system

The system addresses real-time detection and response to security threats by using AI for collecting, analyzing, and automatically blocking abnormal activities, enhancing system and network security.

JP2026066712APending Publication Date: 2026-04-17SOFTBANK GROUP CORP
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
SOFTBANK GROUP CORP
Filing Date
2024-10-07
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

Existing systems face challenges in detecting abnormal activities in real time and responding quickly to security threats.

Method used

A system comprising a collection unit, an analysis unit, and a blocking unit that collects, analyzes, and automatically blocks security threats in response to abnormal activity, utilizing AI for real-time detection and response.

Benefits of technology

Enables real-time detection and automatic blocking of security threats, preventing incidents and allowing for quick administrator action through countermeasure proposals.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026066712000001_ABST
    Figure 2026066712000001_ABST
Patent Text Reader

Abstract

The system according to this embodiment aims to detect abnormal activity in the system and network in real time and automatically block security threats. [Solution] The system according to the embodiment comprises a collection unit, an analysis unit, and a blocking unit. The collection unit collects activity data of the system or network. The analysis unit analyzes the data collected by the collection unit and detects abnormal activity. The blocking unit automatically blocks security threats against the abnormal activity detected by the analysis unit.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The technology of the present disclosure relates to a system.

Background Art

[0002] Patent Document 1 discloses a method for controlling a persona chatbot, which is performed by at least one processor and includes steps of receiving a user utterance, adding the user utterance to a prompt including an instruction sentence related to an explanation of a chatbot character, encoding the prompt, and inputting the encoded prompt into a language model to generate a chatbot utterance in response to the user utterance.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] In the conventional technology, there is a problem that it is difficult to detect abnormal activities of a system or network in real time and respond quickly.

[0005] The system according to the embodiment aims to detect abnormal activities of a system or network in real time and automatically block security threats.

Means for Solving the Problems

[0006] The system according to this embodiment comprises a collection unit, an analysis unit, and a blocking unit. The collection unit collects activity data of the system or network. The analysis unit analyzes the data collected by the collection unit and detects abnormal activity. The blocking unit automatically blocks security threats in response to the abnormal activity detected by the analysis unit. [Effects of the Invention]

[0007] The system according to this embodiment can detect abnormal activity in the system and network in real time and automatically block security threats. [Brief explanation of the drawing]

[0008] [Figure 1] This is a conceptual diagram showing an example of the configuration of a data processing system according to the first embodiment. [Figure 2] This is a conceptual diagram showing an example of the essential functions of a data processing device and a smart device according to the first embodiment. [Figure 3] This is a conceptual diagram showing an example of the configuration of a data processing system according to the second embodiment. [Figure 4] This is a conceptual diagram showing an example of the main functions of a data processing device and smart glasses according to the second embodiment. [Figure 5] This is a conceptual diagram showing an example of the configuration of a data processing system according to the third embodiment. [Figure 6] This is a conceptual diagram showing an example of the main functions of a data processing device and a headset-type terminal according to the third embodiment. [Figure 7] This is a conceptual diagram showing an example of the configuration of a data processing system according to the fourth embodiment. [Figure 8] This is a conceptual diagram showing an example of the main functions of a data processing device and a robot according to the fourth embodiment. [Figure 9] This shows an emotion map where multiple emotions are mapped. [Figure 10] This shows an emotion map where multiple emotions are mapped. [Modes for carrying out the invention]

[0009] Hereinafter, an example of an embodiment of the system relating to the technology of this disclosure will be described with reference to the attached drawings.

[0010] First, let's explain the terminology used in the following explanation.

[0011] In the following embodiments, the signed processor (hereinafter simply referred to as "processor") may be a single arithmetic unit or a combination of multiple arithmetic units. Furthermore, the processor may be a single type of arithmetic unit or a combination of multiple types of arithmetic units. Examples of arithmetic units include CPU (Central Processing Unit), GPU (Graphics Processing Unit), GPGPU (General-Purpose computing on Graphics Processing Units), APU (Accelerated Processing Unit), or TPU (Tensor Processing Unit).

[0012] In the following embodiments, signed RAM (Random Access Memory) is a memory that temporarily stores information and is used as work memory by the processor.

[0013] In the following embodiments, the signed storage is one or more non-volatile storage devices that store various programs and various parameters. Examples of non-volatile storage devices include flash memory (SSD (Solid State Drive)), magnetic disks (e.g., hard disks), or magnetic tapes.

[0014] In the following embodiments, the labeled communication I / F (Interface) is an interface including a communication processor, an antenna, and the like. The communication I / F manages communication between a plurality of computers. Examples of communication standards applied to the communication I / F include wireless communication standards such as 5G (5th Generation Mobile Communication System), Wi-Fi (registered trademark), or Bluetooth (registered trademark).

[0015] In the following embodiments, "A and / or B" is synonymous with "at least one of A and B". That is, "A and / or B" means that it may be only A, only B, or a combination of A and B. Also, in this specification, when expressing three or more matters connected by "and / or", the same concept as "A and / or B" is applied.

[0016] [First Embodiment] FIG. 1 shows an example of the configuration of a data processing system 10 according to the first embodiment.

[0017] As shown in FIG. 1, the data processing system 10 includes a data processing device 12 and a smart device 14. An example of the data processing device 12 is a server.

[0018] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. Also, the database 24 and the communication I / F 26 are connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[0019] The smart device 14 comprises a computer 36, a receiving device 38, an output device 40, a camera 42, and a communication interface 44. The computer 36 comprises a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The receiving device 38, output device 40, and camera 42 are also connected to the bus 52.

[0020] The reception device 38 is equipped with a touch panel 38A and a microphone 38B, and accepts user input. The touch panel 38A accepts user input via touch by detecting contact with an object (e.g., a pen or finger). The microphone 38B accepts user input via voice by detecting the user's voice. The control unit 46A transmits data indicating the user input received by the touch panel 38A and microphone 38B to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 (see Figure 2) acquires the data indicating the user input.

[0021] The output device 40 includes a display 40A and a speaker 40B, and presents data to the user by outputting the data in a form perceptible to the user (e.g., audio and / or text). The display 40A displays visible information such as text and images according to instructions from the processor 46. The speaker 40B outputs audio according to instructions from the processor 46. The camera 42 is a small digital camera equipped with an optical system such as a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor.

[0022] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various types of information between processor 46 and processor 28 via network 54.

[0023] Figure 2 shows an example of the main functions of the data processing device 12 and the smart device 14.

[0024] As shown in Figure 2, in the data processing device 12, a specific processing is performed by the processor 28. A specific processing program 56 is stored in the storage 32. The specific processing program 56 is an example of a "program" related to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 according to the specific processing program 56 executed on the RAM 30.

[0025] Storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290. The identification processing unit 290 can estimate the user's emotions using the emotion identification model 59 and perform identification processing using the user's emotions. The emotion estimation function (emotion identification function) using the emotion identification model 59 performs various estimations and predictions regarding the user's emotions, including but not limited to these examples. Furthermore, emotion estimation and prediction also include, for example, emotion analysis.

[0026] In the smart device 14, specific processing is performed by the processor 46. The storage 50 stores a specific processing program 60. The specific processing program 60 is used in conjunction with the specific processing program 56 by the data processing system 10. The processor 46 reads the specific processing program 60 from the storage 50 and executes the read specific processing program 60 on the RAM 48. The specific processing is realized by the processor 46 operating as a control unit 46A according to the specific processing program 60 executed on the RAM 48. The smart device 14 also has a data generation model 58 and an emotion identification model 59, similar to the data generation model and emotion identification model 59, and can perform processing similar to that of the specific processing unit 290 using these models.

[0027] Furthermore, other devices besides the data processing device 12 may also have the data generation model 58. For example, a server device (e.g., a generation server) may have the data generation model 58. In this case, the data processing device 12 obtains processing results (such as prediction results) using the data generation model 58 by communicating with the server device having the data generation model 58. The data processing device 12 may also be a server device or a terminal device owned by a user (e.g., a mobile phone, robot, home appliance, etc.). Next, an example of processing by the data processing system 10 according to the first embodiment will be described.

[0028] (Example of form 1) The AI ​​assistant for information security according to an embodiment of the present invention is a system that detects abnormal activity in systems and networks in real time, automatically blocks security threats, and proposes countermeasures. The AI ​​assistant for information security collects activity data from systems and networks, and the AI ​​analyzes it to detect abnormal activity. In response to the detected abnormal activity, the AI ​​automatically blocks security threats and proposes countermeasures. This mechanism strengthens the security of systems and networks and enables rapid response. For example, the AI ​​assistant for information security collects activity data from systems and networks. In this process, it collects detailed data such as various log data and traffic data. For example, this includes access logs and communication logs. This allows for an understanding of the overall activity status of the system and network. Next, the AI ​​analyzes the collected data. The AI ​​analyzes the collected data in real time and detects abnormal activity. For example, it can detect unusual access patterns and communication patterns. This allows for the early detection of potential security threats. In response to the detected abnormal activity, the AI ​​automatically blocks security threats. For example, it can automatically block unauthorized access and malware communication. This allows for countermeasures to be taken before security threats affect the system or network. Furthermore, the AI ​​proposes countermeasures for detected anomalous activity. For example, it can suggest changes to specific security settings or the implementation of additional security measures. This allows system administrators to take quick and appropriate action. This mechanism strengthens system and network security and enables rapid response. For instance, by detecting anomalous activity in real time and automatically blocking security threats, security incidents can be prevented from occurring. In addition, the proposed countermeasures allow system administrators to take quick and appropriate action. This improves system and network security and ensures overall safety.This allows the AI ​​assistant for information security support to detect abnormal activity in systems and networks in real time and automatically block security threats.

[0029] The AI ​​assistant for information security according to this embodiment comprises a collection unit, an analysis unit, and a block unit. The collection unit collects system and network activity data. System and network activity data includes, but is not limited to, log data, traffic data, and user activity data. The collection unit collects various log data, such as system logs, application logs, and security logs. The collection unit can also collect traffic data, such as network traffic and packet data. Furthermore, the collection unit can collect user activity data, such as user operation history and access history. For example, the collection unit collects system logs in real time to detect abnormal login attempts or a series of authentication failures. Application logs monitor the operating status of specific applications and detect abnormal behavior. Security logs record security events across the entire system and detect abnormal access or attacks. The analysis unit analyzes the data collected by the collection unit and detects abnormal activity. The analysis unit detects, for example, unusual access patterns or communication patterns. Unusual access patterns include, for example, a sudden increase in access frequency or an abnormality in the source IP address. Unusual communication patterns include, for example, sudden spikes in traffic volume and the use of abnormal protocols. The analysis unit can detect these abnormal patterns in real time, enabling early detection of potential security threats. For example, the analysis unit can detect sudden spikes in access frequency, allowing for early detection of signs of a DDoS attack. It can also detect abnormal protocol usage, enabling early detection of malware communication. Furthermore, the analysis unit can detect abnormal source IP addresses, enabling early detection of signs of unauthorized access. The blocking unit automatically blocks security threats in response to abnormal activity detected by the analysis unit. For example, the blocking unit automatically blocks unauthorized access and malware communication. Unauthorized access includes, for example, a series of authentication failures and abnormal login attempts. Malware communication includes, for example, known malware communication patterns and abnormal external communications.The blocking unit can intercept these security threats in real time and address them before they affect the system or network. For example, the blocking unit can detect a series of authentication failures and automatically block fraudulent login attempts. It can also detect known malware communication patterns and automatically block malware communications. Furthermore, the blocking unit can detect abnormal external communications and automatically block fraudulent data transmissions. As a result, the information security support AI assistant according to the embodiment can detect abnormal activity in the system and network in real time and automatically block security threats.

