system

The system automates vulnerability management through AI-driven units to quickly identify, propose, and correct vulnerabilities, improving efficiency and reducing the burden on developers.

JP2026072662APending Publication Date: 2026-05-01SOFTBANK GROUP CORP
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
SOFTBANK GROUP CORP
Filing Date
2024-10-18
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

Existing vulnerability countermeasures are inefficient and difficult to implement quickly, posing a challenge in addressing software vulnerabilities effectively.

Method used

A system comprising an acquisition unit, analysis unit, proposal unit, correction unit, and verification unit that automatically identifies vulnerabilities, proposes countermeasures, and applies fixes using AI to streamline the vulnerability response process.

Benefits of technology

The system enables rapid and efficient vulnerability management by automating the identification, proposal, and correction of vulnerabilities, reducing the burden on engineers and enhancing development productivity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026072662000001_ABST
    Figure 2026072662000001_ABST
Patent Text Reader

Abstract

The system according to this embodiment aims to address vulnerabilities quickly and efficiently. [Solution] The system according to the embodiment comprises an acquisition unit, an analysis unit, a proposal unit, a modification unit, and a verification unit. The acquisition unit acquires the CVE number and its description, the documentation and version log of the relevant library. The analysis unit checks whether the library being used has a vulnerability based on the information acquired by the acquisition unit. The proposal unit presents proposed countermeasures and procedures based on the results of the analysis performed by the analysis unit. The modification unit automatically modifies the modifiable parts based on the countermeasures proposed by the proposal unit. The verification unit confirms the content modified by the modification unit.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The technology of the present disclosure relates to a system.

Background Art

[0002] Patent Document 1 discloses a persona chatbot control method performed by at least one processor, the method including steps of receiving a user utterance, adding the user utterance to a prompt including an instruction sentence related to an explanation of a character of the chatbot, encoding the prompt, and inputting the encoded prompt into a language model to generate a chatbot utterance as a response to the user utterance.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] In the prior art, there is a problem that vulnerability countermeasures cover a wide range and are difficult to perform quickly and efficiently.

[0005] The system according to the embodiment aims to perform vulnerability countermeasures quickly and efficiently.

Means for Solving the Problems

[0006] The system according to this embodiment comprises an acquisition unit, an analysis unit, a proposal unit, a modification unit, and a verification unit. The acquisition unit acquires the CVE number and its description, the documentation and version log of the relevant library. The analysis unit checks whether the library being used has a vulnerability based on the information acquired by the acquisition unit. The proposal unit presents proposed countermeasures and procedures based on the results of the analysis performed by the analysis unit. The modification unit automatically modifies the modifiable parts based on the countermeasures proposed by the proposal unit. The verification unit confirms the content modified by the modification unit. [Effects of the Invention]

[0007] The system according to this embodiment can quickly and efficiently address vulnerabilities. [Brief explanation of the drawing]

[0008] [Figure 1] This is a conceptual diagram showing an example of the configuration of a data processing system according to the first embodiment. [Figure 2] This is a conceptual diagram showing an example of the essential functions of a data processing device and a smart device according to the first embodiment. [Figure 3] This is a conceptual diagram showing an example of the configuration of a data processing system according to the second embodiment. [Figure 4] This is a conceptual diagram showing an example of the main functions of a data processing device and smart glasses according to the second embodiment. [Figure 5] This is a conceptual diagram showing an example of the configuration of a data processing system according to the third embodiment. [Figure 6] This is a conceptual diagram showing an example of the main functions of a data processing device and a headset-type terminal according to the third embodiment. [Figure 7] This is a conceptual diagram showing an example of the configuration of a data processing system according to the fourth embodiment. [Figure 8] This is a conceptual diagram showing an example of the main functions of a data processing device and a robot according to the fourth embodiment. [Figure 9] This shows an emotion map where multiple emotions are mapped. [Figure 10] This shows an emotion map where multiple emotions are mapped. [Modes for carrying out the invention]

[0009] Hereinafter, an example of an embodiment of the system relating to the technology of this disclosure will be described with reference to the attached drawings.

[0010] First, let's explain the terminology used in the following explanation.

[0011] In the following embodiments, the signed processor (hereinafter simply referred to as "processor") may be a single arithmetic unit or a combination of multiple arithmetic units. Furthermore, the processor may be a single type of arithmetic unit or a combination of multiple types of arithmetic units. Examples of arithmetic units include CPU (Central Processing Unit), GPU (Graphics Processing Unit), GPGPU (General-Purpose computing on Graphics Processing Units), APU (Accelerated Processing Unit), or TPU (Tensor Processing Unit).

[0012] In the following embodiments, signed RAM (Random Access Memory) is a memory that temporarily stores information and is used as work memory by the processor.

[0013] In the following embodiments, the signed storage is one or more non-volatile storage devices that store various programs and various parameters. Examples of non-volatile storage devices include flash memory (SSD (Solid State Drive)), magnetic disks (e.g., hard disks), or magnetic tapes.

[0014] In the following embodiments, the labeled communication I / F (Interface) is an interface including a communication processor, an antenna, and the like. The communication I / F manages communication between a plurality of computers. Examples of communication standards applied to the communication I / F include wireless communication standards including 5G (5th Generation Mobile Communication System), Wi-Fi (registered trademark), or Bluetooth (registered trademark).

[0015] In the following embodiments, "A and / or B" is synonymous with "at least one of A and B". That is, "A and / or B" means that it may be only A, only B, or a combination of A and B. Also, in this specification, when expressing three or more matters connected by "and / or", the same concept as "A and / or B" is applied.

[0016] [First Embodiment] FIG. 1 shows an example of the configuration of a data processing system 10 according to the first embodiment.

[0017] As shown in FIG. 1, the data processing system 10 includes a data processing device 12 and a smart device 14. An example of the data processing device 12 is a server.

[0018] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. Also, the database 24 and the communication I / F 26 are connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[0019] The smart device 14 comprises a computer 36, a receiving device 38, an output device 40, a camera 42, and a communication interface 44. The computer 36 comprises a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The receiving device 38, output device 40, and camera 42 are also connected to the bus 52.

[0020] The reception device 38 is equipped with a touch panel 38A and a microphone 38B, and accepts user input. The touch panel 38A accepts user input via touch by detecting contact with an object (e.g., a pen or finger). The microphone 38B accepts user input via voice by detecting the user's voice. The control unit 46A transmits data indicating the user input received by the touch panel 38A and microphone 38B to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 (see Figure 2) acquires the data indicating the user input.

[0021] The output device 40 includes a display 40A and a speaker 40B, and presents data to the user by outputting the data in a form perceptible to the user (e.g., audio and / or text). The display 40A displays visible information such as text and images according to instructions from the processor 46. The speaker 40B outputs audio according to instructions from the processor 46. The camera 42 is a small digital camera equipped with an optical system such as a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor.

[0022] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various types of information between processor 46 and processor 28 via network 54.

[0023] Figure 2 shows an example of the main functions of the data processing device 12 and the smart device 14.

[0024] As shown in Figure 2, in the data processing device 12, a specific processing is performed by the processor 28. A specific processing program 56 is stored in the storage 32. The specific processing program 56 is an example of a "program" related to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 according to the specific processing program 56 executed on the RAM 30.

[0025] Storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290. The identification processing unit 290 can estimate the user's emotions using the emotion identification model 59 and perform identification processing using the user's emotions. The emotion estimation function (emotion identification function) using the emotion identification model 59 performs various estimations and predictions regarding the user's emotions, including but not limited to these examples. Furthermore, emotion estimation and prediction also include, for example, emotion analysis.

[0026] In the smart device 14, specific processing is performed by the processor 46. The storage 50 stores a specific processing program 60. The specific processing program 60 is used in conjunction with the specific processing program 56 by the data processing system 10. The processor 46 reads the specific processing program 60 from the storage 50 and executes the read specific processing program 60 on the RAM 48. The specific processing is realized by the processor 46 operating as a control unit 46A according to the specific processing program 60 executed on the RAM 48. The smart device 14 also has a data generation model 58 and an emotion identification model 59, similar to the data generation model and emotion identification model 59, and can perform processing similar to that of the specific processing unit 290 using these models.

[0027] Furthermore, other devices besides the data processing device 12 may also have the data generation model 58. For example, a server device (e.g., a generation server) may have the data generation model 58. In this case, the data processing device 12 obtains processing results (such as prediction results) using the data generation model 58 by communicating with the server device having the data generation model 58. The data processing device 12 may also be a server device or a terminal device owned by a user (e.g., a mobile phone, robot, home appliance, etc.). Next, an example of processing by the data processing system 10 according to the first embodiment will be described.

[0028] (Example of form 1) The vulnerability response support system according to an embodiment of the present invention is a system for solving the "vulnerability response" problem that developers face when quickly coding orders from management and releasing them. This system provides AI that quickly tells the system which version and migration target to the vulnerability library. This AI system acquires vulnerability information such as CVEs, proposes countermeasures when vulnerabilities are found, and can automatically perform minor fixes. First, when a developer submits a Pull Request (PR), the AI ​​checks whether the library being used has vulnerabilities. If a vulnerability is found as a result of the check, the AI ​​presents several suggestions and procedures on how to deal with it, prompting the developer who submitted the PR to make a decision. After a decision is made, the AI ​​automatically commits the parts that can be fixed as fixes to the PR. After that, a reviewer checks it, and if there are no problems, it is merged as is. If there are problems, the problem is communicated to the AI ​​again, or the fix is ​​performed manually and feedback is given to the AI. This system reduces the burden of vulnerability response for engineers, allowing them to focus more on development. For example, the CVE number and its description, the documentation and version log of the relevant library are entered. Next, the AI ​​retrieves vulnerability information such as CVEs and checks whether the libraries being used have vulnerabilities. If vulnerabilities are found as a result of the check, the AI ​​provides suggested solutions and procedures. The developer decides on a solution, and the AI ​​automatically commits the parts that can be fixed to a pull request. A reviewer checks it, and if there are no problems, it is merged. If there are problems, the developer either informs the AI ​​of the problem again or fixes it manually and provides feedback to the AI. This system can obtain vulnerability information such as CVEs because it is publicly available, and it can be trained on current large-scale language models (LLMs). This is expected to allow engineers to focus more on development and improve productivity. In this way, the vulnerability response support system reduces the burden of vulnerability response for engineers, allowing them to focus more on development.

[0029] The vulnerability response support system according to the embodiment comprises an acquisition unit, an analysis unit, a proposal unit, a correction unit, and a verification unit. The acquisition unit acquires CVE numbers and their descriptions, as well as documentation and version logs for the relevant libraries. For example, the acquisition unit acquires CVE numbers from a security database and collects documentation and version logs for the relevant libraries. The acquisition unit can also crawl publicly available information on the internet to collect the latest vulnerability information. Furthermore, the acquisition unit can acquire version logs for specific libraries based on information provided by the developers. The analysis unit checks whether the libraries being used have vulnerabilities based on the information acquired by the acquisition unit. For example, the analysis unit checks whether vulnerabilities exist in the libraries being used by comparing them with a known vulnerability database. The analysis unit can also perform security scans to detect vulnerabilities in libraries. Furthermore, the analysis unit can use AI to analyze the library code and identify potential vulnerabilities. The proposal unit presents proposed countermeasures and procedures based on the results analyzed by the analysis unit. For example, the proposal unit proposes patch application procedures and configuration change procedures. Furthermore, the proposal unit can provide a procedural manual showing how to fix the vulnerability. In addition, the proposal unit can use AI to suggest the optimal remediation method. The correction unit automatically corrects the parts that can be corrected based on the remediation method proposed by the proposal unit. For example, the correction unit automatically modifies code and changes configuration files. The correction unit can also use AI to identify the areas that need correction and automatically perform the corrections. Furthermore, the correction unit can also automatically perform corrections according to the correction procedures provided by the developer. The verification unit verifies the content corrected by the correction unit. For example, the verification unit reviews the corrected areas and checks for any problems. Furthermore, the verification unit can use AI to automatically verify the content of the corrections. Furthermore, the verification unit can also verify the content of the corrections according to the verification procedures provided by the developer. As a result, the vulnerability response support system according to the embodiment reduces the burden of vulnerability response on engineers, allowing them to focus more on development.

