system
The AI-driven cybersecurity system addresses the challenge of real-time cyber threat detection and automated countermeasures, improving data protection and compliance through efficient threat identification and response.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- SOFTBANK GROUP CORP
- Filing Date
- 2024-10-18
- Publication Date
- 2026-05-01
AI Technical Summary
Existing systems fail to adequately detect cyber threats in real time and automate effective countermeasures against evolving cyberattacks.
A cybersecurity system utilizing AI-driven data collection, detection, generation, implementation, and report generation units to identify cyber threats, generate countermeasures, and provide real-time incident response analysis.
Enables real-time threat detection and automated countermeasures, reducing the workload of security personnel and enhancing data protection and compliance by providing rapid and accurate response mechanisms.
Smart Images

Figure 2026073130000001_ABST
Abstract
Description
Technical Field
[0001] The technology of the present disclosure relates to a system.
Background Art
[0002] Patent Document 1 discloses a method for controlling a persona chatbot, which is performed by at least one processor, including steps of receiving a user utterance, adding the user utterance to a prompt including an instruction sentence related to an explanation of a character of the chatbot, encoding the prompt, and inputting the encoded prompt into a language model to generate a chatbot utterance in response to the user utterance.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] In the conventional technology, threat detection and automation of countermeasures for coping with the evolution of cyberattacks have not been sufficiently carried out, and there is room for improvement.
[0005] The system according to the embodiment aims to detect cyber threats in real time and automatically implement countermeasures.
Means for Solving the Problems
[0006] The system according to this embodiment comprises a collection unit, a detection unit, a generation unit, an implementation unit, and a report generation unit. The collection unit collects data on cyberattacks. The detection unit analyzes the data collected by the collection unit and detects cyber threats. The generation unit generates countermeasures for the threats detected by the detection unit. The implementation unit implements the countermeasures generated by the generation unit. The report generation unit generates an incident response analysis report. [Effects of the Invention]
[0007] The system according to this embodiment can detect cyber threats in real time and automatically implement countermeasures. [Brief explanation of the drawing]
[0008] [Figure 1] This is a conceptual diagram showing an example of the configuration of a data processing system according to the first embodiment. [Figure 2] This is a conceptual diagram showing an example of the essential functions of a data processing device and a smart device according to the first embodiment. [Figure 3] This is a conceptual diagram showing an example of the configuration of a data processing system according to the second embodiment. [Figure 4] This is a conceptual diagram showing an example of the main functions of a data processing device and smart glasses according to the second embodiment. [Figure 5] This is a conceptual diagram showing an example of the configuration of a data processing system according to the third embodiment. [Figure 6] This is a conceptual diagram showing an example of the main functions of a data processing device and a headset-type terminal according to the third embodiment. [Figure 7] This is a conceptual diagram showing an example of the configuration of a data processing system according to the fourth embodiment. [Figure 8] This is a conceptual diagram showing an example of the main functions of a data processing device and a robot according to the fourth embodiment. [Figure 9] This shows an emotion map where multiple emotions are mapped. [Figure 10] This shows an emotion map where multiple emotions are mapped. [Modes for carrying out the invention]
[0009] Hereinafter, an example of an embodiment of the system relating to the technology of this disclosure will be described with reference to the attached drawings.
[0010] First, let's explain the terminology used in the following explanation.
[0011] In the following embodiments, the signed processor (hereinafter simply referred to as "processor") may be a single arithmetic unit or a combination of multiple arithmetic units. Furthermore, the processor may be a single type of arithmetic unit or a combination of multiple types of arithmetic units. Examples of arithmetic units include CPU (Central Processing Unit), GPU (Graphics Processing Unit), GPGPU (General-Purpose computing on Graphics Processing Units), APU (Accelerated Processing Unit), or TPU (Tensor Processing Unit).
[0012] In the following embodiments, signed RAM (Random Access Memory) is a memory that temporarily stores information and is used as work memory by the processor.
[0013] In the following embodiments, the signed storage is one or more non-volatile storage devices that store various programs and various parameters. Examples of non-volatile storage devices include flash memory (SSD (Solid State Drive)), magnetic disks (e.g., hard disks), or magnetic tapes.
[0014] In the following embodiments, the labeled communication I / F (Interface) is an interface including a communication processor, an antenna, and the like. The communication I / F controls communication between a plurality of computers. Examples of communication standards applied to the communication I / F include wireless communication standards including 5G (5th Generation Mobile Communication System), Wi-Fi (registered trademark), or Bluetooth (registered trademark).
[0015] In the following embodiments, "A and / or B" is synonymous with "at least one of A and B". That is, "A and / or B" means that it may be only A, only B, or a combination of A and B. Also, in this specification, when expressing three or more matters connected by "and / or", the same concept as "A and / or B" is applied.
[0016] [First Embodiment] FIG. 1 shows an example of the configuration of a data processing system 10 according to the first embodiment.
[0017] As shown in FIG. 1, the data processing system 10 includes a data processing device 12 and a smart device 14. An example of the data processing device 12 is a server.
[0018] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. Also, the database 24 and the communication I / F 26 are connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0019] The smart device 14 comprises a computer 36, a receiving device 38, an output device 40, a camera 42, and a communication interface 44. The computer 36 comprises a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The receiving device 38, output device 40, and camera 42 are also connected to the bus 52.
[0020] The reception device 38 is equipped with a touch panel 38A and a microphone 38B, and accepts user input. The touch panel 38A accepts user input via touch by detecting contact with an object (e.g., a pen or finger). The microphone 38B accepts user input via voice by detecting the user's voice. The control unit 46A transmits data indicating the user input received by the touch panel 38A and microphone 38B to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 (see Figure 2) acquires the data indicating the user input.
[0021] The output device 40 includes a display 40A and a speaker 40B, and presents data to the user by outputting the data in a form perceptible to the user (e.g., audio and / or text). The display 40A displays visible information such as text and images according to instructions from the processor 46. The speaker 40B outputs audio according to instructions from the processor 46. The camera 42 is a small digital camera equipped with an optical system such as a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor.
[0022] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various types of information between processor 46 and processor 28 via network 54.
[0023] Figure 2 shows an example of the main functions of the data processing device 12 and the smart device 14.
[0024] As shown in Figure 2, in the data processing device 12, a specific processing is performed by the processor 28. A specific processing program 56 is stored in the storage 32. The specific processing program 56 is an example of a "program" related to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 according to the specific processing program 56 executed on the RAM 30.
[0025] Storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290. The identification processing unit 290 can estimate the user's emotions using the emotion identification model 59 and perform identification processing using the user's emotions. The emotion estimation function (emotion identification function) using the emotion identification model 59 performs various estimations and predictions regarding the user's emotions, including but not limited to these examples. Furthermore, emotion estimation and prediction also include, for example, emotion analysis.
[0026] In the smart device 14, specific processing is performed by the processor 46. The storage 50 stores a specific processing program 60. The specific processing program 60 is used in conjunction with the specific processing program 56 by the data processing system 10. The processor 46 reads the specific processing program 60 from the storage 50 and executes the read specific processing program 60 on the RAM 48. The specific processing is realized by the processor 46 operating as a control unit 46A according to the specific processing program 60 executed on the RAM 48. The smart device 14 also has a data generation model 58 and an emotion identification model 59, similar to the data generation model and emotion identification model 59, and can perform processing similar to that of the specific processing unit 290 using these models.
[0027] Furthermore, other devices besides the data processing device 12 may also have the data generation model 58. For example, a server device (e.g., a generation server) may have the data generation model 58. In this case, the data processing device 12 obtains processing results (such as prediction results) using the data generation model 58 by communicating with the server device having the data generation model 58. The data processing device 12 may also be a server device or a terminal device owned by a user (e.g., a mobile phone, robot, home appliance, etc.). Next, an example of processing by the data processing system 10 according to the first embodiment will be described.
[0028] (Example of form 1) The cybersecurity system according to an embodiment of the present invention is an AI-driven system that supports corporate data protection and compliance protection by detecting and predicting cyber threats in real time and automatically implementing countermeasures. This cybersecurity system expands the scope of response by consolidating all cyber attack cases on the cloud through a SaaS service contract and platform implementation. It is basically automated and automatically generates and provides incident response analysis reports in real time. This creates a state where it is possible to monitor whether there are any problems with the security status. First, cyber attack cases are consolidated on the cloud. At this time, data on past cyber attacks and newly occurring attacks are collected and stored on the cloud. For example, cases such as phishing attacks and malware attacks are collected. This creates a database for understanding cyber attack patterns and generating countermeasures. Next, cyber threats are automatically detected by combining machine learning and natural language processing. The machine learning model analyzes the collected data and detects abnormal activity. For example, by detecting communications that differ from normal traffic patterns, signs of cyber attacks can be found. Furthermore, natural language processing is used to analyze the intent and methods of attackers. This enables the early detection of cyber threats. Furthermore, the system automatically generates and implements countermeasures for detected threats. For example, it can isolate detected malware and automatically delete emails in response to phishing attacks. This minimizes the impact of cyberattacks. Finally, it automatically generates and provides real-time incident response analysis reports. This allows security personnel to understand the current security state and take necessary measures. For example, it provides reports with detailed analysis results of past incidents and current threat levels. This reduces the workload of security personnel and enables rapid response. This mechanism improves the quality of cybersecurity and reduces the workload of cybersecurity personnel.Companies can implement effective countermeasures against ever-evolving cyberattacks, thereby strengthening data protection and compliance. In this way, cybersecurity systems can support companies in protecting their data and ensuring compliance.
[0029] The cybersecurity system according to the embodiment comprises a collection unit, a detection unit, a generation unit, an implementation unit, and a report generation unit. The collection unit collects data on cyberattacks. The collection unit collects data on past cyberattacks and data on newly occurring attacks, for example. The collection unit can collect log data, network traffic data, malware samples, etc. The collection unit can collect data in real time and store it in the cloud, for example. The detection unit analyzes the data collected by the collection unit and detects cyber threats. The detection unit detects anomalous activity, for example, using a machine learning model. The detection unit can find signs of cyberattacks, for example, by detecting communications that differ from normal traffic patterns. The detection unit can use machine learning models such as deep learning models and support vector machines, for example. The generation unit generates countermeasures for threats detected by the detection unit. The generation unit analyzes the attacker's intentions and methods using natural language processing, for example, and generates countermeasures. The generation unit can use natural language processing techniques such as morphological analysis, grammatical analysis, and semantic analysis, for example. The generation unit can, for example, analyze attack patterns and analyze the attacker's activity history. The implementation unit implements the countermeasures generated by the generation unit. The implementation unit can, for example, take isolation measures against detected malware. The implementation unit can, for example, take isolation measures such as disconnecting from the network or moving to a specific folder. The implementation unit can, for example, automatically delete emails related to phishing attacks. The implementation unit can, for example, use methods such as analyzing the content of emails or verifying links. The report generation unit generates an incident response analysis report. The report generation unit can, for example, automatically generate and provide the report in real time. The report generation unit can, for example, generate a report that includes an overview of the incident that occurred, details of the countermeasures, and future countermeasures. In this way, the cybersecurity system according to the embodiment can support corporate data protection and compliance protection.Some or all of the above-described processes in the collection unit, detection unit, generation unit, implementation unit, and report generation unit may be performed using AI, for example, or without AI. For example, the collection unit can use an AI model to collect data on cyberattacks. The detection unit can input the data collected by the collection unit into an AI model to detect cyber threats. The generation unit can use an AI model to generate countermeasures for threats detected by the detection unit. The implementation unit can use an AI model to implement the countermeasures generated by the generation unit. The report generation unit can generate an incident response analysis report using an AI model.
[0030] The data collection unit collects data on cyberattacks. For example, it collects data on past cyberattacks and newly occurring attacks. Specifically, the unit can collect log data, network traffic data, malware samples, and more. Log data records the operation history of systems and applications and is an important source of information for detecting traces of attacks and abnormal behavior. Network traffic data records details of communications on the network and is used to detect abnormal communication patterns and signs of unauthorized access. Malware samples are actual instances of detected malware, and their analysis can identify attack methods and infection routes. The data collection unit can collect this data in real time and store it in the cloud. Storing data in the cloud allows for efficient management of large amounts of data and enables collaboration with analysis departments and other systems. Furthermore, the data collection unit can use AI models to collect data. For example, AI models can automatically detect abnormal patterns in network traffic and prioritize the collection of important data. The data collection unit can also dynamically adjust the frequency and target of data collection to respond flexibly to specific situations and threats. This allows the data collection unit to efficiently and effectively collect data on cyberattacks, thereby improving the overall security of the system.
[0031] The detection unit analyzes the data collected by the collection unit to detect cyber threats. The detection unit can detect anomalous activity using, for example, machine learning models. Specifically, it can use machine learning models such as deep learning models and support vector machines. Deep learning models have the ability to learn from large amounts of data and recognize complex patterns, enabling them to detect unknown threats and new attack methods with high accuracy. Support vector machines can map data features into a high-dimensional space, effectively identifying anomalous data points. The detection unit can find signs of cyberattacks by detecting communications that differ from normal traffic patterns. For example, it can quickly detect anomalous activity such as large amounts of data being sent externally outside of normal business hours or frequent unauthorized access from specific IP addresses. Furthermore, the detection unit can analyze the collected data in real time using AI models to perform early detection of cyber threats. AI models can learn from past attack data and automatically identify new attacks with similar patterns. This allows the detection unit to quickly and accurately detect cyber threats and enhance the overall system security.
