence stored in a database to assess the risk level of new attacks. The risk level is classified as low, medium, or high, and countermeasures are determined.

[1404] Step 5: Generate automated responses

[1405] Subject: Generative AI

[1406] The generation AI automatically generates response scenarios based on the risk level. For example, if a high risk is detected, specific countermeasures such as blocking IP addresses, disconnecting specific devices from the network, and changing firewall settings are generated.

[1407] Step 6: Execute automated response

[1408] Subject: Generative AI

[1409] Based on automated response scenarios generated by a generative AI, security measures are executed sequentially. For example, harmful IP addresses are immediately blocked, and specific devices are isolated from the network.

[1410] Step 7: Alert generation and administrator notification

[1411] Subject: Generative AI

[1412] The generative AI notifies administrators of the results of its automated response. Notifications are sent in real time via email, SMS, dashboards, etc. A detailed report is also generated for administrator review. This report includes detected anomalies, implemented countermeasures, and risk assessments.

[1413] By following these steps, it is possible to effectively prevent digital crimes against industries with high information confidentiality and to respond quickly.

[1414] (Example 1)

[1415] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".

[1416] In today's advanced information society, industries with high information density and significant economic impact (e.g., government, finance, telecommunications) are particularly vulnerable to cyberattacks. Advanced security measures are necessary to prevent digital crime against these industries. However, conventional systems struggle with rapid and effective anomaly detection, threat prediction, and automated response.

[1417] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.

[1418] In this invention, the server includes means for collecting data from multiple terminals in a distributed network in order to detect abnormal patterns in real time; data analysis means for generating normal activity patterns and creating a baseline pattern based on the data; threat prediction means using generative AI to detect anomalies that deviate from the baseline pattern and predict future attack patterns; automated response means for automatically generating and executing countermeasures against anomalies detected by the threat prediction means; and alert issuing means for notifying the administrator of the results of the response by the automated response means. This enables rapid and effective prevention of digital crime and makes it possible to protect critical industries more securely.

[1419] An "abnormal pattern" refers to data or behavior that deviates from normal activity patterns.

[1420] "Data collection method" refers to a system that collects log data, traffic information, and other data from multiple terminals within a distributed network.

[1421] "Data analysis methods" refer to technologies and algorithms that analyze collected data, generate normal activity patterns, and create baseline patterns.

[1422] A "reference pattern" is a definition of a normal activity pattern generated by data analysis methods, and serves as a criterion for detecting abnormal patterns.

[1423] "Generative AI" refers to technologies that use machine learning and artificial intelligence to detect anomalies and perform threat prediction and risk assessment.

[1424] "Threat prediction methods" refer to technologies that use generative AI to detect anomalies that deviate from standard patterns and predict future attack patterns.

[1425] "Automated response measures" refer to technologies that automatically generate and execute appropriate countermeasures in response to anomalies detected by threat prediction measures.

[1426] "Alert notification method" refers to technology used to notify administrators of the results of responses by automated response methods.

[1427] A "machine learning algorithm" refers to an algorithm used in data analysis, specifically a statistical method or model used for anomaly detection.

[1428] "Automatic firewall settings change" refers to a function that automatically changes the settings of the system's protective barrier.

[1429] "Disconnecting a specific device from the network" refers to a function that isolates devices exhibiting abnormal behavior from the network.

[1430] "Blocking harmful IP addresses" refers to a function that blocks IP addresses that may be used for malicious communication.

[1431] This invention is a system for preventing digital crime against industries with high information sensitivity and significant economic impact. This system has multiple functions, including detection of anomalous patterns, threat prediction, automated response, and administrator notification. The specific implementation method of this system is described below.

[1432] Data collection

[1433] Subject: Server

[1434] The server continuously collects log data and traffic information in real time from multiple terminals within a distributed network. Data is efficiently acquired using log analysis tools such as the syslog protocol, NetFlow, and sFlow. The collected data is stored in a NoSQL database (e.g., MongoDB) and organized for later analysis.

[1435] Data analysis and reference pattern generation

[1436] Subject: Server

[1437] Next, the server analyzes the collected data and generates normal activity patterns. Using Python and Scikit-learn, the data is preprocessed, and then a clustering algorithm (e.g., K-means) is executed to create a baseline pattern. This generated baseline pattern forms the basis for anomaly detection.

[1438] Real-time analysis and anomaly detection

[1439] Subject: Generative AI

[1440] Generative AI scans data in real time and uses deep learning frameworks such as TensorFlow to compare generated baseline patterns with historical data. Anomaly detection algorithms such as autoencoders are used to quickly identify anomalous traffic and activity.

[1441] Threat prediction and risk assessment

[1442] Subject: Generative AI

[1443] Generative AI predicts threats and performs risk assessments based on detected anomalies. This is done using the MITRE ATT&CK framework and LSTM models. For predicted attack patterns, it evaluates the risk level as low, medium, or high and determines the priority of response.

[1444] Generation and execution of automated responses

[1445] Subject: Generative AI

[1446] The generative AI generates and executes automated response scenarios based on risk levels. In high-risk cases, it automatically modifies firewall settings using iptables commands to block harmful IP addresses. It also automatically disconnects devices exhibiting abnormal activity from the network.

[1447] Alert generation and administrator notifications

[1448] Subject: Generative AI

[1449] The generative AI notifies administrators of the results of its automated responses. These notifications are sent via email APIs and SMS gateways, and the results are also displayed on a dedicated web dashboard. Furthermore, a detailed report is generated and provided to administrators.

[1450] Specific example

[1451] Specific example 1: Suspicious transactions at financial institutions

[1452] Subject: Server

[1453] The server monitors financial institutions' transaction data in real time, and a generative AI analyzes that data. The generative AI detects unusually high-value transactions and determines that they are highly likely to be fraudulent.

[1454] Subject: Generative AI

[1455] The generation AI automatically implements a temporary freeze measure and sends an alert to the administrator. The administrator reviews a detailed report and conducts further investigation.

[1456] Specific example 2: Cyberattacks on government agencies

[1457] Subject: Server

[1458] The server monitors government agency communication traffic 24 hours a day. The server detects unusual large-scale file transfers, and generative AI analyzes them.