[0030] The acquisition unit retrieves CVE numbers and their descriptions, as well as documentation and version logs for the relevant libraries. Specifically, the acquisition unit retrieves CVE numbers from security databases and collects their detailed descriptions. CVE numbers are widely used as Common Vulnerabilities and Exposure Identifiers and provide detailed information about specific vulnerabilities. Based on this information, the acquisition unit collects documentation and version logs for the relevant libraries. Library documentation describes the library's functions, usage, and known issues, while version logs describe changes and fixes in each version. This allows the acquisition unit to centrally collect detailed information about vulnerabilities and related libraries. Furthermore, the acquisition unit can also collect the latest vulnerability information by crawling publicly available information on the internet. For example, it collects the latest information from security forums, developer communities, and official security advisories and incorporates it into the system. The acquisition unit can also obtain version logs for specific libraries based on information provided by developers. This allows the acquisition unit to quickly collect the latest vulnerability information and improve the overall security of the system.

[0031] The analysis unit checks whether the libraries being used have vulnerabilities based on the information acquired by the acquisition unit. Specifically, the analysis unit compares the data with a database of known vulnerabilities to confirm whether vulnerabilities exist in the libraries being used. The vulnerability database contains information on vulnerabilities reported in the past and how to address them, and the analysis unit uses this to evaluate the security of the libraries. The analysis unit can also perform security scans to detect vulnerabilities in libraries. Security scans are tools for analyzing the library's code and configuration files to identify known and potential vulnerabilities. Furthermore, the analysis unit can use AI to analyze the library's code and identify potential vulnerabilities. The AI ​​uses machine learning algorithms to learn from past vulnerability data and predict new vulnerabilities. For example, it can analyze code patterns and structures to identify areas where vulnerabilities are likely to occur. This allows the analysis unit to quickly and accurately analyze the collected data and understand the vulnerabilities of the libraries being used in real time. In addition, the analysis unit can utilize historical data and statistical information to perform long-term risk assessments and trend analysis. This allows the analysis unit to not only understand the situation in real time but also to handle long-term risk management and anomaly detection, improving the reliability and security of the entire system.

[0032] The proposal department, based on the results of the analysis conducted by the analysis department, presents proposed countermeasures and procedures. Specifically, the proposal department proposes patch application procedures and configuration change procedures. Patch application procedures outline the steps for updating software to fix vulnerabilities, while configuration change procedures show how to modify system settings to circumvent vulnerabilities. The proposal department can also provide procedure manuals outlining how to fix vulnerabilities. These manuals include specific correction steps and points to note, helping engineers to address vulnerabilities quickly and accurately. Furthermore, the proposal department can use AI to propose the optimal countermeasures. The AI ​​learns from past countermeasures and their effectiveness, and proposes the most effective countermeasures. For example, it can propose the optimal patch application procedures and configuration change procedures based on past countermeasures for similar vulnerabilities. This allows the proposal department to help engineers address vulnerabilities quickly and effectively, improving the overall system security. In addition, the proposal department can evaluate the effectiveness of countermeasures and make improvement suggestions as needed. This allows the proposal department to always provide the optimal countermeasures based on the latest information, continuously improving system security.

[0033] The fix unit automatically corrects fixable parts based on the countermeasures proposed by the proposal unit. Specifically, the fix unit automatically modifies code and changes configuration files. For example, it applies patches to fix vulnerabilities and makes necessary configuration changes. The fix unit can also use AI to identify and automatically fix the affected areas. The AI ​​learns from past fix data and proposes the optimal fix method. For example, it can propose the optimal fix procedure based on past fixes for similar vulnerabilities and automatically perform the fix. Furthermore, the fix unit can automatically perform fixes according to the fix procedures provided by the developer. This allows the fix unit to reduce the workload on engineers and fix vulnerabilities quickly and accurately. In addition, the fix unit records the fix details for later review. This allows the fix unit to manage the fix history and review the fix details as needed. In this way, the fix unit can help engineers fix vulnerabilities quickly and accurately, improving the overall system security.

[0034] The verification unit verifies the changes made by the correction unit. Specifically, the verification unit reviews the corrected areas and checks for any problems. For example, it checks the corrected code and configuration files to confirm that vulnerabilities have been properly fixed. The verification unit can also use AI to automatically verify the corrected content. The AI ​​analyzes the corrected content and confirms that vulnerabilities have been properly fixed. For example, it can analyze the corrected code and check whether vulnerabilities will reappear. Furthermore, the verification unit can also verify the corrected content according to the verification procedures provided by the developer. This allows the verification unit to confirm that the corrected content is appropriate and ensure the security of the entire system. In addition, the verification unit can evaluate the effectiveness of the corrected content and suggest additional corrections as needed. This allows the verification unit to perform highly accurate verifications based on the latest information at all times, continuously improving the security of the system.

[0035] The acquisition unit can analyze past vulnerability response history and select the optimal acquisition method. For example, the acquisition unit prioritizes acquiring information on frequently used libraries from past vulnerability response history. The acquisition unit can also select an effective acquisition method for a specific vulnerability based on past response history. Furthermore, the acquisition unit can achieve efficient response by analyzing past history and acquiring data at specific time periods. This enables efficient vulnerability response by selecting the optimal acquisition method based on past history. Some or all of the above processing in the acquisition unit may be performed using AI, for example, or without using AI.

[0036] The data acquisition unit can filter data based on the project's progress and priorities. For example, it can prioritize acquiring information before important milestones, taking into account the project's progress. It can also prioritize acquiring critical vulnerability information based on the project's priorities. Furthermore, the data acquisition unit can adjust the scope of information acquired according to the project's progress. This enables information acquisition tailored to the project's progress. Some or all of the processing described above in the data acquisition unit may be performed using AI, for example, or without AI.

[0037] The data acquisition unit can prioritize the acquisition of highly relevant information by considering geographical location information. For example, the data acquisition unit can prioritize the acquisition of region-specific vulnerability information based on the user's current location. It can also prioritize the acquisition of information about the region where the user's project is being implemented. Furthermore, the data acquisition unit can filter and acquire highly relevant information based on geographical location information. This allows for the acquisition of more appropriate information by considering geographical relevance. Some or all of the above processing in the data acquisition unit may be performed using AI, for example, or without using AI.

[0038] The acquisition unit can analyze social media activity and acquire relevant information. For example, the acquisition unit prioritizes acquiring vulnerability information that is trending on social media. The acquisition unit can also analyze social media posts and acquire relevant vulnerability information. Furthermore, the acquisition unit can filter and acquire important vulnerability information based on social media trends. This allows for the acquisition of important information based on social media trends. Some or all of the above processing in the acquisition unit may be performed using AI, for example, or without using AI.

[0039] The analysis unit can improve the accuracy of its analysis by considering the interrelationships between libraries. For example, the analysis unit can accurately analyze the scope of vulnerability impact by considering dependencies between libraries. Furthermore, the analysis unit can identify the root cause of a vulnerability based on the interrelationships between libraries. In addition, the analysis unit can analyze the interrelationships between libraries and propose the optimal remediation method. This improves the accuracy of the analysis by considering the dependencies between libraries. Some or all of the above-described processes in the analysis unit may be performed using AI, for example, or without AI.

[0040] The analysis unit can perform analysis considering the frequency of use and importance of libraries. For example, the analysis unit can prioritize the analysis of frequently used libraries and evaluate the impact of vulnerabilities. It can also focus on analyzing libraries of high importance and evaluate the risk of vulnerabilities. Furthermore, the analysis unit can determine the priority of analysis based on frequency of use and importance. This enables efficient analysis by determining the priority of analysis based on frequency of use and importance. Some or all of the above processes in the analysis unit may be performed using AI, for example, or without using AI.

[0041] The analysis unit can perform analysis while considering geographical distribution. For example, the analysis unit prioritizes analyzing vulnerability information in geographically close areas. The analysis unit can also evaluate the scope of vulnerability impact based on geographical distribution. Furthermore, the analysis unit can propose optimal countermeasures while considering geographical distribution. This allows for more appropriate analysis by considering geographical relationships. Some or all of the above-described processes in the analysis unit may be performed using AI, for example, or without using AI.

[0042] The analysis unit can improve the accuracy of its analysis by referring to relevant literature. For example, the analysis unit can analyze the impact of the vulnerability in detail based on the relevant literature. The analysis unit can also refer to the relevant literature and propose the optimal remediation method. Furthermore, the analysis unit can identify the root cause of the vulnerability based on the relevant literature. As a result, the accuracy of the analysis is improved by performing the analysis based on relevant literature. Some or all of the above processes in the analysis unit may be performed using AI, for example, or without using AI.

[0043] The proposal unit can adjust the level of detail of its proposals based on the severity of the vulnerability. For example, the proposal unit will provide detailed proposals for high-severity vulnerabilities. Conversely, it can provide concise proposals for low-severity vulnerabilities. Furthermore, the proposal unit can adjust the level of detail of its proposals according to the severity. This allows for appropriate countermeasures to be implemented by adjusting the level of detail of proposals according to the severity of the vulnerability. Some or all of the above processing in the proposal unit may be performed using AI, for example, or without using AI.

[0044] The proposal unit can apply different proposal algorithms depending on the vulnerability category. For example, the proposal unit may apply a specific proposal algorithm to SQL injection vulnerabilities. It may also apply a different proposal algorithm to cross-site scripting vulnerabilities. Furthermore, the proposal unit can select the optimal proposal algorithm depending on the vulnerability category. This enables optimal proposals tailored to each vulnerability category. Some or all of the above processing in the proposal unit may be performed using AI, for example, or without AI.

[0045] The proposal department can determine the priority of proposals based on when the vulnerability was discovered. For example, the proposal department will prioritize proposals for recently discovered vulnerabilities. Conversely, the proposal department may postpone proposals for older vulnerabilities. Furthermore, the proposal department can adjust the priority of proposals based on when they were discovered. This allows for a rapid response by adjusting the priority of proposals according to when the vulnerability was discovered. Some or all of the above processes in the proposal department may be performed using AI, for example, or not using AI.

[0046] The proposal unit can adjust the order of proposals based on the relevance of the vulnerabilities. For example, the proposal unit will prioritize proposals for highly relevant vulnerabilities. It can also postpone proposals for less relevant vulnerabilities. Furthermore, the proposal unit can adjust the order of proposals based on relevance. This enables proposals to be tailored to the relevance of the vulnerabilities. Some or all of the above processing in the proposal unit may be performed using AI, for example, or without AI.

[0047] The correction unit can analyze past correction history and select the optimal correction method. For example, the correction unit can select an effective correction method from past correction history. The correction unit can also propose the optimal correction procedure based on past correction history. Furthermore, the correction unit can analyze past correction history and select the most efficient correction method. This enables efficient correction by selecting the optimal correction method based on past history. Some or all of the above processes in the correction unit may be performed using AI, for example, or without using AI.

