system
The system addresses the inefficiencies of existing email filters by implementing advanced analysis and sentiment recognition to accurately identify and manage email threats, enhancing user safety and comfort.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-10-02
- Publication Date
- 2026-04-14
AI Technical Summary
Existing email filtering systems lack accuracy and speed in detecting phishing and malware, leading to inadequate protection against email-mediated threats.
A system comprising means for receiving, analyzing, performing security scans, evaluating authenticity, and determining actions on emails, utilizing machine learning and natural language processing to identify and quarantine suspicious emails.
Enables high-accuracy and rapid detection of email threats, ensuring secure delivery of legitimate emails and reducing user emotional stress through sentiment analysis.
Smart Images

Figure 2026064675000001_ABST
Abstract
Description
Technical Field
[0001] The technology of the present disclosure relates to a system.
Background Art
[0002] Patent Document 1 discloses a method for controlling a persona chatbot, which is performed by at least one processor, the method including steps of receiving a user utterance, adding the user utterance to a prompt including an instruction sentence related to an explanation of a character of the chatbot, encoding the prompt, and inputting the encoded prompt into a language model to generate a chatbot utterance as a response to the user utterance.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] In the modern Internet environment, phishing attacks mediated by emails and the spread of malware have become serious problems. Such threats may cause significant damage and data leakage to recipients. Therefore, a highly effective email filtering system is required. However, existing systems have limitations in the accuracy and processing speed of security scans, making it difficult to accurately and quickly detect threats. For this reason, it is necessary to develop a system that can evaluate the authenticity of emails with high accuracy and execute appropriate actions.
Means for Solving the Problems
[0005] The present invention provides a system comprising means for receiving emails, means for analyzing the content of received emails, means for performing security scans based on the analyzed content, means for evaluating the authenticity of emails based on the results of security scans, and means for determining actions to take regarding emails based on the evaluation results. Specifically, it analyzes received emails and performs security scans that have the function of checking whether they match virus or malware signatures. It also includes means for moving spam emails to a quarantine folder based on the results of security scans. This system makes it possible to detect email-mediated threats with high accuracy and speed, and to take appropriate defensive measures.
[0006] Understood. Below are the definitions of the important words.
[0007] "Means of receiving email" refers to a device or program that retrieves email received by a user via the Internet and converts it into a format that can be processed within the system.
[0008] "Means for analyzing email content" refers to a device or program that analyzes the header information and body of a received email and extracts the necessary data.
[0009] "Means of performing a security scan" refers to a device or program that performs security checks based on the analyzed email content and verifies for any match with virus or malware signatures.
[0010] "Means for evaluating the authenticity of an email" refers to a device or program that determines whether an email is legitimate based on the results of security scans or other analyses.
[0011] "Means of determining email action" refers to a device or program that, based on the results of a credibility assessment, decides whether to deliver an email to the inbox, move it to the spam / quarantine folder, or delete it.
[0012] A "virus or malware signature" is a digital pattern or characteristic information specific to a known virus or malware.
[0013] A "quarantine folder" is a dedicated folder for temporarily storing spam or suspicious emails, and it is managed separately from other normal emails. [Brief explanation of the drawing]
[0014] [Figure 1] This is a conceptual diagram showing an example of the configuration of a data processing system according to the first embodiment. [Figure 2] This is a conceptual diagram showing an example of the essential functions of a data processing device and a smart device according to the first embodiment. [Figure 3] This is a conceptual diagram showing an example of the configuration of a data processing system according to the second embodiment. [Figure 4] This is a conceptual diagram showing an example of the main functions of a data processing device and smart glasses according to the second embodiment. [Figure 5] This is a conceptual diagram showing an example of the configuration of a data processing system according to the third embodiment. [Figure 6] This is a conceptual diagram showing an example of the main functions of a data processing device and a headset-type terminal according to the third embodiment. [Figure 7] This is a conceptual diagram showing an example of the configuration of a data processing system according to the fourth embodiment. [Figure 8] This is a conceptual diagram showing an example of the main functions of a data processing device and a robot according to the fourth embodiment. [Figure 9] This shows an emotion map where multiple emotions are mapped. [Figure 10] This shows an emotion map where multiple emotions are mapped. [Figure 11] This is a sequence diagram showing the processing flow of the data processing system in Example 1. [Figure 12] This is a sequence diagram showing the processing flow of the data processing system in Application Example 1. [Figure 13]It is a sequence diagram showing the processing flow of the data processing system in Embodiment 2 when the emotion engine is combined. [Figure 14] It is a sequence diagram showing the processing flow of the data processing system in Application Example 2 when the emotion engine is combined.
Mode for Carrying Out the Invention
[0015] Hereinafter, an example of an embodiment of the system according to the technology of the present disclosure will be described with reference to the accompanying drawings.
[0016] First, the terms used in the following description will be explained.
[0017] In the following embodiments, the numbered processor (hereinafter simply referred to as "processor") may be one arithmetic unit or a combination of a plurality of arithmetic units. Also, the processor may be one type of arithmetic unit or a combination of a plurality of types of arithmetic units. Examples of arithmetic units include a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), a GPGPU (General-Purpose computing on Graphics Processing Units), an APU (Accelerated Processing Unit), and the like.
[0018] In the following embodiments, the numbered RAM (Random Access Memory) is a memory in which information is temporarily stored and is used as a work memory by the processor.
[0019] In the following embodiments, the numbered storage is one or more non-volatile storage devices that store various programs and various parameters, etc. Examples of non-volatile storage devices include flash memory (SSD (Solid State Drive)), magnetic disks (e.g., hard disks), or magnetic tapes, etc.
[0020] In the following embodiments, the signed communication interface (I / F) is an interface that includes a communication processor and an antenna, etc. The communication interface manages communication between multiple computers. Examples of communication standards applicable to the communication interface include wireless communication standards such as 5G (5th Generation Mobile Communication System), Wi-Fi (registered trademark), or Bluetooth (registered trademark).
[0021] In the following embodiments, "A and / or B" is synonymous with "at least one of A and B." That is, "A and / or B" means that it may be A alone, or B alone, or a combination of A and B. Furthermore, in this specification, the same concept as "A and / or B" applies when expressing three or more things linked by "and / or."
[0022] [First Embodiment]
[0023] Figure 1 shows an example of the configuration of the data processing system 10 according to the first embodiment.
[0024] As shown in Figure 1, the data processing system 10 includes a data processing device 12 and a smart device 14. An example of the data processing device 12 is a server.
[0025] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0026] The smart device 14 comprises a computer 36, a reception device 38, an output device 40, a camera 42, and a communication interface 44. The computer 36 comprises a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The reception device 38, output device 40, and camera 42 are also connected to the bus 52.
[0027] The reception device 38 is equipped with a touch panel 38A and a microphone 38B, etc., and receives user input. The touch panel 38A receives user input by detecting contact with an object (e.g., a pen or finger). The microphone 38B receives user input by detecting the user's voice. The control unit 46A transmits data indicating the user input received by the touch panel 38A and microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the data indicating the user input.
[0028] The output device 40 includes a display 40A and a speaker 40B, and presents data to the user 20 by outputting the data in a form perceptible to the user 20 (e.g., audio and / or text). The display 40A displays visible information such as text and images according to instructions from the processor 46. The speaker 40B outputs audio according to instructions from the processor 46. The camera 42 is a small digital camera equipped with an optical system such as a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor.
[0029] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various types of information between processor 46 and processor 28 via network 54.
[0030] Figure 2 shows an example of the main functions of the data processing device 12 and the smart device 14.
[0031] As shown in Figure 2, in the data processing device 12, a specific processing is performed by the processor 28. A specific processing program 56 is stored in the storage 32. The specific processing program 56 is an example of a "program" related to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 according to the specific processing program 56 executed on the RAM 30.
[0032] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[0033] In the smart device 14, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The reception output program 60 is used in conjunction with a specific processing program 56 by the data processing system 10. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.
[0034] Next, the specific processing performed by the specific processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the smart device 14 as the "terminal".
[0035] The system according to the present invention has the function of automatically determining appropriate actions by analyzing emails received by the user with high accuracy, performing security scans, and evaluating their authenticity. This system consists of several main means.
[0036] First, the server has a means of receiving email. Users receive emails through a regular email client, but the received email is first sent to the server. Here, the server retrieves the email header information and body and converts it into a parseable format. Through this analysis, the server extracts important data such as the sender, recipient, subject, and body of the email.
[0037] Next, the server is equipped with means to analyze the content of emails. It analyzes the header information and body of received emails to perform tasks such as verifying the validity of the sender domain and detecting anomalies in the message content. This allows for a basic check of whether the email content is appropriate.
[0038] Next, the server has the means to perform security scans. Here, security checks are performed based on the content of the analyzed emails. This check includes verifying matches with virus and malware signatures. Machine learning models are also used to detect phishing and spam patterns.
[0039] The server then uses methods to evaluate the authenticity of the email. Based on the results of security scans and other analyses, it determines whether the email is legitimate or a phishing or spam email. At this point, a more advanced analysis engine may use natural language processing (NLP) techniques to evaluate the context and content of the email.
[0040] Based on the evaluation results, the server uses a means to determine the action to take on emails. For example, emails deemed safe are delivered to the regular inbox, while emails identified as spam or phishing are moved to a quarantine folder. The server also sends an alert to the administrator if it detects a high-level threat.
[0041] As a concrete example, consider a scenario where a user opens their email client and receives a new email. This email is received by the server and its contents are analyzed. A security scan is then performed to check for any virus signatures. After evaluating the email's authenticity, it is determined to be spam. Finally, the server moves this email to a quarantine folder and does not display it in the inbox.
[0042] The system of the present invention allows users to receive secure emails that have been filtered with high accuracy, significantly improving their protection against malicious emails.
[0043] The following describes the processing flow.
[0044] Step 1:
[0045] The server receives a new email from the user's email client. The received email is first stored on the server, and a process begins to parse the header information and body.
[0046] Step 2:
[0047] The server analyzes the email header information. It extracts and logs the sender address, recipient address, subject, date, and sender IP address. It also verifies whether the email's sender domain is legitimate through authentication methods such as SPF, DKIM, and DMARC.
[0048] Step 3:
[0049] The server analyzes the email body. The analysis engine divides the email content into sections and extracts text information from each section. Links and attachments within the email are also identified and analyzed individually.
[0050] Step 4:
[0051] The server performs a security scan. It compares the analyzed email text, links, and attachments against a database of virus and malware signatures. It also uses machine learning models to detect phishing and spam patterns.
[0052] Step 5:
[0053] The server uses a natural language processing (NLP) engine to analyze the context of the email. This contextual analysis helps determine whether the email content is legitimate business communication or a phishing email.
[0054] Step 6:
[0055] The server evaluates the authenticity of emails based on the results of security scans and NLP analysis. It calculates security level and risk scores to determine the overall reliability of the email.
[0056] Step 7:
[0057] The server determines the action to take regarding the email. Based on the evaluation, it either delivers it to the inbox as a regular email or moves it to the quarantine folder as spam or phishing email. If necessary, it sends an alert to the administrator.
[0058] Step 8:
[0059] Users check their emails in their inbox or quarantine folder. They can open and review emails deemed safe. For emails moved to the quarantine folder, users can report them as spam or correct false positives.
[0060] Following these processing steps, the system of the present invention can achieve highly accurate email filtering and protect users from email-based threats.
[0061] (Example 1)
[0062] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server," and the smart device 14 will be referred to as the "terminal."
[0063] Traditional email systems often fail to adequately evaluate and filter incoming emails, resulting in malicious and spam emails remaining in users' inboxes. Furthermore, the lack of adequate mechanisms for quickly notifying administrators of advanced threats increases security risks for businesses and individuals. Therefore, there is a growing need for more accurate analysis and security scanning, along with reliability assessments, when receiving emails.
[0064] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.
[0065] In this invention, the server includes means for receiving emails, means for analyzing the content of emails, means for performing security scans based on the analyzed content, means for evaluating the authenticity of emails based on the results of security scans and additional analysis, means for determining actions to take regarding emails based on the evaluated results, and means for sending alerts to administrators when advanced threats are detected. This enables users to receive only safe emails, filters out malicious emails with high accuracy, quickly notifies administrators of advanced threats, and mitigates security risks.
[0066] "Means of receiving email" refers to the function by which a server retrieves email from a user's email client. This is done using communication protocols such as IMAP and POP3.
[0067] "Methods for analyzing email content" refer to the function of a server that analyzes the header information and body of received emails and extracts important data (sender, recipient, subject, body text, etc.). Software tools such as the Python email package are often used for this purpose.
[0068] "Means of performing security scans" refers to a function where the server performs security checks based on the content of analyzed emails, such as virus and malware signature checks and pattern recognition for phishing and spam emails. This may involve using tools like ClamAV or machine learning models.
[0069] "Methods for evaluating email authenticity" refers to a function that allows a server to assess the reliability of an incoming email and determine whether the email content is trustworthy, based on security scans and additional analysis results. This utilizes NLP technology and generative AI models.
[0070] "Means for determining email actions" refers to the function that allows the server to process emails appropriately (e.g., deliver to the inbox, move to the quarantine folder) based on the credibility assessment results.
[0071] "Method for sending alerts to administrators when advanced threats are detected" refers to a function that notifies administrators in real time when the server detects advanced security threats such as phishing or malware. This includes sending emails using the SMTP protocol, as well as notifications via the management dashboard.
[0072] Modes for carrying out the invention
[0073] The system according to the present invention has the function of automatically determining appropriate actions by analyzing emails received by users with high accuracy, performing security scans, and evaluating their authenticity. The main components of this system include a server, a terminal, and a user.
[0074] Hardware and software to be used
[0075] server:
[0076] The server uses IMAP or POP3 protocols to access the user's mailbox and retrieve emails.
[0077] The server uses Python's email package to parse the headers and body of received emails and extract important data, such as the sender, recipient, subject, and email body text.
[0078] The server uses ClamAV (open-source antivirus software) to compare incoming emails and attachments against virus and malware signatures.
[0079] The server uses machine learning models (e.g., TENSORFLOW® or Scikit-learn) to identify patterns in phishing and spam emails.
[0080] The server uses a generative AI model (e.g., GPT-3®) and leverages natural language processing technology to evaluate the context and reliability of the email's content.
[0081] The server uses the SMTP protocol to send an alert to the administrator if an advanced threat is detected.
[0082] Terminal:
[0083] The user's device functions as a regular email client (e.g., Microsoft Outlook or Gmail), receiving and viewing emails after they have been parsed and evaluated by the server.
[0084] System operation example
[0085] When a user receives a new email using Microsoft Outlook, the email is first sent to the server. The server then performs the following actions in sequence:
[0086] 1. Receiving emails: The server uses the IMAP protocol to access the user's Outlook account and retrieve new emails.
[0087] 2. Email parsing: The server uses the Python email package to parse the header information and body of the email, and extract the sender and subject.
[0088] 3. Security scan: The server runs ClamAV to check for viruses, and then uses a machine learning model to determine if it is phishing or spam.
[0089] 4. Credibility Assessment: The server uses a generated AI model (GPT-3) to evaluate the credibility of the email body using natural language processing technology.
[0090] 5. Decision on action: The server moves emails identified as spam to a quarantine folder and delivers safe emails to the inbox.
[0091] 6. Sending alerts to the administrator: The server uses the SMTP protocol to notify the administrator of any detected threats.
[0092] Example of a prompt
[0093] Please analyze the content of the following email and assess its credibility:
[0094] Sender: example@example.com
[0095] Subject: Important Notice
[0096] Body: This email is urgent. Click to see details.
[0097] This means users receive highly filtered and secure emails, and their protection from malicious emails is enhanced.
[0098] The flow of the specific processing in Example 1 will be explained using Figure 11.
[0099] Step 1:
[0100] Receiving emails
[0101] Input: The user sends an email, or the server retrieves new mail from the mail server using the IMAP / POP3 protocol.
[0102] Specific operation: The server uses the IMAP protocol to access the user's mailbox (e.g., Gmail, Outlook) and retrieve new emails.
[0103] Output: The retrieved email data is saved to the server.
[0104] Step 2:
[0105] Email analysis
[0106] Input: Email data obtained in Step 1.
[0107] Specific operation: The server uses the Python email package to parse email header information (sender, recipient, subject) and body text.
[0108] Data processing / data calculation: Analyze email headers and body text to extract important data.
[0109] Output: Analyzed email data (sender address, recipient address, subject, body text).
[0110] Step 3:
[0111] Run a security scan
[0112] Input: Email data analyzed in Step 2.
[0113] Specific operation: The server uses ClamAV to scan email bodies and attachments for virus and malware signatures. It also uses machine learning models (e.g., TensorFlow or Scikit-learn) to detect phishing and spam patterns.
[0114] Data processing / data calculation: Matching email content with virus and malware signatures, identifying phishing and spam patterns.
[0115] Output: Security scan results (presence or absence of security risks).
[0116] Step 4:
[0117] Email credibility assessment
[0118] Input: Security scan results obtained in Step 3 and email data analyzed in Step 2.
[0119] Specific operation: The server uses a generated AI model (e.g., GPT-3) and natural language processing techniques to determine the reliability of the email body.
[0120] Data processing / data calculation: Evaluating the reliability of the context and content of email bodies.
[0121] Output: Credibility assessment results (e.g., trustworthy, spam, phishing).
[0122] Step 5:
[0123] Email Action Decision
[0124] Input: The results of the credibility assessment obtained in Step 4.
[0125] Specific operation: Based on the credibility assessment results, the server decides whether to deliver the email to the inbox or move it to the quarantine folder.
[0126] Data processing / data calculation: Email sorting based on evaluation results.
[0127] Output: Sorted emails (Inbox, Quarantine folder).
[0128] Step 6:
[0129] Sending alerts to administrators
[0130] Input: Security risks and threats detected in Steps 3 and 4.
[0131] Specific operation: The server uses the SMTP protocol to notify administrators of security threats, including real-time notifications to the management dashboard.
[0132] Data processing / data computation: Generating threat intelligence and calling notification protocols.
[0133] Output: Alert notifications sent to the administrator (email, dashboard notification).
[0134] (Application Example 1)
[0135] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server," and the smart device 14 will be referred to as the "terminal."
[0136] In modern email communication, users are frequently exposed to threats such as spam, phishing, and virus emails, making it difficult to provide a secure email environment. Furthermore, traditional email filtering systems lack sufficient accuracy, leading to frequent false positives and missed detections. Additionally, notifications to users and administrators may be delayed when email threats occur. There is a need to solve these problems and provide highly accurate and rapid email security measures.
[0137] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.
[0138] In this invention, the server includes means for receiving emails, means for analyzing the content of emails, means for performing security scans based on the analyzed content, means for evaluating the authenticity of emails based on the results of security scans, means for determining actions to take regarding emails based on the evaluation results, means for detecting phishing and spam patterns using machine learning models, and means for sending real-time notifications to users based on the evaluation results. As a result, users receive only safe emails that have been filtered with high accuracy, improving their defense against malicious emails and enabling quick responses.
[0139] "Means of receiving email" refers to the functions and mechanisms for obtaining email from an external mail server.
[0140] "Methods for analyzing email content" refer to technologies for analyzing the header information and body of received emails and extracting the data contained therein.
[0141] "Means of performing security scans" refers to functions that, based on the content of analyzed emails, check for matches with virus and malware signatures, and detect phishing and spam patterns.
[0142] "Methods for evaluating the authenticity of emails" refer to functions that determine whether an email is legitimate, phishing, or spam, based on the results of security scans.
[0143] "Means for determining email actions" refers to the function that determines, based on evaluation results, whether to deliver the email to the inbox, move it to a quarantine folder, or take other actions.
[0144] "Methods for detecting phishing and spam patterns using machine learning models" refers to technologies that use machine learning algorithms to detect phishing and spam characteristics in received emails and assess their risk.
[0145] "Means of sending real-time notifications to users based on the evaluation results" refers to a function or system that immediately issues a warning to users or administrators if the evaluation results of an email are determined to contain malicious content.