[1459] Subject: Generative AI

[1460] The generation AI identifies a high-risk situation and automatically takes action such as changing firewall settings and blocking suspicious IP addresses. It also disconnects the relevant devices from the network and sends an emergency alert to the administrator. The administrator reviews the generated detailed report and takes further action.

[1461] Example of a prompt

[1462] "Detect anomalous patterns from the given traffic data, compare them to relevant past attack patterns to perform a risk assessment, and then generate appropriate automated countermeasures."

[1463] This invention combines advanced AI technology with automated security measures to quickly and effectively protect critical industries from digital crime.

[1464] The flow of the specific processing in Example 1 will be explained using Figure 11.

[1465] Step 1: Data Collection

[1466] Subject: Server

[1467] Input: Log data and traffic information sent from multiple terminals within a distributed network.

[1468] Specific operation: The server uses the syslog protocol, NetFlow, and sFlow to retrieve log data and traffic information from each terminal. The server uses ping to verify connectivity with each terminal, then starts the syslog daemon to collect log data. It also uses a NetFlow collector to collect traffic information. The collected data is stored in a NoSQL database (e.g., MongoDB).

[1469] Output: Log data and traffic information stored in the database

[1470] Step 2: Data analysis and reference pattern generation

[1471] Subject: Server

[1472] Input: Log data and traffic information stored in the database

[1473] Specific operation: The server analyzes log data and traffic information using Python and Scikit-learn. Data preprocessing includes denoising and data standardization. Then, a clustering algorithm (e.g., K-means) is executed to create a baseline pattern. The generated baseline pattern is then saved back into the database.

[1474] Output: Database where the reference pattern is stored.

[1475] Step 3: Real-time analysis and anomaly detection

[1476] Subject: Generative AI

[1477] Input: Real-time acquired log data and traffic information, baseline patterns

[1478] Specific operation: Generative AI scans data in real time and compares it with historical data and baseline patterns. TensorFlow is used to perform anomaly detection with an Autoencoder algorithm. When abnormal traffic or activity is detected, an alert is generated.

[1479] Output: Anomaly detection results and alerts

[1480] Step 4: Threat prediction and risk assessment

[1481] Subject: Generative AI

[1482] Input: Data on detected anomalies, baseline patterns, and known threat databases.

[1483] Specific operation: Generative AI analyzes detected anomalies using the MITRE ATT&CK framework and LSTM models. It compares them with a known threat database to predict future attack patterns. Risk is assessed in three stages: "low," "medium," and "high," and the priority of response is determined.

[1484] Output: Risk assessment and predicted threat patterns

[1485] Step 5: Generate and execute automated responses

[1486] Subject: Generative AI

[1487] Input: Risk assessment results, anomaly detection results

[1488] Specific operation: The generative AI generates automated response scenarios based on the risk level. In high-risk cases, it modifies firewall settings using iptables commands to block harmful IP addresses. It also automatically disconnects devices exhibiting abnormal activity from the network.

[1489] Output: Automated countermeasures taken and their results

[1490] Step 6: Alert generation and administrator notification

[1491] Subject: Generative AI

[1492] Input: Automated response results, anomaly detection results, risk assessment

[1493] Specific operation: The generative AI notifies the administrator of the results of its automated response. Communication is conducted via email API and SMS gateway, and the results are displayed on a web dashboard. A detailed report is generated for the administrator to review.

[1494] Output: Notification to administrator and detailed report

[1495] (Application Example 1)

[1496] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".

[1497] Current security systems often lack sufficient capabilities to detect anomalies in real time and respond immediately. Furthermore, even when an anomaly is detected, there is a lack of systems that efficiently notify administrators and quickly implement countermeasures. In addition, few systems have reporting capabilities that allow administrators to easily understand the details of anomalies. To address these issues, there is a need for security systems with more advanced anomaly detection, prediction, notification, and reporting capabilities.

[1498] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.

[1499] In this invention, the server includes means for collecting data from multiple terminals in a distributed network in order to detect abnormal patterns in real time; data analysis means for generating normal activity patterns and creating a baseline pattern based on the data; threat prediction means using generative AI to detect abnormalities that deviate from the baseline pattern and predict future attack patterns; automated response means for automatically generating and executing countermeasures against abnormalities detected by the threat prediction means; notification means for sending alerts to an administrator from a specific device and creating a detailed report when a high-risk abnormality is detected; and a notification application that monitors network traffic in real time and reports to the administrator in real time when an abnormality is detected. This makes it possible to quickly detect abnormal patterns and respond immediately, thereby realizing advanced security measures.

[1500] An "anomalous pattern" refers to data on unusual activity or traffic that deviates from the generated baseline pattern.

[1501] A "distributed network" is a network structure in which multiple terminals are connected to each other and exchange data.

[1502] "Data analysis" is the process of using collected data to generate typical activity patterns and baseline patterns.

[1503] A "reference pattern" is an indicator of normal activity patterns generated through data analysis, and serves as a criterion for detecting anomalies.

[1504] "Generative AI" refers to artificial intelligence technology used to predict threats and detect anomalies based on data analysis.

[1505] "Threat prediction" is the process of predicting future attack patterns and risks using generative AI.

[1506] An "automated response mechanism" is a function that automatically generates and executes countermeasures in response to detected anomalies.

[1507] "Notification means" refers to a function that informs administrators of the results of automated response measures and details of any anomalies.

[1508] "Network traffic" refers to data that flows over a network.

[1509] A "notification application" is software that monitors network traffic in real time and reports any anomalies to the administrator.

[1510] A "detailed report" is a document that provides administrators with detailed information about any anomalies that occurred and the countermeasures taken.

[1511] This invention is a security system for preventing digital crime against industries with high information sensitivity and significant economic impact. The specific implementation of this system is described below.

[1512] 1. Data Collection

[1513] Subject: Server

[1514] The server continuously collects log data and traffic information in real time from multiple terminals within a distributed network. This data is stored in a central database and prepared for later analysis. APIs and log analysis tools are used in this process.