[0032] The generation unit generates countermeasures for threats detected by the detection unit. For example, the generation unit uses natural language processing to analyze the attacker's intentions and methods, and then generates countermeasures. Specifically, it can utilize natural language processing techniques such as morphological analysis, grammatical analysis, and semantic analysis. Morphological analysis is a technique that divides text into words and analyzes the meaning and role of each word. Grammatical analysis is a technique that analyzes the structure of a sentence and clarifies the relationships between subjects, predicates, and objects. Semantic analysis is a technique that understands the meaning of a sentence and generates appropriate countermeasures according to the context. The generation unit can combine these techniques to analyze attack patterns and the attacker's behavioral history. For example, it can analyze specific commands and tools used by an attacker and propose effective defensive measures against them. Furthermore, the generation unit can use an AI model to automatically generate the optimal countermeasures for detected threats. The AI model learns the effectiveness of past countermeasures and can propose the most effective countermeasures for similar threats. This allows the generation unit to generate countermeasures quickly and effectively, improving its defenses against cyberattacks.
[0033] The implementation unit will carry out the countermeasures generated by the generation unit. For example, the implementation unit can take isolation measures against detected malware. Specifically, it can take isolation measures such as disconnecting from the network or moving to a specific folder. Disconnecting from the network is a method to prevent the spread of malware by physically separating the infected device from the network. Moving to a specific folder is a method to move the infected file to a safe location to prevent infection of other files. The implementation unit can automatically execute these measures and quickly contain the threat. In addition, the implementation unit can automatically delete emails that are relevant to phishing attacks. Specifically, it can use methods such as email content analysis and link verification. Email content analysis is a method of analyzing the text of the email body to detect signs of phishing. Link verification is a method of analyzing the destination of links in the email to prevent access to malicious sites. The implementation unit can combine these methods to implement effective countermeasures against phishing attacks. Furthermore, the implementation unit can use an AI model to automatically carry out the countermeasures generated by the generation unit. The AI model can learn from past implementation results and select the optimal implementation method. This allows the implementing department to quickly and effectively implement countermeasures and minimize the impact of cyberattacks.
[0034] The report generation unit generates incident response analysis reports. For example, it can automatically generate and deliver these reports in real time. Specifically, it can generate reports that include an overview of the incident, details of the response measures, and future countermeasures. The incident overview includes the type of attack, the date and time of occurrence, and the scope of impact. Details of the response measures include the specific measures taken, the tools and technologies used, and the effectiveness of the measures. Future countermeasures include suggestions for preventing recurrence, improvements, and additional security measures. The report generation unit can automatically collect and integrate this information to generate reports. Furthermore, the report generation unit can use AI models to generate incident response analysis reports. The AI models can learn from past incident data and automatically generate optimal reports for similar incidents. This allows the report generation unit to generate analysis reports quickly and accurately, supporting corporate data protection and compliance. Additionally, the report generation unit can automatically distribute the generated reports to relevant parties. For example, it can provide reports in real time via email or dashboards to support rapid decision-making. This allows the report generation unit to improve the transparency and efficiency of incident response and strengthen overall security management within the enterprise.
[0035] The data collection unit can collect data on past cyberattacks and newly occurring attacks. For example, the data collection unit can collect data on past cyberattacks. For example, the data collection unit can collect data for the past year or data on specific types of attacks. For example, the data collection unit can collect data on newly occurring attacks. For example, the data collection unit can collect data in real time or data within a specific period. This makes it possible to build a database for understanding cyberattack patterns and generating countermeasures by collecting data on past cyberattacks and newly occurring attacks. Some or all of the above processing in the data collection unit may be performed using AI, for example, or without AI. For example, the data collection unit can input data on past cyberattacks and newly occurring attacks into an AI model and collect the data.
[0036] The detection unit can detect anomalous activity using machine learning models. For example, the detection unit can detect anomalous activity using deep learning models. For example, the detection unit can find signs of a cyberattack by detecting communications that differ from normal traffic patterns. The detection unit can also detect anomalous activity using support vector machines. For example, the detection unit can find anomalous activity by detecting a large volume of access to a specific port. For example, the detection unit can apply an anomaly detection algorithm to detect anomalous traffic patterns. This allows for high-precision detection of anomalous activity using machine learning models. Some or all of the above-described processes in the detection unit may be performed using AI, for example, or without AI. For example, the detection unit can input data collected by the collection unit into an AI model to detect anomalous activity.
[0037] The generation unit can analyze the attacker's intent and methods using natural language processing and generate countermeasures. For example, the generation unit can analyze the attacker's intent using morphological analysis. For example, the generation unit can analyze the attacker's behavioral history and identify attack patterns. For example, the generation unit can also analyze the attacker's methods using grammatical analysis. For example, the generation unit can apply semantic analysis to analyze the attacker's intent. For example, the generation unit can analyze attack patterns and generate appropriate countermeasures. In this way, by using natural language processing, the attacker's intent and methods can be analyzed and appropriate countermeasures can be generated. Some or all of the above processing in the generation unit may be performed using AI, for example, or without AI. For example, the generation unit can generate countermeasures using an AI model for threats detected by the detection unit.
[0038] The implementation unit can take isolation measures against detected malware. For example, the implementation unit may disconnect it from the network. The implementation unit may also move it to a specific folder. For example, the implementation unit may move malware to a specific folder for isolation. For example, the implementation unit can prevent the spread of malware by disconnecting it from the network. For example, the implementation unit may move malware to a specific folder for isolation. This minimizes the impact of cyberattacks by taking isolation measures against detected malware. Some or all of the above processes in the implementation unit may be performed using AI, for example, or without AI. For example, the implementation unit may input detected malware into an AI model and perform isolation measures.
[0039] The implementation unit can automatically delete emails that are phishing attacks. The implementation unit can, for example, analyze the content of the email. The implementation unit can also, for example, verify links. The implementation unit can identify phishing emails by, for example, detecting specific keywords. The implementation unit can identify phishing emails by, for example, analyzing the email header. The implementation unit can detect specific keywords in order to automatically delete phishing emails. This minimizes the impact of cyberattacks by automatically deleting emails that are phishing attacks. Some or all of the above processes performed by the implementation unit may be performed using AI, for example, or not using AI. For example, the implementation unit can input the content of a phishing email into an AI model and automatically delete the email.
[0040] The report generation unit can automatically generate and provide incident response analysis reports in real time. For example, the report generation unit can generate a report that includes an overview of the incident that occurred. The report generation unit can also generate a report that includes details of the countermeasures taken. The report generation unit can also generate a report that includes future countermeasures. For example, the report generation unit can collect data in real time and automatically generate reports. For example, the report generation unit can generate a report that includes detailed analysis results of the incident that occurred. This reduces the workload of security personnel and enables a rapid response by automatically generating and providing incident response analysis reports in real time. Some or all of the above processes in the report generation unit may be performed using AI, for example, or without AI. For example, the report generation unit can input incident response data into an AI model and automatically generate reports.
[0041] The data collection unit can analyze past cyberattack data and select the optimal collection method. For example, the data collection unit can identify attack patterns that frequently occur during specific time periods from past data and focus data collection during those periods. For example, the data collection unit can select an effective collection method for a specific attack technique based on past attack data. For example, the data collection unit can analyze past data and select a collection method specialized for a specific industry or region. This enables efficient data collection by selecting the optimal collection method through the analysis of past data. Some or all of the above-described processes in the data collection unit may be performed using AI, for example, or without AI. For example, the data collection unit can input past cyberattack data into an AI model to select the optimal collection method.
[0042] The data collection unit can filter cyberattack data based on specific industries or regions. For example, the data collection unit can prioritize the collection of attack data related to a specific industry (e.g., the financial industry). For example, the data collection unit can filter and collect attack data in a specific region (e.g., the Asian region). For example, the data collection unit can filter data based on a specific combination of industry and region (e.g., the Asian financial industry). This allows for the efficient collection of highly relevant data by filtering data based on specific industries and regions. Some or all of the above processing in the data collection unit may be performed using AI, for example, or without AI. For example, the data collection unit can input cyberattack data into an AI model and filter it based on specific industries or regions.
[0043] The data collection unit can prioritize the collection of highly relevant data based on the user's geographical location when collecting cyberattack data. For example, if the user is in a specific region, the data collection unit will prioritize the collection of attack data related to that region. For example, the data collection unit can collect attack data that occurred in nearby areas based on the user's geographical location. For example, the data collection unit can collect highly relevant data in real time, taking into account the user's location. This enables efficient data collection by prioritizing the collection of highly relevant data based on the user's geographical location. Some or all of the above processing in the data collection unit may be performed using AI, for example, or without AI. For example, the data collection unit can input the user's geographical location into an AI model and collect highly relevant data.
[0044] The data collection unit can analyze a user's social media activity and collect relevant data when collecting cyberattack data. For example, the data collection unit can collect information about cyberattacks from a user's social media activity. For example, the data collection unit can analyze posts from security experts that a user follows and collect relevant data. For example, the data collection unit can detect early signs of an attack based on a user's social media activity and collect data. This allows for the efficient collection of relevant data by analyzing a user's social media activity. Some or all of the above processing in the data collection unit may be performed using AI, for example, or without AI. For example, the data collection unit can input user social media activity data into an AI model and collect relevant data.
[0045] The detection unit can use a machine learning model to detect abnormal activity during specific time periods or on specific days of the week. For example, the detection unit can detect abnormal activity that occurs frequently during specific time periods (e.g., late at night). For example, the detection unit can detect abnormal activity on specific days of the week (e.g., weekends) and take countermeasures. For example, the detection unit can analyze abnormal activity patterns for each time period or day of the week and build a predictive model. This enables efficient detection of abnormal activity by detecting abnormal activity during specific time periods or days of the week. Some or all of the above processing in the detection unit may be performed using AI, for example, or without AI. For example, the detection unit can input data collected by the collection unit into an AI model to detect abnormal activity during specific time periods or days of the week.
[0046] The detection unit can apply different detection algorithms depending on the type of abnormal activity detected. For example, the detection unit can apply a specific signature-based algorithm to detect malware. For example, the detection unit can apply an algorithm using natural language processing to detect phishing attacks. For example, the detection unit can apply an algorithm using traffic analysis to detect DDoS attacks. This enables efficient detection of abnormal activity by applying different detection algorithms depending on the type of abnormal activity. Some or all of the above processing in the detection unit may be performed using AI, for example, or without AI. For example, the detection unit can input data collected by the collection unit into an AI model and apply different detection algorithms to detect abnormal activity.
[0047] The detection unit can perform detection while considering the geographical distribution of anomalous activity. For example, if anomalous activity is concentrated in a particular area, the detection unit can perform detection specific to that area. For example, the detection unit can identify the source of anomalous activity based on its geographical distribution. For example, the detection unit can predict the spread of anomalous activity while considering its geographical distribution. This makes it possible to efficiently detect anomalous activity by considering its geographical distribution. Some or all of the above processing in the detection unit may be performed using AI, for example, or without AI. For example, the detection unit can input data collected by the collection unit into an AI model and perform detection of anomalous activity while considering its geographical distribution.
[0048] The detection unit can improve the accuracy of detection by referring to relevant literature on anomalous activity during detection. For example, the detection unit can improve the detection algorithm by referring to the latest research papers related to anomalous activity. For example, the detection unit can improve accuracy by comparing the detection results of anomalous activity with relevant literature. For example, the detection unit can improve detection accuracy by automatically referring to relevant literature depending on the type of anomalous activity. In this way, detection accuracy can be improved by referring to relevant literature. Some or all of the above processing in the detection unit may be performed using AI, for example, or without using AI. For example, the detection unit can input data on anomalous activity into an AI model and improve detection accuracy by referring to relevant literature.
[0049] The generation unit can generate the optimal countermeasure by analyzing the effectiveness of past countermeasures when generating countermeasures. For example, the generation unit can evaluate the effectiveness of past countermeasures and select the most effective countermeasure. For example, the generation unit can analyze past countermeasure failures and generate countermeasures to avoid similar failures. For example, the generation unit can generate the optimal countermeasure for a specific attack method based on data from past countermeasures. In this way, the optimal countermeasure can be generated by analyzing the effectiveness of past countermeasures. Some or all of the above processing in the generation unit may be performed using AI, for example, or without using AI. For example, the generation unit can input data from past countermeasures into an AI model and generate the optimal countermeasure.
[0050] The generation unit can apply different generation algorithms depending on the type of cyberattack when generating countermeasures. For example, the generation unit can apply an algorithm to take isolation measures against malware attacks. For example, the generation unit can apply an algorithm to delete emails in response to phishing attacks. For example, the generation unit can apply an algorithm to restrict traffic against DDoS attacks. By applying different generation algorithms depending on the type of cyberattack, appropriate countermeasures can be generated. Some or all of the above processing in the generation unit may be performed using AI, for example, or without AI. For example, the generation unit can input cyberattack data into an AI model and generate countermeasures by applying different generation algorithms.
[0051] The generation unit can determine the priority of countermeasures based on the timing of the cyberattack when generating countermeasures. For example, the generation unit can quickly generate and implement countermeasures immediately after a cyberattack occurs. For example, the generation unit can generate the optimal countermeasure based on past data, taking into account the timing of the cyberattack. For example, the generation unit can adjust priorities according to the timing of the cyberattack to generate effective countermeasures. This allows for the rapid generation of effective countermeasures by determining the priority of countermeasures based on the timing of the cyberattack. Some or all of the above processing in the generation unit may be performed using AI, for example, or without AI. For example, the generation unit can input data on the timing of cyberattacks into an AI model to determine the priority of countermeasures.