[0030] The data collection unit collects system and network activity data. This data includes, but is not limited to, log data, traffic data, and user activity data. The unit collects various types of log data, such as system logs, application logs, and security logs. Specifically, system logs record system startup and shutdown, error messages, and system resource usage, and are used to understand the overall system operation. Application logs record the operation of specific applications in detail and are used to detect application errors and abnormal behavior. Security logs record system-wide security events and play a crucial role in detecting abnormal access and attacks. The data collection unit collects this log data in real time and transmits it to a central database. Furthermore, the data collection unit can also collect traffic data, such as network traffic and packet data. Network traffic data is used to monitor the flow of data on the network and detect abnormal traffic patterns and malicious communications. Packet data provides detailed information about individual data packets on the network and is used to analyze communication content and protocol usage. Additionally, the data collection unit can collect user activity data, such as user operation history and access history. User activity data records user login history, file access history, and operation history, and is used to understand user behavior patterns. For example, the data collection unit collects system logs in real time to detect abnormal login attempts and consecutive authentication failures. Application logs monitor the operation status of specific applications and detect abnormal behavior. Security logs record security events across the entire system and detect abnormal access and attacks. This allows the data collection unit to collect a wide range of data from diverse data sources and understand the status of the system and network in real time. Furthermore, the data collection unit can centrally manage this data and collaborate with other systems and departments as needed.For example, collected data is stored on a cloud server, making it accessible to the analysis and block divisions. Furthermore, by adjusting the frequency and accuracy of data collection, flexible responses to specific situations and conditions become possible. This allows the data collection unit to collect data efficiently and effectively, improving the overall system performance.

[0031] The analysis unit analyzes data collected by the collection unit and detects abnormal activity. For example, the analysis unit detects unusual access patterns and communication patterns. Specifically, it uses AI to analyze data in real time and identify abnormal patterns. Unusual access patterns include, for example, a sudden increase in access frequency or abnormal source IP addresses. A sudden increase in access frequency may indicate a DDoS attack, and the analysis unit can prevent system overload by detecting this early. Abnormal source IP addresses may indicate unauthorized access, and the analysis unit can identify potential attackers by detecting this. Unusual communication patterns include, for example, a sudden increase in traffic volume or the use of abnormal protocols. A sudden increase in traffic volume may indicate malware activity or data leakage, and the analysis unit can minimize damage by detecting this early. The use of abnormal protocols may indicate malware communication or unauthorized data transmission, and the analysis unit can detect this early to discover potential threats. The analysis unit can detect these abnormal patterns in real time and discover potential security threats early. For example, the analysis unit can detect a surge in access frequency and identify early signs of a DDoS attack. It can also detect unusual protocol usage and identify malware communications early. Furthermore, it can detect unusual source IP addresses and identify early signs of unauthorized access. The analysis unit can also utilize historical data and statistical information to perform long-term risk assessments and trend analyses. For instance, it can predict risk fluctuations in specific time periods or regions based on past attack data and formulate future countermeasures. Additionally, the analysis unit can use anomaly detection algorithms to detect unusual patterns and abnormal data, issuing early warnings. This allows the analysis unit to not only grasp the situation in real time but also to handle long-term risk management and anomaly detection, improving the overall reliability and security of the system.

[0032] The blocking unit automatically blocks security threats in response to abnormal activity detected by the analysis unit. For example, the blocking unit automatically blocks unauthorized access and malware communications. Unauthorized access includes, for example, a series of authentication failures and abnormal login attempts. A series of authentication failures may indicate a brute-force attack, and when the blocking unit detects this, it can prevent the attack by temporarily blocking the corresponding IP address. Abnormal login attempts may indicate unauthorized access, and when the blocking unit detects this, it can enhance security by temporarily locking the corresponding account. Malware communications include, for example, known malware communication patterns and abnormal external communications. Known malware communication patterns are identified based on past attack data, and when the blocking unit detects them, it can prevent the spread of malware by immediately blocking the corresponding communications. Abnormal external communications may indicate data leakage or unauthorized data transmission, and when the blocking unit detects this, it can prevent information leakage by blocking the corresponding communications. The blocking unit can block these security threats in real time and address them before they affect the system or network. For example, the blocking unit can detect a series of authentication failures and automatically block fraudulent login attempts. It can also detect known malware communication patterns and automatically block malware communications. Furthermore, it can detect abnormal external communications and automatically block unauthorized data transmissions. This allows the blocking unit to detect abnormal system and network activity in real time and automatically block security threats. Additionally, the blocking unit can issue warnings to users and prompt them to take necessary actions. For instance, if an abnormal login attempt is detected, it sends a notification to the user prompting them to change their password. Similarly, if malware communications are detected, it sends a notification to the user prompting them to scan the system and remove the malware. This allows the blocking unit to not only automatically block security threats but also improve overall system security by prompting users to take appropriate action.

[0033] The proposal unit proposes countermeasures for detected abnormal activity. For example, the proposal unit proposes changes to specific security settings or the implementation of additional security measures. Changes to specific security settings include, for example, changes to firewall settings or updates to access control lists. Additional security measures include, for example, the installation of antivirus software or the application of security patches. The proposal unit proposes these countermeasures in real time, enabling system administrators to take quick and appropriate action. For example, the proposal unit proposes changes to firewall settings to prevent unauthorized access. The proposal unit can also propose updates to access control lists to restrict access from specific IP addresses. Furthermore, the proposal unit can propose the installation of antivirus software to prevent malware infection. This enables quick and appropriate responses by proposing countermeasures for abnormal activity. Some or all of the above processing in the proposal unit may be performed using, for example, AI, or not using AI. For example, the proposal unit can input data on detected abnormal activity into a generating AI and have the generating AI generate countermeasures.

[0034] The collection unit can collect various log data or traffic data. For example, the collection unit collects various log data such as system logs, application logs, and security logs. For example, the collection unit can collect system logs in real time to detect abnormal login attempts or a series of authentication failures. The collection unit can also collect application logs to monitor the operation status of a specific application and detect abnormal behavior. The collection unit can also collect security logs to record security events across the entire system and detect abnormal access or attacks. The collection unit can also collect traffic data such as network traffic and packet data. For example, the collection unit can monitor network traffic in real time and detect abnormal communication patterns. The collection unit can also collect packet data to detect abnormal protocol usage or sudden increases in traffic volume. This allows for a comprehensive understanding of the overall activity of the system and network by collecting detailed data. Some or all of the above-described processes in the collection unit may be performed using AI, for example, or without AI. For example, the collection unit can input system logs into a generating AI and have the generating AI detect abnormal login attempts or a series of authentication failures.

[0035] The analysis unit can detect unusual access patterns or communication patterns. For example, the analysis unit can detect unusual access patterns such as a sudden increase in access frequency or an abnormal access source IP address. The analysis unit can also detect unusual communication patterns such as a sudden increase in traffic volume or the use of abnormal protocols. The analysis unit can detect these abnormal patterns in real time and detect potential security threats early. For example, the analysis unit can detect a sudden increase in access frequency and detect early signs of a DDoS attack. The analysis unit can also detect abnormal protocol usage and detect malware communication early. Furthermore, the analysis unit can detect abnormal access source IP addresses and detect early signs of unauthorized access. This allows for the early detection of potential security threats. Some or all of the above-described processes in the analysis unit may be performed using AI, for example, or without AI. For example, the analysis unit can input collected data into a generating AI and have the generating AI perform the detection of abnormal patterns.

[0036] The blocking unit can block unauthorized access or malware communications. For example, it can block unauthorized access such as a series of authentication failures or abnormal login attempts. It can also block malware communications such as known malware communication patterns or abnormal external communications. The blocking unit can block these security threats in real time and address them before they affect the system or network. For example, the blocking unit can detect a series of authentication failures and automatically block unauthorized login attempts. It can also detect known malware communication patterns and automatically block malware communications. Furthermore, it can detect abnormal external communications and automatically block unauthorized data transmissions. This allows security threats to be addressed before they affect the system or network. Some or all of the above processing in the blocking unit may be performed using AI, for example, or without AI. For example, the blocking unit can input data on detected abnormal activity into a generating AI and have the generating AI perform the blocking.

[0037] The proposal unit can propose changes to specific security settings or additional security measures. For example, the proposal unit may propose changes to specific security settings, such as changing firewall settings or updating access control lists. The proposal unit may also propose additional security measures, such as installing antivirus software or applying security patches. The proposal unit proposes these countermeasures in real time, enabling system administrators to take quick and appropriate action. For example, the proposal unit may propose changing firewall settings to prevent unauthorized access. It may also propose updating access control lists to restrict access from specific IP addresses. Furthermore, the proposal unit may propose installing antivirus software to prevent malware infection. This enables system administrators to take quick and appropriate action. Some or all of the above processing in the proposal unit may be performed using AI, for example, or not using AI. For example, the proposal unit may input data on detected abnormal activity into a generating AI and have the generating AI generate countermeasures.

[0038] The data collection unit can dynamically change the frequency of data collection according to the system's operating status. For example, the data collection unit may decrease the frequency of data collection when the system is under heavy load. For example, the data collection unit may increase the frequency of data collection when the system is under light load. The data collection unit may adjust the frequency of data collection in real time according to the system's operating status. This allows for efficient data collection by adjusting the frequency of data collection according to the system's operating status. Some or all of the above-described processes in the data collection unit may be performed using AI, for example, or without AI. For example, the data collection unit may input system operating status data into a generating AI and have the generating AI adjust the frequency of data collection.

[0039] The data collection unit can expand the scope of data collection based on specific time periods or events. For example, the data collection unit expands the scope of data collection when an important event occurs. For example, the data collection unit broadens the scope of data collection during a specific time period. For example, the data collection unit dynamically adjusts the scope of data collection according to the importance of the event. This enables more detailed data collection during important events or specific time periods. Some or all of the above processing in the data collection unit may be performed using AI, for example, or without AI. For example, the data collection unit can input data for a specific time period or event into a generating AI and have the generating AI perform the expansion of the data collection scope.

[0040] The data collection unit can select data collection targets based on the geographical location of the system. For example, the data collection unit selects important data collection targets based on the geographical location of the system. For example, the data collection unit dynamically changes the data collection targets according to the geographical location. For example, the data collection unit determines the priority of data collection considering the geographical location. This allows for the selection of important data collection targets based on the geographical location of the system. Some or all of the above processing in the data collection unit may be performed using AI, for example, or without AI. For example, the data collection unit can input geographical location data of the system into a generating AI and have the generating AI perform the selection of data collection targets.

[0041] The collection unit can integrate and collect data from external security information sources. For example, the collection unit can collect data from external security information sources in real time. For example, the collection unit can integrate data from external security information sources to perform detailed data collection. For example, the collection unit can adjust the types of data to be collected based on the data from external security information sources. This makes it possible to collect more detailed data by integrating data from external security information sources. Some or all of the above processing in the collection unit may be performed using AI, for example, or without AI. For example, the collection unit can input data from external security information sources into a generating AI and have the generating AI perform data integration.

[0042] The analysis unit can optimize the analysis algorithm by referring to past abnormal activity data. For example, the analysis unit optimizes the analysis algorithm based on past abnormal activity data. For example, the analysis unit analyzes patterns of abnormal activity and adjusts the analysis algorithm. For example, the analysis unit improves the accuracy of detecting abnormal activity by referring to past data. As a result, the accuracy of detecting abnormal activity is improved by optimizing the analysis algorithm based on past data. Some or all of the above processes in the analysis unit may be performed using AI, for example, or without using AI. For example, the analysis unit can input past abnormal activity data into a generating AI and have the generating AI perform the optimization of the analysis algorithm.

[0043] The analysis unit can focus on specific system components and perform detailed analyses. For example, the analysis unit can focus on specific system components and perform detailed analyses. For example, the analysis unit can perform abnormal activity analyses for each system component. For example, the analysis unit can perform detailed analyses of abnormal activity for specific components. This makes detailed analysis of specific system components possible. Some or all of the above-described processes in the analysis unit may be performed using AI, for example, or without AI. For example, the analysis unit can input data of specific system components into a generating AI and have the generating AI perform a detailed analysis.

[0044] The analysis unit can identify abnormal activity based on the geographical location of the system. The analysis unit identifies abnormal activity based on the geographical location of the system, for example. The analysis unit identifies abnormal activity considering the geographical location, for example. The analysis unit determines the priority of abnormal activity according to the geographical location, for example. This makes it possible to identify abnormal activity based on the geographical location of the system. Some or all of the above processing in the analysis unit may be performed using AI, for example, or without AI. For example, the analysis unit can input geographical location data of the system into a generating AI and have the generating AI perform the identification of abnormal activity.