[0146] This invention relates to a system that analyzes emails received by users with high accuracy, performs security scans, and evaluates their authenticity. The following describes how to implement this system.
[0147] First, the server has the means to receive email. Specifically, the server has the function to retrieve email from an external mail server and convert its contents into a format that can be processed. This email is received through the email client that the user normally uses, but it is processed by the server first.
[0148] Next, the server is equipped with a means to analyze the content of emails. It analyzes the header information and body of received emails and extracts important data. Software such as Python's email library is used for this analysis. The analyzed data includes information such as the sender, recipient, subject, and body of the email.
[0149] Next, the server has the means to perform a security scan based on the content of the analyzed email. This security scan includes the ability to check for matches with virus and malware signatures. Antivirus software and machine learning models are used for the security scan.
[0150] Furthermore, the server has a means to detect phishing and spam patterns using machine learning models. This means that it can determine with high accuracy whether an received email is phishing or spam. Specifically, machine learning models using libraries such as Python's scikit-learn are used.
[0151] Furthermore, the server has a means to evaluate the authenticity of emails based on the results of security scans and evaluations of machine learning models. This means determines whether an email is legitimate or fraudulent.
[0152] Finally, the server has a mechanism to determine the action to take on an email based on the evaluation results. This mechanism ensures that emails deemed safe are delivered to the regular inbox, while emails identified as spam or phishing are moved to a quarantine folder. It also includes a mechanism to send real-time notifications to the user based on the evaluation results.
[0153] As a concrete example, consider a scenario where a user opens their email client and receives a new email. The server receives this email and analyzes its contents. It then performs a security scan to check for any matches with virus signatures. Next, it uses a machine learning model to detect phishing and spam patterns. Based on the evaluation results, spam emails are moved to a quarantine folder, and users receive real-time notifications for important threats.
[0154] Example of a prompt:
[0155] "Please introduce our ultra-high-performance email security scanning system. This system analyzes email headers and body text, enabling highly accurate detection of viruses, malware, phishing, and spam. It also uses natural language processing technology to evaluate email context and content, determining appropriate actions. Using this system ensures only safe emails appear in the user's inbox, significantly improving protection against malicious emails."
[0156] The above is a detailed explanation for carrying out the present invention.
[0157] The flow of a specific process in Application Example 1 will be explained using Figure 12.
[0158] Step 1:
[0159] The server receives new emails sent from the user's email client. The input is the entire incoming email, and its contents are passed directly to the next step. Specifically, the server connects to the mail server via the POP3 or IMAP protocol and retrieves unread emails.
[0160] Step 2:
[0161] The server parses the header information and body of received emails. The input is the entire received email, and the output is the parsed data. This parsing uses the Python email library to extract the sender, recipient, subject, and body of the email.
[0162] Step 3:
[0163] The server performs a security scan based on the content of the analyzed email. The input is the analyzed email data, and the output is the security scan results. Specifically, it uses antivirus software to compare the data against virus and malware signatures and check for matches.
[0164] Step 4:
[0165] The server uses a machine learning model to detect phishing and spam patterns. The input is analyzed email data, and the output is the evaluation result for phishing and spam. Specifically, the scikit-learn library in Python is used to evaluate the features of emails with a pre-trained machine learning model.
[0166] Step 5:
[0167] The server evaluates the authenticity of emails based on security scan results and machine learning model evaluations. The inputs are scan results and machine learning evaluation results, and the output is the email authenticity rating. Specifically, these evaluations are integrated, and a scoring system determines whether the email is legitimate.
[0168] Step 6:
[0169] The server determines the action to take on an email based on the credibility assessment result. The input is the credibility assessment result, and the output is the email sorting action. Specifically, emails deemed safe are delivered to the regular inbox, while emails identified as spam or phishing are moved to a quarantine folder.
[0170] Step 7:
[0171] The server sends real-time notifications to users based on the evaluation results. The input is the evaluation result, and the output is the notification message. Specifically, if a serious threat is detected, the server sends a warning to the user and administrator via push notification or email.
[0172] This process ensures that users receive only highly filtered and secure emails, significantly improving their protection against malicious emails.
[0173] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.
[0174] The system according to the present invention analyzes emails received by users with high accuracy, performs security scans, evaluates their authenticity, and, by incorporating an emotion engine, recognizes the user's emotions to complement email evaluation. This system consists of several main means.
[0175] First, the server receives a new email from the user's email client. The received email is initially stored on the server, and a process begins to analyze the header information and body. The server analyzes the email header information, extracting the sender address, recipient address, subject, date, etc., and recording them in a log. In addition, during the analysis of the email body, links and attachments are identified and analyzed individually.
[0176] Next, the server performs a security scan. It compares the analyzed email text, links, and attachments against a database of virus and malware signatures. Machine learning models are also used to detect phishing and spam patterns. Furthermore, a natural language processing (NLP) engine is used to analyze the context of the email and assess whether it is legitimate business communication.
[0177] Furthermore, a key feature of this invention is the inclusion of an emotion engine. The server operates the emotion engine based on the email body and contextual information to recognize the emotions a user felt when reading the email. Specifically, it classifies emotions as positive, negative, or neutral based on specific keywords and contextual patterns within the email. This emotion classification result is then integrated with the security scan results to complement the final credibility assessment.
[0178] Based on the evaluation results, the server decides what action to take with the email. For example, emails deemed safe are delivered to the regular inbox, while emails identified as spam or phishing are moved to a quarantine folder. If the user's sentiment is perceived as negative, a more detailed analysis is performed, and an alert is sent to the administrator if necessary.
[0179] As a concrete example, consider a scenario where a user opens an email client and receives a new email. The email is received by the server, and its header information and body are analyzed. Then, a security scan is performed, and a virus check is conducted. The sentiment engine analyzes the context of the email and determines that the user may experience negative emotions upon reading it. As a result, the email undergoes further detailed analysis and is ultimately moved to the quarantine folder. The user cannot view this email in their inbox; they can review its contents in the quarantine folder and take appropriate action (e.g., report it as spam or correct a false positive).
[0180] The system of this invention allows users to receive secure emails that have been filtered with high accuracy, and furthermore, by using an emotion engine, it is possible to reduce the emotional stress caused by reading emails. As a result, a safer and more comfortable email environment is provided for users.
[0181] The following describes the processing flow.
[0182] Step 1:
[0183] The server receives a new email from the email client. The received email is first stored on the server in preparation for the next analysis step.
[0184] Step 2:
[0185] The server analyzes the email header information. It extracts the sender address, recipient address, subject, date, sender IP address, etc., and records them in a log. It also performs authentication checks such as SPF, DKIM, and DMARC.
[0186] Step 3:
[0187] The server analyzes the email body. It breaks down the text portion of the email, identifies the main sections, and extracts the text information from each section. It also identifies links and attachments and analyzes them individually.
[0188] Step 4:
[0189] The server performs a security scan. It compares the analyzed email text, links, and attachments against a database of virus and malware signatures. Furthermore, it uses machine learning models to detect phishing and spam patterns.
[0190] Step 5:
[0191] The server uses a natural language processing (NLP) engine to analyze the context of the email. This contextual analysis helps determine whether the email content is legitimate business communication or a scam or spam email.
[0192] Step 6:
[0193] The server uses an emotion engine to recognize the user's emotions based on the content of the email. For example, it can determine, based on specific keywords and context, whether the email is likely to evoke positive, negative, or neutral emotions.
[0194] Step 7:
[0195] The server evaluates the authenticity of emails based on security scans, NLP analysis, and sentiment engine results. This allows it to calculate an overall security level and risk score, determining the reliability of the email.
[0196] Step 8:
[0197] The server determines the action to take on an email. For example, emails deemed safe are delivered to the inbox, while emails identified as spam or phishing are moved to a quarantine folder. If the user's sentiment is perceived as negative, further detailed analysis is performed, and an alert is sent to the administrator if necessary.
[0198] Step 9:
[0199] Users check their emails in their inbox or quarantine folder. They can open and review emails deemed safe. For emails moved to the quarantine folder, users can report them as spam or correct false positives.
[0200] In this way, the server performs a series of processes, allowing users to receive highly accurate, filtered, and secure emails. Furthermore, the introduction of an emotion engine reduces the emotional stress associated with reading emails, providing a more comfortable email environment.
[0201] (Example 2)
[0202] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server" and the smart device 14 will be referred to as the "terminal".
[0203] Traditional email systems perform security scans on emails, but lack the complementary evaluation of email content through sentiment analysis. This makes it difficult to reliably detect emails that evoke negative emotions in users or are malicious. In particular, malicious activities such as phishing and spam emails have become more sophisticated, and simple virus checks and signature matching are no longer sufficient countermeasures. Furthermore, the risk of users experiencing psychological stress due to the content of emails they receive is also increasing. Therefore, there is a need for a system that simultaneously reduces both email security and user emotional stress.
[0204] The identification processing performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means. In this invention, the server includes means for receiving emails, means for analyzing the content of the emails, means for performing a security scan based on the analyzed content, means for evaluating the authenticity of the emails based on the results of the security scans, and means for recognizing the sentiment of the emails using a sentiment analysis engine and supplementing the authenticity evaluation. As a result, emails received by the user are filtered with high accuracy, and emails that pose a risk of causing negative emotions are detected through sentiment analysis, making it possible to provide a safer and more comfortable email environment for the user.
[0205] "Means of receiving emails" refers to the function of retrieving new emails from the user's email client and saving them on the server.
[0206] "Means for analyzing the contents of the email" refers to a system that examines the header information and body of a received email and extracts the sender's address, recipient's address, subject, date, links, attachments, etc.
[0207] "Means for performing a security scan based on the analyzed content" refers to a system that uses the analysis results to examine emails against signatures of viruses and malicious programs, and has the function of detecting malicious activity.
[0208] "Means for evaluating the authenticity of an email based on the results of the security scan" refers to a mechanism that determines and evaluates the legitimacy and potential risks of an email through the results of a security scan.
[0209] "Means for determining email action based on the evaluated results" refers to a system that determines specific actions, such as whether to deliver the email to the inbox or move it to a quarantine folder, based on the credibility assessment.
[0210] "A means of recognizing the emotions in emails using an emotion analysis engine to complement credibility evaluation" refers to a system that analyzes the content of an email, classifies the positive, negative, or neutral emotions that a user might feel upon reading it, and then uses the results to further enhance the credibility evaluation of the email.
[0211] Modes for carrying out the invention
[0212] The system according to the present invention analyzes emails received by users with high accuracy, performs security scans, evaluates their credibility, and, by incorporating an emotion engine, recognizes the user's emotions to complement email evaluation. This system consists of several main means.
[0213] First, the server receives new emails from the user's email client. The received emails are initially stored on the server, and a process begins to parse the header information and body. Specifically, the server runs on high-performance hardware (e.g., AWS® EC2 instances) and uses email server software (e.g., Postfix) to receive and store emails. Next, the server uses a Python script and the email package to parse and log the email header information (sender address, recipient address, subject, date, etc.). It also uses BeautifulSoup to parse the HTML body, identify links and attachments, and analyze this information individually.
[0214] Next, the server performs a security scan. This scan first uses ClamAV to compare the email text, links, and attachments against a signature database of viruses and malicious programs. Furthermore, a pre-trained machine learning model (e.g., TensorFlow) is used to detect phishing and spam patterns. The TensorFlow model extracts and evaluates phishing and spam features from the email body text.
[0215] Subsequently, the server uses a natural language processing engine (e.g., Google's BERT) to analyze the context of the email and evaluate whether it is legitimate business communication. Furthermore, a distinctive feature of this invention is the inclusion of an emotion engine. Based on the email body and contextual information, the server operates an emotion engine (e.g., IBM Watson's Tone Analyzer) to recognize the emotions the user felt when reading the email. Specifically, it classifies emotions as positive, negative, or neutral based on specific keywords and contextual patterns within the email. This emotion classification result is then integrated with the security scan results to complement the final credibility assessment.
[0216] Based on the evaluation results, the server decides what action to take with the email. For example, emails deemed safe are delivered to the regular inbox, while emails identified as spam or malicious are moved to a quarantine folder. If the user's sentiment is perceived as negative, a more detailed analysis is performed, and an alert is sent to the administrator if necessary.
[0217] As a concrete example, consider a scenario where a user opens an email client (e.g., Microsoft Outlook) and receives a new email. The email is received by the server, and its header information and body are analyzed. Then, a security scan is performed, and a virus check is conducted. Furthermore, the sentiment engine analyzes the context of the email and determines that the user may experience negative emotions upon reading it. As a result, the email undergoes further detailed analysis and is ultimately moved to a quarantine folder. The user cannot view this email in their inbox; they can review its contents in the quarantine folder and take appropriate action (such as reporting it as spam or correcting a false positive).
[0218] An example of a prompt message is as follows:
[0219] When a user opens their email client and receives a new email, the server receives and stores the email. The server uses a Python script to parse the header and body information and extract the necessary information. Next, it performs a virus scan with ClamAV and detects spam and phishing with a TensorFlow model. Finally, it uses the IBM Watson API to perform sentiment analysis and report a final rating. Please describe the specific steps of these processes.
[0220] The flow of the specific processing in Example 2 will be explained using Figure 13.
[0221] Detailed explanation of the program's processing steps
[0222] Step 1:
[0223] incoming mail
[0224] Input: New email from the user's email client
[0225] Processing: The server receives emails via port 25 and temporarily stores them in a temporary directory.
[0226] Output: Mail files stored on the server
[0227] Specific operation: The server uses mail server software to execute the receiving process. The server listens on a specific port, and when it receives new mail, it writes it to a temporary directory.
[0228] Step 2:
[0229] Email analysis
[0230] Input: Mail files saved in a temporary directory
[0231] Processing: The server analyzes the email header information and body, extracting sender address, recipient address, subject, date, links, attachments, etc.
[0232] Output: Analyzed header information and body content
[0233] Specific operation: The server executes a Python script and parses header information using the email package. It uses BeautifulSoup to identify links and attachments from the HTML body. The extracted information is recorded in a database and log files.
[0234] Step 3:
[0235] Security scan
[0236] Input: Parsed header information and body content
[0237] Processing: The server performs virus scanning and spam / phishing detection using machine learning models.
[0238] Output: Security scan evaluation results
[0239] Specific operation: The server uses ClamAV to scan attachments and the email body for viruses. It also runs a TensorFlow machine learning model to analyze the email body and determine if it is phishing or spam.
[0240] Step 4:
[0241] Emotion analysis
[0242] Input: Analyzed email body
[0243] Processing: The server activates an emotion engine to classify the email content into positive, negative, or neutral emotions.
[0244] Output: Results of sentiment analysis
[0245] Specific operation: The server sends the email body to the IBM Watson Tone Analyzer API and retrieves the returned sentiment classification result. The result is classified as either positive, negative, or neutral.
[0246] Step 5:
[0247] Credibility assessment and final action decision
[0248] Input: Security scan evaluation results and sentiment analysis results
[0249] Processing: The server integrates these results, evaluates the authenticity of the email, and determines the appropriate action.
[0250] Output: Determination of the email delivery destination (inbox or quarantine folder)
[0251] Specific operation: The server runs a credibility assessment algorithm and calculates a final score. Based on the score, if the email is deemed safe, it is delivered to the inbox; if deemed dangerous, it is moved to a quarantine folder. In addition, if negative sentiment is detected, a detailed analysis is performed and an alert is sent to the administrator if necessary.
[0252] (Application Example 2)
[0253] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as a "server" and the smart device 14 as a "terminal".
[0254] Traditional email systems prioritize security to protect users from viruses, malware, phishing, and spam. However, this alone lacks consideration for the emotional stress and negative feelings users experience, meaning certain emails can cause significant emotional distress. Therefore, a system is needed that integrates security scanning with sentiment analysis, considering the impact on users' emotions along with evaluating the reliability of emails.
[0255] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means. In this invention, the server includes means for receiving emails, means for analyzing the content of the emails, means for performing a security scan based on the analyzed content, an emotion engine having the function of recognizing and classifying emotions based on the content and contextual information of the emails, and means for determining the final email action, including an evaluation of the emotion engine. This makes it possible to detect viruses and malware, quarantine spam emails, and reduce the emotional stress on the user.
[0256] "Means of receiving email" refers to the function that allows a server to retrieve emails from a user's email client.
[0257] "Means for analyzing the contents of the email" refers to the process of analyzing the header information, body, links, and attachments of a received email and extracting data for security and sentiment evaluation.
[0258] "Means for performing a security scan based on the analyzed content" refers to a function that compares the analyzed email content with a virus and malware signature database to detect phishing and spam patterns.
[0259] "Means for evaluating the authenticity of an email based on the results of the security scan" refers to algorithms or machine learning models used to evaluate whether an email is trustworthy based on the results of the security scan.
[0260] A "sentiment engine that recognizes and classifies emotions based on email content and contextual information" is a system that analyzes specific keywords and contextual patterns within an email body and classifies the emotions (positive, negative, or neutral) a user feels when reading the email.
[0261] "Means for determining the final email action, including the evaluation of the sentiment engine" refers to logic that integrates the results of security scans and sentiment evaluations to determine the final action, such as sending or quarantining the email.
[0262] The system for realizing this invention provides a function that, upon receiving an email from a user, analyzes the email with high accuracy and evaluates its reliability and emotional impact using a security scan and sentiment engine. Specifically, the following processes take place between the server, terminal, and user.
[0263] The system first has the function of receiving new emails from the user's email client. The received emails are stored on the server, and then a process of analyzing the email header information and body begins. The header information extracted includes the sender address, recipient address, subject, and date, and these are recorded in the log. In the body analysis, links and attachments are also identified and analyzed separately.
[0264] Next, the server performs a security scan. This process compares the analyzed email text, links, and attachments against a database of virus and malware signatures. Machine learning models are also used to detect phishing and spam patterns. Furthermore, a natural language processing (NLP) engine is used to analyze the context of the email and assess whether it is legitimate business communication.
[0265] In addition, the system's signature emotion engine is activated. Based on the email body and contextual information, the emotion engine identifies specific keywords and patterns and classifies them as positive, negative, or neutral. This emotion classification result is integrated with the results of the aforementioned security scan and complements the final email authenticity assessment.
[0266] Based on the credibility assessment, the server decides what to do with the email. For example, emails deemed safe by the security check are delivered to the regular inbox, while emails suspected of being spam or phishing, or those classified as potentially causing negative emotions, are moved to a quarantine folder. In cases of high importance, an alert may also be sent to the administrator.
[0267] To perform these processes, the server implements machine learning models using libraries such as Python and TensorFlow, a natural language processing engine, and spam / phishing detection algorithms. User information, email data, and analysis results are stored in the database.
[0268] Specific example
[0269] When a user receives a new email on their smartphone, it is sent to the server where its header information and body are analyzed. A security scan is then performed to check for viruses. The sentiment engine analyzes the email's context, and if it determines that the email may evoke negative emotions, it is moved to a quarantine folder. The user receives a warning notification at this time.
[0270] Example of a prompt
[0271] "Implement a system that performs security and sentiment analysis on newly received emails and takes appropriate actions to help users maintain positive emotions."
[0272] This system allows users to enjoy a safe and comfortable email environment that is free from spam and phishing emails, and also takes emotional impact into consideration.
[0273] The flow of a specific process in Application Example 2 will be explained using Figure 14.
[0274] Step 1:
[0275] The server receives a new email from the user's email client. At this point, the input data is the raw data of the received email. The server retrieves this data and stores it as an email object.
[0276] Step 2:
[0277] The server analyzes the header information and body of received emails. The header information analysis extracts the sender address, recipient address, subject, date, etc. The input data requires an email object, and the output is the analyzed header information. Specifically, this information is extracted and logged using the Python email library.
[0278] Step 3:
[0279] The server analyzes the body of the email to identify links and attached files. The input is the email object and its body text, and the output is a list of the identified links and attached files. This is done using Python's regular expression and URL parsing libraries.