[0052] The generation unit can improve the accuracy of countermeasures by referring to relevant literature on cyberattacks when generating countermeasures. For example, the generation unit can refer to the latest research papers related to cyberattacks and generate countermeasures. For example, the generation unit can improve the accuracy by comparing the generated countermeasures with relevant literature when generating them. For example, the generation unit can improve the accuracy of countermeasures by automatically referring to relevant literature depending on the type of cyberattack. In this way, the accuracy of countermeasures can be improved by referring to relevant literature. Some or all of the above processing in the generation unit may be performed using AI, for example, or without using AI. For example, the generation unit can input cyberattack data into an AI model and improve the accuracy of countermeasures by referring to relevant literature.
[0053] The implementation unit can analyze past implementation results and select the optimal implementation method at the time of implementation. For example, the implementation unit can evaluate past implementation results and select the most effective implementation method. For example, the implementation unit can analyze past implementation failures and select implementation methods to avoid similar failures. For example, the implementation unit can select the optimal implementation method for a specific attack method based on past implementation result data. In this way, the optimal implementation method can be selected by analyzing past implementation results. Some or all of the above processes in the implementation unit may be performed using AI, for example, or without AI. For example, the implementation unit can input past implementation result data into an AI model and select the optimal implementation method.
[0054] The implementation unit can apply different implementation measures depending on the type of cyberattack during implementation. For example, the implementation unit can apply measures to take isolation measures against malware attacks. For example, the implementation unit can apply measures to delete relevant emails against phishing attacks. For example, the implementation unit can apply measures to restrict traffic against DDoS attacks. By applying different implementation measures depending on the type of cyberattack, appropriate countermeasures can be implemented. Some or all of the above processing in the implementation unit may be performed using AI, for example, or without AI. For example, the implementation unit can input cyberattack data into an AI model and implement countermeasures by applying different implementation measures.
[0055] The implementation unit can take into account the geographical distribution of cyberattacks when carrying out countermeasures. For example, if cyberattacks are concentrated in a particular area, the implementation unit can carry out countermeasures specifically tailored to that area. For example, the implementation unit can identify the source of an attack based on its geographical distribution and carry out countermeasures. For example, the implementation unit can take measures to prevent the spread of attacks by considering the geographical distribution. This makes it possible to implement countermeasures efficiently by considering the geographical distribution of cyberattacks. Some or all of the above-mentioned processes in the implementation unit may be carried out using AI, for example, or not using AI. For example, the implementation unit can input data on the geographical distribution of cyberattacks into an AI model and carry out countermeasures while considering the geographical distribution.
[0056] The implementation unit can improve the accuracy of its implementation by referring to relevant literature on cyberattacks during implementation. For example, the implementation unit can improve its implementation methods by referring to the latest research papers related to cyberattacks. For example, the implementation unit can improve accuracy by comparing with relevant literature during implementation. For example, the implementation unit can improve the accuracy of its implementation by automatically referring to relevant literature depending on the type of cyberattack. In this way, the accuracy of implementation can be improved by referring to relevant literature. Some or all of the above processing in the implementation unit may be performed using AI, for example, or without using AI. For example, the implementation unit can input cyberattack data into an AI model and improve the accuracy of implementation by referring to relevant literature.
[0057] The report generation unit can optimize the report content by referring to past incident data when generating a report. For example, the report generation unit can generate a report that prioritizes displaying the most important information based on past incident data. For example, the report generation unit can analyze past incident data and generate a report that includes countermeasures for similar incidents occurring. For example, the report generation unit can refer to past incident data and generate a report that includes detailed analysis results for specific attack methods. In this way, the optimal report can be generated by referring to past incident data. Some or all of the above processing in the report generation unit may be performed using AI, for example, or without AI. For example, the report generation unit can input past incident data into an AI model to optimize the report content.
[0058] The report generation unit can apply different report generation algorithms depending on the type of cyberattack when generating a report. For example, for malware attacks, the report generation unit can apply an algorithm that generates a report including details of quarantine measures. For example, for phishing attacks, the report generation unit can apply an algorithm that generates a report including procedures for deleting the relevant emails. For example, for DDoS attacks, the report generation unit can apply an algorithm that generates a report including details of traffic restrictions. In this way, by applying different report generation algorithms depending on the type of cyberattack, an appropriate report can be generated. Some or all of the above processing in the report generation unit may be performed using AI, for example, or without AI. For example, the report generation unit can input cyberattack data into an AI model and generate a report by applying different report generation algorithms.
[0059] The report generation unit can adjust the content of the report based on the timing of the cyberattack when generating the report. For example, the report generation unit can quickly generate a report including countermeasures immediately after a cyberattack occurs. For example, the report generation unit can consider the timing of the cyberattack and generate an optimal report based on past data. For example, the report generation unit can adjust priorities according to the timing of the cyberattack to generate an effective report. In this way, by adjusting the content of the report based on the timing of the cyberattack, it is possible to generate a quick and effective report. Some or all of the above processing in the report generation unit may be performed using AI, for example, or without using AI. For example, the report generation unit can input data on the timing of the cyberattack into an AI model and adjust the content of the report.
[0060] The report generation unit can improve the accuracy of the report by referring to relevant literature on cyberattacks during report generation. For example, the report generation unit can refer to the latest research papers related to cyberattacks and generate the report. For example, the report generation unit can improve accuracy by comparing the report with relevant literature during report generation. For example, the report generation unit can improve the accuracy of the report by automatically referring to relevant literature depending on the type of cyberattack. In this way, the accuracy of the report can be improved by referring to relevant literature. Some or all of the above processing in the report generation unit may be performed using AI, for example, or without using AI. For example, the report generation unit can input cyberattack data into an AI model and improve the accuracy of the report by referring to relevant literature.
[0061] The system according to the embodiment is not limited to the example described above, and various modifications are possible, for example, as follows.
[0062] A cybersecurity system, in its data collection section, can analyze past cyberattack data and select the optimal collection method. For example, it can identify attack patterns that frequently occur during specific time periods from past data and focus data collection during those times. It can also select collection methods that are effective against specific attack techniques. Furthermore, it can select collection methods tailored to specific industries or regions. By analyzing past data, the system can select the optimal collection method and enable efficient data collection.
[0063] The detection unit can apply different detection algorithms depending on the type of abnormal activity detected. For example, a specific signature-based algorithm can be applied to malware detection, and an algorithm using natural language processing can be applied to phishing attack detection. Furthermore, an algorithm using traffic analysis can be applied to DDoS attack detection. This allows for efficient detection of abnormal activity by applying different detection algorithms depending on the type of activity.
[0064] The generation unit can generate the optimal countermeasure by analyzing the effectiveness of past countermeasures. For example, it can evaluate the effectiveness of past countermeasures and select the most effective one. It can also analyze past countermeasure failures and generate countermeasures to avoid similar failures. Furthermore, it can generate the optimal countermeasure for specific attack methods. In this way, the optimal countermeasure can be generated by analyzing the effectiveness of past countermeasures.
[0065] The implementing unit can apply different implementation methods depending on the type of cyberattack at the time of implementation. For example, for malware attacks, it can apply measures to take isolation measures, and for phishing attacks, it can apply measures to delete the relevant emails. Furthermore, for DDoS attacks, it can apply measures to restrict traffic. In this way, appropriate countermeasures can be implemented by applying different implementation methods depending on the type of cyberattack.
[0066] The report generation unit can optimize report content by referencing past incident data during report generation. For example, it can generate reports that prioritize displaying the most important information based on past incident data. It can also analyze past incident data and generate reports that include countermeasures for similar incidents. Furthermore, it can generate reports that include detailed analysis results for specific attack methods. In this way, by referring to past incident data, the optimal report can be generated.
[0067] The following briefly describes the processing flow for example form 1.
[0068] Step 1: The collection unit collects data on cyberattacks. The collection unit can collect data on past cyberattacks and newly occurring attacks, for example. The collection unit can collect log data, network traffic data, malware samples, etc. The collection unit can collect data in real time and store it in the cloud, for example. Step 2: The detection unit analyzes the data collected by the collection unit and detects cyber threats. The detection unit detects anomalous activity, for example, using machine learning models. The detection unit can find signs of cyberattacks, for example, by detecting communications that differ from normal traffic patterns. The detection unit can use machine learning models such as deep learning models or support vector machines. Step 3: The generation unit generates countermeasures for the threats detected by the detection unit. The generation unit analyzes the attacker's intentions and methods using natural language processing, for example, and generates countermeasures. The generation unit can use natural language processing techniques such as morphological analysis, grammatical analysis, and semantic analysis. The generation unit can, for example, analyze attack patterns and analyze the attacker's behavioral history. Step 4: The implementation unit implements the countermeasures generated by the generation unit. The implementation unit can, for example, take isolation measures against detected malware. The implementation unit can, for example, take isolation measures such as disconnecting from the network or moving to a specific folder. The implementation unit can, for example, automatically delete emails related to phishing attacks. The implementation unit can, for example, use methods such as analyzing the content of emails or verifying links. Step 5: The report generation unit generates an analysis report of the incident response. The report generation unit can, for example, automatically generate and provide the report in real time. The report generation unit can generate a report that includes, for example, an overview of the incident that occurred, details of the countermeasures taken, and future countermeasures.
[0069] (Example of form 2) The cybersecurity system according to an embodiment of the present invention is an AI-driven system that supports corporate data protection and compliance protection by detecting and predicting cyber threats in real time and automatically implementing countermeasures. This cybersecurity system expands the scope of response by consolidating all cyber attack cases on the cloud through a SaaS service contract and platform implementation. It is basically automated and automatically generates and provides incident response analysis reports in real time. This creates a state where it is possible to monitor whether there are any problems with the security status. First, cyber attack cases are consolidated on the cloud. At this time, data on past cyber attacks and newly occurring attacks are collected and stored on the cloud. For example, cases such as phishing attacks and malware attacks are collected. This creates a database for understanding cyber attack patterns and generating countermeasures. Next, cyber threats are automatically detected by combining machine learning and natural language processing. The machine learning model analyzes the collected data and detects abnormal activity. For example, by detecting communications that differ from normal traffic patterns, signs of cyber attacks can be found. Furthermore, natural language processing is used to analyze the intent and methods of attackers. This enables the early detection of cyber threats. Furthermore, the system automatically generates and implements countermeasures for detected threats. For example, it can isolate detected malware and automatically delete emails in response to phishing attacks. This minimizes the impact of cyberattacks. Finally, it automatically generates and provides real-time incident response analysis reports. This allows security personnel to understand the current security state and take necessary measures. For example, it provides reports with detailed analysis results of past incidents and current threat levels. This reduces the workload of security personnel and enables rapid response. This mechanism improves the quality of cybersecurity and reduces the workload of cybersecurity personnel.Companies can implement effective countermeasures against ever-evolving cyberattacks, thereby strengthening data protection and compliance. In this way, cybersecurity systems can support companies in protecting their data and ensuring compliance.
[0070] The cybersecurity system according to the embodiment comprises a collection unit, a detection unit, a generation unit, an implementation unit, and a report generation unit. The collection unit collects data on cyberattacks. The collection unit collects data on past cyberattacks and data on newly occurring attacks, for example. The collection unit can collect log data, network traffic data, malware samples, etc. The collection unit can collect data in real time and store it in the cloud, for example. The detection unit analyzes the data collected by the collection unit and detects cyber threats. The detection unit detects anomalous activity, for example, using a machine learning model. The detection unit can find signs of cyberattacks, for example, by detecting communications that differ from normal traffic patterns. The detection unit can use machine learning models such as deep learning models and support vector machines, for example. The generation unit generates countermeasures for threats detected by the detection unit. The generation unit analyzes the attacker's intentions and methods using natural language processing, for example, and generates countermeasures. The generation unit can use natural language processing techniques such as morphological analysis, grammatical analysis, and semantic analysis, for example. The generation unit can, for example, analyze attack patterns and analyze the attacker's activity history. The implementation unit implements the countermeasures generated by the generation unit. The implementation unit can, for example, take isolation measures against detected malware. The implementation unit can, for example, take isolation measures such as disconnecting from the network or moving to a specific folder. The implementation unit can, for example, automatically delete emails related to phishing attacks. The implementation unit can, for example, use methods such as analyzing the content of emails or verifying links. The report generation unit generates an incident response analysis report. The report generation unit can, for example, automatically generate and provide the report in real time. The report generation unit can, for example, generate a report that includes an overview of the incident that occurred, details of the countermeasures, and future countermeasures. In this way, the cybersecurity system according to the embodiment can support corporate data protection and compliance protection.Some or all of the above-described processes in the collection unit, detection unit, generation unit, implementation unit, and report generation unit may be performed using AI, for example, or without AI. For example, the collection unit can use an AI model to collect data on cyberattacks. The detection unit can input the data collected by the collection unit into an AI model to detect cyber threats. The generation unit can use an AI model to generate countermeasures for threats detected by the detection unit. The implementation unit can use an AI model to implement the countermeasures generated by the generation unit. The report generation unit can generate an incident response analysis report using an AI model.