[0045] The analysis unit can integrate and analyze data from external security information sources. For example, the analysis unit integrates data from external security information sources to perform a detailed analysis. For example, the analysis unit identifies anomalous activity based on data from external security information sources. For example, the analysis unit optimizes the analysis algorithm by referring to data from external security information sources. This enables a detailed analysis by integrating data from external security information sources. Some or all of the above processes in the analysis unit may be performed using AI, for example, or without AI. For example, the analysis unit can input data from external security information sources into a generating AI and have the generating AI perform the analysis.

[0046] The block unit can optimize the block algorithm by referring to past block data. For example, the block unit optimizes the block algorithm based on past block data. For example, the block unit analyzes block patterns and adjusts the block algorithm. For example, the block unit improves block accuracy by referring to past data. This improves block accuracy by optimizing the block algorithm based on past data. Some or all of the above processes in the block unit may be performed using AI, for example, or without AI. For example, the block unit can input past block data into a generating AI and have the generating AI perform the optimization of the block algorithm.

[0047] The blocking unit can perform detailed blocking by focusing on specific system components. For example, the blocking unit can perform detailed blocking by focusing on specific system components. For example, the blocking unit can adjust the blocking method for each system component. For example, the blocking unit can provide a detailed method for blocking specific components. This enables detailed blocking for specific system components. Some or all of the above-described processes in the blocking unit may be performed using AI, for example, or without AI. For example, the blocking unit can input data for specific system components into a generating AI and have the generating AI perform detailed blocking.

[0048] The block unit can select targets to be blocked based on the geographical location of the system. For example, the block unit selects targets to be blocked based on the geographical location of the system. For example, the block unit dynamically changes the targets to be blocked, taking geographical location into consideration. For example, the block unit determines the priority of blocks, taking geographical location into consideration. This allows for the selection of targets to be blocked based on the geographical location of the system. Some or all of the above-described processes in the block unit may be performed using AI, for example, or without AI. For example, the block unit can input geographical location data of the system into a generating AI and have the generating AI perform the selection of targets to be blocked.

[0049] The blocking unit can integrate data from external security information sources to perform blocking. For example, the blocking unit selects targets for blocking based on data from external security information sources. For example, the blocking unit performs detailed blocking by integrating data from external security information sources. For example, the blocking unit optimizes the blocking algorithm by referring to data from external security information sources. This enables detailed blocking by integrating data from external security information sources. Some or all of the above-described processes in the blocking unit may be performed using AI, for example, or without AI. For example, the blocking unit can input data from external security information sources into a generating AI and have the generating AI perform the blocking.

[0050] The proposal unit can optimize the proposal algorithm by referring to past proposal data. For example, the proposal unit optimizes the proposal algorithm based on past proposal data. For example, the proposal unit analyzes proposal patterns and adjusts the proposal algorithm. For example, the proposal unit improves the accuracy of proposals by referring to past data. As a result, the accuracy of proposals is improved by optimizing the proposal algorithm based on past data. Some or all of the above processes in the proposal unit may be performed using AI, for example, or without AI. For example, the proposal unit can input past proposal data into a generating AI and have the generating AI perform the optimization of the proposal algorithm.

[0051] The proposal unit can focus on specific system components and make detailed proposals. For example, the proposal unit can focus on specific system components and make detailed proposals. For example, the proposal unit can adjust the content of the proposal for each system component. For example, the proposal unit can provide detailed proposals for specific components. This makes it possible to make detailed proposals for specific system components. Some or all of the above processing in the proposal unit may be performed using AI, for example, or not using AI. For example, the proposal unit can input data for specific system components into a generating AI and have the generating AI execute detailed proposals.

[0052] The proposal unit can select proposals based on the geographical location of the system. For example, the proposal unit selects proposals based on the geographical location of the system. For example, the proposal unit dynamically changes the content of proposals considering the geographical location. For example, the proposal unit determines the priority of proposals considering the geographical location. This allows the proposal to be selected based on the geographical location of the system. Some or all of the above processes in the proposal unit may be performed using AI, for example, or without AI. For example, the proposal unit can input geographical location data of the system into a generating AI and have the generating AI perform the selection of proposals.

[0053] The proposal unit can integrate data from external security information sources to make proposals. For example, the proposal unit selects proposal content based on data from external security information sources. For example, the proposal unit integrates data from external security information sources to make detailed proposals. For example, the proposal unit optimizes the proposal algorithm by referring to data from external security information sources. This makes it possible to make detailed proposals by integrating data from external security information sources. Some or all of the above processes in the proposal unit may be performed using AI, for example, or without AI. For example, the proposal unit can input data from external security information sources into a generating AI and have the generating AI execute the proposals.

[0054] The system according to the embodiment is not limited to the example described above, and various modifications are possible, for example, as follows.

[0055] The AI ​​assistant for information security support can also be equipped with a predictive unit. The predictive unit predicts future security threats based on data obtained from the collection and analysis units. For example, it can analyze past anomalous activity data and predict the likelihood of similar patterns recurring. The predictive unit can also predict potential security risks based on system operating status and network traffic fluctuations. Furthermore, the predictive unit can integrate data from external security sources and make predictions based on the latest threat information. This allows system administrators to take preventative measures and prevent security incidents from occurring.

[0056] The AI ​​assistant for information security support can also include an audit department. This department regularly audits the security status of systems and networks and reports any problems. For example, it can detect security configuration flaws and vulnerabilities and report them to administrators. Furthermore, the audit department can analyze changes in security status based on past audit data and propose improvements. In addition, the audit department can conduct audits based on external security standards and regulations to ensure compliance. This allows for continuous monitoring and improvement of the security status of systems and networks.

[0057] The AI ​​assistant for information security support can also include an analytics department. This department analyzes collected data in detail to identify the root causes of security threats. For example, it can identify the source of anomalous activity and the attacker's methods, providing information for countermeasures. Furthermore, the analytics department can analyze security threat trends based on historical data and predict future risks. It can also integrate data from external security sources and perform analysis based on the latest threat intelligence. This allows system administrators to implement more effective security measures.

[0058] The AI ​​assistant for information security support can also be equipped with a statistics department. This department performs statistical analysis based on collected data to understand security threat trends. For example, it can analyze the frequency and types of anomalous activity to evaluate the effectiveness of security measures. Furthermore, the statistics department can build predictive models of security threats based on historical data to forecast future risks. In addition, the statistics department can integrate data from external security sources to perform more accurate analysis. This enables system administrators to implement data-driven and effective security measures.

[0059] The AI ​​assistant for information security support can also be equipped with a simulation unit. This unit simulates security threats in a virtual environment and verifies the effectiveness of countermeasures. For example, it can simulate DDoS attacks and malware infections to assess system vulnerabilities. The simulation unit can also pre-verify the effectiveness of proposed countermeasures and select the optimal solution. Furthermore, the simulation unit can simulate the latest threat scenarios based on data from external security sources. This allows system administrators to prepare for actual security incidents.

[0060] The following briefly describes the processing flow for example form 1.

[0061] Step 1: The collection unit collects system and network activity data. Specifically, it collects various log data such as system logs, application logs, and security logs, traffic data such as network traffic and packet data, and user activity data such as user operation history and access history. For example, the collection unit collects system logs in real time to detect abnormal login attempts or a series of authentication failures. Application logs monitor the operation status of specific applications and detect abnormal behavior. Security logs record security events across the entire system and detect abnormal access or attacks. Step 2: The analysis unit analyzes the data collected by the collection unit and detects abnormal activity. Specifically, it detects unusual access patterns and communication patterns. For example, it detects sudden increases in access frequency, abnormal source IP addresses, sudden increases in communication volume, and abnormal protocol usage. The analysis unit detects these abnormal patterns in real time, enabling early detection of potential security threats. For example, it can detect sudden increases in access frequency to identify early signs of a DDoS attack. It can also detect abnormal protocol usage to identify malware communication early. Furthermore, it can detect abnormal source IP addresses to identify early signs of unauthorized access. Step 3: The blocking unit automatically blocks security threats in response to abnormal activity detected by the analysis unit. Specifically, it automatically blocks unauthorized access and malware communications. Unauthorized access includes consecutive authentication failures and abnormal login attempts. Malware communications include known malware communication patterns and abnormal external communications. The blocking unit blocks these security threats in real time and addresses them before they affect the system or network. For example, it can detect consecutive authentication failures and automatically block unauthorized login attempts. It can also detect known malware communication patterns and automatically block malware communications. Furthermore, it can detect abnormal external communications and automatically block unauthorized data transmissions.

[0062] (Example of form 2) The AI ​​assistant for information security according to an embodiment of the present invention is a system that detects abnormal activity in systems and networks in real time, automatically blocks security threats, and proposes countermeasures. The AI ​​assistant for information security collects activity data from systems and networks, and the AI ​​analyzes it to detect abnormal activity. In response to the detected abnormal activity, the AI ​​automatically blocks security threats and proposes countermeasures. This mechanism strengthens the security of systems and networks and enables rapid response. For example, the AI ​​assistant for information security collects activity data from systems and networks. In this process, it collects detailed data such as various log data and traffic data. For example, this includes access logs and communication logs. This allows for an understanding of the overall activity status of the system and network. Next, the AI ​​analyzes the collected data. The AI ​​analyzes the collected data in real time and detects abnormal activity. For example, it can detect unusual access patterns and communication patterns. This allows for the early detection of potential security threats. In response to the detected abnormal activity, the AI ​​automatically blocks security threats. For example, it can automatically block unauthorized access and malware communication. This allows for countermeasures to be taken before security threats affect the system or network. Furthermore, the AI ​​proposes countermeasures for detected anomalous activity. For example, it can suggest changes to specific security settings or the implementation of additional security measures. This allows system administrators to take quick and appropriate action. This mechanism strengthens system and network security and enables rapid response. For instance, by detecting anomalous activity in real time and automatically blocking security threats, security incidents can be prevented from occurring. In addition, the proposed countermeasures allow system administrators to take quick and appropriate action. This improves system and network security and ensures overall safety.This allows the AI ​​assistant for information security support to detect abnormal activity in systems and networks in real time and automatically block security threats.

[0063] The AI ​​assistant for information security according to this embodiment comprises a collection unit, an analysis unit, and a block unit. The collection unit collects system and network activity data. System and network activity data includes, but is not limited to, log data, traffic data, and user activity data. The collection unit collects various log data, such as system logs, application logs, and security logs. The collection unit can also collect traffic data, such as network traffic and packet data. Furthermore, the collection unit can collect user activity data, such as user operation history and access history. For example, the collection unit collects system logs in real time to detect abnormal login attempts or a series of authentication failures. Application logs monitor the operating status of specific applications and detect abnormal behavior. Security logs record security events across the entire system and detect abnormal access or attacks. The analysis unit analyzes the data collected by the collection unit and detects abnormal activity. The analysis unit detects, for example, unusual access patterns or communication patterns. Unusual access patterns include, for example, a sudden increase in access frequency or an abnormality in the source IP address. Unusual communication patterns include, for example, sudden spikes in traffic volume and the use of abnormal protocols. The analysis unit can detect these abnormal patterns in real time, enabling early detection of potential security threats. For example, the analysis unit can detect sudden spikes in access frequency, allowing for early detection of signs of a DDoS attack. It can also detect abnormal protocol usage, enabling early detection of malware communication. Furthermore, the analysis unit can detect abnormal source IP addresses, enabling early detection of signs of unauthorized access. The blocking unit automatically blocks security threats in response to abnormal activity detected by the analysis unit. For example, the blocking unit automatically blocks unauthorized access and malware communication. Unauthorized access includes, for example, a series of authentication failures and abnormal login attempts. Malware communication includes, for example, known malware communication patterns and abnormal external communications.The blocking unit can intercept these security threats in real time and address them before they affect the system or network. For example, the blocking unit can detect a series of authentication failures and automatically block fraudulent login attempts. It can also detect known malware communication patterns and automatically block malware communications. Furthermore, the blocking unit can detect abnormal external communications and automatically block fraudulent data transmissions. As a result, the information security support AI assistant according to the embodiment can detect abnormal activity in the system and network in real time and automatically block security threats.