[0280] Step 4:
[0281] The server performs a security scan. At this stage, the body of the email, links, and attached files are compared against a virus and malware signature database. The input data is each part of the analyzed email, and the output is the scan result (e.g., safe, virus detected, phishing suspicion, etc.). This process is performed using ClamAV or the VirusTotal API.
[0282] Step 5:
[0283] The server uses a machine learning model to detect phishing and spam patterns. The input is the text data of the email, and the output is a spam score and a phishing score. This is done using models from Scikit-learn or TensorFlow.
[0284] Step 6:
[0285] The server analyzes the context of the email using a natural language processing (NLP) engine. The input data is the body of the email, and the output is an evaluation result as to whether the email is a legitimate business communication. The context is analyzed using Python's nltk or spaCy libraries.
[0286] Step 7:
[0287] The server operates an emotion engine that recognizes and classifies emotions based on the email body and context. The input data is the email body and contextual information, and the output is the emotion classification result (positive, negative, or neutral). This is done using a pre-trained TensorFlow model.
[0288] Step 8:
[0289] The server integrates the results of security scans and the sentiment engine to evaluate the final authenticity of the email. The input data consists of the results of each scan and sentiment classification, and the output is the overall evaluation result. Based on this, the processing action for the email (for example, safe emails go to the inbox, suspicious emails go to the quarantine folder) is determined.
[0290] Step 9:
[0291] The server performs email actions based on the evaluation results. The input data is the final overall evaluation result, and the output is the sorting of emails into the user's inbox or quarantine folder. Specifically, emails deemed safe are delivered to the regular inbox, while emails identified as spam or phishing are moved to the quarantine folder.
[0292] This series of processes will allow users to enjoy a safe and emotionally sensitive email environment.
[0293] The specific processing unit 290 transmits the result of the specific processing to the smart device 14. In the smart device 14, the control unit 46A causes the output device 40 to output the result of the specific processing. The microphone 38B acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.
[0294] Data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of data generation model 58 is ChatGPT (registered trademark) (Internet search).<URL: https: / / openai.com / blog / chatgpt> ), Gemini (registered trademark) (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[0295] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and the specific processing may also be performed by the smart device 14.
[0296] [Second Embodiment]
[0297] Figure 3 shows an example of the configuration of the data processing system 210 according to the second embodiment.
[0298] As shown in Figure 3, the data processing system 210 includes a data processing device 12 and smart glasses 214. An example of the data processing device 12 is a server.
[0299] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0300] The smart glasses 214 include a computer 36, a microphone 238, a speaker 240, a camera 42, and a communication interface 44. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, and camera 42 are also connected to the bus 52.
[0301] The microphone 238 receives voice signals from the user 20 and receives instructions from the user 20. The microphone 238 captures the voice signals from the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.
[0302] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the area around the user 20 (for example, an imaging range defined by a field of view equivalent to the width of a typical healthy person's field of vision).
[0303] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.
[0304] Figure 4 shows an example of the main functions of the data processing device 12 and the smart glasses 214. As shown in Figure 4, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.
[0305] The specific processing program 56 is an example of the "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by operating as the specific processing unit 290 according to the specific processing program 56 executed by the processor 28 on the RAM 30.
[0306] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the specific processing unit 290.
[0307] In the smart glasses 214, the processor 46 performs receiving and output processing. The storage 50 stores a receiving and output program 60. The processor 46 reads the receiving and output program 60 from the storage 50 and executes the read receiving and output program 60 on the RAM 48. The receiving and output processing is realized by operating as the control unit 46A according to the receiving and output program 60 executed by the processor 46 on the RAM 48.
[0308] Next, the specific processing by the specific processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 is referred to as a "server", and the smart glasses 214 are referred to as a "terminal".
[0309] The system according to the present invention has a function of automatically determining appropriate actions by analyzing electronic mails received by a user with high precision, performing a security scan, and evaluating the authenticity. This system is composed of several main means.
[0310] First, the server is provided with means for receiving mails. The user receives an electronic mail through a normal mail client, but the received mail is first sent to the server. Here, the server acquires the header information and the text of the mail and converts them into an analyzable form. By this analysis, the server extracts important data such as the sender, recipient, subject, and text of the mail.
[0311] Next, the server is equipped with means to analyze the content of emails. It analyzes the header information and body of received emails to perform tasks such as verifying the validity of the sender domain and detecting anomalies in the message content. This allows for a basic check of whether the email content is appropriate.
[0312] Next, the server has the means to perform security scans. Here, security checks are performed based on the content of the analyzed emails. This check includes verifying matches with virus and malware signatures. Machine learning models are also used to detect phishing and spam patterns.
[0313] The server then uses methods to evaluate the authenticity of the email. Based on the results of security scans and other analyses, it determines whether the email is legitimate or a phishing or spam email. At this point, a more advanced analysis engine may use natural language processing (NLP) techniques to evaluate the context and content of the email.
[0314] Based on the evaluation results, the server uses a means to determine the action to take on emails. For example, emails deemed safe are delivered to the regular inbox, while emails identified as spam or phishing are moved to a quarantine folder. The server also sends an alert to the administrator if it detects a high-level threat.
[0315] As a concrete example, consider a scenario where a user opens their email client and receives a new email. This email is received by the server and its contents are analyzed. A security scan is then performed to check for any virus signatures. After evaluating the email's authenticity, it is determined to be spam. Finally, the server moves this email to a quarantine folder and does not display it in the inbox.
[0316] The system of the present invention allows users to receive secure emails that have been filtered with high accuracy, significantly improving their protection against malicious emails.
[0317] The following describes the processing flow.
[0318] Step 1:
[0319] The server receives a new email from the user's email client. The received email is first stored on the server, and a process begins to parse the header information and body.
[0320] Step 2:
[0321] The server analyzes the email header information. It extracts and logs the sender address, recipient address, subject, date, and sender IP address. It also verifies whether the email's sender domain is legitimate through authentication methods such as SPF, DKIM, and DMARC.
[0322] Step 3:
[0323] The server analyzes the email body. The analysis engine divides the email content into sections and extracts text information from each section. Links and attachments within the email are also identified and analyzed individually.
[0324] Step 4:
[0325] The server performs a security scan. It compares the analyzed email text, links, and attachments against a database of virus and malware signatures. It also uses machine learning models to detect phishing and spam patterns.
[0326] Step 5:
[0327] The server uses a natural language processing (NLP) engine to analyze the context of the email. This contextual analysis helps determine whether the email content is legitimate business communication or a phishing email.
[0328] Step 6:
[0329] The server evaluates the authenticity of emails based on the results of security scans and NLP analysis. It calculates security level and risk scores to determine the overall reliability of the email.
[0330] Step 7:
[0331] The server determines the action to take regarding the email. Based on the evaluation, it either delivers it to the inbox as a regular email or moves it to the quarantine folder as spam or phishing email. If necessary, it sends an alert to the administrator.
[0332] Step 8:
[0333] Users check their emails in their inbox or quarantine folder. They can open and review emails deemed safe. For emails moved to the quarantine folder, users can report them as spam or correct false positives.
[0334] Following these processing steps, the system of the present invention can achieve highly accurate email filtering and protect users from email-based threats.
[0335] (Example 1)
[0336] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server," and the smart glasses 214 will be referred to as the "terminal."
[0337] Traditional email systems often fail to adequately evaluate and filter incoming emails, resulting in malicious and spam emails remaining in users' inboxes. Furthermore, the lack of adequate mechanisms for quickly notifying administrators of advanced threats increases security risks for businesses and individuals. Therefore, there is a growing need for more accurate analysis and security scanning, along with reliability assessments, when receiving emails.
[0338] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.
[0339] In this invention, the server includes means for receiving emails, means for analyzing the content of emails, means for performing security scans based on the analyzed content, means for evaluating the authenticity of emails based on the results of security scans and additional analysis, means for determining actions to take regarding emails based on the evaluated results, and means for sending alerts to administrators when advanced threats are detected. This enables users to receive only safe emails, filters out malicious emails with high accuracy, quickly notifies administrators of advanced threats, and mitigates security risks.
[0340] "Means of receiving email" refers to the function by which a server retrieves email from a user's email client. This is done using communication protocols such as IMAP and POP3.
[0341] "Methods for analyzing email content" refer to the function of a server that analyzes the header information and body of received emails and extracts important data (sender, recipient, subject, body text, etc.). Software tools such as the Python email package are often used for this purpose.
[0342] "Means of performing security scans" refers to a function where the server performs security checks based on the content of analyzed emails, such as virus and malware signature checks and pattern recognition for phishing and spam emails. This may involve using tools like ClamAV or machine learning models.
[0343] "Methods for evaluating email authenticity" refers to a function that allows a server to assess the reliability of an incoming email and determine whether the email content is trustworthy, based on security scans and additional analysis results. This utilizes NLP technology and generative AI models.
[0344] "Means for determining email actions" refers to the function that allows the server to process emails appropriately (e.g., deliver to the inbox, move to the quarantine folder) based on the credibility assessment results.
[0345] "Method for sending alerts to administrators when advanced threats are detected" refers to a function that notifies administrators in real time when the server detects advanced security threats such as phishing or malware. This includes sending emails using the SMTP protocol, as well as notifications via the management dashboard.
[0346] Modes for carrying out the invention
[0347] The system according to the present invention has the function of automatically determining appropriate actions by analyzing emails received by users with high accuracy, performing security scans, and evaluating their authenticity. The main components of this system include a server, a terminal, and a user.
[0348] Hardware and software to be used
[0349] server:
[0350] The server uses IMAP or POP3 protocols to access the user's mailbox and retrieve emails.
[0351] The server uses Python's email package to parse the headers and body of received emails and extract important data, such as the sender, recipient, subject, and email body text.
[0352] The server uses ClamAV (open-source antivirus software) to compare incoming emails and attachments against virus and malware signatures.
[0353] The server uses machine learning models (e.g., TensorFlow or Scikit-learn) to identify patterns in phishing and spam emails.
[0354] The server uses a generative AI model (e.g., GPT-3) and leverages natural language processing techniques to evaluate the context and reliability of the email's content.
[0355] The server uses the SMTP protocol to send an alert to the administrator if an advanced threat is detected.
[0356] Terminal:
[0357] The user's device functions as a regular email client (e.g., Microsoft Outlook or Gmail), receiving and viewing emails after they have been analyzed and evaluated by the server.
[0358] System operation example
[0359] When a user receives a new email using Microsoft Outlook, the email is first sent to the server. The server then performs the following actions in sequence:
[0360] 1. Receiving emails: The server uses the IMAP protocol to access the user's Outlook account and retrieve new emails.
[0361] 2. Email parsing: The server uses the Python email package to parse the header information and body of the email, and extract the sender and subject.
[0362] 3. Security scan: The server runs ClamAV to check for viruses, and then uses a machine learning model to determine if it is phishing or spam.
[0363] 4. Credibility Assessment: The server uses a generated AI model (GPT-3) to evaluate the credibility of the email body using natural language processing technology.
[0364] 5. Decision on action: The server moves emails identified as spam to a quarantine folder and delivers safe emails to the inbox.
[0365] 6. Sending alerts to the administrator: The server uses the SMTP protocol to notify the administrator of any detected threats.
[0366] Example of a prompt
[0367] Please analyze the content of the following email and assess its credibility:
[0368] Sender: example@example.com
[0369] Subject: Important Notice
[0370] Body: This email is urgent. Click to see details.
[0371] This means users receive highly filtered and secure emails, and their protection from malicious emails is enhanced.
[0372] The flow of the specific processing in Example 1 will be explained using Figure 11.
[0373] Step 1:
[0374] Receiving emails
[0375] Input: The user sends an email, or the server retrieves new mail from the mail server using the IMAP / POP3 protocol.
[0376] Specific operation: The server uses the IMAP protocol to access the user's mailbox (e.g., Gmail, Outlook) and retrieve new emails.
[0377] Output: The retrieved email data is saved to the server.
[0378] Step 2:
[0379] Email analysis
[0380] Input: Email data obtained in Step 1.
[0381] Specific operation: The server uses the Python email package to parse email header information (sender, recipient, subject) and body text.
[0382] Data processing / data calculation: Analyze email headers and body text to extract important data.
[0383] Output: Analyzed email data (sender address, recipient address, subject, body text).
[0384] Step 3:
[0385] Run a security scan
[0386] Input: Email data analyzed in Step 2.
[0387] Specific operation: The server uses ClamAV to scan email bodies and attachments for virus and malware signatures. It also uses machine learning models (e.g., TensorFlow or Scikit-learn) to detect phishing and spam patterns.
[0388] Data processing / data calculation: Matching email content with virus and malware signatures, identifying phishing and spam patterns.
[0389] Output: Security scan results (presence or absence of security risks).
[0390] Step 4:
[0391] Email credibility assessment
[0392] Input: Security scan results obtained in Step 3 and email data analyzed in Step 2.
[0393] Specific operation: The server uses a generated AI model (e.g., GPT-3) and natural language processing techniques to determine the reliability of the email body.
[0394] Data processing / data calculation: Evaluating the reliability of the context and content of email bodies.
[0395] Output: Credibility assessment results (e.g., trustworthy, spam, phishing).
[0396] Step 5:
[0397] Email Action Decision
[0398] Input: The results of the credibility assessment obtained in Step 4.
[0399] Specific operation: Based on the credibility assessment results, the server decides whether to deliver the email to the inbox or move it to the quarantine folder.
[0400] Data processing / data calculation: Email sorting based on evaluation results.
[0401] Output: Sorted emails (Inbox, Quarantine folder).
[0402] Step 6:
[0403] Sending alerts to administrators
[0404] Input: Security risks and threats detected in Steps 3 and 4.
[0405] Specific operation: The server uses the SMTP protocol to notify administrators of security threats, including real-time notifications to the management dashboard.
[0406] Data processing / data computation: Generating threat intelligence and calling notification protocols.
[0407] Output: Alert notifications sent to the administrator (email, dashboard notification).
[0408] (Application Example 1)
[0409] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server," and the smart glasses 214 will be referred to as the "terminal."
[0410] In modern email communication, users are frequently exposed to threats such as spam, phishing, and virus emails, making it difficult to provide a secure email environment. Furthermore, traditional email filtering systems lack sufficient accuracy, leading to frequent false positives and missed detections. Additionally, notifications to users and administrators may be delayed when email threats occur. There is a need to solve these problems and provide highly accurate and rapid email security measures.
[0411] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.
[0412] In this invention, the server includes means for receiving emails, means for analyzing the content of emails, means for performing security scans based on the analyzed content, means for evaluating the authenticity of emails based on the results of security scans, means for determining actions to take regarding emails based on the evaluation results, means for detecting phishing and spam patterns using machine learning models, and means for sending real-time notifications to users based on the evaluation results. As a result, users receive only safe emails that have been filtered with high accuracy, improving their defense against malicious emails and enabling quick responses.
[0413] "Means of receiving email" refers to the functions and mechanisms for obtaining email from an external mail server.
[0414] "Methods for analyzing email content" refer to technologies for analyzing the header information and body of received emails and extracting the data contained therein.
[0415] "Means of performing security scans" refers to functions that, based on the content of analyzed emails, check for matches with virus and malware signatures, and detect phishing and spam patterns.
[0416] "Methods for evaluating the authenticity of emails" refer to functions that determine whether an email is legitimate, phishing, or spam, based on the results of security scans.
[0417] "Means for determining email actions" refers to the function that determines, based on evaluation results, whether to deliver the email to the inbox, move it to a quarantine folder, or take other actions.
[0418] "Methods for detecting phishing and spam patterns using machine learning models" refers to technologies that use machine learning algorithms to detect phishing and spam characteristics in received emails and assess their risk.
[0419] "Means of sending real-time notifications to users based on the evaluation results" refers to a function or system that immediately issues a warning to users or administrators if the evaluation results of an email are determined to contain malicious content.
[0420] This invention relates to a system that analyzes emails received by users with high accuracy, performs security scans, and evaluates their authenticity. The following describes how to implement this system.
[0421] First, the server has the means to receive email. Specifically, the server has the function to retrieve email from an external mail server and convert its contents into a format that can be processed. This email is received through the email client that the user normally uses, but it is processed by the server first.
[0422] Next, the server is equipped with a means to analyze the content of emails. It analyzes the header information and body of received emails and extracts important data. Software such as Python's email library is used for this analysis. The analyzed data includes information such as the sender, recipient, subject, and body of the email.
[0423] Next, the server has the means to perform a security scan based on the content of the analyzed email. This security scan includes the ability to check for matches with virus and malware signatures. Antivirus software and machine learning models are used for the security scan.
[0424] Furthermore, the server has a means to detect phishing and spam patterns using machine learning models. This means that it can determine with high accuracy whether an received email is phishing or spam. Specifically, machine learning models using libraries such as Python's scikit-learn are used.
[0425] Furthermore, the server has a means to evaluate the authenticity of emails based on the results of security scans and evaluations of machine learning models. This means determines whether an email is legitimate or fraudulent.
[0426] Finally, the server has a mechanism to determine the action to take on an email based on the evaluation results. This mechanism ensures that emails deemed safe are delivered to the regular inbox, while emails identified as spam or phishing are moved to a quarantine folder. It also includes a mechanism to send real-time notifications to the user based on the evaluation results.
[0427] As a concrete example, consider a scenario where a user opens their email client and receives a new email. The server receives this email and analyzes its contents. It then performs a security scan to check for any matches with virus signatures. Next, it uses a machine learning model to detect phishing and spam patterns. Based on the evaluation results, spam emails are moved to a quarantine folder, and users receive real-time notifications for important threats.
[0428] Example of a prompt:
[0429] "Please introduce our ultra-high-performance email security scanning system. This system analyzes email headers and body text, enabling highly accurate detection of viruses, malware, phishing, and spam. It also uses natural language processing technology to evaluate email context and content, determining appropriate actions. Using this system ensures only safe emails appear in the user's inbox, significantly improving protection against malicious emails."
[0430] The above is a detailed explanation for carrying out the present invention.
[0431] The flow of a specific process in Application Example 1 will be explained using Figure 12.
[0432] Step 1:
[0433] The server receives new emails sent from the user's email client. The input is the entire incoming email, and its contents are passed directly to the next step. Specifically, the server connects to the mail server via the POP3 or IMAP protocol and retrieves unread emails.
[0434] Step 2:
[0435] The server parses the header information and body of received emails. The input is the entire received email, and the output is the parsed data. This parsing uses the Python email library to extract the sender, recipient, subject, and body of the email.
[0436] Step 3:
[0437] The server performs a security scan based on the content of the analyzed email. The input is the analyzed email data, and the output is the security scan results. Specifically, it uses antivirus software to compare the data against virus and malware signatures and check for matches.
[0438] Step 4:
[0439] The server uses a machine learning model to detect phishing and spam patterns. The input is analyzed email data, and the output is the evaluation result for phishing and spam. Specifically, the scikit-learn library in Python is used to evaluate the features of emails with a pre-trained machine learning model.
[0440] Step 5:
[0441] The server evaluates the authenticity of emails based on security scan results and machine learning model evaluations. The inputs are scan results and machine learning evaluation results, and the output is the email authenticity rating. Specifically, these evaluations are integrated, and a scoring system determines whether the email is legitimate.
[0442] Step 6:
[0443] The server determines the action to take on an email based on the credibility assessment result. The input is the credibility assessment result, and the output is the email sorting action. Specifically, emails deemed safe are delivered to the regular inbox, while emails identified as spam or phishing are moved to a quarantine folder.
[0444] Step 7:
[0445] The server sends real-time notifications to users based on the evaluation results. The input is the evaluation result, and the output is the notification message. Specifically, if a serious threat is detected, the server sends a warning to the user and administrator via push notification or email.
[0446] This process ensures that users receive only highly filtered and secure emails, significantly improving their protection against malicious emails.
[0447] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.
[0448] The system according to the present invention analyzes emails received by users with high accuracy, performs security scans, evaluates their authenticity, and, by incorporating an emotion engine, recognizes the user's emotions to complement email evaluation. This system consists of several main means.