[0071] The data collection unit collects data on cyberattacks. For example, it collects data on past cyberattacks and newly occurring attacks. Specifically, the unit can collect log data, network traffic data, malware samples, and more. Log data records the operation history of systems and applications and is an important source of information for detecting traces of attacks and abnormal behavior. Network traffic data records details of communications on the network and is used to detect abnormal communication patterns and signs of unauthorized access. Malware samples are actual instances of detected malware, and their analysis can identify attack methods and infection routes. The data collection unit can collect this data in real time and store it in the cloud. Storing data in the cloud allows for efficient management of large amounts of data and enables collaboration with analysis departments and other systems. Furthermore, the data collection unit can use AI models to collect data. For example, AI models can automatically detect abnormal patterns in network traffic and prioritize the collection of important data. The data collection unit can also dynamically adjust the frequency and target of data collection to respond flexibly to specific situations and threats. This allows the data collection unit to efficiently and effectively collect data on cyberattacks, thereby improving the overall security of the system.
[0072] The detection unit analyzes the data collected by the collection unit to detect cyber threats. The detection unit can detect anomalous activity using, for example, machine learning models. Specifically, it can use machine learning models such as deep learning models and support vector machines. Deep learning models have the ability to learn from large amounts of data and recognize complex patterns, enabling them to detect unknown threats and new attack methods with high accuracy. Support vector machines can map data features into a high-dimensional space, effectively identifying anomalous data points. The detection unit can find signs of cyberattacks by detecting communications that differ from normal traffic patterns. For example, it can quickly detect anomalous activity such as large amounts of data being sent externally outside of normal business hours or frequent unauthorized access from specific IP addresses. Furthermore, the detection unit can analyze the collected data in real time using AI models to perform early detection of cyber threats. AI models can learn from past attack data and automatically identify new attacks with similar patterns. This allows the detection unit to quickly and accurately detect cyber threats and enhance the overall system security.
[0073] The generation unit generates countermeasures for threats detected by the detection unit. For example, the generation unit uses natural language processing to analyze the attacker's intentions and methods, and then generates countermeasures. Specifically, it can utilize natural language processing techniques such as morphological analysis, grammatical analysis, and semantic analysis. Morphological analysis is a technique that divides text into words and analyzes the meaning and role of each word. Grammatical analysis is a technique that analyzes the structure of a sentence and clarifies the relationships between subjects, predicates, and objects. Semantic analysis is a technique that understands the meaning of a sentence and generates appropriate countermeasures according to the context. The generation unit can combine these techniques to analyze attack patterns and the attacker's behavioral history. For example, it can analyze specific commands and tools used by an attacker and propose effective defensive measures against them. Furthermore, the generation unit can use an AI model to automatically generate the optimal countermeasures for detected threats. The AI model learns the effectiveness of past countermeasures and can propose the most effective countermeasures for similar threats. This allows the generation unit to generate countermeasures quickly and effectively, improving its defenses against cyberattacks.
[0074] The implementation unit will carry out the countermeasures generated by the generation unit. For example, the implementation unit can take isolation measures against detected malware. Specifically, it can take isolation measures such as disconnecting from the network or moving to a specific folder. Disconnecting from the network is a method to prevent the spread of malware by physically separating the infected device from the network. Moving to a specific folder is a method to move the infected file to a safe location to prevent infection of other files. The implementation unit can automatically execute these measures and quickly contain the threat. In addition, the implementation unit can automatically delete emails that are relevant to phishing attacks. Specifically, it can use methods such as email content analysis and link verification. Email content analysis is a method of analyzing the text of the email body to detect signs of phishing. Link verification is a method of analyzing the destination of links in the email to prevent access to malicious sites. The implementation unit can combine these methods to implement effective countermeasures against phishing attacks. Furthermore, the implementation unit can use an AI model to automatically carry out the countermeasures generated by the generation unit. The AI model can learn from past implementation results and select the optimal implementation method. This allows the implementing department to quickly and effectively implement countermeasures and minimize the impact of cyberattacks.
[0075] The report generation unit generates incident response analysis reports. For example, it can automatically generate and deliver these reports in real time. Specifically, it can generate reports that include an overview of the incident, details of the response measures, and future countermeasures. The incident overview includes the type of attack, the date and time of occurrence, and the scope of impact. Details of the response measures include the specific measures taken, the tools and technologies used, and the effectiveness of the measures. Future countermeasures include suggestions for preventing recurrence, improvements, and additional security measures. The report generation unit can automatically collect and integrate this information to generate reports. Furthermore, the report generation unit can use AI models to generate incident response analysis reports. The AI models can learn from past incident data and automatically generate optimal reports for similar incidents. This allows the report generation unit to generate analysis reports quickly and accurately, supporting corporate data protection and compliance. Additionally, the report generation unit can automatically distribute the generated reports to relevant parties. For example, it can provide reports in real time via email or dashboards to support rapid decision-making. This allows the report generation unit to improve the transparency and efficiency of incident response and strengthen overall security management within the enterprise.
[0076] The data collection unit can collect data on past cyberattacks and newly occurring attacks. For example, the data collection unit can collect data on past cyberattacks. For example, the data collection unit can collect data for the past year or data on specific types of attacks. For example, the data collection unit can collect data on newly occurring attacks. For example, the data collection unit can collect data in real time or data within a specific period. This makes it possible to build a database for understanding cyberattack patterns and generating countermeasures by collecting data on past cyberattacks and newly occurring attacks. Some or all of the above processing in the data collection unit may be performed using AI, for example, or without AI. For example, the data collection unit can input data on past cyberattacks and newly occurring attacks into an AI model and collect the data.
[0077] The detection unit can detect anomalous activity using machine learning models. For example, the detection unit can detect anomalous activity using deep learning models. For example, the detection unit can find signs of a cyberattack by detecting communications that differ from normal traffic patterns. The detection unit can also detect anomalous activity using support vector machines. For example, the detection unit can find anomalous activity by detecting a large volume of access to a specific port. For example, the detection unit can apply an anomaly detection algorithm to detect anomalous traffic patterns. This allows for high-precision detection of anomalous activity using machine learning models. Some or all of the above-described processes in the detection unit may be performed using AI, for example, or without AI. For example, the detection unit can input data collected by the collection unit into an AI model to detect anomalous activity.
[0078] The generation unit can analyze the attacker's intent and methods using natural language processing and generate countermeasures. For example, the generation unit can analyze the attacker's intent using morphological analysis. For example, the generation unit can analyze the attacker's behavioral history and identify attack patterns. For example, the generation unit can also analyze the attacker's methods using grammatical analysis. For example, the generation unit can apply semantic analysis to analyze the attacker's intent. For example, the generation unit can analyze attack patterns and generate appropriate countermeasures. In this way, by using natural language processing, the attacker's intent and methods can be analyzed and appropriate countermeasures can be generated. Some or all of the above processing in the generation unit may be performed using AI, for example, or without AI. For example, the generation unit can generate countermeasures using an AI model for threats detected by the detection unit.
[0079] The implementation unit can take isolation measures against detected malware. For example, the implementation unit may disconnect it from the network. The implementation unit may also move it to a specific folder. For example, the implementation unit may move malware to a specific folder for isolation. For example, the implementation unit can prevent the spread of malware by disconnecting it from the network. For example, the implementation unit may move malware to a specific folder for isolation. This minimizes the impact of cyberattacks by taking isolation measures against detected malware. Some or all of the above processes in the implementation unit may be performed using AI, for example, or without AI. For example, the implementation unit may input detected malware into an AI model and perform isolation measures.
[0080] The implementation unit can automatically delete emails that are phishing attacks. The implementation unit can, for example, analyze the content of the email. The implementation unit can also, for example, verify links. The implementation unit can identify phishing emails by, for example, detecting specific keywords. The implementation unit can identify phishing emails by, for example, analyzing the email header. The implementation unit can detect specific keywords in order to automatically delete phishing emails. This minimizes the impact of cyberattacks by automatically deleting emails that are phishing attacks. Some or all of the above processes performed by the implementation unit may be performed using AI, for example, or not using AI. For example, the implementation unit can input the content of a phishing email into an AI model and automatically delete the email.
[0081] The report generation unit can automatically generate and provide incident response analysis reports in real time. For example, the report generation unit can generate a report that includes an overview of the incident that occurred. The report generation unit can also generate a report that includes details of the countermeasures taken. The report generation unit can also generate a report that includes future countermeasures. For example, the report generation unit can collect data in real time and automatically generate reports. For example, the report generation unit can generate a report that includes detailed analysis results of the incident that occurred. This reduces the workload of security personnel and enables a rapid response by automatically generating and providing incident response analysis reports in real time. Some or all of the above processes in the report generation unit may be performed using AI, for example, or without AI. For example, the report generation unit can input incident response data into an AI model and automatically generate reports.
[0082] The data collection unit can estimate the user's emotions and adjust the timing of cyberattack data collection based on the estimated emotions. For example, if the user is stressed, the data collection unit can reduce the collection frequency to lessen the system load. For example, if the user is relaxed, the data collection unit can increase the collection frequency to collect more detailed data. For example, if the user is in an emergency, the data collection unit can immediately start collecting data to enable a rapid response. By adjusting the collection timing based on the user's emotions, the system load is reduced and efficient data collection becomes possible. Emotion estimation is achieved using an emotion estimation function, for example, using an emotion engine or generative AI. Generative AI is, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI. Some or all of the above processing in the data collection unit may be performed using AI, for example, or not using AI. For example, the data collection unit can input user emotion data into an AI model and adjust the collection timing.
[0083] The data collection unit can analyze past cyberattack data and select the optimal collection method. For example, the data collection unit can identify attack patterns that frequently occur during specific time periods from past data and focus data collection during those periods. For example, the data collection unit can select an effective collection method for a specific attack technique based on past attack data. For example, the data collection unit can analyze past data and select a collection method specialized for a specific industry or region. This enables efficient data collection by selecting the optimal collection method through the analysis of past data. Some or all of the above-described processes in the data collection unit may be performed using AI, for example, or without AI. For example, the data collection unit can input past cyberattack data into an AI model to select the optimal collection method.
[0084] The data collection unit can filter cyberattack data based on specific industries or regions. For example, the data collection unit can prioritize the collection of attack data related to a specific industry (e.g., the financial industry). For example, the data collection unit can filter and collect attack data in a specific region (e.g., the Asian region). For example, the data collection unit can filter data based on a specific combination of industry and region (e.g., the Asian financial industry). This allows for the efficient collection of highly relevant data by filtering data based on specific industries and regions. Some or all of the above processing in the data collection unit may be performed using AI, for example, or without AI. For example, the data collection unit can input cyberattack data into an AI model and filter it based on specific industries or regions.
[0085] The data collection unit can estimate the user's emotions and prioritize the cyberattack data to collect based on the estimated user emotions. For example, if the user is stressed, the data collection unit will prioritize collecting only high-priority data. For example, if the user is relaxed, the data collection unit can collect a wide range of data and perform detailed analysis. For example, if the user is in an emergency, the data collection unit will prioritize collecting data that is urgently needed. This allows for the priority collection of important data by prioritizing data based on the user's emotions. Emotion estimation is achieved using an emotion estimation function, such as an emotion engine or generative AI. Generative AI includes, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI. Some or all of the above processing in the data collection unit may be performed using AI, for example, or not using AI. For example, the data collection unit can input user emotion data into an AI model to determine data prioritization.
[0086] The data collection unit can prioritize the collection of highly relevant data based on the user's geographical location when collecting cyberattack data. For example, if the user is in a specific region, the data collection unit will prioritize the collection of attack data related to that region. For example, the data collection unit can collect attack data that occurred in nearby areas based on the user's geographical location. For example, the data collection unit can collect highly relevant data in real time, taking into account the user's location. This enables efficient data collection by prioritizing the collection of highly relevant data based on the user's geographical location. Some or all of the above processing in the data collection unit may be performed using AI, for example, or without AI. For example, the data collection unit can input the user's geographical location into an AI model and collect highly relevant data.
[0087] The data collection unit can analyze a user's social media activity and collect relevant data when collecting cyberattack data. For example, the data collection unit can collect information about cyberattacks from a user's social media activity. For example, the data collection unit can analyze posts from security experts that a user follows and collect relevant data. For example, the data collection unit can detect early signs of an attack based on a user's social media activity and collect data. This allows for the efficient collection of relevant data by analyzing a user's social media activity. Some or all of the above processing in the data collection unit may be performed using AI, for example, or without AI. For example, the data collection unit can input user social media activity data into an AI model and collect relevant data.
[0088] The detection unit can estimate the user's emotions and adjust the detection criteria for abnormal activities based on the estimated user emotions. For example, if the user is stressed, the detection unit can relax the detection criteria to reduce false positives. For example, if the user is relaxed, the detection unit can tighten the detection criteria to perform more detailed detections. For example, if the user is in an emergency, the detection unit can prioritize detecting abnormal activities that require immediate attention. By adjusting the detection criteria based on the user's emotions, false positives are reduced, and efficient detection of abnormal activities becomes possible. Emotion estimation is achieved using an emotion estimation function, for example, using an emotion engine or generative AI. Generative AI is, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI. Some or all of the above processing in the detection unit may be performed using AI, for example, or without AI. For example, the detection unit can input user emotion data into an AI model and adjust the detection criteria.
[0089] The detection unit can use a machine learning model to detect abnormal activity during specific time periods or on specific days of the week. For example, the detection unit can detect abnormal activity that occurs frequently during specific time periods (e.g., late at night). For example, the detection unit can detect abnormal activity on specific days of the week (e.g., weekends) and take countermeasures. For example, the detection unit can analyze abnormal activity patterns for each time period or day of the week and build a predictive model. This enables efficient detection of abnormal activity by detecting abnormal activity during specific time periods or days of the week. Some or all of the above processing in the detection unit may be performed using AI, for example, or without AI. For example, the detection unit can input data collected by the collection unit into an AI model to detect abnormal activity during specific time periods or days of the week.