[0064] The data collection unit collects system and network activity data. This data includes, but is not limited to, log data, traffic data, and user activity data. The unit collects various types of log data, such as system logs, application logs, and security logs. Specifically, system logs record system startup and shutdown, error messages, and system resource usage, and are used to understand the overall system operation. Application logs record the operation of specific applications in detail and are used to detect application errors and abnormal behavior. Security logs record system-wide security events and play a crucial role in detecting abnormal access and attacks. The data collection unit collects this log data in real time and transmits it to a central database. Furthermore, the data collection unit can also collect traffic data, such as network traffic and packet data. Network traffic data is used to monitor the flow of data on the network and detect abnormal traffic patterns and malicious communications. Packet data provides detailed information about individual data packets on the network and is used to analyze communication content and protocol usage. Additionally, the data collection unit can collect user activity data, such as user operation history and access history. User activity data records user login history, file access history, and operation history, and is used to understand user behavior patterns. For example, the data collection unit collects system logs in real time to detect abnormal login attempts and consecutive authentication failures. Application logs monitor the operation status of specific applications and detect abnormal behavior. Security logs record security events across the entire system and detect abnormal access and attacks. This allows the data collection unit to collect a wide range of data from diverse data sources and understand the status of the system and network in real time. Furthermore, the data collection unit can centrally manage this data and collaborate with other systems and departments as needed.For example, collected data is stored on a cloud server, making it accessible to the analysis and block divisions. Furthermore, by adjusting the frequency and accuracy of data collection, flexible responses to specific situations and conditions become possible. This allows the data collection unit to collect data efficiently and effectively, improving the overall system performance.

[0065] The analysis unit analyzes data collected by the collection unit and detects abnormal activity. For example, the analysis unit detects unusual access patterns and communication patterns. Specifically, it uses AI to analyze data in real time and identify abnormal patterns. Unusual access patterns include, for example, a sudden increase in access frequency or abnormal source IP addresses. A sudden increase in access frequency may indicate a DDoS attack, and the analysis unit can prevent system overload by detecting this early. Abnormal source IP addresses may indicate unauthorized access, and the analysis unit can identify potential attackers by detecting this. Unusual communication patterns include, for example, a sudden increase in traffic volume or the use of abnormal protocols. A sudden increase in traffic volume may indicate malware activity or data leakage, and the analysis unit can minimize damage by detecting this early. The use of abnormal protocols may indicate malware communication or unauthorized data transmission, and the analysis unit can detect this early to discover potential threats. The analysis unit can detect these abnormal patterns in real time and discover potential security threats early. For example, the analysis unit can detect a surge in access frequency and identify early signs of a DDoS attack. It can also detect unusual protocol usage and identify malware communications early. Furthermore, it can detect unusual source IP addresses and identify early signs of unauthorized access. The analysis unit can also utilize historical data and statistical information to perform long-term risk assessments and trend analyses. For instance, it can predict risk fluctuations in specific time periods or regions based on past attack data and formulate future countermeasures. Additionally, the analysis unit can use anomaly detection algorithms to detect unusual patterns and abnormal data, issuing early warnings. This allows the analysis unit to not only grasp the situation in real time but also to handle long-term risk management and anomaly detection, improving the overall reliability and security of the system.

[0066] The blocking unit automatically blocks security threats in response to abnormal activity detected by the analysis unit. For example, the blocking unit automatically blocks unauthorized access and malware communications. Unauthorized access includes, for example, a series of authentication failures and abnormal login attempts. A series of authentication failures may indicate a brute-force attack, and when the blocking unit detects this, it can prevent the attack by temporarily blocking the corresponding IP address. Abnormal login attempts may indicate unauthorized access, and when the blocking unit detects this, it can enhance security by temporarily locking the corresponding account. Malware communications include, for example, known malware communication patterns and abnormal external communications. Known malware communication patterns are identified based on past attack data, and when the blocking unit detects them, it can prevent the spread of malware by immediately blocking the corresponding communications. Abnormal external communications may indicate data leakage or unauthorized data transmission, and when the blocking unit detects this, it can prevent information leakage by blocking the corresponding communications. The blocking unit can block these security threats in real time and address them before they affect the system or network. For example, the blocking unit can detect a series of authentication failures and automatically block fraudulent login attempts. It can also detect known malware communication patterns and automatically block malware communications. Furthermore, it can detect abnormal external communications and automatically block unauthorized data transmissions. This allows the blocking unit to detect abnormal system and network activity in real time and automatically block security threats. Additionally, the blocking unit can issue warnings to users and prompt them to take necessary actions. For instance, if an abnormal login attempt is detected, it sends a notification to the user prompting them to change their password. Similarly, if malware communications are detected, it sends a notification to the user prompting them to scan the system and remove the malware. This allows the blocking unit to not only automatically block security threats but also improve overall system security by prompting users to take appropriate action.

[0067] The proposal unit proposes countermeasures for detected abnormal activity. For example, the proposal unit proposes changes to specific security settings or the implementation of additional security measures. Changes to specific security settings include, for example, changes to firewall settings or updates to access control lists. Additional security measures include, for example, the installation of antivirus software or the application of security patches. The proposal unit proposes these countermeasures in real time, enabling system administrators to take quick and appropriate action. For example, the proposal unit proposes changes to firewall settings to prevent unauthorized access. The proposal unit can also propose updates to access control lists to restrict access from specific IP addresses. Furthermore, the proposal unit can propose the installation of antivirus software to prevent malware infection. This enables quick and appropriate responses by proposing countermeasures for abnormal activity. Some or all of the above processing in the proposal unit may be performed using, for example, AI, or not using AI. For example, the proposal unit can input data on detected abnormal activity into a generating AI and have the generating AI generate countermeasures.

[0068] The collection unit can collect various log data or traffic data. For example, the collection unit collects various log data such as system logs, application logs, and security logs. For example, the collection unit can collect system logs in real time to detect abnormal login attempts or a series of authentication failures. The collection unit can also collect application logs to monitor the operation status of a specific application and detect abnormal behavior. The collection unit can also collect security logs to record security events across the entire system and detect abnormal access or attacks. The collection unit can also collect traffic data such as network traffic and packet data. For example, the collection unit can monitor network traffic in real time and detect abnormal communication patterns. The collection unit can also collect packet data to detect abnormal protocol usage or sudden increases in traffic volume. This allows for a comprehensive understanding of the overall activity of the system and network by collecting detailed data. Some or all of the above-described processes in the collection unit may be performed using AI, for example, or without AI. For example, the collection unit can input system logs into a generating AI and have the generating AI detect abnormal login attempts or a series of authentication failures.

[0069] The analysis unit can detect unusual access patterns or communication patterns. For example, the analysis unit can detect unusual access patterns such as a sudden increase in access frequency or an abnormal access source IP address. The analysis unit can also detect unusual communication patterns such as a sudden increase in traffic volume or the use of abnormal protocols. The analysis unit can detect these abnormal patterns in real time and detect potential security threats early. For example, the analysis unit can detect a sudden increase in access frequency and detect early signs of a DDoS attack. The analysis unit can also detect abnormal protocol usage and detect malware communication early. Furthermore, the analysis unit can detect abnormal access source IP addresses and detect early signs of unauthorized access. This allows for the early detection of potential security threats. Some or all of the above-described processes in the analysis unit may be performed using AI, for example, or without AI. For example, the analysis unit can input collected data into a generating AI and have the generating AI perform the detection of abnormal patterns.

[0070] The blocking unit can block unauthorized access or malware communications. For example, it can block unauthorized access such as a series of authentication failures or abnormal login attempts. It can also block malware communications such as known malware communication patterns or abnormal external communications. The blocking unit can block these security threats in real time and address them before they affect the system or network. For example, the blocking unit can detect a series of authentication failures and automatically block unauthorized login attempts. It can also detect known malware communication patterns and automatically block malware communications. Furthermore, it can detect abnormal external communications and automatically block unauthorized data transmissions. This allows security threats to be addressed before they affect the system or network. Some or all of the above processing in the blocking unit may be performed using AI, for example, or without AI. For example, the blocking unit can input data on detected abnormal activity into a generating AI and have the generating AI perform the blocking.

[0071] The proposal unit can propose changes to specific security settings or additional security measures. For example, the proposal unit may propose changes to specific security settings, such as changing firewall settings or updating access control lists. The proposal unit may also propose additional security measures, such as installing antivirus software or applying security patches. The proposal unit proposes these countermeasures in real time, enabling system administrators to take quick and appropriate action. For example, the proposal unit may propose changing firewall settings to prevent unauthorized access. It may also propose updating access control lists to restrict access from specific IP addresses. Furthermore, the proposal unit may propose installing antivirus software to prevent malware infection. This enables system administrators to take quick and appropriate action. Some or all of the above processing in the proposal unit may be performed using AI, for example, or not using AI. For example, the proposal unit may input data on detected abnormal activity into a generating AI and have the generating AI generate countermeasures.

[0072] The data collection unit can estimate the user's emotions and adjust the type of data collected based on the estimated emotions. For example, if the user is stressed, the data collection unit will perform simple data collection and avoid detailed data collection. For example, if the user is relaxed, the data collection unit will perform detailed data collection and gather more information. For example, if the user is in a hurry, the data collection unit will prioritize collecting only important data. This allows for more appropriate data collection by adjusting the type of data collected according to the user's emotions. Emotion estimation is achieved using an emotion estimation function, for example, using an emotion engine or generative AI. Generative AI is, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI. Some or all of the above processing in the data collection unit may be performed using AI or not using AI. For example, the data collection unit can input user emotion data into a generative AI and have the generative AI adjust the type of data to be collected.

[0073] The data collection unit can dynamically change the frequency of data collection according to the system's operating status. For example, the data collection unit may decrease the frequency of data collection when the system is under heavy load. For example, the data collection unit may increase the frequency of data collection when the system is under light load. The data collection unit may adjust the frequency of data collection in real time according to the system's operating status. This allows for efficient data collection by adjusting the frequency of data collection according to the system's operating status. Some or all of the above-described processes in the data collection unit may be performed using AI, for example, or without AI. For example, the data collection unit may input system operating status data into a generating AI and have the generating AI adjust the frequency of data collection.

[0074] The data collection unit can expand the scope of data collection based on specific time periods or events. For example, the data collection unit expands the scope of data collection when an important event occurs. For example, the data collection unit broadens the scope of data collection during a specific time period. For example, the data collection unit dynamically adjusts the scope of data collection according to the importance of the event. This enables more detailed data collection during important events or specific time periods. Some or all of the above processing in the data collection unit may be performed using AI, for example, or without AI. For example, the data collection unit can input data for a specific time period or event into a generating AI and have the generating AI perform the expansion of the data collection scope.

[0075] The data collection unit can estimate the user's emotions and determine the priority of data to collect based on the estimated user emotions. For example, if the user is stressed, the data collection unit will prioritize collecting important data. For example, if the user is relaxed, the data collection unit will prioritize collecting detailed data. For example, if the user is in a hurry, the data collection unit will prioritize collecting data that can be collected quickly. In this way, by prioritizing data according to the user's emotions, important data can be collected preferentially. Emotion estimation is achieved using an emotion estimation function, for example, using an emotion engine or generative AI. Generative AI is, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI. Some or all of the above processing in the data collection unit may be performed using AI, for example, or not using AI. For example, the data collection unit can input user emotion data into a generative AI and have the generative AI perform the determination of data prioritization.

[0076] The data collection unit can select data collection targets based on the geographical location of the system. For example, the data collection unit selects important data collection targets based on the geographical location of the system. For example, the data collection unit dynamically changes the data collection targets according to the geographical location. For example, the data collection unit determines the priority of data collection considering the geographical location. This allows for the selection of important data collection targets based on the geographical location of the system. Some or all of the above processing in the data collection unit may be performed using AI, for example, or without AI. For example, the data collection unit can input geographical location data of the system into a generating AI and have the generating AI perform the selection of data collection targets.