[0449] First, the server receives a new email from the user's email client. The received email is initially stored on the server, and a process begins to analyze the header information and body. The server analyzes the email header information, extracting the sender address, recipient address, subject, date, etc., and recording them in a log. In addition, during the analysis of the email body, links and attachments are identified and analyzed individually.
[0450] Next, the server performs a security scan. It compares the analyzed email text, links, and attachments against a database of virus and malware signatures. Machine learning models are also used to detect phishing and spam patterns. Furthermore, a natural language processing (NLP) engine is used to analyze the context of the email and assess whether it is legitimate business communication.
[0451] Furthermore, a key feature of this invention is the inclusion of an emotion engine. The server operates the emotion engine based on the email body and contextual information to recognize the emotions a user felt when reading the email. Specifically, it classifies emotions as positive, negative, or neutral based on specific keywords and contextual patterns within the email. This emotion classification result is then integrated with the security scan results to complement the final credibility assessment.
[0452] Based on the evaluation results, the server decides what action to take with the email. For example, emails deemed safe are delivered to the regular inbox, while emails identified as spam or phishing are moved to a quarantine folder. If the user's sentiment is perceived as negative, a more detailed analysis is performed, and an alert is sent to the administrator if necessary.
[0453] As a concrete example, consider a scenario where a user opens an email client and receives a new email. The email is received by the server, and its header information and body are analyzed. Then, a security scan is performed, and a virus check is conducted. The sentiment engine analyzes the context of the email and determines that the user may experience negative emotions upon reading it. As a result, the email undergoes further detailed analysis and is ultimately moved to the quarantine folder. The user cannot view this email in their inbox; they can review its contents in the quarantine folder and take appropriate action (e.g., report it as spam or correct a false positive).
[0454] The system of this invention allows users to receive secure emails that have been filtered with high accuracy, and furthermore, by using an emotion engine, it is possible to reduce the emotional stress caused by reading emails. As a result, a safer and more comfortable email environment is provided for users.
[0455] The following describes the processing flow.
[0456] Step 1:
[0457] The server receives a new email from the email client. The received email is first stored on the server in preparation for the next analysis step.
[0458] Step 2:
[0459] The server analyzes the email header information. It extracts the sender address, recipient address, subject, date, sender IP address, etc., and records them in a log. It also performs authentication checks such as SPF, DKIM, and DMARC.
[0460] Step 3:
[0461] The server analyzes the email body. It breaks down the text portion of the email, identifies the main sections, and extracts the text information from each section. It also identifies links and attachments and analyzes them individually.
[0462] Step 4:
[0463] The server performs a security scan. It compares the analyzed email text, links, and attachments against a database of virus and malware signatures. Furthermore, it uses machine learning models to detect phishing and spam patterns.
[0464] Step 5:
[0465] The server uses a natural language processing (NLP) engine to analyze the context of the email. This contextual analysis helps determine whether the email content is legitimate business communication or a scam or spam email.
[0466] Step 6:
[0467] The server uses an emotion engine to recognize the user's emotions based on the content of the email. For example, it can determine, based on specific keywords and context, whether the email is likely to evoke positive, negative, or neutral emotions.
[0468] Step 7:
[0469] The server evaluates the authenticity of emails based on security scans, NLP analysis, and sentiment engine results. This allows it to calculate an overall security level and risk score, determining the reliability of the email.
[0470] Step 8:
[0471] The server determines the action to take on an email. For example, emails deemed safe are delivered to the inbox, while emails identified as spam or phishing are moved to a quarantine folder. If the user's sentiment is perceived as negative, further detailed analysis is performed, and an alert is sent to the administrator if necessary.
[0472] Step 9:
[0473] Users check their emails in their inbox or quarantine folder. They can open and review emails deemed safe. For emails moved to the quarantine folder, users can report them as spam or correct false positives.
[0474] In this way, the server performs a series of processes, allowing users to receive highly accurate, filtered, and secure emails. Furthermore, the introduction of an emotion engine reduces the emotional stress associated with reading emails, providing a more comfortable email environment.
[0475] (Example 2)
[0476] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server" and the smart glasses 214 will be referred to as the "terminal".
[0477] Traditional email systems perform security scans on emails, but lack the complementary evaluation of email content through sentiment analysis. This makes it difficult to reliably detect emails that evoke negative emotions in users or are malicious. In particular, malicious activities such as phishing and spam emails have become more sophisticated, and simple virus checks and signature matching are no longer sufficient countermeasures. Furthermore, the risk of users experiencing psychological stress due to the content of emails they receive is also increasing. Therefore, there is a need for a system that simultaneously reduces both email security and user emotional stress.
[0478] The identification processing performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means. In this invention, the server includes means for receiving emails, means for analyzing the content of the emails, means for performing a security scan based on the analyzed content, means for evaluating the authenticity of the emails based on the results of the security scans, and means for recognizing the sentiment of the emails using a sentiment analysis engine and supplementing the authenticity evaluation. As a result, emails received by the user are filtered with high accuracy, and emails that pose a risk of causing negative emotions are detected through sentiment analysis, making it possible to provide a safer and more comfortable email environment for the user.
[0479] "Means of receiving emails" refers to the function of retrieving new emails from the user's email client and saving them on the server.
[0480] "Means for analyzing the contents of the email" refers to a system that examines the header information and body of a received email and extracts the sender's address, recipient's address, subject, date, links, attachments, etc.
[0481] "Means for performing a security scan based on the analyzed content" refers to a system that uses the analysis results to examine emails against signatures of viruses and malicious programs, and has the function of detecting malicious activity.
[0482] "Means for evaluating the authenticity of an email based on the results of the security scan" refers to a mechanism that determines and evaluates the legitimacy and potential risks of an email through the results of a security scan.
[0483] "Means for determining email action based on the evaluated results" refers to a system that determines specific actions, such as whether to deliver the email to the inbox or move it to a quarantine folder, based on the credibility assessment.
[0484] "A means of recognizing the emotions in emails using an emotion analysis engine to complement credibility evaluation" refers to a system that analyzes the content of an email, classifies the positive, negative, or neutral emotions that a user might feel upon reading it, and then uses the results to further enhance the credibility evaluation of the email.
[0485] Modes for carrying out the invention
[0486] The system according to the present invention analyzes emails received by users with high accuracy, performs security scans, evaluates their credibility, and, by incorporating an emotion engine, recognizes the user's emotions to complement email evaluation. This system consists of several main means.
[0487] First, the server receives new emails from the user's email client. The received emails are initially stored on the server, and a process begins to parse the header information and body. Specifically, the server runs on high-performance hardware (e.g., an AWS EC2 instance) and uses email server software (e.g., Postfix) to receive and store emails. Next, the server uses a Python script and the email package to parse and log the email header information (sender address, recipient address, subject, date, etc.). It also uses BeautifulSoup to parse the HTML body, identify links and attachments, and analyze this information individually.
[0488] Next, the server performs a security scan. This scan first uses ClamAV to compare the email text, links, and attachments against a signature database of viruses and malicious programs. Furthermore, a pre-trained machine learning model (e.g., TensorFlow) is used to detect phishing and spam patterns. The TensorFlow model extracts and evaluates phishing and spam features from the email body text.
[0489] Subsequently, the server uses a natural language processing engine (e.g., Google's BERT) to analyze the context of the email and evaluate whether it is legitimate business communication. Furthermore, a distinctive feature of this invention is the inclusion of an emotion engine. Based on the email body and contextual information, the server operates an emotion engine (e.g., IBM Watson Tone Analyzer) to recognize the emotions the user felt when reading the email. Specifically, it classifies emotions as positive, negative, or neutral based on specific keywords and contextual patterns within the email. This emotion classification result is then integrated with the security scan results to complement the final credibility assessment.
[0490] Based on the evaluation results, the server decides what action to take with the email. For example, emails deemed safe are delivered to the regular inbox, while emails identified as spam or malicious are moved to a quarantine folder. If the user's sentiment is perceived as negative, a more detailed analysis is performed, and an alert is sent to the administrator if necessary.
[0491] As a concrete example, consider a scenario where a user opens an email client (e.g., Microsoft Outlook) and receives a new email. The email is received by the server, and its header information and body are analyzed. Then, a security scan is performed, and a virus check is conducted. Furthermore, the sentiment engine analyzes the context of the email and determines that the user may experience negative emotions upon reading it. As a result, the email undergoes further detailed analysis and is ultimately moved to a quarantine folder. The user cannot view this email in their inbox; they can review its contents in the quarantine folder and take appropriate action (such as reporting it as spam or correcting a false positive).
[0492] An example of a prompt message is as follows:
[0493] When a user opens their email client and receives a new email, the server receives and stores the email. The server uses a Python script to parse the header and body information and extract the necessary information. Next, it performs a virus scan with ClamAV and detects spam and phishing with a TensorFlow model. Finally, it uses the IBM Watson API to perform sentiment analysis and report a final rating. Please describe the specific steps of these processes.
[0494] The flow of the specific processing in Example 2 will be explained using Figure 13.
[0495] Detailed explanation of the program's processing steps
[0496] Step 1:
[0497] incoming mail
[0498] Input: New email from the user's email client
[0499] Processing: The server receives emails via port 25 and temporarily stores them in a temporary directory.
[0500] Output: Mail files stored on the server
[0501] Specific operation: The server uses mail server software to execute the receiving process. The server listens on a specific port, and when it receives new mail, it writes it to a temporary directory.
[0502] Step 2:
[0503] Email analysis
[0504] Input: Mail files saved in a temporary directory
[0505] Processing: The server analyzes the email header information and body, extracting sender address, recipient address, subject, date, links, attachments, etc.
[0506] Output: Analyzed header information and body content
[0507] Specific operation: The server executes a Python script and parses header information using the email package. It uses BeautifulSoup to identify links and attachments from the HTML body. The extracted information is recorded in a database and log files.
[0508] Step 3:
[0509] Security scan
[0510] Input: Parsed header information and body content
[0511] Processing: The server performs virus scanning and spam / phishing detection using machine learning models.
[0512] Output: Security scan evaluation results
[0513] Specific operation: The server uses ClamAV to scan attachments and the email body for viruses. It also runs a TensorFlow machine learning model to analyze the email body and determine if it is phishing or spam.
[0514] Step 4:
[0515] Emotion analysis
[0516] Input: Analyzed email body
[0517] Processing: The server activates an emotion engine to classify the email content into positive, negative, or neutral emotions.
[0518] Output: Results of sentiment analysis
[0519] Specific operation: The server sends the email body to the IBM Watson Tone Analyzer API and retrieves the returned sentiment classification result. The result is classified as either positive, negative, or neutral.
[0520] Step 5:
[0521] Credibility assessment and final action decision
[0522] Input: Security scan evaluation results and sentiment analysis results
[0523] Processing: The server integrates these results, evaluates the authenticity of the email, and determines the appropriate action.
[0524] Output: Determination of the email delivery destination (inbox or quarantine folder)
[0525] Specific operation: The server runs a credibility assessment algorithm and calculates a final score. Based on the score, if the email is deemed safe, it is delivered to the inbox; if deemed dangerous, it is moved to a quarantine folder. In addition, if negative sentiment is detected, a detailed analysis is performed and an alert is sent to the administrator if necessary.
[0526] (Application Example 2)
[0527] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server," and the smart glasses 214 will be referred to as the "terminal."
[0528] Traditional email systems prioritize security to protect users from viruses, malware, phishing, and spam. However, this alone lacks consideration for the emotional stress and negative feelings users experience, meaning certain emails can cause significant emotional distress. Therefore, a system is needed that integrates security scanning with sentiment analysis, considering the impact on users' emotions along with evaluating the reliability of emails.
[0529] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means. In this invention, the server includes means for receiving emails, means for analyzing the content of the emails, means for performing a security scan based on the analyzed content, an emotion engine having the function of recognizing and classifying emotions based on the content and contextual information of the emails, and means for determining the final email action, including an evaluation of the emotion engine. This makes it possible to detect viruses and malware, quarantine spam emails, and reduce the emotional stress on the user.
[0530] "Means of receiving email" refers to the function that allows a server to retrieve emails from a user's email client.
[0531] "Means for analyzing the contents of the email" refers to the process of analyzing the header information, body, links, and attachments of a received email and extracting data for security and sentiment evaluation.
[0532] "Means for performing a security scan based on the analyzed content" refers to a function that compares the analyzed email content with a virus and malware signature database to detect phishing and spam patterns.
[0533] "Means for evaluating the authenticity of an email based on the results of the security scan" refers to algorithms or machine learning models used to evaluate whether an email is trustworthy based on the results of the security scan.
[0534] A "sentiment engine that recognizes and classifies emotions based on email content and contextual information" is a system that analyzes specific keywords and contextual patterns within an email body and classifies the emotions (positive, negative, or neutral) a user feels when reading the email.
[0535] "Means for determining the final email action, including the evaluation of the sentiment engine" refers to logic that integrates the results of security scans and sentiment evaluations to determine the final action, such as sending or quarantining the email.
[0536] The system for realizing this invention provides a function that, upon receiving an email from a user, analyzes the email with high accuracy and evaluates its reliability and emotional impact using a security scan and sentiment engine. Specifically, the following processes take place between the server, terminal, and user.
[0537] The system first has the function of receiving new emails from the user's email client. The received emails are stored on the server, and then a process of analyzing the email header information and body begins. The header information extracted includes the sender address, recipient address, subject, and date, and these are recorded in the log. In the body analysis, links and attachments are also identified and analyzed separately.
[0538] Next, the server performs a security scan. This process compares the analyzed email text, links, and attachments against a database of virus and malware signatures. Machine learning models are also used to detect phishing and spam patterns. Furthermore, a natural language processing (NLP) engine is used to analyze the context of the email and assess whether it is legitimate business communication.
[0539] In addition, the system's signature emotion engine is activated. Based on the email body and contextual information, the emotion engine identifies specific keywords and patterns and classifies them as positive, negative, or neutral. This emotion classification result is integrated with the results of the aforementioned security scan and complements the final email authenticity assessment.
[0540] Based on the credibility assessment, the server decides what to do with the email. For example, emails deemed safe by the security check are delivered to the regular inbox, while emails suspected of being spam or phishing, or those classified as potentially causing negative emotions, are moved to a quarantine folder. In cases of high importance, an alert may also be sent to the administrator.
[0541] To perform these processes, the server implements machine learning models using libraries such as Python and TensorFlow, a natural language processing engine, and spam / phishing detection algorithms. User information, email data, and analysis results are stored in the database.
[0542] Specific example
[0543] When a user receives a new email on their smartphone, it is sent to the server where its header information and body are analyzed. A security scan is then performed to check for viruses. The sentiment engine analyzes the email's context, and if it determines that the email may evoke negative emotions, it is moved to a quarantine folder. The user receives a warning notification at this time.
[0544] Example of a prompt
[0545] "Implement a system that performs security and sentiment analysis on newly received emails and takes appropriate actions to help users maintain positive emotions."
[0546] This system allows users to enjoy a safe and comfortable email environment that is free from spam and phishing emails, and also takes emotional impact into consideration.
[0547] The flow of a specific process in Application Example 2 will be explained using Figure 14.
[0548] Step 1:
[0549] The server receives a new email from the user's email client. At this point, the input data is the raw data of the received email. The server retrieves this data and stores it as an email object.
[0550] Step 2:
[0551] The server analyzes the header information and body of received emails. The header information analysis extracts the sender address, recipient address, subject, date, etc. The input data requires an email object, and the output is the analyzed header information. Specifically, this information is extracted and logged using the Python email library.
[0552] Step 3:
[0553] The server parses the email body to identify links and attachments. The input is the email object and its body text, and the output is a list of identified links and attachments. This is accomplished using Python's regular expressions and URL parsing libraries.
[0554] Step 4:
[0555] The server performs a security scan. At this stage, the email body, links, and attachments are compared against a database of virus and malware signatures. The input data consists of each part of the email being analyzed, and the output is the scan result (e.g., safe, virus detected, suspected phishing, etc.). This process is performed using ClamAV or the VirusTotal API.
[0556] Step 5:
[0557] The server uses machine learning models to detect phishing and spam patterns. The input is email text data, and the output is a spam score and a phishing score. This is done using models from Scikit-learn or TensorFlow.
[0558] Step 6:
[0559] The server uses a natural language processing (NLP) engine to analyze the context of emails. The input data is the email body, and the output is an evaluation result of whether the email is legitimate business communication. Context analysis is performed using Python's nltk and spaCy libraries.
[0560] Step 7:
[0561] The server operates an emotion engine that recognizes and classifies emotions based on the email body and context. The input data is the email body and contextual information, and the output is the emotion classification result (positive, negative, or neutral). This is done using a pre-trained TensorFlow model.
[0562] Step 8:
[0563] The server integrates the results of security scans and the sentiment engine to evaluate the final authenticity of the email. The input data consists of the results of each scan and sentiment classification, and the output is the overall evaluation result. Based on this, the processing action for the email (for example, safe emails go to the inbox, suspicious emails go to the quarantine folder) is determined.
[0564] Step 9:
[0565] The server performs email actions based on the evaluation results. The input data is the final overall evaluation result, and the output is the sorting of emails into the user's inbox or quarantine folder. Specifically, emails deemed safe are delivered to the regular inbox, while emails identified as spam or phishing are moved to the quarantine folder.
[0566] This series of processes will allow users to enjoy a safe and emotionally sensitive email environment.
[0567] The specific processing unit 290 transmits the result of the specific processing to the smart glasses 214. In the smart glasses 214, the control unit 46A causes the speaker 240 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.
[0568] Data generation model 58 is a type of so-called generative AI (Artificial Intelligence). One example of data generation model 58 is ChatGPT (Internet search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[0569] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and the specific processing may also be performed by the smart glasses 214.
[0570] [Third Embodiment]
[0571] Figure 5 shows an example of the configuration of the data processing system 310 according to the third embodiment.
[0572] As shown in Figure 5, the data processing system 310 includes a data processing device 12 and a headset terminal 314. An example of the data processing device 12 is a server.
[0573] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0574] The headset terminal 314 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication interface 44, and a display 343. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, camera 42, and display 343 are also connected to the bus 52.
[0575] The microphone 238 receives voice signals from the user 20 and receives instructions from the user 20. The microphone 238 captures the voice signals from the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.
[0576] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the area around the user 20 (for example, an imaging range defined by a field of view equivalent to the width of a typical healthy person's field of vision).
[0577] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.
[0578] Figure 6 shows an example of the main functions of the data processing device 12 and the headset terminal 314. As shown in Figure 6, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.
[0579] The specific processing program 56 is an example of a "program" relating to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[0580] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[0581] In the headset terminal 314, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.
[0582] Next, the specific processing performed by the specific processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the headset terminal 314 will be referred to as the "terminal".
[0583] The system according to the present invention has the function of automatically determining appropriate actions by analyzing emails received by the user with high accuracy, performing security scans, and evaluating their authenticity. This system consists of several main means.
[0584] First, the server has a means of receiving email. Users receive emails through a regular email client, but the received email is first sent to the server. Here, the server retrieves the email header information and body and converts it into a parseable format. Through this analysis, the server extracts important data such as the sender, recipient, subject, and body of the email.
[0585] Next, the server is equipped with means to analyze the content of emails. It analyzes the header information and body of received emails to perform tasks such as verifying the validity of the sender domain and detecting anomalies in the message content. This allows for a basic check of whether the email content is appropriate.
[0586] Next, the server has the means to perform security scans. Here, security checks are performed based on the content of the analyzed emails. This check includes verifying matches with virus and malware signatures. Machine learning models are also used to detect phishing and spam patterns.
[0587] The server then uses methods to evaluate the authenticity of the email. Based on the results of security scans and other analyses, it determines whether the email is legitimate or a phishing or spam email. At this point, a more advanced analysis engine may use natural language processing (NLP) techniques to evaluate the context and content of the email.