[0090] The detection unit can apply different detection algorithms depending on the type of abnormal activity detected. For example, the detection unit can apply a specific signature-based algorithm to detect malware. For example, the detection unit can apply an algorithm using natural language processing to detect phishing attacks. For example, the detection unit can apply an algorithm using traffic analysis to detect DDoS attacks. This enables efficient detection of abnormal activity by applying different detection algorithms depending on the type of abnormal activity. Some or all of the above processing in the detection unit may be performed using AI, for example, or without AI. For example, the detection unit can input data collected by the collection unit into an AI model and apply different detection algorithms to detect abnormal activity.
[0091] The detection unit can estimate the user's emotions and adjust the order in which it displays the detection results of abnormal activities based on the estimated user emotions. For example, if the user is stressed, the detection unit can prioritize displaying high-priority abnormal activities. For example, if the user is relaxed, the detection unit can display detailed detection results in a sequential manner. For example, if the user is in an emergency, the detection unit can prioritize displaying abnormal activities that require immediate attention. In this way, important information can be prioritized by adjusting the display order of detection results based on the user's emotions. Emotion estimation is achieved using an emotion estimation function, for example, using an emotion engine or generative AI. Generative AI is, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI. Some or all of the above processing in the detection unit may be performed using AI, for example, or without AI. For example, the detection unit can input user emotion data into an AI model and adjust the display order of detection results.
[0092] The detection unit can perform detection while considering the geographical distribution of anomalous activity. For example, if anomalous activity is concentrated in a particular area, the detection unit can perform detection specific to that area. For example, the detection unit can identify the source of anomalous activity based on its geographical distribution. For example, the detection unit can predict the spread of anomalous activity while considering its geographical distribution. This makes it possible to efficiently detect anomalous activity by considering its geographical distribution. Some or all of the above processing in the detection unit may be performed using AI, for example, or without AI. For example, the detection unit can input data collected by the collection unit into an AI model and perform detection of anomalous activity while considering its geographical distribution.
[0093] The detection unit can improve the accuracy of detection by referring to relevant literature on anomalous activity during detection. For example, the detection unit can improve the detection algorithm by referring to the latest research papers related to anomalous activity. For example, the detection unit can improve accuracy by comparing the detection results of anomalous activity with relevant literature. For example, the detection unit can improve detection accuracy by automatically referring to relevant literature depending on the type of anomalous activity. In this way, detection accuracy can be improved by referring to relevant literature. Some or all of the above processing in the detection unit may be performed using AI, for example, or without using AI. For example, the detection unit can input data on anomalous activity into an AI model and improve detection accuracy by referring to relevant literature.
[0094] The generation unit can estimate the user's emotions and adjust the method of generating countermeasures based on the estimated user emotions. For example, if the user is stressed, the generation unit can generate simple and quick countermeasures. For example, if the user is relaxed, the generation unit can generate detailed countermeasures. For example, if the user is in an emergency, the generation unit can generate immediately actionable countermeasures. In this way, appropriate countermeasures can be generated by adjusting the method of generating countermeasures based on the user's emotions. Emotion estimation is achieved using an emotion estimation function, for example, using an emotion engine or a generation AI. The generation AI is, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI. Some or all of the above processing in the generation unit may be performed using AI, for example, or not using AI. For example, the generation unit can input user emotion data into an AI model and adjust the method of generating countermeasures.
[0095] The generation unit can generate the optimal countermeasure by analyzing the effectiveness of past countermeasures when generating countermeasures. For example, the generation unit can evaluate the effectiveness of past countermeasures and select the most effective countermeasure. For example, the generation unit can analyze past countermeasure failures and generate countermeasures to avoid similar failures. For example, the generation unit can generate the optimal countermeasure for a specific attack method based on data from past countermeasures. In this way, the optimal countermeasure can be generated by analyzing the effectiveness of past countermeasures. Some or all of the above processing in the generation unit may be performed using AI, for example, or without using AI. For example, the generation unit can input data from past countermeasures into an AI model and generate the optimal countermeasure.
[0096] The generation unit can apply different generation algorithms depending on the type of cyberattack when generating countermeasures. For example, the generation unit can apply an algorithm to take isolation measures against malware attacks. For example, the generation unit can apply an algorithm to delete emails in response to phishing attacks. For example, the generation unit can apply an algorithm to restrict traffic against DDoS attacks. By applying different generation algorithms depending on the type of cyberattack, appropriate countermeasures can be generated. Some or all of the above processing in the generation unit may be performed using AI, for example, or without AI. For example, the generation unit can input cyberattack data into an AI model and generate countermeasures by applying different generation algorithms.
[0097] The generation unit can estimate the user's emotions and determine the priority of countermeasures to generate based on the estimated user emotions. For example, if the user is stressed, the generation unit will prioritize generating high-priority countermeasures. For example, if the user is relaxed, the generation unit can generate detailed countermeasures in a sequential manner. For example, if the user is in an emergency, the generation unit will prioritize generating immediately actionable countermeasures. In this way, by determining the priority of countermeasures based on the user's emotions, important countermeasures can be generated preferentially. Emotion estimation is achieved using an emotion estimation function, for example, using an emotion engine or a generation AI. The generation AI is, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI. Some or all of the above processing in the generation unit may be performed using AI, for example, or not using AI. For example, the generation unit can input user emotion data into an AI model to determine the priority of countermeasures.
[0098] The generation unit can determine the priority of countermeasures based on the timing of the cyberattack when generating countermeasures. For example, the generation unit can quickly generate and implement countermeasures immediately after a cyberattack occurs. For example, the generation unit can generate the optimal countermeasure based on past data, taking into account the timing of the cyberattack. For example, the generation unit can adjust priorities according to the timing of the cyberattack to generate effective countermeasures. This allows for the rapid generation of effective countermeasures by determining the priority of countermeasures based on the timing of the cyberattack. Some or all of the above processing in the generation unit may be performed using AI, for example, or without AI. For example, the generation unit can input data on the timing of cyberattacks into an AI model to determine the priority of countermeasures.
[0099] The generation unit can improve the accuracy of countermeasures by referring to relevant literature on cyberattacks when generating countermeasures. For example, the generation unit can refer to the latest research papers related to cyberattacks and generate countermeasures. For example, the generation unit can improve the accuracy by comparing the generated countermeasures with relevant literature when generating them. For example, the generation unit can improve the accuracy of countermeasures by automatically referring to relevant literature depending on the type of cyberattack. In this way, the accuracy of countermeasures can be improved by referring to relevant literature. Some or all of the above processing in the generation unit may be performed using AI, for example, or without using AI. For example, the generation unit can input cyberattack data into an AI model and improve the accuracy of countermeasures by referring to relevant literature.
[0100] The implementation unit can estimate the user's emotions and adjust the implementation method of countermeasures based on the estimated user emotions. For example, if the user is stressed, the implementation unit may select a simple and quick implementation method. For example, if the user is relaxed, the implementation unit may select an implementation method that includes detailed steps. For example, if the user is in an emergency, the implementation unit may select an implementation method that can be implemented immediately. This allows for the implementation of appropriate countermeasures by adjusting the implementation method based on the user's emotions. Emotion estimation is achieved using an emotion estimation function, for example, using an emotion engine or generative AI. Generative AI is, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI. Some or all of the above processing in the implementation unit may be performed using AI, for example, or not using AI. For example, the implementation unit can input user emotion data into an AI model and adjust the implementation method.
[0101] The implementation unit can analyze past implementation results and select the optimal implementation method at the time of implementation. For example, the implementation unit can evaluate past implementation results and select the most effective implementation method. For example, the implementation unit can analyze past implementation failures and select implementation methods to avoid similar failures. For example, the implementation unit can select the optimal implementation method for a specific attack method based on past implementation result data. In this way, the optimal implementation method can be selected by analyzing past implementation results. Some or all of the above processes in the implementation unit may be performed using AI, for example, or without AI. For example, the implementation unit can input past implementation result data into an AI model and select the optimal implementation method.
[0102] The implementation unit can apply different implementation measures depending on the type of cyberattack during implementation. For example, the implementation unit can apply measures to take isolation measures against malware attacks. For example, the implementation unit can apply measures to delete relevant emails against phishing attacks. For example, the implementation unit can apply measures to restrict traffic against DDoS attacks. By applying different implementation measures depending on the type of cyberattack, appropriate countermeasures can be implemented. Some or all of the above processing in the implementation unit may be performed using AI, for example, or without AI. For example, the implementation unit can input cyberattack data into an AI model and implement countermeasures by applying different implementation measures.
[0103] The implementation unit can estimate the user's emotions and determine the order in which to implement countermeasures based on the estimated emotions. For example, if the user is stressed, the implementation unit will prioritize implementing high-priority countermeasures. For example, if the user is relaxed, the implementation unit can implement detailed procedures in a sequential manner. For example, if the user is in an emergency, the implementation unit will prioritize implementing countermeasures that can be taken immediately. This ensures that important countermeasures are prioritized by determining the order of implementation based on the user's emotions. Emotion estimation is achieved using an emotion estimation function, for example, using an emotion engine or generative AI. Generative AI is, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI. Some or all of the above processing in the implementation unit may be performed using AI, for example, or not using AI. For example, the implementation unit can input user emotion data into an AI model and determine the order of implementation.
[0104] The implementation unit can take into account the geographical distribution of cyberattacks when carrying out countermeasures. For example, if cyberattacks are concentrated in a particular area, the implementation unit can carry out countermeasures specifically tailored to that area. For example, the implementation unit can identify the source of an attack based on its geographical distribution and carry out countermeasures. For example, the implementation unit can take measures to prevent the spread of attacks by considering the geographical distribution. This makes it possible to implement countermeasures efficiently by considering the geographical distribution of cyberattacks. Some or all of the above-mentioned processes in the implementation unit may be carried out using AI, for example, or not using AI. For example, the implementation unit can input data on the geographical distribution of cyberattacks into an AI model and carry out countermeasures while considering the geographical distribution.
[0105] The implementation unit can improve the accuracy of its implementation by referring to relevant literature on cyberattacks during implementation. For example, the implementation unit can improve its implementation methods by referring to the latest research papers related to cyberattacks. For example, the implementation unit can improve accuracy by comparing with relevant literature during implementation. For example, the implementation unit can improve the accuracy of its implementation by automatically referring to relevant literature depending on the type of cyberattack. In this way, the accuracy of implementation can be improved by referring to relevant literature. Some or all of the above processing in the implementation unit may be performed using AI, for example, or without using AI. For example, the implementation unit can input cyberattack data into an AI model and improve the accuracy of implementation by referring to relevant literature.
[0106] The report generation unit can estimate the user's emotions and adjust how the report is displayed based on the estimated emotions. For example, if the user is stressed, the report generation unit can provide a simple and easy-to-read report. For example, if the user is relaxed, the report generation unit can provide a report containing detailed information. For example, if the user is in an emergency, the report generation unit can provide a report that prioritizes displaying information requiring immediate attention. In this way, by adjusting how the report is displayed based on the user's emotions, a highly visual report can be provided. Emotion estimation is achieved using an emotion estimation function, for example, using an emotion engine or generative AI. Generative AI is, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI. Some or all of the above processing in the report generation unit may be performed using AI, for example, or without AI. For example, the report generation unit can input user emotion data into an AI model and adjust how the report is displayed.
[0107] The report generation unit can optimize the report content by referring to past incident data when generating a report. For example, the report generation unit can generate a report that prioritizes displaying the most important information based on past incident data. For example, the report generation unit can analyze past incident data and generate a report that includes countermeasures for similar incidents occurring. For example, the report generation unit can refer to past incident data and generate a report that includes detailed analysis results for specific attack methods. In this way, the optimal report can be generated by referring to past incident data. Some or all of the above processing in the report generation unit may be performed using AI, for example, or without AI. For example, the report generation unit can input past incident data into an AI model to optimize the report content.
[0108] The report generation unit can apply different report generation algorithms depending on the type of cyberattack when generating a report. For example, for malware attacks, the report generation unit can apply an algorithm that generates a report including details of quarantine measures. For example, for phishing attacks, the report generation unit can apply an algorithm that generates a report including procedures for deleting the relevant emails. For example, for DDoS attacks, the report generation unit can apply an algorithm that generates a report including details of traffic restrictions. In this way, by applying different report generation algorithms depending on the type of cyberattack, an appropriate report can be generated. Some or all of the above processing in the report generation unit may be performed using AI, for example, or without AI. For example, the report generation unit can input cyberattack data into an AI model and generate a report by applying different report generation algorithms.
[0109] The report generation unit can estimate the user's emotions and determine the priority of reports based on the estimated emotions. For example, if the user is stressed, the report generation unit can generate a report that prioritizes displaying highly important information. For example, if the user is relaxed, the report generation unit can generate a report that displays detailed information in a sequential manner. For example, if the user is in an emergency, the report generation unit can generate a report that prioritizes displaying information requiring immediate attention. In this way, important information can be displayed preferentially by determining the priority of reports based on the user's emotions. Emotion estimation is achieved using an emotion estimation function, for example, using an emotion engine or generative AI. Generative AI is, but is not limited to, text generation AI (e.g., LLM) or multimodal generation AI. Some or all of the above processing in the report generation unit may be performed using AI, for example, or without AI. For example, the report generation unit can input user emotion data into an AI model to determine the priority of reports.