[1515] 2. Data Analysis and Reference Pattern Generation

[1516] Subject: Server

[1517] The server analyzes large amounts of data collected using data analysis tools to generate normal activity patterns (reference patterns). Machine learning algorithms (e.g., Python machine learning libraries) are used for this analysis. Based on the generated reference patterns, anomalous data is later detected.

[1518] 3. Real-time analysis and anomaly detection

[1519] Subject: Generative AI

[1520] Generative AI scans data in real time to detect unusual activity and traffic patterns. It compares historical data with baseline patterns to quickly identify anomalies. This process can, for example, detect sudden large-scale data transfers or unusual login attempts.

[1521] 4. Threat prediction and risk assessment

[1522] Subject: Generative AI

[1523] Generative AI predicts future attack patterns based on detected anomalies. This prediction utilizes known threat databases and simulation methods. Based on the prediction results, the risk level is assessed and assigned to a low, medium, or high level. This determines the priority of the response.

[1524] 5. Generation and execution of automated responses

[1525] Subject: Generative AI

[1526] The generative AI generates automated response scenarios based on the risk level. For example, if a high risk is detected, the AI ​​automatically modifies firewall settings, blocks harmful IP addresses, and disconnects specific devices from the network. In the case of medium risk, it enhances system log monitoring and issues warnings for specific actions.

[1527] 6. Alert generation and administrator notifications

[1528] Subject: Generative AI

[1529] After the generation AI completes automated response measures, it sends a real-time notification to the administrator including the results. The notification is delivered via email, SMS, dashboard, etc., and a detailed report is provided to the administrator. This report includes detected anomalies, implemented countermeasures, and risk assessments.

[1530] Specific example

[1531] Example 1: Advanced financial transaction security

[1532] Subject: Server

[1533] A server monitors financial institutions' transaction data in real time, and the server then uses a generative AI to analyze the transaction data. The generative AI detects unusually high-value transactions, compares them to past fraud patterns, and determines that there is a high probability of fraud.

[1534] Subject: Generative AI

[1535] The generation AI automatically implements a temporary freeze measure and sends an alert to the administrator. The administrator reviews the detailed report provided and conducts further investigation.

[1536] Specific example 2: Defending against cyberattacks on government agencies

[1537] Subject: Server

[1538] A server monitors government agency communication traffic 24 hours a day. The server detects unusual large-scale file transfers, and a generative AI analyzes them.

[1539] Subject: Generative AI

[1540] The generating AI identifies a high-risk situation and automatically modifies firewall settings and blocks suspicious IP addresses. It also disconnects the affected devices from the network and sends an emergency alert to the administrator. The administrator reviews the generated detailed report and takes further action.

[1541] Example of a prompt

[1542] "Design a smartphone app with real-time monitoring and anomaly detection capabilities to predict and prevent cyberattacks. This app will use Scapy to analyze network traffic and send email alerts if anomalies are detected."

[1543] The flow of a specific process in Application Example 1 will be explained using Figure 12.

[1544] Step 1:

[1545] Data collection

[1546] Subject: Server

[1547] The server collects log data and network traffic information in real time from multiple terminals within a distributed network. The input consists of communication logs and network traffic data transmitted from each terminal. The server collects this data using APIs and log analysis tools and stores it in a central database. The output is the collected data stored in the central database, prepared for analysis.

[1548] Step 2:

[1549] Data analysis and reference pattern generation

[1550] Subject: Server

[1551] The server analyzes data stored in a central database using data analysis tools (e.g., Python machine learning libraries). Input includes collected log data and network traffic information. The server analyzes this data and generates normal activity patterns (reference patterns). The generated reference patterns are stored in the database as output, forming the basis for anomaly detection.

[1552] Step 3:

[1553] Real-time analysis and anomaly detection

[1554] Subject: Generative AI

[1555] Generative AI scans newly collected data (traffic information and log data) in real time and detects deviations from baseline patterns. Its input includes data collected in real time and baseline patterns. The generative AI identifies anomalies by comparing them to historical data. This often detects abnormal traffic patterns or sudden large-scale data transfers. The output is the generated data of the detected anomalies.

[1556] Step 4:

[1557] Threat prediction and risk assessment

[1558] Subject: Generative AI

[1559] Generative AI predicts future attack patterns based on detected anomalous data. Its inputs include anomalous data and a database of known threats. The generative AI runs simulations and outputs prediction results. These predictions allow for a risk level assessment, categorized into low, medium, and high.

[1560] Step 5:

[1561] Generation and execution of automated responses

[1562] Subject: Generative AI

[1563] The generative AI generates and executes automated response scenarios based on the risk level. Its inputs include risk assessment results and response scenario templates. For example, in high-risk cases, it might automatically modify firewall settings, block harmful IP addresses, or disconnect specific devices from the network. The output records the implemented countermeasures.

[1564] Step 6:

[1565] Alert generation and administrator notifications

[1566] Subject: Generative AI

[1567] The generation AI automatically handles the situation and then sends a real-time notification to the administrator, including the results. Inputs include the automated response results and the administrator's contact information. Notifications are sent via email, SMS, dashboards, etc. Outputs include the notification sent to the administrator and a detailed report. This report includes detected anomalies, implemented countermeasures, and risk assessments.

[1568] The above outlines the specific processing flow within this system.

[1569] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.

[1570] This invention is a system for preventing digital crime in industries with high information density and significant economic impact. The system combines abnormal pattern detection, threat prediction, automated response, administrator notification, and an emotion engine that recognizes user emotions.

[1571] 1. Data Collection

[1572] Subject: Server

[1573] The server continuously collects log data, user activity information, network traffic, and user sentiment data in real time from multiple terminals within the network. The server stores this data in a central database and prepares it for analysis. APIs and log analysis tools are used in this process.

[1574] 2. Data Analysis and Reference Pattern Generation

[1575] Subject: Server

[1576] The server activates a data analysis module and analyzes the large amount of collected data. This analysis uses machine learning algorithms to generate normal activity patterns (reference patterns). Based on these reference patterns, abnormal data is detected.