[0588] Based on the evaluation results, the server uses a means to determine the action to take on emails. For example, emails deemed safe are delivered to the regular inbox, while emails identified as spam or phishing are moved to a quarantine folder. The server also sends an alert to the administrator if it detects a high-level threat.
[0589] As a concrete example, consider a scenario where a user opens their email client and receives a new email. This email is received by the server and its contents are analyzed. A security scan is then performed to check for any virus signatures. After evaluating the email's authenticity, it is determined to be spam. Finally, the server moves this email to a quarantine folder and does not display it in the inbox.
[0590] The system of the present invention allows users to receive secure emails that have been filtered with high accuracy, significantly improving their protection against malicious emails.
[0591] The following describes the processing flow.
[0592] Step 1:
[0593] The server receives a new email from the user's email client. The received email is first stored on the server, and a process begins to parse the header information and body.
[0594] Step 2:
[0595] The server analyzes the email header information. It extracts and logs the sender address, recipient address, subject, date, and sender IP address. It also verifies whether the email's sender domain is legitimate through authentication methods such as SPF, DKIM, and DMARC.
[0596] Step 3:
[0597] The server analyzes the email body. The analysis engine divides the email content into sections and extracts text information from each section. Links and attachments within the email are also identified and analyzed individually.
[0598] Step 4:
[0599] The server performs a security scan. It compares the analyzed email text, links, and attachments against a database of virus and malware signatures. It also uses machine learning models to detect phishing and spam patterns.
[0600] Step 5:
[0601] The server uses a natural language processing (NLP) engine to analyze the context of the email. This contextual analysis helps determine whether the email content is legitimate business communication or a phishing email.
[0602] Step 6:
[0603] The server evaluates the authenticity of emails based on the results of security scans and NLP analysis. It calculates security level and risk scores to determine the overall reliability of the email.
[0604] Step 7:
[0605] The server determines the action to take regarding the email. Based on the evaluation, it either delivers it to the inbox as a regular email or moves it to the quarantine folder as spam or phishing email. If necessary, it sends an alert to the administrator.
[0606] Step 8:
[0607] Users check their emails in their inbox or quarantine folder. They can open and review emails deemed safe. For emails moved to the quarantine folder, users can report them as spam or correct false positives.
[0608] Following these processing steps, the system of the present invention can achieve highly accurate email filtering and protect users from email-based threats.
[0609] (Example 1)
[0610] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."
[0611] Traditional email systems often fail to adequately evaluate and filter incoming emails, resulting in malicious and spam emails remaining in users' inboxes. Furthermore, the lack of adequate mechanisms for quickly notifying administrators of advanced threats increases security risks for businesses and individuals. Therefore, there is a growing need for more accurate analysis and security scanning, along with reliability assessments, when receiving emails.
[0612] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.
[0613] In this invention, the server includes means for receiving emails, means for analyzing the content of emails, means for performing security scans based on the analyzed content, means for evaluating the authenticity of emails based on the results of security scans and additional analysis, means for determining actions to take regarding emails based on the evaluated results, and means for sending alerts to administrators when advanced threats are detected. This enables users to receive only safe emails, filters out malicious emails with high accuracy, quickly notifies administrators of advanced threats, and mitigates security risks.
[0614] "Means of receiving email" refers to the function by which a server retrieves email from a user's email client. This is done using communication protocols such as IMAP and POP3.
[0615] "Methods for analyzing email content" refer to the function of a server that analyzes the header information and body of received emails and extracts important data (sender, recipient, subject, body text, etc.). Software tools such as the Python email package are often used for this purpose.
[0616] "Means of performing security scans" refers to a function where the server performs security checks based on the content of analyzed emails, such as virus and malware signature checks and pattern recognition for phishing and spam emails. This may involve using tools like ClamAV or machine learning models.
[0617] "Methods for evaluating email authenticity" refers to a function that allows a server to assess the reliability of an incoming email and determine whether the email content is trustworthy, based on security scans and additional analysis results. This utilizes NLP technology and generative AI models.
[0618] "Means for determining email actions" refers to the function that allows the server to process emails appropriately (e.g., deliver to the inbox, move to the quarantine folder) based on the credibility assessment results.
[0619] "Method for sending alerts to administrators when advanced threats are detected" refers to a function that notifies administrators in real time when the server detects advanced security threats such as phishing or malware. This includes sending emails using the SMTP protocol, as well as notifications via the management dashboard.
[0620] Modes for carrying out the invention
[0621] The system according to the present invention has the function of automatically determining appropriate actions by analyzing emails received by users with high accuracy, performing security scans, and evaluating their authenticity. The main components of this system include a server, a terminal, and a user.
[0622] Hardware and software to be used
[0623] server:
[0624] The server uses IMAP or POP3 protocols to access the user's mailbox and retrieve emails.
[0625] The server uses Python's email package to parse the headers and body of received emails and extract important data, such as the sender, recipient, subject, and email body text.
[0626] The server uses ClamAV (open-source antivirus software) to compare incoming emails and attachments against virus and malware signatures.
[0627] The server uses machine learning models (e.g., TensorFlow or Scikit-learn) to identify patterns in phishing and spam emails.
[0628] The server uses a generative AI model (e.g., GPT-3) and leverages natural language processing techniques to evaluate the context and reliability of the email's content.
[0629] The server uses the SMTP protocol to send an alert to the administrator if an advanced threat is detected.
[0630] Terminal:
[0631] The user's device functions as a regular email client (e.g., Microsoft Outlook or Gmail), receiving and viewing emails after they have been analyzed and evaluated by the server.
[0632] System operation example
[0633] When a user receives a new email using Microsoft Outlook, the email is first sent to the server. The server then performs the following actions in sequence:
[0634] 1. Receiving emails: The server uses the IMAP protocol to access the user's Outlook account and retrieve new emails.
[0635] 2. Email parsing: The server uses the Python email package to parse the header information and body of the email, and extract the sender and subject.
[0636] 3. Security scan: The server runs ClamAV to check for viruses, and then uses a machine learning model to determine if it is phishing or spam.
[0637] 4. Credibility Assessment: The server uses a generated AI model (GPT-3) to evaluate the credibility of the email body using natural language processing technology.
[0638] 5. Decision on action: The server moves emails identified as spam to a quarantine folder and delivers safe emails to the inbox.
[0639] 6. Sending alerts to the administrator: The server uses the SMTP protocol to notify the administrator of any detected threats.
[0640] Example of a prompt
[0641] Please analyze the content of the following email and assess its credibility:
[0642] Sender: example@example.com
[0643] Subject: Important Notice
[0644] Body: This email is urgent. Click to see details.
[0645] This means users receive highly filtered and secure emails, and their protection from malicious emails is enhanced.
[0646] The flow of the specific processing in Example 1 will be explained using Figure 11.
[0647] Step 1:
[0648] Receiving emails
[0649] Input: The user sends an email, or the server retrieves new mail from the mail server using the IMAP / POP3 protocol.
[0650] Specific operation: The server uses the IMAP protocol to access the user's mailbox (e.g., Gmail, Outlook) and retrieve new emails.
[0651] Output: The retrieved email data is saved to the server.
[0652] Step 2:
[0653] Email analysis
[0654] Input: Email data obtained in Step 1.
[0655] Specific operation: The server uses the Python email package to parse email header information (sender, recipient, subject) and body text.
[0656] Data processing / data calculation: Analyze email headers and body text to extract important data.
[0657] Output: Analyzed email data (sender address, recipient address, subject, body text).
[0658] Step 3:
[0659] Run a security scan
[0660] Input: Email data analyzed in Step 2.
[0661] Specific operation: The server uses ClamAV to scan email bodies and attachments for virus and malware signatures. It also uses machine learning models (e.g., TensorFlow or Scikit-learn) to detect phishing and spam patterns.
[0662] Data processing / data calculation: Matching email content with virus and malware signatures, identifying phishing and spam patterns.
[0663] Output: Security scan results (presence or absence of security risks).
[0664] Step 4:
[0665] Email credibility assessment
[0666] Input: Security scan results obtained in Step 3 and email data analyzed in Step 2.
[0667] Specific operation: The server uses a generated AI model (e.g., GPT-3) and natural language processing techniques to determine the reliability of the email body.
[0668] Data processing / data calculation: Evaluating the reliability of the context and content of email bodies.
[0669] Output: Credibility assessment results (e.g., trustworthy, spam, phishing).
[0670] Step 5:
[0671] Email Action Decision
[0672] Input: The results of the credibility assessment obtained in Step 4.
[0673] Specific operation: Based on the credibility assessment results, the server decides whether to deliver the email to the inbox or move it to the quarantine folder.
[0674] Data processing / data calculation: Email sorting based on evaluation results.
[0675] Output: Sorted emails (Inbox, Quarantine folder).
[0676] Step 6:
[0677] Sending alerts to administrators
[0678] Input: Security risks and threats detected in Steps 3 and 4.
[0679] Specific operation: The server uses the SMTP protocol to notify administrators of security threats, including real-time notifications to the management dashboard.
[0680] Data processing / data computation: Generating threat intelligence and calling notification protocols.
[0681] Output: Alert notifications sent to the administrator (email, dashboard notification).
[0682] (Application Example 1)
[0683] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."
[0684] In modern email communication, users are frequently exposed to threats such as spam, phishing, and virus emails, making it difficult to provide a secure email environment. Furthermore, traditional email filtering systems lack sufficient accuracy, leading to frequent false positives and missed detections. Additionally, notifications to users and administrators may be delayed when email threats occur. There is a need to solve these problems and provide highly accurate and rapid email security measures.
[0685] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.
[0686] In this invention, the server includes means for receiving emails, means for analyzing the content of emails, means for performing security scans based on the analyzed content, means for evaluating the authenticity of emails based on the results of security scans, means for determining actions to take regarding emails based on the evaluation results, means for detecting phishing and spam patterns using machine learning models, and means for sending real-time notifications to users based on the evaluation results. As a result, users receive only safe emails that have been filtered with high accuracy, improving their defense against malicious emails and enabling quick responses.
[0687] "Means of receiving email" refers to the functions and mechanisms for obtaining email from an external mail server.
[0688] "Methods for analyzing email content" refer to technologies for analyzing the header information and body of received emails and extracting the data contained therein.
[0689] "Means of performing security scans" refers to functions that, based on the content of analyzed emails, check for matches with virus and malware signatures, and detect phishing and spam patterns.
[0690] "Methods for evaluating the authenticity of emails" refer to functions that determine whether an email is legitimate, phishing, or spam, based on the results of security scans.
[0691] "Means for determining email actions" refers to the function that determines, based on evaluation results, whether to deliver the email to the inbox, move it to a quarantine folder, or take other actions.
[0692] "Methods for detecting phishing and spam patterns using machine learning models" refers to technologies that use machine learning algorithms to detect phishing and spam characteristics in received emails and assess their risk.
[0693] "Means of sending real-time notifications to users based on the evaluation results" refers to a function or system that immediately issues a warning to users or administrators if the evaluation results of an email are determined to contain malicious content.
[0694] This invention relates to a system that analyzes emails received by users with high accuracy, performs security scans, and evaluates their authenticity. The following describes how to implement this system.
[0695] First, the server has the means to receive email. Specifically, the server has the function to retrieve email from an external mail server and convert its contents into a format that can be processed. This email is received through the email client that the user normally uses, but it is processed by the server first.
[0696] Next, the server is equipped with a means to analyze the content of emails. It analyzes the header information and body of received emails and extracts important data. Software such as Python's email library is used for this analysis. The analyzed data includes information such as the sender, recipient, subject, and body of the email.
[0697] Next, the server has the means to perform a security scan based on the content of the analyzed email. This security scan includes the ability to check for matches with virus and malware signatures. Antivirus software and machine learning models are used for the security scan.
[0698] Furthermore, the server has a means to detect phishing and spam patterns using machine learning models. This means that it can determine with high accuracy whether an received email is phishing or spam. Specifically, machine learning models using libraries such as Python's scikit-learn are used.
[0699] Furthermore, the server has a means to evaluate the authenticity of emails based on the results of security scans and evaluations of machine learning models. This means determines whether an email is legitimate or fraudulent.
[0700] Finally, the server has a mechanism to determine the action to take on an email based on the evaluation results. This mechanism ensures that emails deemed safe are delivered to the regular inbox, while emails identified as spam or phishing are moved to a quarantine folder. It also includes a mechanism to send real-time notifications to the user based on the evaluation results.
[0701] As a concrete example, consider a scenario where a user opens their email client and receives a new email. The server receives this email and analyzes its contents. It then performs a security scan to check for any matches with virus signatures. Next, it uses a machine learning model to detect phishing and spam patterns. Based on the evaluation results, spam emails are moved to a quarantine folder, and users receive real-time notifications for important threats.
[0702] Example of a prompt:
[0703] "Please introduce our ultra-high-performance email security scanning system. This system analyzes email headers and body text, enabling highly accurate detection of viruses, malware, phishing, and spam. It also uses natural language processing technology to evaluate email context and content, determining appropriate actions. Using this system ensures only safe emails appear in the user's inbox, significantly improving protection against malicious emails."
[0704] The above is a detailed explanation for carrying out the present invention.
[0705] The flow of a specific process in Application Example 1 will be explained using Figure 12.
[0706] Step 1:
[0707] The server receives new emails sent from the user's email client. The input is the entire incoming email, and its contents are passed directly to the next step. Specifically, the server connects to the mail server via the POP3 or IMAP protocol and retrieves unread emails.
[0708] Step 2:
[0709] The server parses the header information and body of received emails. The input is the entire received email, and the output is the parsed data. This parsing uses the Python email library to extract the sender, recipient, subject, and body of the email.
[0710] Step 3:
[0711] The server performs a security scan based on the content of the analyzed email. The input is the analyzed email data, and the output is the security scan results. Specifically, it uses antivirus software to compare the data against virus and malware signatures and check for matches.
[0712] Step 4:
[0713] The server uses a machine learning model to detect phishing and spam patterns. The input is analyzed email data, and the output is the evaluation result for phishing and spam. Specifically, the scikit-learn library in Python is used to evaluate the features of emails with a pre-trained machine learning model.
[0714] Step 5:
[0715] The server evaluates the authenticity of emails based on security scan results and machine learning model evaluations. The inputs are scan results and machine learning evaluation results, and the output is the email authenticity rating. Specifically, these evaluations are integrated, and a scoring system determines whether the email is legitimate.
[0716] Step 6:
[0717] The server determines the action to take on an email based on the credibility assessment result. The input is the credibility assessment result, and the output is the email sorting action. Specifically, emails deemed safe are delivered to the regular inbox, while emails identified as spam or phishing are moved to a quarantine folder.
[0718] Step 7:
[0719] The server sends real-time notifications to users based on the evaluation results. The input is the evaluation result, and the output is the notification message. Specifically, if a serious threat is detected, the server sends a warning to the user and administrator via push notification or email.
[0720] This process ensures that users receive only highly filtered and secure emails, significantly improving their protection against malicious emails.
[0721] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.
[0722] The system according to the present invention analyzes emails received by users with high accuracy, performs security scans, evaluates their authenticity, and, by incorporating an emotion engine, recognizes the user's emotions to complement email evaluation. This system consists of several main means.
[0723] First, the server receives a new email from the user's email client. The received email is initially stored on the server, and a process begins to analyze the header information and body. The server analyzes the email header information, extracting the sender address, recipient address, subject, date, etc., and recording them in a log. In addition, during the analysis of the email body, links and attachments are identified and analyzed individually.
[0724] Next, the server performs a security scan. It compares the analyzed email text, links, and attachments against a database of virus and malware signatures. Machine learning models are also used to detect phishing and spam patterns. Furthermore, a natural language processing (NLP) engine is used to analyze the context of the email and assess whether it is legitimate business communication.
[0725] Furthermore, a key feature of this invention is the inclusion of an emotion engine. The server operates the emotion engine based on the email body and contextual information to recognize the emotions a user felt when reading the email. Specifically, it classifies emotions as positive, negative, or neutral based on specific keywords and contextual patterns within the email. This emotion classification result is then integrated with the security scan results to complement the final credibility assessment.
[0726] Based on the evaluation results, the server decides what action to take with the email. For example, emails deemed safe are delivered to the regular inbox, while emails identified as spam or phishing are moved to a quarantine folder. If the user's sentiment is perceived as negative, a more detailed analysis is performed, and an alert is sent to the administrator if necessary.
[0727] As a concrete example, consider a scenario where a user opens an email client and receives a new email. The email is received by the server, and its header information and body are analyzed. Then, a security scan is performed, and a virus check is conducted. The sentiment engine analyzes the context of the email and determines that the user may experience negative emotions upon reading it. As a result, the email undergoes further detailed analysis and is ultimately moved to the quarantine folder. The user cannot view this email in their inbox; they can review its contents in the quarantine folder and take appropriate action (e.g., report it as spam or correct a false positive).
[0728] The system of this invention allows users to receive secure emails that have been filtered with high accuracy, and furthermore, by using an emotion engine, it is possible to reduce the emotional stress caused by reading emails. As a result, a safer and more comfortable email environment is provided for users.
[0729] The following describes the processing flow.
[0730] Step 1:
[0731] The server receives a new email from the email client. The received email is first stored on the server in preparation for the next analysis step.
[0732] Step 2:
[0733] The server analyzes the email header information. It extracts the sender address, recipient address, subject, date, sender IP address, etc., and records them in a log. It also performs authentication checks such as SPF, DKIM, and DMARC.
[0734] Step 3:
[0735] The server analyzes the email body. It breaks down the text portion of the email, identifies the main sections, and extracts the text information from each section. It also identifies links and attachments and analyzes them individually.
[0736] Step 4:
[0737] The server performs a security scan. It compares the analyzed email text, links, and attachments against a database of virus and malware signatures. Furthermore, it uses machine learning models to detect phishing and spam patterns.
[0738] Step 5:
[0739] The server uses a natural language processing (NLP) engine to analyze the context of the email. This contextual analysis helps determine whether the email content is legitimate business communication or a scam or spam email.
[0740] Step 6:
[0741] The server uses an emotion engine to recognize the user's emotions based on the content of the email. For example, it can determine, based on specific keywords and context, whether the email is likely to evoke positive, negative, or neutral emotions.
[0742] Step 7:
[0743] The server evaluates the authenticity of emails based on security scans, NLP analysis, and sentiment engine results. This allows it to calculate an overall security level and risk score, determining the reliability of the email.
[0744] Step 8:
[0745] The server determines the action to take on an email. For example, emails deemed safe are delivered to the inbox, while emails identified as spam or phishing are moved to a quarantine folder. If the user's sentiment is perceived as negative, further detailed analysis is performed, and an alert is sent to the administrator if necessary.
[0746] Step 9:
[0747] Users check their emails in their inbox or quarantine folder. They can open and review emails deemed safe. For emails moved to the quarantine folder, users can report them as spam or correct false positives.
[0748] In this way, the server performs a series of processes, allowing users to receive highly accurate, filtered, and secure emails. Furthermore, the introduction of an emotion engine reduces the emotional stress associated with reading emails, providing a more comfortable email environment.
[0749] (Example 2)
[0750] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."
[0751] Traditional email systems perform security scans on emails, but lack the complementary evaluation of email content through sentiment analysis. This makes it difficult to reliably detect emails that evoke negative emotions in users or are malicious. In particular, malicious activities such as phishing and spam emails have become more sophisticated, and simple virus checks and signature matching are no longer sufficient countermeasures. Furthermore, the risk of users experiencing psychological stress due to the content of emails they receive is also increasing. Therefore, there is a need for a system that simultaneously reduces both email security and user emotional stress.
[0752] The identification processing performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means. In this invention, the server includes means for receiving emails, means for analyzing the content of the emails, means for performing a security scan based on the analyzed content, means for evaluating the authenticity of the emails based on the results of the security scans, and means for recognizing the sentiment of the emails using a sentiment analysis engine and supplementing the authenticity evaluation. As a result, emails received by the user are filtered with high accuracy, and emails that pose a risk of causing negative emotions are detected through sentiment analysis, making it possible to provide a safer and more comfortable email environment for the user.