[0077] The collection unit can integrate and collect data from external security information sources. For example, the collection unit can collect data from external security information sources in real time. For example, the collection unit can integrate data from external security information sources to perform detailed data collection. For example, the collection unit can adjust the types of data to be collected based on the data from external security information sources. This makes it possible to collect more detailed data by integrating data from external security information sources. Some or all of the above processing in the collection unit may be performed using AI, for example, or without AI. For example, the collection unit can input data from external security information sources into a generating AI and have the generating AI perform data integration.

[0078] The analysis unit can estimate the user's emotions and adjust the display method of the analysis results based on the estimated user emotions. For example, if the user is tense, the analysis unit provides a simple and highly visible display method. For example, if the user is relaxed, the analysis unit provides a display method that includes detailed information. For example, if the user is in a hurry, the analysis unit provides a display method that gets straight to the point. By adjusting the display method of the analysis results according to the user's emotions, it becomes possible to provide more appropriate information. Emotion estimation is achieved using an emotion estimation function, for example, using an emotion engine or a generative AI. The generative AI is a text generation AI (e.g., LLM) or a multimodal generation AI, but is not limited to such examples. Some or all of the above processing in the analysis unit may be performed using AI, for example, or without AI. For example, the analysis unit can input user emotion data into the generative AI and have the generative AI adjust the display method of the analysis results.

[0079] The analysis unit can optimize the analysis algorithm by referring to past abnormal activity data. For example, the analysis unit optimizes the analysis algorithm based on past abnormal activity data. For example, the analysis unit analyzes patterns of abnormal activity and adjusts the analysis algorithm. For example, the analysis unit improves the accuracy of detecting abnormal activity by referring to past data. As a result, the accuracy of detecting abnormal activity is improved by optimizing the analysis algorithm based on past data. Some or all of the above processes in the analysis unit may be performed using AI, for example, or without using AI. For example, the analysis unit can input past abnormal activity data into a generating AI and have the generating AI perform the optimization of the analysis algorithm.

[0080] The analysis unit can focus on specific system components and perform detailed analyses. For example, the analysis unit can focus on specific system components and perform detailed analyses. For example, the analysis unit can perform abnormal activity analyses for each system component. For example, the analysis unit can perform detailed analyses of abnormal activity for specific components. This makes detailed analysis of specific system components possible. Some or all of the above-described processes in the analysis unit may be performed using AI, for example, or without AI. For example, the analysis unit can input data of specific system components into a generating AI and have the generating AI perform a detailed analysis.

[0081] The analysis unit can estimate the user's emotions and determine the priority of analysis based on the estimated emotions. For example, if the user is tense, the analysis unit will prioritize important analyses. For example, if the user is relaxed, the analysis unit will prioritize detailed analyses. For example, if the user is in a hurry, the analysis unit will prioritize items that can be analyzed quickly. In this way, by determining the priority of analysis according to the user's emotions, important analyses can be prioritized. Emotion estimation is achieved using an emotion estimation function, for example, using an emotion engine or generative AI. Generative AI is, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI. Some or all of the above processing in the analysis unit may be performed using AI, for example, or not using AI. For example, the analysis unit can input user emotion data into a generative AI and have the generative AI determine the priority of analysis.

[0082] The analysis unit can identify abnormal activity based on the geographical location of the system. The analysis unit identifies abnormal activity based on the geographical location of the system, for example. The analysis unit identifies abnormal activity considering the geographical location, for example. The analysis unit determines the priority of abnormal activity according to the geographical location, for example. This makes it possible to identify abnormal activity based on the geographical location of the system. Some or all of the above processing in the analysis unit may be performed using AI, for example, or without AI. For example, the analysis unit can input geographical location data of the system into a generating AI and have the generating AI perform the identification of abnormal activity.

[0083] The analysis unit can integrate and analyze data from external security information sources. For example, the analysis unit integrates data from external security information sources to perform a detailed analysis. For example, the analysis unit identifies anomalous activity based on data from external security information sources. For example, the analysis unit optimizes the analysis algorithm by referring to data from external security information sources. This enables a detailed analysis by integrating data from external security information sources. Some or all of the above processes in the analysis unit may be performed using AI, for example, or without AI. For example, the analysis unit can input data from external security information sources into a generating AI and have the generating AI perform the analysis.

[0084] The blocking unit can estimate the user's emotions and adjust the blocking method based on the estimated emotions. For example, if the user is tense, the blocking unit provides a simple and quick blocking method. For example, if the user is relaxed, the blocking unit provides a detailed blocking method. For example, if the user is in a hurry, the blocking unit provides a method that allows for quick blocking. This allows for more appropriate blocking by adjusting the blocking method according to the user's emotions. Emotion estimation is achieved using an emotion estimation function, for example, using an emotion engine or generative AI. The generative AI is, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI. Some or all of the above processing in the blocking unit may be performed using AI, for example, or without AI. For example, the blocking unit can input user emotion data into the generative AI and have the generative AI perform the adjustment of the blocking method.

[0085] The block unit can optimize the block algorithm by referring to past block data. For example, the block unit optimizes the block algorithm based on past block data. For example, the block unit analyzes block patterns and adjusts the block algorithm. For example, the block unit improves block accuracy by referring to past data. This improves block accuracy by optimizing the block algorithm based on past data. Some or all of the above processes in the block unit may be performed using AI, for example, or without AI. For example, the block unit can input past block data into a generating AI and have the generating AI perform the optimization of the block algorithm.

[0086] The blocking unit can perform detailed blocking by focusing on specific system components. For example, the blocking unit can perform detailed blocking by focusing on specific system components. For example, the blocking unit can adjust the blocking method for each system component. For example, the blocking unit can provide a detailed method for blocking specific components. This enables detailed blocking for specific system components. Some or all of the above-described processes in the blocking unit may be performed using AI, for example, or without AI. For example, the blocking unit can input data for specific system components into a generating AI and have the generating AI perform detailed blocking.

[0087] The blocking unit can estimate the user's emotions and determine the priority of blocks based on the estimated emotions. For example, if the user is tense, the blocking unit will prioritize important blocks. If the user is relaxed, the blocking unit will prioritize detailed blocks. If the user is in a hurry, the blocking unit will prioritize items that can be blocked quickly. In this way, by determining the priority of blocks according to the user's emotions, important blocks can be prioritized. Emotion estimation is achieved using an emotion estimation function, for example, using an emotion engine or generative AI. Generative AI is, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI. Some or all of the above processing in the blocking unit may be performed using AI or not using AI. For example, the blocking unit can input user emotion data into a generative AI and have the generative AI perform the determination of block priorities.

[0088] The block unit can select targets to be blocked based on the geographical location of the system. For example, the block unit selects targets to be blocked based on the geographical location of the system. For example, the block unit dynamically changes the targets to be blocked, taking geographical location into consideration. For example, the block unit determines the priority of blocks, taking geographical location into consideration. This allows for the selection of targets to be blocked based on the geographical location of the system. Some or all of the above-described processes in the block unit may be performed using AI, for example, or without AI. For example, the block unit can input geographical location data of the system into a generating AI and have the generating AI perform the selection of targets to be blocked.

[0089] The blocking unit can integrate data from external security information sources to perform blocking. For example, the blocking unit selects targets for blocking based on data from external security information sources. For example, the blocking unit performs detailed blocking by integrating data from external security information sources. For example, the blocking unit optimizes the blocking algorithm by referring to data from external security information sources. This enables detailed blocking by integrating data from external security information sources. Some or all of the above-described processes in the blocking unit may be performed using AI, for example, or without AI. For example, the blocking unit can input data from external security information sources into a generating AI and have the generating AI perform the blocking.

[0090] The suggestion unit can estimate the user's emotions and adjust the way suggestions are presented based on those emotions. For example, if the user is nervous, the suggestion unit will provide simple and easily understandable suggestions. If the user is relaxed, the suggestion unit will provide suggestions that include detailed information. If the user is in a hurry, the suggestion unit will provide suggestions that get straight to the point. By adjusting the way suggestions are presented according to the user's emotions, more appropriate suggestions can be made. Emotion estimation is achieved using an emotion estimation function, such as an emotion engine or generative AI. Generative AI may be, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI. Some or all of the above processing in the suggestion unit may be performed using AI or not. For example, the suggestion unit can input user emotion data into a generative AI and have the generative AI adjust the way suggestions are presented.

[0091] The proposal unit can optimize the proposal algorithm by referring to past proposal data. For example, the proposal unit optimizes the proposal algorithm based on past proposal data. For example, the proposal unit analyzes proposal patterns and adjusts the proposal algorithm. For example, the proposal unit improves the accuracy of proposals by referring to past data. As a result, the accuracy of proposals is improved by optimizing the proposal algorithm based on past data. Some or all of the above processes in the proposal unit may be performed using AI, for example, or without AI. For example, the proposal unit can input past proposal data into a generating AI and have the generating AI perform the optimization of the proposal algorithm.

[0092] The proposal unit can focus on specific system components and make detailed proposals. For example, the proposal unit can focus on specific system components and make detailed proposals. For example, the proposal unit can adjust the content of the proposal for each system component. For example, the proposal unit can provide detailed proposals for specific components. This makes it possible to make detailed proposals for specific system components. Some or all of the above processing in the proposal unit may be performed using AI, for example, or not using AI. For example, the proposal unit can input data for specific system components into a generating AI and have the generating AI execute detailed proposals.

[0093] The suggestion unit can estimate the user's emotions and determine the priority of suggestions based on the estimated emotions. For example, if the user is tense, the suggestion unit will prioritize important suggestions. For example, if the user is relaxed, the suggestion unit will prioritize detailed suggestions. For example, if the user is in a hurry, the suggestion unit will prioritize items that can be suggested quickly. In this way, by determining the priority of suggestions according to the user's emotions, important suggestions can be prioritized. Emotion estimation is achieved using an emotion estimation function, for example, using an emotion engine or generative AI. Generative AI is, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI. Some or all of the above processing in the suggestion unit may be performed using AI or not using AI. For example, the suggestion unit can input user emotion data into a generative AI and have the generative AI determine the priority of suggestions.

[0094] The proposal unit can select proposals based on the geographical location of the system. For example, the proposal unit selects proposals based on the geographical location of the system. For example, the proposal unit dynamically changes the content of proposals considering the geographical location. For example, the proposal unit determines the priority of proposals considering the geographical location. This allows the proposal to be selected based on the geographical location of the system. Some or all of the above processes in the proposal unit may be performed using AI, for example, or without AI. For example, the proposal unit can input geographical location data of the system into a generating AI and have the generating AI perform the selection of proposals.

[0095] The proposal unit can integrate data from external security information sources to make proposals. For example, the proposal unit selects proposal content based on data from external security information sources. For example, the proposal unit integrates data from external security information sources to make detailed proposals. For example, the proposal unit optimizes the proposal algorithm by referring to data from external security information sources. This makes it possible to make detailed proposals by integrating data from external security information sources. Some or all of the above processes in the proposal unit may be performed using AI, for example, or without AI. For example, the proposal unit can input data from external security information sources into a generating AI and have the generating AI execute the proposals.

[0096] The system according to the embodiment is not limited to the example described above, and various modifications are possible, for example, as follows.

[0097] The AI ​​assistant for information security support can also be equipped with a predictive unit. The predictive unit predicts future security threats based on data obtained from the collection and analysis units. For example, it can analyze past anomalous activity data and predict the likelihood of similar patterns recurring. The predictive unit can also predict potential security risks based on system operating status and network traffic fluctuations. Furthermore, the predictive unit can integrate data from external security sources and make predictions based on the latest threat information. This allows system administrators to take preventative measures and prevent security incidents from occurring.

[0098] The AI ​​assistant for information security support can also include a notification function. This notification function informs system administrators of detected anomalous activity and proposed countermeasures. For example, it can send real-time alerts to administrators when anomalous activity is detected. It can also send notifications with detailed explanations to administrators when countermeasures are proposed. Furthermore, the notification function can estimate the administrator's mood and select a notification method appropriate to the urgency. For example, if the administrator is stressed, it can send a concise and clear notification; if relaxed, it can send a notification with more detailed information. This allows administrators to respond quickly and appropriately.