[1577] 3. Real-time analysis and anomaly detection

[1578] Subject: Generative AI

[1579] Generative AI scans new data in real time to detect any anomalous patterns that deviate from the baseline. If an anomaly is found, it analyzes its details to identify the type of anomaly. For example, large-scale data transfers or unusual login attempts might be detected here.

[1580] 4. Analysis using an emotion engine

[1581] Subject: Generative AI

[1582] Generative AI analyzes user emotional data in real time to detect abnormal emotional patterns. Specifically, the emotion engine uses emotion recognition algorithms to track changes in the user's emotions and identify anomalies that deviate from the normal range. This allows for an assessment of whether the user's stress or anxiety is related to a cyberattack.

[1583] 5. Threat Prediction and Risk Assessment

[1584] Subject: Generative AI

[1585] Generative AI predicts future attack patterns based on detected anomaly and sentiment data. This prediction utilizes a database of known threats and simulation methods to assess risk levels. Risk levels are classified as low, medium, or high, and the priority of response is determined accordingly.

[1586] 6. Generation and execution of automated responses

[1587] Subject: Generative AI

[1588] The generative AI automatically generates response scenarios based on the risk level. For example, if a high risk is detected, specific countermeasures are generated, such as changing firewall settings, blocking harmful IP addresses, disconnecting specific devices from the network, and sending emotional care notifications to users.

[1589] 7. Execute automated response

[1590] Subject: Generative AI

[1591] Based on automated response scenarios generated by a generative AI, security measures are implemented sequentially. For example, it sends emotional care notifications to users and suggests psychological counseling as needed.

[1592] 8. Alert generation and administrator notifications

[1593] Subject: Generative AI

[1594] The generative AI notifies administrators of the results of its automated response. Notifications are sent in real time via email, SMS, dashboards, etc. A detailed report is also generated for administrator review. This report includes information on detected anomalies, implemented countermeasures, risk assessments, and user sentiment.

[1595] Specific example

[1596] Specific example 1: Suspicious transactions at financial institutions

[1597] Subject: Server

[1598] A server monitors financial institution transaction data and user sentiment data in real time. The server then uses a generative AI to analyze the transaction and sentiment data. If the generative AI detects an unusually high-value transaction and the user's sentiment data also shows abnormalities, it indicates a potential fraud.

[1599] Subject: Generative AI

[1600] The generative AI automatically implements temporary suspension measures and sends emotional care notifications to the user. An alert is sent to the administrator, and a detailed report is provided, allowing for further investigation and corrective action.

[1601] Specific example 2: Cyberattacks on government agencies

[1602] Subject: Server

[1603] The server monitors government agency communication traffic and employee sentiment data 24 hours a day. The server detects unusual large-scale file transfers, and generative AI analyzes them.

[1604] Subject: Generative AI

[1605] The generative AI identifies a high-risk situation and automatically modifies firewall settings and blocks suspicious IP addresses. It also disconnects the relevant devices from the network and sends emotional care notifications to users. An emergency alert is sent to the administrator, along with a detailed report. The administrator reviews the report and takes further action.

[1606] As described above, by combining this system with an emotion engine, it enables more accurate anomaly detection and rapid response, effectively protecting industries with high information confidentiality.

[1607] The following describes the processing flow.

[1608] Step 1: Data Collection

[1609] Subject: Server

[1610] The server collects log data, user activity information, network traffic, and user sentiment data in real time from multiple terminals within the network. The server stores this data in a central database. The collection process uses APIs and log analysis tools to retrieve and record data in a consistent format.

[1611] Step 2: Data analysis and reference pattern generation

[1612] Subject: Server

[1613] The server activates a data analysis module and analyzes the collected data. It applies machine learning algorithms to learn and generate normal activity patterns (reference patterns) and emotional patterns. Based on these reference patterns, abnormal data is detected.

[1614] Step 3: Analyzing user sentiment data

[1615] Subject: Generative AI

[1616] Generative AI analyzes user emotional data in real time to detect abnormal emotional fluctuations. The emotion engine uses emotion recognition algorithms to monitor the user's emotional state and identify changes that deviate from the normal range. If the user is experiencing excessive stress or anxiety, this information is recorded.

[1617] Step 4: Real-time analysis and anomaly detection

[1618] Subject: Generative AI

[1619] Generative AI scans new data in real time and detects anomalous patterns that deviate from the baseline. For example, it can detect large-scale data transfers or fraudulent login attempts. Furthermore, if anomalies in emotional data are associated with technical anomalies, that information is also analyzed.

[1620] Step 5: Threat prediction and risk assessment

[1621] Subject: Generative AI

[1622] Generative AI predicts future attack patterns based on detected anomalies. It compares these anomalies against a database of known threats to predict how they will develop. Simultaneously, it considers user sentiment data to assess the risk level, which is categorized as low, medium, or high.

[1623] Step 6: Generate automated responses

[1624] Subject: Generative AI

[1625] The generative AI generates automated response scenarios based on the risk level. For example, if the risk is high, it will automatically change firewall settings, block harmful IP addresses, disconnect specific devices from the network, and send emotional care notifications to users.

[1626] Step 7: Execute automated response

[1627] Subject: Generative AI

[1628] Based on automated response scenarios generated by a generative AI, security measures are executed sequentially. For example, firewall settings are changed in real time, related IP addresses are blocked, and specific devices are disconnected from the network. Additionally, emotional support notifications are sent to users, suggesting responses such as psychological counseling.

[1629] Step 8: Alert generation and administrator notification

[1630] Subject: Generative AI

[1631] The generative AI notifies administrators of the results of its automated response. Notifications are sent in real time via email, SMS, dashboards, etc. A detailed report is generated and provided to administrators. This report includes information on detected anomalies, actions taken, risk assessments, and user sentiment.

[1632] The above steps enable effective prevention of digital crime in industries with high information confidentiality, and allow for rapid response. By combining this with an emotion engine, the correlation between technical anomalies and users' emotional states is enhanced, enabling more accurate anomaly detection and countermeasures.

[1633] (Example 2)

[1634] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".