[0110] The report generation unit can adjust the content of the report based on the timing of the cyberattack when generating the report. For example, the report generation unit can quickly generate a report including countermeasures immediately after a cyberattack occurs. For example, the report generation unit can consider the timing of the cyberattack and generate an optimal report based on past data. For example, the report generation unit can adjust priorities according to the timing of the cyberattack to generate an effective report. In this way, by adjusting the content of the report based on the timing of the cyberattack, it is possible to generate a quick and effective report. Some or all of the above processing in the report generation unit may be performed using AI, for example, or without using AI. For example, the report generation unit can input data on the timing of the cyberattack into an AI model and adjust the content of the report.
[0111] The report generation unit can improve the accuracy of the report by referring to relevant literature on cyberattacks during report generation. For example, the report generation unit can refer to the latest research papers related to cyberattacks and generate the report. For example, the report generation unit can improve accuracy by comparing the report with relevant literature during report generation. For example, the report generation unit can improve the accuracy of the report by automatically referring to relevant literature depending on the type of cyberattack. In this way, the accuracy of the report can be improved by referring to relevant literature. Some or all of the above processing in the report generation unit may be performed using AI, for example, or without using AI. For example, the report generation unit can input cyberattack data into an AI model and improve the accuracy of the report by referring to relevant literature.
[0112] The system according to the embodiment is not limited to the example described above, and various modifications are possible, for example, as follows.
[0113] Cybersecurity systems can also estimate user emotions and adjust their operation based on those emotions. For example, if the data collection unit is stressed, it can reduce the frequency of data collection to lessen the system load. Conversely, if the user is relaxed, it can increase the collection frequency to gather more detailed data. Furthermore, if the user is in an emergency, it can immediately begin data collection to enable a rapid response. In this way, adjusting system operation based on user emotions enables efficient data collection and reduces system load.
[0114] A cybersecurity system, in its data collection section, can analyze past cyberattack data and select the optimal collection method. For example, it can identify attack patterns that frequently occur during specific time periods from past data and focus data collection during those times. It can also select collection methods that are effective against specific attack techniques. Furthermore, it can select collection methods tailored to specific industries or regions. By analyzing past data, the system can select the optimal collection method and enable efficient data collection.
[0115] The detection unit can estimate the user's emotions and adjust the detection criteria for abnormal activity based on the estimated emotions. For example, if the user is stressed, the detection criteria can be relaxed to reduce false positives. Conversely, if the user is relaxed, the detection criteria can be made stricter to perform more detailed detection. Furthermore, if the user is in an emergency, abnormal activity requiring immediate attention can be prioritized for detection. In this way, adjusting the detection criteria based on the user's emotions reduces false positives and enables efficient detection of abnormal activity.
[0116] The detection unit can apply different detection algorithms depending on the type of abnormal activity detected. For example, a specific signature-based algorithm can be applied to malware detection, and an algorithm using natural language processing can be applied to phishing attack detection. Furthermore, an algorithm using traffic analysis can be applied to DDoS attack detection. This allows for efficient detection of abnormal activity by applying different detection algorithms depending on the type of activity.
[0117] The generation unit can estimate the user's emotions and adjust the method of generating countermeasures based on those emotions. For example, if the user is stressed, it can generate simple and quick countermeasures. If the user is relaxed, it can generate detailed countermeasures. Furthermore, if the user is in an emergency, it can generate immediately actionable countermeasures. In this way, by adjusting the method of generating countermeasures based on the user's emotions, appropriate countermeasures can be generated.
[0118] The generation unit can generate the optimal countermeasure by analyzing the effectiveness of past countermeasures. For example, it can evaluate the effectiveness of past countermeasures and select the most effective one. It can also analyze past countermeasure failures and generate countermeasures to avoid similar failures. Furthermore, it can generate the optimal countermeasure for specific attack methods. In this way, the optimal countermeasure can be generated by analyzing the effectiveness of past countermeasures.
[0119] The implementation unit can estimate the user's emotions and adjust the implementation method of countermeasures based on those emotions. For example, if the user is stressed, a simple and quick implementation method can be selected. If the user is relaxed, an implementation method including detailed procedures can be selected. Furthermore, if the user is in an emergency, an implementation method that can be acted on immediately can be selected. In this way, appropriate countermeasures can be implemented by adjusting the implementation method based on the user's emotions.
[0120] The implementing unit can apply different implementation methods depending on the type of cyberattack at the time of implementation. For example, for malware attacks, it can apply measures to take isolation measures, and for phishing attacks, it can apply measures to delete the relevant emails. Furthermore, for DDoS attacks, it can apply measures to restrict traffic. In this way, appropriate countermeasures can be implemented by applying different implementation methods depending on the type of cyberattack.
[0121] The report generation unit can estimate the user's emotions and adjust how the report is displayed based on those emotions. For example, if the user is stressed, it can provide a simple and easy-to-read report. If the user is relaxed, it can provide a report with more detailed information. Furthermore, if the user is in an emergency, it can provide a report that prioritizes displaying information requiring immediate attention. In this way, by adjusting how the report is displayed based on the user's emotions, it is possible to provide a highly visual report.
[0122] The report generation unit can optimize report content by referencing past incident data during report generation. For example, it can generate reports that prioritize displaying the most important information based on past incident data. It can also analyze past incident data and generate reports that include countermeasures for similar incidents. Furthermore, it can generate reports that include detailed analysis results for specific attack methods. In this way, by referring to past incident data, the optimal report can be generated.
[0123] The following briefly describes the processing flow for example form 2.
[0124] Step 1: The collection unit collects data on cyberattacks. The collection unit can collect data on past cyberattacks and newly occurring attacks, for example. The collection unit can collect log data, network traffic data, malware samples, etc. The collection unit can collect data in real time and store it in the cloud, for example. Step 2: The detection unit analyzes the data collected by the collection unit and detects cyber threats. The detection unit detects anomalous activity, for example, using machine learning models. The detection unit can find signs of cyberattacks, for example, by detecting communications that differ from normal traffic patterns. The detection unit can use machine learning models such as deep learning models or support vector machines. Step 3: The generation unit generates countermeasures for the threats detected by the detection unit. The generation unit analyzes the attacker's intentions and methods using natural language processing, for example, and generates countermeasures. The generation unit can use natural language processing techniques such as morphological analysis, grammatical analysis, and semantic analysis. The generation unit can, for example, analyze attack patterns and analyze the attacker's behavioral history. Step 4: The implementation unit implements the countermeasures generated by the generation unit. The implementation unit can, for example, take isolation measures against detected malware. The implementation unit can, for example, take isolation measures such as disconnecting from the network or moving to a specific folder. The implementation unit can, for example, automatically delete emails related to phishing attacks. The implementation unit can, for example, use methods such as analyzing the content of emails or verifying links. Step 5: The report generation unit generates an analysis report of the incident response. The report generation unit can, for example, automatically generate and provide the report in real time. The report generation unit can generate a report that includes, for example, an overview of the incident that occurred, details of the countermeasures taken, and future countermeasures.
[0125] The specific processing unit 290 transmits the result of the specific processing to the smart device 14. In the smart device 14, the control unit 46A causes the output device 40 to output the result of the specific processing. The microphone 38B acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.
[0126] Data generation model 58 is a form of so-called generative AI (Artificial Intelligence). An example of data generation model 58 is ChatGPT (registered trademark) (Internet search).<URL: https: / / openai.com / blog / chatgpt> Examples of generative AI include text generation AI, image generation AI, and multimodal generation AI. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images (e.g., still image data or video data). The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference result in one or more data formats from audio data, text data, and image data. The data generation model 58 includes, for example, text generation AI, image generation AI, and multimodal generation AI. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization. The specific processing unit 290 performs the specific processing described above using the data generation model 58. The data generation model 58 may be a fine-tuned model that outputs inference results from prompts that do not contain instructions, in which case the data generation model 58 can output inference results from prompts that do not contain instructions. In the data processing device 12, etc., there are multiple types of data generation models 58, and the data generation model 58 includes AI other than generative AI. AI other than generative AI includes, for example, linear regression, logistic regression, decision trees, random forests, support vector machines (SVMs), k-means clustering, convolutional neural networks (CNNs), recurrent neural networks (RNNs), generative adversarial networks (GANs), or naive Bayes, and can perform various processes, but is not limited to these examples. Also, the AI may be an AI agent. Furthermore, when the processing of each of the above parts is performed by the AI, the processing may be performed by the AI in part or in whole, but is not limited to this example.Furthermore, processing performed by AI, including generative AI, may be replaced with rule-based processing, and rule-based processing may be replaced with processing performed by AI, including generative AI.
[0127] Furthermore, the processing performed by the data processing system 10 described above is carried out by the specific processing unit 290 of the data processing device 12 or the control unit 46A of the smart device 14, but it may also be carried out by the specific processing unit 290 of the data processing device 12 and the control unit 46A of the smart device 14. In addition, the specific processing unit 290 of the data processing device 12 acquires or collects information necessary for processing from the smart device 14 or an external device, and the smart device 14 acquires or collects information necessary for processing from the data processing device 12 or an external device.
[0128] Each of the multiple elements described above, including the collection unit, detection unit, generation unit, implementation unit, and report generation unit, is implemented in at least one of the smart device 14 and the data processing unit 12. For example, the collection unit collects cyberattack data using the camera 42 and microphone 38B of the smart device 14 and analyzes it using the identification processing unit 290 of the data processing unit 12. The detection unit is implemented by the identification processing unit 290 of the data processing unit 12 and detects cyber threats by analyzing the collected data. The generation unit is implemented by the identification processing unit 290 of the data processing unit 12 and generates countermeasures for the detected threats. The implementation unit is implemented by the control unit 46A of the smart device 14 and implements the generated countermeasures. The report generation unit is implemented by the identification processing unit 290 of the data processing unit 12 and generates an incident response analysis report. The correspondence between each unit and the device or control unit is not limited to the example described above and can be modified in various ways.
[0129] [Second Embodiment] Figure 3 shows an example of the configuration of the data processing system 210 according to the second embodiment.
[0130] As shown in Figure 3, the data processing system 210 includes a data processing device 12 and smart glasses 214. An example of the data processing device 12 is a server.
[0131] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN and / or LAN.
[0132] The smart glasses 214 include a computer 36, a microphone 238, a speaker 240, a camera 42, and a communication interface 44. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, and camera 42 are also connected to the bus 52.
[0133] The microphone 238 receives voice commands and other instructions from the user by receiving voice signals. The microphone 238 captures the voice signals from the user, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.
[0134] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, which captures images of the area around the user (for example, an imaging range defined by a field of view equivalent to the field of vision of a typical healthy person).
[0135] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.
[0136] Figure 4 shows an example of the main functions of the data processing device 12 and the smart glasses 214. As shown in Figure 4, the data processing device 12 performs specific processing by the processor 28. The storage 32 stores the specific processing program 56.
[0137] The processor 28 reads a specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 acting as a specific processing unit 290 according to the specific processing program 56 executed on the RAM 30.
[0138] Storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290. The identification processing unit 290 can estimate the user's emotions using the emotion identification model 59 and perform identification processing using the user's emotions. The emotion estimation function (emotion identification function) using the emotion identification model 59 performs various estimations and predictions regarding the user's emotions, including but not limited to these examples. Furthermore, emotion estimation and prediction also include, for example, emotion analysis.
[0139] In the smart glasses 214, specific processing is performed by the processor 46. The storage 50 stores a specific processing program 60. The processor 46 reads the specific processing program 60 from the storage 50 and executes the read specific processing program 60 on the RAM 48. The specific processing is realized by the processor 46 acting as a control unit 46A according to the specific processing program 60 executed on the RAM 48. The smart glasses 214 also have a data generation model 58 and an emotion identification model 59, similar to the data generation model and emotion identification model 59, and can perform processing similar to that of the specific processing unit 290 using these models.
[0140] Furthermore, other devices besides the data processing device 12 may also have the data generation model 58. For example, a server device may have the data generation model 58. In this case, the data processing device 12 obtains processing results (such as prediction results) using the data generation model 58 by communicating with the server device that has the data generation model 58. Also, the data processing device 12 may be a server device or a terminal device owned by the user (for example, a mobile phone, robot, home appliance, etc.).
[0141] The specific processing unit 290 transmits the result of the specific processing to the smart glasses 214. In the smart glasses 214, the control unit 46A causes the speaker 240 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.
[0142] The data generation model 58 is a so-called generative AI. An example of a data generation model 58 is a generative AI such as ChatGPT. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and inference data such as audio data representing speech, text data representing text, and image data representing images (e.g., still image data or video data). The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference result in one or more data formats such as audio data, text data, and image data. The data generation model 58 includes, for example, text generation AI, image generation AI, and multimodal generation AI. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization. The specific processing unit 290 performs the specific processing described above using the data generation model 58. The data generation model 58 may be a fine-tuned model that outputs inference results from prompts that do not contain instructions, in which case the data generation model 58 can output inference results from prompts that do not contain instructions. In the data processing device 12, etc., there are multiple types of data generation models 58, and the data generation model 58 includes AI other than generative AI. AI other than generative AI includes, for example, linear regression, logistic regression, decision trees, random forests, support vector machines (SVM), k-means clustering, convolutional neural networks (CNN), recurrent neural networks (RNN), generative adversarial networks (GAN), or naive Bayes, and can perform various processes, but is not limited to these examples. Also, the AI may be an AI agent. Furthermore, when the processing of each part described above is performed by the AI, the processing may be performed by the AI in part or in whole, but is not limited to this example. Also, processing performed by an AI including a generative AI may be replaced by rule-based processing, and rule-based processing may be replaced by processing performed by an AI including a generative AI.