[0048] The correction unit can customize the means of correction based on the project's progress. For example, the correction unit can prioritize corrections before important milestones, taking into account the project's progress. The correction unit can also adjust the means of correction according to the project's progress. Furthermore, the correction unit can select the optimal means of correction based on the project's progress. This enables optimal corrections according to the project's progress. Some or all of the above processes in the correction unit may be performed using AI, for example, or without AI.

[0049] The correction unit can select the optimal correction method by considering geographical location information. For example, the correction unit can prioritize selecting region-specific correction methods based on the user's current location. It can also select the optimal correction method based on information about the region where the user's project is deployed. Furthermore, the correction unit can select highly relevant correction methods by considering geographical location information. This allows for the selection of a more appropriate correction method by considering geographical relevance. Some or all of the above-described processes in the correction unit may be performed using AI, for example, or without AI.

[0050] The correction unit can analyze social media activity and propose correction methods. For example, the correction unit can prioritize proposing correction methods that are trending on social media. The correction unit can also analyze social media posts and propose relevant correction methods. Furthermore, the correction unit can propose important correction methods based on social media trends. This allows the correction unit to propose important correction methods based on social media trends. Some or all of the above processing in the correction unit may be performed using AI, for example, or not using AI.

[0051] The verification unit can select the optimal verification method by referring to past verification history. For example, the verification unit can select an effective verification method from past verification history. The verification unit can also propose the optimal verification procedure based on past verification history. Furthermore, the verification unit can analyze past verification history and select the most efficient verification method. This enables efficient verification by selecting the optimal verification method based on past history. Some or all of the above processes in the verification unit may be performed using AI, for example, or without using AI.

[0052] The verification unit can select the optimal verification method by considering device information. For example, if the user is using a smartphone, the verification unit provides a verification method that matches the screen size. Furthermore, if the user is using a tablet, the verification unit can provide a verification method optimized for a larger screen. Additionally, if the user is using a smartwatch, the verification unit can provide a concise and highly visible verification method. This enables efficient verification by selecting the optimal verification method based on device information. Some or all of the above-described processes in the verification unit may be performed using AI, for example, or without AI.

[0053] The verification unit can suggest the optimal verification method by referring to the user's past verification history. For example, the verification unit can suggest the optimal verification method based on the verification methods the user has used in the past. The verification unit can also predict and suggest verification methods to be used during specific time periods based on the user's past verification history. Furthermore, the verification unit can analyze the user's past verification history and suggest the most efficient verification method. This enables efficient verification by suggesting the optimal verification method based on past history. Some or all of the above processing in the verification unit may be performed using AI, for example, or without using AI.

[0054] The verification unit can refer to the user's calendar information and propose a verification method based on the schedule. For example, the verification unit can refer to the schedule registered in the user's calendar and propose the most suitable verification method. The verification unit can also propose a verification method related to a specific event from the user's calendar information. Furthermore, the verification unit can propose the most suitable verification method tailored to the schedule based on the user's calendar information. This enables efficient verification by proposing the most suitable verification method based on calendar information. Some or all of the above processing in the verification unit may be performed using AI, for example, or without using AI.

[0055] The system according to the embodiment is not limited to the example described above, and various modifications are possible, for example, as follows.

[0056] The acquisition unit can analyze past vulnerability response history and select the optimal acquisition method. For example, the acquisition unit prioritizes acquiring information on frequently used libraries from past vulnerability response history. The acquisition unit can also select an effective acquisition method for a specific vulnerability based on past response history. Furthermore, the acquisition unit can achieve efficient response by analyzing past history and acquiring data at specific time periods. This enables efficient vulnerability response by selecting the optimal acquisition method based on past history. Some or all of the above processing in the acquisition unit may be performed using AI, for example, or without using AI.

[0057] The data acquisition unit can filter data based on the project's progress and priorities. For example, it can prioritize acquiring information before important milestones, taking into account the project's progress. It can also prioritize acquiring critical vulnerability information based on the project's priorities. Furthermore, the data acquisition unit can adjust the scope of information acquired according to the project's progress. This enables information acquisition tailored to the project's progress. Some or all of the processing described above in the data acquisition unit may be performed using AI, for example, or without AI.

[0058] The data acquisition unit can prioritize the acquisition of highly relevant information by considering geographical location information. For example, the data acquisition unit can prioritize the acquisition of region-specific vulnerability information based on the user's current location. It can also prioritize the acquisition of information about the region where the user's project is being implemented. Furthermore, the data acquisition unit can filter and acquire highly relevant information based on geographical location information. This allows for the acquisition of more appropriate information by considering geographical relevance. Some or all of the above processing in the data acquisition unit may be performed using AI, for example, or without using AI.

[0059] The acquisition unit can analyze social media activity and acquire relevant information. For example, the acquisition unit prioritizes acquiring vulnerability information that is trending on social media. The acquisition unit can also analyze social media posts and acquire relevant vulnerability information. Furthermore, the acquisition unit can filter and acquire important vulnerability information based on social media trends. This allows for the acquisition of important information based on social media trends. Some or all of the above processing in the acquisition unit may be performed using AI, for example, or without using AI.

[0060] The analysis unit can improve the accuracy of its analysis by considering the interrelationships between libraries. For example, the analysis unit can accurately analyze the scope of vulnerability impact by considering dependencies between libraries. Furthermore, the analysis unit can identify the root cause of a vulnerability based on the interrelationships between libraries. In addition, the analysis unit can analyze the interrelationships between libraries and propose the optimal remediation method. This improves the accuracy of the analysis by considering the dependencies between libraries. Some or all of the above-described processes in the analysis unit may be performed using AI, for example, or without AI.

[0061] The analysis unit can perform analysis considering the frequency of use and importance of libraries. For example, the analysis unit can prioritize the analysis of frequently used libraries and evaluate the impact of vulnerabilities. It can also focus on analyzing libraries of high importance and evaluate the risk of vulnerabilities. Furthermore, the analysis unit can determine the priority of analysis based on frequency of use and importance. This enables efficient analysis by determining the priority of analysis based on frequency of use and importance. Some or all of the above processes in the analysis unit may be performed using AI, for example, or without using AI.

[0062] The following briefly describes the processing flow for example form 1.

[0063] Step 1: The acquisition unit retrieves the CVE number and its description, as well as the documentation and version log of the relevant library. For example, it retrieves the CVE number from a security database and collects the documentation and version log of the relevant library. It can also crawl publicly available information on the internet to collect the latest vulnerability information. Furthermore, it can obtain the version log of a specific library based on information provided by the developer. Step 2: The analysis unit checks whether the libraries being used have vulnerabilities based on the information obtained by the acquisition unit. For example, it checks whether vulnerabilities exist in the libraries being used by comparing them with a database of known vulnerabilities. It can also perform security scans to detect vulnerabilities in the libraries. Furthermore, it can use AI to analyze the library code and identify potential vulnerabilities. Step 3: The proposal unit presents proposed solutions and procedures based on the results analyzed by the analysis unit. For example, it may propose patch application procedures or configuration change procedures. It can also provide procedures showing how to fix vulnerabilities. Furthermore, it can use AI to suggest the optimal solution. Step 4: The correction unit automatically corrects the parts that can be corrected based on the solutions proposed by the proposal unit. For example, it can automatically modify code or change configuration files. It can also use AI to identify the areas that need correction and perform the corrections automatically. Furthermore, it can automatically perform corrections according to the correction procedures provided by the developer. Step 5: The verification section checks the changes made by the correction section. For example, it reviews the corrected parts and checks for any problems. It is also possible to automatically verify the changes using AI. Furthermore, it is possible to verify the changes by following the verification procedures provided by the developer.

[0064] (Example of form 2) The vulnerability response support system according to an embodiment of the present invention is a system for solving the "vulnerability response" problem that developers face when quickly coding orders from management and releasing them. This system provides AI that quickly tells the system which version and migration target to the vulnerability library. This AI system acquires vulnerability information such as CVEs, proposes countermeasures when vulnerabilities are found, and can automatically perform minor fixes. First, when a developer submits a Pull Request (PR), the AI ​​checks whether the library being used has vulnerabilities. If a vulnerability is found as a result of the check, the AI ​​presents several suggestions and procedures on how to deal with it, prompting the developer who submitted the PR to make a decision. After a decision is made, the AI ​​automatically commits the parts that can be fixed as fixes to the PR. After that, a reviewer checks it, and if there are no problems, it is merged as is. If there are problems, the problem is communicated to the AI ​​again, or the fix is ​​performed manually and feedback is given to the AI. This system reduces the burden of vulnerability response for engineers, allowing them to focus more on development. For example, the CVE number and its description, the documentation and version log of the relevant library are entered. Next, the AI ​​retrieves vulnerability information such as CVEs and checks whether the libraries being used have vulnerabilities. If vulnerabilities are found as a result of the check, the AI ​​provides suggested solutions and procedures. The developer decides on a solution, and the AI ​​automatically commits the parts that can be fixed to a pull request. A reviewer checks it, and if there are no problems, it is merged. If there are problems, the developer either informs the AI ​​of the problem again or fixes it manually and provides feedback to the AI. This system can obtain vulnerability information such as CVEs because it is publicly available, and it can be trained on current large-scale language models (LLMs). This is expected to allow engineers to focus more on development and improve productivity. In this way, the vulnerability response support system reduces the burden of vulnerability response for engineers, allowing them to focus more on development.

[0065] The vulnerability response support system according to the embodiment comprises an acquisition unit, an analysis unit, a proposal unit, a correction unit, and a verification unit. The acquisition unit acquires CVE numbers and their descriptions, as well as documentation and version logs for the relevant libraries. For example, the acquisition unit acquires CVE numbers from a security database and collects documentation and version logs for the relevant libraries. The acquisition unit can also crawl publicly available information on the internet to collect the latest vulnerability information. Furthermore, the acquisition unit can acquire version logs for specific libraries based on information provided by the developers. The analysis unit checks whether the libraries being used have vulnerabilities based on the information acquired by the acquisition unit. For example, the analysis unit checks whether vulnerabilities exist in the libraries being used by comparing them with a known vulnerability database. The analysis unit can also perform security scans to detect vulnerabilities in libraries. Furthermore, the analysis unit can use AI to analyze the library code and identify potential vulnerabilities. The proposal unit presents proposed countermeasures and procedures based on the results analyzed by the analysis unit. For example, the proposal unit proposes patch application procedures and configuration change procedures. Furthermore, the proposal unit can provide a procedural manual showing how to fix the vulnerability. In addition, the proposal unit can use AI to suggest the optimal remediation method. The correction unit automatically corrects the parts that can be corrected based on the remediation method proposed by the proposal unit. For example, the correction unit automatically modifies code and changes configuration files. The correction unit can also use AI to identify the areas that need correction and automatically perform the corrections. Furthermore, the correction unit can also automatically perform corrections according to the correction procedures provided by the developer. The verification unit verifies the content corrected by the correction unit. For example, the verification unit reviews the corrected areas and checks for any problems. Furthermore, the verification unit can use AI to automatically verify the content of the corrections. Furthermore, the verification unit can also verify the content of the corrections according to the verification procedures provided by the developer. As a result, the vulnerability response support system according to the embodiment reduces the burden of vulnerability response on engineers, allowing them to focus more on development.

[0066] The acquisition unit retrieves CVE numbers and their descriptions, as well as documentation and version logs for the relevant libraries. Specifically, the acquisition unit retrieves CVE numbers from security databases and collects their detailed descriptions. CVE numbers are widely used as Common Vulnerabilities and Exposure Identifiers and provide detailed information about specific vulnerabilities. Based on this information, the acquisition unit collects documentation and version logs for the relevant libraries. Library documentation describes the library's functions, usage, and known issues, while version logs describe changes and fixes in each version. This allows the acquisition unit to centrally collect detailed information about vulnerabilities and related libraries. Furthermore, the acquisition unit can also collect the latest vulnerability information by crawling publicly available information on the internet. For example, it collects the latest information from security forums, developer communities, and official security advisories and incorporates it into the system. The acquisition unit can also obtain version logs for specific libraries based on information provided by developers. This allows the acquisition unit to quickly collect the latest vulnerability information and improve the overall security of the system.