[1635] To prevent digital crime in industries with high information density and significant economic impact, it is necessary to perform complex analysis that considers not only the detection of abnormal data patterns but also the emotional state of users. However, conventional systems do not provide a consistent solution that includes the analysis of emotional data, the detection of its anomalies, and the generation and execution of automated countermeasures. As a result, the accuracy of anomaly detection and threat prediction is insufficient, making it difficult to respond quickly and appropriately. Furthermore, there is a lack of functionality to notify administrators of the results of the response after an anomaly is detected in real time and to provide detailed reports.

[1636] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.

[1637] In this invention, the server includes means for continuously collecting log data, user activity information, network traffic, and sentiment data from multiple terminals in a distributed network in order to prevent digital crime; data analysis means for generating normal activity patterns and creating a baseline pattern based on the data; real-time analysis means for detecting anomalies that deviate from the baseline pattern and performing detailed analysis to identify the type of anomaly; sentiment analysis means for analyzing user sentiment data and detecting anomalies that deviate from the normal range; threat prediction means for predicting future attack patterns and evaluating risk levels based on the anomaly data and sentiment data; automated response means for generating automated response scenarios according to the risk level evaluated by the threat prediction means and automatically executing security measures when the risk is high; and alert issuing means for notifying the administrator of the results of the response by the automated response means and generating a detailed report. This improves the accuracy of anomaly detection in information-sensitive industries and enables quick and appropriate responses.

[1638] A "distributed network" is a network in which multiple terminals and servers are distributed and communicate with each other to share data.

[1639] "Log data" refers to records of operations generated by systems and applications, and includes access logs, authentication logs, error logs, etc.

[1640] "User activity information" refers to the history of operations and actions performed by a user within a system or application, and includes operation logs, browsing history, and other similar information.

[1641] "Network traffic" refers to the flow of data sent and received through a network, and includes the volume of packets sent and received, as well as the timing of communication.

[1642] "Emotional data" refers to data that indicates a user's emotional state, and includes facial expression data and biosignals acquired from emotion recognition systems and biometric sensors.

[1643] "Data analysis methods" refer to means for analyzing collected data and generating normal activity patterns or baseline patterns, and include machine learning algorithms and data mining techniques.

[1644] A "reference pattern" is a standard data pattern that represents normal activity and serves as a comparison criterion for identifying abnormal data.

[1645] "Real-time analysis means" refers to a method for analyzing new data in real time, detecting anomalies that deviate from the standard pattern, and identifying their type.

[1646] "Emotional analysis means" refers to methods for analyzing a user's emotional data and detecting anomalies that deviate from the normal range, and includes emotional recognition algorithms and biosignal analysis technologies.

[1647] "Threat prediction tools" refer to methods for predicting future attack patterns and assessing risk levels based on anomalous data and sentiment data.

[1648] "Automated response measures" refer to methods that automatically generate security measures based on risk assessments using threat prediction and execute them when the risk is high, and include changing firewall settings and disconnecting from the network.

[1649] "Alert generation method" refers to a method for notifying administrators of the results of responses by automated response methods and generating and providing detailed reports.

[1650] This invention is a system for preventing digital crime in industries with high information density and significant economic impact. The system combines abnormal pattern detection, threat prediction, automated response, administrator notification, and an emotion engine that recognizes user emotions.

[1651] Data collection

[1652] Subject: Server

[1653] The server continuously collects data from multiple terminals within the corporate network. This data includes log data (access logs, authentication logs, error logs, etc.), user activity information (operation logs, browsing history, etc.), network traffic, and sentiment data (facial expression data from sentiment recognition systems and biometric sensors, etc.). To collect this data, the server uses APIs and log analysis tools (e.g., Elasticsearch, Splunk). The collected data is stored in a central database and prepared for analysis.

[1654] Data Analysis

[1655] Subject: Server

[1656] The server starts the data analysis module and analyzes the collected data. Specifically, the process proceeds as follows:

[1657] Machine learning algorithms (e.g., TensorFlow and Scikit-learn) are used to learn typical activity patterns from past data.

[1658] Clustering and anomaly detection techniques are used to generate normal activity patterns (reference patterns).

[1659] Real-time analysis

[1660] Subject: Generative AI

[1661] The generative AI retrieves new data from a central database in real time and compares it against a baseline pattern. This allows for the detection of anomalous patterns in real time. The stream processing engine used (e.g., Apache Kafka, Apache Storm) monitors the new data in real time and detects anomalous patterns that deviate from the baseline pattern.

[1662] Analysis using an emotion engine

[1663] Subject: Generative AI

[1664] Generative AI analyzes user emotional data in real time. Specifically, it uses emotion recognition algorithms (e.g., face detection using Haar-like features, deep learning emotion classification models) to analyze the user's real-time facial expressions and biometric information. If the emotional data deviates from the normal range, the generative AI identifies the anomaly.

[1665] Threat prediction

[1666] Subject: Generative AI

[1667] Generative AI predicts future attack patterns based on anomalous and sentiment data. By cross-referencing with known threat databases (e.g., CVE databases) and using simulation methods, it constructs risk scenarios and assesses risk levels. Risk levels are classified into three stages: low, medium, and high.

[1668] Automated response scenarios

[1669] Subject: Generative AI

[1670] The generative AI generates automated response scenarios based on risk assessments. Specific countermeasures include modifying firewall settings, blocking harmful IP addresses, and disconnecting specific devices from the network. It also provides emotional care notifications and suggests psychological counseling as countermeasures against emotional disturbances.

[1671] Execute automated response

[1672] Subject: Generative AI

[1673] The generative AI will perform the following security measures based on the generated automated response scenarios:

[1674] You will need to use a network management tool (e.g., Cisco ASA, pfSense) to change firewall settings.

[1675] Update the access control list to block suspicious IP addresses.

[1676] Disconnect the terminal experiencing the malfunction from the network.

[1677] Additionally, the system sends emotional care notifications to users and suggests psychological counseling as needed.

[1678] Alert generation and administrator notifications

[1679] Subject: Generative AI

[1680] The generative AI notifies administrators of the results of its automated responses. These notifications are delivered in real time via email, SMS, or a dashboard. Furthermore, a detailed report is generated for administrator review. This report includes information on detected anomalies, implemented actions, risk assessments, and user sentiment.