[0143] The data processing system 210 according to the second embodiment performs the same processing as the data processing system 10 according to the first embodiment. The processing by the data processing system 210 is performed by the specific processing unit 290 of the data processing device 12 or the control unit 46A of the smart glasses 214, but it may also be performed by the specific processing unit 290 of the data processing device 12 and the control unit 46A of the smart glasses 214. In addition, the specific processing unit 290 of the data processing device 12 acquires or collects information necessary for processing from the smart glasses 214 or an external device, and the smart glasses 214 acquires or collects information necessary for processing from the data processing device 12 or an external device.
[0144] Each of the multiple elements described above, including the collection unit, detection unit, generation unit, implementation unit, and report generation unit, is implemented by, for example, at least one of the smart glasses 214 and the data processing unit 12. For example, the collection unit collects cyberattack data using the camera 42 and microphone 238 of the smart glasses 214 and analyzes it by the identification processing unit 290 of the data processing unit 12. The detection unit is implemented by the identification processing unit 290 of the data processing unit 12 and detects cyber threats by analyzing the collected data. The generation unit is implemented by the identification processing unit 290 of the data processing unit 12 and generates countermeasures for the detected threats. The implementation unit is implemented by the control unit 46A of the smart glasses 214 and implements the generated countermeasures. The report generation unit is implemented by the identification processing unit 290 of the data processing unit 12 and generates an incident response analysis report. The correspondence between each unit and the device or control unit is not limited to the example described above and can be changed in various ways.
[0145] [Third Embodiment] Figure 5 shows an example of the configuration of the data processing system 310 according to the third embodiment.
[0146] As shown in Figure 5, the data processing system 310 includes a data processing device 12 and a headset terminal 314. An example of the data processing device 12 is a server.
[0147] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN and / or LAN.
[0148] The headset terminal 314 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication interface 44, and a display 343. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, camera 42, and display 343 are also connected to the bus 52.
[0149] The microphone 238 receives voice commands and other instructions from the user by receiving voice signals. The microphone 238 captures the voice signals from the user, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.
[0150] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, which captures images of the area around the user (for example, an imaging range defined by a field of view equivalent to the field of vision of a typical healthy person).
[0151] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.
[0152] Figure 6 shows an example of the main functions of the data processing device 12 and the headset terminal 314. As shown in Figure 6, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.
[0153] The processor 28 reads a specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 acting as a specific processing unit 290 according to the specific processing program 56 executed on the RAM 30.
[0154] Storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290. The identification processing unit 290 can estimate the user's emotions using the emotion identification model 59 and perform identification processing using the user's emotions. The emotion estimation function (emotion identification function) using the emotion identification model 59 performs various estimations and predictions regarding the user's emotions, including but not limited to these examples. Furthermore, emotion estimation and prediction also include, for example, emotion analysis.
[0155] In the headset terminal 314, specific processing is performed by the processor 46. The storage 50 stores a specific program 60. The processor 46 reads the specific program 60 from the storage 50 and executes the read specific program 60 on the RAM 48. The specific processing is realized by the processor 46 acting as a control unit 46A according to the specific program 60 executed on the RAM 48. The headset terminal 314 also has a data generation model 58 and an emotion identification model 59, similar to the data generation model and emotion identification model 59, and can perform processing similar to that of the specific processing unit 290 using these models.
[0156] Furthermore, other devices besides the data processing device 12 may also have the data generation model 58. For example, a server device may have the data generation model 58. In this case, the data processing device 12 obtains processing results (such as prediction results) using the data generation model 58 by communicating with the server device that has the data generation model 58. Also, the data processing device 12 may be a server device or a terminal device owned by the user (for example, a mobile phone, robot, home appliance, etc.).
[0157] The specific processing unit 290 transmits the result of the specific processing to the headset terminal 314. In the headset terminal 314, the control unit 46A causes the speaker 240 and display 343 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.
[0158] The data generation model 58 is a so-called generative AI. An example of a data generation model 58 is a generative AI such as ChatGPT. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and inference data such as audio data representing speech, text data representing text, and image data representing images (e.g., still image data or video data). The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference result in one or more data formats such as audio data, text data, and image data. The data generation model 58 includes, for example, text generation AI, image generation AI, and multimodal generation AI. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization. The specific processing unit 290 performs the specific processing described above using the data generation model 58. The data generation model 58 may be a fine-tuned model that outputs inference results from prompts that do not contain instructions, in which case the data generation model 58 can output inference results from prompts that do not contain instructions. In the data processing device 12, etc., there are multiple types of data generation models 58, and the data generation model 58 includes AI other than generative AI. AI other than generative AI includes, for example, linear regression, logistic regression, decision trees, random forests, support vector machines (SVM), k-means clustering, convolutional neural networks (CNN), recurrent neural networks (RNN), generative adversarial networks (GAN), or naive Bayes, and can perform various processes, but is not limited to these examples. Also, the AI may be an AI agent. Furthermore, when the processing of each part described above is performed by the AI, the processing may be performed by the AI in part or in whole, but is not limited to this example. Also, processing performed by an AI including a generative AI may be replaced by rule-based processing, and rule-based processing may be replaced by processing performed by an AI including a generative AI.
[0159] The data processing system 310 according to the third embodiment performs the same processing as the data processing system 10 according to the first embodiment. The processing by the data processing system 310 is performed by the specific processing unit 290 of the data processing device 12 or the control unit 46A of the headset terminal 314, but may also be performed by the specific processing unit 290 of the data processing device 12 and the control unit 46A of the headset terminal 314. In addition, the specific processing unit 290 of the data processing device 12 acquires or collects information necessary for processing from the headset terminal 314 or an external device, and the headset terminal 314 acquires or collects information necessary for processing from the data processing device 12 or an external device.
[0160] Each of the multiple elements described above, including the collection unit, detection unit, generation unit, implementation unit, and report generation unit, is implemented in at least one of the headset terminal 314 and the data processing unit 12. For example, the collection unit collects cyberattack data using the camera 42 and microphone 238 of the headset terminal 314 and analyzes it using the identification processing unit 290 of the data processing unit 12. The detection unit is implemented by the identification processing unit 290 of the data processing unit 12 and detects cyber threats by analyzing the collected data. The generation unit is implemented by the identification processing unit 290 of the data processing unit 12 and generates countermeasures for the detected threats. The implementation unit is implemented by the control unit 46A of the headset terminal 314 and implements the generated countermeasures. The report generation unit is implemented by the identification processing unit 290 of the data processing unit 12 and generates an incident response analysis report. The correspondence between each unit and the device or control unit is not limited to the example described above and can be modified in various ways.
[0161] [Fourth Embodiment] Figure 7 shows an example of the configuration of the data processing system 410 according to the fourth embodiment.
[0162] As shown in Figure 7, the data processing system 410 includes a data processing device 12 and a robot 414. An example of the data processing device 12 is a server.
[0163] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN and / or LAN.
[0164] The robot 414 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication interface 44, and a controlled object 443. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, camera 42, and controlled object 443 are also connected to the bus 52.
[0165] The microphone 238 receives voice commands and other instructions from the user by receiving voice signals. The microphone 238 captures the voice signals from the user, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.
[0166] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS image sensor or CCD image sensor, which captures images of the area around the user (for example, an imaging range defined by a field of view equivalent to the field of vision of a typical healthy person).
[0167] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.
[0168] The controlled object 443 includes a display device, LEDs in the eyes, and motors that drive the arms, hands, and feet. The posture and gestures of the robot 414 are controlled by controlling the motors of the arms, hands, and feet. Some of the robot 414's emotions can be expressed by controlling these motors. The robot 414's facial expressions can also be expressed by controlling the illumination state of the LEDs in its eyes.
[0169] Figure 8 shows an example of the main functions of the data processing device 12 and the robot 414. As shown in Figure 8, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.
[0170] The processor 28 reads a specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 acting as a specific processing unit 290 according to the specific processing program 56 executed on the RAM 30.
[0171] Storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290. The identification processing unit 290 can estimate the user's emotions using the emotion identification model 59 and perform identification processing using the user's emotions. The emotion estimation function (emotion identification function) using the emotion identification model 59 performs various estimations and predictions regarding the user's emotions, including but not limited to these examples. Furthermore, emotion estimation and prediction also include, for example, emotion analysis.
[0172] In robot 414, specific processing is performed by processor 46. A specific program 60 is stored in storage 50. Processor 46 reads the specific program 60 from storage 50 and executes it on RAM 48. The specific processing is achieved by processor 46 acting as a control unit 46A according to the specific program 60 executed on RAM 48. Robot 414 also has data generation model 58 and emotion identification model 59, similar to those of the robot, and can perform processing similar to that of the specific processing unit 290 using these models.
[0173] Furthermore, other devices besides the data processing device 12 may also have the data generation model 58. For example, a server device may have the data generation model 58. In this case, the data processing device 12 obtains processing results (such as prediction results) using the data generation model 58 by communicating with the server device that has the data generation model 58. Also, the data processing device 12 may be a server device or a terminal device owned by the user (for example, a mobile phone, robot, home appliance, etc.).
[0174] The specific processing unit 290 transmits the result of the specific processing to the robot 414. In the robot 414, the control unit 46A causes the speaker 240 and the controlled object 443 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.
[0175] The data generation model 58 is a so-called generative AI. An example of a data generation model 58 is a generative AI such as ChatGPT. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and inference data such as audio data representing speech, text data representing text, and image data representing images (e.g., still image data or video data). The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference result in one or more data formats such as audio data, text data, and image data. The data generation model 58 includes, for example, text generation AI, image generation AI, and multimodal generation AI. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization. The specific processing unit 290 performs the specific processing described above using the data generation model 58. The data generation model 58 may be a fine-tuned model that outputs inference results from prompts that do not contain instructions, in which case the data generation model 58 can output inference results from prompts that do not contain instructions. In the data processing device 12, etc., there are multiple types of data generation models 58, and the data generation model 58 includes AI other than generative AI. AI other than generative AI includes, for example, linear regression, logistic regression, decision trees, random forests, support vector machines (SVM), k-means clustering, convolutional neural networks (CNN), recurrent neural networks (RNN), generative adversarial networks (GAN), or naive Bayes, and can perform various processes, but is not limited to these examples. Also, the AI may be an AI agent. Furthermore, when the processing of each part described above is performed by the AI, the processing may be performed by the AI in part or in whole, but is not limited to this example. Also, processing performed by an AI including a generative AI may be replaced by rule-based processing, and rule-based processing may be replaced by processing performed by an AI including a generative AI.
[0176] The data processing system 410 according to the fourth embodiment performs the same processing as the data processing system 10 according to the first embodiment. The processing by the data processing system 410 is performed by the specific processing unit 290 of the data processing device 12 or the control unit 46A of the robot 414, but it may also be performed by the specific processing unit 290 of the data processing device 12 and the control unit 46A of the robot 414. In addition, the specific processing unit 290 of the data processing device 12 acquires or collects information necessary for processing from the robot 414 or an external device, and the robot 414 acquires or collects information necessary for processing from the data processing device 12 or an external device.
[0177] Each of the multiple elements described above, including the collection unit, detection unit, generation unit, implementation unit, and report generation unit, is implemented by, for example, at least one of the robot 414 and the data processing unit 12. For example, the collection unit collects cyberattack data using the camera 42 and microphone 238 of the robot 414 and analyzes it by the identification processing unit 290 of the data processing unit 12. The detection unit is implemented by the identification processing unit 290 of the data processing unit 12 and detects cyber threats by analyzing the collected data. The generation unit is implemented by the identification processing unit 290 of the data processing unit 12 and generates countermeasures for the detected threats. The implementation unit is implemented by the control unit 46A of the robot 414 and implements the generated countermeasures. The report generation unit is implemented by the identification processing unit 290 of the data processing unit 12 and generates an incident response analysis report. The correspondence between each unit and the device or control unit is not limited to the example described above and can be changed in various ways.
[0178] Furthermore, the emotion identification model 59, acting as an emotion engine, may determine the user's emotion according to a specific mapping. Specifically, the emotion identification model 59 may determine the user's emotion according to a specific mapping, which is an emotion map (see Figure 9). Similarly, the emotion identification model 59 may also determine the robot's emotion, and the identification processing unit 290 may perform identification processing using the robot's emotion.
[0179] Figure 9 shows the emotion map 400, in which multiple emotions are mapped. In the emotion map 400, emotions are arranged in concentric circles radiating from the center. The closer to the center of the concentric circles, the more primitive the emotions are located. Further out of the concentric circles, emotions representing states and actions arising from mental states are located. Emotion is a concept that includes feelings and mental states. On the left side of the concentric circles, emotions that are generally generated from reactions occurring in the brain are located. On the right side of the concentric circles, emotions that are generally induced by situational judgment are located. Above and below the concentric circles, emotions that are generally generated from reactions occurring in the brain and induced by situational judgment are located. In addition, the emotion of "pleasure" is located on the upper side of the concentric circles, and the emotion of "displeasure" is located on the lower side. Thus, in the emotion map 400, multiple emotions are mapped based on the structure in which emotions arise, and emotions that are likely to occur simultaneously are mapped close together.