[0099] The AI ​​assistant for information security support can also include an education function. This function provides security education to system administrators and users. For example, it can teach countermeasures and preventative measures based on past security incident cases. The education function can also provide information on the latest security threats, helping users acquire the knowledge to take appropriate measures. Furthermore, the education function can estimate the user's emotions and adjust the learning content and methods accordingly. For example, if the user is stressed, it can provide concise and easy-to-understand content; if relaxed, it can provide detailed information. This allows users to effectively acquire security knowledge.

[0100] The AI ​​assistant for information security support can also include an audit department. This department regularly audits the security status of systems and networks and reports any problems. For example, it can detect security configuration flaws and vulnerabilities and report them to administrators. Furthermore, the audit department can analyze changes in security status based on past audit data and propose improvements. In addition, the audit department can conduct audits based on external security standards and regulations to ensure compliance. This allows for continuous monitoring and improvement of the security status of systems and networks.

[0101] The AI ​​assistant for information security support can also include a backup function. This function helps to regularly back up critical data and system settings, enabling rapid recovery in the event of a security incident. For example, it can create regular system-wide backups and restore from the latest backup when abnormal activity is detected. The backup function can also verify the integrity of backup data, checking for corruption or tampering. Furthermore, it can estimate the user's mood and adjust the backup frequency and method accordingly. For example, if the user is stressed, it can offer a simple backup method; if relaxed, it can provide detailed backup instructions. This ensures the protection of critical data and rapid recovery.

[0102] The AI ​​assistant for information security support can also include an analytics department. This department analyzes collected data in detail to identify the root causes of security threats. For example, it can identify the source of anomalous activity and the attacker's methods, providing information for countermeasures. Furthermore, the analytics department can analyze security threat trends based on historical data and predict future risks. It can also integrate data from external security sources and perform analysis based on the latest threat intelligence. This allows system administrators to implement more effective security measures.

[0103] An AI assistant for information security support can also be equipped with a feedback function. This feedback function collects feedback from system administrators and users to improve the system. For example, it can collect feedback on the effectiveness and usability of proposed solutions and incorporate that feedback into system improvements. Furthermore, the feedback function can estimate the user's emotions and adjust the feedback collection method accordingly. For instance, if the user is stressed, feedback can be collected through a simple questionnaire; if they are relaxed, more detailed opinions can be requested. This allows for effective collection of user feedback to improve the system.

[0104] The AI ​​assistant for information security support can also be equipped with a statistics department. This department performs statistical analysis based on collected data to understand security threat trends. For example, it can analyze the frequency and types of anomalous activity to evaluate the effectiveness of security measures. Furthermore, the statistics department can build predictive models of security threats based on historical data to forecast future risks. In addition, the statistics department can integrate data from external security sources to perform more accurate analysis. This enables system administrators to implement data-driven and effective security measures.

[0105] The AI ​​assistant for information security support can also be equipped with a simulation unit. This unit simulates security threats in a virtual environment and verifies the effectiveness of countermeasures. For example, it can simulate DDoS attacks and malware infections to assess system vulnerabilities. The simulation unit can also pre-verify the effectiveness of proposed countermeasures and select the optimal solution. Furthermore, the simulation unit can simulate the latest threat scenarios based on data from external security sources. This allows system administrators to prepare for actual security incidents.

[0106] The AI ​​assistant for information security support can also include a reporting function. This function generates security reports periodically based on collected data and analysis results. For example, it can create monthly or quarterly reports and provide them to system administrators. Furthermore, the reporting function can estimate the user's mood and adjust the content and format of the reports accordingly. For instance, if the user is stressed, it can provide a concise and to-the-point report; if relaxed, it can provide a more detailed report. This allows system administrators to understand the security situation and take appropriate measures.

[0107] The following briefly describes the processing flow for example form 2.

[0108] Step 1: The collection unit collects system and network activity data. Specifically, it collects various log data such as system logs, application logs, and security logs, traffic data such as network traffic and packet data, and user activity data such as user operation history and access history. For example, the collection unit collects system logs in real time to detect abnormal login attempts or a series of authentication failures. Application logs monitor the operation status of specific applications and detect abnormal behavior. Security logs record security events across the entire system and detect abnormal access or attacks. Step 2: The analysis unit analyzes the data collected by the collection unit and detects abnormal activity. Specifically, it detects unusual access patterns and communication patterns. For example, it detects sudden increases in access frequency, abnormal source IP addresses, sudden increases in communication volume, and abnormal protocol usage. The analysis unit detects these abnormal patterns in real time, enabling early detection of potential security threats. For example, it can detect sudden increases in access frequency to identify early signs of a DDoS attack. It can also detect abnormal protocol usage to identify malware communication early. Furthermore, it can detect abnormal source IP addresses to identify early signs of unauthorized access. Step 3: The blocking unit automatically blocks security threats in response to abnormal activity detected by the analysis unit. Specifically, it automatically blocks unauthorized access and malware communications. Unauthorized access includes consecutive authentication failures and abnormal login attempts. Malware communications include known malware communication patterns and abnormal external communications. The blocking unit blocks these security threats in real time and addresses them before they affect the system or network. For example, it can detect consecutive authentication failures and automatically block unauthorized login attempts. It can also detect known malware communication patterns and automatically block malware communications. Furthermore, it can detect abnormal external communications and automatically block unauthorized data transmissions.

[0109] The specific processing unit 290 transmits the result of the specific processing to the smart device 14. In the smart device 14, the control unit 46A causes the output device 40 to output the result of the specific processing. The microphone 38B acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.

[0110] Data generation model 58 is a form of so-called generative AI (Artificial Intelligence). An example of data generation model 58 is ChatGPT (registered trademark) (Internet search).<URL: https: / / openai.com / blog / chatgpt> Examples of generative AI include text generation AI, image generation AI, and multimodal generation AI. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images (e.g., still image data or video data). The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference result in one or more data formats from audio data, text data, and image data. The data generation model 58 includes, for example, text generation AI, image generation AI, and multimodal generation AI. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization. The specific processing unit 290 performs the specific processing described above using the data generation model 58. The data generation model 58 may be a fine-tuned model that outputs inference results from prompts that do not contain instructions, in which case the data generation model 58 can output inference results from prompts that do not contain instructions. In the data processing device 12, etc., there are multiple types of data generation models 58, and the data generation model 58 includes AI other than generative AI. AI other than generative AI includes, for example, linear regression, logistic regression, decision trees, random forests, support vector machines (SVMs), k-means clustering, convolutional neural networks (CNNs), recurrent neural networks (RNNs), generative adversarial networks (GANs), or naive Bayes, and can perform various processes, but is not limited to these examples. Also, the AI ​​may be an AI agent. Furthermore, when the processing of each of the above parts is performed by the AI, the processing may be performed by the AI ​​in part or in whole, but is not limited to this example.Furthermore, processing performed by AI, including generative AI, may be replaced with rule-based processing, and rule-based processing may be replaced with processing performed by AI, including generative AI.

[0111] Furthermore, the processing performed by the data processing system 10 described above is carried out by the specific processing unit 290 of the data processing device 12 or the control unit 46A of the smart device 14, but it may also be carried out by the specific processing unit 290 of the data processing device 12 and the control unit 46A of the smart device 14. In addition, the specific processing unit 290 of the data processing device 12 acquires or collects information necessary for processing from the smart device 14 or an external device, and the smart device 14 acquires or collects information necessary for processing from the data processing device 12 or an external device.

[0112] For example, the collection unit can collect system and network activity data using the camera 42 and communication I / F 44 of the smart device 14. The analysis unit is implemented by the specific processing unit 290 of the data processing device 12 and analyzes the collected data in real time to detect abnormal activity. The blocking unit is implemented by the specific processing unit 290 of the data processing device 12 and automatically blocks security threats in response to detected abnormal activity. The proposal unit is implemented by the specific processing unit 290 of the data processing device 12 and proposes countermeasures for detected abnormal activity. The correspondence between each unit and the device or control unit is not limited to the example described above and can be modified in various ways.

[0113] [Second Embodiment] Figure 3 shows an example of the configuration of the data processing system 210 according to the second embodiment.

[0114] As shown in Figure 3, the data processing system 210 includes a data processing device 12 and smart glasses 214. An example of the data processing device 12 is a server.

[0115] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN and / or LAN.

[0116] The smart glasses 214 include a computer 36, a microphone 238, a speaker 240, a camera 42, and a communication interface 44. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, and camera 42 are also connected to the bus 52.

[0117] The microphone 238 receives voice signals from the user and accepts instructions from the user. The microphone 238 captures the voice signals from the user, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.

[0118] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, which captures images of the area around the user (for example, an imaging range defined by a field of view equivalent to the field of vision of a typical healthy person).

[0119] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.

[0120] Figure 4 shows an example of the main functions of the data processing device 12 and the smart glasses 214. As shown in Figure 4, the data processing device 12 performs specific processing by the processor 28. The storage 32 stores the specific processing program 56.

[0121] The processor 28 reads a specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 acting as a specific processing unit 290 according to the specific processing program 56 executed on the RAM 30.

[0122] Storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290. The identification processing unit 290 can estimate the user's emotions using the emotion identification model 59 and perform identification processing using the user's emotions. The emotion estimation function (emotion identification function) using the emotion identification model 59 performs various estimations and predictions regarding the user's emotions, including but not limited to these examples. Furthermore, emotion estimation and prediction also include, for example, emotion analysis.

[0123] In the smart glasses 214, specific processing is performed by the processor 46. The storage 50 stores a specific processing program 60. The processor 46 reads the specific processing program 60 from the storage 50 and executes the read specific processing program 60 on the RAM 48. The specific processing is realized by the processor 46 acting as a control unit 46A according to the specific processing program 60 executed on the RAM 48. The smart glasses 214 also have a data generation model 58 and an emotion identification model 59, similar to the data generation model and emotion identification model 59, and can perform processing similar to that of the specific processing unit 290 using these models.

[0124] Furthermore, other devices besides the data processing device 12 may also have the data generation model 58. For example, a server device may have the data generation model 58. In this case, the data processing device 12 obtains processing results (such as prediction results) using the data generation model 58 by communicating with the server device that has the data generation model 58. Also, the data processing device 12 may be a server device or a terminal device owned by the user (for example, a mobile phone, robot, home appliance, etc.).

[0125] The specific processing unit 290 transmits the result of the specific processing to the smart glasses 214. In the smart glasses 214, the control unit 46A causes the speaker 240 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.

[0126] The data generation model 58 is a so-called generative AI. An example of a data generation model 58 is a generative AI such as ChatGPT. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and inference data such as audio data representing speech, text data representing text, and image data representing images (e.g., still image data or video data). The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference result in one or more data formats such as audio data, text data, and image data. The data generation model 58 includes, for example, text generation AI, image generation AI, and multimodal generation AI. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization. The specific processing unit 290 performs the specific processing described above using the data generation model 58. The data generation model 58 may be a fine-tuned model that outputs inference results from prompts that do not contain instructions, in which case the data generation model 58 can output inference results from prompts that do not contain instructions. In the data processing device 12, etc., there are multiple types of data generation models 58, and the data generation model 58 includes AI other than generative AI. AI other than generative AI includes, for example, linear regression, logistic regression, decision trees, random forests, support vector machines (SVM), k-means clustering, convolutional neural networks (CNN), recurrent neural networks (RNN), generative adversarial networks (GAN), or naive Bayes, and can perform various processes, but is not limited to these examples. Also, the AI ​​may be an AI agent. Furthermore, when the processing of each part described above is performed by the AI, the processing may be performed by the AI ​​in part or in whole, but is not limited to this example. Also, processing performed by an AI including a generative AI may be replaced by rule-based processing, and rule-based processing may be replaced by processing performed by an AI including a generative AI.