[1681] Specific example

[1682] Specific example 1: Suspicious transactions at financial institutions

[1683] Subject: Server

[1684] A server monitors financial institution transaction data and user sentiment data in real time. The server then uses generative AI to analyze the transaction and sentiment data. If the generative AI detects an unusually high-value transaction and the user sentiment data also shows abnormalities, it indicates a potential fraud.

[1685] Subject: Generative AI

[1686] The generative AI automatically implements temporary suspension measures and sends emotional care notifications to the user. It also sends alerts to administrators and provides detailed reports to facilitate further investigation and countermeasures.

[1687] Specific example 2: Cyberattacks on government agencies

[1688] Subject: Server

[1689] The server monitors government agency communication traffic and employee sentiment data 24 hours a day. The server detects unusual large-scale file transfers, which are then analyzed by generative AI.

[1690] Subject: Generative AI

[1691] The generation AI identifies the situation as high-risk and automatically modifies firewall settings and blocks suspicious IP addresses. It also disconnects the relevant devices from the network and sends emotional care notifications to users. An emergency alert is sent to the administrator, providing a detailed report. The administrator reviews the report and takes further action.

[1692] Example of a prompt

[1693] "Based on the analysis of the new data, an abnormal pattern has been detected. The sentiment data also shows abnormalities, so please generate specific countermeasures."

[1694] The flow of the specific processing in Example 2 will be explained using Figure 13.

[1695] Step 1:

[1696] Inputs: Log data, user activity information, network traffic, sentiment data

[1697] Specific operation: The server collects this data in real time from multiple terminals within the corporate network.

[1698] Data processing: Collect data using APIs and log analysis tools (e.g., Elasticsearch, Splunk) and store it in a central database.

[1699] Output: Collected data stored in the central database

[1700] Step 2:

[1701] Input: Collected data stored in the central database

[1702] Specific operation: The server starts the data analysis module and begins analyzing the stored data.

[1703] Data processing: Machine learning algorithms (e.g., TensorFlow or Scikit-learn) are used to learn normal activity patterns from past data and generate normal activity patterns (reference patterns). Clustering and anomaly detection methods are employed.

[1704] Output: Generated reference pattern

[1705] Step 3:

[1706] Input: Newly collected data, reference pattern

[1707] Specific operation: The generative AI retrieves new data from a central database in real time and compares it against a reference pattern.

[1708] Data processing: Using stream processing engines (e.g., Apache Kafka, Apache Storm), new data is monitored in real time, and abnormal patterns that deviate from the baseline pattern are detected.

[1709] Output: List of detected anomaly patterns

[1710] Step 4:

[1711] Input: Collected emotional data

[1712] Specific operation: A generative AI analyzes emotional data in real time.

[1713] Data processing: We analyze user facial expressions and biometric information using emotion recognition algorithms (e.g., face detection using Haar-like features, deep learning emotion classification models).

[1714] Output: List of abnormal emotional patterns

[1715] Step 5:

[1716] Input: Abnormal data, sentiment data

[1717] Specific operation: Generative AI predicts future attack patterns based on anomaly data and emotional data.

[1718] Data processing: The data is compared with known threat databases (e.g., CVE databases), and risk scenarios are constructed using simulation methods to evaluate risk levels.

[1719] Output: Risk Assessment Report

[1720] Step 6:

[1721] Input: Risk assessment report

[1722] Specific operation: The generative AI generates automated response scenarios based on risk assessment.

[1723] Data processing: As automated response scenarios, it performs actions such as changing firewall settings, blocking harmful IP addresses, disconnecting specific devices from the network, and generating emotional care notifications.

[1724] Output: Automated response scenario

[1725] Step 7:

[1726] Input: Automated response scenario

[1727] Specific operation: The generative AI executes security measures based on the scenarios it generates.

[1728] Data processing: Use network management tools (e.g., Cisco ASA, pfSense) to modify firewall settings, block IP addresses to prevent unauthorized access, and disconnect terminals that have experienced problems. Also, send emotional care notifications to users and suggest psychological counseling as needed.

[1729] Output: Security measures taken

[1730] Step 8:

[1731] Input: Results of security measures taken

[1732] Specific operation: The generative AI notifies the administrator of the results of its response.

[1733] Data processing: Generate detailed reports and send real-time notifications to administrators via email, SMS, and dashboards.

[1734] Output: Notification to administrator and detailed report

[1735] (Application Example 2)

[1736] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".

[1737] Traditional security systems focus on detecting and countering unusual patterns of digital crime, but they fail to consider the emotional state of users. This shortcoming can lead to reduced accuracy in predicting potential threats and delays in optimal responses, especially in industries with high information sensitivity and significant economic impact. Furthermore, there is a lack of emotional support for users who experience psychological stress as a result of cyberattacks. This increases the risk of data breaches and cyberattacks, which is a significant challenge.

[1738] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means.

[1739] In this invention, the server includes means for collecting data from multiple terminals in a distributed network in order to detect abnormal patterns in real time; data analysis means for generating normal activity patterns and creating a reference pattern based on the data; threat prediction means using generative AI to detect abnormalities that deviate from the reference pattern and predict future attack patterns; automated response means for automatically generating and executing countermeasures against abnormalities detected by the threat prediction means; emotion analysis means for the automated response means to monitor the user's emotional state in real time and detect abnormal emotional patterns; means for generating an emotional care notification when an abnormality is detected; and alert issuing means. This enables rapid and accurate detection of abnormalities, execution of appropriate countermeasures, and care that takes into account the user's emotional state.

[1740] An "abnormal pattern" refers to data or behavioral tendencies that deviate from the standard pattern and are not typically observed.

[1741] A "distributed network" refers to a network in which multiple terminals are interconnected and data is exchanged in a distributed manner.

[1742] "Data collection means" refers to methods and devices for collecting log data, user activity information, network traffic, and user sentiment data from terminals within a network.

[1743] "Data analysis means" refers to methods and devices for analyzing collected data, generating normal activity patterns, and creating reference patterns.