[0180] These emotions are distributed at the 3 o'clock position on the Emotion Map 400, and usually fluctuate between feelings of security and anxiety. In the right half of the Emotion Map 400, situational awareness takes precedence over internal feelings, resulting in a calm impression.
[0181] The inside of the Emotion Map 400 represents inner thoughts, while the outside represents actions. Therefore, the further you go from the outside of the Emotion Map 400, the more visible (expressed in actions) your emotions become.
[0182] Here, human emotions are based on various balances, such as posture and blood sugar levels. When these balances deviate from the ideal, it results in discomfort, and when they approach the ideal, it results in pleasure. Similarly, in robots, cars, and motorcycles, emotions can be created based on various balances, such as posture and battery level. When these balances deviate from the ideal, it results in discomfort, and when they approach the ideal, it results in pleasure. The emotion map can be generated based, for example, on Dr. Mitsuyoshi's emotion map (Research on a system for analyzing brain physiological signals of speech emotion recognition and emotion, Tokushima University, doctoral dissertation: https: / / ci.nii.ac.jp / naid / 500000375379). The left half of the emotion map contains emotions belonging to a region called "response," where sensation is dominant. The right half of the emotion map contains emotions belonging to a region called "situation," where situational awareness is dominant.
[0183] The emotion map defines two emotions that promote learning. One is the emotion around the middle of the negative "repentance" and "reflection" on the situation side. In other words, it is when the robot experiences negative emotions such as "I never want to feel this way again" or "I don't want to be scolded again." The other is the emotion around the positive "desire" on the reaction side. In other words, it is when the robot has positive feelings such as "I want more" or "I want to know more."
[0184] The emotion identification model 59 inputs user input into a pre-trained neural network, obtains emotion values representing each emotion shown in the emotion map 400, and determines the user's emotion. This neural network is pre-trained based on multiple training data sets, which are combinations of user input and emotion values representing each emotion shown in the emotion map 400. Furthermore, this neural network is trained so that emotions located close together have similar values, as shown in the emotion map 900 in Figure 10. Figure 10 shows an example where multiple emotions such as "reassured," "calm," and "confident" have similar emotion values.
[0185] In the above embodiment, an example was given in which a specific process is performed by a single computer 22. However, the technology of this disclosure is not limited thereto, and a distributed processing method for the specific process may be used, which includes computer 22 and multiple other computers.
[0186] In the above embodiment, an example was given in which the specific processing program 56 is stored in the storage 32, but the technology of this disclosure is not limited thereto. For example, the specific processing program 56 may be stored in a portable, computer-readable, non-temporary storage medium such as a USB (Universal Serial Bus) memory. The specific processing program 56 stored in the non-temporary storage medium is installed in the computer 22 of the data processing device 12. The processor 28 executes specific processing according to the specific processing program 56.
[0187] Alternatively, the specific processing program 56 may be stored in a storage device such as a server connected to the data processing device 12 via the network 54, and the specific processing program 56 may be downloaded and installed on the computer 22 in response to a request from the data processing device 12.
[0188] Furthermore, it is not necessary to store the entirety of the specific processing program 56 in a storage device such as a server connected to the data processing device 12 via the network 54, or to store the entirety of the specific processing program 56 in the storage 32; it is acceptable to store only a portion of the specific processing program 56.
[0189] The following types of processors can be used as hardware resources to perform specific processing. Examples of processors include a CPU, a general-purpose processor that functions as a hardware resource to perform specific processing by executing software, i.e., a program. Other examples of processors include dedicated electrical circuits, such as FPGAs (Field-Programmable Gate Arrays), PLDs (Programmable Logic Devices), or ASICs (Application Specific Integrated Circuits), which have circuit configurations specifically designed to perform specific processing. All of these processors have built-in or connected memory, and all of them perform specific processing by using memory.
[0190] The hardware resource that performs a specific process may consist of one of these various processors, or it may consist of a combination of two or more processors of the same or different types (for example, a combination of multiple FPGAs, or a combination of a CPU and an FPGA). Alternatively, the hardware resource that performs a specific process may consist of a single processor.
[0191] Examples of configurations using a single processor include, firstly, a configuration in which one or more CPUs and software are combined to form a single processor, and this processor functions as a hardware resource that performs a specific process. Secondly, there is a configuration using a processor that realizes the functions of the entire system, including multiple hardware resources that perform a specific process, on a single IC chip, as exemplified by SoCs (System-on-a-chip). In this way, a specific process is realized using one or more of the above types of processors as hardware resources.
[0192] Furthermore, the hardware structure of these various processors can more specifically utilize electrical circuits that combine circuit elements such as semiconductor devices. Also, the specific processing described above is merely an example. Therefore, it goes without saying that unnecessary steps can be deleted, new steps added, or the processing order rearranged, as long as it does not deviate from the main purpose.
[0193] Furthermore, although the above-described examples were divided into four embodiments, some or all of these embodiments may be combined. Also, the smart device 14, smart glasses 214, headset terminal 314, and robot 414 are just examples, and they may be combined, or other devices may be used. Also, although the above-described examples were divided into two embodiments, Embodiment 1 and Embodiment 2, these may be combined.
[0194] The descriptions and illustrations presented above are detailed explanations of the technical aspects of this disclosure and are merely examples of the technical aspects. For example, the above descriptions of the structure, function, operation, and effect are examples of the structure, function, operation, and effect of the technical aspects of this disclosure. Therefore, it goes without saying that you may delete unnecessary parts, add new elements, or replace elements in the descriptions and illustrations presented above, as long as you do not deviate from the essence of the technical aspects of this disclosure. Furthermore, in order to avoid confusion and facilitate understanding of the technical aspects of this disclosure, explanations of common technical knowledge and other things that do not require special explanation to enable the implementation of the technical aspects of this disclosure have been omitted from the descriptions and illustrations presented above.
[0195] All documents, patent applications, and technical standards described herein are incorporated by reference to the same extent as if each individual document, patent application, and technical standard were specifically and individually noted to be incorporated by reference.
[0196] (Note 1) The data collection unit collects data on cyberattacks, A detection unit analyzes the data collected by the aforementioned collection unit and detects cyber threats, A generation unit generates countermeasures for threats detected by the detection unit, An implementation unit that implements the countermeasures generated by the generation unit, It comprises a report generation unit that generates an analysis report for incident response, and A system characterized by the following features. (Note 2) The aforementioned collection unit is Collect data on past cyberattacks and data on newly occurring attacks. The system described in Appendix 1, characterized by the features described herein. (Note 3) The detection unit is Detecting anomalous activity using machine learning models The system described in Appendix 1, characterized by the features described herein. (Note 4) The generating unit is Using natural language processing, we analyze the attacker's intentions and methods and generate countermeasures. The system described in Appendix 1, characterized by the features described herein. (Note 5) The aforementioned implementation unit is Isolation measures will be taken for detected malware. The system described in Appendix 1, characterized by the features described herein. (Note 6) The aforementioned implementation unit is Automatically delete emails that are suspected of being phishing attacks. The system described in Appendix 1, characterized by the features described herein. (Note 7) The report generation unit, We automatically generate and provide real-time analysis reports for incident response. The system described in Appendix 1, characterized by the features described herein. (Note 8) The aforementioned collection unit is We estimate user sentiment and adjust the timing of cyberattack data collection based on the estimated user sentiment. The system described in Appendix 1, characterized by the features described herein. (Note 9) The aforementioned collection unit is Analyze past cyberattack data to select the optimal data collection method. The system described in Appendix 1, characterized by the features described herein. (Note 10) The aforementioned collection unit is When collecting cyberattack data, filter it based on specific industries or regions. The system described in Appendix 1, characterized by the features described herein. (Note 11) The aforementioned collection unit is It estimates user sentiment and determines the priority of cyberattack data to collect based on the estimated user sentiment. The system described in Appendix 1, characterized by the features described herein. (Note 12) The aforementioned collection unit is When collecting cyberattack data, the system prioritizes collecting highly relevant data based on the user's geographical location. The system described in Appendix 1, characterized by the features described herein. (Note 13) The aforementioned collection unit is When collecting cyberattack data, we analyze users' social media activity and collect relevant data. The system described in Appendix 1, characterized by the features described herein. (Note 14) The detection unit is It estimates the user's emotions and adjusts the detection criteria for abnormal activity based on the estimated user emotions. The system described in Appendix 1, characterized by the features described herein. (Note 15) The detection unit is Using machine learning models to detect anomalous activity during specific time periods or days of the week. The system described in Appendix 1, characterized by the features described herein. (Note 16) The detection unit is When detecting an abnormal activity, different detection algorithms are applied depending on the type of abnormal activity. The system described in Appendix 1, characterized by the features described herein. (Note 17) The detection unit is It estimates the user's emotions and adjusts the order in which abnormal activity detection results are displayed based on the estimated user emotions. The system described in Appendix 1, characterized by the features described herein. (Note 18) The detection unit is When detecting abnormal activity, the geographical distribution of the activity should be taken into consideration. The system described in Appendix 1, characterized by the features described herein. (Note 19) The detection unit is During detection, we improve the accuracy of the detection by referring to relevant literature on abnormal activity. The system described in Appendix 1, characterized by the features described herein. (Note 20) The generating unit is We estimate the user's emotions and adjust the method of generating countermeasures based on the estimated user emotions. The system described in Appendix 1, characterized by the features described herein. (Note 21) The generating unit is When generating countermeasures, the effectiveness of past countermeasures is analyzed to generate the optimal countermeasure. The system described in Appendix 1, characterized by the features described herein. (Note 22) The generating unit is When generating countermeasures, different generation algorithms are applied depending on the type of cyberattack. The system described in Appendix 1, characterized by the features described herein. (Note 23) The generating unit is It estimates the user's emotions and determines the priority of countermeasures to be generated based on the estimated user emotions. The system described in Appendix 1, characterized by the features described herein. (Note 24) The generating unit is When generating countermeasures, prioritize them based on when the cyberattack occurred. The system described in Appendix 1, characterized by the features described herein. (Note 25) The generating unit is When generating countermeasures, we refer to relevant literature on cyberattacks to improve the accuracy of those countermeasures. The system described in Appendix 1, characterized by the features described herein. (Note 26) The aforementioned implementation unit is We estimate the user's emotions and adjust the implementation of countermeasures based on the estimated user emotions. The system described in Appendix 1, characterized by the features described herein. (Note 27) The aforementioned implementation unit is During implementation, past implementation results will be analyzed to select the optimal implementation method. The system described in Appendix 1, characterized by the features described herein. (Note 28) The aforementioned implementation unit is When implementing the attack, different methods of implementation will be applied depending on the type of cyberattack. The system described in Appendix 1, characterized by the features described herein. (Note 29) The aforementioned implementation unit is The system estimates the user's emotions and determines the order in which countermeasures should be implemented based on those estimated emotions. The system described in Appendix 1, characterized by the features described herein. (Note 30) The aforementioned implementation unit is When implementing the measures, the geographical distribution of cyberattacks will be taken into consideration. The system described in Appendix 1, characterized by the features described herein. (Note 31) The aforementioned implementation unit is During implementation, refer to relevant literature on cyberattacks to improve the accuracy of the implementation. The system described in Appendix 1, characterized by the features described herein. (Note 32) The report generation unit, It estimates user sentiment and adjusts how reports are displayed based on the estimated user sentiment. The system described in Appendix 1, characterized by the features described herein. (Note 33) The report generation unit, When generating reports, the report content is optimized by referring to past incident data. The system described in Appendix 1, characterized by the features described herein. (Note 34) The report generation unit, When generating reports, different report generation algorithms are applied depending on the type of cyberattack. The system described in Appendix 1, characterized by the features described herein. (Note 35) The report generation unit, It estimates user sentiment and prioritizes reports based on the estimated user sentiment. The system described in Appendix 1, characterized by the features described herein. (Note 36) The report generation unit, When generating the report, adjust the report content based on when the cyberattack occurred. The system described in Appendix 1, characterized by the features described herein. (Note 37) The report generation unit, When generating reports, we refer to relevant literature on cyberattacks to improve the accuracy of the reports. The system described in Appendix 1, characterized by the features described herein. [Explanation of symbols]
[0197] 10, 210, 310, 410 Data Processing Systems 12 Data Processing Devices 14 Smart Devices 214 Smart Glasses 314 Headset-type terminal 414 Robots
Claims
1. The data collection unit collects data on cyberattacks, A detection unit analyzes the data collected by the aforementioned collection unit and detects cyber threats, A generation unit generates countermeasures for threats detected by the detection unit, An implementation unit that implements the countermeasures generated by the generation unit, It comprises a report generation unit that generates an analysis report for incident response, and A system characterized by the following features.
2. The aforementioned collection unit is Collect data on past cyberattacks and data on newly occurring attacks. The system according to feature 1.
3. The detection unit is Detecting anomalous activity using machine learning models The system according to feature 1.
4. The generating unit is Using natural language processing, we analyze the attacker's intentions and methods and generate countermeasures. The system according to feature 1.
5. The aforementioned implementation unit is Isolation measures will be taken for detected malware. The system according to feature 1.
6. The aforementioned implementation unit is Automatically delete emails that are suspected of being phishing attacks. The system according to feature 1.
7. The report generation unit, We automatically generate and provide real-time analysis reports for incident response. The system according to feature 1.
8. The aforementioned collection unit is We estimate user sentiment and adjust the timing of cyberattack data collection based on the estimated user sentiment. The system according to feature 1.
Citation Information
Patent Citations
Persona chatbot control method and system
JP2022180282A