[0753] "Means of receiving emails" refers to the function of retrieving new emails from the user's email client and saving them on the server.
[0754] "Means for analyzing the contents of the email" refers to a system that examines the header information and body of a received email and extracts the sender's address, recipient's address, subject, date, links, attachments, etc.
[0755] "Means for performing a security scan based on the analyzed content" refers to a system that uses the analysis results to examine emails against signatures of viruses and malicious programs, and has the function of detecting malicious activity.
[0756] "Means for evaluating the authenticity of an email based on the results of the security scan" refers to a mechanism that determines and evaluates the legitimacy and potential risks of an email through the results of a security scan.
[0757] "Means for determining email action based on the evaluated results" refers to a system that determines specific actions, such as whether to deliver the email to the inbox or move it to a quarantine folder, based on the credibility assessment.
[0758] "A means of recognizing the emotions in emails using an emotion analysis engine to complement credibility evaluation" refers to a system that analyzes the content of an email, classifies the positive, negative, or neutral emotions that a user might feel upon reading it, and then uses the results to further enhance the credibility evaluation of the email.
[0759] Modes for carrying out the invention
[0760] The system according to the present invention analyzes emails received by users with high accuracy, performs security scans, evaluates their credibility, and, by incorporating an emotion engine, recognizes the user's emotions to complement email evaluation. This system consists of several main means.
[0761] First, the server receives new emails from the user's email client. The received emails are initially stored on the server, and a process begins to parse the header information and body. Specifically, the server runs on high-performance hardware (e.g., an AWS EC2 instance) and uses email server software (e.g., Postfix) to receive and store emails. Next, the server uses a Python script and the email package to parse and log the email header information (sender address, recipient address, subject, date, etc.). It also uses BeautifulSoup to parse the HTML body, identify links and attachments, and analyze this information individually.
[0762] Next, the server performs a security scan. This scan first uses ClamAV to compare the email text, links, and attachments against a signature database of viruses and malicious programs. Furthermore, a pre-trained machine learning model (e.g., TensorFlow) is used to detect phishing and spam patterns. The TensorFlow model extracts and evaluates phishing and spam features from the email body text.
[0763] Subsequently, the server uses a natural language processing engine (e.g., Google's BERT) to analyze the context of the email and evaluate whether it is legitimate business communication. Furthermore, a distinctive feature of this invention is the inclusion of an emotion engine. Based on the email body and contextual information, the server operates an emotion engine (e.g., IBM Watson Tone Analyzer) to recognize the emotions the user felt when reading the email. Specifically, it classifies emotions as positive, negative, or neutral based on specific keywords and contextual patterns within the email. This emotion classification result is then integrated with the security scan results to complement the final credibility assessment.
[0764] Based on the evaluation results, the server decides what action to take with the email. For example, emails deemed safe are delivered to the regular inbox, while emails identified as spam or malicious are moved to a quarantine folder. If the user's sentiment is perceived as negative, a more detailed analysis is performed, and an alert is sent to the administrator if necessary.
[0765] As a concrete example, consider a scenario where a user opens an email client (e.g., Microsoft Outlook) and receives a new email. The email is received by the server, and its header information and body are analyzed. Then, a security scan is performed, and a virus check is conducted. Furthermore, the sentiment engine analyzes the context of the email and determines that the user may experience negative emotions upon reading it. As a result, the email undergoes further detailed analysis and is ultimately moved to a quarantine folder. The user cannot view this email in their inbox; they can review its contents in the quarantine folder and take appropriate action (such as reporting it as spam or correcting a false positive).
[0766] An example of a prompt message is as follows:
[0767] When a user opens their email client and receives a new email, the server receives and stores the email. The server uses a Python script to parse the header and body information and extract the necessary information. Next, it performs a virus scan with ClamAV and detects spam and phishing with a TensorFlow model. Finally, it uses the IBM Watson API to perform sentiment analysis and report a final rating. Please describe the specific steps of these processes.
[0768] The flow of the specific processing in Example 2 will be explained using Figure 13.
[0769] Detailed explanation of the program's processing steps
[0770] Step 1:
[0771] incoming mail
[0772] Input: New email from the user's email client
[0773] Processing: The server receives emails via port 25 and temporarily stores them in a temporary directory.
[0774] Output: Mail files stored on the server
[0775] Specific operation: The server uses mail server software to execute the receiving process. The server listens on a specific port, and when it receives new mail, it writes it to a temporary directory.
[0776] Step 2:
[0777] Email analysis
[0778] Input: Mail files saved in a temporary directory
[0779] Processing: The server analyzes the email header information and body, extracting sender address, recipient address, subject, date, links, attachments, etc.
[0780] Output: Analyzed header information and body content
[0781] Specific operation: The server executes a Python script and parses header information using the email package. It uses BeautifulSoup to identify links and attachments from the HTML body. The extracted information is recorded in a database and log files.
[0782] Step 3:
[0783] Security scan
[0784] Input: Parsed header information and body content
[0785] Processing: The server performs virus scanning and spam / phishing detection using machine learning models.
[0786] Output: Security scan evaluation results
[0787] Specific operation: The server uses ClamAV to scan attachments and the email body for viruses. It also runs a TensorFlow machine learning model to analyze the email body and determine if it is phishing or spam.
[0788] Step 4:
[0789] Emotion analysis
[0790] Input: Analyzed email body
[0791] Processing: The server activates an emotion engine to classify the email content into positive, negative, or neutral emotions.
[0792] Output: Results of sentiment analysis
[0793] Specific operation: The server sends the email body to the IBM Watson Tone Analyzer API and retrieves the returned sentiment classification result. The result is classified as either positive, negative, or neutral.
[0794] Step 5:
[0795] Credibility assessment and final action decision
[0796] Input: Security scan evaluation results and sentiment analysis results
[0797] Processing: The server integrates these results, evaluates the authenticity of the email, and determines the appropriate action.
[0798] Output: Determination of the email delivery destination (inbox or quarantine folder)
[0799] Specific operation: The server runs a credibility assessment algorithm and calculates a final score. Based on the score, if the email is deemed safe, it is delivered to the inbox; if deemed dangerous, it is moved to a quarantine folder. In addition, if negative sentiment is detected, a detailed analysis is performed and an alert is sent to the administrator if necessary.
[0800] (Application Example 2)
[0801] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."
[0802] Traditional email systems prioritize security to protect users from viruses, malware, phishing, and spam. However, this alone lacks consideration for the emotional stress and negative feelings users experience, meaning certain emails can cause significant emotional distress. Therefore, a system is needed that integrates security scanning with sentiment analysis, considering the impact on users' emotions along with evaluating the reliability of emails.
[0803] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means. In this invention, the server includes means for receiving emails, means for analyzing the content of the emails, means for performing a security scan based on the analyzed content, an emotion engine having the function of recognizing and classifying emotions based on the content and contextual information of the emails, and means for determining the final email action, including an evaluation of the emotion engine. This makes it possible to detect viruses and malware, quarantine spam emails, and reduce the emotional stress on the user.
[0804] "Means of receiving email" refers to the function that allows a server to retrieve emails from a user's email client.
[0805] "Means for analyzing the contents of the email" refers to the process of analyzing the header information, body, links, and attachments of a received email and extracting data for security and sentiment evaluation.
[0806] "Means for performing a security scan based on the analyzed content" refers to a function that compares the analyzed email content with a virus and malware signature database to detect phishing and spam patterns.
[0807] "Means for evaluating the authenticity of an email based on the results of the security scan" refers to algorithms or machine learning models used to evaluate whether an email is trustworthy based on the results of the security scan.
[0808] A "sentiment engine that recognizes and classifies emotions based on email content and contextual information" is a system that analyzes specific keywords and contextual patterns within an email body and classifies the emotions (positive, negative, or neutral) a user feels when reading the email.
[0809] "Means for determining the final email action, including the evaluation of the sentiment engine" refers to logic that integrates the results of security scans and sentiment evaluations to determine the final action, such as sending or quarantining the email.
[0810] The system for realizing this invention provides a function that, upon receiving an email from a user, analyzes the email with high accuracy and evaluates its reliability and emotional impact using a security scan and sentiment engine. Specifically, the following processes take place between the server, terminal, and user.
[0811] The system first has the function of receiving new emails from the user's email client. The received emails are stored on the server, and then a process of analyzing the email header information and body begins. The header information extracted includes the sender address, recipient address, subject, and date, and these are recorded in the log. In the body analysis, links and attachments are also identified and analyzed separately.
[0812] Next, the server performs a security scan. This process compares the analyzed email text, links, and attachments against a database of virus and malware signatures. Machine learning models are also used to detect phishing and spam patterns. Furthermore, a natural language processing (NLP) engine is used to analyze the context of the email and assess whether it is legitimate business communication.
[0813] In addition, the system's signature emotion engine is activated. Based on the email body and contextual information, the emotion engine identifies specific keywords and patterns and classifies them as positive, negative, or neutral. This emotion classification result is integrated with the results of the aforementioned security scan and complements the final email authenticity assessment.
[0814] Based on the credibility assessment, the server decides what to do with the email. For example, emails deemed safe by the security check are delivered to the regular inbox, while emails suspected of being spam or phishing, or those classified as potentially causing negative emotions, are moved to a quarantine folder. In cases of high importance, an alert may also be sent to the administrator.
[0815] To perform these processes, the server implements machine learning models using libraries such as Python and TensorFlow, a natural language processing engine, and spam / phishing detection algorithms. User information, email data, and analysis results are stored in the database.
[0816] Specific example
[0817] When a user receives a new email on their smartphone, it is sent to the server where its header information and body are analyzed. A security scan is then performed to check for viruses. The sentiment engine analyzes the email's context, and if it determines that the email may evoke negative emotions, it is moved to a quarantine folder. The user receives a warning notification at this time.
[0818] Example of a prompt
[0819] "Implement a system that performs security and sentiment analysis on newly received emails and takes appropriate actions to help users maintain positive emotions."
[0820] This system allows users to enjoy a safe and comfortable email environment that is free from spam and phishing emails, and also takes emotional impact into consideration.
[0821] The flow of a specific process in Application Example 2 will be explained using Figure 14.
[0822] Step 1:
[0823] The server receives a new email from the user's email client. At this point, the input data is the raw data of the received email. The server retrieves this data and stores it as an email object.
[0824] Step 2:
[0825] The server analyzes the header information and body of received emails. The header information analysis extracts the sender address, recipient address, subject, date, etc. The input data requires an email object, and the output is the analyzed header information. Specifically, this information is extracted and logged using the Python email library.
[0826] Step 3:
[0827] The server parses the email body to identify links and attachments. The input is the email object and its body text, and the output is a list of identified links and attachments. This is accomplished using Python's regular expressions and URL parsing libraries.
[0828] Step 4:
[0829] The server performs a security scan. At this stage, the email body, links, and attachments are compared against a database of virus and malware signatures. The input data consists of each part of the email being analyzed, and the output is the scan result (e.g., safe, virus detected, suspected phishing, etc.). This process is performed using ClamAV or the VirusTotal API.
[0830] Step 5:
[0831] The server uses machine learning models to detect phishing and spam patterns. The input is email text data, and the output is a spam score and a phishing score. This is done using models from Scikit-learn or TensorFlow.
[0832] Step 6:
[0833] The server uses a natural language processing (NLP) engine to analyze the context of emails. The input data is the email body, and the output is an evaluation result of whether the email is legitimate business communication. Context analysis is performed using Python's nltk and spaCy libraries.
[0834] Step 7:
[0835] The server operates an emotion engine that recognizes and classifies emotions based on the email body and context. The input data is the email body and contextual information, and the output is the emotion classification result (positive, negative, or neutral). This is done using a pre-trained TensorFlow model.
[0836] Step 8:
[0837] The server integrates the results of security scans and the sentiment engine to evaluate the final authenticity of the email. The input data consists of the results of each scan and sentiment classification, and the output is the overall evaluation result. Based on this, the processing action for the email (for example, safe emails go to the inbox, suspicious emails go to the quarantine folder) is determined.
[0838] Step 9:
[0839] The server performs email actions based on the evaluation results. The input data is the final overall evaluation result, and the output is the sorting of emails into the user's inbox or quarantine folder. Specifically, emails deemed safe are delivered to the regular inbox, while emails identified as spam or phishing are moved to the quarantine folder.
[0840] This series of processes will allow users to enjoy a safe and emotionally sensitive email environment.
[0841] The specific processing unit 290 transmits the result of the specific processing to the headset terminal 314. In the headset terminal 314, the control unit 46A causes the speaker 240 and display 343 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.
[0842] Data generation model 58 is a type of so-called generative AI (Artificial Intelligence). One example of data generation model 58 is ChatGPT (Internet search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[0843] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and specific processing may also be performed by the headset terminal 314.
[0844] [Fourth Embodiment]
[0845] Figure 7 shows an example of the configuration of the data processing system 410 according to the fourth embodiment.
[0846] As shown in Figure 7, the data processing system 410 includes a data processing device 12 and a robot 414. An example of the data processing device 12 is a server.
[0847] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0848] The robot 414 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication interface 44, and a controlled object 443. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, camera 42, and controlled object 443 are also connected to the bus 52.
[0849] The microphone 238 receives voice signals from the user 20 and receives instructions from the user 20. The microphone 238 captures the voice signals from the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.
[0850] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the area around the user 20 (for example, an imaging range defined by a field of view equivalent to the width of a typical healthy person's field of vision).
[0851] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.
[0852] The controlled object 443 includes a display device, LEDs in the eyes, and motors that drive the arms, hands, and feet. The posture and gestures of the robot 414 are controlled by controlling the motors of the arms, hands, and feet. Some of the robot 414's emotions can be expressed by controlling these motors. Furthermore, the robot 414's facial expressions can also be expressed by controlling the illumination state of the LEDs in its eyes.
[0853] Figure 8 shows an example of the main functions of the data processing device 12 and the robot 414. As shown in Figure 8, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.
[0854] The specific processing program 56 is an example of a "program" relating to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[0855] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[0856] In robot 414, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.
[0857] Next, the specific processing performed by the specific processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".
[0858] The system according to the present invention has the function of automatically determining appropriate actions by analyzing emails received by the user with high accuracy, performing security scans, and evaluating their authenticity. This system consists of several main means.
[0859] First, the server has a means of receiving email. Users receive emails through a regular email client, but the received email is first sent to the server. Here, the server retrieves the email header information and body and converts it into a parseable format. Through this analysis, the server extracts important data such as the sender, recipient, subject, and body of the email.
[0860] Next, the server is equipped with means to analyze the content of emails. It analyzes the header information and body of received emails to perform tasks such as verifying the validity of the sender domain and detecting anomalies in the message content. This allows for a basic check of whether the email content is appropriate.
[0861] Next, the server has the means to perform security scans. Here, security checks are performed based on the content of the analyzed emails. This check includes verifying matches with virus and malware signatures. Machine learning models are also used to detect phishing and spam patterns.
[0862] The server then uses methods to evaluate the authenticity of the email. Based on the results of security scans and other analyses, it determines whether the email is legitimate or a phishing or spam email. At this point, a more advanced analysis engine may use natural language processing (NLP) techniques to evaluate the context and content of the email.
[0863] Based on the evaluation results, the server uses a means to determine the action to take on emails. For example, emails deemed safe are delivered to the regular inbox, while emails identified as spam or phishing are moved to a quarantine folder. The server also sends an alert to the administrator if it detects a high-level threat.
[0864] As a concrete example, consider a scenario where a user opens their email client and receives a new email. This email is received by the server and its contents are analyzed. A security scan is then performed to check for any virus signatures. After evaluating the email's authenticity, it is determined to be spam. Finally, the server moves this email to a quarantine folder and does not display it in the inbox.
[0865] The system of the present invention allows users to receive secure emails that have been filtered with high accuracy, significantly improving their protection against malicious emails.
[0866] The following describes the processing flow.
[0867] Step 1:
[0868] The server receives a new email from the user's email client. The received email is first stored on the server, and a process begins to parse the header information and body.
[0869] Step 2:
[0870] The server analyzes the email header information. It extracts and logs the sender address, recipient address, subject, date, and sender IP address. It also verifies whether the email's sender domain is legitimate through authentication methods such as SPF, DKIM, and DMARC.
[0871] Step 3:
[0872] The server analyzes the email body. The analysis engine divides the email content into sections and extracts text information from each section. Links and attachments within the email are also identified and analyzed individually.
[0873] Step 4:
[0874] The server performs a security scan. It compares the analyzed email text, links, and attachments against a database of virus and malware signatures. It also uses machine learning models to detect phishing and spam patterns.
[0875] Step 5:
[0876] The server uses a natural language processing (NLP) engine to analyze the context of the email. This contextual analysis helps determine whether the email content is legitimate business communication or a phishing email.
[0877] Step 6:
[0878] The server evaluates the authenticity of emails based on the results of security scans and NLP analysis. It calculates security level and risk scores to determine the overall reliability of the email.
[0879] Step 7:
[0880] The server determines the action to take regarding the email. Based on the evaluation, it either delivers it to the inbox as a regular email or moves it to the quarantine folder as spam or phishing email. If necessary, it sends an alert to the administrator.
[0881] Step 8:
[0882] Users check their emails in their inbox or quarantine folder. They can open and review emails deemed safe. For emails moved to the quarantine folder, users can report them as spam or correct false positives.
[0883] Following these processing steps, the system of the present invention can achieve highly accurate email filtering and protect users from email-based threats.
[0884] (Example 1)
[0885] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".
[0886] Traditional email systems often fail to adequately evaluate and filter incoming emails, resulting in malicious and spam emails remaining in users' inboxes. Furthermore, the lack of adequate mechanisms for quickly notifying administrators of advanced threats increases security risks for businesses and individuals. Therefore, there is a growing need for more accurate analysis and security scanning, along with reliability assessments, when receiving emails.
[0887] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.
[0888] In this invention, the server includes means for receiving emails, means for analyzing the content of emails, means for performing security scans based on the analyzed content, means for evaluating the authenticity of emails based on the results of security scans and additional analysis, means for determining actions to take regarding emails based on the evaluated results, and means for sending alerts to administrators when advanced threats are detected. This enables users to receive only safe emails, filters out malicious emails with high accuracy, quickly notifies administrators of advanced threats, and mitigates security risks.
[0889] "Means of receiving email" refers to the function by which a server retrieves email from a user's email client. This is done using communication protocols such as IMAP and POP3.
[0890] "Methods for analyzing email content" refer to the function of a server that analyzes the header information and body of received emails and extracts important data (sender, recipient, subject, body text, etc.). Software tools such as the Python email package are often used for this purpose.
[0891] "Means of performing security scans" refers to a function where the server performs security checks based on the content of analyzed emails, such as virus and malware signature checks and pattern recognition for phishing and spam emails. This may involve using tools like ClamAV or machine learning models.
[0892] "Methods for evaluating email authenticity" refers to a function that allows a server to assess the reliability of an incoming email and determine whether the email content is trustworthy, based on security scans and additional analysis results. This utilizes NLP technology and generative AI models.
[0893] "Means for determining email actions" refers to the function that allows the server to process emails appropriately (e.g., deliver to the inbox, move to the quarantine folder) based on the credibility assessment results.
[0894] "Method for sending alerts to administrators when advanced threats are detected" refers to a function that notifies administrators in real time when the server detects advanced security threats such as phishing or malware. This includes sending emails using the SMTP protocol, as well as notifications via the management dashboard.
[0895] Modes for carrying out the invention
[0896] The system according to the present invention has the function of automatically determining appropriate actions by analyzing emails received by users with high accuracy, performing security scans, and evaluating their authenticity. The main components of this system include a server, a terminal, and a user.
[0897] Hardware and software to be used
[0898] server:
[0899] The server uses IMAP or POP3 protocols to access the user's mailbox and retrieve emails.
[0900] The server uses Python's email package to parse the headers and body of received emails and extract important data, such as the sender, recipient, subject, and email body text.