[1744] "Generative AI" refers to artificial intelligence systems that use machine learning and deep learning technologies to analyze data in real time and detect anomalies.

[1745] "Threat prediction means" refers to methods and devices that use generative AI to predict future attack patterns based on detected anomaly data.

[1746] "Automated response means" refers to methods or devices for automatically generating and executing countermeasures in response to detected anomalies.

[1747] "Emotional analysis means" refers to methods and devices for monitoring a user's emotional state in real time and detecting abnormal emotional patterns.

[1748] "Emotional care notifications" refer to relaxation notifications and support suggestions sent to a user when their emotional state is abnormal.

[1749] "Alert notification means" refers to methods or devices for notifying administrators of the results of responses by automated response means.

[1750] The system that implements this application has the following configuration.

[1751] 1. Data acquisition module

[1752] The server collects log data, user activity information, network traffic, and user sentiment data in real time from multiple terminals within a distributed network. APIs and log analysis tools (e.g., Splunk, Prometheus) are used for this purpose. The collected data is stored in a central database and prepared for subsequent analysis.

[1753] 2. Data Analysis Module

[1754] The server analyzes the large amount of collected data using machine learning algorithms (e.g., Scikit-learn, TensorFlow). As a result of the analysis, normal activity patterns (reference patterns) are generated, which serve as criteria for detecting anomalies. These reference patterns are stored in the server's central database and form the basis for real-time analysis.

[1755] 3. Real-time analysis module

[1756] Generative AI scans new data in real time and detects anomalous patterns that deviate from the baseline pattern. This process uses AI models (e.g., YOLO, RNN) to perform data calculations. If an anomaly is found, its details are analyzed to identify the type of anomaly (e.g., large-scale data transfer, abnormal login attempt).

[1757] 4. Emotion Analysis Module

[1758] Generative AI analyzes user emotional data in real time to detect abnormal emotional patterns. Emotional analysis uses emotion recognition algorithms (e.g., OpenCV, IBM Watson) to track changes in the user's emotions. This identifies emotional anomalies that deviate from the normal range and allows for evaluation of whether the user's stress or anxiety is related to cyberattacks.

[1759] 5. Threat Prediction Module

[1760] Generative AI predicts future attack patterns based on detected anomaly and sentiment data. Threat prediction utilizes known threat databases and simulation methods, and risk levels are assessed. Risk levels are classified as low, medium, or high, and response priorities are determined.

[1761] 6. Automated response module

[1762] The generative AI generates automated response scenarios based on the risk level. If a high risk is detected, firewall settings are modified, harmful IP addresses are blocked, specific devices are disconnected from the network, and emotional care notifications are generated for the user. These countermeasures are executed sequentially, with the server coordinating the entire process.

[1763] 7. Alert generation module

[1764] The generative AI notifies administrators of the results of automated responses in real time. Notifications are sent via email, SMS, and dashboards (e.g., Grafana). A detailed report is also generated for administrator review. This report includes information on detected anomalies, actions taken, risk assessment, and user sentiment.

[1765] For example, a server might detect a combination of abnormal network traffic and a sudden increase in user stress. In this case, the system automatically isolates the network segment and sends a relaxation notification to the user.

[1766] Examples of prompt statements are as follows:

[1767] Monitor network traffic for sudden increases and user stress levels, and implement automated countermeasures if anomalies are detected.

[1768] The above describes the embodiments for carrying out this invention.

[1769] The flow of a specific process in Application Example 2 will be explained using Figure 14.

[1770] Step 1: Data Collection

[1771] The server collects log data, user activity information, network traffic, and user sentiment data in real time from multiple terminals within the network. APIs (e.g., RESTful APIs) and log analysis tools (e.g., Splunk, Prometheus) are used for this collection. The collected data is sent to and stored in a central database. Inputs include terminal log data, network traffic data, and sentiment data, while output is the integration of this data into the central database.

[1772] Step 2: Data Analysis

[1773] The server launches a data analysis module and analyzes the large amount of collected data using machine learning algorithms (e.g., Scikit-learn, TensorFlow). The goal of the analysis is to generate normal activity patterns and create a baseline pattern. The input includes data stored in a central database, and the output is a baseline pattern. This baseline pattern serves as the basis for subsequent real-time analysis.

[1774] Step 3: Real-time analysis

[1775] Generative AI scans new data in real time to check for anomalous patterns that deviate from the baseline pattern. An AI model (e.g., YOLO, RNN) is used for this scan. Input includes newly collected real-time data and the baseline pattern, and output is details of any detected anomalies. If an anomaly is found, its details are passed on to the next analysis step.

[1776] Step 4: Emotion Analysis

[1777] The generative AI uses an emotion analysis module to analyze user emotion data in real time. The input includes emotion data acquired in real time, and the output detects abnormal emotion patterns. Emotion recognition algorithms (e.g., OpenCV, IBM Watson) are used to track changes in the user's emotions and identify anomalies that deviate from the normal range.

[1778] Step 5: Threat Prediction

[1779] Generative AI predicts future attack patterns based on anomalies detected through real-time analysis and sentiment analysis. This prediction utilizes a database of known threats and simulation methods, and the risk level is assessed. Input includes detected anomaly data and sentiment data, and output is a prediction result categorized by risk level. The risk level is classified as either low, medium, or high.

[1780] Step 6: Generate and execute automated responses

[1781] The generative AI generates automated response scenarios based on the risk level. If a high risk is detected, it will take actions such as changing firewall settings, blocking harmful IP addresses, disconnecting specific devices from the network, and generating emotional care notifications for users. The input includes prediction results categorized by risk level, and the output is the execution of specific countermeasures.

[1782] Step 7: Issue an alert

[1783] The generative AI notifies administrators of the results of automated responses. Notifications are sent in real time via email, SMS, and dashboards (e.g., Grafana). Inputs include the results of automated responses, and outputs generate alerts for administrators. A detailed report is also generated, which includes information on detected anomalies, implemented countermeasures, risk assessments, and user sentiment.