[0127] The data processing system 210 according to the second embodiment performs the same processing as the data processing system 10 according to the first embodiment. The processing by the data processing system 210 is performed by the specific processing unit 290 of the data processing device 12 or the control unit 46A of the smart glasses 214, but it may also be performed by the specific processing unit 290 of the data processing device 12 and the control unit 46A of the smart glasses 214. In addition, the specific processing unit 290 of the data processing device 12 acquires or collects information necessary for processing from the smart glasses 214 or an external device, and the smart glasses 214 acquires or collects information necessary for processing from the data processing device 12 or an external device.

[0128] For example, the data collection unit can collect system and network activity data using the camera 42 and communication I / F 44 of the smart glasses 214. The analysis unit is implemented by the specific processing unit 290 of the data processing device 12 and analyzes the collected data in real time to detect abnormal activity. The blocking unit is implemented by the specific processing unit 290 of the data processing device 12 and automatically blocks security threats in response to detected abnormal activity. The proposal unit is implemented by the specific processing unit 290 of the data processing device 12 and proposes countermeasures for detected abnormal activity. The correspondence between each unit and the device or control unit is not limited to the example described above and can be modified in various ways.

[0129] [Third Embodiment] Figure 5 shows an example of the configuration of the data processing system 310 according to the third embodiment.

[0130] As shown in Figure 5, the data processing system 310 includes a data processing device 12 and a headset terminal 314. An example of the data processing device 12 is a server.

[0131] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN and / or LAN.

[0132] The headset terminal 314 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication interface 44, and a display 343. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, camera 42, and display 343 are also connected to the bus 52.

[0133] The microphone 238 receives voice signals from the user and accepts instructions from the user. The microphone 238 captures the voice signals from the user, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.

[0134] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, which captures images of the area around the user (for example, an imaging range defined by a field of view equivalent to the field of vision of a typical healthy person).

[0135] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.

[0136] Figure 6 shows an example of the main functions of the data processing device 12 and the headset terminal 314. As shown in Figure 6, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.

[0137] The processor 28 reads a specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 acting as a specific processing unit 290 according to the specific processing program 56 executed on the RAM 30.

[0138] Storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290. The identification processing unit 290 can estimate the user's emotions using the emotion identification model 59 and perform identification processing using the user's emotions. The emotion estimation function (emotion identification function) using the emotion identification model 59 performs various estimations and predictions regarding the user's emotions, including but not limited to these examples. Furthermore, emotion estimation and prediction also include, for example, emotion analysis.

[0139] In the headset terminal 314, specific processing is performed by the processor 46. The storage 50 stores a specific program 60. The processor 46 reads the specific program 60 from the storage 50 and executes the read specific program 60 on the RAM 48. The specific processing is realized by the processor 46 acting as a control unit 46A according to the specific program 60 executed on the RAM 48. The headset terminal 314 also has a data generation model 58 and an emotion identification model 59, similar to the data generation model and emotion identification model 59, and can perform processing similar to that of the specific processing unit 290 using these models.

[0140] Furthermore, other devices besides the data processing device 12 may also have the data generation model 58. For example, a server device may have the data generation model 58. In this case, the data processing device 12 obtains processing results (such as prediction results) using the data generation model 58 by communicating with the server device that has the data generation model 58. Also, the data processing device 12 may be a server device or a terminal device owned by the user (for example, a mobile phone, robot, home appliance, etc.).

[0141] The specific processing unit 290 transmits the result of the specific processing to the headset terminal 314. In the headset terminal 314, the control unit 46A causes the speaker 240 and display 343 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.

[0142] The data generation model 58 is a so-called generative AI. An example of a data generation model 58 is a generative AI such as ChatGPT. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and inference data such as audio data representing speech, text data representing text, and image data representing images (e.g., still image data or video data). The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference result in one or more data formats such as audio data, text data, and image data. The data generation model 58 includes, for example, text generation AI, image generation AI, and multimodal generation AI. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization. The specific processing unit 290 performs the specific processing described above using the data generation model 58. The data generation model 58 may be a fine-tuned model that outputs inference results from prompts that do not contain instructions, in which case the data generation model 58 can output inference results from prompts that do not contain instructions. In the data processing device 12, etc., there are multiple types of data generation models 58, and the data generation model 58 includes AI other than generative AI. AI other than generative AI includes, for example, linear regression, logistic regression, decision trees, random forests, support vector machines (SVM), k-means clustering, convolutional neural networks (CNN), recurrent neural networks (RNN), generative adversarial networks (GAN), or naive Bayes, and can perform various processes, but is not limited to these examples. Also, the AI ​​may be an AI agent. Furthermore, when the processing of each part described above is performed by the AI, the processing may be performed by the AI ​​in part or in whole, but is not limited to this example. Also, processing performed by an AI including a generative AI may be replaced by rule-based processing, and rule-based processing may be replaced by processing performed by an AI including a generative AI.

[0143] The data processing system 310 according to the third embodiment performs the same processing as the data processing system 10 according to the first embodiment. The processing by the data processing system 310 is performed by the specific processing unit 290 of the data processing device 12 or the control unit 46A of the headset terminal 314, but may also be performed by the specific processing unit 290 of the data processing device 12 and the control unit 46A of the headset terminal 314. In addition, the specific processing unit 290 of the data processing device 12 acquires or collects information necessary for processing from the headset terminal 314 or an external device, and the headset terminal 314 acquires or collects information necessary for processing from the data processing device 12 or an external device.

[0144] For example, the collection unit can collect system and network activity data using the camera 42 and communication I / F 44 of the headset terminal 314. The analysis unit is implemented by the specific processing unit 290 of the data processing device 12 and analyzes the collected data in real time to detect abnormal activity. The blocking unit is implemented by the specific processing unit 290 of the data processing device 12 and automatically blocks security threats in response to detected abnormal activity. The proposal unit is implemented by the specific processing unit 290 of the data processing device 12 and proposes countermeasures for detected abnormal activity. The correspondence between each unit and the device or control unit is not limited to the example described above and can be modified in various ways.

[0145] [Fourth Embodiment] Figure 7 shows an example of the configuration of the data processing system 410 according to the fourth embodiment.

[0146] As shown in Figure 7, the data processing system 410 includes a data processing device 12 and a robot 414. An example of the data processing device 12 is a server.

[0147] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN and / or LAN.

[0148] The robot 414 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication interface 44, and a controlled object 443. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, camera 42, and controlled object 443 are also connected to the bus 52.

[0149] The microphone 238 receives voice signals from the user and accepts instructions from the user. The microphone 238 captures the voice signals from the user, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.

[0150] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS image sensor or CCD image sensor, which captures images of the area around the user (for example, an imaging range defined by a field of view equivalent to the field of vision of a typical healthy person).

[0151] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.

[0152] The controlled object 443 includes a display device, LEDs in the eyes, and motors that drive the arms, hands, and feet. The posture and gestures of the robot 414 are controlled by controlling the motors of the arms, hands, and feet. Some of the robot 414's emotions can be expressed by controlling these motors. The robot 414's facial expressions can also be expressed by controlling the illumination state of the LEDs in its eyes.

[0153] Figure 8 shows an example of the main functions of the data processing device 12 and the robot 414. As shown in Figure 8, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.

[0154] The processor 28 reads a specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 acting as a specific processing unit 290 according to the specific processing program 56 executed on the RAM 30.

[0155] Storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290. The identification processing unit 290 can estimate the user's emotions using the emotion identification model 59 and perform identification processing using the user's emotions. The emotion estimation function (emotion identification function) using the emotion identification model 59 performs various estimations and predictions regarding the user's emotions, including but not limited to these examples. Furthermore, emotion estimation and prediction also include, for example, emotion analysis.

[0156] In robot 414, specific processing is performed by processor 46. A specific program 60 is stored in storage 50. Processor 46 reads the specific program 60 from storage 50 and executes it on RAM 48. The specific processing is achieved by processor 46 acting as a control unit 46A according to the specific program 60 executed on RAM 48. Robot 414 also has data generation model 58 and emotion identification model 59, similar to those of the robot, and can perform processing similar to that of the specific processing unit 290 using these models.

[0157] Furthermore, other devices besides the data processing device 12 may also have the data generation model 58. For example, a server device may have the data generation model 58. In this case, the data processing device 12 obtains processing results (such as prediction results) using the data generation model 58 by communicating with the server device that has the data generation model 58. Also, the data processing device 12 may be a server device or a terminal device owned by the user (for example, a mobile phone, robot, home appliance, etc.).

[0158] The specific processing unit 290 transmits the result of the specific processing to the robot 414. In the robot 414, the control unit 46A causes the speaker 240 and the controlled object 443 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.

[0159] The data generation model 58 is a so-called generative AI. An example of a data generation model 58 is a generative AI such as ChatGPT. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and inference data such as audio data representing speech, text data representing text, and image data representing images (e.g., still image data or video data). The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference result in one or more data formats such as audio data, text data, and image data. The data generation model 58 includes, for example, text generation AI, image generation AI, and multimodal generation AI. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization. The specific processing unit 290 performs the specific processing described above using the data generation model 58. The data generation model 58 may be a fine-tuned model that outputs inference results from prompts that do not contain instructions, in which case the data generation model 58 can output inference results from prompts that do not contain instructions. In the data processing device 12, etc., there are multiple types of data generation models 58, and the data generation model 58 includes AI other than generative AI. AI other than generative AI includes, for example, linear regression, logistic regression, decision trees, random forests, support vector machines (SVM), k-means clustering, convolutional neural networks (CNN), recurrent neural networks (RNN), generative adversarial networks (GAN), or naive Bayes, and can perform various processes, but is not limited to these examples. Also, the AI ​​may be an AI agent. Furthermore, when the processing of each part described above is performed by the AI, the processing may be performed by the AI ​​in part or in whole, but is not limited to this example. Also, processing performed by an AI including a generative AI may be replaced by rule-based processing, and rule-based processing may be replaced by processing performed by an AI including a generative AI.

[0160] The data processing system 410 according to the fourth embodiment performs the same processing as the data processing system 10 according to the first embodiment. The processing by the data processing system 410 is performed by the specific processing unit 290 of the data processing device 12 or the control unit 46A of the robot 414, but it may also be performed by the specific processing unit 290 of the data processing device 12 and the control unit 46A of the robot 414. In addition, the specific processing unit 290 of the data processing device 12 acquires or collects information necessary for processing from the robot 414 or an external device, and the robot 414 acquires or collects information necessary for processing from the data processing device 12 or an external device.

[0161] For example, the collection unit can collect system and network activity data using the camera 42 and communication I / F 44 of the robot 414. The analysis unit is implemented by the specific processing unit 290 of the data processing device 12 and analyzes the collected data in real time to detect abnormal activity. The blocking unit is implemented by the specific processing unit 290 of the data processing device 12 and automatically blocks security threats in response to detected abnormal activity. The proposal unit is implemented by the specific processing unit 290 of the data processing device 12 and proposes countermeasures for detected abnormal activity. The correspondence between each unit and the device or control unit is not limited to the example described above and can be modified in various ways.

[0162] Furthermore, the emotion identification model 59, acting as an emotion engine, may determine the user's emotion according to a specific mapping. Specifically, the emotion identification model 59 may determine the user's emotion according to a specific mapping, which is an emotion map (see Figure 9). Similarly, the emotion identification model 59 may also determine the robot's emotion, and the identification processing unit 290 may perform identification processing using the robot's emotion.

[0163] Figure 9 shows the emotion map 400, in which multiple emotions are mapped. In the emotion map 400, emotions are arranged in concentric circles radiating from the center. The closer to the center of the concentric circles, the more primitive the emotions are located. Further out of the concentric circles, emotions representing states and actions arising from mental states are located. Emotion is a concept that includes feelings and mental states. On the left side of the concentric circles, emotions that are generally generated from reactions occurring in the brain are located. On the right side of the concentric circles, emotions that are generally induced by situational judgment are located. Above and below the concentric circles, emotions that are generally generated from reactions occurring in the brain and induced by situational judgment are located. In addition, the emotion of "pleasure" is located on the upper side of the concentric circles, and the emotion of "displeasure" is located on the lower side. Thus, in the emotion map 400, multiple emotions are mapped based on the structure in which emotions arise, and emotions that are likely to occur simultaneously are mapped close together.