[0901] The server uses ClamAV (open-source antivirus software) to compare incoming emails and attachments against virus and malware signatures.
[0902] The server uses machine learning models (e.g., TensorFlow or Scikit-learn) to identify patterns in phishing and spam emails.
[0903] The server uses a generative AI model (e.g., GPT-3) and leverages natural language processing techniques to evaluate the context and reliability of the email's content.
[0904] The server uses the SMTP protocol to send an alert to the administrator if an advanced threat is detected.
[0905] Terminal:
[0906] The user's device functions as a regular email client (e.g., Microsoft Outlook or Gmail), receiving and viewing emails after they have been analyzed and evaluated by the server.
[0907] System operation example
[0908] When a user receives a new email using Microsoft Outlook, the email is first sent to the server. The server then performs the following actions in sequence:
[0909] 1. Receiving emails: The server uses the IMAP protocol to access the user's Outlook account and retrieve new emails.
[0910] 2. Email parsing: The server uses the Python email package to parse the header information and body of the email, and extract the sender and subject.
[0911] 3. Security scan: The server runs ClamAV to check for viruses, and then uses a machine learning model to determine if it is phishing or spam.
[0912] 4. Credibility Assessment: The server uses a generated AI model (GPT-3) to evaluate the credibility of the email body using natural language processing technology.
[0913] 5. Decision on action: The server moves emails identified as spam to a quarantine folder and delivers safe emails to the inbox.
[0914] 6. Sending alerts to the administrator: The server uses the SMTP protocol to notify the administrator of any detected threats.
[0915] Example of a prompt
[0916] Please analyze the content of the following email and assess its credibility:
[0917] Sender: example@example.com
[0918] Subject: Important Notice
[0919] Body: This email is urgent. Click to see details.
[0920] This means users receive highly filtered and secure emails, and their protection from malicious emails is enhanced.
[0921] The flow of the specific processing in Example 1 will be explained using Figure 11.
[0922] Step 1:
[0923] Receiving emails
[0924] Input: The user sends an email, or the server retrieves new mail from the mail server using the IMAP / POP3 protocol.
[0925] Specific operation: The server uses the IMAP protocol to access the user's mailbox (e.g., Gmail, Outlook) and retrieve new emails.
[0926] Output: The retrieved email data is saved to the server.
[0927] Step 2:
[0928] Email analysis
[0929] Input: Email data obtained in Step 1.
[0930] Specific operation: The server uses the Python email package to parse email header information (sender, recipient, subject) and body text.
[0931] Data processing / data calculation: Analyze email headers and body text to extract important data.
[0932] Output: Analyzed email data (sender address, recipient address, subject, body text).
[0933] Step 3:
[0934] Run a security scan
[0935] Input: Email data analyzed in Step 2.
[0936] Specific operation: The server uses ClamAV to scan email bodies and attachments for virus and malware signatures. It also uses machine learning models (e.g., TensorFlow or Scikit-learn) to detect phishing and spam patterns.
[0937] Data processing / data calculation: Matching email content with virus and malware signatures, identifying phishing and spam patterns.
[0938] Output: Security scan results (presence or absence of security risks).
[0939] Step 4:
[0940] Email credibility assessment
[0941] Input: Security scan results obtained in Step 3 and email data analyzed in Step 2.
[0942] Specific operation: The server uses a generated AI model (e.g., GPT-3) and natural language processing techniques to determine the reliability of the email body.
[0943] Data processing / data calculation: Evaluating the reliability of the context and content of email bodies.
[0944] Output: Credibility assessment results (e.g., trustworthy, spam, phishing).
[0945] Step 5:
[0946] Email Action Decision
[0947] Input: The results of the credibility assessment obtained in Step 4.
[0948] Specific operation: Based on the credibility assessment results, the server decides whether to deliver the email to the inbox or move it to the quarantine folder.
[0949] Data processing / data calculation: Email sorting based on evaluation results.
[0950] Output: Sorted emails (Inbox, Quarantine folder).
[0951] Step 6:
[0952] Sending alerts to administrators
[0953] Input: Security risks and threats detected in Steps 3 and 4.
[0954] Specific operation: The server uses the SMTP protocol to notify administrators of security threats, including real-time notifications to the management dashboard.
[0955] Data processing / data computation: Generating threat intelligence and calling notification protocols.
[0956] Output: Alert notifications sent to the administrator (email, dashboard notification).
[0957] (Application Example 1)
[0958] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".
[0959] In modern email communication, users are frequently exposed to threats such as spam, phishing, and virus emails, making it difficult to provide a secure email environment. Furthermore, traditional email filtering systems lack sufficient accuracy, leading to frequent false positives and missed detections. Additionally, notifications to users and administrators may be delayed when email threats occur. There is a need to solve these problems and provide highly accurate and rapid email security measures.
[0960] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.
[0961] In this invention, the server includes means for receiving emails, means for analyzing the content of emails, means for performing security scans based on the analyzed content, means for evaluating the authenticity of emails based on the results of security scans, means for determining actions to take regarding emails based on the evaluation results, means for detecting phishing and spam patterns using machine learning models, and means for sending real-time notifications to users based on the evaluation results. As a result, users receive only safe emails that have been filtered with high accuracy, improving their defense against malicious emails and enabling quick responses.
[0962] "Means of receiving email" refers to the functions and mechanisms for obtaining email from an external mail server.
[0963] "Methods for analyzing email content" refer to technologies for analyzing the header information and body of received emails and extracting the data contained therein.
[0964] "Means of performing security scans" refers to functions that, based on the content of analyzed emails, check for matches with virus and malware signatures, and detect phishing and spam patterns.
[0965] "Methods for evaluating the authenticity of emails" refer to functions that determine whether an email is legitimate, phishing, or spam, based on the results of security scans.
[0966] "Means for determining email actions" refers to the function that determines, based on evaluation results, whether to deliver the email to the inbox, move it to a quarantine folder, or take other actions.
[0967] "Methods for detecting phishing and spam patterns using machine learning models" refers to technologies that use machine learning algorithms to detect phishing and spam characteristics in received emails and assess their risk.
[0968] "Means of sending real-time notifications to users based on the evaluation results" refers to a function or system that immediately issues a warning to users or administrators if the evaluation results of an email are determined to contain malicious content.
[0969] This invention relates to a system that analyzes emails received by users with high accuracy, performs security scans, and evaluates their authenticity. The following describes how to implement this system.
[0970] First, the server has the means to receive email. Specifically, the server has the function to retrieve email from an external mail server and convert its contents into a format that can be processed. This email is received through the email client that the user normally uses, but it is processed by the server first.
[0971] Next, the server is equipped with a means to analyze the content of emails. It analyzes the header information and body of received emails and extracts important data. Software such as Python's email library is used for this analysis. The analyzed data includes information such as the sender, recipient, subject, and body of the email.
[0972] Next, the server has the means to perform a security scan based on the content of the analyzed email. This security scan includes the ability to check for matches with virus and malware signatures. Antivirus software and machine learning models are used for the security scan.
[0973] Furthermore, the server has a means to detect phishing and spam patterns using machine learning models. This means that it can determine with high accuracy whether an received email is phishing or spam. Specifically, machine learning models using libraries such as Python's scikit-learn are used.
[0974] Furthermore, the server has a means to evaluate the authenticity of emails based on the results of security scans and evaluations of machine learning models. This means determines whether an email is legitimate or fraudulent.
[0975] Finally, the server has a mechanism to determine the action to take on an email based on the evaluation results. This mechanism ensures that emails deemed safe are delivered to the regular inbox, while emails identified as spam or phishing are moved to a quarantine folder. It also includes a mechanism to send real-time notifications to the user based on the evaluation results.
[0976] As a concrete example, consider a scenario where a user opens their email client and receives a new email. The server receives this email and analyzes its contents. It then performs a security scan to check for any matches with virus signatures. Next, it uses a machine learning model to detect phishing and spam patterns. Based on the evaluation results, spam emails are moved to a quarantine folder, and users receive real-time notifications for important threats.
[0977] Example of a prompt:
[0978] "Please introduce our ultra-high-performance email security scanning system. This system analyzes email headers and body text, enabling highly accurate detection of viruses, malware, phishing, and spam. It also uses natural language processing technology to evaluate email context and content, determining appropriate actions. Using this system ensures only safe emails appear in the user's inbox, significantly improving protection against malicious emails."
[0979] The above is a detailed explanation for carrying out the present invention.
[0980] The flow of a specific process in Application Example 1 will be explained using Figure 12.
[0981] Step 1:
[0982] The server receives new emails sent from the user's email client. The input is the entire incoming email, and its contents are passed directly to the next step. Specifically, the server connects to the mail server via the POP3 or IMAP protocol and retrieves unread emails.
[0983] Step 2:
[0984] The server parses the header information and body of received emails. The input is the entire received email, and the output is the parsed data. This parsing uses the Python email library to extract the sender, recipient, subject, and body of the email.
[0985] Step 3:
[0986] The server performs a security scan based on the content of the analyzed email. The input is the analyzed email data, and the output is the security scan results. Specifically, it uses antivirus software to compare the data against virus and malware signatures and check for matches.
[0987] Step 4:
[0988] The server uses a machine learning model to detect phishing and spam patterns. The input is analyzed email data, and the output is the evaluation result for phishing and spam. Specifically, the scikit-learn library in Python is used to evaluate the features of emails with a pre-trained machine learning model.
[0989] Step 5:
[0990] The server evaluates the authenticity of emails based on security scan results and machine learning model evaluations. The inputs are scan results and machine learning evaluation results, and the output is the email authenticity rating. Specifically, these evaluations are integrated, and a scoring system determines whether the email is legitimate.
[0991] Step 6:
[0992] The server determines the action to take on an email based on the credibility assessment result. The input is the credibility assessment result, and the output is the email sorting action. Specifically, emails deemed safe are delivered to the regular inbox, while emails identified as spam or phishing are moved to a quarantine folder.
[0993] Step 7:
[0994] The server sends real-time notifications to users based on the evaluation results. The input is the evaluation result, and the output is the notification message. Specifically, if a serious threat is detected, the server sends a warning to the user and administrator via push notification or email.
[0995] This process ensures that users receive only highly filtered and secure emails, significantly improving their protection against malicious emails.
[0996] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.
[0997] The system according to the present invention analyzes emails received by users with high accuracy, performs security scans, evaluates their authenticity, and, by incorporating an emotion engine, recognizes the user's emotions to complement email evaluation. This system consists of several main means.
[0998] First, the server receives a new email from the user's email client. The received email is initially stored on the server, and a process begins to analyze the header information and body. The server analyzes the email header information, extracting the sender address, recipient address, subject, date, etc., and recording them in a log. In addition, during the analysis of the email body, links and attachments are identified and analyzed individually.
[0999] Next, the server performs a security scan. It compares the analyzed email text, links, and attachments against a database of virus and malware signatures. Machine learning models are also used to detect phishing and spam patterns. Furthermore, a natural language processing (NLP) engine is used to analyze the context of the email and assess whether it is legitimate business communication.
[1000] Furthermore, a key feature of this invention is the inclusion of an emotion engine. The server operates the emotion engine based on the email body and contextual information to recognize the emotions a user felt when reading the email. Specifically, it classifies emotions as positive, negative, or neutral based on specific keywords and contextual patterns within the email. This emotion classification result is then integrated with the security scan results to complement the final credibility assessment.
[1001] Based on the evaluation results, the server decides what action to take with the email. For example, emails deemed safe are delivered to the regular inbox, while emails identified as spam or phishing are moved to a quarantine folder. If the user's sentiment is perceived as negative, a more detailed analysis is performed, and an alert is sent to the administrator if necessary.
[1002] As a concrete example, consider a scenario where a user opens an email client and receives a new email. The email is received by the server, and its header information and body are analyzed. Then, a security scan is performed, and a virus check is conducted. The sentiment engine analyzes the context of the email and determines that the user may experience negative emotions upon reading it. As a result, the email undergoes further detailed analysis and is ultimately moved to the quarantine folder. The user cannot view this email in their inbox; they can review its contents in the quarantine folder and take appropriate action (e.g., report it as spam or correct a false positive).
[1003] The system of this invention allows users to receive secure emails that have been filtered with high accuracy, and furthermore, by using an emotion engine, it is possible to reduce the emotional stress caused by reading emails. As a result, a safer and more comfortable email environment is provided for users.
[1004] The following describes the processing flow.
[1005] Step 1:
[1006] The server receives a new email from the email client. The received email is first stored on the server in preparation for the next analysis step.
[1007] Step 2:
[1008] The server analyzes the email header information. It extracts the sender address, recipient address, subject, date, sender IP address, etc., and records them in a log. It also performs authentication checks such as SPF, DKIM, and DMARC.
[1009] Step 3:
[1010] The server analyzes the email body. It breaks down the text portion of the email, identifies the main sections, and extracts the text information from each section. It also identifies links and attachments and analyzes them individually.
[1011] Step 4:
[1012] The server performs a security scan. It compares the analyzed email text, links, and attachments against a database of virus and malware signatures. Furthermore, it uses machine learning models to detect phishing and spam patterns.
[1013] Step 5:
[1014] The server uses a natural language processing (NLP) engine to analyze the context of the email. This contextual analysis helps determine whether the email content is legitimate business communication or a scam or spam email.
[1015] Step 6:
[1016] The server uses an emotion engine to recognize the user's emotions based on the content of the email. For example, it can determine, based on specific keywords and context, whether the email is likely to evoke positive, negative, or neutral emotions.
[1017] Step 7:
[1018] The server evaluates the authenticity of emails based on security scans, NLP analysis, and sentiment engine results. This allows it to calculate an overall security level and risk score, determining the reliability of the email.
[1019] Step 8:
[1020] The server determines the action to take on an email. For example, emails deemed safe are delivered to the inbox, while emails identified as spam or phishing are moved to a quarantine folder. If the user's sentiment is perceived as negative, further detailed analysis is performed, and an alert is sent to the administrator if necessary.
[1021] Step 9:
[1022] Users check their emails in their inbox or quarantine folder. They can open and review emails deemed safe. For emails moved to the quarantine folder, users can report them as spam or correct false positives.
[1023] In this way, the server performs a series of processes, allowing users to receive highly accurate, filtered, and secure emails. Furthermore, the introduction of an emotion engine reduces the emotional stress associated with reading emails, providing a more comfortable email environment.
[1024] (Example 2)
[1025] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".
[1026] Traditional email systems perform security scans on emails, but lack the complementary evaluation of email content through sentiment analysis. This makes it difficult to reliably detect emails that evoke negative emotions in users or are malicious. In particular, malicious activities such as phishing and spam emails have become more sophisticated, and simple virus checks and signature matching are no longer sufficient countermeasures. Furthermore, the risk of users experiencing psychological stress due to the content of emails they receive is also increasing. Therefore, there is a need for a system that simultaneously reduces both email security and user emotional stress.
[1027] The identification processing performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means. In this invention, the server includes means for receiving emails, means for analyzing the content of the emails, means for performing a security scan based on the analyzed content, means for evaluating the authenticity of the emails based on the results of the security scans, and means for recognizing the sentiment of the emails using a sentiment analysis engine and supplementing the authenticity evaluation. As a result, emails received by the user are filtered with high accuracy, and emails that pose a risk of causing negative emotions are detected through sentiment analysis, making it possible to provide a safer and more comfortable email environment for the user.
[1028] "Means of receiving emails" refers to the function of retrieving new emails from the user's email client and saving them on the server.
[1029] "Means for analyzing the contents of the email" refers to a system that examines the header information and body of a received email and extracts the sender's address, recipient's address, subject, date, links, attachments, etc.
[1030] "Means for performing a security scan based on the analyzed content" refers to a system that uses the analysis results to examine emails against signatures of viruses and malicious programs, and has the function of detecting malicious activity.
[1031] "Means for evaluating the authenticity of an email based on the results of the security scan" refers to a mechanism that determines and evaluates the legitimacy and potential risks of an email through the results of a security scan.
[1032] "Means for determining email action based on the evaluated results" refers to a system that determines specific actions, such as whether to deliver the email to the inbox or move it to a quarantine folder, based on the credibility assessment.
[1033] "A means of recognizing the emotions in emails using an emotion analysis engine to complement credibility evaluation" refers to a system that analyzes the content of an email, classifies the positive, negative, or neutral emotions that a user might feel upon reading it, and then uses the results to further enhance the credibility evaluation of the email.
[1034] Modes for carrying out the invention
[1035] The system according to the present invention analyzes emails received by users with high accuracy, performs security scans, evaluates their credibility, and, by incorporating an emotion engine, recognizes the user's emotions to complement email evaluation. This system consists of several main means.
[1036] First, the server receives new emails from the user's email client. The received emails are initially stored on the server, and a process begins to parse the header information and body. Specifically, the server runs on high-performance hardware (e.g., an AWS EC2 instance) and uses email server software (e.g., Postfix) to receive and store emails. Next, the server uses a Python script and the email package to parse and log the email header information (sender address, recipient address, subject, date, etc.). It also uses BeautifulSoup to parse the HTML body, identify links and attachments, and analyze this information individually.
[1037] Next, the server performs a security scan. This scan first uses ClamAV to compare the email text, links, and attachments against a signature database of viruses and malicious programs. Furthermore, a pre-trained machine learning model (e.g., TensorFlow) is used to detect phishing and spam patterns. The TensorFlow model extracts and evaluates phishing and spam features from the email body text.
[1038] Subsequently, the server uses a natural language processing engine (e.g., Google's BERT) to analyze the context of the email and evaluate whether it is legitimate business communication. Furthermore, a distinctive feature of this invention is the inclusion of an emotion engine. Based on the email body and contextual information, the server operates an emotion engine (e.g., IBM Watson Tone Analyzer) to recognize the emotions the user felt when reading the email. Specifically, it classifies emotions as positive, negative, or neutral based on specific keywords and contextual patterns within the email. This emotion classification result is then integrated with the security scan results to complement the final credibility assessment.
[1039] Based on the evaluation results, the server decides what action to take with the email. For example, emails deemed safe are delivered to the regular inbox, while emails identified as spam or malicious are moved to a quarantine folder. If the user's sentiment is perceived as negative, a more detailed analysis is performed, and an alert is sent to the administrator if necessary.
[1040] As a concrete example, consider a scenario where a user opens an email client (e.g., Microsoft Outlook) and receives a new email. The email is received by the server, and its header information and body are analyzed. Then, a security scan is performed, and a virus check is conducted. Furthermore, the sentiment engine analyzes the context of the email and determines that the user may experience negative emotions upon reading it. As a result, the email undergoes further detailed analysis and is ultimately moved to a quarantine folder. The user cannot view this email in their inbox; they can review its contents in the quarantine folder and take appropriate action (such as reporting it as spam or correcting a false positive).
[1041] An example of a prompt message is as follows:
[1042] When a user opens their email client and receives a new email, the server receives and stores the email. The server uses a Python script to parse the header and body information and extract the necessary information. Next, it performs a virus scan with ClamAV and detects spam and phishing with a TensorFlow model. Finally, it uses the IBM Watson API to perform sentiment analysis and report a final rating. Please describe the specific steps of these processes.
[1043] The flow of the specific processing in Example 2 will be explained using Figure 13.
[1044] Detailed explanation of the program's processing steps
[1045] Step 1:
[1046] incoming mail
[1047] Input: New email from the user's email client
[1048] Processing: The server receives emails via port 25 and temporarily stores them in a temporary directory.
[1049] Output: Mail files stored on the server
[1050] Specific operation: The server uses mail server software to execute the receiving process. The server listens on a specific port, and when it receives new mail, it writes it to a temporary directory.
[1051] Step 2:
[1052] Email analysis
[1053] Input: Mail files saved in a temporary directory
[1054] Processing: The server analyzes the email header information and body, extracting sender address, recipient address, subject, date, links, attachments, etc.
[1055] Output: Analyzed header information and body content
[1056] Specific operation: The server executes a Python script and parses header information using the email package. It uses BeautifulSoup to identify links and attachments from the HTML body. The extracted information is recorded in a database and log files.