[0067] The analysis unit checks whether the libraries being used have vulnerabilities based on the information acquired by the acquisition unit. Specifically, the analysis unit compares the data with a database of known vulnerabilities to confirm whether vulnerabilities exist in the libraries being used. The vulnerability database contains information on vulnerabilities reported in the past and how to address them, and the analysis unit uses this to evaluate the security of the libraries. The analysis unit can also perform security scans to detect vulnerabilities in libraries. Security scans are tools for analyzing the library's code and configuration files to identify known and potential vulnerabilities. Furthermore, the analysis unit can use AI to analyze the library's code and identify potential vulnerabilities. The AI ​​uses machine learning algorithms to learn from past vulnerability data and predict new vulnerabilities. For example, it can analyze code patterns and structures to identify areas where vulnerabilities are likely to occur. This allows the analysis unit to quickly and accurately analyze the collected data and understand the vulnerabilities of the libraries being used in real time. In addition, the analysis unit can utilize historical data and statistical information to perform long-term risk assessments and trend analysis. This allows the analysis unit to not only understand the situation in real time but also to handle long-term risk management and anomaly detection, improving the reliability and security of the entire system.

[0068] The proposal department, based on the results of the analysis conducted by the analysis department, presents proposed countermeasures and procedures. Specifically, the proposal department proposes patch application procedures and configuration change procedures. Patch application procedures outline the steps for updating software to fix vulnerabilities, while configuration change procedures show how to modify system settings to circumvent vulnerabilities. The proposal department can also provide procedure manuals outlining how to fix vulnerabilities. These manuals include specific correction steps and points to note, helping engineers to address vulnerabilities quickly and accurately. Furthermore, the proposal department can use AI to propose the optimal countermeasures. The AI ​​learns from past countermeasures and their effectiveness, and proposes the most effective countermeasures. For example, it can propose the optimal patch application procedures and configuration change procedures based on past countermeasures for similar vulnerabilities. This allows the proposal department to help engineers address vulnerabilities quickly and effectively, improving the overall system security. In addition, the proposal department can evaluate the effectiveness of countermeasures and make improvement suggestions as needed. This allows the proposal department to always provide the optimal countermeasures based on the latest information, continuously improving system security.

[0069] The fix unit automatically corrects fixable parts based on the countermeasures proposed by the proposal unit. Specifically, the fix unit automatically modifies code and changes configuration files. For example, it applies patches to fix vulnerabilities and makes necessary configuration changes. The fix unit can also use AI to identify and automatically fix the affected areas. The AI ​​learns from past fix data and proposes the optimal fix method. For example, it can propose the optimal fix procedure based on past fixes for similar vulnerabilities and automatically perform the fix. Furthermore, the fix unit can automatically perform fixes according to the fix procedures provided by the developer. This allows the fix unit to reduce the workload on engineers and fix vulnerabilities quickly and accurately. In addition, the fix unit records the fix details for later review. This allows the fix unit to manage the fix history and review the fix details as needed. In this way, the fix unit can help engineers fix vulnerabilities quickly and accurately, improving the overall system security.

[0070] The verification unit verifies the changes made by the correction unit. Specifically, the verification unit reviews the corrected areas and checks for any problems. For example, it checks the corrected code and configuration files to confirm that vulnerabilities have been properly fixed. The verification unit can also use AI to automatically verify the corrected content. The AI ​​analyzes the corrected content and confirms that vulnerabilities have been properly fixed. For example, it can analyze the corrected code and check whether vulnerabilities will reappear. Furthermore, the verification unit can also verify the corrected content according to the verification procedures provided by the developer. This allows the verification unit to confirm that the corrected content is appropriate and ensure the security of the entire system. In addition, the verification unit can evaluate the effectiveness of the corrected content and suggest additional corrections as needed. This allows the verification unit to perform highly accurate verifications based on the latest information at all times, continuously improving the security of the system.

[0071] The acquisition unit can estimate the user's emotions and adjust the timing of acquiring CVE numbers and library information based on the estimated emotions. For example, if the user is stressed, the acquisition unit can delay the acquisition timing and acquire the information when the user is relaxed. Furthermore, if the user is in a hurry, the acquisition unit can immediately acquire CVE numbers and library information to enable a quick response. Additionally, if the user is concentrating, the acquisition unit can adjust the acquisition timing to minimize interruptions to their work. This reduces user stress by adjusting the timing of information acquisition according to the user's emotions. Emotion estimation is achieved using an emotion estimation function, such as an emotion engine or generative AI. Generative AI includes, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI.

[0072] The acquisition unit can analyze past vulnerability response history and select the optimal acquisition method. For example, the acquisition unit prioritizes acquiring information on frequently used libraries from past vulnerability response history. The acquisition unit can also select an effective acquisition method for a specific vulnerability based on past response history. Furthermore, the acquisition unit can achieve efficient response by analyzing past history and acquiring data at specific time periods. This enables efficient vulnerability response by selecting the optimal acquisition method based on past history. Some or all of the above processing in the acquisition unit may be performed using AI, for example, or without using AI.

[0073] The data acquisition unit can filter data based on the project's progress and priorities. For example, it can prioritize acquiring information before important milestones, taking into account the project's progress. It can also prioritize acquiring critical vulnerability information based on the project's priorities. Furthermore, the data acquisition unit can adjust the scope of information acquired according to the project's progress. This enables information acquisition tailored to the project's progress. Some or all of the processing described above in the data acquisition unit may be performed using AI, for example, or without AI.

[0074] The information acquisition unit can estimate the user's emotions and determine the priority of information to acquire based on the estimated emotions. For example, if the user is stressed, the acquisition unit will postpone less important information and prioritize acquiring more important information. If the user is relaxed, the acquisition unit can acquire all information equally. Furthermore, if the user is in a hurry, the acquisition unit can prioritize acquiring only the most important information. In this way, by adjusting the priority of information according to the user's emotions, important information can be acquired preferentially. Emotion estimation is achieved using an emotion estimation function, for example, using an emotion engine or generative AI. Generative AI is, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI.

[0075] The data acquisition unit can prioritize the acquisition of highly relevant information by considering geographical location information. For example, the data acquisition unit can prioritize the acquisition of region-specific vulnerability information based on the user's current location. It can also prioritize the acquisition of information about the region where the user's project is being implemented. Furthermore, the data acquisition unit can filter and acquire highly relevant information based on geographical location information. This allows for the acquisition of more appropriate information by considering geographical relevance. Some or all of the above processing in the data acquisition unit may be performed using AI, for example, or without using AI.

[0076] The acquisition unit can analyze social media activity and acquire relevant information. For example, the acquisition unit prioritizes acquiring vulnerability information that is trending on social media. The acquisition unit can also analyze social media posts and acquire relevant vulnerability information. Furthermore, the acquisition unit can filter and acquire important vulnerability information based on social media trends. This allows for the acquisition of important information based on social media trends. Some or all of the above processing in the acquisition unit may be performed using AI, for example, or without using AI.

[0077] The analysis unit can estimate the user's emotions and adjust the analysis criteria based on the estimated emotions. For example, if the user is stressed, the analysis unit can relax the analysis criteria and provide results quickly. If the user is relaxed, the analysis unit can perform a detailed analysis and provide highly accurate results. Furthermore, if the user is in a hurry, the analysis unit can focus on the most important points. This allows for quick and appropriate analysis by adjusting the analysis criteria according to the user's emotions. Emotion estimation is achieved using an emotion estimation function, such as an emotion engine or generative AI. Generative AI includes, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI.

[0078] The analysis unit can improve the accuracy of its analysis by considering the interrelationships between libraries. For example, the analysis unit can accurately analyze the scope of vulnerability impact by considering dependencies between libraries. Furthermore, the analysis unit can identify the root cause of a vulnerability based on the interrelationships between libraries. In addition, the analysis unit can analyze the interrelationships between libraries and propose the optimal remediation method. This improves the accuracy of the analysis by considering the dependencies between libraries. Some or all of the above-described processes in the analysis unit may be performed using AI, for example, or without AI.

[0079] The analysis unit can perform analysis considering the frequency of use and importance of libraries. For example, the analysis unit can prioritize the analysis of frequently used libraries and evaluate the impact of vulnerabilities. It can also focus on analyzing libraries of high importance and evaluate the risk of vulnerabilities. Furthermore, the analysis unit can determine the priority of analysis based on frequency of use and importance. This enables efficient analysis by determining the priority of analysis based on frequency of use and importance. Some or all of the above processes in the analysis unit may be performed using AI, for example, or without using AI.

[0080] The analysis unit can estimate the user's emotions and adjust the display order of the analysis results based on the estimated emotions. For example, if the user is stressed, the analysis unit can display important results first and detailed results later. If the user is relaxed, the analysis unit can also display detailed results in order. Furthermore, if the user is in a hurry, the analysis unit can display results that summarize the key points first. In this way, important information can be provided quickly by adjusting the display order of analysis results according to the user's emotions. Emotion estimation is achieved using an emotion estimation function, for example, using an emotion engine or generative AI. Generative AI is, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI.

[0081] The analysis unit can perform analysis while considering geographical distribution. For example, the analysis unit prioritizes analyzing vulnerability information in geographically close areas. The analysis unit can also evaluate the scope of vulnerability impact based on geographical distribution. Furthermore, the analysis unit can propose optimal countermeasures while considering geographical distribution. This allows for more appropriate analysis by considering geographical relationships. Some or all of the above-described processes in the analysis unit may be performed using AI, for example, or without using AI.

[0082] The analysis unit can improve the accuracy of its analysis by referring to relevant literature. For example, the analysis unit can analyze the impact of the vulnerability in detail based on the relevant literature. The analysis unit can also refer to the relevant literature and propose the optimal remediation method. Furthermore, the analysis unit can identify the root cause of the vulnerability based on the relevant literature. As a result, the accuracy of the analysis is improved by performing the analysis based on relevant literature. Some or all of the above processes in the analysis unit may be performed using AI, for example, or without using AI.

[0083] The suggestion function can estimate the user's emotions and adjust the way it presents suggestions based on those emotions. For example, if the user is stressed, the suggestion function will provide simple and easy-to-understand suggestions. If the user is relaxed, it can also provide suggestions with detailed explanations. Furthermore, if the user is in a hurry, it can provide suggestions that get straight to the point. By adjusting the way suggestions are presented according to the user's emotions, more effective suggestions become possible. Emotion estimation is achieved using emotion estimation functions, such as emotion engines or generative AI. Generative AI includes, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI.

[0084] The proposal unit can adjust the level of detail of its proposals based on the severity of the vulnerability. For example, the proposal unit will provide detailed proposals for high-severity vulnerabilities. Conversely, it can provide concise proposals for low-severity vulnerabilities. Furthermore, the proposal unit can adjust the level of detail of its proposals according to the severity. This allows for appropriate countermeasures to be implemented by adjusting the level of detail of proposals according to the severity of the vulnerability. Some or all of the above processing in the proposal unit may be performed using AI, for example, or without using AI.