[1784] The specific processing unit 290 transmits the result of the specific processing to the robot 414. In the robot 414, the control unit 46A causes the speaker 240 and the controlled object 443 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.

[1785] Data generation model 58 is a type of so-called generative AI (Artificial Intelligence). One example of data generation model 58 is ChatGPT (Internet search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[1786] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and the specific processing may also be performed by the robot 414.

[1787] Furthermore, the emotion identification model 59, acting as an emotion engine, may determine the user's emotion according to a specific mapping. Specifically, the emotion identification model 59 may determine the user's emotion according to a specific mapping, which is an emotion map (see Figure 9). Similarly, the emotion identification model 59 may also determine the robot's emotion, and the identification processing unit 290 may perform identification processing using the robot's emotion.

[1788] Figure 9 shows an emotion map 400 in which multiple emotions are mapped. In the emotion map 400, emotions are arranged in concentric circles radiating from the center. The closer to the center of the concentric circles, the more primitive the emotions are located. Further out of the concentric circles, emotions representing states and actions arising from mental states are located. Emotion is a concept that includes feelings and mental states. On the left side of the concentric circles, emotions that are generally generated from reactions occurring in the brain are located. On the right side of the concentric circles, emotions that are generally induced by situational judgment are located. Above and below the concentric circles, emotions that are generally generated from reactions occurring in the brain and induced by situational judgment are located. In addition, the emotion of "pleasure" is located on the upper side of the concentric circles, and the emotion of "displeasure" is located on the lower side. Thus, in the emotion map 400, multiple emotions are mapped based on the structure in which emotions arise, and emotions that are likely to occur simultaneously are mapped close together.

[1789] These emotions are distributed at the 3 o'clock position on the Emotion Map 400, and usually fluctuate between feelings of security and anxiety. In the right half of the Emotion Map 400, situational awareness takes precedence over internal feelings, resulting in a calm impression.

[1790] The inside of the Emotion Map 400 represents inner thoughts, while the outside represents actions. Therefore, the further you go from the outside of the Emotion Map 400, the more visible (expressed in actions) your emotions become.

[1791] Here, human emotions are based on various balances, such as posture and blood sugar levels. When these balances deviate from the ideal, it results in discomfort, and when they approach the ideal, it results in pleasure. Similarly, in robots, cars, motorcycles, etc., emotions can be created based on various balances, such as posture and battery level. When these balances deviate from the ideal, it results in discomfort, and when they approach the ideal, it results in pleasure. The emotion map can be generated, for example, based on Dr. Mitsuyoshi's emotion map (Research on a system for analyzing brain physiological signals of speech emotion recognition and emotion, Tokushima University, doctoral dissertation: https: / / ci.nii.ac.jp / naid / 500000375379). The left half of the emotion map contains emotions belonging to a region called "response," where sensation is dominant. The right half of the emotion map contains emotions belonging to a region called "situation," where situational awareness is dominant.

[1792] The emotion map defines two emotions that promote learning. One is the emotion around the middle of the negative "repentance" and "reflection" on the situation side. In other words, it is when the robot experiences negative emotions such as "I never want to feel this way again" or "I don't want to be scolded again." The other is the emotion around the positive "desire" on the reaction side. In other words, it is when the robot has positive feelings such as "I want more" or "I want to know more."

[1793] The emotion identification model 59 inputs user input into a pre-trained neural network, obtains emotion values ​​representing each emotion shown in the emotion map 400, and determines the user's emotion. This neural network is pre-trained based on multiple training data sets, which are combinations of user input and emotion values ​​representing each emotion shown in the emotion map 400. Furthermore, this neural network is trained so that emotions located close together have similar values, as shown in the emotion map 900 in Figure 10. Figure 10 shows an example where multiple emotions such as "reassured," "calm," and "confident" have similar emotion values.

[1794] The above description primarily focuses on the functions of the data processing device 12 in relation to this disclosure. However, the system related to this disclosure is not necessarily implemented on a server. The system related to this disclosure may be implemented as a general information processing system. This disclosure may be implemented, for example, as a software program that runs on a personal computer or as an application that runs on a smartphone. The method related to this disclosure may be provided to users in SaaS (Software as a Service) format.

[1795] In the above embodiment, an example was given in which a specific process is performed by a single computer 22. However, the technology of this disclosure is not limited thereto, and a distributed processing of the specific process may be performed by multiple computers, including computer 22. For example, a data generation model 58 may be provided in an external device of the data processing device 12, and the external device may generate data according to the input data.

[1796] In the above embodiment, an example was given in which the specific processing program 56 is stored in the storage 32, but the technology of this disclosure is not limited thereto. For example, the specific processing program 56 may be stored in a portable, computer-readable, non-temporary storage medium such as a USB (Universal Serial Bus) memory. The specific processing program 56 stored in the non-temporary storage medium is installed in the computer 22 of the data processing device 12. The processor 28 executes specific processing according to the specific processing program 56.

[1797] Alternatively, the specific processing program 56 may be stored in a storage device such as a server connected to the data processing device 12 via the network 54, and the specific processing program 56 may be downloaded and installed on the computer 22 in response to a request from the data processing device 12.

[1798] Furthermore, it is not necessary to store the entirety of the specific processing program 56 in a storage device such as a server connected to the data processing device 12 via the network 54, or to store the entirety of the specific processing program 56 in the ...

Claims

1. In order to detect abnormal patterns in real time, a means of collecting data from multiple terminals within a distributed network, A data analysis means for generating normal activity patterns and creating a reference pattern based on the aforementioned data, A threat prediction method using generative AI that detects anomalies that deviate from the aforementioned standard pattern and predicts future attack patterns, An automated response means that automatically generates and executes countermeasures in response to anomalies detected by the threat prediction means, Alert sending means for notifying the administrator of the results of the response by the automated response means. A system that includes this.

2. The system according to claim 1, characterized in that the data analysis means uses a machine learning algorithm to detect anomalies.

3. The system according to claim 1, characterized in that the automatic response means includes automatic modification of firewall settings, disconnection of specific terminals from the network, and blocking of harmful IP addresses.

Citation Information

Patent Citations

  • Persona chatbot control method and system

    JP2022180282A