[1057] Step 3:
[1058] Security scan
[1059] Input: Parsed header information and body content
[1060] Processing: The server performs virus scanning and spam / phishing detection using machine learning models.
[1061] Output: Security scan evaluation results
[1062] Specific operation: The server uses ClamAV to scan attachments and the email body for viruses. It also runs a TensorFlow machine learning model to analyze the email body and determine if it is phishing or spam.
[1063] Step 4:
[1064] Emotion analysis
[1065] Input: Analyzed email body
[1066] Processing: The server activates an emotion engine to classify the email content into positive, negative, or neutral emotions.
[1067] Output: Results of sentiment analysis
[1068] Specific operation: The server sends the email body to the IBM Watson Tone Analyzer API and retrieves the returned sentiment classification result. The result is classified as either positive, negative, or neutral.
[1069] Step 5:
[1070] Credibility assessment and final action decision
[1071] Input: Security scan evaluation results and sentiment analysis results
[1072] Processing: The server integrates these results, evaluates the authenticity of the email, and determines the appropriate action.
[1073] Output: Determination of the email delivery destination (inbox or quarantine folder)
[1074] Specific operation: The server runs a credibility assessment algorithm and calculates a final score. Based on the score, if the email is deemed safe, it is delivered to the inbox; if deemed dangerous, it is moved to a quarantine folder. In addition, if negative sentiment is detected, a detailed analysis is performed and an alert is sent to the administrator if necessary.
[1075] (Application Example 2)
[1076] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".
[1077] Traditional email systems prioritize security to protect users from viruses, malware, phishing, and spam. However, this alone lacks consideration for the emotional stress and negative feelings users experience, meaning certain emails can cause significant emotional distress. Therefore, a system is needed that integrates security scanning with sentiment analysis, considering the impact on users' emotions along with evaluating the reliability of emails.
[1078] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means. In this invention, the server includes means for receiving emails, means for analyzing the content of the emails, means for performing a security scan based on the analyzed content, an emotion engine having the function of recognizing and classifying emotions based on the content and contextual information of the emails, and means for determining the final email action, including an evaluation of the emotion engine. This makes it possible to detect viruses and malware, quarantine spam emails, and reduce the emotional stress on the user.
[1079] "Means of receiving email" refers to the function that allows a server to retrieve emails from a user's email client.
[1080] "Means for analyzing the contents of the email" refers to the process of analyzing the header information, body, links, and attachments of a received email and extracting data for security and sentiment evaluation.
[1081] "Means for performing a security scan based on the analyzed content" refers to a function that compares the analyzed email content with a virus and malware signature database to detect phishing and spam patterns.
[1082] "Means for evaluating the authenticity of an email based on the results of the security scan" refers to algorithms or machine learning models used to evaluate whether an email is trustworthy based on the results of the security scan.
[1083] A "sentiment engine that recognizes and classifies emotions based on email content and contextual information" is a system that analyzes specific keywords and contextual patterns within an email body and classifies the emotions (positive, negative, or neutral) a user feels when reading the email.
[1084] "Means for determining the final email action, including the evaluation of the sentiment engine" refers to logic that integrates the results of security scans and sentiment evaluations to determine the final action, such as sending or quarantining the email.
[1085] The system for realizing this invention provides a function that, upon receiving an email from a user, analyzes the email with high accuracy and evaluates its reliability and emotional impact using a security scan and sentiment engine. Specifically, the following processes take place between the server, terminal, and user.
[1086] The system first has the function of receiving new emails from the user's email client. The received emails are stored on the server, and then a process of analyzing the email header information and body begins. The header information extracted includes the sender address, recipient address, subject, and date, and these are recorded in the log. In the body analysis, links and attachments are also identified and analyzed separately.
[1087] Next, the server performs a security scan. This process compares the analyzed email text, links, and attachments against a database of virus and malware signatures. Machine learning models are also used to detect phishing and spam patterns. Furthermore, a natural language processing (NLP) engine is used to analyze the context of the email and assess whether it is legitimate business communication.
[1088] In addition, the system's signature emotion engine is activated. Based on the email body and contextual information, the emotion engine identifies specific keywords and patterns and classifies them as positive, negative, or neutral. This emotion classification result is integrated with the results of the aforementioned security scan and complements the final email authenticity assessment.
[1089] Based on the credibility assessment, the server decides what to do with the email. For example, emails deemed safe by the security check are delivered to the regular inbox, while emails suspected of being spam or phishing, or those classified as potentially causing negative emotions, are moved to a quarantine folder. In cases of high importance, an alert may also be sent to the administrator.
[1090] To perform these processes, the server implements machine learning models using libraries such as Python and TensorFlow, a natural language processing engine, and spam / phishing detection algorithms. User information, email data, and analysis results are stored in the database.
[1091] Specific example
[1092] When a user receives a new email on their smartphone, it is sent to the server where its header information and body are analyzed. A security scan is then performed to check for viruses. The sentiment engine analyzes the email's context, and if it determines that the email may evoke negative emotions, it is moved to a quarantine folder. The user receives a warning notification at this time.
[1093] Example of a prompt
[1094] "Implement a system that performs security and sentiment analysis on newly received emails and takes appropriate actions to help users maintain positive emotions."
[1095] This system allows users to enjoy a safe and comfortable email environment that is free from spam and phishing emails, and also takes emotional impact into consideration.
[1096] The flow of a specific process in Application Example 2 will be explained using Figure 14.
[1097] Step 1:
[1098] The server receives a new email from the user's email client. At this point, the input data is the raw data of the received email. The server retrieves this data and stores it as an email object.
[1099] Step 2:
[1100] The server analyzes the header information and body of received emails. The header information analysis extracts the sender address, recipient address, subject, date, etc. The input data requires an email object, and the output is the analyzed header information. Specifically, this information is extracted and logged using the Python email library.
[1101] Step 3:
[1102] The server parses the email body to identify links and attachments. The input is the email object and its body text, and the output is a list of identified links and attachments. This is accomplished using Python's regular expressions and URL parsing libraries.
[1103] Step 4:
[1104] The server performs a security scan. At this stage, the email body, links, and attachments are compared against a database of virus and malware signatures. The input data consists of each part of the email being analyzed, and the output is the scan result (e.g., safe, virus detected, suspected phishing, etc.). This process is performed using ClamAV or the VirusTotal API.
[1105] Step 5:
[1106] The server uses machine learning models to detect phishing and spam patterns. The input is email text data, and the output is a spam score and a phishing score. This is done using models from Scikit-learn or TensorFlow.
[1107] Step 6:
[1108] The server uses a natural language processing (NLP) engine to analyze the context of emails. The input data is the email body, and the output is an evaluation result of whether the email is legitimate business communication. Context analysis is performed using Python's nltk and spaCy libraries.
[1109] Step 7:
[1110] The server operates an emotion engine that recognizes and classifies emotions based on the email body and context. The input data is the email body and contextual information, and the output is the emotion classification result (positive, negative, or neutral). This is done using a pre-trained TensorFlow model.
[1111] Step 8:
[1112] The server integrates the results of security scans and the sentiment engine to evaluate the final authenticity of the email. The input data consists of the results of each scan and sentiment classification, and the output is the overall evaluation result. Based on this, the processing action for the email (for example, safe emails go to the inbox, suspicious emails go to the quarantine folder) is determined.
[1113] Step 9:
[1114] The server performs email actions based on the evaluation results. The input data is the final overall evaluation result, and the output is the sorting of emails into the user's inbox or quarantine folder. Specifically, emails deemed safe are delivered to the regular inbox, while emails identified as spam or phishing are moved to the quarantine folder.
[1115] This series of processes will allow users to enjoy a safe and emotionally sensitive email environment.
[1116] The specific processing unit 290 transmits the result of the specific processing to the robot 414. In the robot 414, the control unit 46A causes the speaker 240 and the controlled object 443 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.
[1117] Data generation model 58 is a type of so-called generative AI (Artificial Intelligence). One example of data generation model 58 is ChatGPT (Internet search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[1118] In the above embodiment, an example was given in which the specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and the specific processing may also be performed by the robot 414.
[1119] Furthermore, the emotion identification model 59, acting as an emotion engine, may determine the user's emotion according to a specific mapping. Specifically, the emotion identification model 59 may determine the user's emotion according to a specific mapping, which is an emotion map (see Figure 9). Similarly, the emotion identification model 59 may also determine the robot's emotion, and the identification processing unit 290 may perform identification processing using the robot's emotion.
[1120] Figure 9 shows an emotion map 400 in which multiple emotions are mapped. In the emotion map 400, emotions are arranged in concentric circles radiating from the center. The closer to the center of the concentric circles, the more primitive the emotions are located. Further out of the concentric circles, emotions representing states and actions arising from mental states are located. Emotion is a concept that includes feelings and mental states. On the left side of the concentric circles, emotions that are generally generated from reactions occurring in the brain are located. On the right side of the concentric circles, emotions that are generally induced by situational judgment are located. Above and below the concentric circles, emotions that are generally generated from reactions occurring in the brain and induced by situational judgment are located. In addition, the emotion of "pleasure" is located on the upper side of the concentric circles, and the emotion of "displeasure" is located on the lower side. Thus, in the emotion map 400, multiple emotions are mapped based on the structure in which emotions arise, and emotions that are likely to occur simultaneously are mapped close together.
[1121] These emotions are distributed at the 3 o'clock position on the Emotion Map 400, and usually fluctuate between feelings of security and anxiety. In the right half of the Emotion Map 400, situational awareness takes precedence over internal feelings, resulting in a calm impression.
[1122] The inside of the Emotion Map 400 represents inner thoughts, while the outside represents actions. Therefore, the further you go from the outside of the Emotion Map 400, the more visible (expressed in actions) your emotions become.
[1123] Here, human emotions are based on various balances, such as posture and blood sugar levels. When these balances deviate from the ideal, it results in discomfort, and when they approach the ideal, it results in pleasure. Similarly, in robots, cars, motorcycles, etc., emotions can be created based on various balances, such as posture and battery level. When these balances deviate from the ideal, it results in discomfort, and when they approach the ideal, it results in pleasure. The emotion map can be generated, for example, based on Dr. Mitsuyoshi's emotion map (Research on a system for analyzing brain physiological signals of speech emotion recognition and emotion, Tokushima University, doctoral dissertation: https: / / ci.nii.ac.jp / naid / 500000375379). The left half of the emotion map contains emotions belonging to a region called "response," where sensation is dominant. The right half of the emotion map contains emotions belonging to a region called "situation," where situational awareness is dominant.
[1124] The emotion map defines two emotions that promote learning. One is the emotion around the middle of the negative "repentance" and "reflection" on the situation side. In other words, it is when the robot experiences negative emotions such as "I never want to feel this way again" or "I don't want to be scolded again." The other is the emotion around the positive "desire" on the reaction side. In other words, it is when the robot has positive feelings such as "I want more" or "I want to know more."
[1125] The emotion identification model 59 inputs user input into a pre-trained neural network, obtains emotion values representing each emotion shown in the emotion map 400, and determines the user's emotion. This neural network is pre-trained based on multiple training data sets, which are combinations of user input and emotion values representing each emotion shown in the emotion map 400. Furthermore, this neural network is trained so that emotions located close together have similar values, as shown in the emotion map 900 in Figure 10. Figure 10 shows an example where multiple emotions such as "reassured," "calm," and "confident" have similar emotion values.
[1126] The above description primarily focuses on the functions of the data processing device 12 in relation to this disclosure. However, the system related to this disclosure is not necessarily implemented on a server. The system related to this disclosure may be implemented as a general information processing system. This disclosure may be implemented, for example, as a software program that runs on a personal computer or as an application that runs on a smartphone. The method related to this disclosure may be provided to users in SaaS (Software as a Service) format.
[1127] In the above embodiment, an example was given in which a specific process is performed by a single computer 22. However, the technology of this disclosure is not limited thereto, and a distributed processing of the specific process may be performed by multiple computers, including computer 22. For example, a data generation model 58 may be provided in an external device of the data processing device 12, and the external device may generate data according to the input data.
[1128] In the above embodiment, an example was given in which the specific processing program 56 is stored in the storage 32, but the technology of this disclosure is not limited thereto. For example, the specific processing program 56 may be stored in a portable, computer-readable, non-temporary storage medium such as a USB (Universal Serial Bus) memory. The specific processing program 56 stored in the non-temporary storage medium is installed in the computer 22 of the data processing device 12. The processor 28 executes specific processing according to the specific processing program 56.
[1129] Alternatively, the specific processing program 56 may be stored in a storage device such as a server connected to the data processing device 12 via the network 54, and the specific processing program 56 may be downloaded and installed on the computer 22 in response to a request from the data processing device 12.
[1130] Furthermore, it is not necessary to store the entirety of the specific processing program 56 in a storage device such as a server connected to the data processing device 12 via the network 54, or to store the entirety of the specific processing program 56 in the storage 32; it is acceptable to store only a portion of the specific processing program 56.
[1131] The following types of processors can be used as hardware resources to perform specific processing. Examples of processors include a CPU, a general-purpose processor that functions as a hardware resource to perform specific processing by executing software, i.e., a program. Other examples of processors include dedicated electrical circuits, such as FPGAs (Field-Programmable Gate Arrays), PLDs (Programmable Logic Devices), or ASICs (Application Specific Integrated Circuits), which have circuit configurations specifically designed to perform specific processing. All of these processors have built-in or connected memory, and all of them perform specific processing by using memory.
[1132] The hardware resource that performs a specific process may consist of one of these various processors, or it may consist of a combination of two or more processors of the same or different types (for example, a combination of multiple FPGAs, or a combination of a CPU and an FPGA). Alternatively, the hardware resource that performs a specific process may consist of a single processor.
[1133] Examples of configurations using a single processor include, firstly, a configuration in which one or more CPUs and software are combined to form a single processor, and this processor functions as a hardware resource that performs a specific process. Secondly, there is a configuration using a processor that realizes the functions of the entire system, including multiple hardware resources that perform a specific process, on a single IC chip, as exemplified by SoCs (System-on-a-chip). In this way, a specific process is realized using one or more of the above types of processors as hardware resources.
[1134] Furthermore, the hardware structure of these various processors can more specifically utilize electrical circuits that combine circuit elements such as semiconductor devices. Also, the specific processing described above is merely an example. Therefore, it goes without saying that unnecessary steps can be deleted, new steps added, or the processing order rearranged, as long as it does not deviate from the main purpose.
[1135] The descriptions and illustrations presented above are detailed explanations of the technical aspects of this disclosure and are merely examples of the technical aspects. For example, the above descriptions of the structure, function, operation, and effect are examples of the structure, function, operation, and effect of the technical aspects of this disclosure. Therefore, it goes without saying that you may delete unnecessary parts, add new elements, or replace elements in the descriptions and illustrations presented above, as long as you do not deviate from the essence of the technical aspects of this disclosure. Furthermore, in order to avoid confusion and facilitate understanding of the technical aspects of this disclosure, explanations of common technical knowledge and the like that do not require special explanation to enable the implementation of the technical aspects of this disclosure have been omitted from the descriptions and illustrations presented above.
[1136] All documents, patent applications, and technical standards described herein are incorporated by reference to the same extent as if each individual document, patent application, and technical standard were specifically and individually noted to be incorporated by reference.
[1137] The following is further disclosed regarding the embodiments described above.
[1138] Understood. Below is a draft of the claims relating to a secure email filtering system.
[1139] (Claim 1)
[1140] Means of receiving emails,
[1141] A means for analyzing the contents of the aforementioned email,
[1142] A means for performing a security scan based on the analyzed content,
[1143] A means for evaluating the authenticity of an email based on the results of the security scan,
[1144] A means for determining an email action based on the evaluated results,
[1145] A system that includes this.
[1146] (Claim 2)
[1147] The system according to claim 1, which includes a function to verify whether the means for performing the security scan matches the signature of a virus or malware.
[1148] (Claim 3)
[1149] The system according to claim 1, comprising means for moving spam emails to a quarantine folder based on the results of the evaluation.
[1150] "Example 1"
[1151] (Claim 1)
[1152] Means of receiving emails,
[1153] A means for analyzing the contents of the aforementioned email,
[1154] A means for performing a security scan based on the analyzed content,
[1155] A means for evaluating the authenticity of an email based on the results of the security scan and additional analysis results,
[1156] A means for determining an email action based on the evaluated results,
[1157] A means of sending an alert to the administrator when a high-level threat is detected,
[1158] A system that includes this.
[1159] (Claim 2)
[1160] The system according to claim 1, comprising a means for performing the security scan, a function for verifying whether it matches the signature of a virus or malware, and a function for detecting phishing or spam using a machine learning model.
[1161] (Claim 3)
[1162] The system according to claim 1, comprising means for evaluating the credibility of an email using a generative AI model and natural language processing technology based on the evaluated results.
[1163] "Application Example 1"
[1164] (Claim 1)
[1165] Means of receiving emails,
[1166] A means for analyzing the contents of the aforementioned email,
[1167] A means for performing a security scan based on the analyzed content,
[1168] A means for evaluating the authenticity of an email based on the results of the security scan,
[1169] A means for determining an email action based on the evaluated results,
[1170] A method for detecting phishing and spam patterns using machine learning models,
[1171] A means for sending notifications to the user in real time based on the evaluation results,
[1172] A system that includes this.
[1173] (Claim 2)
[1174] The system according to claim 1, which includes a function to verify whether the means for performing the security scan matches the signature of a virus or malware.
[1175] (Claim 3)
[1176] The system according to claim 1, comprising means for moving spam emails to a quarantine folder based on the results of the evaluation.
[1177] "Example 2 of combining an emotion engine"
[1178] (Claim 1)
[1179] Means of receiving emails,
[1180] A means for analyzing the contents of the aforementioned email,
[1181] A means for performing a security scan based on the analyzed content,
[1182] A means for evaluating the authenticity of an email based on the results of the security scan,
[1183] A means for determining an email action based on the evaluated results,
[1184] A means to recognize the emotions in emails using an emotion analysis engine and to complement credibility evaluation,
[1185] A system that includes this.
[1186] (Claim 2)
[1187] The system according to claim 1, comprising a function to verify whether the means for performing the security scan matches the signature of a virus or malicious program.
[1188] (Claim 3)
[1189] The system according to claim 1, comprising means for moving malicious emails to a quarantine folder based on the results of the evaluation.
[1190] "Application example 2 when combining with an emotional engine"
[1191] (Claim 1)
[1192] Means of receiving emails,
[1193] A means for analyzing the contents of the aforementioned email,
[1194] A means for performing a security scan based on the analyzed content,
[1195] A means for evaluating the authenticity of an email based on the results of the security scan,
[1196] An emotion engine that has the function of recognizing and classifying emotions based on the content and contextual information of an email,
[1197] A means for determining the final email action, including the evaluation of the aforementioned emotion engine,
[1198] A system that includes this.
[1199] (Claim 2)
[1200] The system according to claim 1, which includes a function to verify whether the means for performing the security scan matches the signature of a virus or malware.
[1201] (Claim 3)
[1202] The system according to claim 1, comprising means for moving emails determined to be spam or phishing to a quarantine folder based on the results of the evaluation. [Explanation of Symbols]
[1203] 10, 210, 310, 410 Data Processing Systems 12 Data Processing Devices 14 Smart Devices 214 Smart Glasses 314 Headset-type terminal 414 Robots< / url:> < / url:> < / url:> < / url:>
Claims
1. Means of receiving emails, A means for analyzing the contents of the aforementioned email, A means for performing a security scan based on the analyzed content, A means for evaluating the authenticity of an email based on the results of the security scan, A means for determining an email action based on the evaluated results, A system that includes this.
2. The system according to claim 1, which includes a function to verify whether the means for performing the security scan matches the signature of a virus or malware.
3. The system according to claim 1, comprising means for moving spam emails to a quarantine folder based on the results of the evaluation.
Citation Information
Patent Citations
Persona chatbot control method and system
JP2022180282A