[0085] The proposal unit can apply different proposal algorithms depending on the vulnerability category. For example, the proposal unit may apply a specific proposal algorithm to SQL injection vulnerabilities. It may also apply a different proposal algorithm to cross-site scripting vulnerabilities. Furthermore, the proposal unit can select the optimal proposal algorithm depending on the vulnerability category. This enables optimal proposals tailored to each vulnerability category. Some or all of the above processing in the proposal unit may be performed using AI, for example, or without AI.

[0086] The suggestion function can estimate the user's emotions and adjust the length of the suggestions based on those emotions. For example, if the user is stressed, the suggestion function will provide short, concise suggestions. If the user is relaxed, the suggestion function can provide longer suggestions with more detailed explanations. Furthermore, if the user is in a hurry, the suggestion function can provide concise and quick suggestions. By adjusting the length of suggestions according to the user's emotions, more effective suggestions can be made. Emotion estimation is achieved using emotion estimation functions, such as emotion engines or generative AI. Generative AI includes, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI.

[0087] The proposal department can determine the priority of proposals based on when the vulnerability was discovered. For example, the proposal department will prioritize proposals for recently discovered vulnerabilities. Conversely, the proposal department may postpone proposals for older vulnerabilities. Furthermore, the proposal department can adjust the priority of proposals based on when they were discovered. This allows for a rapid response by adjusting the priority of proposals according to when the vulnerability was discovered. Some or all of the above processes in the proposal department may be performed using AI, for example, or not using AI.

[0088] The proposal unit can adjust the order of proposals based on the relevance of the vulnerabilities. For example, the proposal unit will prioritize proposals for highly relevant vulnerabilities. It can also postpone proposals for less relevant vulnerabilities. Furthermore, the proposal unit can adjust the order of proposals based on relevance. This enables proposals to be tailored to the relevance of the vulnerabilities. Some or all of the above processing in the proposal unit may be performed using AI, for example, or without AI.

[0089] The correction unit can estimate the user's emotions and adjust the correction method based on the estimated emotions. For example, if the user is stressed, the correction unit can provide a simple and quick correction method. It can also provide detailed correction steps if the user is relaxed. Furthermore, if the user is in a hurry, the correction unit can provide the most effective correction method. This allows for quick and appropriate correction by adjusting the correction method according to the user's emotions. Emotion estimation is achieved using an emotion estimation function, such as an emotion engine or generative AI. Generative AI includes, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI.

[0090] The correction unit can analyze past correction history and select the optimal correction method. For example, the correction unit can select an effective correction method from past correction history. The correction unit can also propose the optimal correction procedure based on past correction history. Furthermore, the correction unit can analyze past correction history and select the most efficient correction method. This enables efficient correction by selecting the optimal correction method based on past history. Some or all of the above processes in the correction unit may be performed using AI, for example, or without using AI.

[0091] The correction unit can customize the means of correction based on the project's progress. For example, the correction unit can prioritize corrections before important milestones, taking into account the project's progress. The correction unit can also adjust the means of correction according to the project's progress. Furthermore, the correction unit can select the optimal means of correction based on the project's progress. This enables optimal corrections according to the project's progress. Some or all of the above processes in the correction unit may be performed using AI, for example, or without AI.

[0092] The editing unit can estimate the user's emotions and determine the priority of corrections based on those emotions. For example, if the user is stressed, the editing unit will prioritize high-priority corrections. If the user is relaxed, the editing unit can also distribute all corrections evenly. Furthermore, if the user is in a hurry, the editing unit can prioritize the most important corrections. This allows for prioritizing important corrections by adjusting the priority of corrections according to the user's emotions. Emotion estimation is achieved using emotion estimation functions, such as emotion engines or generative AI. Generative AI includes, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI.

[0093] The correction unit can select the optimal correction method by considering geographical location information. For example, the correction unit can prioritize selecting region-specific correction methods based on the user's current location. It can also select the optimal correction method based on information about the region where the user's project is deployed. Furthermore, the correction unit can select highly relevant correction methods by considering geographical location information. This allows for the selection of a more appropriate correction method by considering geographical relevance. Some or all of the above-described processes in the correction unit may be performed using AI, for example, or without AI.

[0094] The correction unit can analyze social media activity and propose correction methods. For example, the correction unit can prioritize proposing correction methods that are trending on social media. The correction unit can also analyze social media posts and propose relevant correction methods. Furthermore, the correction unit can propose important correction methods based on social media trends. This allows the correction unit to propose important correction methods based on social media trends. Some or all of the above processing in the correction unit may be performed using AI, for example, or not using AI.

[0095] The verification unit can estimate the user's emotions and adjust the verification method based on the estimated emotions. For example, if the user is stressed, the verification unit can provide a simple and quick verification method. If the user is relaxed, the verification unit can also provide a detailed verification procedure. Furthermore, if the user is in a hurry, the verification unit can provide the most effective verification method. This allows for quick and appropriate verification by adjusting the verification method according to the user's emotions. Emotion estimation is achieved using an emotion estimation function, for example, using an emotion engine or generative AI. Generative AI includes, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI.

[0096] The verification unit can select the optimal verification method by referring to past verification history. For example, the verification unit can select an effective verification method from past verification history. The verification unit can also propose the optimal verification procedure based on past verification history. Furthermore, the verification unit can analyze past verification history and select the most efficient verification method. This enables efficient verification by selecting the optimal verification method based on past history. Some or all of the above processes in the verification unit may be performed using AI, for example, or without using AI.

[0097] The verification unit can estimate the user's emotions and determine the priority of verifications based on the estimated emotions. For example, if the user is stressed, the verification unit will prioritize high-priority verifications. If the user is relaxed, the verification unit can perform all verifications equally. Furthermore, if the user is in a hurry, the verification unit can prioritize the most important verifications. In this way, important verifications can be prioritized by adjusting the priority of verifications according to the user's emotions. Emotion estimation is achieved using an emotion estimation function, for example, using an emotion engine or generative AI. Generative AI is, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI.

[0098] The verification unit can select the optimal verification method by considering device information. For example, if the user is using a smartphone, the verification unit provides a verification method that matches the screen size. Furthermore, if the user is using a tablet, the verification unit can provide a verification method optimized for a larger screen. Additionally, if the user is using a smartwatch, the verification unit can provide a concise and highly visible verification method. This enables efficient verification by selecting the optimal verification method based on device information. Some or all of the above-described processes in the verification unit may be performed using AI, for example, or without AI.

[0099] The verification unit can suggest the optimal verification method by referring to the user's past verification history. For example, the verification unit can suggest the optimal verification method based on the verification methods the user has used in the past. The verification unit can also predict and suggest verification methods to be used during specific time periods based on the user's past verification history. Furthermore, the verification unit can analyze the user's past verification history and suggest the most efficient verification method. This enables efficient verification by suggesting the optimal verification method based on past history. Some or all of the above processing in the verification unit may be performed using AI, for example, or without using AI.

[0100] The verification unit can refer to the user's calendar information and propose a verification method based on the schedule. For example, the verification unit can refer to the schedule registered in the user's calendar and propose the most suitable verification method. The verification unit can also propose a verification method related to a specific event from the user's calendar information. Furthermore, the verification unit can propose the most suitable verification method tailored to the schedule based on the user's calendar information. This enables efficient verification by proposing the most suitable verification method based on calendar information. Some or all of the above processing in the verification unit may be performed using AI, for example, or without using AI.

[0101] The system according to the embodiment is not limited to the example described above, and various modifications are possible, for example, as follows.

[0102] The acquisition unit can estimate the user's emotions and adjust the timing of acquiring CVE numbers and library information based on the estimated emotions. For example, if the user is stressed, the acquisition unit can delay the acquisition timing and acquire the information when the user is relaxed. Furthermore, if the user is in a hurry, the acquisition unit can immediately acquire CVE numbers and library information to enable a quick response. Additionally, if the user is concentrating, the acquisition unit can adjust the acquisition timing to minimize interruptions to their work. This reduces user stress by adjusting the timing of information acquisition according to the user's emotions. Emotion estimation is achieved using an emotion estimation function, such as an emotion engine or generative AI. Generative AI includes, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI.

[0103] The acquisition unit can analyze past vulnerability response history and select the optimal acquisition method. For example, the acquisition unit prioritizes acquiring information on frequently used libraries from past vulnerability response history. The acquisition unit can also select an effective acquisition method for a specific vulnerability based on past response history. Furthermore, the acquisition unit can achieve efficient response by analyzing past history and acquiring data at specific time periods. This enables efficient vulnerability response by selecting the optimal acquisition method based on past history. Some or all of the above processing in the acquisition unit may be performed using AI, for example, or without using AI.

[0104] The data acquisition unit can filter data based on the project's progress and priorities. For example, it can prioritize acquiring information before important milestones, taking into account the project's progress. It can also prioritize acquiring critical vulnerability information based on the project's priorities. Furthermore, the data acquisition unit can adjust the scope of information acquired according to the project's progress. This enables information acquisition tailored to the project's progress. Some or all of the processing described above in the data acquisition unit may be performed using AI, for example, or without AI.

[0105] The information acquisition unit can estimate the user's emotions and determine the priority of information to acquire based on the estimated emotions. For example, if the user is stressed, the acquisition unit will postpone less important information and prioritize acquiring more important information. If the user is relaxed, the acquisition unit can acquire all information equally. Furthermore, if the user is in a hurry, the acquisition unit can prioritize acquiring only the most important information. In this way, by adjusting the priority of information according to the user's emotions, important information can be acquired preferentially. Emotion estimation is achieved using an emotion estimation function, for example, using an emotion engine or generative AI. Generative AI is, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI.

[0106] The data acquisition unit can prioritize the acquisition of highly relevant information by considering geographical location information. For example, the data acquisition unit can prioritize the acquisition of region-specific vulnerability information based on the user's current location. It can also prioritize the acquisition of information about the region where the user's project is being implemented. Furthermore, the data acquisition unit can filter and acquire highly relevant information based on geographical location information. This allows for the acquisition of more appropriate information by considering geographical relevance. Some or all of the above processing in the data acquisition unit may be performed using AI, for example, or without using AI.

[0107] The acquisition unit can analyze social media activity and acquire relevant information. For example, the acquisition unit prioritizes acquiring vulnerability information that is trending on social media. The acquisition unit can also analyze social media posts and acquire relevant vulnerability information. Furthermore, the acquisition unit can filter and acquire important vulnerability information based on social media trends. This allows for the acquisition of important information based on social media trends. Some or all of the above processing in the acquisition unit may be performed using AI, for example, or without using AI.

[0108] The analysis unit can estimate the user's emotions and adjust the analysis criteria based on the estimated emotions. For example, if the user is stressed, the analysis unit can relax the analysis criteria and provide results quickly. If the user is relaxed, the analysis unit can perform a detailed analysis and provide highly accurate results. Furthermore, if the user is in a hurry, the analysis unit can focus on the most important points. This allows for quick and appropriate analysis by adjusting the analysis criteria according to the user's emotions. Emotion estimation is achieved using an emotion estimation function, such as an emotion engine or generative AI. Generative AI includes, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI.

[0109] The analysis unit can improve the accuracy of its analysis by considering the interrelationships between libraries. For example, the analysis unit can accurately analyze the scope of vulnerability impact by considering dependencies between libraries. Furthermore, the analysis unit can identify the root cause of a vulnerability based on the interrelationships between libraries. In addition, the analysis unit can analyze the interrelationships between libraries and propose the optimal remediation method. This improves the accuracy of the analysis by considering the dependencies between libraries. Some or all of the above-described processes in the analysis unit may be performed using AI, for example, or without AI.