[0164] These emotions are distributed at the 3 o'clock position on the Emotion Map 400, and usually fluctuate between feelings of security and anxiety. In the right half of the Emotion Map 400, situational awareness takes precedence over internal feelings, resulting in a calm impression.

[0165] The inside of the Emotion Map 400 represents inner thoughts, while the outside represents actions. Therefore, the further you go from the outside of the Emotion Map 400, the more visible (expressed in actions) your emotions become.

[0166] Here, human emotions are based on various balances, such as posture and blood sugar levels. When these balances deviate from the ideal, it results in discomfort, and when they approach the ideal, it results in pleasure. Similarly, in robots, cars, and motorcycles, emotions can be created based on various balances, such as posture and battery level. When these balances deviate from the ideal, it results in discomfort, and when they approach the ideal, it results in pleasure. The emotion map can be generated based, for example, on Dr. Mitsuyoshi's emotion map (Research on a system for analyzing brain physiological signals of speech emotion recognition and emotion, Tokushima University, doctoral dissertation: https: / / ci.nii.ac.jp / naid / 500000375379). The left half of the emotion map contains emotions belonging to a region called "response," where sensation is dominant. The right half of the emotion map contains emotions belonging to a region called "situation," where situational awareness is dominant.

[0167] The emotion map defines two emotions that promote learning. One is the emotion around the middle of the negative "repentance" and "reflection" on the situation side. In other words, it is when the robot experiences negative emotions such as "I never want to feel this way again" or "I don't want to be scolded again." The other is the emotion around the positive "desire" on the reaction side. In other words, it is when the robot has positive feelings such as "I want more" or "I want to know more."

[0168] The emotion identification model 59 inputs user input into a pre-trained neural network, obtains emotion values ​​representing each emotion shown in the emotion map 400, and determines the user's emotion. This neural network is pre-trained based on multiple training data sets, which are combinations of user input and emotion values ​​representing each emotion shown in the emotion map 400. Furthermore, this neural network is trained so that emotions located close together have similar values, as shown in the emotion map 900 in Figure 10. Figure 10 shows an example where multiple emotions such as "reassured," "calm," and "confident" have similar emotion values.

[0169] In the above embodiment, an example was given in which a specific process is performed by a single computer 22. However, the technology of this disclosure is not limited thereto, and a distributed processing method for the specific process may be used, which includes computer 22 and multiple other computers.

[0170] In the above embodiment, an example was given in which the specific processing program 56 is stored in the storage 32, but the technology of this disclosure is not limited thereto. For example, the specific processing program 56 may be stored in a portable, computer-readable, non-temporary storage medium such as a USB (Universal Serial Bus) memory. The specific processing program 56 stored in the non-temporary storage medium is installed in the computer 22 of the data processing device 12. The processor 28 executes specific processing according to the specific processing program 56.

[0171] Alternatively, the specific processing program 56 may be stored in a storage device such as a server connected to the data processing device 12 via the network 54, and the specific processing program 56 may be downloaded and installed on the computer 22 in response to a request from the data processing device 12.

[0172] Furthermore, it is not necessary to store the entirety of the specific processing program 56 in a storage device such as a server connected to the data processing device 12 via the network 54, or to store the entirety of the specific processing program 56 in the storage 32; it is acceptable to store only a portion of the specific processing program 56.

[0173] The following types of processors can be used as hardware resources to perform specific processing. Examples of processors include a CPU, a general-purpose processor that functions as a hardware resource to perform specific processing by executing software, i.e., a program. Other examples of processors include dedicated electrical circuits, such as FPGAs (Field-Programmable Gate Arrays), PLDs (Programmable Logic Devices), or ASICs (Application Specific Integrated Circuits), which have circuit configurations specifically designed to perform specific processing. All of these processors have built-in or connected memory, and all of them perform specific processing by using memory.

[0174] The hardware resource that performs a specific process may consist of one of these various processors, or it may consist of a combination of two or more processors of the same or different types (for example, a combination of multiple FPGAs, or a combination of a CPU and an FPGA). Alternatively, the hardware resource that performs a specific process may consist of a single processor.

[0175] Examples of configurations using a single processor include, firstly, a configuration in which one or more CPUs and software are combined to form a single processor, and this processor functions as a hardware resource that performs a specific process. Secondly, there is a configuration using a processor that realizes the functions of the entire system, including multiple hardware resources that perform a specific process, on a single IC chip, as exemplified by SoCs (System-on-a-chip). In this way, a specific process is realized using one or more of the above types of processors as hardware resources.

[0176] Furthermore, the hardware structure of these various processors can more specifically utilize electrical circuits that combine circuit elements such as semiconductor devices. Also, the specific processing described above is merely an example. Therefore, it goes without saying that unnecessary steps can be deleted, new steps added, or the processing order rearranged, as long as it does not deviate from the main purpose.

[0177] Furthermore, although the above-described examples were divided into four embodiments, some or all of these embodiments may be combined. Also, the smart device 14, smart glasses 214, headset terminal 314, and robot 414 are just examples, and they may be combined, or other devices may be used. Also, although the above-described examples were divided into two embodiments, Embodiment 1 and Embodiment 2, these may be combined.

[0178] The descriptions and illustrations presented above are detailed explanations of the technical aspects of this disclosure and are merely examples of the technical aspects. For example, the above descriptions of the structure, function, operation, and effect are examples of the structure, function, operation, and effect of the technical aspects of this disclosure. Therefore, it goes without saying that you may delete unnecessary parts, add new elements, or replace elements in the descriptions and illustrations presented above, as long as you do not deviate from the essence of the technical aspects of this disclosure. Furthermore, in order to avoid confusion and facilitate understanding of the technical aspects of this disclosure, explanations of common technical knowledge and other things that do not require special explanation to enable the implementation of the technical aspects of this disclosure have been omitted from the descriptions and illustrations presented above.

[0179] All documents, patent applications, and technical standards described herein are incorporated by reference to the same extent as if each individual document, patent application, and technical standard were specifically and individually noted to be incorporated by reference.

[0180] (Note 1) A collection unit that collects system or network activity data, An analysis unit analyzes the data collected by the aforementioned collection unit and detects abnormal activity, The system includes a blocking unit that automatically blocks security threats in response to abnormal activity detected by the analysis unit. A system characterized by the following features. (Note 2) It includes a proposal section that suggests countermeasures for detected abnormal activity. The system described in Appendix 1, characterized by the features described herein. (Note 3) The aforementioned collection unit is Collect various log data or traffic data. The system described in Appendix 1, characterized by the features described herein. (Note 4) The aforementioned analysis unit, Detects unusual access or communication patterns. The system described in Appendix 1, characterized by the features described herein. (Note 5) The aforementioned block section is Block unauthorized access or malware communications. The system described in Appendix 1, characterized by the features described herein. (Note 6) The aforementioned proposal section is, Suggests changes to specific security settings or additional security measures. The system described in Appendix 2, characterized by the features described herein. (Note 7) The aforementioned collection unit is It estimates the user's emotions and adjusts the types of data collected based on those estimated emotions. The system described in Appendix 1, characterized by the features described herein. (Note 8) The aforementioned collection unit is The frequency of data collection is dynamically changed according to the system's operating status. The system described in Appendix 1, characterized by the features described herein. (Note 9) The aforementioned collection unit is Expand the scope of data collection based on specific time periods or events. The system described in Appendix 1, characterized by the features described herein. (Note 10) The aforementioned collection unit is It estimates the user's emotions and prioritizes the data to collect based on those estimated emotions. The system described in Appendix 1, characterized by the features described herein. (Note 11) The aforementioned collection unit is The target of data collection is selected based on the geographical location of the system. The system described in Appendix 1, characterized by the features described herein. (Note 12) The aforementioned collection unit is Integrate and collect data from external security sources. The system described in Appendix 1, characterized by the features described herein. (Note 13) The aforementioned analysis unit, It estimates the user's emotions and adjusts how the analysis results are displayed based on the estimated emotions. The system described in Appendix 1, characterized by the features described herein. (Note 14) The aforementioned analysis unit, Optimize the analysis algorithm by referring to past abnormal activity data. The system described in Appendix 1, characterized by the features described herein. (Note 15) The aforementioned analysis unit, Perform a detailed analysis focusing on specific system components. The system described in Appendix 1, characterized by the features described herein. (Note 16) The aforementioned analysis unit, The system estimates the user's emotions and determines the priority of analysis based on the estimated emotions. The system described in Appendix 1, characterized by the features described herein. (Note 17) The aforementioned analysis unit, Identify anomalous activity based on the geographical location of the system. The system described in Appendix 1, characterized by the features described herein. (Note 18) The aforementioned analysis unit, Integrate and analyze data from external security sources. The system described in Appendix 1, characterized by the features described herein. (Note 19) The aforementioned block section is It estimates the user's emotions and adjusts the blocking method based on the estimated user emotions. The system described in Appendix 1, characterized by the features described herein. (Note 20) The aforementioned block section is Optimize the block algorithm by referring to past block data. The system described in Appendix 1, characterized by the features described herein. (Note 21) The aforementioned block section is Perform detailed blocking by focusing on a specific system component. The system described in Appendix 1, characterized by the features described herein. (Note 22) The aforementioned block section is It estimates the user's emotions and determines the priority of blocking based on the estimated user emotions. The system described in Appendix 1, characterized by the features described herein. (Note 23) The aforementioned block section is Blocked areas are selected based on the geographical location of the system. The system described in Appendix 1, characterized by the features described herein. (Note 24) The aforementioned block section is Integrate and block data from external security sources. The system described in Appendix 1, characterized by the features described herein. (Note 25) The aforementioned proposal section is, It estimates the user's emotions and adjusts the way suggestions are presented based on those estimated emotions. The system described in Appendix 2, characterized by the features described herein. (Note 26) The aforementioned proposal section is, Optimize the proposed algorithm by referring to past proposal data. The system described in Appendix 2, characterized by the features described herein. (Note 27) The aforementioned proposal section is, We will make detailed suggestions focusing on specific system components. The system described in Appendix 2, characterized by the features described herein. (Note 28) The aforementioned proposal section is, It estimates the user's emotions and determines the priority of suggestions based on the estimated user emotions. The system described in Appendix 2, characterized by the features described herein. (Note 29) The aforementioned proposal section is, The proposed solutions will be selected based on the geographical location of the systems. The system described in Appendix 2, characterized by the features described herein. (Note 30) The aforementioned proposal section is, Integrate and propose data from external security sources. The system described in Appendix 2, characterized by the features described herein. [Explanation of Symbols]

[0181] 10, 210, 310, 410 Data Processing Systems 12 Data Processing Devices 14 Smart Devices 214 Smart Glasses 314 Headset-type terminal 414 Robots

Claims

1. A collection unit that collects system or network activity data, An analysis unit analyzes the data collected by the aforementioned collection unit and detects abnormal activity, The system includes a blocking unit that automatically blocks security threats in response to abnormal activity detected by the analysis unit. A system characterized by the following features.

2. It includes a proposal section that suggests countermeasures for detected abnormal activity. The system according to feature 1.

3. The aforementioned collection unit is Collect various log data or traffic data. The system according to feature 1.

4. The aforementioned analysis unit, Detects unusual access or communication patterns. The system according to feature 1.

5. The aforementioned block section is Block unauthorized access or malware communications. The system according to feature 1.

6. The aforementioned proposal section is, Suggests changes to specific security settings or additional security measures. The system according to feature 2.

7. The aforementioned collection unit is It estimates the user's emotions and adjusts the types of data collected based on those estimated emotions. The system according to feature 1.

8. The aforementioned collection unit is The frequency of data collection is dynamically changed according to the system's operating status. The system according to feature 1.

9. The aforementioned collection unit is Expand the scope of data collection based on specific time periods or events. The system according to feature 1.

10. The aforementioned collection unit is It estimates the user's emotions and prioritizes the data to collect based on those estimated emotions. The system according to feature 1.

Citation Information

Patent Citations

  • Persona chatbot control method and system

    JP2022180282A