[0110] The analysis unit can perform analysis considering the frequency of use and importance of libraries. For example, the analysis unit can prioritize the analysis of frequently used libraries and evaluate the impact of vulnerabilities. It can also focus on analyzing libraries of high importance and evaluate the risk of vulnerabilities. Furthermore, the analysis unit can determine the priority of analysis based on frequency of use and importance. This enables efficient analysis by determining the priority of analysis based on frequency of use and importance. Some or all of the above processes in the analysis unit may be performed using AI, for example, or without using AI.

[0111] The analysis unit can estimate the user's emotions and adjust the display order of the analysis results based on the estimated emotions. For example, if the user is stressed, the analysis unit can display important results first and detailed results later. If the user is relaxed, the analysis unit can also display detailed results in order. Furthermore, if the user is in a hurry, the analysis unit can display results that summarize the key points first. In this way, important information can be provided quickly by adjusting the display order of analysis results according to the user's emotions. Emotion estimation is achieved using an emotion estimation function, for example, using an emotion engine or generative AI. Generative AI is, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI.

[0112] The following briefly describes the processing flow for example form 2.

[0113] Step 1: The acquisition unit retrieves the CVE number and its description, as well as the documentation and version log of the relevant library. For example, it retrieves the CVE number from a security database and collects the documentation and version log of the relevant library. It can also crawl publicly available information on the internet to collect the latest vulnerability information. Furthermore, it can obtain the version log of a specific library based on information provided by the developer. Step 2: The analysis unit checks whether the libraries being used have vulnerabilities based on the information obtained by the acquisition unit. For example, it checks whether vulnerabilities exist in the libraries being used by comparing them with a database of known vulnerabilities. It can also perform security scans to detect vulnerabilities in the libraries. Furthermore, it can use AI to analyze the library code and identify potential vulnerabilities. Step 3: The proposal unit presents proposed solutions and procedures based on the results analyzed by the analysis unit. For example, it may propose patch application procedures or configuration change procedures. It can also provide procedures showing how to fix vulnerabilities. Furthermore, it can use AI to suggest the optimal solution. Step 4: The correction unit automatically corrects the parts that can be corrected based on the solutions proposed by the proposal unit. For example, it can automatically modify code or change configuration files. It can also use AI to identify the areas that need correction and perform the corrections automatically. Furthermore, it can automatically perform corrections according to the correction procedures provided by the developer. Step 5: The verification section checks the changes made by the correction section. For example, it reviews the corrected parts and checks for any problems. It is also possible to automatically verify the changes using AI. Furthermore, it is possible to verify the changes by following the verification procedures provided by the developer.

[0114] The specific processing unit 290 transmits the result of the specific processing to the smart device 14. In the smart device 14, the control unit 46A causes the output device 40 to output the result of the specific processing. The microphone 38B acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.

[0115] Data generation model 58 is a form of so-called generative AI (Artificial Intelligence). An example of data generation model 58 is ChatGPT (registered trademark) (Internet search).<URL: https: / / openai.com / blog / chatgpt> Examples of generative AI include text generation AI, image generation AI, and multimodal generation AI. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images (e.g., still image data or video data). The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference result in one or more data formats from audio data, text data, and image data. The data generation model 58 includes, for example, text generation AI, image generation AI, and multimodal generation AI. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization. The specific processing unit 290 performs the specific processing described above using the data generation model 58. The data generation model 58 may be a fine-tuned model that outputs inference results from prompts that do not contain instructions, in which case the data generation model 58 can output inference results from prompts that do not contain instructions. In the data processing device 12, etc., there are multiple types of data generation models 58, and the data generation model 58 includes AI other than generative AI. AI other than generative AI includes, for example, linear regression, logistic regression, decision trees, random forests, support vector machines (SVMs), k-means clustering, convolutional neural networks (CNNs), recurrent neural networks (RNNs), generative adversarial networks (GANs), or naive Bayes, and can perform various processes, but is not limited to these examples. Also, the AI ​​may be an AI agent. Furthermore, when the processing of each of the above parts is performed by the AI, the processing may be performed by the AI ​​in part or in whole, but is not limited to this example.Furthermore, processing performed by AI, including generative AI, may be replaced with rule-based processing, and rule-based processing may be replaced with processing performed by AI, including generative AI.

[0116] Furthermore, the processing performed by the data processing system 10 described above is carried out by the specific processing unit 290 of the data processing device 12 or the control unit 46A of the smart device 14, but it may also be carried out by the specific processing unit 290 of the data processing device 12 and the control unit 46A of the smart device 14. In addition, the specific processing unit 290 of the data processing device 12 acquires or collects information necessary for processing from the smart device 14 or an external device, and the smart device 14 acquires or collects information necessary for processing from the data processing device 12 or an external device.

[0117] Each of the multiple elements described above, including the acquisition unit, analysis unit, proposal unit, modification unit, and verification unit, is implemented in at least one of the smart device 14 and the data processing unit 12. For example, the acquisition unit is implemented by the control unit 46A of the smart device 14 or the specific processing unit 290 of the data processing unit 12. The analysis unit is implemented by the specific processing unit 290 of the data processing unit 12. The proposal unit is implemented by the specific processing unit 290 of the data processing unit 12. The modification unit is implemented by the control unit 46A of the smart device 14 or the specific processing unit 290 of the data processing unit 12. The verification unit is implemented by the control unit 46A of the smart device 14 or the specific processing unit 290 of the data processing unit 12. The correspondence between each unit and the device or control unit is not limited to the example described above, and various changes are possible.

[0118] [Second Embodiment] Figure 3 shows an example of the configuration of the data processing system 210 according to the second embodiment.

[0119] As shown in Figure 3, the data processing system 210 includes a data processing device 12 and smart glasses 214. An example of the data processing device 12 is a server.

[0120] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN and / or LAN.

[0121] The smart glasses 214 include a computer 36, a microphone 238, a speaker 240, a camera 42, and a communication interface 44. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, and camera 42 are also connected to the bus 52.

[0122] The microphone 238 receives voice signals from the user and accepts instructions from the user. The microphone 238 captures the voice signals from the user, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.

[0123] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, which captures images of the area around the user (for example, an imaging range defined by a field of view equivalent to the field of vision of a typical healthy person).

[0124] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.

[0125] Figure 4 shows an example of the main functions of the data processing device 12 and the smart glasses 214. As shown in Figure 4, the data processing device 12 performs specific processing by the processor 28. The storage 32 stores the specific processing program 56.

[0126] The processor 28 reads a specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 acting as a specific processing unit 290 according to the specific processing program 56 executed on the RAM 30.

[0127] Storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290. The identification processing unit 290 can estimate the user's emotions using the emotion identification model 59 and perform identification processing using the user's emotions. The emotion estimation function (emotion identification function) using the emotion identification model 59 performs various estimations and predictions regarding the user's emotions, including but not limited to these examples. Furthermore, emotion estimation and prediction also include, for example, emotion analysis.

[0128] In the smart glasses 214, specific processing is performed by the processor 46. The storage 50 stores a specific processing program 60. The processor 46 reads the specific processing program 60 from the storage 50 and executes the read specific processing program 60 on the RAM 48. The specific processing is realized by the processor 46 acting as a control unit 46A according to the specific processing program 60 executed on the RAM 48. The smart glasses 214 also have a data generation model 58 and an emotion identification model 59, similar to the data generation model and emotion identification model 59, and can perform processing similar to that of the specific processing unit 290 using these models.

[0129] Furthermore, other devices besides the data processing device 12 may also have the data generation model 58. For example, a server device may have the data generation model 58. In this case, the data processing device 12 obtains processing results (such as prediction results) using the data generation model 58 by communicating with the server device that has the data generation model 58. Also, the data processing device 12 may be a server device or a terminal device owned by the user (for example, a mobile phone, robot, home appliance, etc.).

[0130] The specific processing unit 290 transmits the result of the specific processing to the smart glasses 214. In the smart glasses 214, the control unit 46A causes the speaker 240 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.

[0131] The data generation model 58 is a so-called generative AI. An example of a data generation model 58 is a generative AI such as ChatGPT. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and inference data such as audio data representing speech, text data representing text, and image data representing images (e.g., still image data or video data). The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference result in one or more data formats such as audio data, text data, and image data. The data generation model 58 includes, for example, text generation AI, image generation AI, and multimodal generation AI. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization. The specific processing unit 290 performs the specific processing described above using the data generation model 58. The data generation model 58 may be a fine-tuned model that outputs inference results from prompts that do not contain instructions, in which case the data generation model 58 can output inference results from prompts that do not contain instructions. In the data processing device 12, etc., there are multiple types of data generation models 58, and the data generation model 58 includes AI other than generative AI. AI other than generative AI includes, for example, linear regression, logistic regression, decision trees, random forests, support vector machines (SVM), k-means clustering, convolutional neural networks (CNN), recurrent neural networks (RNN), generative adversarial networks (GAN), or naive Bayes, and can perform various processes, but is not limited to these examples. Also, the AI ​​may be an AI agent. Furthermore, when the processing of each part described above is performed by the AI, the processing may be performed by the AI ​​in part or in whole, but is not limited to this example. Also, processing performed by an AI including a generative AI may be replaced by rule-based processing, and rule-based processing may be replaced by processing performed by an AI including a generative AI.

[0132] The data processing system 210 according to the second embodiment performs the same processing as the data processing system 10 according to the first embodiment. The processing by the data processing system 210 is performed by the specific processing unit 290 of the data processing device 12 or the control unit 46A of the smart glasses 214, but it may also be performed by the specific processing unit 290 of the data processing device 12 and the control unit 46A of the smart glasses 214. In addition, the specific processing unit 290 of the data processing device 12 acquires or collects information necessary for processing from the smart glasses 214 or an external device, and the smart glasses 214 acquires or collects information necessary for processing from the data processing device 12 or an external device.

[0133] Each of the multiple elements described above, including the acquisition unit, analysis unit, proposal unit, modification unit, and verification unit, is implemented, for example, in at least one of the smart glasses 214 and the data processing unit 12. For example, the acquisition unit is implemented by the control unit 46A of the smart glasses 214 or the specific processing unit 290 of the data processing unit 12. The analysis unit is implemented, for example, by the specific processing unit 290 of the data processing unit 12. The proposal unit is implemented, for example, by the specific processing unit 290 of the data processing unit 12. The modification unit is implemented, for example, by the control unit 46A of the smart glasses 214 or the specific processing unit 290 of the data processing unit 12. The verification unit is implemented, for example, by the control unit 46A of the smart glasses 214 or the specific processing unit 290 of the data processing unit 12. The correspondence between each unit and the device or control unit is not limited to the example described above, and various changes are possible.

[0134] [Third Embodiment] Figure 5 shows an example of the configuration of the data processing system 310 according to the third embodiment.

[0135] As shown in Figure 5, the data processing system 310 includes a data processing device 12 and a headset terminal 314. An example of the data processing device 12 is a server.

[0136] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN and / or LAN.

[0137] The headset terminal 314 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication interface 44, and a display 343. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, camera 42, and display 343 are also connected to the bus 52.

[0138] The microphone 238 receives voice signals from the user and accepts instructions from the user. The microphone 238 captures the voice signals from the user, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.

[0139] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, which captures images of the area around the user (for example, an imaging range defined by a field of view equivalent to the field of vision of a typical healthy person).

[0140] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.

[0141] Figure 6 shows an example of the main functions of the data processing device 12 and the headset terminal 314. As shown in Figure 6, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.

[0142] The processor 28 reads a specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 acting as a specific processing unit 290 according to the specific processing program 56 executed on the RAM 30.

[0143] Storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290. The identification processing unit 290 can estimate the user's emotions using the emotion identification model 59 and perform identification processing using the user's emotions. The emotion estimation function (emotion identification function) using the emotion identification model 59 performs various estimations and predictions regarding the user's emotions, including but not limited to these examples. Furthermore, emotion estimation and prediction also include, for example, emotion analysis.

[0144] In the headset terminal 314, specific processing is performed by the processor 46. The storage 50 stores a specific program 60. The processor 46 reads the specific program 60 from the storage 50 and executes the read specific program 60 on the RAM 48. The specific processing is realized by the processor 46 acting as a control unit 46A according to the specific program 60 executed on the RAM 48. The headset terminal 314 also has a data generation model 58 and an emotion identification model 59, similar to the data generation model and emotion identification model 59, and can perform processing similar to that of the specific processing unit 290 using these models.

[0145] Furthermore, other devices besides the data processing device 12 may also have the data generation model 58. For example, a server device may have the data generation model 58. In this case, the data processing device 12 obtains processing results (such as prediction results) using the data generation model 58 by communicating with the server device that has the data generation model 58. Also, the data processing device 12 may be a server device or a terminal device owned by the user (for example, a mobile phone, robot, home appliance, etc.).

[0146] The specific processing unit 290 transmits the result of the specific processing to the headset terminal 314. In the headset terminal 314, the control unit 46A causes the speaker 240 and display 343 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.

[0147] The data generation model 58 is a so-called generative AI. An example of a data generation model 58 is a generative AI such as ChatGPT. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and inference data such as audio data representing speech, text data representing text, and image data representing images (e.g., still image data or video data). The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference result in one or more data formats such as audio data, text data, and image data. The data generation model 58 includes, for example, text generation AI, image generation AI, and multimodal generation AI. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization. The specific processing unit 290 performs the specific processing described above using the data generation model 58. The data generation model 58 may be a fine-tuned model that outputs inference results from prompts that do not contain instructions, in which case the data generation model 58 can output inference results from prompts that do not contain instructions. In the data processing device 12, etc., there are multiple types of data generation models 58, and the data generation model 58 includes AI other than generative AI. AI other than generative AI includes, for example, linear regression, logistic regression, decision trees, random forests, support vector machines (SVM), k-means clustering, convolutional neural networks (CNN), recurrent neural networks (RNN), generative adversarial networks (GAN), or naive Bayes, and can perform various processes, but is not limited to these examples. Also, the AI ​​may be an AI agent. Furthermore, when the processing of each part described above is performed by the AI, the processing may be performed by the AI ​​in part or in whole, but is not limited to this example. Also, processing performed by an AI including a generative AI may be replaced by rule-based processing, and rule-based processing may be replaced by processing performed by an AI including a generative AI.

[0148] The data processing system 310 according to the third embodiment performs the same processing as the data processing system 10 according to the first embodiment. The processing by the data processing system 310 is performed by the specific processing unit 290 of the data processing device 12 or the control unit 46A of the headset terminal 314, but may also be performed by the specific processing unit 290 of the data processing device 12 and the control unit 46A of the headset terminal 314. In addition, the specific processing unit 290 of the data processing device 12 acquires or collects information necessary for processing from the headset terminal 314 or an external device, and the headset terminal 314 acquires or collects information necessary for processing from the data processing device 12 or an external device.

[0149] Each of the multiple elements described above, including the acquisition unit, analysis unit, proposal unit, modification unit, and verification unit, is implemented in at least one of the headset terminal 314 and the data processing unit 12. For example, the acquisition unit is implemented by the control unit 46A of the headset terminal 314 or the specific processing unit 290 of the data processing unit 12. The analysis unit is implemented by the specific processing unit 290 of the data processing unit 12. The proposal unit is implemented by the specific processing unit 290 of the data processing unit 12. The modification unit is implemented by the control unit 46A of the headset terminal 314 or the specific processing unit 290 of the data processing unit 12. The verification unit is implemented by the control unit 46A of the headset terminal 314 or the specific processing unit 290 of the data processing unit 12. The correspondence between each unit and the device or control unit is not limited to the example described above, and various modifications are possible.

[0150] [Fourth Embodiment] Figure 7 shows an example of the configuration of the data processing system 410 according to the fourth embodiment.

[0151] As shown in Figure 7, the data processing system 410 includes a data processing device 12 and a robot 414. An example of the data processing device 12 is a server.

[0152] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN and / or LAN.

[0153] The robot 414 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication interface 44, and a controlled object 443. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, camera 42, and controlled object 443 are also connected to the bus 52.

[0154] The microphone 238 receives voice signals from the user and accepts instructions from the user. The microphone 238 captures the voice signals from the user, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.

[0155] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS image sensor or CCD image sensor, which captures images of the area around the user (for example, an imaging range defined by a field of view equivalent to the field of vision of a typical healthy person).

[0156] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.

[0157] The controlled object 443 includes a display device, LEDs in the eyes, and motors that drive the arms, hands, and feet. The posture and gestures of the robot 414 are controlled by controlling the motors of the arms, hands, and feet. Some of the robot 414's emotions can be expressed by controlling these motors. The robot 414's facial expressions can also be expressed by controlling the illumination state of the LEDs in its eyes.

[0158] Figure 8 shows an example of the main functions of the data processing device 12 and the robot 414. As shown in Figure 8, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.

[0159] The processor 28 reads a specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 acting as a specific processing unit 290 according to the specific processing program 56 executed on the RAM 30.

[0160] Storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290. The identification processing unit 290 can estimate the user's emotions using the emotion identification model 59 and perform identification processing using the user's emotions. The emotion estimation function (emotion identification function) using the emotion identification model 59 performs various estimations and predictions regarding the user's emotions, including but not limited to these examples. Furthermore, emotion estimation and prediction also include, for example, emotion analysis.

[0161] In robot 414, specific processing is performed by processor 46. A specific program 60 is stored in storage 50. Processor 46 reads the specific program 60 from storage 50 and executes it on RAM 48. The specific processing is achieved by processor 46 acting as a control unit 46A according to the specific program 60 executed on RAM 48. Robot 414 also has data generation model 58 and emotion identification model 59, similar to those of the robot, and can perform processing similar to that of the specific processing unit 290 using these models.

[0162] Furthermore, other devices besides the data processing device 12 may also have the data generation model 58. For example, a server device may have the data generation model 58. In this case, the data processing device 12 obtains processing results (such as prediction results) using the data generation model 58 by communicating with the server device that has the data generation model 58. Also, the data processing device 12 may be a server device or a terminal device owned by the user (for example, a mobile phone, robot, home appliance, etc.).

[0163] The specific processing unit 290 transmits the result of the specific processing to the robot 414. In the robot 414, the control unit 46A causes the speaker 240 and the controlled object 443 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.

[0164] The data generation model 58 is a so-called generative AI. An example of a data generation model 58 is a generative AI such as ChatGPT. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and inference data such as audio data representing speech, text data representing text, and image data representing images (e.g., still image data or video data). The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference result in one or more data formats such as audio data, text data, and image data. The data generation model 58 includes, for example, text generation AI, image generation AI, and multimodal generation AI. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization. The specific processing unit 290 performs the specific processing described above using the data generation model 58. The data generation model 58 may be a fine-tuned model that outputs inference results from prompts that do not contain instructions, in which case the data generation model 58 can output inference results from prompts that do not contain instructions. In the data processing device 12, etc., there are multiple types of data generation models 58, and the data generation model 58 includes AI other than generative AI. AI other than generative AI includes, for example, linear regression, logistic regression, decision trees, random forests, support vector machines (SVM), k-means clustering, convolutional neural networks (CNN), recurrent neural networks (RNN), generative adversarial networks (GAN), or naive Bayes, and can perform various processes, but is not limited to these examples. Also, the AI ​​may be an AI agent. Furthermore, when the processing of each part described above is performed by the AI, the processing may be performed by the AI ​​in part or in whole, but is not limited to this example. Also, processing performed by an AI including a generative AI may be replaced by rule-based processing, and rule-based processing may be replaced by processing performed by an AI including a generative AI.

[0165] The data processing system 410 according to the fourth embodiment performs the same processing as the data processing system 10 according to the first embodiment. The processing by the data processing system 410 is performed by the specific processing unit 290 of the data processing device 12 or the control unit 46A of the robot 414, but it may also be performed by the specific processing unit 290 of the data processing device 12 and the control unit 46A of the robot 414. In addition, the specific processing unit 290 of the data processing device 12 acquires or collects information necessary for processing from the robot 414 or an external device, and the robot 414 acquires or collects information necessary for processing from the data processing device 12 or an external device.

[0166] Each of the multiple elements described above, including the acquisition unit, analysis unit, proposal unit, modification unit, and verification unit, is implemented, for example, in at least one of the robot 414 and the data processing unit 12. For example, the acquisition unit is implemented by the control unit 46A of the robot 414 or the specific processing unit 290 of the data processing unit 12. The analysis unit is implemented, for example, by the specific processing unit 290 of the data processing unit 12. The proposal unit is implemented, for example, by the specific processing unit 290 of the data processing unit 12. The modification unit is implemented, for example, by the control unit 46A of the robot 414 or the specific processing unit 290 of the data processing unit 12. The verification unit is implemented, for example, by the control unit 46A of the robot 414 or the specific processing unit 290 of the data processing unit 12. The correspondence between each unit and the device or control unit is not limited to the example described above, and various modifications are possible.

[0167] Furthermore, the emotion identification model 59, acting as an emotion engine, may determine the user's emotion according to a specific mapping. Specifically, the emotion identification model 59 may determine the user's emotion according to a specific mapping, which is an emotion map (see Figure 9). Similarly, the emotion identification model 59 may also determine the robot's emotion, and the identification processing unit 290 may perform identification processing using the robot's emotion.

[0168] Figure 9 shows the emotion map 400, in which multiple emotions are mapped. In the emotion map 400, emotions are arranged in concentric circles radiating from the center. The closer to the center of the concentric circles, the more primitive the emotions are located. Further out of the concentric circles, emotions representing states and actions arising from mental states are located. Emotion is a concept that includes feelings and mental states. On the left side of the concentric circles, emotions that are generally generated from reactions occurring in the brain are located. On the right side of the concentric circles, emotions that are generally induced by situational judgment are located. Above and below the concentric circles, emotions that are generally generated from reactions occurring in the brain and induced by situational judgment are located. In addition, the emotion of "pleasure" is located on the upper side of the concentric circles, and the emotion of "displeasure" is located on the lower side. Thus, in the emotion map 400, multiple emotions are mapped based on the structure in which emotions arise, and emotions that are likely to occur simultaneously are mapped close together.

[0169] These emotions are distributed at the 3 o'clock position on the Emotion Map 400, and usually fluctuate between feelings of security and anxiety. In the right half of the Emotion Map 400, situational awareness takes precedence over internal feelings, resulting in a calm impression.

[0170] The inside of the Emotion Map 400 represents inner thoughts, while the outside represents actions. Therefore, the further you go from the outside of the Emotion Map 400, the more visible (expressed in actions) your emotions become.

[0171] Here, human emotions are based on various balances, such as posture and blood sugar levels. When these balances deviate from the ideal, it results in discomfort, and when they approach the ideal, it results in pleasure. Similarly, in robots, cars, and motorcycles, emotions can be created based on various balances, such as posture and battery level. When these balances deviate from the ideal, it results in discomfort, and when they approach the ideal, it results in pleasure. The emotion map can be generated based, for example, on Dr. Mitsuyoshi's emotion map (Research on a system for analyzing brain physiological signals of speech emotion recognition and emotion, Tokushima University, doctoral dissertation: https: / / ci.nii.ac.jp / naid / 500000375379). The left half of the emotion map contains emotions belonging to a region called "response," where sensation is dominant. The right half of the emotion map contains emotions belonging to a region called "situation," where situational awareness is dominant.

[0172] The emotion map defines two emotions that promote learning. One is the emotion around the middle of the negative "repentance" and "reflection" on the situation side. In other words, it is when the robot experiences negative emotions such as "I never want to feel this way again" or "I don't want to be scolded again." The other is the emotion around the positive "desire" on the reaction side. In other words, it is when the robot has positive feelings such as "I want more" or "I want to know more."

[0173] The emotion identification model 59 inputs user input into a pre-trained neural network, obtains emotion values ​​representing each emotion shown in the emotion map 400, and determines the user's emotion. This neural network is pre-trained based on multiple training data sets, which are combinations of user input and emotion values ​​representing each emotion shown in the emotion map 400. Furthermore, this neural network is trained so that emotions located close together have similar values, as shown in the emotion map 900 in Figure 10. Figure 10 shows an example where multiple emotions such as "reassured," "calm," and "confident" have similar emotion values.

[0174] In the above embodiment, an example was given in which a specific process is performed by a single computer 22. However, the technology of this disclosure is not limited thereto, and a distributed processing method for the specific process may be used, which includes computer 22 and multiple other computers.

[0175] In the above embodiment, an example was given in which the specific processing program 56 is stored in the storage 32, but the technology of this disclosure is not limited thereto. For example, the specific processing program 56 may be stored in a portable, computer-readable, non-temporary storage medium such as a USB (Universal Serial Bus) memory. The specific processing program 56 stored in the non-temporary storage medium is installed in the computer 22 of the data processing device 12. The processor 28 executes specific processing according to the specific processing program 56.

[0176] Alternatively, the specific processing program 56 may be stored in a storage device such as a server connected to the data processing device 12 via the network 54, and the specific processing program 56 may be downloaded and installed on the computer 22 in response to a request from the data processing device 12.

[0177] Furthermore, it is not necessary to store the entirety of the specific processing program 56 in a storage device such as a server connected to the data processing device 12 via the network 54, or to store the entirety of the specific processing program 56 in the storage 32; it is acceptable to store only a portion of the specific processing program 56.

[0178] The following types of processors can be used as hardware resources to perform specific processing. Examples of processors include a CPU, a general-purpose processor that functions as a hardware resource to perform specific processing by executing software, i.e., a program. Other examples of processors include dedicated electrical circuits, such as FPGAs (Field-Programmable Gate Arrays), PLDs (Programmable Logic Devices), or ASICs (Application Specific Integrated Circuits), which have circuit configurations specifically designed to perform specific processing. All of these processors have built-in or connected memory, and all of them perform specific processing by using memory.

[0179] The hardware resource that performs a specific process may consist of one of these various processors, or it may consist of a combination of two or more processors of the same or different types (for example, a combination of multiple FPGAs, or a combination of a CPU and an FPGA). Alternatively, the hardware resource that performs a specific process may consist of a single processor.

[0180] Examples of configurations using a single processor include, firstly, a configuration in which one or more CPUs and software are combined to form a single processor, and this processor functions as a hardware resource that performs a specific process. Secondly, there is a configuration using a processor that realizes the functions of the entire system, including multiple hardware resources that perform a specific process, on a single IC chip, as exemplified by SoCs (System-on-a-chip). In this way, a specific process is realized using one or more of the above types of processors as hardware resources.

[0181] Furthermore, the hardware structure of these various processors can more specifically utilize electrical circuits that combine circuit elements such as semiconductor devices. Also, the specific processing described above is merely an example. Therefore, it goes without saying that unnecessary steps can be deleted, new steps added, or the processing order rearranged, as long as it does not deviate from the main purpose.

[0182] Furthermore, although the above-described examples were divided into four embodiments, some or all of these embodiments may be combined. Also, the smart device 14, smart glasses 214, headset terminal 314, and robot 414 are just examples, and they may be combined, or other devices may be used. Also, although the above-described examples were divided into two embodiments, Embodiment 1 and Embodiment 2, these may be combined.

[0183] The descriptions and illustrations presented above are detailed explanations of the technical aspects of this disclosure and are merely examples of the technical aspects. For example, the above descriptions of the structure, function, operation, and effect are examples of the structure, function, operation, and effect of the technical aspects of this disclosure. Therefore, it goes without saying that you may delete unnecessary parts, add new elements, or replace elements in the descriptions and illustrations presented above, as long as you do not deviate from the essence of the technical aspects of this disclosure. Furthermore, in order to avoid confusion and facilitate understanding of the technical aspects of this disclosure, explanations of common technical knowledge and other things that do not require special explanation to enable the implementation of the technical aspects of this disclosure have been omitted from the descriptions and illustrations presented above.

[0184] All documents, patent applications, and technical standards described herein are incorporated by reference to the same extent as if each individual document, patent application, and technical standard were specifically and individually noted to be incorporated by reference.

[0185] (Note 1) This unit retrieves the CVE number and its description, as well as the documentation and version log for the relevant library. Based on the information obtained by the acquisition unit, an analysis unit checks whether the library being used has vulnerabilities. Based on the results of the analysis performed by the aforementioned analysis unit, a proposal unit presents suggested countermeasures and procedures, Based on the countermeasure proposed by the aforementioned proposal unit, a correction unit automatically corrects the parts that can be corrected, The system includes a confirmation unit that verifies the content modified by the modification unit. A system characterized by the following features. (Note 2) The acquisition unit is, The system estimates the user's emotions and adjusts the timing of retrieving CVE numbers and library information based on the estimated emotions. The system described in Appendix 1, characterized by the features described herein. (Note 3) The acquisition unit is, Analyze past vulnerability response history and select the optimal acquisition method. The system described in Appendix 1, characterized by the features described herein. (Note 4) The acquisition unit is, Filter based on project progress and priority. The system described in Appendix 1, characterized by the features described herein. (Note 5) The acquisition unit is, It estimates the user's emotions and determines the priority of information to acquire based on the estimated user emotions. The system described in Appendix 1, characterized by the features described herein. (Note 6) The acquisition unit is, Prioritize retrieving highly relevant information by considering geographical location. The system described in Appendix 1, characterized by the features described herein. (Note 7) The acquisition unit is, Analyze social media activity and obtain relevant information. The system described in Appendix 1, characterized by the features described herein. (Note 8) The aforementioned analysis unit, We estimate the user's emotions and adjust the analysis criteria based on the estimated user emotions. The system described in Appendix 1, characterized by the features described herein. (Note 9) The aforementioned analysis unit, Improve the accuracy of the analysis by considering the interrelationships between libraries. The system described in Appendix 1, characterized by the features described herein. (Note 10) The aforementioned analysis unit, The analysis will be performed considering the frequency and importance of library usage. The system described in Appendix 1, characterized by the features described herein. (Note 11) The aforementioned analysis unit, It estimates the user's emotions and adjusts the display order of the analysis results based on the estimated user emotions. The system described in Appendix 1, characterized by the features described herein. (Note 12) The aforementioned analysis unit, The analysis will be conducted taking geographical distribution into consideration. The system described in Appendix 1, characterized by the features described herein. (Note 13) The aforementioned analysis unit, Refer to related literature to improve the accuracy of the analysis. The system described in Appendix 1, characterized by the features described herein. (Note 14) The aforementioned proposal section is, It estimates the user's emotions and adjusts the way suggestions are presented based on those estimated emotions. The system described in Appendix 1, characterized by the features described herein. (Note 15) The aforementioned proposal section is, Adjust the level of detail of the proposal based on the severity of the vulnerability. The system described in Appendix 1, characterized by the features described herein. (Note 16) The aforementioned proposal section is, Apply different proposed algorithms depending on the vulnerability category. The system described in Appendix 1, characterized by the features described herein. (Note 17) The aforementioned proposal section is, It estimates the user's emotions and adjusts the length of the suggestion based on the estimated emotions. The system described in Appendix 1, characterized by the features described herein. (Note 18) The aforementioned proposal section is, Prioritize proposals based on when the vulnerability was discovered. The system described in Appendix 1, characterized by the features described herein. (Note 19) The aforementioned proposal section is, Adjust the order of proposals based on the relevance of the vulnerabilities. The system described in Appendix 1, characterized by the features described herein. (Note 20) The aforementioned modification section is, It estimates the user's emotions and adjusts the correction method based on the estimated user emotions. The system described in Appendix 1, characterized by the features described herein. (Note 21) The aforementioned modification section is, Analyze past revision history to select the optimal revision method. The system described in Appendix 1, characterized by the features described herein. (Note 22) The aforementioned modification section is, Customize the means of correction based on the project's progress. The system described in Appendix 1, characterized by the features described herein. (Note 23) The aforementioned modification section is, It estimates user sentiment and determines the priority of modifications based on the estimated user sentiment. The system described in Appendix 1, characterized by the features described herein. (Note 24) The aforementioned modification section is, Select the optimal correction method considering geographical location information. The system described in Appendix 1, characterized by the features described herein. (Note 25) The aforementioned modification section is, Analyze social media activity and propose corrective measures. The system described in Appendix 1, characterized by the features described herein. (Note 26) The aforementioned verification unit is We estimate the user's emotions and adjust the confirmation method based on the estimated user emotions. The system described in Appendix 1, characterized by the features described herein. (Note 27) The aforementioned verification unit is Refer to past verification history to select the most suitable verification method. The system described in Appendix 1, characterized by the features described herein. (Note 28) The aforementioned verification unit is The system estimates the user's emotions and determines the priority of confirmations based on those estimated emotions. The system described in Appendix 1, characterized by the features described herein. (Note 29) The aforementioned verification unit is Select the optimal verification method considering the device information. The system described in Appendix 1, characterized by the features described herein. (Note 30) The aforementioned verification unit is We will suggest the optimal verification method based on the user's past verification history. The system described in Appendix 1, characterized by the features described herein. (Note 31) The aforementioned verification unit is Referencing the user's calendar information, we suggest a confirmation method based on their schedule. The system described in Appendix 1, characterized by the features described herein. [Explanation of Symbols]

[0186] 10, 210, 310, 410 Data Processing Systems 12 Data Processing Devices 14 Smart Devices 214 Smart Glasses 314 Headset-type terminal 414 Robots

Claims

1. This unit retrieves the CVE number and its description, as well as the documentation and version log for the relevant library. Based on the information obtained by the acquisition unit, an analysis unit checks whether the library being used has vulnerabilities. Based on the results of the analysis performed by the aforementioned analysis unit, a proposal unit presents suggested countermeasures and procedures, Based on the countermeasure proposed by the aforementioned proposal unit, a correction unit automatically corrects the parts that can be corrected, The system includes a confirmation unit that verifies the content modified by the modification unit. A system characterized by the following features.

2. The acquisition unit is, The system estimates the user's emotions and adjusts the timing of retrieving CVE numbers and library information based on the estimated emotions. The system according to feature 1.

3. The acquisition unit is, Analyze past vulnerability response history and select the optimal acquisition method. The system according to feature 1.

4. The acquisition unit is, Filter based on project progress and priority. The system according to feature 1.

5. The acquisition unit is, It estimates the user's emotions and determines the priority of information to acquire based on the estimated user emotions. The system according to feature 1.

6. The acquisition unit is, Prioritize retrieving highly relevant information by considering geographical location. The system according to feature 1.

7. The acquisition unit is, Analyze social media activity and obtain relevant information. The system according to feature 1.

8. The aforementioned analysis unit, We estimate the user's emotions and adjust the analysis criteria based on the estimated user emotions. The system according to feature 1.

Citation Information

Patent Citations

  • Persona chatbot control method and system

    JP2022180282A